Privacy Policy
Last updated: 02.07.2026
Techarus Technology S.R.L., headquartered at Timis Street No. 39, Room 1, Staircase C, Apt. 26, Giroc Village, Giroc Commune, Timis County (Registration No. J35/673/15.02.2023; Tax ID: 47639451) (hereinafter referred to as the „Controller”), collects and processes personal data in accordance with Regulation (EU) 2016/679 (GDPR). For any inquiries regarding your data, you may contact us at apticodev@gmail.com
1. Legal Entity Data and B2B Representatives
As our service is primarily intended for professionals and legal entities, we collect your company’s tax details (name, tax identification number, registered office address) strictly as necessary for issuing invoices and fulfilling the commercial contract.
At the same time, we process the personal data of legal representatives or employees designated to manage the account (full name, professional email address, phone number, job title). The processing of this data is based on our legitimate interest in facilitating inter-organizational communication, providing technical support, and ensuring the optimal performance of the SaaS contract concluded with the organization you represent.
2. Registration and Authentication Data
To create and securely maintain your user account, we automatically collect essential information such as your email address, name, interface configuration preferences, and settings history.
Additionally, for strict security reasons and to prevent unauthorized access to your account, we automatically record activity logs that include the IP address used for connection, browser type, device used, and the date and time of successful or failed login attempts. This technical data is processed based on our legitimate interest in ensuring the platform's cybersecurity.
3. Billing and Payment Information
To ensure the highest level of financial security, transactions are processed exclusively through specialized third-party electronic payment providers (payment gateways) that are PCI-DSS certified.
We do not collect, view, or store any bank card data, transaction history, or invoices on our servers. All such information is managed directly by Stripe and is accessible to the user via our platform through a link to the Stripe portal. Invoices are available on the Stripe platform and are not sent by us via email.
4. Data Storage Location and Sovereignty
We are committed to protecting the privacy of your data in accordance with European standards. Production data and backups are stored exclusively on ultra-secure servers physically located within the European Union / European Economic Area (EEA).
In cases where it is strictly necessary to work with technical service providers (sub-processors) that maintain infrastructure outside the EEA (e.g., the United States), we ensure that data transfers are lawful and rigorously protected through mechanisms approved by the European Commission, such as the use of Standard Contractual Clauses (SCCs) and the implementation of additional encryption measures.
5. Data Retention Policy
We store your personal information and data generated within the application for as long as your account remains active, in order to provide the service to you.
Upon a request to close your account, the data will enter a 30-day grace period (necessary to prevent accidental deletion and resolve any potential financial disputes). After this period expires, the data will be irreversibly deleted from our production databases. Certain analytical data may be retained, but it will be fully anonymized (meaning it can no longer be linked to you) and used exclusively for statistical purposes.6. Usage Analysis and Product Optimization
To understand how the platform is used and to develop relevant new features, we use product analytics tools that monitor your interactions with the interface (e.g., most frequently used modules, system errors encountered, session duration).
These tools help us identify bottlenecks and optimize the user experience (UI/UX). The data collected for this purpose is, to the extent possible, pseudonymized or aggregated, and the legal basis for this processing is our legitimate interest in continuously improving the software we provide.7. Your Rights Under GDPR (Regulation 679/2016)
As a data subject, the General Data Protection Regulation (GDPR) grants you fundamental and inalienable rights regarding your personal data:
- Right of access: You have the right to obtain confirmation of whether we process your data and, if so, to receive a copy along with detailed information about the purpose and manner of processing.
- Right to rectification: You may request correction of inaccurate personal data or completion of incomplete data.
- Right to erasure ('Right to be forgotten'): You may request permanent deletion of data when it is no longer necessary for the purposes collected, when consent is withdrawn, or when processing was unlawful. (Note: this right is not absolute and may be limited by our legal retention obligations, such as archiving invoices for accounting purposes).
- Right to restriction of processing: You may request temporary blocking of data processing (we will store but not use it) in specific cases, such as while contesting data accuracy.
- Right to data portability: You have the right to receive data you provided to us in a structured, commonly used, machine-readable format, or request direct transfer to another data controller of your choice.
- Right to object: You may object absolutely and at any time to data processing for direct marketing purposes (including profiling) or processing based on legitimate interest, for reasons related to your particular situation.
- Right regarding automated decision-making: You have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or significantly affects you.
To exercise any of these rights free of charge, please send a written, dated, and clearly formulated request to: apticodev@gmail.com. We commit to investigating the request and providing an official response within a maximum of 30 days from receipt of the valid request.
8. Contact, Complaints, and Supervisory Authority (ANSPDCP)
We make constant efforts and invest in security technologies to ensure the highest level of data protection. If you have questions, concerns, or complaints regarding how we have collected or processed your personal data, we encourage you to contact us first at apticodev@gmail.com. We guarantee a transparent approach and a prompt attempt at amicable resolution.
If, following our efforts, you still believe your GDPR rights have been violated and are unsatisfied with our response, you have the inalienable legal right to file a formal complaint with the competent state authority in Romania:
Autoritatea Naional de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP)
Address: B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336, Bucharest, Romania
Phone: +40.318.059.211 or +40.318.059.212
Email: anspdcp@dataprotection.ro
Online complaint platform: www.dataprotection.ro
9. Sub-Processors
For the operation of aptico.ro, we use the following third-party service providers:
- Clerk, Inc. — Authentication and user management (USA, SCC)
- Stripe, Inc. — Payment processing (USA, SCC, PCI-DSS)
- Hetzner GmbH — Server infrastructure and hosting (Germany, EU)
Data Processing Agreement (DPA)
This Agreement is an integral part of the Terms and Conditions of Use on aptico.ro and governs the conditions under which the Controller processes data through its processors, in accordance with Regulation (EU) 2016/679 (GDPR).
Parties:
- Controller: Techarus Technology S.R.L., a company registered under Romanian law, based in Sat Giroc, Comuna Giroc, Strada Timis, Nr 39, Camera 1, Scara C, Ap. 26, Judet Timis, registered at the Trade Registry under no. J35/673/15.02.2023, CUI 47639451, contact: apticodev@gmail.com.
- Processors: Third-party service providers used for the operation of aptico.ro and service delivery.
1. Object and Duration of Processing: The Processor shall process personal data only on behalf of and according to the Controller's instructions, for the duration of the main contract or commercial collaboration.
2. Nature and Purpose of Processing: Processing is carried out for the purpose of providing the services requested on aptico.ro (e.g., order processing, hosting, customer support).
3. Technical and Organizational Measures: The Controller ensures all processors implement appropriate security measures, including: data encryption in transit and at rest, role-based access control (RBAC), and periodic security audits.
4. Data Location: Production data and backups are stored exclusively on ultra-secure servers physically located within the EU/EEA. Where sub-processors have infrastructure outside the EEA, transfers are protected through Standard Contractual Clauses (SCC) and additional encryption measures.
5. Data Subject Rights: Processors will assist the Controller in fulfilling obligations to respond to requests regarding data subject rights. For any GDPR-related requests, clients may contact the Controller at apticodev@gmail.com.
6. Security Breach Notification: In the event of a security incident, the Processor will notify the Controller without undue delay, to allow Techarus Technology S.R.L. to report to the supervisory authority (ANSPDCP) within 72 hours, in accordance with applicable law.
We reserve the right to review and update this Privacy Policy periodically, to faithfully reflect potential legislative changes, modifications to our internal practices, or the introduction of new platform features. Any substantial change will be brought to your attention by displaying a visible notice on the site or through direct email communication, before the new provisions come into effect.