This policy explains what personal data BLESSED LOGIC SYSTEMS S.R.L. processes, why, on what legal basis, for how long, and which rights you hold under Regulation (EU) 2016/679 (GDPR) and, in Romania, Legea nr. 190/2018 and Legea nr. 506/2004.
1. Who is responsible
The data controller is:
| Legal name | BLESSED LOGIC SYSTEMS S.R.L. |
|---|---|
| CUI | 54775375 |
| Trade Register No. | J2026034847000 |
| Country of establishment | Romania, European Union |
| Contact for data protection | blessed.logic.systems@gmail.com |
The company is not required to appoint a Data Protection Officer, as it does not carry out large-scale monitoring or process special categories of data on a large scale. Data protection enquiries are handled directly at the address above.
2. What data is processed
2.1 Data collected by this website: none
This website has no contact form, no account, no newsletter and no comment field. There is nothing to fill in and nothing is submitted, so browsing it does not create any record about you beyond the technical log described in 2.3. If you want to reach the Provider you do so on Discord or by email, using your own account, on your own terms.
2.2 Data exchanged if you choose to make contact
If you write on Discord or by email, that conversation exists in the account you used and in the Provider's mailbox. Where an order follows, the Provider also processes the technical material you send (log files, crash dumps, source code excerpts, configuration) and the billing identification required for a valid invoice: for business clients the company name, registered address and tax identification number; for consumers, name and address.
Invoice data is kept because the law requires it, not by choice. Everything else is deleted on request, and technical material is deleted once the work it was sent for is finished.
2.3 Data generated automatically by this website
The web server writes a technical log entry for each request, containing the IP address, the date and time, the requested address, the response status, the referring page and the browser identification string. This log exists to keep the service running and to detect abuse.
2.4 What is deliberately not collected
- No analytics or statistics service of any kind.
- No advertising, remarketing or profiling technology.
- No social network buttons or embedded trackers.
- No fonts, scripts or stylesheets loaded from external servers, every asset on this site is served from this domain, so simply visiting a page does not reveal your address to any third party.
- No special categories of data under Article 9 GDPR are ever requested.
3. Purposes and legal bases
| Purpose | Data | Legal basis | Kept for |
|---|---|---|---|
| Answering a message you sent | The correspondence itself | Art. 6(1)(b), steps prior to a contract at your request | 24 months from the last exchange |
| Performing a contract | Correspondence, technical material, billing identification | Art. 6(1)(b), performance of a contract | Duration of the contract, then as below |
| Issuing and keeping invoices | Billing identification, order data | Art. 6(1)(c), legal obligation (accounting and tax law) | 10 years, under Legea contabilității nr. 82/1991 |
| Keeping the website available and secure | Server log data | Art. 6(1)(f), legitimate interest in security and availability | 30 days, then deleted |
| Defending or establishing legal claims | Contract file | Art. 6(1)(f), legitimate interest in legal defence | Until the limitation period expires |
| Keeping you signed in to the administration area | Session cookie | Art. 6(1)(f), strictly necessary for a service you requested | 7 days, or until sign-out |
4. Who else sees the data
Personal data is not sold, rented or exchanged. It is disclosed only to the following categories of recipient, and only to the extent necessary:
- The hosting provider of this website, acting as a processor under a written agreement.
- The email provider used for correspondence, acting as a processor.
- The accountant and, where required, the tax authority, for invoices and accounting records.
- The banking institution, for the execution of payments.
- Legal advisers or courts, where necessary to establish, exercise or defend a legal claim.
5. Transfers outside the European Economic Area
Processing takes place within the European Economic Area wherever possible. If a processor operates outside it, the transfer is covered by an adequacy decision of the European Commission or by the Standard Contractual Clauses. You can ask for details of the safeguards in place at any time.
6. Your rights
Under the GDPR you have the right to:
- Access, obtain confirmation of whether your data is processed and receive a copy of it (Art. 15).
- Rectification, have inaccurate data corrected or incomplete data completed (Art. 16).
- Erasure, have data deleted where it is no longer necessary and no legal obligation requires it to be kept (Art. 17).
- Restriction, have processing limited while a dispute about accuracy or lawfulness is resolved (Art. 18).
- Portability, receive data you provided in a structured, commonly used, machine-readable format (Art. 20).
- Objection, object to processing based on legitimate interest, on grounds relating to your situation (Art. 21).
- Withdraw consent at any time, where processing is based on consent, without affecting prior lawful processing.
Requests go to blessed.logic.systems@gmail.com and are answered within one month. That period may be extended by two further months for complex requests, in which case you are informed of the reason within the first month. Exercising these rights is free of charge; a reasonable fee may be charged only for manifestly unfounded or excessive repeat requests.
Note that invoices and accounting records cannot be deleted on request, because they are kept under a legal obligation for the retention period set by law.
7. Right to complain
If you believe your data has been processed unlawfully, you may lodge a complaint with the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement. In Romania that authority is Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, sector 1, Bucharest. Its powers in Romania are set out in Legea nr. 102/2005 and Legea nr. 190/2018. You may also seek a judicial remedy before the Romanian courts under article 79 GDPR.
8. How data is protected
- Traffic to this website is served over an encrypted connection.
- Administrative access is protected by a password hashed with bcrypt, session-bound authentication and rate limiting against brute force.
- All state-changing requests carry an anti-forgery token.
- Uploaded files are restricted by type and size, and are stored outside any executable path.
- Access to correspondence and client material is limited to the person operating the company.
- Client technical material, dumps, source excerpts, credentials shared for a task, is deleted once the task is complete, and always on request.
9. Automated decision-making
No automated decision-making or profiling within the meaning of Article 22 GDPR takes place. Every decision about an order is made by a person.
10. Children
This website and these services are directed at professional and business users and are not intended for children. Personal data of children is not knowingly collected. If you believe a child has sent personal data through this site, write to the address above and it will be deleted.
11. Changes to this policy
This policy may be updated to reflect changes in the service or in the law. The date of the version in force is shown at the top of this page. Material changes affecting existing clients are communicated by email.
BLESSED LOGIC SYSTEMS S.R.L. · CUI 54775375 · Trade Register No. J2026034847000 · blessed.logic.systems@gmail.com