Privacy Policy
Last updated: January 2024 · In compliance with Regulation (EU) 2016/679 (GDPR)
Data we collect
We collect personal data only when necessary to provide our services and in accordance with GDPR (EU Regulation 2016/679). Collection occurs in the context of:
- Orders, quote requests and inquiries about products and services
- Account registration on the Customer Portal platform
- Submission of an application for a job vacancy
- Technical support or post-implementation assistance requests
- Subscription to commercial communications (newsletter, webinars, events)
Directly provided data
First and last name, email address, phone number, company name, job title, billing address.
Automatically collected data
IP address, browser type, operating system, pages visited, time of visit, session duration, traffic source.
How we use your data
We use collected data solely for the purposes for which they were provided, based on a valid legal basis under GDPR (contract, consent, legitimate interest or legal obligation).
Order and contract processing
Fulfilling orders, issuing invoices, managing license contracts and subscriptions.
Technical support and assistance
Diagnosing and resolving issues, software updates, communication about planned outages.
Commercial communications and marketing
Sending offers, product news, webinar and event invitations — only with your explicit consent.
Research and service improvement
Anonymized usage behavior analysis to optimize software platforms and user experience.
Data sharing with third parties
We do not sell, rent or lease your personal data to third parties for commercial purposes.
We may share personal data with service providers acting as associated processors or processors on our behalf, exclusively for the purpose of providing contracted services:
- Cloud infrastructure and web hosting providers (secure servers in the EU)
- Email marketing platforms used for communications you have subscribed to
- Analytics tool providers (anonymized data)
- Accountants, auditors or legal advisors — when necessary for legal compliance
All service providers are carefully selected and contractually obligated to maintain data confidentiality and GDPR requirements. We may disclose data to competent authorities when required by law or to prevent fraud.
Your rights (GDPR)
As a data subject, you benefit from all rights conferred by the General Data Protection Regulation (GDPR). You may exercise these rights at any time, free of charge, by contacting our Data Protection Officer.
Right of access
You may request a copy of the personal data we hold about you.
Right to rectification
You may request correction of inaccurate data or completion of incomplete data.
Right to erasure
You may request deletion of personal data (right to be forgotten), under conditions provided by GDPR.
Right to portability
You may request your data in a structured, usable and machine-readable format.
Withdrawal of consent
You may withdraw consent at any time without affecting the legality of prior processing.
Right to object
You may object to processing for direct marketing purposes or based on legitimate interest.
To exercise any of these rights, contact our Data Protection Officer at: rosistem@rosistem.com. We respond within 30 calendar days.
Data security
The security of your data is a priority. We implement appropriate technical, physical and administrative measures to protect data against unauthorized access, disclosure, alteration or destruction.
Technical
TLS/SSL encryption, two-factor authentication, activity monitoring, automatic backup.
Physical
Servers in certified data centers, card-based restricted access, surveillance cameras.
Administrative
Internal security policies, employee training, confidentiality agreements, periodic audits.
In the event of a security incident affecting your data, we will notify you in accordance with GDPR obligations, within 72 hours of discovery, if the incident presents a high risk to your rights and freedoms.
Minors
Rosistem services are intended exclusively for B2B users — companies, organizations and adult professionals. We do not intentionally collect personal data from individuals under 18 years of age.
If you are a parent or legal guardian and have reason to believe that a minor in your care has provided us with personal data without your consent, please contact us immediately at rosistem@rosistem.com. We will promptly delete this data from our systems.
Data Protection Officer (DPO)
ROSISTEM.ro S.R.L.
București, Sector 1, Str. Surorilor, Nr. 30,
Camera Nr. 1, Lot 1, Etaj 2, Ap. 8 – 012476
VAT: RO15117808 · ID: J2003000157406
EUID: ROONRC.J2003000157406
D-U-N-S: 684329126
Do you have questions about how we process your data or want to exercise your GDPR rights?