Privacy Policy
Last updated: September 17, 2026
Operator (controller of personal data): S.C. RODALEX C.S. S.R.L.
Version 1.0.
CHAPTER I — GENERAL PROVISIONS
Article 1 — Introduction
1.1. This Privacy Policy establishes the manner in which S.C. RODALEX C.S. S.R.L., in its capacity as Operator of the „to you." Platform, collects, uses, stores and protects the personal data of users.
1.2. Respect for private life and the protection of personal data are a priority for the Operator. All processing of data is carried out in compliance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation and the security of the data.
1.3. This Policy applies to all persons who use the „to you." Platform, whether they act as Client or as Professional.
Article 2 — The Operator of personal data
2.1. The Operator of personal data is:
- S.C. RODALEX C.S. S.R.L., a Romanian legal person;
- registered office: Iași, str. Teascului nr. 77, Iași County, Romania;
- registered with the Trade Register Office under no. J2025069464002;
- unique registration code: 52501616;
- legally represented by its administrator.
2.2. The Operator determines the purposes and the means of the processing of personal data collected through the „to you." Platform.
2.3. The Operator's contact address for any matter concerning the processing of personal data is [email protected]. The complete contact details are set out in Article 52 and are published in the application and on the official website of the Platform.
Article 3 — Scope
3.1. This Policy applies to all data processing activities carried out through the „to you." Platform, in all the forms in which it is made available to users:
- a) the „to you." mobile application for iOS and Android;
- b) the web application available at
app.toyou.ro; -
c) the
toyou.rowebsite, which comprises the presentation pages, the legal pages and the public profiles of Professionals.
3.2. In the web application referred to in paragraph 3.1 letter b), authentication is provided by Firebase Authentication, a service which keeps the user's session in the local memory of the browser, and the confirmation of the telephone number is carried out through an invisible reCAPTCHA mechanism provided by Google. In the mobile application, the confirmation of the telephone number is carried out through the native component of the same service, without reCAPTCHA.
3.3. The Policy applies both to Clients and to Professionals who use the Platform.
3.4. The use of the Platform entails the processing of certain personal data necessary for the functioning of the application and for the provision of the intermediation services.
3.5. The minimum age for creating an account on the „to you." Platform is 16 years, pursuant to Article 8 of Regulation (EU) 2016/679 (GDPR) and Article 2(3) of Law no. 190/2018. Persons who have not reached the age of 16 may not create an account and may not use the Platform.
3.6. The rule set out in paragraph 3.5 is a condition of use of the Platform. The Platform does not request the date of birth and does not apply a technical age verification. The Operator deletes the account which it finds to belong to a person who has not reached the age of 16. A parent or guardian may report such a situation at the address set out in Article 52.
3.7. The use of cookies and similar technologies on the toyou.ro website is
governed by the Cookie Policy, which supplements this
Policy.
Article 4 — Definitions
For the purposes of this Policy:
- Operator — S.C. RODALEX C.S. S.R.L.;
- Platform — the „to you." mobile application for iOS and Android, the
app.toyou.roweb application and thetoyou.rowebsite; - Client — the person who uses the Platform in order to identify a Professional and to make an appointment;
- Professional — the authorised natural person, the sole trader, the family enterprise, the company or another entity which offers services through the Platform;
- Personal data — any information relating to an identified or identifiable natural person, in accordance with Regulation (EU) 2016/679 (GDPR);
- Biometric data — data resulting from specific processing techniques relating to the physical characteristics of a natural person, which allow or confirm the unique identification of that person, within the meaning of Article 4(14) GDPR;
- Processing — any operation performed upon personal data, such as the collection, recording, organisation, storage, use, transmission or erasure of that data;
- Processor — the natural or legal person which processes personal data on behalf of the Operator, within the meaning of Article 4(8) GDPR.
Article 5 — The principles of data processing
The Operator processes personal data in accordance with the following principles:
- a) lawfulness, fairness and transparency;
- b) the collection of data only for specified, explicit and legitimate purposes;
- c) the processing exclusively of the data necessary for the functioning of the Platform;
- d) the keeping of the data in a form which permits the identification of persons only for the period necessary;
- e) ensuring the integrity and confidentiality of the data through appropriate technical and organisational measures.
Article 6 — Applicable legislation
This Policy is drawn up in accordance with:
- Regulation (EU) 2016/679 on the protection of personal data (GDPR);
- Law no. 190/2018 on implementing measures for Regulation (EU) 2016/679;
- the other national legal acts applicable in the field of data protection;
- other legal acts applicable to the activity of the „to you." Platform.
Article 7 — Acceptance of the Privacy Policy
7.1. By creating an account and using the „to you." Platform, the user confirms that he or she has taken note of this Privacy Policy.
7.2. This Policy is to be read together with the Terms and Conditions of use, the two supplementing each other.
7.3. Where the Privacy Policy is amended, users are informed through the Platform, under the conditions provided by law and in Article 50.
CHAPTER II — THE PERSONAL DATA COLLECTED AND THE MANNER OF COLLECTION
Article 8 — Categories of personal data
8.1. The „to you." Platform processes only the personal data necessary for the functioning of the application and for the provision of the intermediation services between Clients and Professionals.
