Compliance

Regulatory Alignment

All legal protocols governing the engagement between Summerdevsstore and its clients, partners, and data subjects.

Privacy Policy

Controller Identity. The data controller responsible for the processing of personal data collected through this platform is Summerdevsstore, registered at 817151, Str. Salcâmilor nr. 16, Sat Cuza Voda, Romania. For all inquiries related to data protection, you may contact our designated Data Protection Officer at [email protected].

Legal Basis for Processing. We process personal data exclusively on the following legal bases as defined by Article 6 of the General Data Protection Regulation (EU) 2016/679: (a) the data subject has given consent to the processing of their personal data for one or more specific purposes; (b) processing is necessary for the performance of a contract to which the data subject is party; (c) processing is necessary for the purposes of the legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights of the data subject.

Categories of Data Collected. The following categories of personal data may be collected through this platform: identification data (name, email address, telephone number), communication data (messages, inquiries, project descriptions), technical data (IP address, browser type, device identifiers, usage analytics), and financial data (transaction records processed exclusively through our Stripe payment processor — we do not store payment card data).

Purpose of Processing. Personal data is processed for the following purposes: responding to inquiries and establishing commercial relationships, executing contracted services and delivering project milestones, sending transactional communications (project updates, invoices, delivery notifications), complying with legal and regulatory obligations, and improving platform performance through anonymized analytics.

Data Retention. Personal data is retained for the minimum duration necessary to fulfill the purposes for which it was collected. Contact form submissions are retained for 24 months from the date of submission. Contract-related data is retained for the duration of the contractual relationship plus 6 years in compliance with Romanian commercial record-keeping obligations. Technical analytics data is retained for 13 months in anonymized form.

Data Subject Rights. Under the GDPR, you have the following rights: (a) Right of Access (Article 15) — obtain confirmation of whether your personal data is being processed and receive a copy of that data; (b) Right to Rectification (Article 16) — request correction of inaccurate personal data; (c) Right to Erasure (Article 17) — request deletion of your personal data where no overriding legal obligation requires its retention; (d) Right to Restrict Processing (Article 18) — request limitation of processing under specific circumstances; (e) Right to Data Portability (Article 20) — receive your personal data in a structured, machine-readable format; (f) Right to Object (Article 21) — object to processing based on legitimate interests or direct marketing; (g) Right to Withdraw Consent (Article 7) — withdraw consent at any time without affecting the lawfulness of prior processing.

Data Transfers. Personal data may be transferred to recipients located outside the European Economic Area (EEA). In such cases, we ensure adequate safeguards are in place through Standard Contractual Clauses (SCCs) approved by the European Commission or through adequacy decisions as defined under Article 46 of the GDPR.

Data Breach Notification. In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR. Where the breach is likely to result in a high risk, affected data subjects will be notified without undue delay.

Supervisory Authority. You have the right to lodge a complaint with the supervisory authority responsible for data protection in Romania: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, București, Romania.

Cookie Governance

Cookie Definition. Cookies are small text files placed on your device when you visit our platform. They enable us to recognize your device, store preferences, and analyze platform usage patterns.

Strictly Necessary Cookies. These cookies are essential for the platform to function correctly. They enable core features such as session management, security token validation, and user interface state persistence. These cookies do not require consent under the ePrivacy Directive (2002/58/EC) as they are strictly necessary for the provision of the service explicitly requested by the user.

Analytics Cookies. We use anonymized analytics cookies to understand how visitors interact with our platform. These cookies collect aggregated, non-identifying information about page views, session duration, navigation paths, and device characteristics. All analytics data is processed in aggregate and cannot be used to identify individual users. Analytics cookies are only activated upon your explicit consent.

Functional Cookies. Functional cookies enable enhanced functionality and personalization, such as remembering your preferred language, display preferences, and consent choices. These cookies are only set in response to actions you take, and are retained for the duration of your session or up to 12 months.

Third-Party Cookies. Our platform may incorporate third-party services that set their own cookies: Google Maps (for embedded map functionality), Stripe (for payment processing), and our analytics provider (for anonymized usage data). Each third-party service operates under its own privacy policy, which we encourage you to review.

Consent Management. Upon your first visit, you will be presented with a cookie consent banner allowing you to accept or decline non-essential cookies. Your choice is stored in your browser's localStorage and respected for 12 months. You may modify your consent preferences at any time by accessing the cookie settings through the link in our platform footer.

Cookie Deletion. You may delete cookies at any time through your browser settings. Most browsers provide options to block all cookies, accept all cookies, or receive a notification when a cookie is set. Please note that blocking strictly necessary cookies may impair the functionality of this platform.

Refund Framework

Scope of Application. This refund framework applies to all services provided by Summerdevsstore to its clients. It governs the conditions under which payments may be partially or fully refunded in accordance with applicable Romanian consumer protection legislation and EU Directive 2011/83/EU on consumer rights.

