- Home
- Privacy policy
Privacy policy
This page says what we do with the personal data that reaches us through the uitdesk.ro website and the UITDesk application. No pointers to other documents, no wording you cannot parse.
1. Who is responsible for the data
The controller is HRFINANCETOP SRL, VAT code 49180397, Trade Register J40/22392/2023, registered office at str. Constantin Apostol nr. 16B, bl. C4C5, ap. 305, sector 6, Bucharest, Romania.
Write to contact@uitdesk.ro or call +40 727 524 502. For anything concerning your data, email is the best route: it leaves a record and we can answer you in writing.
We are not legally required to appoint a data protection officer and have not appointed one. Requests are handled by the company’s management.
Two different roles — keep them apart:
- For data on the website — the contact and order forms, cookies — we are the controller.
- For the data you enter in the application (companies, partners, vehicles, goods, declarations, your people’s accounts) you are the controller and we are only a processor: we process it to make the application work, on your instructions, and for nothing else. The details are in the application’s terms.
2. What data, why, on what basis, for how long
| Category of data | Why | Legal basis (GDPR) | How long |
|---|---|---|---|
| Order form: name, email, phone; company name, VAT code, trade register number, address; chosen plan | To issue the proforma, open the account, invoice you | Art. 6(1)(b) — performance of the contract and pre-contractual steps | 10 years from the end of the financial year (accounting obligation) |
| Invoices and payment records | Tax and accounting obligation | Art. 6(1)(c) — legal obligation | 10 years |
| Contact form: name, email, phone, company, subject, message | To answer your question | Art. 6(1)(f) — our legitimate interest in replying to someone who writes to us | 2 years from the last message |
| Application account: name, email, role, activity journal | To run the account; the journal shows who did what | Art. 6(1)(b) | for the life of the account, then 90 days; the journal is never rewritten |
| Traffic data and analytics cookies (see below) | To understand which pages are useful | Art. 6(1)(a) — your consent | see the Cookie policy |
| Message sent through the WhatsApp button | To reply on the channel you chose | Art. 6(1)(f) | 2 years in our records |
Order data is stored in a file on the website’s server and, at the same time, emailed to contact@uitdesk.ro. The file on the server is not publicly accessible.
We never ask you for a personal identification number, card details or copies of ID documents. We do not process special categories of data. We take no automated decisions affecting you and we do no profiling.
The fields marked in the forms are the ones we need in order to serve you. Without them the order cannot be processed. The rest are optional.
3. Who receives the data
We sell data to nobody and pass it on to nobody for someone else’s advertising. It reaches only the providers we need in order to operate, and the authorities the law obliges us to inform.
| Who | What they do | Where |
|---|---|---|
| Hostinger | hosts the uitdesk.ro website and the email |
European Union |
| Hetzner | hosts the app.uitdesk.ro application and the database |
Falkenstein, Germany (EU) |
| ANAF | receives the transport declarations; a separate controller, acting under its own legal powers | Romania |
| Google (Analytics 4) | traffic statistics — only if you consented | USA / EU |
| Meta (pixel, WhatsApp) | advertising measurement — only if you consented; WhatsApp, if you use the chat button | USA / EU |
| Accountant and bank | invoices and payments | Romania |
Every provider processing data for us is bound by contract to the same confidentiality and security obligations.
We may also give data to authorities — tax administration, courts, police — but only when the law requires it, and only as much as it requires.
4. Transfers outside the European Union
The site and the application sit on servers inside the European Union. There is no transfer there.
Google and Meta may transfer data to the United States. This happens only if you accepted their cookies. Both rely on the Standard Contractual Clauses approved by the European Commission and on the EU–US Data Privacy Framework. If you do not want that transfer, refuse the cookies — the rest of the site works exactly the same.
The WhatsApp button opens the WhatsApp app on your device. The message leaves from your own account to our number; Meta processes it under its own rules, which we do not control. If you would rather not go through Meta, email us instead.
5. Your rights
Over your data you have the right to:
- access — find out what data we hold about you and receive a copy;
- rectification — have wrong or incomplete data corrected;
- erasure — the “right to be forgotten”, where we have no legal reason left to keep it;
- restriction — have processing paused while something is being checked;
- portability — receive your data in a format you can take elsewhere;
- objection — object to processing based on legitimate interest;
- withdraw consent at any time, for cookies and analytics — through “Cookie settings” in the site footer. Withdrawal does not affect what was lawfully processed before it.
You exercise them by writing to contact@uitdesk.ro. We answer within 30 days at the latest, the period set by the Regulation. If a request is complex, we tell you within that period how much longer we need. There is no charge.
So that we do not hand your data to someone pretending to be you, we may ask you to confirm who you are — usually a reply from the email address we have on file.
Some of these rights the application gives you directly: you export your records, take a copy of the database, and withdraw your account from the account menu.
6. Complaint to the supervisory authority
If you think we have not respected your rights, tell us first — it is usually a misunderstanding that clears up quickly.
You always have the right, though, to complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): B-dul G-ral. Gheorghe Magheru nr. 28–30, sector 1, Bucharest, anspdcp.ro, anspdcp@dataprotection.ro. You may also go to court.
7. How we keep the data safe
- The connection to the site and the application is encrypted (HTTPS), with security headers set at the server.
- Secrets — passwords, ANAF tokens, the email server password — are encrypted in the database and never shown on screen.
- The digital certificate password is never saved anywhere: it is asked for at every submission.
- Account passwords are stored through a one-way function; not even we can read them.
- Access is granted by role and by company; the application journal shows who did what and is never rewritten.
- Backups run daily and are verified by restoring them — a backup you discover is broken exactly when you need it is not a backup.
No system is perfectly secure. If a security breach puts your data at risk, we notify ANSPDCP within 72 hours and notify you as well, where the law requires it.
8. Minors
The service is aimed at companies. It is not aimed at people under 16 and we do not knowingly collect their data. If you learn that a minor has left us data, write to us and we will delete it.
9. Changes
This policy changes when what we do changes. We update the date above at every change. If the change is significant — a new purpose, a new recipient — we tell you by email or through a message in the application, before it takes effect.
See also the Terms and conditions and the Cookie policy.
