Updated 21 September 2026
Privacy Policy
This English version is provided for convenience. The Romanian version at /ro/informatii-legale/politica-de-confidentialitate/ is the binding text.
This policy explains which personal data we process, why, for how long and what rights you have. We have written it for visitors to the amazingsoft.ro website, for the contact persons of our clients, prospects and suppliers, for those who book a consultation, for those who complete our brand questionnaire (“Brand discovery”), for those who send us a CV and for those who write to us on LinkedIn or WhatsApp.
This policy replaces the privacy policy of 2 September 2020. The old policy mentioned tools we do not use (Slack, Notion, Jira, Backblaze, Make, Dropbox, Uptime Robot, LiveChat, Google AdSense, Facebook Audience Network, WordPress.com) and a “data protection officer”; both have been corrected here.
1. Who we are
The data controller is Amazing Soft SRL, with its registered office in Bucharest, Sector 6, Str. Sg. Alexandru Cutieru nr. 25B, camera 1, bl. 2, sc. 2, et. 11, ap. 278, postal code 061422, registered with the Trade Register (Registrul Comerțului) under no. J2016000150403, VAT no. RO35387202.
Data protection contact: [email protected], with “Data protection” in the subject line, or by post at the address above. We are not legally required to appoint a data protection officer (Article 37 GDPR) and have not appointed one; requests are handled by the company’s management.
2. When we are a controller and when we are not
We are the controller for the data described in this policy: the data of website visitors and the data of the people with whom we enter into a business relationship.
We are a processor when we work with our clients’ data as part of projects: the users of their applications, the customers of their online shops, the conversations of the AI agents we build. Those processing operations are governed by the Data Processing Agreement, not by this policy. If you are a user of an application or website we built for a client, please contact that client; they decide how your data is used.
For the brand questionnaire we are the controller, even though you work for the client company: we built the questionnaire, we decide what we ask, how the profile is calculated and how long we keep the answers, and the purpose is to prepare our own brand identity proposal. The Data Processing Agreement covers the data we process on the client’s instructions, inside their products; the questionnaire does not fall there, but under this policy.
Our products (for example Listero, DuoDive, Cluekeep, undepierzi.ro, Tasao) have their own privacy policies, published on their websites. This policy does not cover them.
3. What data we process, why and for how long
| Situation | Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|---|
| You visit the website | IP address, browser and device type, pages accessed, date and time, referring address; security logs (blocked requests) | Displaying the website, security, preventing attacks, troubleshooting | Legitimate interest, Article 6(1)(f): the secure operation of the website | Server and security logs: for as long as needed for the security of the website, then deletion |
| You accept statistics cookies | Cookie identifiers (_ga, _ga_*), navigation events, approximate location data (city level), device type | Traffic statistics (Google Analytics 4, via Google Tag Manager) | Consent, Article 6(1)(a) and Article 4(5) of Law no. 506/2004 on the processing of personal data and privacy in the electronic communications sector | Cookies: up to 2 years; data in Google Analytics: 14 months. You can withdraw your consent at any time from “Manage cookies” |
| Cookie-free statistics (Umami) | Pages accessed, device type, country, referring address; no IP address stored; a session identifier that changes every month | Measuring traffic without tracking individuals (Umami, hosted by us) | Legitimate interest, Article 6(1)(f): understanding how the website is used | 13 months (395 days), then deleted; does not identify individuals |
| You fill in the contact form | Name, company, e-mail, phone, what you need, message, how you heard about us, date of submission | To reply to you, assess your request and prepare a quote | Pre-contractual steps at your request, Article 6(1)(b); for messages that do not lead to a contract, legitimate interest, Article 6(1)(f) | Correspondence: 24 months from the last contact; if you become a client, for the duration of the relationship and then as per the row “You are a client” |
| You book a free consultation (Calendly) | Name, e-mail, optionally phone and the topic of the discussion, the chosen time; Calendly also processes the technical data of the booking | Organising a 30-minute conversation | Pre-contractual steps, Article 6(1)(b) | As for the contact form. Calendly LLC (USA) processes the data as our processor and, if you have a Calendly account, under its own policy for your account |
| You complete the brand questionnaire (private “Brand discovery” link) | Your first name, your role in the company, your e-mail address (optional, so that you can resume on another device and receive the profile), the language you chose; your answers to the 9 steps: the brand and its field, what the company does, the type of project, the current website, the audiences and the ideal client, the competitors and their positioning, the attribute choices, the personality sliders, the visual choices, the moods, the moodboard images, the accepted and rejected colour palettes, the brands you admire and avoid, forbidden or mandatory colours, clichés to avoid, where the logo will be used, the deliverables, the tagline, the brand’s languages, the desired timing, the name and role of the person who makes the final decision, how many people will also give feedback, and your free-text notes; the archetype profile, the visual profile and the contradiction flags, all calculated automatically from your answers; the details we type in ourselves when we generate the link (the company, the contact person’s name and e-mail address, the language, the account manager, the welcome message, the expiry date, an internal note); technical data: the random token in the link, the cryptographic fingerprint (SHA-256) of your session token — we never keep it in the clear — and a fingerprint of the IP address, kept temporarily to limit abuse | To understand the brand, to compare the answers received through the same link and to prepare the brand identity proposal and the working session with your company | Legitimate interest, Article 6(1)(f): preparing the brand identity proposal for the company that asked for it; where you answer as a party to the pre-contractual steps yourself, Article 6(1)(b) | Links without the “Project signed” tick: the link and all the answers are deleted automatically and permanently 12 months after the link was created, by a daily task. With “Project signed” ticked: the answers stay for the duration of the project and are deleted manually. The link itself expires (by default after 30 days), but expiry does not delete the data. The draft saved in your browser stays until you delete it (see the Cookie Policy) |
