1. Data protection contact
For GDPR and privacy requests relating to Xeotype public websites, product enquiries, robotics orders, collaboration requests, email communication or WhatsApp conversations started from Xeotype websites, contact contact@xeotype.com.
Please use the subject line “GDPR request” so the request can be identified quickly.
2. Rights you may exercise
Depending on the situation and legal conditions, you may have the following rights under the GDPR:
- Right to information: receive clear information about how personal data is processed.
- Right of access: ask whether Xeotype processes your personal data and request a copy of relevant data.
- Right to rectification: ask Xeotype to correct inaccurate or incomplete data.
- Right to erasure: ask Xeotype to delete data where the legal conditions are met.
- Right to restriction: ask Xeotype to limit processing in specific circumstances.
- Right to data portability: receive data you provided in a structured, commonly used and machine-readable format where applicable.
- Right to object: object to processing based on legitimate interests or direct marketing, where applicable.
- Right to withdraw consent: withdraw consent where processing is based on consent, without affecting earlier lawful processing.
- Rights related to automated decisions: rights connected to certain decisions based solely on automated processing. Xeotype does not currently use the public websites for such decisions.
3. What to include in a request
To help Xeotype identify and answer the request, please include:
- your full name and the email address or phone number used when contacting Xeotype;
- the right you want to exercise;
- the website, project, order, message, quote or collaboration request the data relates to;
- approximate dates of communication, if known;
- any specific data, file, photo, message or page you want us to check;
- whether you are acting for yourself or as an authorised representative.
4. Identity verification
To protect personal data, Xeotype may ask for additional information to verify that the request is made by the correct person or an authorised representative. This is especially important for requests involving access, deletion, invoices, project files, student-related information, event photos or business communication.
Xeotype will not request unnecessary identity documents. If identity proof is needed, we will ask only for information reasonably necessary to prevent unauthorised disclosure, modification or deletion.
5. Response time
Xeotype aims to respond to valid GDPR requests without undue delay and within the timeframe required by the GDPR. Where the request is complex, covers many records, involves third-party rights or requires additional verification, the response period may be extended where permitted by law and you will be informed when required.
6. When a request may be limited
Some requests cannot always be fulfilled completely. Xeotype may need to keep or restrict certain data where required or permitted by law, including for:
- accounting, tax, invoicing or audit obligations;
- contract evidence, order history, warranty or delivery records;
- fraud prevention, website security and incident investigation;
- legal claims, dispute resolution or enforcement of rights;
- protecting intellectual property, trade secrets or confidential business information;
- protecting the rights and freedoms of other people;
- public event documentation or portfolio materials lawfully published in context.
If Xeotype cannot fulfil a request fully, we will explain the relevant reason where appropriate.
7. Requests involving photos, videos or public events
If your request concerns photos, videos, robotics competitions, educational events, public demonstrations or portfolio materials, please identify the specific material as clearly as possible. Useful details include the event name, date, URL, screenshot, project name or image description.
Where removal is legally required or appropriate, Xeotype will take reasonable steps. In some situations, complete removal may not be possible from third-party platforms, cached pages, search engines, public event organisers or materials already distributed outside Xeotype’s control.
8. Requests involving minors
If a request relates to a minor, Xeotype may require confirmation that the requester is the parent, legal guardian, authorised school representative or another person legally entitled to act. This protects minors and prevents unauthorised disclosure or deletion.
9. Requests sent by representatives
If you act on behalf of another person, Xeotype may ask for proof of authorisation. This can include a written mandate, legal representation proof or other appropriate confirmation, depending on the context.
10. Withdrawal of consent
Where processing is based on consent, you may withdraw consent at any time by contacting Xeotype. Withdrawal does not affect processing that was lawful before withdrawal, and it may not affect processing required for legal obligations, contracts, invoices, disputes or legitimate security reasons.
11. Objection to legitimate-interest processing
You may object to processing based on legitimate interests. Xeotype will review the request and stop processing unless there are compelling legitimate grounds to continue or the data is needed for legal claims or other legally permitted reasons.
12. Complaint authority
If you believe your data protection rights have not been respected, you can contact Xeotype first at contact@xeotype.com. You may also contact the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, through dataprotection.ro.
13. Related policies
For the broader explanation of how Xeotype processes data, see the Privacy Policy. For cookies and similar technologies, see the Cookie Policy. For company and website terms, see the Legal Notice.
14. Updates
This GDPR request procedure may be updated as Xeotype websites, products, legal requirements and internal processes evolve. The latest version will be published on this page.