Privacy Policy
Contents
Who we are
The data controller is SC Delta Communications Network SRL, with registered office at Calea Văcărești 207, Sector 4, Bucharest, Romania, registered at the Trade Register under no. J40/17458/2004, tax ID (CUI) 16890789, not a VAT payer, hereinafter referred to as "ServerHost", "we" or the "controller".
You can reach us at: contact@serverhost.ro.
Data protection contact: dpo@serverhost.ro
What data we collect and why
We collect only the data strictly necessary to provide our services:
- Contact details (first name, last name, email address, phone number, company) — provided voluntarily via the contact form or within the contractual relationship. Purpose: communication, invoicing, technical support.
- Technical data (IP address, browser, operating system, pages visited, session duration) — collected automatically via server logs and cookies. Purpose: security, abuse prevention, service improvement.
- Billing data (name/company name, address, VAT/tax ID, bank details) — required for contract performance and legal accounting/tax obligations.
- Correspondence (emails, support messages) — retained to document the contractual relationship and resolve disputes.
Legal basis for processing
We process your data on the following legal grounds (pursuant to Art. 6 GDPR):
- Contract performance (Art. 6(1)(b)) — to provide the services you have purchased.
- Legal obligation (Art. 6(1)(c)) — to comply with accounting, tax and archiving requirements under Romanian law.
- Legitimate interest (Art. 6(1)(f)) — for infrastructure security, fraud prevention and service improvement.
- Consent (Art. 6(1)(a)) — for marketing communications, if you have explicitly opted in.
How long we keep your data
- Accounting documents and related data — 5 years, calculated from 1 July of the year following the financial year in which the document was drawn up, in accordance with Romanian Accounting Law no. 82/1991, as amended by Law no. 36/2023. Certain documents are kept longer where the law expressly requires it.
- Contractual data — for the duration of the contract and 3 years after its termination, corresponding to the general limitation period. In the event of a dispute, the relevant data is kept until the dispute is finally settled.
- Correspondence and support — 3 years from the last interaction.
- Server logs and technical data — maximum 90 days.
- Contact form data — 1 year from last communication, if no contract was concluded.
Upon expiry of the retention period, data is deleted or irreversibly anonymised.
Data transfers to third parties
We do not sell or rent your data. We may share it with:
- Oblio.eu (SC Oblio Software SRL) — invoicing platform used to issue fiscal documents. Billing data (name, address, VAT/tax ID) is transmitted to them for invoice generation. Processing of this data is governed by Oblio.eu's privacy policy, which may be updated independently of ServerHost.
- Accounting/legal service providers — strictly for legal obligations, under confidentiality agreements.
- Public authorities — upon explicit legal request (courts, tax authorities, police).
- Analytics & marketing providers (only with your consent) — depending on your choices in the cookie banner, we may use Google (Google Analytics / Tag Manager), Meta Platforms (Facebook Pixel), Microsoft (Bing UET) and/or Matomo (self-hosted on our infrastructure). These tools collect data such as IP address and on-site interaction. Without consent, none are activated.
Transfers outside the European Union: our hosting infrastructure is physically located in Romania. A transfer outside the EU may occur only if you enable Google, Meta or Microsoft, in which case it relies on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC). Matomo runs on our infrastructure in Romania and involves no transfer. If you do not consent to the optional analytics and marketing services, your data is not transferred outside the European Union.
Cookies
We use cookies and similar technologies, grouped into categories:
- Strictly necessary — for the site to function (session, CSRF security, storing consent preferences). No consent required.
- Analytics (consent only) — to understand how the site is used: Google Analytics and/or Matomo (self-hosted).
- Marketing (consent only) — to measure campaigns: Meta (Facebook) Pixel, Microsoft/Bing UET.
On your first visit we show a banner where you can accept or reject each provider individually. No analytics or marketing cookie loads before your explicit consent. You can change or withdraw your choices anytime via the "Cookie settings" link in the site footer, or through your browser settings.
Your rights
Under GDPR, you have the following rights:
- Right of access — you may request a copy of the data we hold about you.
- Right to rectification — you may request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — you may request deletion of your data, subject to legal retention obligations.
- Right to restriction of processing — you may request temporary suspension of processing.
