Our GDPR philosophy
GDPR is not a checkbox — it is the default operating model for every system we design, every contract we sign, and every line of code we write. Privacy by design and by default (Article 25) is embedded into our SDLC: every new feature passes a privacy review before it ships, every new integration goes through a data flow analysis, and every storage decision is challenged against the data minimisation principle.
Controller details
The seven principles, applied
Article 5 GDPR sets seven principles. Here is how each one shows up in our operations:
- Lawfulness, fairness, transparency — every processing activity is mapped in our internal Record of Processing Activities (Art. 30) and publicly described in this notice and our Privacy Policy.
- Purpose limitation — data collected for one purpose is never repurposed without a fresh lawful basis or compatibility assessment.
- Data minimisation — we collect the smallest dataset that satisfies the purpose, and challenge every new field at design review.
- Accuracy — we offer self-service rectification where possible and respond to corrections within 30 days.
- Storage limitation — every data class has a documented retention period and an automated deletion or anonymisation job.
- Integrity & confidentiality — encryption, access controls, and continuous monitoring (see Security below).
- Accountability — we maintain documented evidence of compliance, including DPIAs for high-risk processing.
Data Protection Impact Assessments
For any processing likely to result in a high risk to data subjects — large-scale processing of special-category data, systematic monitoring, automated decision-making — we conduct a DPIA before going live. The DPIA is reviewed by our legal counsel and, when residual risk remains high, consultation with ANSPDCP is initiated.
Sub-processors register
We maintain an up-to-date register of every sub-processor that may handle client data. The current core register includes:
| Sub-processor | Service | Hosting region | Safeguard |
|---|---|---|---|
| Microsoft Ireland Operations | Azure infrastructure, M365 | EU (Ireland, Netherlands) | DPA + SCCs |
| Oracle Romania | Database & cloud services | EU (Frankfurt) | DPA + SCCs |
| Google Ireland | Workspace, Analytics | EU + US | DPA + SCCs + TIA |
| Supabase EU | Application backend | EU (Frankfurt) | DPA |
| Cloudflare | CDN, WAF, DDoS protection | Global edge | DPA + SCCs |
A complete and current list is available on request at office@wle.ro.
International transfers
We prefer EU-region hosting whenever technically feasible. Where transfers outside the EEA are unavoidable, they are governed by the European Commission's 2021 Standard Contractual Clauses, supplemented by encryption, pseudonymisation, and contractual restrictions on government access requests. Each transfer is documented in a Transfer Impact Assessment.
Breach notification
Exercising your rights
Send a written request to office@wle.ro with enough information to verify your identity. We will acknowledge receipt within 5 working days and complete the response within 30 days (extendable by 60 days for complex cases, with notice). If you are dissatisfied with our response you have the right to complain to ANSPDCP (B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest).