8.2. The data collected differs according to the category of user and to the functionalities used within the Platform.
Article 9 — Data collected from Clients
9.1. Upon the creation and the use of the Client account, the Platform collects:
- the displayed name, as well as the first name and the surname provided upon registration;
- the email address;
- the telephone number of the account and the moment at which it was confirmed by SMS;
- the account identifier in the authentication service and the role of the account;
- the notification preferences;
- the evidence of the consents given upon registration: what was accepted, the date of acceptance and the version of the document in force at that moment;
- the appointments made, their history and the moment of any cancellation;
- the messages sent through the messaging system and the photographs attached to them;
- the ratings given and received, expressed exclusively as a value from 1 to 5;
- the counters on the basis of which the displayed rating is calculated: the number of ratings received, their sum and the number of late cancellations;
- the posts published, their photographs and the likes given and received;
- the reports submitted and the blocks applied;
- the saved addresses, together with their geographic coordinates;
- the technical data set out in Article 11.
9.2. The Operator does not store the account password, in any form. Authentication is delegated entirely to the Firebase Authentication service, provided by Google. The Operator's database does not contain a password column, and the password is reset exclusively through that service.
9.3. The Operator does not collect bank card or bank account data. The payment of Professionals' subscriptions is processed by the provider set out in Article 27, and the Operator receives only the confirmation of the payment and the transaction identifiers.
Article 10 — Data collected from Professionals
10.1. The Professional account comprises the data set out in Article 9. For the creation and the administration of the professional profile, the Platform additionally collects:
- the publicly displayed name;
- the city in which the services are offered and its geographic coordinates;
- the description of the activity;
- the public contact number;
- the profile photograph and the published photographs;
- the service categories offered;
- the status of the profile and, where applicable, the reason for its rejection or restriction;
- the subscription information: the plan, the status, the period and the transaction identifiers with the payment processor.
10.2. The Operator does not collect from Professionals invoicing data, unique registration code, company name, professional seat, correspondence address or working hours. The interval within which appointments may be made is a single rule of the Platform, not a schedule established by each Professional.
10.3. For the verification of the Professional's identity, provided as a condition in Article 15, the following are processed:
- the image of the identity document, front and back;
- the portrait taken from the identity document;
- the liveness check photograph, carried out within the provider's flow, by which it is confirmed that a living person is in front of the camera;
- the result of the face match between the portrait on the identity document and the liveness check photograph, expressed as a score from 0 to 100, together with the liveness score, the method used and the age estimation;
- the full name, the series of the document and its expiry date;
- the personal numeric code.
10.4. The liveness check photograph and the face match set out in paragraph 10.3 constitute processing of biometric data for the purpose of uniquely identifying a natural person, that is, a special category of data within the meaning of Article 9(1) GDPR. The analysis is carried out by the provider set out in Article 27, and the Operator determines the purpose of the processing, requests the face match and receives the result, including the two images, in order for it to be assessed by its authorised personnel. In respect of this processing as well, S.C. RODALEX C.S. S.R.L. holds the capacity of Operator within the meaning of Article 4(7) GDPR. The purpose, the legal basis, the consequences of refusal and the manner of withdrawing consent are set out in Article 17 and in Article 21.
10.5. The Operator does not store the images and the biometric data set out in paragraph 10.3. They are made available by the identity verification provider, through temporary addresses, exclusively for display to the authorised personnel of the Operator who take the decision. From the verification, only the full name, the series of the document, its expiry date, the identifier of the verification session and the result of that session remain stored in the Operator's systems.
10.6. The personal numeric code is processed without being stored. It is displayed to the authorised personnel for the duration of the verification, for comparison with the personal numeric code written on the qualification documents. Only the result of the comparison is stored, in the form “matches”, “does not match” or “does not appear on the document”. The processing of the personal numeric code is carried out under the conditions of Article 4 of Law no. 190/2018.
10.7. For the verification of qualifications, the Professional may upload photographs of diplomas, certificates or attestations. The Operator stores the photograph, its digital fingerprint, the result of the verification and, in the event of rejection, the reason for it. The photographs are deleted within the period set out in Article 32.
Article 11 — Data collected automatically
11.1. During the use of the Platform, the following information is collected automatically, for the functioning and the security of the application:
- device identifiers;
- the version of the application;
- the operating system;
- the IP address;
- technical logs concerning the functioning of the application;
- information concerning technical errors and the performance of the application.
11.2. This data is used for the administration of the Platform, the prevention of fraud, the improvement of performance and the security of the services.
11.3. The notification token of the device is not collected automatically. It is obtained only after the notification permission has been granted from the operating system of the device.
11.4. The precise location of the device is not collected automatically. It is processed only after the permission has been granted from the operating system, exclusively while the application is open and exclusively for searching for Professionals within the radius chosen by the user and for establishing the place of a post. The Operator does not request permission to access location in the background. Geographic coordinates are stored on the addresses saved by the user, on posts and on the profiles of Professionals.
