Skip to content

Privacy Policy

How Wing Leading Edge collects, processes, stores, and safeguards your personal data — in plain language and full compliance with GDPR, the Romanian Data Protection Law (190/2018), and applicable sector-specific regulations.
Effective
1 January 2026
Last Updated
28 May 2026
Version
v3.2
Jurisdiction
Romania / EU
01

Who we are

Wing Leading Edge S.R.L. ("WING", "we", "us", "our") is a Romanian software engineering and digital transformation company headquartered at 17–19 Scărlătescu Street, 1st Floor, Sector 1, Bucharest, Romania. We are registered with the Romanian Trade Registry and act as a data controller for the personal data described in this notice.

For all privacy-related questions you can reach our Data Protection contact at office@wle.ro or by post at the address above.

02

What data we collect

We only collect data that we genuinely need. Depending on how you interact with us, this may include:

  • Identification & contact data — name, business email, phone number, employer, job title — provided through our contact forms, partnership inquiries, or correspondence.
  • Professional information — for prospective hires: CV, education, work history, references, and any information voluntarily shared during the recruitment process.
  • Commercial data — when you represent a client or supplier organization: contract details, billing data, project communications.
  • Technical data — IP address, browser type, device identifiers, operating system, referring URL, pages visited, and approximate location derived from IP — collected automatically through server logs and analytics.
  • Cookie & session data — see our separate Cookie Policy for the full inventory.
  • Communications — content of emails, messages, support tickets, and call records (where lawfully recorded with notice).
03

Why we process your data — lawful basis

We process personal data only when we have a valid lawful basis under Article 6 GDPR. The matrix below shows what we do, why, and on what basis.

Processing activityPurposeLawful basisRetention
Responding to inquiriesReply to your contact form or emailLegitimate interest (Art. 6(1)(f))24 months after last contact
Pre-contractual discussionsQuotes, proposals, RFP responsesSteps prior to contract (Art. 6(1)(b))5 years (commercial archive)
Service deliveryPerforming software, integration & support contractsContractual necessity (Art. 6(1)(b))Contract term + 10 years (fiscal)
RecruitmentEvaluating candidates, hiringConsent + pre-contract (Art. 6(1)(a), (b))12 months unless you opt to stay in our talent pool
Security & loggingDetecting fraud, abuse, breachesLegitimate interest (Art. 6(1)(f))12 months
Legal & fiscal obligationsAccounting, tax, audit, reportingLegal obligation (Art. 6(1)(c))10 years (per Law 82/1991)
Marketing communicationsNewsletters, event invitationsConsent (Art. 6(1)(a))Until you unsubscribe
04

Who we share data with

We never sell personal data. We share it only with carefully selected parties, under written data processing agreements, where strictly necessary:

  • Sub-processors & cloud providers — Microsoft Azure, Oracle Cloud, Google Workspace, Supabase (hosted in EU regions where available).
  • Professional advisors — auditors, lawyers, tax consultants — bound by professional secrecy.
  • Public authorities — only where required by law (e.g., ANAF, ANSPDCP, courts, law enforcement with a valid order).
  • Clients & partners — only when you are acting on their behalf or where required to deliver a joint service, and only the minimum data necessary.
No international transfers without safeguards
When data must leave the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (2021/914) plus supplementary technical and organizational measures, after a documented Transfer Impact Assessment.
05

How we protect your data

Security is engineered into everything we ship — from infrastructure to the application layer. Our controls follow ISO/IEC 27001 principles and include:

  • TLS 1.3 in transit, AES-256 at rest for sensitive stores.
  • Role-based access control, least-privilege provisioning, and quarterly access reviews.
  • Multi-factor authentication for all internal systems and administrative consoles.
  • Continuous vulnerability scanning, dependency monitoring, and annual third-party penetration testing.
  • Segregated production environments, encrypted backups, and tested disaster recovery procedures (RPO ≤ 4h, RTO ≤ 24h).
  • Mandatory security awareness training for every team member, refreshed annually.
  • Documented incident response procedure with a 72-hour breach notification commitment to authorities and affected individuals.
06

Your rights under GDPR

As a data subject you have a comprehensive set of rights. We will respond to any verified request within one calendar month, free of charge except in clearly excessive cases.

Right of access
Obtain a copy of the personal data we hold about you.
Right to rectification
Correct inaccurate or incomplete data.
Right to erasure
Have your data deleted when no longer necessary.
Right to restrict
Pause processing while a dispute is resolved.
Right to portability
Receive your data in a structured, machine-readable format.
Right to object
Object to processing based on legitimate interests or for marketing.
Right to withdraw consent
Withdraw consent at any time, without affecting prior processing.
Right to lodge a complaint
Contact ANSPDCP — the Romanian Data Protection Authority — at anspdcp.ro.
07

Changes to this policy

We may update this notice to reflect changes in our services, technology, or legal requirements. Material changes will be communicated by a banner on our site or, where appropriate, by email at least 14 days before they take effect. The version and effective date at the top of this page will always indicate the most recent revision.

Document v3.2 · Last updated 28 May 2026Report an issue

Questions about this document? Contact us.