Last updated 11 September 2026
This Privacy Policy explains how BEST STIL SRL processes the personal data of people who visit https://www.studio-80.ro/, request a reservation, send a message, or interact with the digital services used by Studio 80. It describes the data collected, the purposes and legal bases of processing, recipients, retention periods, and data subject rights.
1. Data controller
The controller of personal data is BEST STIL SRL.
Trade Register number: J2014002589230
Tax identification number: RO15671462
Registered office: 154-156 1 Decembrie Street, Lot 1, ground floor, Building 5, Apartment 2, Tunari Village, Tunari Commune, Ilfov County, Romania
Place of business: 80 Aleea Privighetorilor, 014031, District 1, Bucharest, Romania
Email for personal data requests: office@studio-80.ro
Telephone: +40 749 788 346
2. People and activities covered
This Policy applies to website visitors, people who request information or reservations, event attendees who communicate through the available channels, and people who interact with Studio 80 advertisements or profiles on external platforms.
Processing carried out directly by Google, Meta, TikTok, WhatsApp, or Tripadvisor for their own purposes is also governed by the policies of those operators.
3. Personal data we may process
- Identification and contact data, such as a name, telephone number, email address, and the account identifier used for communication.
- Reservation or enquiry data, such as the date, time, number of guests, stated preferences, message, and correspondence history.
- Technical data, such as the IP address, device and browser type, operating system, language, access date and time, pages viewed, referring page, and identifiers stored through cookies or similar technologies.
- Interaction and advertising data, such as clicks on telephone or WhatsApp links, page views, campaign source, conversions, and inclusion in an audience segment, where the user has given consent.
- Data provided voluntarily in a message. Users should not submit information that is unnecessary for their request, particularly sensitive health data, except for dietary information strictly necessary to manage a reservation.
4. Sources of personal data
Personal data is obtained directly from the data subject, from their use of the website and chosen contact channels, or from analytics and advertising providers to the extent allowed by the user’s settings and consent. Google Search Console mainly provides the operator with aggregate reports about the website’s search visibility and its use by the operator does not, by itself, require a Search Console cookie to be placed in a visitor’s browser.
5. Purposes and legal bases
Enquiries and reservations
We use contact information and request details to respond, check availability, confirm or amend a reservation, and provide the requested service. The legal basis is taking steps at the data subject’s request before entering into a contract and performing the contract under Article 6(1)(b) GDPR.
Legal obligations
We may process data for financial and accounting records, requests from authorities, food safety, complaint handling, and other obligations imposed by law. The legal basis is Article 6(1)(c) GDPR.
Security and the protection of legal rights
We may use technical logs and relevant correspondence to protect the website, prevent abuse, investigate incidents, and establish, exercise, or defend legal claims. The legal basis is the legitimate interest provided for in Article 6(1)(f) GDPR. We aim to ensure that this processing is proportionate and that the data subject’s rights do not override that interest.
Website analytics and improvement
We use Google Analytics and associated tools to produce statistics about website use only after obtaining consent for analytics cookies where the technology stores or accesses information on the device. The legal basis is Article 6(1)(a) GDPR, together with the cookie rules in Romanian Law No. 506/2004.
Advertising and conversion measurement
Google Ads, Meta Ads, and TikTok Pixel may be used to measure campaigns, attribute conversions, limit repeated advertisements, and, where the user consents, create or use advertising audiences. These non-essential technologies must be activated only after consent. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
Marketing communications
We do not send marketing communications by email, SMS, or similar services without the prior consent required by law, subject to the exceptions expressly permitted for existing customers. Each communication provides a simple method of unsubscribing.
6. Cookies and similar technologies
Cookies are files or identifiers stored on or read from a device. The website may use first-party cookies and technologies supplied by third parties.
Strictly necessary cookies
These support functions such as language selection, interface operation, security, and the storage of essential preferences. They may be used without consent where they are strictly necessary for the service requested. Examples observed on the website include pll_language, which stores the language preference, and porto_active_lang, which the theme uses temporarily for the active language.
Analytics cookies
Google Analytics may use identifiers such as _ga to distinguish visits and produce statistics. The exact duration depends on the active configuration; Google states that the main _ga cookie ordinarily lasts for up to two years. These cookies are used only after consent.
Advertising cookies
Google Ads, Meta Pixel, and TikTok Pixel may use cookies, pixels, and identifiers for conversion measurement and advertising. Their names and duration may vary depending on the platform and configuration. The list available in the cookie preferences panel must be updated whenever the technical implementation changes.
External content and links
Google or Tripadvisor review widgets and links to WhatsApp or social networks may send technical information to the provider when the content is loaded or accessed. External content that uses non-essential technologies must be blocked until the user makes the corresponding choice.