Article 12 — Data provided through the use of the Platform
12.1. Users may voluntarily provide additional information by:
- completing the profile;
- sending messages and photographs in conversations;
- uploading photographs to the profile and in posts;
- publishing posts;
- submitting reports;
- contacting the support service.
12.2. The ratings given through the Platform are exclusively values from 1 to 5. The Platform does not allow ratings with free text and does not allow photographs to be attached to a rating.
12.3. Photographs sent in conversations are stored in a public space, at an address with a name which is impossible to guess, and are served with a browser cache lifetime of one year. The conversation remains private and cannot be read by other persons; however, a photograph may be opened, without an account, by any person who comes into possession of its direct address.
12.4. Messages which are the subject of a report remain in the conversation and are not deleted. By way of exception, where the account of either of the participants is deleted, including where the deletion of the account is ordered as a moderation measure, the conversation is deleted in its entirety, together with the messages contained in it and the reports concerning it.
12.5. Users are responsible for the accuracy and the lawfulness of the information which they choose to publish or to transmit through the Platform.
Article 13 — The sources of the data
13.1. Personal data is obtained:
- directly from users, upon the creation and the use of the account;
- through the use of the functionalities of the Platform;
- from the documents uploaded by Professionals for the verification of identity or of qualifications;
- from the identity verification provider, in the form of the result of the verification set out in Article 10;
- from the interactions of users with the Platform.
13.2. The Operator does not collect data from third-party sources without a legal basis or without informing the data subject, where the law requires this.
Article 14 — The accuracy of the data
14.1. Users have the obligation to provide correct, complete and up-to-date data.
14.2. Where personal data changes, users are encouraged to update the information in their account without delay.
14.3. The provision of false or inaccurate data may affect the functioning of the account and, in the cases provided for by the Terms and Conditions of the Platform, may lead to the suspension or the limitation of access.
Article 15 — The mandatory nature of the provision of data
15.1. The provision of the data set out in this Article is mandatory, within the meaning of Article 13(2)(e) GDPR, for the purposes indicated.
15.2. The email address and the displayed name are necessary for the creation of the account. In their absence the account cannot be created.
15.3. The confirmation of the telephone number by SMS is mandatory before the identity verification begins. The verification request is rejected for as long as the telephone number is not confirmed.
15.4. Identity verification and an active subscription are conditions for the visibility of the Professional in searches and for the publication of posts in that capacity. In the absence of either of them, the account remains functional as a Client account.
15.5. The location permission is optional. In its absence, searching by radius and the establishment of the place of a post do not work.
15.6. The other data — the description of the activity, the profile photograph, the published photographs and the qualification documents — is optional. Its absence does not limit access to the Platform.
CHAPTER III — THE PURPOSES AND THE LEGAL BASES OF THE PROCESSING OF PERSONAL DATA
Article 16 — The purposes of the processing
16.1. The Operator processes personal data exclusively for specified, explicit and legitimate purposes, necessary for the functioning of the „to you." Platform and for the provision of its services.
16.2. Personal data is processed for the following purposes:
- a) the creation and the administration of user accounts;
- b) the identification of users and authentication in the Platform;
- c) the confirmation of the telephone number of the account;
- d) the display of the profiles of Professionals;
- e) the facilitation of appointments between Clients and Professionals;
- f) communication through the messaging system integrated in the Platform;
- g) the verification of the identity of Professionals;
- h) the verification of the qualifications declared by Professionals;
- i) the management of the subscriptions of Professionals and the issuance of the related fiscal documents;
- j) the sending of notifications concerning the use of the Platform;
- k) the sending of commercial communications, under the conditions of Article 21;
- l) the moderation of content, the resolution of reports, of requests and of complaints, as well as the fulfilment of the obligations incumbent upon the Operator in its capacity as provider of intermediary services;
- m) ensuring the security of the Platform and preventing fraudulent use;
- n) the improvement of the functionalities of the application and of the user experience;
- o) the compilation of usage statistics for the
toyou.rowebsite; - p) compliance with the legal obligations incumbent upon the Operator;
- q) the establishment, the exercise or the defence of a legal claim.
Article 17 — The legal bases of the processing
17.1. The processing of personal data is carried out in accordance with Article 6 of Regulation (EU) 2016/679 (GDPR).
17.2. Depending on the situation, the processing may be based on one or more of the following bases:
- the performance of the contract or the taking of the steps necessary prior to its conclusion;
- compliance with a legal obligation of the Operator;
- the legitimate interest of the Operator, where it is not overridden by the rights and freedoms of the data subject;
- the consent of the user, where this is required by law.
17.3. The processing of the biometric data set out in Article 10, paragraphs 10.3 and 10.4, is based on the explicit consent of the Professional, given under the conditions of Article 9(2)(a) GDPR, exclusively for the purpose of confirming that the person who applies for the capacity of Professional is the person identified by the identity document presented.
17.4. The basis set out in paragraph 17.3 is added to the bases provided for in Article 6(1)(b) and (f) GDPR, which cover the other operations of the identity verification, and does not replace them. The conditions under which consent is requested and withdrawn are set out in Article 21.
