Who we are
Wing Leading Edge S.R.L. ("WING", "we", "us", "our") is a Romanian software engineering and digital transformation company headquartered at 17–19 Scărlătescu Street, 1st Floor, Sector 1, Bucharest, Romania. We are registered with the Romanian Trade Registry and act as a data controller for the personal data described in this notice.
For all privacy-related questions you can reach our Data Protection contact at office@wle.ro or by post at the address above.
What data we collect
We only collect data that we genuinely need. Depending on how you interact with us, this may include:
- Identification & contact data — name, business email, phone number, employer, job title — provided through our contact forms, partnership inquiries, or correspondence.
- Professional information — for prospective hires: CV, education, work history, references, and any information voluntarily shared during the recruitment process.
- Commercial data — when you represent a client or supplier organization: contract details, billing data, project communications.
- Technical data — IP address, browser type, device identifiers, operating system, referring URL, pages visited, and approximate location derived from IP — collected automatically through server logs and analytics.
- Cookie & session data — see our separate Cookie Policy for the full inventory.
- Communications — content of emails, messages, support tickets, and call records (where lawfully recorded with notice).
Why we process your data — lawful basis
We process personal data only when we have a valid lawful basis under Article 6 GDPR. The matrix below shows what we do, why, and on what basis.
| Processing activity | Purpose | Lawful basis | Retention |
|---|---|---|---|
| Responding to inquiries | Reply to your contact form or email | Legitimate interest (Art. 6(1)(f)) | 24 months after last contact |
| Pre-contractual discussions | Quotes, proposals, RFP responses | Steps prior to contract (Art. 6(1)(b)) | 5 years (commercial archive) |
| Service delivery | Performing software, integration & support contracts | Contractual necessity (Art. 6(1)(b)) | Contract term + 10 years (fiscal) |
| Recruitment | Evaluating candidates, hiring | Consent + pre-contract (Art. 6(1)(a), (b)) | 12 months unless you opt to stay in our talent pool |
| Security & logging | Detecting fraud, abuse, breaches | Legitimate interest (Art. 6(1)(f)) | 12 months |
| Legal & fiscal obligations | Accounting, tax, audit, reporting | Legal obligation (Art. 6(1)(c)) | 10 years (per Law 82/1991) |
| Marketing communications | Newsletters, event invitations | Consent (Art. 6(1)(a)) | Until you unsubscribe |
How we protect your data
Security is engineered into everything we ship — from infrastructure to the application layer. Our controls follow ISO/IEC 27001 principles and include:
- TLS 1.3 in transit, AES-256 at rest for sensitive stores.
- Role-based access control, least-privilege provisioning, and quarterly access reviews.
- Multi-factor authentication for all internal systems and administrative consoles.
- Continuous vulnerability scanning, dependency monitoring, and annual third-party penetration testing.
- Segregated production environments, encrypted backups, and tested disaster recovery procedures (RPO ≤ 4h, RTO ≤ 24h).
- Mandatory security awareness training for every team member, refreshed annually.
- Documented incident response procedure with a 72-hour breach notification commitment to authorities and affected individuals.
Your rights under GDPR
As a data subject you have a comprehensive set of rights. We will respond to any verified request within one calendar month, free of charge except in clearly excessive cases.
Changes to this policy
We may update this notice to reflect changes in our services, technology, or legal requirements. Material changes will be communicated by a banner on our site or, where appropriate, by email at least 14 days before they take effect. The version and effective date at the top of this page will always indicate the most recent revision.

