Privacy policy
Information for data subjects in accordance with Regulation (EU) 2016/679 on the protection of personal data (GDPR).
Last updated: 8 August 2026
English translation, provided for convenience. The binding version of this privacy policy is the Romanian one, published at www.powergrid-solution.ro/legal/confidentialitate. In case of any discrepancy between the two texts, the Romanian version prevails.
This policy explains how S.C. POWERGRID SOLUTION S.R.L. collects and processes the personal data of the persons who use the website www.powergrid-solution.ro and its contact form. The policy complies with Regulation (EU) 2016/679 (GDPR), Law no. 190/2018 on the implementation of the GDPR in Romania and Law no. 506/2004 on the processing of personal data in the electronic communications sector.
1. The data controller
The controller of the personal data is S.C. POWERGRID SOLUTION S.R.L., with its registered office at Str. Costea Voda nr. 20, etaj 1, Valea Adanca, com. Miroslava, jud. Iasi, CUI (registration code) RO50072089, Trade Register J2024001661220.
Requests concerning data protection may be sent to [email protected] or to the general address [email protected]. The company has not been required to appoint a data protection officer within the meaning of Art. 37 GDPR, but it has set up a dedicated address for the requests of data subjects.
2. Categories of data collected
Through the contact form, the user voluntarily submits:
- first name and surname;
- e-mail address;
- telephone number;
- the name of the company they represent;
- the content of the message and of the request (description of the project, location, capacities, deadlines).
Automatically, at the moment the request is submitted, the system also records the following associated technical data: the page from which the request was sent, the interface language, the source the visitor came from (the marketing channel or referrer), the date and time of sending, the IP address used for the transmission. This data is used for security, for preventing abuse and for improving the response process.
Separately from the contact form, if the visitor gives consent in the cookie banner, the PostHog analytics tool collects: a pseudonymous identifier of the visitor and of the session, the pages visited and the order in which they were visited, the source of the visit (referrer or marketing channel), the interface language, the type of device, the operating system and the browser, the IP address and the approximate country, region or city derived from it, together with the diagnostics of application errors (the error message, the page and the technical context in which it occurred). Without consent none of this is collected, and the analytics library is not even loaded in the browser.
3. Purposes of the processing and legal basis
| Purpose | Legal basis |
|---|---|
| Answering a request for a quotation or a request for information | Art. 6 (1) (b) GDPR: steps taken prior to entering into a contract, at the request of the data subject |
| Internal record of requests in the PowerGrid AI CRM system | Art. 6 (1) (f) GDPR: legitimate interest of the company in managing the commercial relationship |
| Subsequent commercial communications (newsletter, thematic offers) | Art. 6 (1) (a) GDPR: express consent of the data subject, withdrawable at any time |
| Performance of the service contracts concluded with the beneficiaries | Art. 6 (1) (b) GDPR: performance of the contract |
| Fulfilment of tax, accounting and archiving obligations | Art. 6 (1) (c) GDPR: legal obligation (Accounting Law no. 82/1991 and the subsequent acts) |
| Security, prevention of abuse, technical logging | Art. 6 (1) (f) GDPR: legitimate interest in the security of the systems |
| Product analytics and automatic capture of application errors, through PostHog | Art. 6 (1) (a) GDPR: explicit consent of the visitor, given in the cookie banner and withdrawable at any time |
4. Recipients and processors
The data is accessed by the authorised personnel of PowerGrid Solution. In its current activity, the company works with the following categories of processors, on the basis of processing agreements in accordance with Art. 28 GDPR:
- Supabase, for hosting the database of the PowerGrid AI platform (infrastructure within the EU);
- Hetzner Online GmbH, for hosting the applications and the web interfaces (data centres in Germany, EU);
- Resend, for the delivery of transactional e-mails (provider with infrastructure partly in the USA);
- PostHog, Inc., 2261 Market St. #4008, San Francisco, CA 94114, United States of America, for product analytics and for the automatic capture of application errors, on the basis of consent only. Collection runs through the PostHog Cloud EU instance (eu.i.posthog.com), with storage in the European Union, on Amazon Web Services infrastructure in Frankfurt, Germany (the eu-central-1 region);
- IT service providers, legal, accounting or audit consultants, under strict confidentiality clauses;
- public authorities, where there is a legal obligation to disclose.
