Barbell Studio
    HomeShopAboutGalleryContact
    LoginJoin Now

    Privacy Policy

    What data we collect, why, and the rights you have over it — in plain language.

    Last updated: 7 August 2026

    On this page

    1. 1.Who we are
    2. 2.What data we collect
    3. 3.Why we process your data and on what legal basis
    4. 4.Who we share data with
    5. 5.How long we keep your data
    6. 6.Your rights under the GDPR
    7. 7.Cookies
    8. 8.How we protect your data
    9. 9.Children
    10. 10.Changes and contact

    At a glance

    We collect only the data you give us — nothing behind your back

    We never sell or rent your personal data

    Card details are handled by NETOPIA Payments and never touch our servers

    Full GDPR rights — one email away

    Ask us to erase you and we do — only the invoices stay, as the law requires

    1.Who we are

    Barbell Studio (“we”) operates the gym at Strada Pătlaginei 18, Bucharest, and this website. We are the data controller for the personal data described in this policy and we process it in accordance with the EU General Data Protection Regulation (GDPR).

    For any question about this policy or about your data, write to us at info@barbellstudio.ro.

    2.What data we collect

    We collect only data that you provide to us directly:

    • Account and profile data — name, email address and password (stored only in encrypted form), plus optionally phone number, birthday and social media handles.
    • Membership application data — the details you submit when applying to join the gym.
    • Payment and order data — your orders, invoiced amounts and payment status. Card payments are processed by NETOPIA Payments; your card number never reaches our servers.
    • Billing details — the address you give at checkout, and, if you ask for the invoice to be issued to a company, that company's name, CUI and trade register number. These appear on the invoice.
    • Profile picture — only if you choose to upload one. It is shown next to your testimonial if that testimonial is published.
    • Testimonials — if you choose to write one. Nothing is published until our team approves it, and it then appears publicly with your first name, the initial of your surname and your profile picture.
    • Saved card reference — only if you turn on automatic renewal. We store a token from NETOPIA plus the last four digits, never the card number itself, and you can remove it at any time.
    • Messages — what you send us through the contact form: name, email, optional phone number and your message.
    • Technical data — a session cookie while you are signed in and your language preference.

    We do not collect health data, we do not track you across other websites and we do not use advertising cookies. Nothing you write or upload is published without your say-so — a testimonial and profile picture appear on the site only after you submit them and our team approves them.

    3.Why we process your data and on what legal basis

    We process your data only for the purposes below, each resting on a legal basis under the GDPR:

    • Running your membership (performance of a contract) — creating your account, managing your plan and processing your orders.
    • Billing and accounting (legal obligation) — keeping the payment records required by Romanian fiscal law.
    • Answering you (legitimate interest) — reviewing membership applications and replying to contact form messages.
    • Service emails (performance of a contract) — application status, payment confirmations, membership expiry reminders and password resets. We do not send marketing emails.
    • Protecting the site against abuse (legitimate interest) — captcha verification and rate limiting on the contact form.
    • Publishing testimonials (consent) — only if you write one and we approve it. You can withdraw it at any time by deleting it from your profile or asking us to remove it.
    • Automatic renewal (consent) — only if you enable it. Withdrawing consent removes the saved card reference immediately.

    4.Who we share data with

    We never sell or rent your personal data. We share it only with the service providers we need in order to run the gym:

    • NETOPIA Payments — secure card payment processing.
    • Oblio.eu — issuing and storing our fiscal invoices. Your name, and where applicable your address and company details, appear on the invoice as the law requires.
    • Resend — delivering our service emails (confirmations, reminders, password resets).
    • Cloudflare Turnstile — protecting the contact form against bots.
    • Our hosting provider — the servers this website and its database run on.

    Each provider processes data only on our instructions, under GDPR-compliant data processing agreements. Where a provider processes data outside the EU, it does so under the safeguards provided by the GDPR (such as standard contractual clauses).

