Privacy Policy
Last updated: 18 September 2026
This notice explains personal-data processing for the FlyNCP presentation website, demo enquiries and related correspondence with business representatives. Platform account administration and campaign participant processing are outside this website notice. This notice is provided under Articles 13 and 14 GDPR. It informs you about our processing; it does not ask for your consent, except for the optional services described in section 4 (diagnostics, analytics and advertising measurement).
1. Who we are
The controller for the website and its own business-contact processing is:
EVENTRIO ACTION S.R.L. (limited liability company, Romania)FlyNCP is a brand of EVENTRIO ACTION S.R.L.
Trade Register: J2018005400408
Tax ID (CUI/VAT): RO39216884
Share capital: 200 RON
Registered office: Str. Orientului nr. 9, camera 1, Tunari, Ilfov County, 012071, Romania
Phone: +40 314 329 430
Email: hello@flyncp.com
Data protection contact: hello@flyncp.com.
2. Scope of this notice
This notice covers visitors to our presentation pages and people contacting us about FlyNCP, including representatives of prospective and existing business customers. The operation of customer accounts within the platform and processing of campaign participant data remain outside this website notice.
If you enter a promotional campaign, read the privacy notice linked from that campaign. It identifies the responsible organization, the data requested and the campaign’s processing purposes. A brand, agency and FlyNCP may have different roles in that arrangement. Customer services and processing on a customer’s behalf are governed separately from this public website.
This website notice does not replace a campaign notice or a customer’s data-processing agreement. Questions about eligibility, participant communications or campaign data should follow the contacts in the campaign notice.
3. Information we process
- Demo enquiries:
- Your name, work email and company (required)
- Your estimated campaign volume (required)
- Your phone number (required — used only to arrange and hold your demo call)
We also process follow-up correspondence. Fields marked as required are needed to submit the form. If you prefer not to provide them, you can contact us by email instead.
- Website and security information: technical request information, IP address and pseudonymised identifiers used for rate limiting, and relevant security logs. Pseudonymised information is not necessarily anonymous.
- Form protection: a Turnstile token and technical signals processed by Cloudflare to check for automated abuse, including IP and browser information.
- Requested preferences: the homepage theme you select and your choices for the optional diagnostics, analytics and advertising-measurement categories.
- Optional diagnostics: if you accept browser diagnostics on these presentation pages, Sentry can receive error details, session identifiers, page URLs, browser, operating-system and device information, timestamps, software versions and contextual records of clicks, navigation, console messages and requests. Sentry sees the IP address used for the connection. Our project’s “Prevent Storing of IP Addresses” setting is enabled, so IP addresses are not stored for new events. Enabling this setting does not delete IP addresses from historical events; those records remain subject to the retention periods below. Filtering reduces some information but does not make all diagnostic data anonymous.
- Optional analytics: if you accept analytics, Google Analytics 4 receives pages viewed, referring source, approximate country or region derived from your IP address (Google Analytics does not log or store IP addresses of EU users), device and browser information and interactions such as opening the demo form, linked to a random identifier stored in a cookie. It does not receive your name, email, phone number, company or form content.
- Optional advertising measurement: if you accept advertising measurement and you arrive from a Google ad, Google Ads receives the ad-click identifier, the fact that a demo request was submitted, and technical request information (including IP address) in order to attribute the conversion. No form content is sent, and the ad-personalisation signal is always denied.
Information comes from you, your browser and the technical services involved in those interactions. The demo form does not request participant records or receipt images; please do not include them in a demo enquiry.
4. Purposes and legal grounds
- Responding to enquiries and managing business relationships
- Legal basis: our legitimate interest (Article 6(1)(f) GDPR) in responding to business enquiries addressed to us and in communicating with representatives of prospective and existing business customers. Where you contact us on your own behalf, for example as a sole trader or freelancer, Article 6(1)(b) GDPR (steps taken at your request before entering into a contract) applies instead. You may object to processing based on our legitimate interests at any time (see section 8).
- Providing the website and preventing abuse
- Our legitimate interest under Article 6(1)(f) GDPR is to maintain the reliability and security of the website and protect it from abusive requests. Rules for storing or accessing information on your device are considered separately from this GDPR basis.
- Optional diagnostics, analytics and advertising measurement
- Your consent under Article 6(1)(a) GDPR and Article 4(5) of Law 506/2004, given separately for each category through the privacy banner or Privacy choices. You can refuse or withdraw it at any time through Privacy choices without losing access to the presentation pages or demo form. Google services are not loaded before you accept.
- Legal obligations
- Where a specific legal record-keeping or disclosure obligation applies, the relevant processing is based on Article 6(1)(c), rather than optional diagnostic consent.
- Requested preferences and your privacy choice
- Storing the homepage theme you select is a function you request; where this involves personal data, our legal basis is our legitimate interest in providing that requested function (Article 6(1)(f) GDPR). Storing your choice for each optional category is necessary for us to demonstrate that consent was given or refused (Article 7(1) and Article 6(1)(c) GDPR). Neither is used to track you. These requested preferences and the security check are necessary technologies exempt from prior consent under Article 4(5)(b) of Romanian Law 506/2004.
We do not use your data for automated decision-making or profiling within the meaning of Article 22 GDPR on this website. Legal obligations under Article 6(1)(c) include responding to lawful requests from public authorities and keeping records required by tax and accounting law.
Sending a demo request does not subscribe you to a marketing newsletter. Campaign participation and any optional campaign marketing require their own purposes and appropriate legal grounds.