| You write to us on WhatsApp | Phone number, profile name, content of the messages | Answering questions; communication with clients | Pre-contractual steps or contract, Article 6(1)(b); legitimate interest, Article 6(1)(f) | Conversations: 24 months from the last message. WhatsApp (Meta) processes messages under its own terms; we do not use the WhatsApp Business Platform for our own website |
| You contact us on LinkedIn or we contact you | Name, job title, company, public profile, messages | Professional networking, B2B prospecting, replying to messages | Legitimate interest, Article 6(1)(f): developing business relationships with people in a professional role | Messages stay on LinkedIn; data taken into our records: 24 months from the last contact |
| You are a client or represent a client | Name, job title, e-mail, phone, signature, correspondence, data from contracts, invoices and payments | Concluding and performing the contract, invoicing, support, accounting records, defending our rights in court | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c) (invoicing, accounting); legitimate interest, Article 6(1)(f) (records, disputes) | For the duration of the contract; financial and accounting documents (invoices, contracts underlying the accounting entries): 5 years from 1 July of the year following the end of the financial year (Article 25 of the Accounting Law no. 82/1991), except for documents concerning assets with a longer useful life; contractual correspondence: 3 years from termination (the general limitation period) |
| You are a supplier or represent a supplier | Name, job title, e-mail, phone, invoicing details; for sole traders (PFA), the tax identification code, which may be the same as the personal identification number (CNP) | Orders, payments, records | Contract, Article 6(1)(b); legal obligation, Article 6(1)(c); for the CNP, Article 4(1) of Law no. 190/2018 (processing required by tax legislation) | As for clients |
| You send us a CV (we do not have a careers page) | The data in the CV and in the message | Assessing a possible collaboration | Pre-contractual steps at your request, Article 6(1)(b) | 6 months from receipt, then deletion, unless we agree otherwise in writing |
| You appear in our materials (portfolio, case studies, awards and recognitions) | Name, job title, company, quote, image | Presenting our projects and recognitions | Consent, Article 6(1)(a), or the agreement in the contract with the client | For as long as the material is published; withdrawal of consent leads to removal within 30 days |
We do not sell data, do not build marketing profiles and do not make automated decisions with legal effects on you.
From your answers, the brand questionnaire automatically calculates a brand profile: archetypes, a visual profile and flags for contradictions between answers. It is a profile of the brand you told us about, not a profile of you as a person: we do not use it for marketing, advertising or segmentation, we do not combine it with data about you from other sources, and on its own it produces no decision with effects on you — it is working material for the team preparing the proposal. The contradiction flags are visible only to the Amazing Soft team.
We have no user accounts on the website: there is no registration, no password and no public profile. On the brand questionnaire link, each respondent has a session identified by a random token, so that they can resume their answers on another device; it is not an account and we do not ask you for a password. We do not send a newsletter. The website is not aimed at minors.
Providing data in the forms is voluntary, but without a name, e-mail address and message we cannot reply. The “how did you hear about us” field is required: it shows us which channels work. In the brand questionnaire, the only field required at the start is your first name; your e-mail address is optional and we use it only to send you the resume link and the profile. You can skip questions or stop at any time; whatever you have filled in until then stays saved as a draft. For clients and suppliers, identification and invoicing details are necessary for concluding the contract and for tax obligations.
If we did not receive your data directly from you (for example, a colleague named you as the client’s or supplier’s contact person, or we found you on LinkedIn), the source is the company you represent or your public profile; we give you this information at the latest at the first contact (Article 14 GDPR). This is also how we obtain the name and e-mail address of the contact person to whom we send the brand questionnaire link: we type them in ourselves, from the commercial correspondence with the company you represent.
There is also a situation in which we may never contact you at all: a colleague of yours who completes the questionnaire gives us the name and role of the person who makes the final decision about the brand. The source of that data is the colleague who completed the questionnaire, and the data is the name, the role and the connection to the project. We provide the information required by Article 14 GDPR through this policy, and we ask the client company to inform the colleagues named in this way. If you have been named like this and do not want to appear, write to us at [email protected] and we will remove your name from the answers.
4. Who we share data with
The data is accessible to the people at Amazing Soft who need it and to the providers below, which process it on our behalf under the data processing agreements or contracts concluded with them:
- Romarg SRL (Romania): hosting of the website; server logs.
- Cloudflare, Inc. (USA): DNS; proxy and protection, if enabled.
