Privacy policy (GDPR)
Last updated: July 2026 · In accordance with Regulation (EU) 2016/679 (GDPR) and Law no. 190/2018
1. Data controller
The controller of your personal data is ElectroSchema, the service available at electroschema.ro. For any matter relating to data protection you can contact us at gdpr@electroschema.ro or through the Contact page. The full identification details of the entity operating the service (name, registered office, unique registration code, order number in the Registrul Comerțului) are made available upon its registration and on the invoicing documents.
2. Categories of data collected
We process only the data necessary for the operation of the service: • Identification and contact data: name, email address, company name (optional), ANRE authorisation number (optional, declared by you). • Authentication data: your password (stored exclusively as a hash, never in plain text) or, if you sign in with Google, the account identifier and the tokens it issues. • Application content: the projects, plans, cost estimates, clients and appointments you create. • Billing and payment data: processed directly by the payment providers (Stripe, PayPal) — we do not store the full card number. • Google Calendar data: if you connect your Google account (see section 3). • Content sent to the artificial-intelligence features, at your request (see section 4). • Technical and usage data: IP address, browser type, access logs and cookies, for security and operation. For the data of your own clients that you enter in the application (name, contact), ElectroSchema acts as a processor, and you are the controller of that data (art. 28 GDPR); a data processing agreement (DPA) is available on request.
3. Google data (Limited Use)
If you choose to connect Google Calendar, the application requests permission to view and edit events (the calendar.events scope) in order to synchronise your appointments. We securely store the access and refresh tokens issued by Google, used to read, create, update and delete events in your calendar, at your request. ElectroSchema’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: we use this data only to provide you with the calendar feature, we do NOT sell it, we do NOT use it for advertising and we do NOT disclose it to others, except where strictly necessary to provide the service or required by law. Google Calendar data is NOT transmitted to the artificial-intelligence provider and is NOT used to train any model. You can revoke access at any time from your Google account, at myaccount.google.com/permissions; likewise, deleting your ElectroSchema account removes the stored tokens.
4. Purposes of processing
We use the data to: provide and maintain the service; create and manage the account; process payments and issue invoices; synchronise appointments with Google Calendar (if you enable it); run the artificial-intelligence features (the chat assistant, recognition of plans from images, the design agent) — enabled only at your request, in which case the relevant content is sent to the AI provider to generate the response (this content is not used to train the provider’s models); send account-related communications and, with your consent, notifications; ensure security and prevent fraud and abuse; comply with legal obligations (accounting, tax).
5. Legal basis
Processing is based, as applicable, on: • performance of the contract — art. 6(1)(b) GDPR (provision of the service, the account, payments); • your consent — art. 6(1)(a) GDPR (optional notifications, connecting Google Calendar, the AI features, non-essential cookies) — which you can withdraw at any time; • legal obligation — art. 6(1)(c) GDPR (keeping financial-accounting records); • legitimate interest — art. 6(1)(f) GDPR (platform security, fraud prevention, service improvement). The processing also complies with Law no. 190/2018.
6. Recipients and processors
We do not sell your data. We disclose it only to the providers that help us operate the service, acting as processors, under confidentiality and security obligations: • Google Ireland Ltd. — authentication and Google Calendar synchronisation; • Stripe and PayPal — payment processing; • Anthropic PBC (USA) — the artificial-intelligence features (processes the content you send to these features); • the email provider (SMTP) — sending transactional messages; • Cloudflare — anti-bot protection at sign-up (Turnstile); • the hosting and database providers (e.g. Vercel, the PostgreSQL provider). We may also disclose data to authorities where required by law.
7. Transfers outside the EEA
Some providers (for example Anthropic, Stripe, PayPal or Cloudflare, with infrastructure in the United States or global) may process data outside the European Economic Area. These transfers take place only on the basis of the safeguards provided by the GDPR — the Standard Contractual Clauses adopted by the European Commission or, where applicable, an adequacy decision (e.g. the EU–U.S. Data Privacy Framework). A copy of the safeguards can be requested at gdpr@electroschema.ro.
8. Retention period
We keep account data for as long as the account exists. Supporting financial-accounting documents (for example invoices) are kept in accordance with the law — 5 years, under the Accounting Law no. 82/1991 (as in force); annual financial statements are kept for 10 years. Technical logs are kept for a limited period, as needed for security. Google tokens are kept until disconnection or account deletion. After the account is deleted, we delete or anonymise the data within a reasonable time, except for data we are required by law to keep.
9. Data security
We apply appropriate technical and organisational measures: traffic encryption (HTTPS/TLS), storing passwords only as a hash (bcrypt), restricted access to data on a need-to-know basis, secure storage of tokens and abuse monitoring. No system is, however, absolutely secure; please protect your login credentials.
10. Your rights
Under the GDPR (art. 15–22), you have the right to: access your data; rectification; erasure (the right to be forgotten); restriction of processing; data portability; objection; withdrawal of consent (without affecting prior processing); and not to be subject to a decision based solely on automated processing that produces legal effects. You can delete your account directly from your profile settings. For any other request, write to gdpr@electroschema.ro — we respond within 30 days at most.
11. Cookies
We use only cookies and technologies strictly necessary for operation: the authentication session, the language preference and the anti-bot protection (Cloudflare Turnstile). We do not use advertising or tracking (analytics) cookies. Strictly necessary cookies do not require consent; you can manage or delete them at any time from your browser settings. The processing complies with Law no. 506/2004.
12. Automated decisions and artificial intelligence
The I7 standard validation features and the artificial-intelligence features are assistance tools: they provide you with suggestions and analyses, but they do not make decisions with legal effects on you within the meaning of art. 22 GDPR. Design decisions and professional responsibility rest entirely with you (see the Terms and Conditions).
13. Minors
The service is intended for professionals and adults. We do not knowingly collect data from minors. If we notice that we have collected such data, we delete it.
14. Complaints to the authority
If you consider that your rights are being infringed, you can contact the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul General Gheorghe Magheru nr. 28–30, sector 1, Bucharest, postal code 010336, email anspdcp@dataprotection.ro, web dataprotection.ro.
15. Changes to the policy
We may update this policy to reflect changes in the service or in legislation. The date of the last update is shown above, and significant changes will be communicated to you. Continuing to use the service after an update means acceptance of the revised version.
16. Language
This policy is available in several languages for your convenience. In the event of any discrepancy between versions, the Romanian-language version prevails.