Consent choices and withdrawal
On the first visit, users must be able to accept, reject, or configure the non-essential categories separately. Rejecting them must be as easy as accepting them and must not prevent use of the website’s essential functions. Users may subsequently change their choice through the Cookie Settings link that is permanently available on the website or by deleting cookies from their browser.
7. Services and recipients of personal data
Depending on the user’s interaction and cookie choices, personal data may be disclosed to the following categories of recipients:
- Hosting, WordPress maintenance, security, email, and communications providers that support the operation of the website and services.
- Google, for Google Analytics, Google Ads, conversion tags, and Google Search Console reports. More information is available at https://policies.google.com/privacy?hl=en and https://policies.google.com/technologies/partner-sites?hl=en.
- Meta Platforms, for Meta Ads and Meta Pixel. More information is available at https://www.facebook.com/privacy/policy/.
- TikTok and its group companies when TikTok Pixel is active. More information is available at https://www.tiktok.com/legal/page/eea/privacy-policy/en.
- WhatsApp and Meta if the user chooses to make contact through WhatsApp.
- Tripadvisor and review widget providers if the user accesses or loads that content.
- Public authorities, courts, advisers, or other recipients where disclosure is required by law or necessary to protect legal rights.
Providers that process personal data on our behalf receive only the data necessary for their role and must comply with contractual instructions and applicable confidentiality and security obligations.
8. Transfers outside the European Economic Area
Some technology providers may process personal data in the United States or other countries outside the European Economic Area. Depending on the circumstances, transfers rely on an adequacy decision, including the EU-US Data Privacy Framework for certified organisations, the standard contractual clauses approved by the European Commission, or another mechanism under Chapter V GDPR. Information about the mechanism used may be requested at office@studio-80.ro.
9. Retention periods
We retain personal data only for as long as necessary for the purpose for which it was collected, taking account of legal obligations and limitation periods.
- Enquiries and reservations are retained while they are being handled and, as a rule, for no longer than three years after the last interaction or provision of the service, unless a legal obligation or dispute justifies a longer period.
- Financial and accounting records are retained for the period required by applicable law.
- Technical and security logs are generally retained for up to 90 days, except where they are required to investigate an incident.
- Records of consent and its withdrawal may be retained for as long as necessary to demonstrate compliance and protect legal rights.
- Analytics and advertising platforms retain data according to account settings and provider policies for campaign reporting and optimisation. Aggregated data that no longer identifies an individual may be kept longer.
At the end of the applicable period, personal data is deleted, anonymised, or archived with restricted access where the law requires its retention.
10. Data security
We apply technical and organisational measures appropriate to the risk, including access controls, updates to website components, backups, protection of communications, and data minimisation. No transmission or storage method can provide absolute security. If an incident occurs, we will apply the assessment, notification, and information requirements under the GDPR.
11. Data subject rights
Subject to the conditions of the GDPR, a data subject may request:
- Access to personal data and a copy of it.
- Correction of inaccurate data or completion of incomplete data.
- Erasure where there is no longer a legal basis for retention.
- Restriction of processing in the cases provided by law.
- Portability of data provided by the data subject where processing is based on consent or a contract and is carried out by automated means.
- Objection to processing based on legitimate interests and, at any time, to direct marketing.
- Withdrawal of consent at any time without affecting processing carried out before withdrawal.
- Lodging a complaint with a supervisory authority and bringing legal proceedings.
Requests may be sent to office@studio-80.ro. To protect personal data, we may request reasonable information to confirm the requester’s identity. We respond without undue delay and generally within one month. This period may be extended by up to two months for complex requests or where several requests have been received, provided that the data subject is informed within the initial period.
12. Complaints to the supervisory authority
Data subjects may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing. Its current contact details and complaint form are available at https://www.dataprotection.ro/. We encourage data subjects to contact us first at office@studio-80.ro so that we can investigate and address the matter directly, without limiting their right to contact the authority.
13. Profiling and automated decision making
Advertising platforms may create audience segments or make estimates about interests, depending on the user’s settings and consent. BEST STIL SRL does not use the website to make decisions based solely on automated processing that produce legal effects or similarly significant effects for the user.
14. Children’s personal data
The website is intended for a general audience and does not seek to collect personal data from children intentionally. If a minor submits a request that requires the consent of a legal representative, we may seek confirmation of that consent or delete data that is unnecessary.
15. Changes to this Policy
We may update this Policy when the website, providers, purposes of processing, or applicable law changes. The date of the latest update appears at the beginning. Where required by law, material changes will be communicated through a prominent website notice or another appropriate method before they take effect.
16. Relevant legal framework
The processing of personal data is governed primarily by Regulation (EU) 2016/679 on data protection, Romanian Law No. 190/2018 implementing the GDPR, and Romanian Law No. 506/2004 on privacy in the electronic communications sector.