Prezentare Platforma
Nottral este o platforma de programari care conecteaza utilizatorii cu afacerile. Datele tale permit aceste conexiuni.
Learn how we collect, use, and protect your personal data in compliance with GDPR
Lucruri importante despre aceasta Politica de Confidentialitate
Nottral este o platforma de programari care conecteaza utilizatorii cu afacerile. Datele tale permit aceste conexiuni.
Colectam date de identificare, contact si tehnice necesare pentru furnizarea serviciilor noastre.
Actionam ca Operator pentru contul tau si ca Persoana Imputernicita pentru datele gestionate de afaceri.
Datele tale sunt folosite pentru furnizarea serviciilor, comunicare, securitate si, cu consimtamant, marketing.
Gestioneaza-ti datele, setarile de confidentialitate si preferintele cookie direct din contul tau.
Acceseaza, rectifica, sterge sau exporta datele tale. Opune-te prelucrarii sau retrage consimtamantul oricand.
This Privacy Policy describes how Nottral ("we", "the company" or "the platform") collects, uses, stores, and protects your personal data when you use our services.
Nottral operates as a multi-tenant platform, meaning we serve both individual users and businesses. Depending on how you interact with the platform, Nottral may act as a Data Controller (for your user account) or as a Data Processor (for data processed on behalf of businesses).
Under GDPR, the data controller is the entity that determines the purposes and means of processing personal data.
For any questions regarding personal data processing, please contact our GDPR contact.
We are the controller for:
We act as a processor for:
Businesses using Nottral are independent controllers for their customer data. They determine the purposes of processing and are responsible for GDPR compliance in their relationship with customers.
We only collect data necessary for providing our services. Below are the categories of data collected:
| Category | Data Types | Purpose | Legal Basis | Retention |
|---|---|---|---|---|
| Identification Data | First and last name, Username, Profile photo (optional) | Account creation and management | Contract performance | Account duration + 30 days |
| Contact Data | Email address, Phone number, Postal address (optional) | Communication and notifications | Contract performance | Account duration |
| Demographic Data | Date of birth, Gender (optional), Language preferences | Experience personalization | Consent | Until consent withdrawal |
| Technical Data | IP address (anonymized/hashed), Device and browser type, Operating system | Security and diagnostics | Legitimate interest | 12 months |
| Transactional Data | Appointment history, Payments and invoices, Communications with businesses | Service delivery | Contract performance / Legal obligation | 3 years / 10 years (tax documents) |
When you make an appointment with a business, they will have access to:
Businesses do not have access to your email address or Nottral account billing data.
We process personal data for the following specific purposes:
Creating and managing accounts, processing appointments, facilitating communication between users and businesses.
Sending appointment confirmations, status notifications, reminders, and important service updates.
Fraud prevention, suspicious activity detection, account and platform infrastructure protection.
Analyzing platform usage to improve features and user experience.
Meeting legal obligations, including tax and reporting requirements.
Sending offers and news about our services, only with your explicit consent.
We process personal data only when we have a valid legal basis:
Processing necessary for services you have requested.
When you have given us explicit permission for processing.
When we are legally required to retain or provide data.
When we have a justified interest that does not override your rights.
We retain personal data only as long as necessary for the established purposes or as required by legal obligations:
| Data Types | Retention | Purpose |
|---|---|---|
| Account data | Account duration + 30 days | Allowing account recovery in case of accidental deletion |
| Appointments and services | 3 years from completion | Dispute resolution and statistics |
| Invoices and tax documents | 10 years | Compliance with Romanian tax legislation |
| Security logs | 12 months | Security incident investigation |
| Consent records | Until withdrawal + 3 years | Proof of granted consent |
When the retention period expires or upon your request, data is permanently deleted or irreversibly anonymized.
GDPR grants you extensive rights over your personal data. Nottral facilitates exercising these rights through the privacy interface in your account.
You can request a copy of all personal data we hold about you.
You can correct inaccurate data or complete incomplete data directly from account settings.
You can request deletion of personal data ("right to be forgotten"), except for data retained for legal reasons.
You can request limitation of processing in certain circumstances.
You can receive data in a structured format or transfer it to another controller.
You can object to processing based on our legitimate interest or for marketing purposes.
You have the right not to be subject to decisions based solely on automated processing.
You can exercise most rights directly from your account settings, "Privacy & Data" section. For complex requests, contact our GDPR contact.
We will respond to requests within 30 days, in accordance with GDPR Art. 12.3.
We pay special attention to protecting children's and minors' data:
If you discover that a minor has used your email address to create an account without permission, please contact us immediately so we can take necessary action.
We implement technical and organizational measures to protect your data:
In case of a data security breach that may affect your rights, we will notify you without undue delay and will notify the supervisory authority (ANSPDCP) within 72 hours of becoming aware of the breach, as required by GDPR Art. 33.
Your data is primarily stored and processed within the European Union:
For specific functionality, we work with trusted providers:
| Service | Purpose | Location | Safeguards |
|---|---|---|---|
| Stripe | Payment processing | EU/USA | Standard Contractual Clauses |
| MongoDB Atlas | Data storage | EU (Frankfurt) | EU storage |
| Resend | Email sending | USA | Standard Contractual Clauses |
We do not sell your personal data. We share data only in the following circumstances:
When you make an appointment, the respective business receives data necessary to serve you (name, phone, appointment details).
Partners who help us operate the platform (hosting, email, payment processing), contractually bound to protect data.
When legally required (court orders, requests from competent authorities).
To protect our rights, safety, or property, that of our users, or the public.
Email and Nottral billing data are NOT shared with businesses.
We may periodically update this Privacy Policy to reflect changes in our practices or legal requirements:
For substantial changes affecting your rights, we will request acceptance of the new version before continuing to use the services.
If you have questions, concerns, or complaints about data processing, we encourage you to contact us:
If you are not satisfied with our response, you have the right to file a complaint with the supervisory authority: