GDPR Information & Commitment Notice
Last updated: 20 July 2026
S.C. CRONOXY SOFT SOLUTIONS S.R.L., as a software development services provider, is committed to complying with Regulation (EU) 2016/679 (GDPR) and Romanian data protection law. This notice sets out our roles, the principles we apply, our commitments and the rights of data subjects. It complements the Privacy Policy.
1. Who we are and our roles
The operator is S.C. CRONOXY SOFT SOLUTIONS S.R.L., and in relation to personal data we have two roles:
- Controller — for data processed for our own purposes (visitors, offer requesters, relationship with clients and partners, recruitment, billing, security);
- Processor — for personal data we process within projects, on behalf of and per the instructions of our Client, who is the controller of that data.
2. Data protection contact
For any data protection matter you can contact us at office@cronoxy.ro.
3. The principles we uphold
We process data in accordance with the GDPR principles:
- lawfulness, fairness and transparency;
- purpose limitation — we collect data for specified, legitimate purposes;
- data minimization;
- accuracy — we keep data correct and up to date;
- storage limitation — we keep data only as long as necessary;
- integrity and confidentiality — we protect data with appropriate measures;
- accountability — we can demonstrate compliance.
4. Our compliance commitment
To achieve and maintain GDPR compliance:
- we keep records of processing activities;
- we apply data protection by design and by default in the solutions we build;
- we sign data processing agreements (DPAs) with clients and with our sub-processors;
- we assess risks and carry out impact assessments (DPIAs) where appropriate;
- we train staff and limit data access on a need-to-know basis;
- we handle data subject rights requests;
- we have procedures to detect, report and investigate security incidents.
5. Data processing agreement (DPA) for clients
When we process data on behalf of the Client (for example when we develop, integrate or maintain software solutions that contain the Client's data), we do so exclusively on their documented instructions, under a processing agreement compliant with Art. 28 GDPR, which includes:
- the subject matter, duration, nature and purpose of the processing;
- the confidentiality obligation of personnel;
- the security measures implemented;
- the conditions for using sub-processors;
- assistance to the Client for handling data subject rights and incident notifications;
- deletion or return of data upon completion of the project.
- The DPA is available to clients on request, at office@cronoxy.ro.
6. Sub-processors
We use third-party providers (sub-processors) for hosting and cloud infrastructure, IT and collaboration tools, e-mail, payments and accounting, analytics, as well as subcontractors for delivering projects. They are contractually bound to uphold at least the same level of protection. An up-to-date list of sub-processors is available on request.
7. International transfers
If certain data is processed outside the European Economic Area, we ensure appropriate safeguards, typically the standard contractual clauses approved by the European Commission, together with supplementary measures where needed.
8. Data subject rights
Data subjects have the rights provided by the GDPR: access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and the right not to be subject to a decision based solely on automated processing with significant effects.
Requests can be sent to us at office@cronoxy.ro and we generally resolve them within 30 days. For data processed on behalf of a Client, the request is addressed to the Client-controller, whom we assist under the DPA.
9. Data security
We apply appropriate technical and organizational measures: encryption in transit and, where applicable, at rest; access control; logging; backups; environment separation; vendor assessment; staff training.
10. Security incidents
We have incident management procedures. When acting as controller, we notify the supervisory authority within 72 hours of becoming aware, if there is a risk to individuals' rights, and inform data subjects when the risk is high. When acting as processor, we notify the Client-controller without undue delay.
11. Contact and supervisory authority
For questions or to exercise your rights: office@cronoxy.ro.
You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) — 28-30 G-ral. Gheorghe Magheru Blvd., District 1, postcode 010336, Bucharest; e-mail: anspdcp@dataprotection.ro; phone: +40.318.059.211; web: dataprotection.ro.
12. Updates
We may update this notice as legislation or compliance practice evolves. The applicable version is the one published on the website, with the last-updated date shown above.
