Skip to content

GDPR Compliance Statement

Our full commitment to Regulation (EU) 2016/679 — covering governance, the lawful processing matrix, sub-processors, international transfers, breach response, and your enforceable rights as a data subject.
Regulation
EU 2016/679
Authority
ANSPDCP
Last Audit
Q1 2026
Status
Compliant
01

Our GDPR philosophy

GDPR is not a checkbox — it is the default operating model for every system we design, every contract we sign, and every line of code we write. Privacy by design and by default (Article 25) is embedded into our SDLC: every new feature passes a privacy review before it ships, every new integration goes through a data flow analysis, and every storage decision is challenged against the data minimisation principle.

02

Controller details

Legal entity
Wing Leading Edge S.R.L.
Registered office
17–19 Scărlătescu St., Sector 1, Bucharest, Romania
Privacy contact
office@wle.ro
Coordinates
44°27'14.0"N · 26°05'10.7"E
03

The seven principles, applied

Article 5 GDPR sets seven principles. Here is how each one shows up in our operations:

  • Lawfulness, fairness, transparency — every processing activity is mapped in our internal Record of Processing Activities (Art. 30) and publicly described in this notice and our Privacy Policy.
  • Purpose limitation — data collected for one purpose is never repurposed without a fresh lawful basis or compatibility assessment.
  • Data minimisation — we collect the smallest dataset that satisfies the purpose, and challenge every new field at design review.
  • Accuracy — we offer self-service rectification where possible and respond to corrections within 30 days.
  • Storage limitation — every data class has a documented retention period and an automated deletion or anonymisation job.
  • Integrity & confidentiality — encryption, access controls, and continuous monitoring (see Security below).
  • Accountability — we maintain documented evidence of compliance, including DPIAs for high-risk processing.
04

Data Protection Impact Assessments

For any processing likely to result in a high risk to data subjects — large-scale processing of special-category data, systematic monitoring, automated decision-making — we conduct a DPIA before going live. The DPIA is reviewed by our legal counsel and, when residual risk remains high, consultation with ANSPDCP is initiated.

05

Sub-processors register

We maintain an up-to-date register of every sub-processor that may handle client data. The current core register includes:

Sub-processorServiceHosting regionSafeguard
Microsoft Ireland OperationsAzure infrastructure, M365EU (Ireland, Netherlands)DPA + SCCs
Oracle RomaniaDatabase & cloud servicesEU (Frankfurt)DPA + SCCs
Google IrelandWorkspace, AnalyticsEU + USDPA + SCCs + TIA
Supabase EUApplication backendEU (Frankfurt)DPA
CloudflareCDN, WAF, DDoS protectionGlobal edgeDPA + SCCs

A complete and current list is available on request at office@wle.ro.

06

International transfers

We prefer EU-region hosting whenever technically feasible. Where transfers outside the EEA are unavoidable, they are governed by the European Commission's 2021 Standard Contractual Clauses, supplemented by encryption, pseudonymisation, and contractual restrictions on government access requests. Each transfer is documented in a Transfer Impact Assessment.

07

Breach notification

72-hour commitment
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify ANSPDCP within 72 hours of becoming aware, in accordance with Article 33. Where the risk is high, we notify affected individuals without undue delay. Our internal incident response runbook is rehearsed twice a year.
08

Exercising your rights

Send a written request to office@wle.ro with enough information to verify your identity. We will acknowledge receipt within 5 working days and complete the response within 30 days (extendable by 60 days for complex cases, with notice). If you are dissatisfied with our response you have the right to complain to ANSPDCP (B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest).

Document v3.2 · Last updated 28 May 2026Report an issue

Questions about this document? Contact us.