Article 18 — Performance of the contract
18.1. The majority of the processing carried out through the „to you." Platform is necessary for the provision of the services requested by users, on the basis of Article 6(1)(b) GDPR.
18.2. For this purpose, the Operator processes data for:
- the creation and the administration of the account;
- the management of the user's profile;
- the facilitation of appointments and communication through the messaging system;
- the verification of the identity and of the qualifications of Professionals;
- the sending of notifications concerning the use of the Platform;
- the administration of the subscriptions of Professionals.
Article 19 — Compliance with legal obligations
19.1. The Operator processes personal data in order to comply with the obligations imposed by the applicable legislation, including in the fiscal and accounting fields, in the field of data protection, of information security and of the obligations incumbent upon providers of intermediary services, on the basis of Article 6(1)(c) GDPR.
19.2. Data may be communicated to the competent authorities where this is provided for by law.
Article 20 — Legitimate interest
20.1. The Operator processes certain data on the basis of legitimate interest, pursuant to Article 6(1)(f) GDPR, to the extent that such processing is necessary and does not disproportionately affect the rights and freedoms of users.
20.2. Such processing operations are:
- the prevention of fraud and of false accounts;
- ensuring the security of the application, including through the automatic caps set out in Article 24;
- the investigation of technical incidents;
- the moderation of content and the resolution of reports;
- the improvement of the functioning of the Platform;
- the defence of the rights of the Operator in the event of disputes.
Article 21 — The consent of the user
21.1. Where the law requires that consent be obtained, the Operator requests the agreement of the user before the processing is carried out.
21.2. Explicit consent for the processing of the biometric data set out in Article 10 is requested separately, on a dedicated screen, before the identity verification begins, and concerns exclusively the purpose set out in Article 17, paragraph 17.3. This consent is not comprised in the acceptance of the Terms and Conditions or of this Policy.
21.3. The refusal of the consent set out in paragraph 21.2 has as a consequence the impossibility of verifying the identity and, in the absence of the verification, the impossibility of being visible as a Professional in searches and of publishing posts in that capacity. The account remains functional as a Client account, without any other limitation.
21.4. Commercial communications, including personalised recommendations, are sent only on the basis of consent given separately, pursuant to Article 6(1)(a) GDPR. Consent is disabled by default; in the absence of it being given, no commercial communication is sent. Notifications related to the functioning of the service — the confirmation of an appointment, the receipt of a message, a change in the status of the account — do not constitute commercial communications and are sent on the basis set out in Article 18.
21.5. Consent for commercial communications is withdrawn from the application, from Setări → Notificări (Settings → Notifications), or by a request sent to the address set out in Article 52. The withdrawal takes effect immediately, and the evidence of the consent is deleted.
21.6. The consent set out in paragraph 21.2 is withdrawn by a request sent to the address set out in Article 52 or by the deletion of the account. Following the withdrawal, the capacity of verified Professional ceases, and the data retained from the identity document is deleted.
21.7. Consent may be withdrawn at any time, without affecting the lawfulness of the processing carried out prior to its withdrawal, pursuant to Article 7(3) GDPR.
21.8. The withdrawal of consent does not affect the processing operations based on other legal bases provided for by the GDPR.
21.9. The usage statistics for the toyou.ro website are collected only on the basis
of the consent expressed through the cookie banner, under the conditions set out in the
Cookie Policy.
Article 22 — Purpose limitation
22.1. Personal data is not used for purposes other than those for which it was collected, save in the situations permitted by law.
22.2. Where the Operator intends to use the data for a different purpose, users are informed beforehand, under the conditions provided by the applicable legislation.
Article 23 — Data minimisation
23.1. The Operator collects and processes only the data strictly necessary for the achievement of the declared purposes.
23.2. The Platform is designed so as to limit the collection of data to the information necessary for the functioning of the application and for the provision of the intermediation services.
Article 24 — Automated processing and automated decisions
24.1. The Operator does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning the user or which similarly affect him or her to a significant extent, within the meaning of Article 22 GDPR.
24.2. The verdicts concerning identity verification, the verification of qualifications and moderation measures are taken by the authorised personnel of the Operator. The author of each decision remains recorded in the system.
24.3. The following processing operations are carried out automatically and produce effects upon the user:
- a) the displayed rating is calculated automatically, as the average of the ratings received, from which 0.05 is subtracted for each late cancellation made by the user, with a minimum threshold of 1.0, the result being truncated to one decimal place. The penalty applies to the user who made the cancellation and applies identically to Clients and to Professionals;
- b) the subscriptions of Professionals expire automatically at the end of the contracted period;
- c) appointments end automatically upon the passing of the interval for which they were established;
- d) the starting of an identity verification is limited automatically to one request every 10 minutes and to no more than 5 requests in 24 hours.
24.4. The user may contest the result of a processing operation set out in paragraph 24.3 by a request sent to the address set out in Article 52.
CHAPTER IV — THE RECIPIENTS OF PERSONAL DATA
Article 25 — General principles
25.1. S.C. RODALEX C.S. S.R.L. treats all personal data as confidential and does not sell it, does not rent it and does not make it available to third parties for commercial purposes.
