Xeotype
Studio Projects Process Collaborate

Legal documents

GDPR Rights

Last updated: 29 July 2026. This page explains how you can exercise data protection rights in relation to hub.Xeotype.

1. Who to contact

Send GDPR requests to contact@xeotype.com. Please include your name, contact details, the right you want to exercise and enough information for us to identify the relevant communication or project request.

2. Rights you may exercise

  • Access: ask whether we process your personal data and request a copy.
  • Rectification: ask us to correct inaccurate or incomplete information.
  • Erasure: ask us to delete data where the legal conditions are met.
  • Restriction: ask us to limit processing in specific circumstances.
  • Portability: request data you provided in a structured format where applicable.
  • Objection: object to processing based on legitimate interests.
  • Withdrawal of consent: withdraw consent where processing relies on consent.

3. Identity verification

We may ask for additional information to confirm your identity before answering a request, especially when the request involves access, deletion, sensitive business discussions or project files.

4. Response time

We aim to respond without undue delay and within the period required by GDPR. If a request is complex or covers many records, we may need additional time and will inform you when required.

5. Limits

Some requests may be limited by legal obligations, accounting rules, contract evidence, security obligations, dispute handling, intellectual property protection or the rights of other persons. If we cannot fulfil a request completely, we will explain the reason where legally possible.

6. Supervisory authority

If you believe your personal data rights were not respected, you may contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 28-30 G-ral Gheorghe Magheru Bld., District 1, Bucharest, Romania, email anspdcp@dataprotection.ro.

7. How to submit a request

Send your request from the email address you used when contacting Xeotype, if possible. Describe the context: website form, WhatsApp conversation, product request, collaboration, invoice, MobilityCloud-related communication, robotics request or another Xeotype project. This helps us identify the relevant records.

8. Requests made on behalf of another person

If you act on behalf of another person, organisation, student, team member or partner, Xeotype may ask for proof of authority before disclosing, correcting or deleting data. This protects the rights and confidentiality of the person concerned.

9. Backup and archive limits

When deletion or rectification is accepted, active records will be updated or removed where possible. Some data may remain for a limited period in backups, logs, email archives, accounting records or legal evidence systems until routine deletion, retention expiry or legal limitation periods apply.

10. Objection and legitimate interests

You may object to processing based on legitimate interests, such as maintaining business communication records, protecting against abuse, defending legal claims or keeping project history. Xeotype will assess the objection and stop processing unless compelling legitimate grounds or legal claims justify continued processing.

11. Complaint before escalation

You may contact ANSPDCP at any time, but we encourage you to contact Xeotype first so we can understand and resolve the issue quickly. This does not limit your right to complain to the supervisory authority.

12. Request scope across Xeotype products

When submitting a request, specify whether it concerns the hub website, MobilityCloud, robotics.Xeotype, prints.Xeotype, a product order, an invoice, WhatsApp communication, email correspondence, a file attachment, a public collaboration page or another Xeotype product. This helps us search the correct systems and answer faster.

13. Excessive, repetitive or unfounded requests

GDPR allows controllers to refuse or charge a reasonable fee for requests that are manifestly unfounded or excessive, especially because of their repetitive character. If this applies, Xeotype will explain the reason in the response.

14. Third-party and mixed files

Some project files or communications may contain information about several people, organisations or confidential business matters. Before disclosing, deleting or copying such data, Xeotype may redact, separate or limit information in order to protect the rights and freedoms of others.

15. Contractual and accounting conflicts

Data protection rights may interact with contractual, tax, accounting, warranty, dispute, intellectual property and product safety obligations. If a GDPR request conflicts with a legal duty to keep certain records, Xeotype will keep only what is necessary and explain the applicable limitation where possible.

Data protection

Most hub.Xeotype requests are handled by email or WhatsApp, so the fastest route is to contact us using the same email address you used before.

Privacy Cookies Terms
Xeotype xeotype.com contact@xeotype.com contact privacy cookies terms GDPR