Smartbiz

Privacy policy

What data this site collects, why, for how long, and what your rights are.

Last updated: 30 September 2026

This policy explains what personal data we collect through smartbiz.ro and smartbizcorp.com, why we collect it, how long we keep it and what your rights are. We wrote it to be read, not just ticked.

1. Who we are

The data controller is [FULL LEGAL NAME OF THE COMPANY], with its registered office at [REGISTERED ADDRESS], registered with the Romanian Trade Register under no. [J…./…./….], tax identification code [CUI] (“Smartbiz”, “we”).

For any question about your data, write to the address shown on the contact page or use the form there.

2. What data we collect and why

The contact form

When you write to us through the form, we collect your name, email address and message and, if you fill them in, your company and phone number. We use them solely to reply to you and, if the conversation continues, to prepare a proposal. The legal basis is our legitimate interest in answering enquiries and, later, steps taken prior to entering into a contract (Art. 6(1)(b) and (f) GDPR).

Your message reaches our mailbox through an email delivery service (see section 4). We keep correspondence for at most 24 months from the last exchange, then delete it, unless it led to a contract, in which case statutory archiving periods apply.

The AI assistant (“Describe your situation”)

The text you type into the assistant is sent, together with our solution catalogue, to a language model provided by Anthropic (see section 4), which generates an indicative proposal. We do not store the descriptions you submit and do not link them to your identity; we do not ask for your name or email at this step. Please do not enter personal data (yours or other people’s) or confidential company information; the assistant only needs a general description of the situation.

If you then click “Let’s talk”, the description is pre-filled into the contact form, where the rules above apply.

Technical access data

Like any website, on each visit the hosting server automatically processes your IP address, browser type, the page requested and the time of access, in order to deliver the pages, protect the site against abuse and measure traffic in aggregate. The legal basis is our legitimate interest in running a secure website. These logs are kept by the hosting provider for a short period (usually under 30 days).

3. Cookies and tracking

The site uses no tracking, advertising or analytics cookies and embeds no social-media scripts. We do not build a profile of you and do not follow you across other sites. The only items stored in your browser are strictly technical ones needed to display the page (for example, fonts), which do not identify you.

Should we ever add traffic-analytics tools, we will update this page and ask for your consent where the law requires it.

4. Who we share data with

We do not sell or rent personal data. We share it only with providers that help us run the site, under contracts that oblige them to protect it:

  • Cloudflare, Inc. (hosting of the site and of the contact / assistant functions; servers in the European Union and other regions, with standard contractual clauses for transfers);
  • Resend (the service through which form messages reach our mailbox);
  • Anthropic, PBC (the language model that generates the assistant’s proposal; under its policies, data sent through the API is not used to train models);
  • Romarg (domain registration and email hosting).

Some of these providers may process data outside the European Economic Area. In such cases the transfer relies on European Commission adequacy decisions or standard contractual clauses.

We may also disclose data to authorities where the law requires it.

5. How long we keep data

In short: form correspondence, at most 24 months; assistant descriptions, not at all; technical logs, short-term, at the hosting provider. Data that becomes part of a contractual relationship is kept for as long as tax and commercial law require.

6. Your rights

Under the GDPR you have the right to request access to your data, its rectification or erasure, restriction of processing, data portability, and to object to processing based on legitimate interest. You can write to us at any time at the address on the contact page; we reply within one month.

If you are not satisfied with our answer, you may lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), 28-30 G-ral. Gheorghe Magheru Blvd., Bucharest, www.dataprotection.ro, or with the supervisory authority of your own country.

7. Security

The site is served over HTTPS only. The form is protected against bots, and our email addresses are displayed in a form that cannot be harvested automatically. Access to received messages is limited to the people handling client relations.

8. Changes

We may update this policy when something changes on the site or with our providers. The current version, with its update date, is always the one on this page.

What's on your mind?

Describe your situation in a few sentences. Our assistant shows you within seconds which Smartbiz approaches would fit, then we talk specifics, with no commitment.