Privacy Policy
Last updated: 20 July 2026
Your data privacy is important to us. This policy explains what personal data S.C. CRONOXY SOFT SOLUTIONS S.R.L. processes through the cronoxy.ro website and in the course of its software development services, for what purposes, on what legal basis, and what your rights are, in accordance with Regulation (EU) 2016/679 (GDPR).
1. The data controller
The cronoxy.ro website and the Cronoxy services are operated by S.C. CRONOXY SOFT SOLUTIONS S.R.L. (hereinafter „Cronoxy”, „we” or „the Operator”).
Identification details:
- Company name: S.C. CRONOXY SOFT SOLUTIONS S.R.L.
- Sole registration code (CUI): 34790877
- Trade Register no.: J33/1059/2020
- Contact e-mail: office@cronoxy.ro
2. Our roles: controller and processor
We act as controller for data we process for our own purposes (website visitors, offer/contact requesters, managing the relationship with clients and partners, billing, recruitment, security).
We act as processor when, within a project, we process personal data on behalf of the Client — for example when we develop, integrate, test or maintain software solutions that contain the Client's data. In this case the Client is the controller of that data and the processing is governed by the data processing agreement (DPA).
3. Data protection contact
For any data protection matter you can contact us at office@cronoxy.ro.
4. What data we process and about whom
We process data about the following categories of people:
- Website visitors and offer/contact requesters — name, company, e-mail and, optionally, phone and the message or request submitted;
- Contact persons and representatives of clients and partners — name, role, professional contact details, for the business relationship and projects;
- Job applicants — CV and recruitment-process data, when you apply to Cronoxy;
- Personal data processed within projects, on behalf of the Client — the data contained in the Client's systems, databases or materials that we access in order to develop, integrate, test or maintain the software solutions; we process it as a processor, per the Client's instructions;
- Technical data — IP address, browser/device type, pages visited — for the operation and security of the website;
- Billing data — for clients, in accordance with legal obligations.
5. Sources of the data
We collect data: directly from you (forms, communications, job applications); automatically, through use of the website (technical data, logs); from our Clients (data processed within projects, on their behalf); and from partners or public sources, to the extent needed for the business relationship.
6. Purposes and legal bases of processing
- To respond to offer/contact requests — legitimate interest and pre-contractual steps (Art. 6(1)(b) and (f) GDPR);
- To provide the Services and carry out projects — performance of the contract (Art. 6(1)(b));
- To process data within projects, on behalf of the Client — as processor, based on the Client's instructions (the controller sets the legal basis);
- For recruitment — pre-contractual steps and legitimate interest (Art. 6(1)(b)/(f)); with consent to keep your application for future opportunities;
- For website security and abuse prevention — legitimate interest (Art. 6(1)(f));
- For commercial communications — consent or legitimate interest, with the right to object (Art. 6(1)(a)/(f));
- To comply with legal obligations (e.g. tax, accounting) — legal obligation (Art. 6(1)(c)).
7. Automated decisions
We do not make decisions based solely on automated processing that produce legal or similarly significant effects on you through the website.
If a project involves automated processing or artificial-intelligence components in the solutions we build for a Client, this is carried out on behalf of and under the control of the Client-controller, per its instructions.
8. Cookies
The website uses cookies as described in the Cookie Policy. Cookies that are not strictly necessary are used only with your consent.
9. Who we share data with (categories of processors)
We do not sell personal data. We may disclose it to providers who support us, acting as processors, under contracts that ensure data protection:
- hosting and cloud infrastructure providers;
- IT, collaboration, communication and project-management tools;
- e-mail and communications providers;
- payment processors, accounting services and professional advisers;
- subcontractors and collaborators involved in delivering projects, under confidentiality obligations;
- analytics and monitoring tools;
- public authorities, when required by law.
- The list of sub-processors used for data processed on behalf of a Client is available on request and within the data processing agreement (DPA).
10. International transfers
Some providers may process data outside the European Economic Area. In such cases we ensure appropriate safeguards — typically the standard contractual clauses approved by the European Commission — and, where necessary, supplementary protection measures.
11. How long we keep the data
We keep data only as long as necessary for the described purposes:
- contact/offer form data — for the duration of handling the request and any resulting business relationship;
- project data — for the duration of the project and per the Project Agreement and the DPA;
- applicant data — for the duration of the recruitment process and, with consent, a reasonable period afterwards;
- accounting and tax data — per statutory retention periods (usually 10 years);
- afterwards, data is securely deleted or anonymized.
12. Your rights
Under the GDPR, you have the following rights:
- the right of access to your data;
- the right to rectification;
- the right to erasure („the right to be forgotten”);
- the right to restriction of processing;
- the right to data portability;
- the right to object;
- the right not to be subject to an automated decision with significant effects;
- the right to withdraw your consent at any time, without affecting the lawfulness of prior processing.
13. How to exercise your rights
You can exercise your rights by writing to us at office@cronoxy.ro. We may request additional information to verify your identity. We generally respond within 30 days, a period that may be extended, with justification, for complex requests.
If the data concerns you and is processed by us as a processor within a Client's project, the request is generally addressed to that Client as controller; we can direct you to them.
14. Data security
We apply appropriate technical and organizational measures to protect data against unauthorized access, loss, alteration or disclosure: encryption in transit and, where applicable, at rest; access control on a need-to-know basis; logging; backups; vendor assessment; staff training.
15. Security incidents
In the event of a data breach posing a risk to individuals' rights, we will notify the supervisory authority and, where appropriate, the data subjects, within the timeframes set by the GDPR. When acting as processor, we notify the Client-controller without undue delay.
16. Commercial communications
We may send you commercial communications only based on consent or, for services similar to those contracted, based on legitimate interest. You can unsubscribe at any time via the mechanism indicated in the message or by writing to us.
17. Minors
The Services and the website are intended for professional use and are not directed at persons under 16. We do not knowingly collect minors' data.
18. Changes to this policy
We may update this policy. The applicable version is the one published on the website, with the last-updated date shown above.
19. Contact and supervisory authority
To exercise your rights or for any question about your data, write to us at office@cronoxy.ro.
You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) — 28-30 G-ral. Gheorghe Magheru Blvd., District 1, postcode 010336, Bucharest; e-mail: anspdcp@dataprotection.ro; phone: +40.318.059.211; web: dataprotection.ro.