    5.How long we keep your data

    • Account and profile data — for as long as your account exists. When your account is closed, your name, email, phone, address, company details and profile picture are permanently erased.
    • Payment and order records — 10 years, as required by Romanian accounting legislation. These are kept even after your account is closed, but stripped of the personal details we no longer need: what remains is the amounts, dates and invoice numbers.
    • Invoices — 10 years at our invoicing provider, Oblio.eu. An issued invoice must by law carry the name and, where applicable, the address it was made out to, so that information stays on the invoice itself.
    • Profile picture and testimonial — until you remove them or your account is closed, whichever comes first.
    • Saved card reference — until you turn off automatic renewal or your account is closed.
    • Membership applications — until the application is resolved and for a reasonable period afterwards. They are deleted when the account they belong to is closed.
    • Contact form messages — until your inquiry is resolved.

    6.Your rights under the GDPR

    You have the right to:

    • Access the personal data we hold about you and receive a copy of it.
    • Have inaccurate data corrected.
    • Have your data deleted (“the right to be forgotten”), where there is no legal obligation for us to keep it. See below for exactly what this means in practice.
    • Restrict or object to the processing of your data.
    • Receive your data in a portable format.
    • Withdraw your consent at any time, where processing is based on consent.

    What erasure actually does: we permanently remove your name, email, phone number, date of birth, address, company details, social handles, profile picture, testimonial and any saved card reference, and your membership application is deleted. Your account can no longer be used to sign in.

    What we must keep: the orders, payments and invoices behind them. Romanian accounting law requires us to retain these for 10 years, and the GDPR (Article 17(3)(b)) allows exactly this exception. They are kept without the personal details we no longer need — the amounts, dates and invoice numbers remain, and the invoice itself carries the name it was legally issued to.

    If you would rather simply stop using your account without erasing anything, ask us to deactivate it instead — sign-in is blocked and nothing is deleted, and we can undo it whenever you want.

    To exercise any of these rights, email us at info@barbellstudio.ro — we reply within 30 days. You also have the right to lodge a complaint with the Romanian supervisory authority, ANSPDCP (www.dataprotection.ro).

    7.Cookies

    We use no advertising or cross-site tracking cookies. Your browser stores only what is strictly necessary for the site to work:

    • A session cookie — keeps you signed in to your account; it disappears when it expires or when you sign out.
    • Security cookies — set by our sign-in system to protect forms against cross-site request forgery (CSRF).
    • Your language preference — a cookie remembering whether you chose English or Romanian, so pages load in the right language.
    • Cloudflare Turnstile — may set a cookie on the contact page, strictly for telling humans and bots apart.
    • No payment cookies are set on our site — paying by card takes you to NETOPIA's own secure page.

    The full details — every cookie, its duration and how to control them — are on our Cookie Policy page.

    8.How we protect your data

    Passwords are stored only in encrypted (hashed) form, connections to the site are encrypted (HTTPS), access to member data is restricted to authorized staff, and card data is handled exclusively by NETOPIA Payments. No method of transmission over the internet is 100% secure, but we follow good industry practice to protect your data.

    9.Children

    Our services are intended for people aged 16 and over. We do not knowingly collect data from children under 16; if you believe a child has provided us personal data, contact us and we will delete it.

    10.Changes and contact

    We may update this policy as the service evolves. Significant changes are announced by email or on this page, and the date at the top always reflects the latest version.

    Questions? Write to info@barbellstudio.ro or visit us at Strada Pătlaginei 18, Bucharest.

    Questions about this document? We're happy to explain anything.

    Contact us
    Barbell Studio

    A private strength training gym in Bucharest. Good iron, no crowds, room to train.

    Quick Links

    • Home
    • Memberships
    • About Us
    • Gallery

    Support

    • Contact
    • FAQ
    • Terms & Conditions
    • Privacy Policy
    • Cookie Policy
    • ANPC – SAL
    • ANPC – SOL

    Contact

    • Str. Pătlăginei, Nr. 18, București
    • +40 735 946 491
    • info@barbellstudio.ro

    BARBELL STUDIO S.R.L. · Reg. Com. J29/1499/2020 · CUI 42966797 · Str. 22 Decembrie, Nr. 20, Municipiul Câmpina, Județ Prahova · EUID ROONRC.J2020001499292

    © 2026 Barbell Studio. All rights reserved.