Data Room SRL
Romania · Bucharest
English translation

Privacy policy

We respect your privacy.

Server Room complies with all Romanian and European regulations and laws on the protection of personal data. Each Server Room user is in control of their data. Server Room does not make use of it freely. Personal data is dealt with transparently, confidentially and securely. Server Room is engaged in a continuous process of protecting the data of its users, in accordance with Regulation (EU) 2016/679 on data protection of 27 April 2016 (hereinafter "GDPR") and with Law no. 190/2018 on measures implementing it.

Our fundamental principles:

  • We ask only for the personal information we need for the purposes described in this policy;
  • We do not sell your personal information. We disclose it only to the recipients listed under Recipients of the data;
  • In particular, we do not publish any of the information that you provide us with, including the websites that you create with Data Room SRL;
  • In accordance with articles 15, 16 and 17 of the GDPR, you have the right to access, rectify and erase data concerning yourself. You can exercise this right by contacting our support team or by addressing a letter to our head office.

Data Room SRL manages the services serverroom.net and reserves the right to create other services. With all of its services, Data Room SRL is committed to applying the same privacy policy.

Visitors

Like the majority of websites, Data Room SRL records information such as the IP address, browser type, language preference, source site, the pages requested and the date and time of each visit in its server logs. These logs are used to operate and secure the website, and to measure, in aggregate, how each page performs: how visitors find it, whether it leads to an order, and which of two wordings of a page works better while we test them. For these statistics the IP address and browser are turned into a salted one-way code. Separately, for a visit that reaches us from an advertisement or a campaign link, we keep a record of the visit (the IP address, the pages opened and for how long, the search terms where the advertising platform gives them, whether the visit led to a chat, the creation of an account, a login or a payment and, for a visitor who signed in, the customer number) and assess how engaged it was, to judge our advertising and to choose which visits we report to the advertising platform. These records are kept for at most 90 days from the visit. We do not sell this information or pass it to advertising or analytics companies, with one exception: a click on one of our advertisements that leads to a visit in which the site is really used, to the creation of an account or to a first payment is reported to the advertising platform it came from, as we show below, under recipients. Nothing is stored on your device for this purpose. The server logs are kept for three years.

Relevance of data

In order to best follow the interest of Server Room's prospects and customers, the file collects all information of visitors of the website serverroom.net relating to their identity and professional information. We do not ask you, for our own purposes, for information about racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health or sexual life (special categories of data, article 9 of the GDPR). Where an identity check is needed, our verification provider compares a photo of your face with your identity document. What you store on a server or write to our support is your own choice.

Lawfulness of processing and conditions of consent (art. 6 and art. 7 of the GDPR)

We process personal data on different grounds, depending on the purpose:

  • to create your account, provide the services you order, bill you and answer your requests: performance of the contract (art. 6(1)(b) of the GDPR) or, where you act for a company that is our customer, our legitimate interest in providing the service to it (art. 6(1)(f));
  • for invoices, accounting and tax records, and to answer requests from authorities: a legal obligation (art. 6(1)(c));
  • for the security of the services, the prevention of fraud and abuse, server logs, improving the services and measuring the results of our advertising (the report to the advertising platform of a click that led to a visit in which the site was really used, to an account or to a first payment): our legitimate interest (art. 6(1)(f)); you can object to this processing at any time (art. 21);
  • for a newsletter and other messages you asked for: your consent (art. 6(1)(a)), which you can withdraw at any time without the withdrawal affecting the processing up to then.

Accepting the terms and conditions is not consent to advertising.

Data retention

We keep personal data for the purposes described in this policy:

  • Your account, services, orders, invoices and payments, the messages you send us (support tickets, emails, live chat and the transcripts of phone calls) and the records of your requests to the dashboard and API: we do not delete these automatically. We keep them so that we have the history of your services, of what we provided and of the payments, and we delete them when you ask us to (see Individual rights). Financial and accounting documents, including invoices and payment records, are kept in any case for at least five years, counted from 1 July of the year following the end of the financial year, as accounting law requires (Accounting Law no. 82/1991, art. 25).
  • Our websites' server logs: three years.
  • Records of payment attempts with our payment processors: one year.
  • Records of calls answered by our voice assistant: one year. The working records of our automated chat assistant: 30 days.

