Privacy policy (GDPR)
Last updated: 27 June 2026
SOUND & LIGHT SOLUTIONS SRL (trading as GxA Solutions) processes your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable national law. This policy explains what data we collect, for what purpose, and what rights you have.
Data controller
- SOUND & LIGHT SOLUTIONS SRL
- CUI 34409850
1. Data we collect
We collect only the data you provide directly through the contact form:
- first and last name;
- email address;
- phone number (optional);
- the content of your message.
Technically, when the form is submitted we also store the IP address and browser type (user-agent), strictly to prevent spam and abuse. We do not collect sensitive data and we never request more information than necessary.
2. Purpose and legal basis
We process the data to respond to your requests, send offers and provide the services you ask for. The legal basis is your consent and/or our legitimate interest in communicating and undertaking pre-contractual steps, under Article 6 of the GDPR.
3. Retention period
We keep contact-message data only for as long as needed to handle the request and, afterwards, for the period required by legal obligations or by managing the business relationship. Once this period expires, the data is deleted or anonymized.
4. Recipients of the data
Data is not sold and is not transferred to third parties for marketing purposes. It may be accessed by our hosting provider (Hosterion) strictly for the technical operation of the site and email service, acting as a processor. We do not transfer data outside the European Economic Area.
5. Your rights
As a data subject, you have the following rights:
- the right of access to the processed data;
- the right to rectify inaccurate data;
- the right to erasure (the “right to be forgotten”);
- the right to restrict processing;
- the right to data portability;
- the right to object and to withdraw consent at any time.
To exercise these rights, you can contact us at the email address below. You also have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP, dataprotection.ro).
6. Data security
We implement appropriate technical and organizational measures (encrypted HTTPS connection, protected storage, restricted database access) to ensure a level of security appropriate to the risk and to protect data against unauthorized access, loss or disclosure.