25.2. Data may be communicated only in the situations provided by law or where this is necessary for the functioning of the „to you." Platform and for the provision of the services offered through it.
25.3. Any transmission of data is carried out in compliance with Regulation (EU) 2016/679 (GDPR) and with appropriate security measures.
Article 26 — Data visible in the Platform
26.1. In order to permit the use of the Platform, the following information from the profile of the Professional is displayed publicly:
- the displayed name;
- the profile photograph;
- the description of the activity;
- the service categories offered;
- the city in which the services are provided;
- the posts published and their photographs;
- the displayed rating, from 1 to 5, and the number of ratings received.
26.2. The profiles of Professionals and their posts
are public on the internet: they may be opened without an account, from the
toyou.ro website, and may be indexed by search engines.
26.3. The public contact number of the Professional is displayed to any authenticated user who opens the profile or a post of that Professional, if the WhatsApp contact option is active. The option is active by default on every new profile and is deactivated from the settings of the profile; from the moment of deactivation, the number is no longer transmitted. The public contact number is not transmitted to unauthenticated visitors.
26.4. The personal data of Clients is not displayed publicly and is accessible only to the extent necessary for carrying out the appointment and for communication with the Professional.
26.5. The telephone number of the account, set out in Article 9, is not published and is distinct from the public contact number of the Professional.
Article 27 — Service providers
27.1. For the functioning of the Platform, the Operator works with the providers listed below, in the capacity of processors. They process the data exclusively on the basis of the instructions of the Operator, under contracts concluded pursuant to Article 28 GDPR. The list is complete as at the date of this version.
| Provider | Purpose of the processing | Data transmitted | Place of processing | Basis of the transfer |
|---|---|---|---|---|
| Google — Firebase Authentication | Authentication of accounts | Email address, password, Google identity, account identifier | EU / USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Google — Firebase Phone Auth | Confirmation of the telephone number by SMS; reCAPTCHA in the web application | Telephone number | EU / USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Google Cloud (Run, SQL, Storage, Tasks, Scheduler) | Hosting of the application and of the database | All stored data | European Union, region europe-west1 | Storage without transfer; support from the USA on the basis of the framework or of the clauses above |
| Didit Identity Spain, S.L. | Identity verification of Professionals | Identity document, portrait, liveness check photograph, biometric data, personal numeric code | Spain (EU) | No transfer outside the European Economic Area |
| Stripe | Processing of payments for the subscriptions of Professionals | Payment data, customer identifier and transaction identifier | EU / USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Resend | Sending of emails | Email address, name, content of the message | USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Expo — push notifications | Delivery of notifications to the device | Device token, content of the notification | USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Expo — EAS Build | Compilation of the application | Does not receive personal data of users | USA | No personal data is transferred |
| Sentry | Reporting of errors in the application | Technical error data, internal identifier of the account | USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Google Maps | Maps and geocoding | Geographic coordinates | EU / USA | EU-US Data Privacy Framework and/or standard contractual clauses |
| Cloudflare | Hosting of the website and delivery of content | Traffic data, IP address | USA, with a global network | EU-US Data Privacy Framework and/or standard contractual clauses |
| Google Analytics 4 |
Usage statistics, exclusively on the toyou.ro website and only with consent
| Pseudonymised usage identifiers | EU / USA | EU-US Data Privacy Framework and/or standard contractual clauses |
27.2. The contracting entity of the identity verification provider, for users from the European Union and from the European Economic Area, is Didit Identity Spain, S.L., with its registered office in Barcelona, Spain, which operates the European data plan of the provider.
27.3. The usage statistics service operates exclusively on the toyou.ro website and
only after consent has been expressed through the cookie banner. It is not present in the mobile
application, nor in the app.toyou.ro web application. The complete conditions are
set out in the Cookie Policy.
27.4. The obligations of processors and the basis of transfers outside the European Economic Area are set out in Article 47 and in Article 48.
Article 28 — Public authorities
28.1. Personal data may be communicated to public authorities or to competent institutions where:
- there is a legal obligation;
- the communication is necessary for the defence of the rights of the Operator;
- it is requested within judicial or administrative proceedings;
- it is necessary for the prevention or the investigation of unlawful acts.
28.2. The communication of data is carried out only within the limits provided by law.
Article 29 — Communication between users
29.1. For the carrying out of appointments and the provision of services, certain contact details are made available to the parties involved.
29.2. The Professional receives the information necessary for carrying out the appointment, and the Client has access to the public information of the Professional, set out in Article 26.
29.3. The data communicated through the messaging system of the Platform must be used exclusively in connection with the services requested through „to you.".
Article 30 — Transfer of data to third parties
30.1. The Operator does not transfer personal data to third parties for marketing purposes.
30.2. No advertising networks are integrated in the Platform and no instruments for tracking users for advertising purposes are used.
30.3. The services which involve the processing of data by processors are carried out only under contracts which ensure compliance with the requirements of the GDPR.
