Direct Softworks
ServicesWorkBlogProcessFAQ
Book a call
Logo
  • Services
  • Work
  • Blog
  • Process
  • FAQ
  • Book a call
Privacy notice for Direct Softworks websiteEffective July 19, 2026

Privacy Policy

What data we collect, why we use it, and how to ask us to delete it.

On this page

  1. 01Who is responsible for your data?
  2. 02What data we collect
  3. 03Enquiries you start but don't send
  4. 04Why we collect this data
  5. 05Our legal basis for each use
  6. 06How long we keep your data
  7. 07Data sharing and third parties
  8. 08Transfers outside the EU
  9. 09Your rights under GDPR
  10. 10Cookies and tracking
  11. 11Contact for privacy questions

01Who is responsible for your data?

The data controller is Direct Softworks SRL (Romania). For any question, email [email protected].

02What data we collect

When you contact us, you give us:

  • Name, so we know who we are talking to.
  • Email address, so we can reply.
  • Phone number (if you share it), so we can call you back.
  • Your message and selected services, so we can prepare a useful reply.
  • If you start our contact form and leave without sending it, whatever you had already typed - see "Enquiries you start but don't send" below, which explains exactly what that means and how to have it deleted.

If you allow the optional cookie categories, we also collect data while you browse: anonymised page views (our own analytics), and - if you accept marketing cookies - your IP address, browser and device details, and the pages you visit, which the Apollo.io tracker uses to identify the company you are visiting from. Both are off unless you switch them on.

03Enquiries you start but don't send

Our contact form asks for your email address on its first screen, then asks five more questions. If you give us the address and then leave without sending the form, we keep what you had typed - the address, and whichever of the later answers you had already given - so that we can follow up on the enquiry you started. This happens whether or not you accepted any cookies, because it is not a cookie: nothing is placed on your device, and the record is kept on our own server against the address you typed. Here is exactly what that does and does not mean:

  • It is only kept once you have moved past the email screen with a valid address. We do not record what you type while you type it, so an address you began and then corrected never reaches us at all.
  • We use it to reply to you about that enquiry. We do not add you to a newsletter, a mailing list or an outreach sequence - that would be marketing you never asked for, and we do not do it.
  • We do not share it with anyone. It is not sent to Apollo.io or to any other third party, and it never leaves the EU.
  • No IP address is stored with it. The country we see comes from Cloudflare, derived from your IP address without us reading or keeping it.
  • It is deleted automatically after 180 days, and straight away if you ask us to.

Our legal basis is legitimate interest (GDPR Art. 6(1)(f)): you had begun sending us a business enquiry, and replying to it is the thing you were in the middle of asking for. Because it is a legitimate interest and not consent, you can object at any time under Art. 21(1) - email [email protected] and we will delete the record, and you do not have to give a reason. If you would rather we never had it in the first place, don't enter your email address until you're ready to send the form.

04Why we collect this data

We use your data to reply, schedule a call, and prepare a proposal if we work together.

We never sell or rent your personal data. We do use one third-party marketing tool, Apollo.io, and only with your consent: it tells us which companies visit our site so we can decide who to reach out to. Everything else stays with us and our hosting and email providers.

05Our legal basis for each use

Under the GDPR we rely on:

  • Consent (Art. 6(1)(a)) for all optional cookies and tracking, including our analytics beacon and the Apollo.io visitor tracker. Nothing in these categories runs before you agree, and you can withdraw at any time.
  • Steps taken at your request before a contract (Art. 6(1)(b)) when we handle your enquiry, quote, or project.
  • Legitimate interest (Art. 6(1)(f)) in keeping the site secure and preventing abuse of our forms.
  • Legitimate interest (Art. 6(1)(f)) in replying to an enquiry you began sending us through our contact form and did not finish. You can object to this at any time and we will delete the record - see "Enquiries you start but don't send" above.
  • Legal obligation (Art. 6(1)(c)) where accounting or tax law requires us to keep records.

06How long we keep your data

We keep emails and contact messages for up to 12 months so we can follow up and keep context. After that, messages may be archived or deleted during normal inbox clean up. Detailed analytics rows - individual visits, page views and clicks - are deleted after 400 days. What survives that is a daily table of counts only (how many visits, from which country, to which page), which contains nothing about any individual and is kept indefinitely so year-on-year comparisons remain possible. An unfinished contact-form enquiry - the email address and answers described under "Enquiries you start but don't send" - is deleted after 180 days, or immediately on request. The random key used to hash anonymous visitor identifiers is deleted after two days. Your cookie choice is stored for 365 days, after which we ask again. Data held inside Apollo.io is kept according to Apollo's own retention policy for as long as our account is active, and we delete records there on request.