Service Commencement and Cancellation. Upon acceptance of a service proposal and receipt of the initial payment, Summerdevsstore will commence project work within the timeline specified in the service agreement. Clients may request cancellation within 14 calendar days of payment without penalty, provided that no substantive project work has been initiated. If work has commenced, the client is liable for the proportional cost of work completed up to the date of cancellation notice.

Milestone-Based Deliverables. For projects structured around defined milestones, payment is tied to the successful completion and delivery of each milestone. Once a milestone has been delivered and accepted by the client (either explicitly or through a 7-day silent acceptance period), that milestone becomes non-refundable. Disputes regarding milestone completion will be resolved through a structured review process as specified in the service agreement.

Non-Satisfactory Delivery. If a delivered milestone does not conform to the specifications defined in the service agreement, the client must notify Summerdevsstore within 14 calendar days of delivery with a detailed written description of the non-conformance. Summerdevsstore will have 30 calendar days to remediate the identified issues. If remediation is unsuccessful, the client is entitled to a proportional refund for the non-conforming portion of the work.

Refund Processing. Approved refunds will be processed within 30 calendar days of refund approval. Refunds are issued exclusively to the original payment method. Summerdevsstore reserves the right to deduct administrative costs (not exceeding 5% of the refund amount) from the refund total. Currency exchange rate fluctuations between the date of payment and the date of refund are borne by the client.

Exclusions. The following are explicitly excluded from refund eligibility: custom design work that has been approved through the client feedback cycle; third-party software licenses, API access fees, or hosting costs incurred on behalf of the client; domain name registrations and SSL certificate purchases; work performed under separately executed Statements of Work (SOWs) that contain their own refund terms.

Dispute Resolution. Refund disputes that cannot be resolved through direct negotiation will be submitted to mediation under the rules of the Bucharest Chamber of Commerce and Industry. If mediation fails, disputes shall be submitted to the competent courts of Bucharest, Romania, in accordance with applicable EU cross-border dispute resolution mechanisms.

Terms of Engagement

Acceptance of Terms. By accessing, browsing, or using the services provided by Summerdevsstore (the "Company"), you (the "Client") agree to be bound by these Terms of Engagement in their entirety. If you do not agree to any provision herein, you must discontinue use of all services immediately.

Scope of Services. The Company provides digital engineering services including but not limited to web development, interface design, API architecture, infrastructure deployment, and technical consulting. The specific scope, deliverables, timelines, and pricing for each engagement are defined in a written Service Agreement or Statement of Work (SOW) executed by both parties prior to work commencement.

Intellectual Property. Upon full payment of all applicable fees, the Client receives full ownership of all custom-designed and custom-developed deliverables specifically created for the engagement. The Company retains ownership of its proprietary frameworks, methodologies, reusable component libraries, and general-purpose tooling used in the delivery process. Pre-existing intellectual property incorporated into deliverables remains the property of its original owner, with the Client receiving a perpetual, non-exclusive license to use such components within the context of the delivered project.

Confidentiality. Both parties agree to maintain the confidentiality of all proprietary information exchanged during the course of the engagement. This obligation survives the termination of the service agreement for a period of 36 months. Confidential information includes but is not limited to business strategies, financial data, technical specifications, user data, and unpublished product roadmaps.

Limitation of Liability. The Company's total aggregate liability under any service agreement shall not exceed the total fees paid by the Client for the specific service giving rise to the claim. The Company shall not be liable for any indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill, regardless of the form of action or theory of liability.

Indemnification. The Client agrees to indemnify, defend, and hold harmless the Company, its officers, directors, employees, and contractors from and against any and all claims, liabilities, damages, losses, and expenses (including reasonable legal fees) arising out of or in connection with the Client's use of the delivered services, violation of these terms, or infringement of third-party rights.

Force Majeure. Neither party shall be liable for any delay or failure to perform its obligations under a service agreement if such delay or failure results from circumstances beyond the reasonable control of the affected party, including but not limited to natural disasters, pandemics, war, terrorism, government actions, power failures, or internet infrastructure failures. The affected party must provide written notice within 48 hours of the force majeure event and use commercially reasonable efforts to mitigate its impact.

Governing Law. These Terms of Engagement and all service agreements are governed by the laws of Romania and, where applicable, the regulations of the European Union. Any dispute arising from or in connection with these terms shall be subject to the exclusive jurisdiction of the courts of Bucharest, Romania.

Modifications. Summerdevsstore reserves the right to modify these Terms of Engagement at any time. Material changes will be communicated to active clients via email at least 30 calendar days before taking effect. Continued use of services after the effective date of modified terms constitutes acceptance of the modified terms.

Severability. If any provision of these terms is found to be invalid, illegal, or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the original intent of the parties.

Entire Agreement. These Terms of Engagement, together with any executed Service Agreements and Statements of Work, constitute the entire agreement between the Client and Summerdevsstore regarding the subject matter herein and supersede all prior and contemporaneous agreements, representations, and understandings.