When you ask us to delete your personal data, we delete it, except what the law requires us to keep and what is needed to establish, exercise or defend a right in court.

Your rights (art. 12-22 of the GDPR)

In accordance with the GDPR, all individuals can exercise their right of access, rectification, objection, restriction of processing, erasure and portability of the data concerning them, by an email to support@serverroom.net, preferably sent from the email address of your account, or by a letter to the registered office of Data Room SRL. We ask for further information to confirm your identity only if we have reasonable doubts about it (art. 12(6) of the GDPR).

You can object at any time to the use of your data for direct marketing, and we then stop using it for that purpose. You can also object to other processing based on our legitimate interest; we then stop, unless we have compelling legitimate grounds that the law accepts.

You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), www.dataprotection.ro, or with the supervisory authority of the member state where you live.

Recipients of the data

We do not sell your personal data. We disclose it only as far as the purposes of this policy require, to:

  • the affiliated company Data Room, Inc. (USA), with which we share the site serverroom.net and the ordering, billing and support systems;
  • the payment processors you pay through (for example Stripe or PayPal);
  • identity verification and fraud prevention providers (for example Sumsub or Stripe Identity), where a check is needed;
  • email and communications providers (for example Google), including WhatsApp, if you write to us there;
  • the artificial intelligence providers that process support messages for our automated assistant (for example Anthropic and OpenAI);
  • advertising platforms (Google, LinkedIn, Reddit and X): when a click on one of our advertisements leads to a visit in which the site is really used, to the creation of an account or to a first payment, we report an event to the platform the click came from, to measure our advertising and to help the platform's bidding. The report holds the identifier the platform itself attached to the click, which can let it connect the event to the person who clicked; the time; the platform's conversion action under which the event is filed; a code we generate for the event, which does not show your account or customer number; and, where one is sent, a value and its currency. Reddit also receives the address of our site's home page. Except for account creations reported to Google, which have an action of their own, these reports are filed under the platform's purchase action and do not show which of the three kinds of event took place. For a visit or an account creation, the value, where one is sent, is an estimate we assign to help the platform's bidding, not an amount paid. We send them no email addresses, phone numbers or other contact details, and no lists of customers;
  • the data centers, network operators and telephony providers our services run on;
  • our accountants, auditors and legal advisers, who act under their own professional duties;
  • courts, authorities and other persons, where a judgment or another valid legal procedure requires it, or where it is necessary to bring or answer a claim in court.

Some of these recipients are outside the European Economic Area, in particular in the USA.

Data security and processing (art. 32 of the GDPR)

The data collected on the website serverroom.net and the associated processing are hosted by the company Data Room SRL. Only persons linked to the technical, marketing and commercial departments of Data Room SRL and its subcontractors have access to the information collected on the website serverroom.net, through a personal and unique identifier for the Server Room platform.

Data breach and communication within 72 hours (art. 33 and art. 34 of the GDPR)

In the event of a breach of the security of personal data for which we are the controller, we notify the National Supervisory Authority for Personal Data Processing (ANSPDCP) without undue delay and, where feasible, within 72 hours at most of the date on which we became aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of persons (art. 33). If the breach is likely to result in a high risk, we also inform the data subjects, without undue delay (art. 34). Where we process data on behalf of a customer, as a processor, we inform that customer without undue delay.

Cookies

Server Room does not use cookies of its own. We do not place cookies on your device to identify you, to track your activity, or for analytics or advertising. Where the website needs to remember something in order to work properly, for example to keep you signed in to your account, it uses your browser's local storage, which stays on your device and is not used to track you across other websites. Page statistics and tests of page wording are worked out from our own server logs, as described above, without cookies and without local storage. Certain third-party services we embed, such as the live chat widget and the payment processor, may place their own strictly necessary cookies when you use those specific features; those cookies are controlled by those providers under their own privacy policies, not by Server Room.

External links

The website serverroom.net points to many other websites. Server Room can in no way be held responsible for the content and privacy policy of these websites. Server Room cannot be held responsible for any direct or indirect damage that may result from their use: in particular access to these websites and to websites linked to them, and, without limitation, damage, financial or commercial loss, operating loss or loss of data, even if we could have been notified beforehand.