This English text is provided for convenience. The authoritative version is the Romanian one and, in the event of any divergence, it prevails.
1Who we are and when this policy applies
1.1.The controller.Your personal data is processed by TECHCORNER S.R.L. (“4Tify”, “we”), with its office at str. Slt. Radu Teoharie, bl. D3, sc. B, et. 1, ap. 21, Târgu Neamț, Neamț county, 615200, Romania, VAT no. 51592659, Trade Register no. J2025025184003.
1.2.Data protection contact.For any question or request about your data, write to us at [email protected] or to our registered office, marked “Data protection”.
1.3.Scope.This policy covers the processing we carry out as a controller, when you: visit 4tify.io; create or use an account on the 4Tify platform; contact us for a quote or for support; subscribe to the newsletter or to newsroom alerts; or represent a client, a prospective client or a partner.
1.4.What it does not cover.This policy does not cover the personal data we process on behalf of our clients, as part of the security services (e.g. email addresses monitored on the Dark Web). For those, the client is the controller and the rules are set out in the Data Processing Agreement (Annex G to the Terms and Conditions). See Section 4.
1.5.Legal framework.We process data in accordance with Regulation (EU) 2016/679 (“GDPR”), Law no. 190/2018 and Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.
2What data we collect, and where from
2.1.Data you give us directly.
- Identification and contact data: first and last name, email, phone, job title, the company you represent.
- Account data: login email, password (stored only as a hash), two-factor authentication settings, preferences.
- Billing data: the company's name and tax details, billing address, contact person's details.
- The content of communications: messages sent through forms, by email or via support tickets.
- Communication preferences: the newsroom topics you subscribe to.
2.2.Data collected automatically.
- Technical and usage data: IP address, browser and device type, operating system, pages visited, date and time of access, actions taken in the platform (audit logs).
- Security data: authentication attempts, security events, session identifiers.
- Cookies and similar technologies, as described in Section 5.
2.3.Data received from third parties.
- from your employer / the 4Tify client, when they add you as a User on their account;
- from the Authorised Partners who refer us or broker offers;
- from the payment processor Stripe: confirmation and status of the payment (we do not receive the full card number);
- from public professional sources (company websites, trade registers), to verify our clients' identity.
2.4.Data we do not ask for.We do not ask you for special categories of data (health, ethnic origin, political opinions, religious beliefs and so on), data relating to criminal convictions, or your personal numeric code. Please do not send them to us.
3Why we use the data, on what basis, and how long we keep it
We use the data only for the purposes below, each with a legal basis under art. 6 GDPR.
| Purpose | Legal basis | How long we keep it |
|---|---|---|
| Creating and administering the account, providing the platform and the services | Art. 6(1)(b) – performance of the contract, or steps taken before entering into it | For the life of the account + 3 years (the general limitation period) |
| Quoting, negotiation and the commercial relationship with clients and partners | Art. 6(1)(b) or (f) – the legitimate interest in developing B2B relationships | 12 months from the last contact, if no contract is concluded |
| Invoicing, accounting and tax obligations | Art. 6(1)(c) – legal obligation (Law no. 82/1991, the Fiscal Code) | The periods required by accounting and tax legislation |
| Processing payments | Art. 6(1)(b) and (c) | As long as the legal obligations applicable to the transactions require |
| Technical support and operational communications (security alerts, service notices) | Art. 6(1)(b) | For the term of the contract + 2 years |
| Platform security, fraud prevention and prevention of abuse | Art. 6(1)(f) – the legitimate interest in protecting the platform and our clients | 12 months; longer only for incidents under investigation |
| Newsletter and newsroom alerts | Art. 6(1)(a) – consent | Until you unsubscribe or withdraw consent |
| Commercial communications to existing clients, about similar services | Art. 12(2) of Law no. 506/2004 and art. 6(1)(f) | Until you object (an unsubscribe link is in every message) |
| Statistics and improving the platform | Art. 6(1)(f), on aggregated or pseudonymised data | 24 months, then anonymisation |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) | Until final resolution and the lapse of the limitation period |
3.1.Legitimate interest.Where we rely on legitimate interest, we have assessed that the processing is necessary, proportionate and foreseeable for you in the context of a professional relationship, and that it does not disproportionately affect your rights. You can ask for details of that assessment and you can object at any time (Section 8).
3.2.Consent.Where processing is based on consent, you can withdraw it at any time, as easily as you gave it, without affecting the lawfulness of processing carried out beforehand.
3.3.Automated decisions.We do not take decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (art. 22 GDPR).
4Data processed on behalf of our clients
4.1.Our role.When a client orders security services from us (vulnerability scanning, pentest, code analysis, Deep/Dark Web monitoring, Attack Surface Management, bug hunting), we may process personal data belonging to their employees, users or customers. In those situations the client is the controller, we are the processor, and we process the data only on their instructions.
4.2.Examples.Your work email address may be checked against databases leaked on the Dark Web, at your employer's request. Your name may appear in the history of a code repository under analysis. Your data may be incidentally visible in an application being tested.
4.3.Safeguards.For this data:
- we process it strictly for the service ordered, not for our own purposes;
- we do not sell it and do not use it for marketing;
- we do not use client code or data to train AI models;
- passwords and sensitive data found in leaks are displayed only masked or as hashes;
- we do not buy stolen data and do not interact with malicious actors.
4.4.How to exercise your rights.If your data is processed in this context, address your request to the organisation that ordered the service (usually your employer). If you contact us directly, we forward the request to the client within 5 business days and assist them in answering you.
