This policy explains how NEXA TLC COMMUNICATION S.R.L. (“NEXA”, “we”) processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and the applicable national laws, when you visit our website, contact us, or use our services as a customer or as an End User of our customers.
1. Controller
NEXA TLC COMMUNICATION S.R.L., Str. Dascălilor nr. 2, Sat Dancu, Comuna Holboca, 707252, Județul Iași, Romania, Trade Register no. J2026004202002, CUI 53389740. Contact for data protection matters: [email protected]. [Contact details of the Data Protection Officer, if appointed]
2. Controller or processor?
We act as controller for the data we need to run our business and to provide electronic communications services (for example contact data, billing data and traffic data).
We act as processor on behalf of our customers when we process data according to their instructions, for example call recordings, content of SMS campaigns, contact lists and conversations handled by AI voice agents. In these cases the customer is the controller and is responsible for informing the people concerned; our processing is governed by a data processing agreement.
3. What data we process, why, and on what legal basis
| Activity | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| Visiting the website | IP address, browser, pages visited, date and time (server logs) | Delivering the website, security, preventing abuse | Legitimate interest (Art. 6(1)(f)) |
| Pricing requests and contacts | Name, company, email, phone, services of interest, volumes, notes, preferred language | Replying to your request and preparing an offer | Steps taken at your request before entering into a contract (Art. 6(1)(b)); for company representatives, legitimate interest (Art. 6(1)(f)) |
| Customer management | Details of the customer’s representatives and contacts, identity and company documents, account data | Concluding and performing the contract, customer support, identity checks required for numbers | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Payments and invoicing | Billing data, top-ups, invoices, payment data | Invoicing, accounting, tax obligations | Contract; legal obligation |
| Providing the services | Traffic data: calling and called numbers, date, time, duration, IP addresses, message metadata | Routing communications, billing, customer usage records | Contract; legal obligation under electronic communications law |
| Emergency calls | Calling number, registered address | Forwarding location information to emergency services | Legal obligation |
| Fraud prevention and network security | Traffic data, access logs | Detecting and blocking fraud, abnormal traffic and attacks | Legitimate interest; legal obligation |
| Requests from authorities | Data required by law | Complying with lawful requests of judicial and public authorities | Legal obligation |
We do not use your data for marketing without your consent, and we do not sell personal data. The content of calls is not recorded unless the customer activates call recording.
4. Automated decisions
Our anti-fraud systems may automatically block traffic that shows patterns typical of fraud. You can ask for the decision to be reviewed by a person by writing to us. We do not make other automated decisions that produce legal effects for you.
5. Recipients
Data is processed by our authorised staff and may be shared with:
- other electronic communications operators and carrier partners, to the extent necessary to route calls and messages and to provide numbers;
- providers of hosting, IT, email and support services [names and countries];
- providers of speech recognition and AI technology used for AI voice agents [names and countries];
- payment service providers, banks and accountants;
- emergency services, and judicial and public authorities, where required by law.
Our service providers act as processors under written agreements. A list of the sub-processors used for customer data is available on request [or: published at …].
6. Transfers outside the European Economic Area
International communications necessarily involve operators located in the destination countries: transfers needed to route a call or message requested by the user take place on the basis of the necessity to perform the contract. Other transfers to countries outside the EEA take place only on the basis of an adequacy decision of the European Commission or of the standard contractual clauses approved by it, with additional safeguards where needed. [List of transfers, if any]
7. How long we keep data
| Data | Retention period |
|---|---|
| Website server logs | [30 days] |
| Pricing requests not followed by a contract | [24 months] from the last contact |
| Contract and customer data | For the duration of the contract and afterwards for the limitation period applicable to legal claims |
| Invoices and accounting records | For the period required by accounting and tax law (currently up to 10 years in Romania) |
| Traffic data for billing | Until the end of the period in which the charges can be challenged or payment can be pursued [e.g. 3 years] |
| Traffic data kept to comply with legal retention obligations | For the period required by the applicable law |
| Call recordings and AI conversations (as processor) | According to the customer’s instructions; deleted at the end of the contract unless otherwise agreed |
8. Your rights
You have the right to access your data, to have it rectified or erased, to restrict its processing, to data portability, and to object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time. To exercise your rights, write to [email protected]. We reply within one month, which may be extended in the cases provided by law.
If your data is processed on behalf of one of our customers (for example in a call recording), please contact that customer; we will assist them in replying.
You also have the right to lodge a complaint with a supervisory authority, in particular the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) – www.dataprotection.ro, or the authority of the EU country where you live or work (for example the Italian Garante per la protezione dei dati personali – www.garanteprivacy.it).
9. Security
We protect personal data with appropriate technical and organisational measures, including access control, encryption where appropriate, traffic monitoring and staff confidentiality obligations. In case of a personal data breach, we notify the competent authorities and the people concerned where required by law.
10. Cookies
Cookies are small text files that a website stores on your device. This website uses only one technical cookie, strictly necessary to provide the service you request:
| Name | Purpose | Duration | Provider |
|---|---|---|---|
nexa_sid | Protects the pricing request form against fraudulent submissions (security token). Set only when you open the pricing page. | Until you close the browser | NEXA TLC COMMUNICATION S.R.L. (first-party) |
We do not use analytics, profiling or advertising cookies, and we do not load content from third parties that set cookies: fonts and all other resources are served from our own servers. Strictly necessary cookies do not require consent under the ePrivacy Directive (Directive 2002/58/EC, art. 5(3)) and the national laws implementing it, so the website does not show a cookie banner. If we introduce other cookies in the future, we will ask for your consent in advance and update this section.
You can delete or block cookies in your browser settings. If you block nexa_sid, the pricing request form may not work; you can still contact us at [email protected].
11. Changes
We may update this policy. The date of the latest update is shown at the top of the page; significant changes are also communicated to customers.
This document is available in English, Italian and Romanian. In case of discrepancies, the English version prevails.