Effective and last updated: 18 June 2026.
This policy explains how personal data is processed through ihavebig.business, in accordance with Regulation (EU) 2016/679 (GDPR).
The controller is TABACU TUDOR-LUCREȚIU P.F.A. (Government Emergency Ordinance no. 44/2008), CUI 52423615, Trade Register F2025032098001, with its registered office at 136 Bucureștii Noi Blvd., apt. 5, Sector 1, Bucharest 012366, Romania. Data-protection contact: tudor.up2u (at) gmail.com.
If the materials sent by the client contain personal data of third parties, they are processed solely on the client's instructions and only to carry out the project, with the controller acting as a processor; the client remains the controller of that data.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Replying to enquiries and preparing a quote | Pre-contractual steps — Art. 6(1)(b) |
| Performing the services contract | Performance of a contract — Art. 6(1)(b) |
| Issuing invoices and collecting payment | Performance of a contract and legal obligation — Art. 6(1)(b) and (c) |
| Meeting tax and accounting obligations | Legal obligation — Art. 6(1)(c) |
| Operating and securing the website | Legitimate interest — Art. 6(1)(f) |
Data is not sold or rented. It may be shared with the following service providers, only as necessary:
Some providers (Stripe, Wise, Vercel, Google) are established outside the European Economic Area. Where data is transferred outside the EEA, the transfer is based on appropriate safeguards provided by the GDPR, in particular the EU Standard Contractual Clauses.
| Category | Period |
|---|---|
| Enquiries with no contract concluded | 24 months from last contact |
| Project correspondence and materials | Duration of the engagement plus 3 years |
| Accounting / invoicing records | 10 years, as required by Romanian Accounting Law no. 82/1991 |
The controller applies appropriate technical and organisational measures: encryption in transit (HTTPS/TLS), restricted access to data, and never receiving full card details. In the event of a security breach that poses a risk to the rights of data subjects, the controller notifies the supervisory authority within 72 hours.
This is a presentation website and does not use marketing cookies, tracking pixels or third-party analytics tools. The hosting provider may set strictly necessary cookies required for operation. To display fonts, the site loads resources from Google Fonts, which receives the visitor's IP address — a technically necessary operation.
You have the right of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent. To exercise these rights, write to tudor.up2u (at) gmail.com; we respond within 30 days. You also have the right to lodge a complaint with the supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP, dataprotection.ro).
This policy may be updated; the "last updated" date above always shows the current version.