Privacy Policy
This Privacy Policy explains how we collect, use, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and Romanian law.
Last updated: 03/09/2026
We collect information you provide directly to us and certain information automatically when you use our website and services.
Information You Provide
When you contact us or use our services, we may collect:
- Contact information (name, email address, phone number)
- Company information (company name, job title, industry)
- Communication records (inquiries, support requests)
- Demo and quotation requests (company, role, plant size, modules of interest)
- Any other information you choose to provide
Information Collected Automatically
When you visit our website, we automatically collect:
- Usage data (pages visited, time spent, referral sources)
- Device information (browser type, operating system)
- Analytics data through Google Analytics (with your consent)
- Cookie data as described in our Cookie Policy
Data processed inside a customer's Phasis deployment, such as production records, quality records, personnel and training records, is processed by that customer as controller, on their own infrastructure or on infrastructure dedicated to them. S.C. Phasis Engineering S.R.L. accesses such data only under a data processing agreement and on the customer's instructions, for support and maintenance purposes. This Privacy Policy covers this website and our direct communications with you. It does not cover the operation of a customer's Phasis deployment.
Where we act as a processor for a customer, a written data processing agreement governs that processing and prevails over this section. That agreement records, at a minimum, the following commitments.
Processing on instructions
We process customer plant data only on the customer's documented instructions, including for transfers of that data, unless required to do otherwise by European Union or Member State law. Where such a legal requirement applies, we inform the customer before processing unless the law forbids it. We do not use customer plant data for our own purposes, and we do not use it to train models or to build or improve products for other customers.
Confidentiality
Every person we authorise to process customer plant data is bound by a written confidentiality obligation that survives the end of their engagement with us. Access is granted to named individuals for a stated purpose, and withdrawn when that purpose ends.
Security of processing
We apply technical and organisational measures appropriate to the risk, as described in section 4 below and in the data processing agreement.
Sub-processors
We engage a sub-processor only under a written contract imposing the same data protection obligations we owe the customer, and we remain fully liable to the customer for that sub-processor's performance. We keep a current list of the sub-processors used for a customer's deployment, and we give the customer advance notice of any intended addition or replacement so that the customer can object. The list for a given deployment is available on request.
Assisting with data subject requests
Taking into account the nature of the processing, we assist the customer with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights, and in meeting the customer's own obligations on security, breach notification, data protection impact assessments and prior consultation.
Personal data breaches
We notify the customer of any personal data breach affecting their data, on the terms and within the time set out in the data processing agreement, so that the customer can meet its own notification obligations as controller.
Return and deletion
On termination of the services, the customer chooses whether their plant data is returned or deleted. We carry out that choice within 30 days and delete existing copies afterwards, unless European Union or Member State law requires us to keep them. We confirm completion in writing on request. Where a deployment runs on the customer's own server, the data is already under the customer's sole control and no return step arises.
Compliance and documentation
We make available to the customer the information necessary to demonstrate compliance with these obligations. In practice that means our security documentation and completed security questionnaires; the data processing agreement sets out the arrangements for audits and inspections.
We use your personal data for the following purposes, based on legitimate interests, contractual necessity, or your consent:
Service Provision
To respond to your inquiries, provide our services, and maintain our business relationship with you.
Website Improvement
To analyze website usage, improve our services, and enhance user experience through analytics and feedback.
Legal Compliance
To comply with applicable laws, regulations, and legal processes, including data retention requirements.
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction.
Security Measures Include:
- • Encrypted data transmission (SSL/TLS)
- • Access controls and authentication
- • Regular security assessments
- • Data minimization principles
- • Secure hosting infrastructure
Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but commit to promptly addressing any security incidents.
Measures Applied to Customer Deployments
Where we host a customer's Phasis deployment, that deployment runs on infrastructure dedicated to that customer within the European Union, never on hardware shared with another customer. Authentication, role-based authorisation and an append-only audit trail are built into the platform and cannot be switched off. Records subject to regulatory retention are never hard-deleted: corrections are written as new records beside the original. Encrypted transport applies to all connections. Access by our personnel is limited to named individuals under the data processing agreement and is itself recorded, and an update is installed only on a date the customer agrees. Where a deployment runs on the customer's own server, the customer controls the hosting environment and the measures applied to it.
We do not sell personal data, and we do not share it for anyone else's marketing. We disclose the data described in section 1 only to the categories of recipient below, and only as far as each needs it.
Hosting and delivery
Our website and its single form-handling function are hosted by Vercel Inc., which also provides the page performance measurement built into the site.
Email delivery
Messages you send through the contact form are delivered to us by Resend, which processes the contents of that message.
Bot protection
The contact form uses Google reCAPTCHA to tell people apart from automated submissions. Google receives request data for that purpose.
Analytics
Google Analytics, loaded through Google Tag Manager and only with your consent, as described in our Cookie Policy.
Professional advisers and authorities
Our accountants, auditors and lawyers, under a duty of confidence, and public authorities or courts where we are legally required to disclose.
Business transfers
If our business or part of it is merged, acquired or reorganised, personal data may pass to the acquirer. We would tell you before your data became subject to a different privacy policy.
Each of these providers acts as our processor under a written contract that permits them to process the data only for the purpose we set. Customer plant data is not shared with any of them; it is covered by section 2.
We are established in Romania and process personal data within the European Economic Area wherever we can. Some of the providers named in section 5 are established in the United States and may process data there or in other countries outside the EEA.
Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses, together with any additional safeguards the transfer requires, or on an adequacy decision covering the destination country where one applies. You may ask us for a copy of the safeguards we rely on, using the contact details below.
Customer plant data that we host stays within the European Union. A customer running Phasis on their own server determines the location of that data themselves.
As a data subject under GDPR, you have the following rights regarding your personal data:
Right of Access
Request information about the personal data we process about you and receive a copy of your data.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data under certain circumstances.
Right to Data Portability
Request your data in a structured, machine-readable format for transfer to another service.
Right to Object
Object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Right to Restriction of Processing
Ask us to limit what we do with your data while an objection or a question of accuracy is being resolved, or instead of deletion where you need the data kept for a legal claim.
Right to Withdraw Consent
Where we rely on your consent, such as for analytics cookies, withdraw it at any time. Withdrawal does not affect processing we carried out before you withdrew.
To exercise any of these rights, please contact us using the information below. We will respond to your request within 30 days as required by GDPR. Exercising these rights is free of charge.
You also have the right to lodge a complaint with a supervisory authority, in the Member State where you live, where you work, or where you believe the problem occurred. Ours is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, dataprotection.ro. We would rather you came to us first, but you do not have to.
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
Contact Information
Retained for 3 years after last contact or until you request deletion.
Demo and Quotation Requests
Retained for 3 years after last contact or until you request deletion.
Analytics Data
Automatically deleted after 26 months by Google Analytics.
Legal Records
Retained as required by Romanian law, typically 5-10 years for business records.
Phasis is an industrial platform sold to businesses, and this website is directed at people acting in a professional capacity. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
If you believe a child has given us personal data, contact us and we will delete it.
If you are a California resident, the California Consumer Privacy Act as amended gives you the right to know what personal information we collect about you and why, to receive a copy of it, to request its deletion, to request correction of inaccurate information, and not to be treated differently for exercising any of these rights.
We do not sell or share personal information as the CCPA defines those terms, and we do not process it for cross-context behavioural advertising, so there is no opt-out for you to exercise. To make any other request, contact us using the details below. We will verify the request against information we already hold, and you may use an authorised agent.
If you have any questions about this Privacy Policy, want to exercise your rights, or have concerns about how we handle your data, please contact us.