Skip to content
Legal01

Privacy Policy

Privacy, without the fog.

What we collect, why it is needed, who may receive it, and the choices you keep — written for people, not just compliance files.

Updated 07 Aug 20266 min read

Collection

Only what is relevant

Contact details you send, limited operational logs, and data needed for client or protected-content workflows.

Tracking

No advertising profiles

The current public website does not run advertising pixels, cross-site marketing trackers, or behavioural profiling.

Control

Your rights stay yours

You can ask what we hold, request a correction or deletion, restrict processing, object, or request portability where applicable.

Who is responsible for this website

HexagonX is the public-facing identity of RAW BTL SRL.

Data controller

Legal entity

RAW BTL SRL, registered in Romania under CUI 36450375 and Trade Register no. J40/11183/2016.

Registered office

Contact point

47 Mehadia Street, Bucharest, Romania. Privacy requests can be sent to contact@hexagonx.ro.

We keep the data surface deliberately small: enough to operate the website, answer enquiries, protect restricted content, and support legitimate client work.

What we use — and why

The purpose comes first. We do not collect personal data simply because we can.

Enquiries

Contract steps / legitimate interest

Name, company, email, phone number, project context, and anything else you choose to include, used to answer you and assess or deliver a project.

Website operation

Legitimate interest

Limited device, browser, request, error, security, and media-delivery data used to keep the service available, diagnose faults, and prevent misuse.

Portfolio & access

Contract / legitimate interest

Project media and metadata supplied through client work, plus access checks when restricted material is opened. Public portfolio material remains visible as editorial content.

Legal records

Legal obligation / claims

Records that must be retained for accounting, compliance, dispute resolution, or the establishment and defence of legal claims.

Who may receive data

We use selected providers for hosting, authentication, media delivery, security, and operational support. They receive only the information needed to provide their service and must handle it under applicable data-protection obligations.

The Contact section includes an interactive OpenStreetMap map. Requests to the map provider are independent from the site's essential cookie notice.

External websites are reached only when you choose to follow a link. Their own privacy terms apply after you leave HexagonX. We do not sell personal data or share it for third-party advertising.

If a provider processes data outside the European Economic Area, we use an available lawful transfer mechanism and appropriate safeguards where required.

How long we keep it

Retention follows the reason for the data, not an unlimited archive.

Enquiries & projects

For the time needed to answer, develop or deliver the work, maintain the business relationship, and meet related legal or contractual requirements.

Technical records

Only while useful for security, fault diagnosis, service recovery, and accountability, unless an incident or legal duty requires longer retention.

End of purpose

Data is deleted or anonymised when it is no longer needed, unless a legal obligation or active legal claim requires it to be retained.

Your GDPR rights

Depending on the processing and its legal basis, you may exercise the following rights.

Send your request to contact@hexagonx.ro. We may ask for enough information to verify your identity. We aim to respond without undue delay and, in principle, within one month.

If you believe your rights were not respected, you may also contact the Romanian supervisory authority, ANSPDCP, or seek a judicial remedy.

  • Be informed and request access to your personal data.
  • Correct inaccurate or incomplete information.
  • Ask for deletion when the legal conditions are met.
  • Restrict processing in specific circumstances.
  • Receive or transfer data where portability applies.
  • Object to processing based on legitimate interest.

Security & changes

Operational systems are limited to authorised users and protected through authentication, access controls, logging, and monitoring where appropriate. No internet service can promise zero risk, so data minimisation remains one of our core safeguards.

We may update this notice when the website, providers, or legal requirements change. The date at the top always identifies the version currently in effect.

Please do not send unnecessary sensitive information through ordinary email or project enquiries.

Direct line

Tell us what you need. We will route the request to the right person and respond as clearly as possible.

Email us