QJQujoAutovermietung

Qujo Autovermietung GmbH

Car rental. Personal. Transparent. Reliable.

Mehedinti 55-57

400678 Cluj-Napoca, Romania

Quick Links

  • About Us
  • Contact
  • Help & Support
  • Browse Cars

Legal

  • Imprint
  • Privacy Notice
  • General Rental Terms
  • Withdrawal-right notice

Contact

  • webira.rem.srl@gmail.com
  • +40771248029

Managing Director: Rusu Emanuel Marius

Commercial Register: 88882222RO

Finante Romania

© 2026 Qujo Autovermietung GmbH. All rights reserved.

Contact →
    HomeBack to homeQJQujoAutovermietungPrivacy Notice

    Privacy Notice

    This notice explains how we process personal data on our website and in connection with booking requests and vehicle rentals.

    Last updated: 20 July 2026

    1. Controller

    Qujo Autovermietung GmbH

    Mehedinti 55-57

    400678 Cluj-Napoca

    Romania

    E-Mail: webira.rem.srl@gmail.com

    Phone: +40771248029

    2. Website access and hosting

    Whenever this website is accessed, our hosting systems process technically necessary connection data, in particular IP address, time, requested URL, referrer, browser/device information and HTTP status. Processing is necessary to provide a secure and reliable website and is based on Article 6(1)(f) GDPR. Server logs are retained only for as long as required for operations, security and abuse investigation.

    3. Customer account and sign-in

    If sign-in is enabled, we process contact and profile data, internal user identifiers, and authentication/session data. When you sign in with Google, we receive the basic profile data you authorise. Processing is based on Article 6(1)(b) GDPR where needed to prepare or perform a rental contract, and otherwise on Article 6(1)(f) GDPR for secure account administration.

    4. Booking requests and vehicle rental

    For booking requests and rental contracts, we process the required identity, contact, driver, licence, booking, vehicle, pricing, payment-status and communication data. Where the booking flow requires it, we also process uploaded identity or driving-licence documents. Processing is based on Article 6(1)(b) GDPR. Legally required evidence and retention are based on Article 6(1)(c); fraud prevention, claims and fleet/operational security on Article 6(1)(f).

    • We do not request documents that are not required.
    • Documents are access-controlled and available only to authorised staff for review.
    • The notices shown in the booking flow about required fields, documents and retention also apply.

    5. Contact form and customer service

    When you contact us, we process your name, email address, subject, message and technical security data to answer the request and prevent abuse. The legal basis is Article 6(1)(b) GDPR for pre-contractual or contractual enquiries and otherwise Article 6(1)(f). Messages are delivered to the internally configured responsible team through our email provider.

    6. Payments

    Available payment methods and instructions are displayed during booking. We process payment status, amounts, references and required accounting information. Full bank-account access credentials or card credentials are not collected through the contact form. Processing is based on Article 6(1)(b) and (c) GDPR.

    7. Recipients and processors

    Depending on the enabled production configuration, we use service providers for hosting, database operation, private file storage, authentication and email delivery. These may include Vercel (hosting and private file storage) and Google (optional sign-in and transactional email through Gmail or Google Workspace). Providers receive only the data necessary for their task and are bound as processors under Article 28 GDPR where required. Authorities, courts, insurers or professional advisers receive data only where legally permitted or necessary to establish, exercise or defend claims.

    8. International transfers

    Some providers may process data outside the European Economic Area, particularly in the United States. In that case, we rely on an applicable adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses and assess supplementary safeguards.

    9. Cookies and local storage

    We use only technically necessary cookies or comparable storage, particularly for secure sign-in, session management, language and protection features. They are required for services requested by you (section 25(2)(2) TDDDG). We currently use no marketing or profiling cookies. If optional technologies are added later, we will obtain consent beforehand.

    10. Retention

    We keep personal data only as long as necessary for its purpose. Contact enquiries are normally deleted no later than twelve months after final resolution unless they relate to a contract or dispute. Account data is retained until the account is deleted. Booking, contract and accounting data is retained for applicable statutory commercial and tax periods. Data required for legal claims may be retained until the relevant limitation periods expire. Uploaded documents follow the purpose-specific deletion periods disclosed in the booking flow.

    11. Your rights

    Subject to the GDPR, you may request access, rectification, erasure, restriction and portability. You may object, on grounds relating to your situation, to processing based on Article 6(1)(f). Consent can be withdrawn at any time for the future. You may also lodge a complaint with a data protection supervisory authority, particularly where you live, work or where an alleged infringement occurred.

    12. Required data and automated decisions

    Data marked as required must be provided so that we can assess a booking request and perform a rental contract. Without it, the service may not be possible. We do not make decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR.

    13. Security and updates

    We use appropriate technical and organisational safeguards, including access limitation, encrypted transmission, private document storage and logging of security-relevant operations. We update this notice when processing, providers or legal bases materially change.