Privacy notice

Last updated: 7 October 2026

This notice explains what personal data TQM Invest SRL handles, why, who else sees it and what rights you have. It covers two groups: people who visit this website or book a call, and business contacts we may research or contact about our services.

Who is responsible

The controller is TQM Invest SRL, a Romanian company.

  • CUI 18249838
  • VAT ID RO18249838
  • Registered office: Satu Mare, Romania
  • Contact for anything in this notice: hello@tqminvest.com

If you visit this website

We measure how the site is used with PostHog, set up so that it identifies no one and stores nothing in your browser.

  • No cookie, local storage or session storage is used for analytics. A new random identifier is created for each page load and is never saved on your device. Because of this, we cannot recognise a returning visitor.
  • The events we record are page views, clicks on links to the booking page (cta_click), clicks on email or phone links (contact_click) and a completed booking (booking_submitted). Each event carries the page address and the standard page and browser details that the PostHog library attaches, such as the referrer.
  • We switch off autocapture of clicks and keystrokes, session recording and surveys.
  • If your browser sends Do Not Track or Global Privacy Control, PostHog is not loaded at all.
  • Events go to PostHog's EU cloud through a relay on our own domain (/ingest). The relay passes on only the content of the event and a few technical headers. It does not forward your IP address or any cookies.

Legal basis: our legitimate interest in understanding which pages and calls to action work (Article 6(1)(f) GDPR). You can object at any time; see "Your rights".

Like any website, our host (Vercel) receives the technical data needed to deliver a page, such as your IP address and request details, and keeps server logs under its own terms.

Case-study images are served from an Amazon Web Services storage bucket through the CloudFront content network. Those files are our own images and contain no visitor data, though any image request reaches CloudFront like any other web request.

If you book a call

Booking is optional. The form asks for your name, email address, company (optional), the service you are interested in, budget range, timeline, a description of your project and the time you choose.

  • First visit details. The form also sends where you first arrived on this site: the landing page, the referring website, and any campaign tags (UTM) or ref value in the link. This is held in your browser's memory only, is sent with the form, and is written on the first record of your enquiry so we know which content produced it. It is lost if you reload the page before booking.
  • Spam protection. Cloudflare Turnstile checks that the submitter is a person. It runs in your browser and Cloudflare tells our server whether the check passed. We also count submissions per IP address (the address is stored as a rate-limit key) to limit repeated submissions within 24 hours.
  • Records. Your details are stored in our database (Neon, a PostgreSQL service hosted in AWS Frankfurt, eu-central-1) as an enquiry and a deal that our team follows up.
  • Emails. Through Resend we send you one confirmation (service, time, budget and timeline) and send our team a notification with your submission and the first visit details. We do not use Resend for marketing or cold email.
  • Team notices. Our internal daily and weekly summaries are posted to a private Discord channel. They name deals and companies (a deal is named after you if you gave no company) and job titles. They do not include your email address or your project description.
  • Proposals. Proposals are written from templates by default. If our team switches on the optional AI engine, the brief for that deal (contact name and role, company, project description, stated budget and timeline, and our notes) is sent to Anthropic's API to draft the text, and a person reviews it before anything is sent to you.

Legal basis: taking steps at your request before a contract (Article 6(1)(b)), and our legitimate interest in keeping the form free of abuse and knowing which content brings enquiries (Article 6(1)(f)).

If you are a business contact we may research or contact

To find companies that may need our services, we keep a database of companies and the people who make technology decisions there. You may be in it even though you have never visited this website.

Where the data comes from. Public sources only:

  • public job and project postings on job boards and freelance marketplaces (for example LinkedIn, Indeed, Glassdoor and Upwork) and public technology communities;
  • public company websites (team, leadership, contact and imprint pages);
  • public professional profile links found in those postings;
  • public procurement notices from EU and Romanian portals (TED and SICAP), which are about organisations;
  • third-party data-enrichment services that return a work contact for a named person at a company (we have used or may use Apollo, Apify, FullEnrich, BetterContact and Dropcontact). Where an address is not published, we may infer it from the company's email naming pattern and ask the company's mail server whether it exists, without sending a message.

