Privacy Policy
Effective Date: January 1, 2025
Graphenerobots SRL, headquartered at Calea Someș 30, processes the personal data of its partners and clients exclusively for the purposes of technical consultancy, implementation of automation systems, and contractual communication. This policy describes the types of data collected, the legal basis for processing, the rights of data subjects, and the security measures implemented.
Data Collected and Purpose of Processing
We collect only the data strictly necessary for conducting contractual relationships and industrial automation services: first name, last name, job title, email address, phone number, company name, billing information, and technical specifications of the equipment in question. The processing is based on the performance of the contract, the legitimate interest of Graphenerobots to provide quality services, and, where applicable, explicit consent for technical promotional communications.
- Identification and contact data (name, email, phone) – for operational communication and technical support.
- Contractual and technical data (assembly line specifications, production parameters) – for design and implementation.
- Billing data (Company Registration Number, tax address) – for issuing financial documents.
- Browsing data (IP address, browser type, pages visited) – for platform optimization and access security.
Legal Basis and Storage Duration
We process data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian legislation. Storage occurs for the duration of the contract and subsequently for the period required by legal archiving obligations (accounting, taxation), but no more than 5 years from the end of the contractual relationship, except where the law provides for a longer term.
- Performance of the contract – the main basis for all operational data.
- Legitimate interest – for technical communications and service improvement.
- Consent – for newsletters and promotional materials specific to automation.
- Legal obligation – for billing and tax reporting data.
Rights of the Data Subject
Any natural person whose data is processed by Graphenerobots has the following rights, which they can exercise by a written request to the email address info@graphenerobots.com or at the headquarters on Calea Someș 30.
- Right of access – you can request confirmation of processing and a copy of the data.
- Right to rectification – you can correct inaccurate or incomplete data.
- Right to erasure – you can request the deletion of data, except where the law requires retention.
- Right to restriction – you can limit processing in certain situations.
- Right to data portability – you can receive the data in a structured format.
- Right to object – you can object to processing based on legitimate interest.
- Right to lodge a complaint – with the National Supervisory Authority for Personal Data Processing.
Data Security and Transfers
Graphenerobots implements appropriate technical and organizational measures to protect data against unauthorized access, loss, or destruction: SSL/TLS encryption for transmissions, role-based access control, storage on secure servers within the European Union, and periodic system audits. We do not transfer personal data to third countries without adequate safeguards. Our partners (IT service providers, consultants) are contractually obligated to adhere to the same standards.
- End-to-end encryption for all electronic communications.
- Restricted access to data only for authorized employees.
- Storage on infrastructure located exclusively within the EEA.
- Annual internal audit and periodic security testing.