Article 31 — Confidentiality of the data
31.1. All persons who have access to personal data within the activity of the Platform have the obligation to observe the confidentiality of that data. Internal access to data is limited to the authorised personnel of the Operator.
31.2. The Operator adopts appropriate technical and organisational measures for the prevention of unauthorised access to, loss of, alteration of or unauthorised disclosure of the data.
CHAPTER V — THE DATA STORAGE PERIOD AND THE RIGHTS OF DATA SUBJECTS
SECTION I — THE DATA STORAGE PERIOD
Article 32 — The data storage period
32.1. The Operator keeps personal data only for the period necessary for the fulfilment of the purposes for which it was collected, as well as for the periods imposed by the applicable legislation.
32.2. The storage period varies according to the nature of the data, to the category of user and to the applicable legal obligations.
32.3. The storage periods are the following:
| Category of data | Storage period |
|---|---|
| The photographs of the qualification documents, uploaded for verification | 60 days from the date of the verdict, after which they are deleted automatically. The result of the verification is retained. |
| The record of the notifications sent | 90 days, after which it is deleted automatically. |
| The record of the notifications which could not be delivered | Retained until the deletion of the account. |
| The subscription data and the transaction identifiers | The periods imposed by the accounting and fiscal legislation of Romania, including after the deletion of the account. |
| The appointments and the ratings from 1 to 5 given and received | Retained after the deletion of the account as well, attached to the anonymised row, under the conditions set out in Article 34 paragraph 34.5 letters e) and f). |
| The other data of the account: messages, posts, saved addresses, the telephone number, the data retained from the identity document | Until the deletion of the account. |
32.4. Save for the periods set out in paragraph 32.3, the data of the account is not subject to automatic deletion on the criterion of age.
32.5. Upon the expiry of the retention period, the data is deleted, anonymised or archived, as the case may be, in accordance with the legislation in force.
Article 33 — Criteria used for establishing the storage period
In establishing the period for which the data is kept, the Operator takes into account:
- the purpose for which the data was collected;
- the legal obligations concerning archiving and accounting records;
- the existence of disputes or complaints;
- the necessity of defending the rights and legitimate interests of the Operator;
- the obligations imposed by the competent authorities.
Article 34 — Deletion of the data
34.1. The user may delete his or her account directly from the application, from Setări → Ștergerea contului (Settings → Account deletion). The deletion is carried out immediately, is definitive, cannot be reversed and is not conditional upon the agreement of the Operator.
34.2. A user who no longer has the application installed or who can no longer authenticate may request the deletion of the account at the address set out in Article 52, from the email address of the account. In that case, the Operator replies and carries out the request within one month at the latest from its receipt, pursuant to Article 12(3) GDPR. The detailed steps are set out in the page concerning account deletion.
34.3. The deletion is carried out by anonymisation: the row of the account remains in the database, emptied of the data which identifies the person. The email address is emptied, the displayed name becomes „Cont șters" (Account deleted), the link with the authentication service is removed, and the account in that service is deleted. Any failure of the latter deletion does not halt the deletion of the other data and is recorded, with a view to subsequent remedy; signing in to the deleted account is not possible in either case.
34.4. The following are effectively deleted:
- the telephone number of the account, together with the date of its confirmation;
- the saved addresses, together with their coordinates;
- the likes given;
- the notifications and the notification tokens of the devices;
- the blocks applied by the user and those applied by other users upon the account;
- the reports submitted by the user;
- the private conversations of the user, in both directions, together with the messages and the photographs contained in them and the reports concerning them;
- in the case of Professionals: the public profile, the posts, all the photographs, including the qualification documents, as well as the data retained from the identity document.
34.5. The following remain attached to the anonymised row:
- a) the record of payments, if a subscription existed;
- b) the results of the verification of the qualification documents, without the document itself;
- c) the reports submitted by other users concerning that account;
- d) the record of the moderation measures, together with their reasons;
- e) the ratings from 1 to 5 given and received, which remain in both directions, including in the account of the person rated;
- f) the appointments, which are not deleted. Those confirmed whose start time has not yet passed are cancelled, and the remainder stay in the status in which they were; there remain attached to the anonymised row the start time and the end time, the title of the service, its category and its price, as well as the address, under the conditions set out in the page concerning the deletion of the account;
- g) an anonymous row comprising the role of the account and the date of its creation.
34.6. The record of the identity verification session, kept by the provider set out in Article 27, is not deleted together with the account, that record being subject to the retention policy of the provider. At the request of the user submitted while the account still exists, the Operator forwards the request for deletion to the provider. Following the deletion of the account, the request can no longer be forwarded: the identifier of the session is deleted together with the other data retained from the identity document, and in its absence the session can no longer be identified with the provider.
34.7. The deletion of the account at the request of the user does not entail the blocking of the email address. A new account may be created at any time with the same address. The blocking of an address, kept in the form of a digital fingerprint, applies exclusively in the case of the deletion of an account ordered by the Operator as a moderation measure.
34.8. In certain situations, the Operator may be obliged to keep certain data in order to comply with legal obligations or to defend its rights within judicial or administrative proceedings.