What we hold. Company name and website, the posting we found, the person's name and job title, a work email address or professional profile link, and our own notes. We aim at business roles only and do not collect special-category data.

Why, and on what basis. To decide which companies to approach and to approach a few of them about our services. The legal basis is our legitimate interest in business-to-business development (Article 6(1)(f) GDPR), which we balance against your interests and reasonable expectations as a professional.

How we contact people. Our rules are that a person reviews every message, messages are not sent in bulk, we write to work addresses and never to private mailboxes, and we apply the rules of the recipient's country, which in some countries means approaching people only through LinkedIn or a personal referral rather than by email. Cold email is never sent through Resend. Any message will say who we are and where we found your details.

Your right to object. You can object to this at any time and we will stop. Email hello@tqminvest.com. We then delete your record or keep only your email address or domain on a do-not-contact list, so that we do not collect or contact you again.

Automated decisions

We do not make decisions about people by automated means that have legal or similarly significant effects. Our software scores and ranks job postings and companies by how well they fit the work we do, to decide what a person on our team looks at first. A person decides whether to contact anyone.

Cookies and similar technology

The public pages of this site set no cookies of our own and use no browser storage. The one third-party component is the Cloudflare Turnstile check on the booking page, which Cloudflare operates under its own terms. We do not use it for tracking, and you can read how it works in Cloudflare's documentation.

Cookies exist only in our private team area (/crm): a sign-in session cookie and a cookie that remembers whether a sidebar is open. They are set for staff when they sign in and never for visitors.

Who else handles your data

These providers process data for us, each for one purpose. We do not sell personal data.

  • Vercel: hosts the website and our team application; sees request data such as IP address.
  • Neon: database hosting (AWS Frankfurt, eu-central-1); holds booking records and the business contact database.
  • PostHog (EU cloud): cookieless site analytics, as described above.
  • Cloudflare: Turnstile spam check on the booking form (it sees your browser and IP address).
  • Resend: sends the booking confirmation and the internal notification (your name, email address and booking details).
  • Discord: receives internal summaries naming deals, companies and job titles.
  • Amazon Web Services: stores case-study images (S3, CloudFront) and our private deal documents (S3, eu-central-1).
  • Anthropic: drafts proposal text from a deal brief, only if the optional AI engine is on.
  • Data-enrichment and scraping services (Apify, Apollo, FullEnrich, BetterContact, Dropcontact): used to find or verify work contacts, as described under business contacts.

We may also disclose data where the law requires it, for example to a court or authority.

Transfers outside the EU

Some of the providers above are based in, or may process data in, the United States or other countries outside the European Economic Area. Where that happens, the transfer relies on the safeguards the provider uses under Chapter V of the GDPR. Ask us at hello@tqminvest.com for details.

How long we keep data

We keep personal data for as long as needed for the purpose it was collected for. Enquiry and deal records are kept while we handle the enquiry and any resulting engagement, and business contact records while they are useful for the purpose above. When you object or ask us to erase your data, we act on it without undue delay and at the latest within one month.

Your rights

Under the GDPR you can ask us for:

  • access to the data we hold about you, and a copy;
  • correction of data that is wrong;
  • erasure of your data;
  • restriction of how we use it;
  • a portable copy of data you gave us, where the law applies;
  • an end to processing based on our legitimate interest (the right to object), including direct marketing, which is absolute;
  • withdrawal of any consent you gave, at any time.

Email hello@tqminvest.com. We may need to confirm who you are before we act. If you are not happy with our answer, you can complain to the Romanian data protection authority, ANSPDCP (dataprotection.ro), or to the authority in the EU country where you live or work.

Changes to this notice

If what we do changes, we update this page and the date at the top.