- Google Ireland Limited: Google Workspace (e-mail, documents, meetings); Google Analytics 4 and Tag Manager (only with consent).
- Calendly LLC (USA): booking consultations.
- Oblio Software SRL (Romania): issuing invoices.
- Hetzner Online GmbH (Germany, servers in Germany): our internal tools (GitLab, automations, monitoring), in which clients’ contact details may appear.
- Anthropic Ireland, Limited (Ireland; processing in the USA): language models used via API in our internal automations (for example, sorting incoming messages and drafting replies), in which contact details and excerpts from correspondence with clients and prospective clients may appear; model training on this data is disabled.
- Consultants and authorities: accountant, lawyer, banks, ANAF (the Romanian tax authority) and other authorities, where the law requires it.
The full list of the providers we use in client projects is on the Sub-processors page.
The brand questionnaire adds no new provider: the page and the answers sit on the website’s server (Romarg), and the three e-mails the questionnaire sends (the notification to the account manager, the resume link to you, and the request for a new link) go out through the Google Workspace mail server of the [email protected] address. The notification e-mail contains the company name and your first name, not your answers. The answers are seen by the Amazing Soft team working on your project. The note displayed in the questionnaire, on the screen where you enter your first name, tells you what from your answers is discussed with your company in the working session; please read it before you answer.
5. Transfers outside the European Economic Area
Some providers are in the United States. For Cloudflare, Calendly and Google LLC (the Google group), transfers are made on the basis of the European Commission’s adequacy decision for the EU–US Data Privacy Framework (DPF) (Decision (EU) 2023/1795), under which these organisations are certified (verified on 11 September 2026), and, as a fallback mechanism, on the basis of the Commission’s Standard Contractual Clauses (SCCs) (Decision (EU) 2021/914). For Anthropic, transfers are made on the basis of the Commission’s Standard Contractual Clauses (Decision (EU) 2021/914). WhatsApp (Meta) and LinkedIn process data as independent controllers, including outside the EEA, under their own policies. If you are in the United Kingdom, communicating with you involves a transfer to the United Kingdom, covered by the Commission’s adequacy decision (renewed in December 2025, valid until 27 December 2031). You can request a copy of the safeguards at the contact address.
6. Your rights
You have the right to request: access to your data (Article 15 GDPR), its rectification (Article 16), erasure (Article 17), restriction of processing (Article 18), portability of the data you have provided, where the processing is based on a contract or on consent (Article 20), and to object to processing based on legitimate interest, including prospecting (Article 21). Where processing is based on consent, you can withdraw it at any time, without affecting the processing carried out before withdrawal.
Write to us at [email protected]. We reply within one month at most; for complex requests we may extend this by two months, and will let you know. We may ask you for information to confirm your identity. Requests are free of charge, except for those that are manifestly unfounded or excessive.
You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing — ANSPDCP (the Romanian data protection authority): B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest; telephone +40 318 059 211; e-mail [email protected]; www.dataprotection.ro. We would be glad if you wrote to us first, so that we can resolve the issue directly.
7. Security
We apply the measures described on the Technical and organisational measures page: encryption in transit (HTTPS) and on devices, two-step authentication on important accounts, access on a least-privilege basis, backups stored separately from the server, confidentiality agreements with all collaborators. The contact form is sent by e-mail to [email protected] and is not stored in the website’s database.
The brand questionnaire works differently: the answers are stored in the website’s database, on the same server, in non-public records that only logged-in administrators can access. The page opens only with the unique link we send you, is not indexed by search engines (X-Robots-Tag: noindex, nofollow, noarchive), is not held in cache and loads no third-party script. Your session token is kept only as a cryptographic fingerprint, never in the clear.
8. Cookies
We use cookies that are necessary for the website to work and, only with your consent, statistics cookies. Details are in the Cookie Policy. You can change your choice at any time from the “Manage cookies” link in the website footer.
The brand questionnaire page saves no cookies and loads neither Google Analytics, nor Umami, nor any other third-party script. The draft of your answers is saved in your browser’s local storage so that you can pick up where you left off; it is strictly necessary for the service you requested, so we do not ask for your consent for it. The details are also in the cookie policy.
9. Applicable law
Regulation (EU) 2016/679 (GDPR), Law no. 190/2018 on measures implementing the GDPR and Law no. 506/2004 on the processing of personal data and privacy in the electronic communications sector.
10. Changes
We publish the current version at this address, with the version number and date. Important changes are announced on the website at least 15 days in advance. Previous versions are available on request.
What changed in version 1.1 (21 September 2026): we added the brand questionnaire (“Brand discovery”) — a new row in Section 3 (what we collect, the legal basis, automatic deletion after 12 months), the clarification in Section 2 that we are the controller for the questionnaire, the distinction between a brand profile and a marketing profile, the Article 14 information for the contact person and for the final decision-maker named by a colleague, and the clarifications in Sections 4, 7 and 8 about where the answers are stored and about the absence of cookies on the questionnaire page.
Amazing Soft SRL · VAT no. RO35387202 · J2016000150403 · [email protected]