5Cookies and similar technologies
We use cookies in accordance with art. 4(5) of Law no. 506/2004: strictly necessary cookies are placed without consent, and all the others only after you give your agreement in the cookie banner.
| Category | Role | Consent | Indicative duration |
|---|---|---|---|
| Strictly necessary | Authentication, session, security (CSRF protection, anti-fraud), remembering your cookie choices | Not required | Session – 12 months |
| Payments | Operation of the Stripe components at checkout, fraud prevention | Not required (necessary for the transaction you requested) | As set by Stripe |
| Preferences | Language (RO/EN), theme, display settings | Yes | Up to 12 months |
| Analytics | Aggregated statistics on how the site is used | Yes | Up to 13 months |
| Marketing | Campaign measurement and remarketing | Yes | Up to 13 months |
5.1.Your control.You can accept, refuse or change your preferences at any time through the “Cookie settings” link in the site footer. Refusing optional cookies does not affect your access to the site or to the platform. You can also delete cookies from your browser settings.
5.2.The detailed list.The exact name, provider and duration of each cookie are shown in the cookie settings panel, updated whenever anything changes.
6Who we share data with, and international transfers
6.1.We do not sell your data.We share it only as far as necessary for the purposes in Section 3, with:
- infrastructure and hosting providers (servers, storage, backup, CDN);
- Stripe, for payment processing; Stripe acts as an independent controller for card data, under its own policy;
- email, communication and support providers;
- AI service providers, only for the features that use them, under contractual no-retention and no-training clauses;
- our accountant, auditors and legal advisers, bound by confidentiality;
- Authorised Partners involved in your offer or contract, for the contact data needed for the commercial relationship;
- authorities and public institutions, where the law obliges us or in order to defend our rights.
The providers that process data on our behalf have signed contracts compliant with art. 28 GDPR. The up-to-date list is available at 4tify.io/subprocesatori.
6.2.Transfers outside the EEA.As a rule, data is stored within the European Economic Area. If a provider processes it outside the EEA, the transfer takes place only on the basis of an adequacy decision of the European Commission (e.g. for Canada or, for certified providers, the EU-U.S. Data Privacy Framework) or of the standard contractual clauses approved by the Commission, with supplementary measures where appropriate. You can request a copy of the safeguards at the contact address.
6.3.Reorganisation.In the event of a merger, division or transfer of the business, the data may be passed to the successor, who will be bound to comply with this policy.
7How we protect the data
7.1.The measures we apply.We apply technical and organisational measures appropriate to the risk, in accordance with art. 32 GDPR, including:
- encryption of data in transit (TLS) and at rest;
- passwords stored only as hashes, with modern algorithms;
- two-factor authentication for users and mandatory multi-factor authentication for our own personnel;
- role-based access to data, strictly for the people who need it;
- logical separation of each client's data;
- access logging and monitoring of security events;
- encrypted backups and tested restore procedures;
- regular staff training and written confidentiality obligations.
7.2.Incidents.If a personal data breach occurs that presents a risk to your rights, we notify the ANSPDCP within 72 hours of becoming aware of it (art. 33 GDPR). If the risk is high, we inform you directly and without undue delay, explaining what happened and what you can do (art. 34 GDPR).
7.3.Your part.Keep your login details confidential, enable two-factor authentication and tell us immediately at [email protected] if you suspect unauthorised access to your account.
7.4.Reporting vulnerabilities.If you discover a vulnerability in the 4Tify platform, please report it responsibly to [email protected]. Do not exploit it and do not make it public before it is fixed.
8Your rights
| Right | What it means |
|---|---|
| Access (art. 15) | To find out whether we process your data and to receive a copy of it, together with information about the processing |
| Rectification (art. 16) | To correct inaccurate data or to complete it |
| Erasure (art. 17) | To ask for your data to be deleted, where it is no longer necessary, you have withdrawn consent or the processing is unlawful, subject to the exceptions provided by law |
| Restriction (art. 18) | To ask for processing to be limited while the accuracy of the data or an objection is being verified |
| Portability (art. 20) | To receive the data you provided in a structured, commonly used format, or to ask for it to be transmitted to another controller |
| Objection (art. 21) | To object to processing based on legitimate interest and, at any time, to marketing communications |
| Withdrawal of consent (art. 7) | To withdraw consent at any time, without affecting processing carried out beforehand |
| Complaint | To contact the ANSPDCP (www.dataprotection.ro) or the competent court |
8.1.How to exercise your rights.Send your request to [email protected] or in writing to our registered office. To protect your data, we may ask for additional information to confirm your identity.
8.2.Response time.We respond within one month of receipt. That period may be extended by a further two months for complex or numerous requests, and we will tell you within the first month (art. 12(3) GDPR).
8.3.Cost.Exercising your rights is free of charge. For manifestly unfounded or excessive requests, in particular repetitive ones, we may charge a reasonable fee or refuse the request, giving reasons.
8.4.Exceptions.Some data must be kept despite an erasure request — for example accounting records, or data needed to defend a legal claim. In that case we explain the reason to you.
9Minors, changes and contact
9.1.Minors.4Tify's services are aimed exclusively at professionals. We do not knowingly collect data relating to persons under 18. If we learn that we have received such data, we delete it.
9.2.Changes.We may update this policy when our services, our providers or the law change. The version in force is published on 4tify.io, with the date it was last updated. For significant changes, we notify account holders by email or in the platform before they take effect.
9.3.Contact.TECHCORNER S.R.L., str. Slt. Radu Teoharie, bl. D3, sc. B, et. 1, ap. 21, Târgu Neamț, Neamț county, 615200, Romania · [email protected].
9.4.Language version.This policy is available in Romanian and English. In the event of any discrepancy, the Romanian version prevails.
Questions about this document?
Write to us and a real person will answer — contract, data protection or scope.