Legal
Privacy Policy
Here you can find information about the privacy policy applicable to the processing of data through the forms and services available on Evaluator-autorizat.ro.
Processing of Personal Data on evaluator-autorizat.ro
Operator / Website Owner: ACCESS BUSINESS SRL
Last updated: 1 August 2026
Version: 1.0
1. WHO IS THE DATA CONTROLLER?
The controller of personal data is ACCESS BUSINESS SRL, Tax Identification Number 32085323, with its registered office in Constanța Municipality, 301 Tomis Boulevard, Building 4B, ground floor, Apartment 4, Constanța County, Romania. Website: https://evaluator-autorizat.ro.
Data protection contact: parteneri@topestate.ro, +40 723 521 521. If a Data Protection Officer is appointed, their contact details will be published here.
2. WHO DOES THIS POLICY APPLY TO?
This Policy applies to website visitors, persons requesting a quotation or information through the form, by telephone, e-mail or WhatsApp, persons submitting documents, as well as persons subscribing to guides, articles or newsletters.
3. WHAT DATA MAY WE COLLECT?
• identification and contact details: name, telephone number, e-mail address and preferred contact channel;
• request-related data: type of applicant, type of property, purpose of the valuation, location, surface area, preferred deadline and details provided voluntarily;
• documents and images: title deeds, land registry extracts, cadastral documentation, floor plans, photographs and other uploaded files;
• communication data: the content of messages, correspondence history and information required to manage the request;
• subscription data: e-mail address, where applicable the person’s name, selected frequency and evidence of the person’s choice or consent;
• technical and security data: IP address, logs, device or browser type and data generated by cookies, in accordance with the Cookie Policy.
Please do not submit data that is not necessary and avoid including special categories of personal data unless such data is strictly necessary and an appropriate legal basis exists.
4. PURPOSES AND LEGAL BASES FOR PROCESSING
Purpose: Receiving and assessing the request
Examples of data: contact details, property data and files
Legal basis: steps taken at the request of the data subject before entering into a contract; legitimate interest in organising and securing communications
Purpose: Preparing a quotation and entering into or performing the contract
Examples of data: assignment details, documents and communications
Legal basis: pre-contractual steps and performance of the contract
Purpose: Compliance with professional, accounting, tax and legal obligations
Examples of data: assignment file data and supporting documents
Legal basis: legal obligation; where applicable, performance of the contract
Purpose: Sending guides and newsletters
Examples of data: e-mail address, preferences and proof of subscription
Legal basis: consent, which may be withdrawn at any time
Purpose: Website security and prevention of misuse
Examples of data: IP address, technical logs and security events
Legal basis: legitimate interest in security, fraud prevention and the protection of legal rights
Purpose: Handling requests and complaints
Examples of data: contact details and correspondence
Legal basis: legal obligation and/or legitimate interest in the protection of legal rights
5. MANDATORY OR OPTIONAL NATURE OF THE DATA
Fields marked as mandatory are required in order to submit the request. All other information is optional; however, the absence of certain data or documents may prevent us from assessing the complexity of the assignment, preparing a quotation or accepting the assignment.
Acceptance of the Terms and Conditions and confirmation that the Privacy Policy has been read may be required in order to use the form. Consent to receive the newsletter must be separate from the request for a service and must not be made a condition for obtaining that service.
6. WHO MAY ACCESS THE DATA?
To the extent necessary, the data may be accessed by the Controller’s authorised personnel, the valuer responsible for the assignment and other authorised valuers or collaborators involved in assessing, allocating or carrying out the request. They must comply with confidentiality obligations and use the data solely for the relevant professional purpose.
The data may also be disclosed to providers of hosting, maintenance, e-mail, communications, storage, security, accounting or other support services, on the basis of contractual relationships and appropriate safeguards. Data may be disclosed to public authorities or other recipients where required or permitted by law.
7. USE OF DATA WITHIN THE SERVICE ECOSYSTEM
The Controller may use interconnected platforms, applications or services as part of the same professional activity. Data provided through the website may be recognised, accessed or used within these components only where this is necessary to assess the request, communicate with the data subject, avoid repeatedly requesting the same information or continue providing the requested service.
