superlabdev

Compliance Matrix

Legal
Framework

Last updated: July 2026

01

Privacy Policy

1.1 Data Controller Identity

The data controller responsible for the processing of personal data through this website is superlabdev, registered at 900402 | Str. Soveja nr. 62A, bl. TCIF | Mun. Constanta, Jud. Constanta | Romania, Romania. For any data protection inquiries, you may contact our designated data protection officer at [email protected].

1.2 Scope of Data Collection

We collect and process personal data strictly within the boundaries of Article 6(1) of the EU General Data Protection Regulation (GDPR). The following categories of personal data may be processed:

  • Contact Data: Full name, email address, phone number, and physical address submitted through our contact form or during project engagement.
  • Technical Data: IP address, browser type and version, operating system, referring URLs, and access timestamps — collected automatically through server logs for security and performance monitoring.
  • Project Data: Business requirements, technical specifications, and related documentation shared during the execution of contracted services.
  • Payment Data: Transaction identifiers processed through our third-party payment processor (Stripe). We do not store credit card numbers, CVV codes, or banking credentials on our servers.

1.3 Legal Basis for Processing

Your personal data is processed under the following legal bases as defined in Article 6(1) GDPR:

  • Consent (Art. 6(1)(a)): Where you have explicitly opted in to receive marketing communications or newsletter content.
  • Contract Performance (Art. 6(1)(b)): Where data processing is necessary for the performance of a contract to which you are a party, or for pre-contractual measures taken at your request.
  • Legitimate Interest (Art. 6(1)(f)): Where processing is necessary for our legitimate interests — specifically, the maintenance of website security, fraud prevention, and service improvement — provided such interests are not overridden by your fundamental rights.
  • Legal Obligation (Art. 6(1)(c)): Where processing is required to comply with applicable Romanian and EU legal obligations, including tax record retention and regulatory reporting.

1.4 Data Retention Periods

Personal data is retained only for the duration necessary to fulfill the purposes for which it was collected:

  • Contact form submissions: Retained for a maximum of 24 months from the date of submission, or until the conclusion of any resulting business relationship, whichever is later.
  • Project-related data: Retained for the duration of the active engagement plus 5 years, in compliance with Romanian commercial record-keeping requirements (Art. 25 of the Romanian Accounting Law).
  • Server logs: Automatically purged after 90 days.
  • Payment transaction records: Retained for 10 years as required by Romanian fiscal legislation (Art. 21 of the Romanian Tax Procedure Code).

1.5 Your Data Subject Rights

Under the GDPR, you possess the following rights regarding your personal data:

  • Right of Access (Art. 15): You may request a copy of all personal data we hold about you, provided in a structured, commonly used, machine-readable format.
  • Right to Rectification (Art. 16): You may request the correction of inaccurate personal data or the completion of incomplete data.
  • Right to Erasure (Art. 17): You may request the deletion of your personal data where there is no compelling legal ground for continued processing.
  • Right to Restriction (Art. 18): You may request the restriction of processing where you contest the accuracy of the data or object to our processing.
  • Right to Data Portability (Art. 20): You may request to receive your personal data in a structured, machine-readable format for transmission to another controller.
  • Right to Object (Art. 21): You may object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

1.6 International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA) where our service providers maintain infrastructure. Such transfers are conducted exclusively under Standard Contractual Clauses (SCCs) approved by the European Commission, or where the recipient country has been deemed to provide an adequate level of data protection under Art. 45 GDPR.

1.7 Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Art. 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also communicate the breach to you without undue delay.

1.8 Supervisory Authority

You have the right to lodge a complaint with the national supervisory authority for data protection in Romania:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)

B-dul Gheorghe Magheru nr. 28-30, Sector 1, București, Romania

Website: www.dataprotection.ro

02

Cookie Directive

2.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They serve to recognize your browser, remember your preferences, and enable certain functionality. Under the ePrivacy Directive (2002/58/EC) as transposed into Romanian law, we are required to obtain your informed consent before placing non-essential cookies on your device.

2.2 Cookies We Use

Strictly Necessary Cookies

Purpose: Essential for the website to function correctly. These cannot be disabled.

cookie_consent: Stores your cookie consent preference (accepted/declined). Duration: 365 days. Type: localStorage.

Session Cookies

Purpose: Maintain your session state during active browsing. Automatically cleared when you close your browser.

session: Server-side session identifier. Duration: Session. Type: HTTP-only cookie.

2.3 Third-Party Cookies

This website does not deploy third-party tracking cookies, advertising pixels, or analytics scripts that set cookies on your device. We do not use Google Analytics, Facebook Pixel, or similar tracking technologies. The Google Maps iframe on our contact page may set cookies as governed by Google's own privacy policy.

2.4 Managing Your Cookie Preferences

When you first visit this website, a cookie consent banner will appear allowing you to accept or decline non-essential cookies. Your choice is stored in your browser's localStorage and will be respected for subsequent visits. You may change your preference at any time by clearing your browser's localStorage for this site and revisiting.

2.5 Browser-Level Controls

Most browsers allow you to block or delete cookies through their settings. Note that disabling strictly necessary cookies may impair the functionality of this website. For detailed instructions, consult your browser's help documentation.

