Privacy Policy
This Privacy Policy explains how Intersect Strategy Consulting ("INCON", "we", "us") collects, uses and protects personal data in connection with incon.ro (the "Site") and our consulting services, in accordance with the EU General Data Protection Regulation (GDPR) and applicable Romanian law.
1. Data controller
The data controller is Intersect Strategy Consulting S.R.L. ("INCON"), a Romanian company registered with the Trade Registry under no. J2023005313407, fiscal code (CUI) RO47838632, with registered office at Piața Națiunile Unite nr. 3-5, Bl. B2, Sc. 1, Et. 5, Ap. 28, Sector 4, Bucharest, Romania, represented by Andrei Panduru, Managing Director. Contact: andrei.panduru@incon.ro, +40 727 802 624.
2. What data we collect
We collect personal data in the following situations:
- When you use the "Book a Pilot Audit" form or contact us directly — name, work email address, company name, and any message or project details you choose to share. This data is sent to us by email and is not stored in a separate database.
- When you browse the Site — if you consent to Analytics cookies (not currently in use), we or an analytics provider may collect technical data such as pages viewed, approximate location (city/country level), device and browser type, and referring website. See our Cookie Policy for details.
Providing this information is voluntary. Without it, we will not be able to respond to your enquiry or schedule a pilot audit.
We do not knowingly collect any special category data (e.g. health, biometric data) through the Site. Eye-tracking data collected as part of a delivered engagement is governed separately by the engagement contract with the client company, not by this Site policy.
3. Why we process your data and legal basis
| Purpose | Legal basis |
|---|---|
| Responding to your enquiry or booking request | Steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) |
| Delivering and managing a client engagement | Performance of a contract (Art. 6(1)(b) GDPR) |
| Site security and preventing misuse | Legitimate interest (Art. 6(1)(f) GDPR) |
| Analytics (only if you consent) | Consent (Art. 6(1)(a) GDPR) |
| Marketing outreach (only if you consent) | Consent (Art. 6(1)(a) GDPR) |
4. Who we share data with
We do not sell personal data. We may share it with service providers who process it on our behalf and under our instructions, such as our email and website hosting provider, and — only if you consent to the relevant cookie category — analytics or marketing platforms (e.g. Google Analytics, Meta, LinkedIn). Where a provider is located outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses. Fonts and other static assets on the Site are self-hosted on our own server, so no data is shared with a font provider simply by visiting the Site.
5. How long we keep your data
Enquiry and contact data is kept for as long as needed to respond to you and, if no engagement follows, for up to 24 months afterwards. Data relating to an active or completed client engagement is kept for the duration required by the contract and by applicable Romanian accounting and tax law. Analytics data, where enabled, is retained according to the provider's default retention settings.
6. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request erasure of your data, where applicable;
- Restrict or object to certain processing;
- Request portability of data you provided to us;
- Withdraw consent at any time, without affecting processing carried out before withdrawal;
- Lodge a complaint with the Romanian supervisory authority, ANSPDCP (www.dataprotection.ro), or with the supervisory authority in your own EU country.
To exercise any of these rights, contact us at andrei.panduru@incon.ro. You can manage cookie-based data collection directly via our Cookie Policy preferences.
7. Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal or similarly significant effects on you.
8. Security
We apply reasonable technical and organisational measures to protect personal data against unauthorised access, loss or misuse. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children
The Site is intended for business audiences and is not directed at, or knowingly used to collect data from, individuals under 16.
10. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date above indicates the latest revision. Material changes will be reflected on this page.
11. Contact
Questions about this policy or how we handle your data can be sent to andrei.panduru@incon.ro.