Last updated: 9 October 2026
Privacy Policy
1. Who we are
The data controller is REAL GROW SOFT SRL (“Real Grow Soft”, “we”).
For any question about your data, write to us at [email protected] or call +40 746 857 568.
2. Scope of this policy
This policy describes how we process the data of people who visit realgrowsoft.com and of those who contact us (through the form, by email or by phone). Processing carried out within client projects is governed separately, by the contracts concluded with those clients.
We process data in accordance with Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian law.
3. Data we process
- Contact data you provide voluntarily through the contact form, email or phone: name, email address, company, phone number (if provided) and the content of your message.
- Technical data logged automatically by the server hosting the site: IP address, browser type and version, operating system, date and time of access and the pages requested. IP addresses are personal data.
- Usage data, only if you accept analytics cookies: pages visited, referral source, interactions with the site (such as button clicks), device type, approximate location (city/country level) and, possibly, session recordings in which form fields are masked.
- Preferences (light/dark theme and your cookie choice), stored only in your browser.
We do not process special categories of data (such as health data) and ask that you do not include them in messages.
4. Purposes and legal bases
- Answering requests and preparing offers. Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in communicating with prospective clients (Art. 6(1)(f) GDPR).
- Operating and securing the site: preventing abuse, diagnosing errors and protecting our infrastructure. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
- Usage statistics and improving the site (Google Analytics 4 and PostHog). Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 4(5) of Romanian Law no. 506/2004), which you can withdraw at any time.
- Complying with legal obligations, such as accounting obligations if we enter into a contract. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
- Establishing, exercising or defending legal claims. Legal basis: legitimate interest (Art. 6(1)(f) GDPR).
We do not use your data for unsolicited marketing, we do not sell it and we do not make decisions based solely on automated processing, including profiling.
5. How long we keep data
- Messages and correspondence: up to 12 months after the last communication, unless a contract is concluded.
- Server logs: up to 90 days, except where needed to investigate a security incident.
- Analytics data (Google Analytics, PostHog): up to 14 months; analytics cookies expire after at most 13 months.
- Documents related to a contractual relationship: for the duration of the contract and afterwards for the periods required by accounting and tax law.
When these periods expire, the data is deleted or anonymised.
6. Who we share data with
Data is accessed only by our staff who need it. We may share it only with:
- service providers processing data on our behalf (processors), under contract and bound by confidentiality: our hosting provider [Furnizor hosting, țara/regiunea centrului de date] and our email provider Google Workspace (Google Ireland Limited);
- analytics providers, only if you accepted analytics cookies: Google Ireland Limited (Google Analytics 4) and PostHog Inc. (data hosted in the European Union);
- professional advisers (such as our accountant or lawyer), where necessary;
- public authorities, only where required by law.
7. Transfers outside the European Economic Area
We prefer providers that store data in the European Economic Area (EEA); PostHog data is hosted in the European Union. Google may transfer data to Google LLC in the United States; this transfer relies on the EU-US Data Privacy Framework, under which Google is certified, and on Standard Contractual Clauses approved by the European Commission. For any other transfer outside the EEA, we ensure there is a European Commission adequacy decision or Standard Contractual Clauses in place. We can provide details of these safeguards on request.
8. Cookies and local storage
We use two categories of storage technologies on your device:
- Strictly necessary (no consent needed): the browser’s local storage (
localStorage) for your theme (rgs-theme) and cookie choice (rgs-consent). - Analytics (only with your consent): Google Analytics cookies (
_ga,_ga_*) and PostHog (ph_*), which show us how the site is used. Until you consent, these tools are not loaded at all and no information about your visit is sent to us. If you decline or later withdraw consent, we stop them and delete their cookies.
We do not use advertising or remarketing cookies. On your first visit we ask for your consent through a banner; you can change your choice at any time via the “Cookie preferences” link in the footer, or by clearing the site’s data in your browser settings.
9. How we protect data
We apply appropriate technical and organisational measures: encrypted connections (HTTPS), role-based access, secure authentication for internal systems and providers offering adequate security guarantees.
10. Your rights
Under the GDPR, you have the right to:
- access the data we hold about you;
- have inaccurate or incomplete data rectified;
- have your data erased (“right to be forgotten”);
- restrict processing;
- data portability;
- object to processing based on our legitimate interest;
- withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of prior processing.
To exercise these rights, write to [email protected]. We reply within one month of receiving your request; for complex requests this may be extended by two further months, in which case we will let you know.
11. Right to lodge a complaint
If you believe we process your data unlawfully, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 28-30 G-ral. Gheorghe Magheru Blvd., Sector 1, Bucharest, www.dataprotection.ro, or with the supervisory authority in your EU country of residence. We encourage you to contact us first so we can resolve the matter together.
12. Do you have to provide data?
No. Providing data is voluntary. Without a name and an email address (or phone number), however, we cannot reply to your request.
13. Children
Our site and services are aimed at companies and professionals. We do not knowingly collect data from anyone under 16.
14. Links to other sites
The site links to social networks (LinkedIn, Facebook, Instagram). These have their own privacy policies, for which we are not responsible. We recommend reading them.
15. Changes to this policy
We may update this policy to reflect legal changes or changes in how we process data. The current version is published on this page with the date of its last update. See also our Terms & Conditions.