- Right to data portability — you may receive the data you provided in a structured, commonly used, machine-readable format.
- Right to object — you may object to processing based on legitimate interest or for direct marketing purposes.
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing.
Automated decision-making and profiling (Art. 22 GDPR): We do not use automated decision-making processes and do not carry out profiling of users in ways that produce legal effects or similarly significantly affect you.
To exercise any of these rights, send an email to dpo@serverhost.ro. We respond within 30 days.
Data security
We take appropriate technical and organisational measures to protect your data:
- Encrypted communications via TLS/HTTPS across all services.
- Access to data restricted on a need-to-know basis.
- Own physical infrastructure located in Romania — no third-party cloud providers for client data.
- Regular, encrypted backups with controlled access.
- Continuous infrastructure monitoring for detection of unauthorised access attempts.
In the event of a personal data breach, we will assess its nature and impact without undue delay. Where the GDPR requires notification to the supervisory authority, such notification will be made without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach (Art. 33 GDPR). Where the breach is likely to result in a high risk to the rights and freedoms of the affected individuals, they will be informed without undue delay, in accordance with the GDPR (Art. 34).
Contact and supervisory authority
For any questions or requests regarding your personal data, you can contact us:
- General email: contact@serverhost.ro
- Data protection contact: dpo@serverhost.ro
- Postal address: SC Delta Communications Network SRL, Calea Văcărești 207, Sector 4, Bucharest, Romania
If you believe your rights have been infringed, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):
- Website: www.dataprotection.ro
- Email: anspdcp@dataprotection.ro
- Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
The AI assistant (Edi) and conversations
The Edi service is an assistant based on artificial intelligence, installed on websites. This section describes the processing of data from the conversations held with it.
- What is processed. The messages written by the visitor and the generated answers, the language and the page where the conversation started, the time of the conversation and the IP address, used to limit abuse.
- Authenticated users. If a visitor is signed in to the Client's website, the Edi integration may provide the assistant with certain information about their account, services or orders in order to provide responses tailored to their situation. This information is provided by the Client's website during the conversation and is limited to the data the Client chooses to make available to the service.
- Purpose. The data is processed in order to provide the Edi service on behalf of the Client: receiving and processing the questions, generating the answers, keeping the conversation context, running and securing the service and preventing abuse. The website owner may add, correct or validate the information used by their own assistant, in order to improve the answers given on their website.
- The assistant's knowledge. The content indexed from the website and the information added, corrected or validated by the Client are used to run and improve their own assistant. This information is not used to improve the assistants of other clients.
- AI model training. Conversations held through Edi are not used to train or fine-tune artificial intelligence models and are not used to improve the assistants of other clients.
- Legal basis. For the processing where ServerHost acts as controller, the data is processed, as the case may be, on the basis of the performance of the contract and of the legitimate interest in providing, securing and preventing abuse of the service. For conversations held with Edi on a client's website, the legal basis for the processing is established by the client, as controller, depending on the purpose and context in which the assistant is used.
- Retention. Conversations are deleted automatically 90 days after the last message. The client account shows the 20 most recent conversations for each site. Information that the website owner adds or explicitly validates as correct becomes knowledge of the assistant and remains stored for as long as the service is active.
- Where it is processed. The artificial intelligence models run on ServerHost's own infrastructure in Romania, European Union. Messages are not sent to artificial intelligence services outside our infrastructure and are not used to train models made available to other clients.
- Data protection roles. For the data needed to administer the account and to provide the service to the client, including metering usage for invoicing, ServerHost acts as controller. For the data submitted by visitors through Edi installed on a client's website, that client is the controller of the data, and ServerHost acts as processor and processes this data only in order to provide the Edi service and in accordance with the client's instructions. For the assistant on serverhost.ro, we are the controller.
- Client responsibility. The client is responsible for establishing the legal basis for the processing and for informing the visitors of their own website about the use of Edi.
- Sensitive data. Edi is not intended for the transmission of passwords, full payment card details or other confidential information that is not necessary for the conversation. We recommend that you do not provide special categories of personal data through the assistant, such as information concerning health, racial or ethnic origin, political opinions, religious beliefs, biometric data or other sensitive information.
The commercial terms of the service are described in the Services based on artificial intelligence section of the Terms and conditions.