The data is not sold and is not passed on to third parties for marketing purposes without the express consent of the data subject.
5. Retention periods
- requests that did not lead to a contract: maximum 36 months from the last relevant interaction, after which they are anonymised or deleted;
- contractual clients: for the duration of the contract and thereafter 10 years from its termination, on the basis of tax and accounting obligations;
- technical security logs: maximum 12 months, depending on the nature of the log;
- data processed on the basis of consent for commercial communications: until the consent is withdrawn;
- analytics and error data collected through PostHog, on the basis of consent: maximum 12 months from the collection of the event, after which it is deleted; when consent is withdrawn the collection stops immediately and the cookies and the locally stored data are deleted from the browser;
- the record of the consent given in the cookie banner (version, date and time, categories accepted): 12 months, after which the choice is asked for again.
6. International transfers
As a rule, the data is processed within the European Economic Area. Where a processor also operates outside the EEA, in particular for transactional e-mail through Resend, the transfer takes place on the basis of the Standard Contractual Clauses adopted by Decision (EU) 2021/914 of the European Commission and of the supplementary technical and organisational measures imposed on the provider (encryption, access control, logging).
Product analytics through PostHog likewise involves a transfer to a third country. The data collected through the PostHog Cloud EU instance is stored in the European Union, on Amazon Web Services infrastructure in Frankfurt, Germany (the eu-central-1 region), but the processor is PostHog, Inc., a company established in the United States of America, whose staff may access the data from the United States. Storage within the European Union does not remove that access, so Chapter V of the GDPR remains applicable. The transfer takes place primarily on the basis of the EU-U.S. Data Privacy Framework, in which PostHog, Inc. is an active participant, under the adequacy decision adopted by the European Commission on 10 July 2023; in the alternative, and should that decision cease to have effect, the transfer takes place on the basis of the Standard Contractual Clauses adopted by Decision (EU) 2021/914 of the European Commission, Module 2 (controller to processor), supplemented by additional technical and organisational measures (encryption in transit and at rest, access control, logging and minimisation of the data collected). This transfer occurs only after consent has been given for the analytics cookies and it ends when that consent is withdrawn.
7. Rights of the data subject
Under the GDPR, the data subject has the following rights:
- the right of access to the processed data (Art. 15);
- the right to rectification of inaccurate data (Art. 16);
- the right to erasure of the data (Art. 17), in the situations provided for by the regulation;
- the right to restriction of processing (Art. 18);
- the right to be informed of the recipients to whom the rectification, erasure or restriction of the data has been communicated, the notification obligation resting with the controller (Art. 19);
- the right to data portability (Art. 20);
- the right to object to processing based on legitimate interest (Art. 21);
- the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject (Art. 22); PowerGrid Solution takes no such decisions;
- the right to withdraw consent at any time, without affecting the lawfulness of the processing carried out beforehand (Art. 7 (3));
- the right to lodge a complaint with the supervisory authority (Art. 13 (2) (d) and Art. 77).
In order to exercise these rights, the data subject may send a request to [email protected]. The response is provided within 30 days, with the possibility of an extension by a further two months in the case of complex requests, in accordance with Art. 12 GDPR.
8. Data security
PowerGrid Solution applies technical and organisational measures appropriate to the risk of the processing, among which: encrypted TLS connections, authentication with strong passwords and multi-factor authentication for the personnel with access, access control policies based on the need-to-know principle, logical separation of the data in the Supabase database through Row Level Security, logging of critical operations, periodic backups and internal incident response procedures.
9. Cookies
Detailed information about the cookies used on the website is available in the cookie policy.
10. Changes to the policy
This policy may be updated to reflect legislative, organisational or technical changes. The version in force is always the one published on this page, together with the date of the last update.
11. Contact and complaints
For notifications or requests concerning personal data:
S.C. POWERGRID SOLUTION S.R.L.
Str. Costea Voda nr. 20, etaj 1, Valea Adanca, com. Miroslava, jud. Iasi
E-mail: [email protected]
Telephone: +40 742 896 137
If the data subject considers that their rights have been infringed, they may lodge a complaint with the competent authority:
Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP) — the Romanian supervisory authority for the protection of personal data
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, postal code 010336, Bucuresti
Telephone: +40 318 059 211 / +40 318 059 212
Fax: +40 318 059 602
E-mail: [email protected]