34.9. In the case of a Professional who holds a subscription, the deletion of the account entails the termination of the subscription with the payment processor. The termination takes effect immediately, and not upon the expiry of the period paid for, and the period paid for and not used is not refunded. The record of payments is retained, pursuant to paragraph 34.5(a), and the details are set out in the page concerning account deletion.
SECTION II — THE RIGHTS OF DATA SUBJECTS
Article 35 — The right to be informed
35.1. Users have the right to receive clear and transparent information concerning the manner in which their personal data is processed.
35.2. This Privacy Policy has the role of providing that information in a manner which is accessible and easy to understand.
Article 36 — The right of access
36.1. Users have the right to request confirmation of the fact that their data is being processed.
36.2. Upon request, the Operator provides a copy of the personal data processed, under the conditions provided by law and within the limits in which the disclosure does not affect the rights and freedoms of other persons.
Article 37 — The right to rectification
37.1. Users have the right to request the correction of inaccurate data or the completion of incomplete data.
37.2. The majority of the data in the account may be corrected directly from the application. For the remainder, the Operator updates the data within a reasonable period, after verification of the request.
Article 38 — The right to erasure (“the right to be forgotten”)
38.1. Users may request the erasure of personal data under the conditions provided by the GDPR. The deletion of the account may be exercised directly from the application, under the conditions set out in Article 34.
38.2. The right to erasure is not absolute and may be limited where the retention of the data is necessary for compliance with a legal obligation, for the establishment, the exercise or the defence of a legal claim or in other situations provided by law. The data which remains after the deletion of the account is set out in Article 34, paragraph 34.5.
Article 39 — The right to restriction of processing
39.1. Users may request the restriction of the processing of the data in the cases provided by the GDPR.
39.2. For the duration of the restriction, the Operator may store the data, but processes it only under the conditions permitted by law.
Article 40 — The right to data portability
40.1. Where the conditions provided by the GDPR are met, users may request the transmission of their data in a structured, commonly used and machine-readable format.
40.2. This right applies only to the processing carried out by automated means and based on consent or on the performance of a contract.
Article 41 — The right to object
41.1. Users have the right to object to the processing of the data in the situations provided by law, including to the processing based on the legitimate interest of the Operator, set out in Article 20.
41.2. The Operator ceases the processing, save where it demonstrates the existence of compelling legitimate grounds which override the interests, the rights and the freedoms of the data subject or where the processing is necessary for the establishment, the exercise or the defence of a legal claim.
Article 42 — The right to lodge a complaint
42.1. If a user considers that his or her rights concerning the protection of data have been infringed, that user has the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP), whose contact details are set out in Article 53.
42.2. The exercise of this right does not limit the possibility of the user of also applying to the competent courts, under the conditions of the law.
CHAPTER VI — DATA SECURITY AND THE TRANSFER OF PERSONAL DATA
Article 43 — Data security
43.1. S.C. RODALEX C.S. S.R.L. adopts appropriate technical and organisational measures for the protection of personal data against unauthorised access, loss, destruction, alteration or accidental or unlawful disclosure.
43.2. The security measures are reviewed periodically and adapted according to technological developments, the risks identified and the applicable legal requirements.
43.3. The Operator ensures a level of security appropriate to the risks associated with the processing of the data.
Article 44 — Technical and organisational measures
44.1. For the protection of personal data, the Operator applies the following measures:
- the authentication of users through a specialised service, the Operator not holding their passwords;
- the encryption of communications between the application, the servers and the providers;
- the limitation of access to data to the authorised personnel of the Operator;
- the recording of the moderation measures together with their author;
- automatic caps on sensitive operations, set out in Article 24;
- the non-storage of the images and of the biometric data of the identity verification, as well as of the personal numeric code, pursuant to Article 10;
- the automatic deletion of the photographs of the qualification documents, within the period set out in Article 32;
- backups carried out periodically;
- the storage of the data on infrastructure located in the European Union;
- the updating of the information systems and of the application;
- measures for the prevention and the detection of unauthorised access.
44.2. No security measure can guarantee the absolute protection of data.
Article 45 — The obligations of users concerning security
45.1. Users are responsible for keeping their authentication data confidential and for the safe use of their account.
45.2. Users undertake:
- not to disclose the password of the account;
- to use strong passwords and not to reuse them on other services;
- to inform the Operator immediately if they suspect unauthorised access to the account;
- to log out from devices used in common, where applicable;
- not to transmit through the messaging system data which is not necessary for the conversation, having regard to the manner of storage of photographs set out in Article 12, paragraph 12.3.
45.3. The Operator does not hold the passwords of users and does not request them in any circumstances. The Operator is not liable for the damage caused by the voluntary disclosure of the authentication data by the user or by the failure to observe the obligations set out in this Article.
Article 46 — Security incidents
46.1. In the event of a security incident which affects personal data, the Operator analyses the situation and adopts the measures necessary for limiting its effects.
46.2. The Operator notifies the supervisory authority within 72 hours at the latest from the date on which it becomes aware of a personal data breach, pursuant to Article 33 GDPR.
