Privacy policy
What personal data we use on vtpgo.ro and in the VTP GO app, why, who else receives it, how long we keep it and what your rights are.
1. Who we are
The controller is DESIGN CREED S.R.L., registered office Str. Gheorghe Lazăr nr. 5B, et. 5, ap. 10, Sector 1, Bucharest, Romania, Trade Register No. J2026029383009, fiscal code 54621252 ("we"). We provide the VTP GO platform: the vtpgo.ro website and the application at app.vtpgo.ro.
For any question about your data, write to contact@vtpgo.ro. We have not appointed a data protection officer; requests reach us directly.
2. What this policy covers
This policy covers the data for which we decide why and how it is used: that of people who write to us through the contact form, people who open an account, users of the app (owners, administrators, coordinators, technicians) and people who ask us for support.
It does not cover the data inspection firms enter about their own customers — names, addresses, phone numbers, appliances, reports, signatures. For that data the controller is the firm carrying out the inspection; we process it only on the firm's behalf and on its instructions, as set out in the section "Processing data on the firm's behalf" of the Terms. If you are a customer of such a firm and have a question about your data, ask the firm; if you write to us, we pass your request on to it.
3. What data we use and why
3.1 The contact form on vtpgo.ro
- Data
- Your name, company, email address, message (if you write one), the language of the page and the IP address it was sent from.
- Why
- To reply and arrange a walkthrough. We keep the IP address so that we can stop abusive submissions. The internal notification we receive for each enquiry contains only its number, not your data.
- Legal basis
- Steps you ask us to take before a possible contract (Article 6(1)(b) GDPR) and our legitimate interest in protecting the form (Article 6(1)(f)).
- How long
- 2 years from submission; after that the enquiry is deleted automatically.
3.2 Opening an account
- Data
- The company name, your first and last name, your email address and the IP address the request came from.
- Why
- To send you the confirmation link and create the firm's account; the IP address, so that we can investigate abusive registrations.
- Legal basis
- Entering into the contract you ask for (Article 6(1)(b)) and our legitimate interest in preventing abuse (Article 6(1)(f)).
- How long
- The confirmation link expires after 24 hours. The registration request is deleted automatically 30 days after the link expired, whether it was confirmed or not. If you confirmed, your details move into the firm's account (3.3).
3.3 The account and use of the app
- Data
- Name, email address, phone number, role in the firm, password (we keep only a cryptographic fingerprint of it, never the password), two-step sign-in data, profile photo (if you upload one), the signature used on reports, ISCIR authorisation and stamp details, the history of actions taken in the account (the activity log) and sign-in sessions.
- Why
- To provide the service, to record who drew up and signed each document, and to keep the account secure.
- Legal basis
- Performance of the contract with the firm (Article 6(1)(b)); for users invited by the firm, the firm's and our legitimate interest in giving them access to the platform and keeping reports traceable (Article 6(1)(f)).
- How long
- For as long as the firm's account exists. A user who has worked on reports cannot be deleted from the firm, only archived, because their name stays on the documents they drew up; a user with no activity can be deleted. Deleting the whole account is described in section 6.
Without this data we cannot create the account or provide the service.
3.4 Support
- Data
- What you write in support tickets in the app or by email, together with your name and address.
- Why
- To resolve what you ask.
- Legal basis
- Performance of the contract (Article 6(1)(b)) and our legitimate interest in answering people who write to us (Article 6(1)(f)).
- How long
- Tickets, for as long as the account exists; messages received by email, at most for as long as the relationship with your firm lasts.
3.5 The emails we send
We send only messages related to using the service: confirmation links, invitations, password resets, account notifications and — when a firm presses the send button — reports to its customers (those on the firm's behalf). We send no newsletters and do no email marketing.