03

Refund Terms

3.1 General Refund Policy

At superlabdev, we are committed to delivering enterprise-grade digital infrastructure. Refunds are evaluated on a milestone-by-milestone basis according to the contractual scope of each engagement. All refund requests must be submitted in writing to [email protected].

3.2 Pre-Engagement Deposits

Initial deposits paid to secure project scheduling and resource allocation are non-refundable once the discovery phase has commenced. If a project is cancelled before the discovery phase begins, a full refund of the deposit will be issued within 14 business days, less any administrative processing fees (capped at 5% of the deposit amount).

3.3 Milestone-Based Refunds

For projects structured around defined milestones:

  • Payments for completed and accepted milestones are non-refundable.
  • If a milestone has been submitted but not yet accepted, you may request a refund within 7 business days of submission. We will review the deliverable against the agreed specification and issue a refund if the work materially fails to meet the documented requirements.
  • Payments for milestones not yet commenced may be cancelled and refunded in full.

3.4 Subscription and Retainer Services

Monthly retainer or subscription services may be cancelled with 30 days' written notice. No refund is provided for the current billing period in which cancellation is submitted. Pre-paid annual subscriptions are refundable on a pro-rata basis for the unused portion, minus a 10% administrative fee.

3.5 Dispute Resolution

If a refund request is denied and you believe the decision is unjust, you may escalate the matter through the following process:

  • Level 1: Written appeal to our management team within 14 days of the denial notification.
  • Level 2: Mediation through an independent mediator agreed upon by both parties.
  • Level 3: Binding arbitration under the rules of the Constanta Chamber of Commerce, Romania.

3.6 EU Consumer Rights

Where services are provided to consumers within the EU, you retain the right to cancel a distance contract within 14 days of its conclusion without providing any reason, in accordance with Art. 9 of Directive 2011/83/EU. However, by requesting the commencement of services before the expiry of the 14-day period, you acknowledge that you waive this right to the extent that services have been performed.

04

Service Agreement

4.1 Acceptance of Terms

By accessing this website or engaging superlabdev for any service, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service. If you do not agree with any provision herein, you must immediately cease use of our services and website.

4.2 Scope of Services

All services are delivered according to the specifications defined in the applicable Statement of Work (SOW) or service agreement executed between the parties. superlabdev reserves the right to modify the scope of any engagement only with prior written consent from the client. Any changes to the scope will be documented through a formal change request process.

4.3 Payment Terms

Unless otherwise specified in the applicable SOW:

  • Invoices are issued upon milestone completion and are payable within 14 calendar days of the invoice date.
  • Late payments accrue interest at a rate of 0.05% per day on the outstanding balance, beginning on the 15th day after invoice issuance.
  • All prices are quoted in Euros (€) and are exclusive of applicable VAT (Romanian TVA at 19%), which will be added to invoices where required by law.
  • Payment is accepted via bank transfer or through our Stripe payment gateway.

4.4 Intellectual Property

Upon full payment of all applicable fees, the client receives full ownership and intellectual property rights to all custom deliverables produced under the engagement. superlabdev retains the right to use generalized methodologies, frameworks, and non-client-specific knowledge developed during the engagement. Pre-existing intellectual property, third-party libraries, and open-source components remain subject to their original licenses.

4.5 Confidentiality

Both parties agree to maintain the confidentiality of all proprietary information exchanged during the course of the engagement. This obligation survives the termination of the agreement for a period of 3 years. Confidential information includes, but is not limited to: business strategies, technical architectures, source code, database schemas, API credentials, and client data.

4.6 Limitation of Liability

To the maximum extent permitted by applicable law, superlabdev's total aggregate liability arising out of or in connection with any service engagement shall not exceed the total fees paid by the client for the specific service giving rise to the claim during the 12-month period preceding the event. superlabdev shall not be liable for indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill.

4.7 Force Majeure

Neither party shall be liable for any delay or failure to perform its obligations under this Agreement where such delay or failure results from circumstances beyond the reasonable control of the affected party, including but not limited to: natural disasters, pandemics, war, terrorism, government actions, power failures, internet outages, or cyberattacks. The affected party shall provide prompt written notice and use reasonable efforts to mitigate the impact of the force majeure event.

4.8 Termination

Either party may terminate a service engagement with 30 days' written notice. Upon termination:

  • The client shall pay for all work completed and accepted up to the termination date.
  • All project deliverables completed to date shall be delivered to the client within 10 business days of termination.
  • Each party shall return or destroy all confidential information belonging to the other party.
  • Provisions relating to confidentiality, intellectual property, limitation of liability, and governing law shall survive termination.

4.9 Governing Law & Jurisdiction

These Terms of Service are governed by and construed in accordance with the laws of Romania and the European Union. Any disputes arising from or in connection with these terms shall be subject to the exclusive jurisdiction of the courts of Constanta, Romania, unless otherwise agreed in the applicable SOW.

4.10 Amendments

superlabdev reserves the right to modify these Terms of Service at any time. Material changes will be communicated via email to active clients at least 14 days before taking effect. Continued use of our services after the effective date of any changes constitutes acceptance of the revised terms.