The data will not be used for purposes incompatible with those for which it was collected and will not be displayed to the user or to other persons in a manner that unjustifiably reveals that the user’s identity is known. Access to the data will be restricted to authorised persons and the necessary technical components, subject to appropriate confidentiality and security measures.
8. WHATSAPP, E-MAIL AND OTHER EXTERNAL SERVICES
When you choose to use WhatsApp, e-mail or another service operated by a third party, your data is also processed in accordance with the rules of the relevant provider. Certain services may involve transfers to or access from outside the European Economic Area. The Controller recommends that you do not send more extensive documents through messaging services than is necessary and that you review the policy of the service provider you use.
9. INTERNATIONAL TRANSFERS
The Controller seeks to use providers that offer safeguards compliant with applicable legislation. Where a provider processes data outside the European Economic Area, the transfer will be carried out on the basis of an applicable legal mechanism, such as an adequacy decision, standard contractual clauses or another safeguard recognised by law.
10. HOW LONG DO WE RETAIN THE DATA?
We retain data only for as long as necessary for the purpose for which it was collected and in order to comply with legal, professional, accounting and tax obligations or to protect legal rights.
• unsuccessful requests and related documents: for a limited period established through an internal procedure, after which they will be deleted or anonymised unless there is a lawful reason for further retention; [specific retention period to be determined];
• files relating to accepted assignments: throughout the duration of the relationship and subsequently in accordance with applicable professional and legal obligations;
• newsletter data: until consent is withdrawn or the service is discontinued, while retaining minimum evidence of the unsubscribe request where necessary;
• security logs: for periods proportionate to the security purpose and the investigation of incidents.
11. DATA SECURITY
We apply reasonable technical and organisational measures to protect data against unauthorised access, loss, alteration or disclosure. Nevertheless, no transmission over the internet can be guaranteed to be completely free of risk. Users should submit only the documents that are necessary and should use secure devices and accounts.
12. RIGHTS OF DATA SUBJECTS
Under Regulation (EU) 2016/679, you may request:
• access to your data and information about its processing;
• rectification of inaccurate data or completion of incomplete data;
• deletion of data where the legal requirements are met;
• restriction of processing;
• data portability in respect of eligible processing activities;
• objection to processing based on legitimate interests;
• withdrawal of consent, without affecting the lawfulness of processing carried out before consent was withdrawn;
• the lodging of a complaint with the National Supervisory Authority for Personal Data Processing.
To exercise your rights, please send a request to parteneri@topestate.ro. We may request reasonable information in order to verify your identity. We will respond within the time limits prescribed by law.
13. AUTOMATED DECISION-MAKING
In its current form, the website does not make decisions based solely on automated processing that produce legal effects concerning a person or similarly significantly affect that person. The mini-guides and recommendations displayed are for guidance purposes only, while the acceptance and terms of an assignment are determined through human assessment.
14. DATA RELATING TO OTHER PERSONS
If you provide us with data relating to co-owners, representatives, heirs or other persons, you must have a legitimate basis for doing so and, where necessary, inform those persons of this Policy. Do not request or submit more data than is necessary.
15. MINORS
The website’s services are not directly intended for minors. If we become aware that a minor’s data has been submitted without an appropriate legal basis, we will take reasonable steps to clarify the situation and, where applicable, delete the data.
16. COOKIES
Information concerning cookies, their categories, providers, retention periods and consent options is set out in the Cookie Policy. Non-essential cookies must be activated only on the basis of a valid choice where consent is required by law.
17. UPDATES TO THIS POLICY
We may update this Policy to reflect changes to the website, service providers or applicable legislation. The current version and the date of the latest update will be published on the website. Material changes may be highlighted separately.
18. CONTACT DETAILS AND COMPLAINTS
Controller: ACCESS BUSINESS SRL, Tax Identification Number 32085323, registered office: Constanța Municipality, 301 Tomis Boulevard, Building 4B, ground floor, Apartment 4, Constanța County, Romania. E-mail: parteneri@topestate.ro. Telephone: +40 723 521 521.
You also have the right to contact the Romanian National Supervisory Authority for Personal Data Processing. The Authority’s contact details are available here: https://www.dataprotection.ro/.