3.6 Technical logs
The application server records incoming requests — IP address, time, the page requested and any errors — so that we can fix problems and stop attacks (legitimate interest, Article 6(1)(f)). The logs are size-limited (30 MB at most), are overwritten automatically as they fill up and are cleared at every update of the application. We keep no access logs for the vtpgo.ro website.
3.7 Invoicing
For invoices we use the firm's details (name, fiscal code, address) and the contact person. The legal basis is a legal obligation (Article 6(1)(c)); invoices are kept for as long as tax and accounting law requires.
4. Who else receives the data
We do not sell personal data and do not use it for advertising. It is received only by the providers without whom the service would not work, under contract and only as far as they need it for what they do for us:
- HostGate (hostgate.ro) — hosts the servers that run the application, the database, uploaded files and backups, in data centres in Bucharest.
- Resend (Plus Five Five, Inc., USA) — sends the application's automatic emails.
- Google Workspace (Google Cloud EMEA Limited, Ireland) — hosts the contact@vtpgo.ro mailbox, and therefore the messages you send us by email.
Data may also reach public authorities, only when the law requires us to disclose it. Within our company, only the people who maintain the platform and answer support requests have access, and only as far as needed.
5. Transfers outside the European Economic Area
Resend is a US company, and Google may also process data outside the European Economic Area. In both cases the transfer relies on the standard contractual clauses adopted by the European Commission, included in the data processing agreements we have with them; both companies are also certified under the EU-U.S. Data Privacy Framework. The application's database and files stay on the servers in Romania.
6. Deleting an account, and backups
Account data stays for as long as the account exists, including after the free trial ends, so that the firm can still consult it and come back. The account owner can ask for deletion at any time by writing to contact@vtpgo.ro: we delete the firm's account and all the data in it — users, customers, appliances, reports, files — within 30 days of the request. Before deletion, the firm can export its data from the app (customers, staff, equipment, appointments, reports).
We back up the database every day, encrypted with a key that is not stored on the server, and keep those backups for 30 days. In addition, before every update that changes the database we take an encrypted copy and keep the last 10. Deleted data can therefore remain in these copies for a while, until they are replaced; we use them only to restore the platform after a failure.
7. Cookies
vtpgo.ro uses no cookies at all and loads nothing from third parties: the fonts are hosted by us and there is no traffic analytics.
The app (app.vtpgo.ro) uses only what is strictly necessary for it to work: the sign-in cookies (access_token, refresh_token) and the form-protection cookie (_csrf). In browser storage we also keep the sign-in state for the length of the session and, on the planning page, the period you chose to display. Because they are strictly necessary for the service you asked for, we do not ask for consent to them (Article 4(5) of Romanian Law 506/2004). We use no advertising or analytics cookies.
8. How we protect the data
- All connections are encrypted (HTTPS).
- Passwords are not stored, only a cryptographic fingerprint of them; accounts are protected by two-step sign-in.
- Each firm's data is separated at the database level, not only in the application.
- Backups are encrypted with a key that is not stored on the server.
- Only the people who maintain the platform have access to the servers.
If a personal data breach nevertheless occurs that may affect your rights, we notify ANSPDCP and, where the law requires it, you.
9. Your rights
Under the GDPR (Articles 15–22) you have the right to request access to your data, its rectification, its erasure, restriction of processing and data portability, and the right to object to processing based on legitimate interest. We make no automated decisions that produce legal effects concerning you and do no profiling.
For any of these, write to contact@vtpgo.ro. We reply within one month; we may first ask you to confirm your identity.
If you are not satisfied with the answer, you can lodge a complaint with the Romanian supervisory authority, ANSPDCP, B-dul G-ral. Gheorghe Magheru nr. 28–30, Sector 1, Bucharest, https://www.dataprotection.ro.
10. Minors
VTP GO is a service for businesses, not for people under 18, and we do not knowingly collect data about them.
11. Changes
When we change this policy, we publish the new version on this page with the update date above. If the change is significant, we also tell account owners by email before it applies.