Collection
Only what is relevant
Contact details you send, limited operational logs, and data needed for client or protected-content workflows.
Privacy,
without the fog.
What we collect, why it is needed, who may receive it, and the choices you keep — written for people, not just compliance files.
Collection
Contact details you send, limited operational logs, and data needed for client or protected-content workflows.
Tracking
Google Analytics and Meta Pixel run only after you accept them in the cookie panel. No hidden profiling.
Control
You can ask what we hold, request a correction or deletion, restrict processing, object, or request portability where applicable.
HexagonX is the public-facing identity of RAW BTL SRL.
Legal entity
RAW BTL SRL, registered in Romania under CUI 36450375 and Trade Register no. J40/11183/2016.
Contact point
47 Mehadia Street, Bucharest, Romania. Privacy requests can be sent to contact@hexagonx.ro.
The purpose comes first. We do not collect personal data simply because we can.
Contract steps / legitimate interest
Name, company, email, and — if you choose to give them — phone number, type of event, event date, indicative budget, and anything else you include in your message, whether you write to us by email or through the contact form. We use them to answer you and to assess or deliver a project. Contact-form requests are stored in our request database together with the page they were sent from and the time of sending, and are read only by the HexagonX team. The form has a hidden anti-spam field; automated submissions that fill it are discarded without being stored.
Legitimate interest
Limited device, browser, request, error, security, and media-delivery data used to keep the service available, diagnose faults, and prevent misuse.
Contract / legitimate interest
Project media and metadata supplied through client work, plus access checks when restricted material is opened. Public portfolio material remains visible as editorial content.
Legal obligation / claims
Records that must be retained for accounting, compliance, dispute resolution, or the establishment and defence of legal claims.
To understand what works on the site and to measure our campaigns, we use two tools. Neither runs before you accept it in the cookie panel.
The legal basis is your consent (Article 6(1)(a) GDPR). You can withdraw it at any time from “Cookie preferences” in the footer of any page; withdrawal does not affect processing carried out before it.
Google and Meta may process data in the United States. Both are certified under the EU-U.S. Data Privacy Framework, and the contracts include the European Commission’s standard clauses.
Provided by Google Ireland Ltd. Collects aggregated data about pages visited, where the visit came from and interactions. The IP address is truncated inside the EU; we do not try to identify you.
Provided by Meta Platforms Ireland Ltd. and Google Ireland Ltd. They measure whether an ad led to a message sent through the contact form and let us show ads to similar audiences. Meta may link the visit to your account if you are signed in.
Retention follows the reason for the data, not an unlimited archive.
Contact-form requests are kept for two years from the day they are sent, then deleted. Where an enquiry becomes a project, the related data is kept for the time needed to develop or deliver the work, maintain the business relationship, and meet related legal or contractual requirements.
Only while useful for security, fault diagnosis, service recovery, and accountability, unless an incident or legal duty requires longer retention.
Data is deleted or anonymised when it is no longer needed, unless a legal obligation or active legal claim requires it to be retained.
Depending on the processing and its legal basis, you may exercise the following rights.
Send your request to contact@hexagonx.ro. We may ask for enough information to verify your identity. We aim to respond without undue delay and, in principle, within one month.
If you believe your rights were not respected, you may also contact the Romanian supervisory authority, ANSPDCP, or seek a judicial remedy.
Operational systems are limited to authorised users and protected through authentication, access controls, logging, and monitoring where appropriate. No internet service can promise zero risk, so data minimisation remains one of our core safeguards.
We may update this notice when the website, providers, or legal requirements change. The date at the top always identifies the version currently in effect.
Please do not send unnecessary sensitive information through ordinary email or project enquiries.
Direct line
Tell us what you need. We will route the request to the right person and respond as clearly as possible.