Privacy policy
How we collect, use and protect your personal data on the Tino website, under Regulation (EU) 2016/679 (GDPR).
Last updated: ⟨dd.mm.yyyy — to be confirmed⟩
1. Who we are (the data controller)
Your personal data is processed by ⟨Speedwell legal entity for Tino — to be confirmed⟩, registered office ⟨address — to be confirmed⟩, Trade Register no. ⟨J…/…/… — to be confirmed⟩, tax ID (CUI) ⟨to be confirmed⟩, part of the Speedwell group, referred to below as “we” or “the controller”.
For any data-protection question, write to ⟨contact email — to be confirmed⟩. Data protection officer (if appointed): ⟨DPO name / email — to be confirmed⟩.
2. What we collect
- Chat conversations: the messages you write to the project assistant and any contact details you choose to share in the conversation (for example name, phone, email), so we can answer and get back to you.
- First-party functional measurement: once you make a choice in the cookie banner, we record visits, sessions, the pages and sections you view and whether the chat works, linked to a random identifier stored in your browser.
- Detailed interaction data (consent only): if you accept the Analytics category, we also record clicks on page elements, cursor paths and heatmaps.
- Where the visit came from: campaign parameters in the page address (for example utm_source) and the referring page, so we know which channels bring visitors.
- Technical data: IP address, device type and browser, processed by the server to deliver pages and for security.
We do not ask for or knowingly collect special categories of data. Please do not share them in the chat.
3. The chat assistant
Chat answers are generated automatically by an AI assistant from information about the project. The assistant takes no decision with legal effect on you. When a question needs a person to confirm it, the project team can take over the conversation.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Answering you in the chat and contacting you at your request (details, availability, viewings) | Steps taken at your request before a contract — Art. 6(1)(b) |
| First-party functional measurement (visits, sessions, chat operation) | Legitimate interest — Art. 6(1)(f): running and improving the site |
| Detailed analytics (clicks, cursor paths, heatmaps) | Consent — Art. 6(1)(a) |
| Marketing and campaign measurement (reserved; inactive today) | Consent — Art. 6(1)(a) |
| Complying with legal obligations and defending legal claims | Legal obligation — Art. 6(1)(c); legitimate interest — Art. 6(1)(f) |
5. How long we keep data
We keep conversations and contact details for as long as needed to handle your request and our relationship with you, then for ⟨period — to be confirmed⟩ after the last contact, unless the law requires longer. Measurement data is kept for ⟨period — to be confirmed⟩. When these periods end, the data is deleted or anonymised.
6. Who we share data with
Only for the purposes above, data may be accessed by:
- the provider of the platform that hosts the website, the chat and the customer-management system, as a processor;
- the provider of the AI model that generates the assistant's answers, as a processor;
- the project's sales team and our advisers (legal, accounting), where needed;
- public authorities, where the law requires it.
List of providers: ⟨to be completed⟩. We do not sell your personal data.
7. Transfers outside the EU/EEA
Some providers (for example the AI model provider) may process data outside the European Economic Area. Where they do, we make sure appropriate safeguards are in place, such as the European Commission's standard contractual clauses. Details: ⟨to be completed⟩.
8. Your rights
Under the GDPR you have the right to: access your data; rectification; erasure (“the right to be forgotten”); restriction of processing; data portability; objection to processing based on legitimate interest; and withdrawal of consent at any time, without affecting the lawfulness of earlier processing.
To exercise them, write to ⟨contact email — to be confirmed⟩. You may also complain to the Romanian data protection authority, ANSPDCP, www.dataprotection.ro.
9. Security
We apply reasonable technical and organisational measures to protect data against unauthorised access, loss or disclosure. No system, however, is completely secure.
10. Cookies
What we store in your browser, and what each consent level does, is set out in the Cookie policy. You can change your choice at any time in Cookie settings.
11. Changes to this policy
We may update this policy from time to time. The version in force is the one published on this page, with the last-updated date shown above.