Skip to content
Legal — Privacy

Privacy policy

What personal data we hold, why, who else sees it, and how to make us stop. Specific, because a privacy policy that could describe any company describes nothing.

Last updated ·

1. Who is responsible

The controller of your personal data is Kicked S.R.L., trade register J2025037766002, tax code 51862990, VAT RO51862990, registered in Pitești, Argeș county, Romania

For anything in this document, write to hello@kicked.ro. We have not appointed a data protection officer: our processing is not on a scale that requires one, and the same address reaches the people who actually run the systems.

2. What we collect, and why

  • When you write to us through the contact form or by email: your name, email address, optionally your company, and whatever you tell us about your project. We use it to answer you and, if it becomes a project, to carry it out. Legal basis: steps taken at your request before entering a contract, and our legitimate interest in replying to people who write to us.
  • When you open an account or order a service: your name, email, billing address, company and tax details, the services you hold, and your invoices. We need these to provide the service and to issue a legally valid invoice. Legal basis: performance of a contract, and a legal obligation for the accounting records.
  • When you register a domain: the registrant details the registry requires, including for .ro the registrant type and fiscal code. These are passed to the registry — that is what registration is. Legal basis: performance of your contract and the registry’s own rules.
  • From our network: our edge inspects traffic for attacks and records the source IP address, the time, and what the attempt looked like. An IP address is personal data, so we say so plainly. These records are about systems attacking ours, never about our customers’ visitors, and they are what the public threat map is built from — the map shows the attacker’s address, never yours. Legal basis: our legitimate interest in defending the network.
  • Server logs: our servers record requests in the ordinary way, including IP addresses, to keep the service running and to investigate abuse. Legal basis: legitimate interest.

3. What we do not do

This website runs no analytics. None — not a self-hosted one, not a "privacy-friendly" one. Nobody is measuring your visit, so there is no profile to build and nothing to opt out of. We do not advertise, we do not use tracking pixels, and we never sell or rent personal data to anyone.

4. Cookies and local storage

One cookie, named NEXT_LOCALE, remembers which language you are reading. That is all it holds — "ro" or "en" — and it is strictly necessary to serve the site in the language you chose, so it needs no consent banner.

Your light or dark theme choice is kept in your browser’s local storage and never leaves your device. The customer panel additionally uses a session cookie to keep you signed in, which is likewise strictly necessary.

5. Who else processes it

We keep the list short on purpose. Each of these acts on our instructions under a data processing agreement.

  • Resend — delivers our transactional email (order confirmations, invoices, replies). It sees the recipient address and the message.
  • Gazduire.Net — our domain registrar partner. Registrant details for a domain you register pass through them to the registry (RoTLD for .ro, EURid for .eu, and the relevant registry otherwise).
  • Our hosting infrastructure partners, who provide the machines and racks in Pitești, Bucharest and Frankfurt, and the reseller account behind part of our shared hosting.

We also disclose data where the law obliges us to — a court order, a lawful request from an authority. We do not hand data to anyone else.

6. Where it lives

In the European Union. Our points of presence are Pitești and Bucharest in Romania and Frankfurt in Germany. Where a processor operates outside the EU, the transfer relies on the European Commission’s standard contractual clauses.

7. How long we keep it

  • Messages from the contact form and the correspondence that follows: three years from the last exchange, then deleted.
  • Account and service data: for as long as you are a customer, and 30 days after a service ends, so that a service cancelled by mistake can be restored.
  • Invoices and accounting records: ten years, because Romanian accounting law requires it. This one we cannot shorten at your request.
  • Attack records behind the threat map: 90 days, then deleted.

8. Your rights

Under the GDPR you may ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a processing based on legitimate interest, and ask for your data in a portable format. Write to hello@kicked.ro and we answer within 30 days. We do not charge for this and we do not require a particular form of words.

If you think we have handled your data badly, tell us — and if that does not satisfy you, you may complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority where you live.

9. Security, and what happens if it fails

Data in transit is encrypted. Access to customer data is limited to the people who need it to do the work, over authenticated accounts. Backups are encrypted and verified by restoring them.

If a breach happens that puts your rights at risk, we notify the supervisory authority within 72 hours and tell you directly without undue delay. We will describe what happened plainly rather than hide it in a notice.

Rather talk to a person? We're one message away.