5. Service providers and transfers
The website’s technical workflow uses hosting and infrastructure services, including Vercel and Supabase; Brevo for sending demo-enquiry emails to our contact mailbox hosted on Google Workspace Business Starter; Cloudflare Turnstile for form protection; and Sentry for diagnostics. With your consent, we also use Google Tag Manager and Google Analytics 4 (audience measurement) and Google Ads conversion measurement, provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. For Google Analytics and Google Tag Manager, Google acts on our instructions under the Google Ads Data Processing Terms. For Google Ads conversion measurement, Google acts as an independent controller under the Google Ads Controller-Controller Data Protection Terms; Google’s privacy policy and its page “How Google uses information from sites or apps that use our services” describe that processing. We do not use Google Signals, remarketing, personalised advertising, enhanced conversions or any transfer of form data to Google. Both Brevo and Google are part of this email workflow so we can handle the request. Email records can include delivery status and opening events for the notification sent to our contact mailbox.
Provider roles depend on the processing purpose. Cloudflare describes both processing on behalf of its customer for Turnstile protection and its own processing for improving bot detection in its Turnstile privacy information. Providers should not all be treated as exclusively acting on our instructions for every purpose.
International transfers. Some of our providers are established in, or provide support from, countries outside the European Economic Area: the United States (Vercel Inc., Functional Software, Inc. d/b/a Sentry, Cloudflare, Inc. and Google LLC — our Google Workspace Business Starter mailbox has no data-region selection; Google Analytics and Google Ads data is collected through EU-based servers and then processed by Google LLC in the United States) and Singapore (Supabase Pte. Ltd; our project is hosted in Europe, but support access may occur from outside the EEA). Brevo (Sendinblue SAS, France) states that its database hosting and storage are in the European Union; this does not mean that all subprocessor or support processing is restricted to the EU. For transfers to the United States, the European Commission’s adequacy decision of 10 July 2023 applies to participating organisations certified under the EU-U.S. Data Privacy Framework, including Vercel, Sentry, Cloudflare and Google. The providers’ data-processing terms also provide for the Standard Contractual Clauses adopted by the Commission (Decision (EU) 2021/914) where applicable, with supplementary measures where needed. You can obtain a copy of the applicable safeguards by writing to hello@flyncp.com.
This recipient information concerns the presentation website and enquiries. Receipt-processing services for customer campaigns fall outside this notice; consult the relevant campaign information.
6. Retention
Our retention policy sets the following periods:
- Demo enquiries and related correspondence that do not lead to further discussions: 12 months from our last exchange.
- Pre-contractual correspondence (offers and negotiations) that does not result in a contract: 3 years from the end of the discussions, for the establishment, exercise or defence of legal claims.
- Correspondence relating to a concluded contract: for the term of the contract and thereafter where required by accounting and tax law. Supporting accounting documents are kept for 5 years, calculated from 1 July of the year following the relevant financial year; financial statements are kept for 10 years.
- Delivery and opening records for our internal notification emails (Brevo): our retention policy is 30 days. This is our retention requirement, not a confirmation that Brevo automatically deletes every record after 30 days. We request deletion of records that exceed this period.
- Security and infrastructure logs: no longer than 90 days, unless needed to investigate a specific incident. Rate-limiting identifiers are retained only for the applicable limiting window, with a maximum of 30 days.
- Optional diagnostic events (Sentry): no longer than 90 days.
- Google Analytics event-level and user-level data: 14 months from collection (aggregated reports contain no personal data). Google Ads click and conversion data: retained by Google as an independent controller, in accordance with Google’s privacy policy.
- Requests to exercise your rights and our replies: 3 years from closure.
We review our contact mailbox at least quarterly and delete enquiries that have reached the end of their retention period. Relevant records may be retained longer where a specific legal obligation or documented legal claim requires it; access and use are restricted to that purpose.
Provider backups are overwritten in the provider’s normal cycle. Deletion from an active system does not necessarily remove a backup copy immediately. Cloudflare’s own retention of Turnstile signals is described in its Turnstile privacy information.
Browser cookie lifetimes are described in the Cookie Policy; they are not retention periods for data already received by a provider. Withdrawing diagnostic consent stops future collection but does not by itself erase data already received; you can request erasure using the contact details below.
7. Security
The website uses form anti-abuse controls, request limits and filtering of diagnostic event data. These measures reduce risk; they do not guarantee that every incident can be prevented or that all diagnostic information is anonymous.
8. Your rights
Subject to the applicable conditions, you may request access, correction, erasure or restriction of processing. Data portability applies in the circumstances set out in the GDPR, including the relevant legal basis and automated processing; it is not a right to every kind of business report.
Right to object: you may object, on grounds relating to your particular situation, to processing based on legitimate interests. If personal data is used for direct marketing, you may object to that use at any time.
Where processing relies on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing before withdrawal. Withdrawing consent for analytics or advertising measurement stops that service and deletes the corresponding first-party Google cookies we control; to request erasure of data already received by Google, contact us and we will forward the request or explain how to address Google directly. Erasure is not absolute: applicable legal obligations and other lawful exceptions may require some information to be retained.
9. Requests and complaints
Email our data protection contact at hello@flyncp.com to exercise rights for processing covered here. We may need proportionate information to confirm your identity and locate the relevant records. The GDPR ordinarily requires a response within one month; where a lawful extension of up to two further months is needed, we will inform you within the first month, with the reasons.
You may lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, Romania, anspdcp@dataprotection.ro, +40 318 059 211, www.dataprotection.ro — or with the supervisory authority of your habitual residence or place of work. You do not need to contact us first.
11. Changes to this notice
The update date identifies this version. We update this notice to reflect changes to website and enquiry processing. A new purpose requiring consent cannot rely on your previous choice merely because this page has changed.