07Data sharing and third parties

We do not sell your personal data. We share it only in these cases:

  • When we are required to do so by law or by a competent authority.
  • With the providers who run our business systems - our hosting provider and the email service that delivers your message to our inbox. They act as our processors, on our instructions.
  • With Apollo.io (Apollo.io, Inc., United States), but only if you accept marketing cookies. Its tracker receives your IP address, user-agent and device details, referring page, and the pages you view on this site, and matches them against Apollo's business database. Details in Apollo's privacy policy at apollo.io/privacy-policy.

08Transfers outside the EU

If you accept marketing cookies, the Apollo.io tracker transfers the data described above to the United States, where Apollo.io, Inc. processes it. That transfer is governed by Apollo's Data Processing Addendum, which forms part of the Apollo terms of service we are bound by as a subscriber, and which incorporates the European Commission's Standard Contractual Clauses. Apollo also states that it complies with the EU-U.S. Data Privacy Framework. If you would rather no data about you left the EU, choose "Essential only" or switch marketing cookies off - every part of this site works exactly the same either way.

09Your rights under GDPR

As an EU resident, you have the right to:

  • Access, ask what personal data we hold about you.
  • Correction, ask us to correct inaccurate data.
  • Deletion, ask us to delete your personal data (when possible).
  • Portability, ask for a copy of your data in a common format.
  • Objection, object to certain types of processing (if it applies).
  • Withdrawal of consent, at any time, for anything we do on the basis of consent - including the Apollo.io tracker. Withdrawing does not affect what was lawful before you withdrew.
  • Complaint, lodge one with the Romanian supervisory authority (ANSPDCP, dataprotection.ro) if you think we have got this wrong.

To use these rights, email [email protected]. To withdraw cookie consent, use "Cookie settings" at the bottom of any page.

10Cookies and tracking

This website uses cookies and similar technologies in three categories. Essential (always active) stores your language preference, your consent choice, and the security tokens behind our forms - no personal profiling. Marketing (optional, off by default) loads the Apollo.io website tracker, which receives your IP address, browser and device details, referring page, and the pages you view, processes them in the United States, and matches them to its business database so we can see which companies visit us. It does not load before you agree to it.

Our own analytics works differently and we want to be exact about it, because it runs whether or not you accept anything. It measures how the site is used - which pages you visit and in what order, the site that referred you, your country, device type, browser and screen size, how far down a page you scroll, how long you actively spend on it, what you click, and where you stop in the contact form. It stores nothing on your device unless you opt in. Your visitor identifier is a one-way hash of your IP address and browser details under a random key that we regenerate daily and delete after two days, after which nobody - including us - can work out which identifier was yours. Your IP address is never written to the analytics database. If you type your email address into the contact form, it is not attached to any of this - your browsing stays anonymous either way. It is kept separately, and only so that we can reply to the enquiry you started: see "Enquiries you start but don't send" above.

Turning on "Recognise me across visits" changes three things and only three: a random identifier is stored in your browser so repeat visits can be recognised as the same person, your approximate region, city and time zone are recorded alongside the country, and an enquiry you send is linked to the pages that led to it. You can turn it back off at any time, which deletes that identifier from your browser.

Your choice is stored in the cookiePrefs cookie for 365 days. Change or withdraw it at any time through "Cookie settings" in the footer - if you switch marketing off, we stop loading the Apollo tracker and clear the identifiers it stored in your browser. We also honour the Global Privacy Control and Do Not Track signals: if your browser sends either, we keep your visit anonymous even if consent was given previously. Refusing optional cookies does not limit any part of this site.

11Contact for privacy questions

For any question about this privacy policy or your personal data, contact Direct Softworks SRL at [email protected].

DIRECT

Internal systems for operations teams. Less spreadsheet chaos.

[email protected]
Services
Business softwareDesktop applicationsWorkflow automationWebsites & landing pagesAll services
Company
WorkLive demosDevelopersBlogAboutGet an estimateContact
Follow us
GitHubX (Twitter)Instagram
© 2026 Direct Softworks SRL
RomânăPrivacy PolicyTerms
Made in Romania