LEGAL
Privacy policy (GDPR)
PRIVACY POLICY (GDPR)
1. Data controllers
The DriftHub site is operated by two entities, each a data controller for its own activities:
— ASOCIAȚIA CLUBUL SPORTIV STRIKE BACK, tax ID 45607593 (community, donations, Form 230, sponsorship);
— S.C. ZDR DIGITAL MARKET CONCEPT S.R.L., company ID RO44172784, Str. Cuțitul de Argint nr. 68, Sector 4, Bucharest (commercial services: experiences, memberships, shop).
Contact for personal data: Contact@SorinFranculescu.ro, tel. 0784677771.
2. Data we collect
— Account data (name, email, encrypted password) — at registration;
— Booking and order data (what you booked/purchased, payment status);
— Form data (contact, sponsorship, Form 230, corporate, marketplace listings);
— Technical data (IP address, access logs, cookies required for operation).
Card data is NOT stored by us — payments are processed entirely by Stripe.
3. Purposes and legal bases
— Providing the requested services (contract performance);
— Issuing contracts, proformas and Form 230 sheets (legal obligations);
— Account and subscription administration (contract performance);
— Communications about our activity (legitimate interest / consent, as applicable);
— Platform security and abuse prevention (legitimate interest).
4. Recipients
Data is accessed only by: Stripe (payment processing), the hosting provider (EU-based VPS) and, for Form 230, the tax authority upon filing. We never sell or rent personal data.
5. Retention
We keep data while your account is active or as required by law (tax documents: 10 years). On request, the account and associated data are deleted, except data under legal retention.
6. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection, as well as the right to lodge a complaint with ANSPDCP (www.dataprotection.ro). To exercise your rights, write to Contact@SorinFranculescu.ro.
7. Cookies
We use strictly necessary cookies (authentication, preferences, security). The consent banner gives you control over optional ones.
8. Security
We apply appropriate technical measures: HTTPS, encrypted passwords (bcrypt), restricted access, logging and temporary lockout after repeated failed logins.
Last updated: August 2026.