Privacy Policy
Autovehicule DAC S.A. respects the confidentiality of your personal data and is committed to protecting it in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).
Last updated: April 27, 2026
Data controller
The personal data controller is Autovehicule DAC S.A., a Romanian legal entity with its registered office in Brașov, Str. Poienelor no. 5, registered with the Trade Register, acting as data controller within the meaning of EU Regulation 2016/679 (GDPR).
Autovehicule DAC S.A.
Str. Poienelor no. 5, Brașov, Romania
Email: contact@dac.eu
Phone: +40 730 072 620
What data we collect
We collect only the data necessary to provide the requested services and to fulfill our legal obligations:
- Identification and contact data: first name, last name, company name, email address, phone number — collected through contact forms, configurator, comparator, or newsletter subscription.
- Site interaction data: pages visited, vehicle configurations generated, saved comparisons, messages sent via chat — to understand commercial interest and personalize recommendations.
- Technical data: IP address, browser type, operating system, visit time — automatically collected in server logs for security and diagnostics.
- Cookies: small files stored in your browser to retain preferences (language, theme, cookie consent) and for traffic analysis.
We do not collect: special categories of data (health data, ethnic origin, political opinions, biometric data, etc.).
How we use your data
- To respond to inquiries submitted through the contact form or by phone.
- To recommend vehicle models suited to your needs (configurator, comparator, TCO calculator).
- To send you commercial offers and information about DAC products (only if you subscribed to the newsletter or agreed to be contacted).
- To improve our website and services through traffic analysis.
- To fulfill legal obligations (fiscal, accounting, commercial).
- For site security and abuse prevention (bot detection, rate limiting).
Legal basis for processing
- Consent (art. 6 (1) (a) GDPR) — for newsletter subscription, non-essential cookies, direct marketing.
- Contract performance (art. 6 (1) (b) GDPR) — for processing quote requests and pre-contractual commercial relationships.
- Legal obligation (art. 6 (1) (c) GDPR) — for fiscal, accounting, and commercial obligations.
- Legitimate interest (art. 6 (1) (f) GDPR) — for site security, fraud prevention, and service improvement.
How long we retain data
- Contact form and lead data: maximum 36 months from the last interaction.
- Newsletter subscription data: until unsubscribed or 24 months of inactivity.
- Chat conversations: 12 months from the last interaction.
- Server logs: maximum 30 days.
- Data required for legal obligations (fiscal, accounting): in accordance with applicable legislation (typically 10 years).
Who we share data with
We do not sell or rent your personal data. We may share it only with:
- IT service providers helping us operate the site (Vercel — hosting; Supabase — database; Resend — transactional email). All are data processors and process data exclusively under our instructions, with servers located in the European Union.
- Public authorities — only based on a legal obligation or legitimate request.
- Authorized DAC service partners — exclusively to connect you with the nearest service point, only upon explicit request.
We do not transfer data outside the European Economic Area (EEA).
Your rights
Under GDPR, you have the following rights:
- Right of access — to know what data we hold about you.
- Right to rectification — to correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — to request deletion of data under conditions established by law.
- Right to restrict processing — to request limits on how data is used.
- Right to data portability — to receive data in a structured, commonly used format.
- Right to object — to object to processing based on legitimate interest or direct marketing.
- Right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP — anspdcp.ro).
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, you can contact us at contact@dac.eu. We will respond within a maximum of 30 days from receiving the request.
Data security
We implement appropriate technical and organizational measures to protect data against unauthorized access, modification, disclosure, or destruction:
- Encrypted communications (HTTPS/TLS) on all pages.
- Passwords stored as hashes using standard algorithms (bcrypt).
- Restricted database access via mandatory authentication.
- Daily database backups.
- User input sanitization and injection protection.
- Rate limiting to prevent abuse.
Cookies
The site uses the following types of cookies:
- Essential cookies: necessary for basic operation (language preference, authentication session). Cannot be disabled.
- Analytics cookies: help us understand how the site is used (pages visited, visit duration). Enabled only with explicit consent.
- Preference cookies: save your settings (dark/light theme, cookie consent).
You can manage cookies directly through your browser or via the banner displayed on first visit.
Data of minors
Our services are intended exclusively for professionals and persons aged at least 18. We do not knowingly collect data about minors. If we identify such data, we delete it immediately.
Changes to this policy
We may update this policy periodically to reflect legislative changes or changes to our services. The current version is always available on this page, with the date of last update shown at the top.
Data protection contact
For any questions regarding this policy or the processing of your personal data, you can contact us:
Autovehicule DAC S.A.
Str. Poienelor no. 5, Brașov, Romania
Email: contact@dac.eu
Phone: +40 730 072 620
Have questions?
Our team responds promptly to any GDPR inquiry.