46.3. Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Operator informs them directly, pursuant to Article 34 GDPR.
Article 47 — Transfer of the data
47.1. The infrastructure on which the data of the Platform is stored is located on the territory of the European Union.
47.2. Some of the providers set out in Article 27 are companies from the United States of America or have support access from the United States. The data transmitted to them is the subject of a transfer outside the European Economic Area.
47.3. The transfers set out in paragraph 47.2 are carried out on the basis of the EU-US Data Privacy Framework, on the basis of the adequacy decision of the European Commission of 10 July 2023, for the providers certified under it, and/or on the basis of the standard contractual clauses adopted by the European Commission, accompanied by supplementary measures. The basis applicable to each provider is indicated in the table in Article 27.
47.4. The user may obtain a copy of the applicable safeguards by a request sent to the address set out in Article 52.
Article 48 — Processors
48.1. The providers set out in Article 27 hold the capacity of processors of the Operator.
48.2. They process the data only on the basis of the instructions of the Operator and under the conditions of the contracts concluded with them, in compliance with the obligations imposed by Article 28 GDPR.
48.3. The Operator does not authorise the use of the data by processors for their own purposes.
Article 49 — Review of the security measures
49.1. The Operator reserves the right to update and to improve the security measures whenever this is necessary for the protection of the Platform and of the data of users.
49.2. The review of the security measures may be carried out as a result of technological developments, of legislative changes or of the identification of new risks.
CHAPTER VII — AMENDMENT OF THE PRIVACY POLICY, CONTACT AND FINAL PROVISIONS
Article 50 — Amendment of the Privacy Policy
50.1. S.C. RODALEX C.S. S.R.L. reserves the right to amend or to supplement this Privacy Policy whenever this is necessary for:
- compliance with legislative changes;
- the implementation of new functionalities of the „to you." Platform;
- the improvement of the services offered;
- adaptation to technological or organisational changes.
50.2. The updated version of the Privacy Policy is published in the „to you." application and on the official website of the Platform. The version in force is the one published, and the date of the last update is displayed at the beginning of this page.
50.3. In the case of significant changes — a new category of data, a new purpose or an amended legal basis — users are informed by notification in the application and, where applicable, by email, before the change takes effect.
50.4. Where the change concerns a processing operation based on consent, the Operator requests new consent.
Article 51 — Exercise of the rights
51.1. Users may exercise the rights provided by Regulation (EU) 2016/679 (GDPR) by sending a request to the address set out in Article 52.
51.2. Requests must contain sufficient information for the identification of the data subject and of the right which is sought to be exercised. The Operator may request additional information in order to confirm the identity of the applicant. The Operator does not request the password of the account and does not request photographs of the identity document for the resolution of a request based on the GDPR.
51.3. The Operator replies to requests within one month at the latest from their receipt, pursuant to Article 12(3) GDPR. That period may be extended by two months for complex or numerous requests, in which case the data subject is informed within the first month, with an indication of the reasons.
51.4. The exercise of the rights is free of charge, save in the situations in which the requests are manifestly unfounded or excessive, in particular because of their repetitive character, in which case the Operator may charge a reasonable fee or may refuse to act upon the request, pursuant to Article 12(5) GDPR. The refusal is reasoned and indicates the means of contesting it.
Article 52 — Contact details
52.1. For questions concerning this Privacy Policy and for the exercise of the rights provided by the GDPR, the Operator may be contacted:
- S.C. RODALEX C.S. S.R.L.;
- registered office: Iași, str. Teascului nr. 77, Iași County, Romania;
- email: [email protected].
52.2. Your data is the responsibility of the administrator of the company, and the address above is the only point of contact for any request related to it. You do not need a form and you do not need a reason.
Article 53 — The supervisory authority
53.1. The competent supervisory authority is:
- the National Supervisory Authority for Personal Data Processing (ANSPDCP);
- B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest, Romania;
- email: [email protected];
- website: www.dataprotection.ro.
53.2. If a user considers that the processing of his or her personal data infringes the applicable legislation, that user has the right to lodge a complaint with the authority set out in paragraph 53.1.
53.3. The exercise of this right is without prejudice to the right of the user to apply to the competent courts, under the conditions of the law.
Article 54 — Final provisions
54.1. This Privacy Policy supplements the Terms and Conditions of use of the „to you." Platform and the Cookie Policy and is to be interpreted together with them.
54.2. In the event that one of the provisions of this Policy is declared null or inapplicable, the remaining provisions remain valid and continue to produce effects.
54.3. This Policy enters into force on the date of its publication in the „to you." Platform and remains applicable until it is replaced by an updated version.
FINAL PROVISION
This Privacy Policy governs the manner in which S.C. RODALEX C.S. S.R.L., in its capacity as Operator of the „to you." Platform, processes the personal data of users.
The Operator undertakes to observe the right of users to private life and to process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and with the applicable legislation of Romania.
The „to you." Platform has as its purpose the facilitation of the connection between Clients and Professionals, and the processing of personal data is carried out exclusively to the extent necessary for the functioning of the application, the administration of accounts, the management of appointments and the fulfilment of legal obligations.