Privacy Policy
Last updated: 2 August 2026
NeuroAI Advance S.R.L. respects the privacy of its visitors and customers. This Privacy Policy explains what categories of personal data we collect, how we use them, who we share them with and what rights you have over them.
Our processing of personal data is governed by Regulation (EU) 2016/679 (GDPR), by Romanian Law (Legea) No. 190/2018 on measures implementing the GDPR in Romania and, where relevant, by applicable sector legislation (the Romanian Labour Code (Codul Muncii) for the OutOfDesk module, Law (Legea) No. 365/2002 on electronic commerce, Regulation (EU) 2024/1689 on artificial intelligence, and so on).
The policy applies to every point of contact accessible through https://neuroai.ro: browsing the public website, the contact form, the AI Readiness Calculator (lead magnet at /calculator-ai), purchases of PDF guides and other digital products, the OutOfDesk application and email correspondence.
This English version is provided for convenience. The Romanian version of this Privacy Policy is the official text; in the event of any divergence between the two language versions, the Romanian version prevails.
1. The data controller
Your personal data is processed by the controller identified below. The trading name used on the website ("NeuroAI Consulting") and the legal name of the company handling your data ("NeuroAI Advance S.R.L.") are one and the same entity — a single controller operating under two names.
- Legal name: NeuroAI Advance S.R.L.
- Trading name: NeuroAI Consulting
- Registered office: Str. Călugărului nr. 17, Sat Bălteni, Comuna Periș, jud. Ilfov, RO
- Tax ID (CUI): 54729441
- Trade Register number: J2026032931002
- Email: [email protected]
- Phone: +40 736 495 817
- Website: https://neuroai.ro
2. The dual role of NeuroAI Advance S.R.L. in processing
Depending on the service you use, NeuroAI Advance S.R.L. may act in two distinct capacities under the GDPR:
(a) Data Controller — for anonymous website visitors, people who submit the contact form or the AI Readiness Calculator, buyers of PDF guides and other digital products sold directly on the site, and for correspondence received by email. In these situations we alone determine the purposes and means of the processing.
(b) Data Processor — for employee data processed in the OutOfDesk application on behalf of employer customers, and also for B2B consulting, digital audit, automation or training projects in which, in the course of performing the contract, we come to access personal data held by the customer (employees, beneficiaries, leads or other data subjects). In these situations the Controller is the customer (the company engaging us), and NeuroAI Advance S.R.L. acts strictly on that customer's instructions. For every such B2B relationship, NeuroAI Advance S.R.L. signs a separate Data Processing Agreement (in international practice: Data Processing Addendum, "DPA") as required by art. 28 GDPR. The agreement is an annex required by law whenever one company processes personal data on behalf of another, and it sets out the exact protection rules.
This distinction matters: if you are an employee of a customer using OutOfDesk, or a data subject within a B2B project of NeuroAI Advance S.R.L., requests to exercise your GDPR rights should be addressed first to the Controller (your employer, or our customer respectively). NeuroAI Advance S.R.L. can assist you, but the legal basis and the final decisions belong to the Controller.
3. The categories of personal data we process
3.1. Data collected automatically while browsing
- IP address (used for security; anonymised for analytics)
- Browser type, operating system, screen resolution, preferred language
- Pages visited, time spent on pages, traffic source (referrer)
- Cookie information (details in the dedicated section)
3.2. Data from the contact form
When you submit the contact form on the /contact page, we collect:
- First and last name
- Email address
- Phone number (optional)
- Company name
- Field of activity / company profile
- Number of employees
- Your objectives (free text — what you want to learn or automate)
- Indicative budget (optional)
- Desired timeline (optional)
- Technical context data attached to the submission: IP address, browser user agent and timestamp — kept on the basis of legitimate interest, for security, spam prevention (Cloudflare Turnstile) and proof of submission
3.3. Data from the AI Readiness Calculator
The AI Readiness Calculator is a free assessment tool available at https://neuroai.ro/calculator-ai. When you complete it and ask for the result to be sent by email, we collect:
- First and last name
- Email address (used to send you the result and for follow-up from our team)
- Company name (optional)
- Free-text message (optional)
- The profile chosen (Company or Individual) and the answers to the 12 questions (these may include field of activity, approximate number of employees, automation objectives, tools in use, indicative budget)
- The calculated score and the AI maturity level assigned on the basis of your answers
- Technical context data: page URL, traffic source (referrer), IP address, browser user agent, timestamp
The scoring and the insights are generated by a deterministic, rule-based algorithm, NOT by a generative AI model — see the section "Artificial intelligence and your data" for details. The result is shown to you in the interface immediately and, if you requested it, is also sent as an email to [email protected] so that our team can follow it up.
3.4. Data from purchases of PDF guides and other digital products
- First and last name
- Email address (for delivering the product and issuing the invoice)
- Billing details as required by tax legislation
- Order history and downloaded products
- Card details are NOT stored by NeuroAI Advance S.R.L. — they are processed directly on the Stripe platform (see the Recipients section)
3.5. Data from use of the OutOfDesk application (B2B customers)
For the employer customer:
- Company name, tax ID (CUI), admin email, number of employees, subscription plan
- Payment and invoice history
For employees (processed on behalf of the employer)
OutOfDesk does not request and does not process special categories of data within the meaning of art. 9 GDPR (health data, political or religious beliefs, or data of any other sensitive nature). If an employer enters such data into a free-text field (for example, the reason for medical leave), legal responsibility rests solely with the employer.
- First name, last name, work email, role / department
- Leave requests (type, period, optional reason, approval status)
- The history of approvals/rejections and of the approvers involved
- The team-level absence calendar
3.6. Data from email correspondence
Any information you send us by email at [email protected], or in reply to our transactional messages, is stored in the email service until the purpose of the communication has been fulfilled, after which it is archived in line with our retention policy.
4. Purposes and legal bases of processing
We process personal data on the following legal bases, in accordance with art. 6 GDPR:
4.1. Performance of a contract or pre-contractual steps (art. 6 para. 1 letter b GDPR)
- Processing orders for PDF guides and other digital products
- Delivering digital products by email (download link or attachment)
- Operating your account in the OutOfDesk application (if you are a B2B customer)
- Responding to enquiries submitted through the contact form
- Sending the AI Readiness Calculator result when you explicitly request it, and follow-up from our team based on your manifest intention to evaluate NeuroAI Advance S.R.L. services (a pre-contractual step)
4.2. Compliance with legal obligations (art. 6 para. 1 letter c GDPR)
- Issuing invoices and keeping accounting records (the Accounting Law (Legea) No. 82/1991, the Romanian Fiscal Code)
- Responding to requests from competent public authorities (ANAF — the National Agency for Fiscal Administration, ANSPDCP — the National Supervisory Authority for Personal Data Processing, courts of law)
- Complying with GDPR obligations (records of processing activities, data breach notification, responding to data subject rights)
4.3. Legitimate interest (art. 6 para. 1 letter f GDPR)
- Securing the website, the backend and our applications (preventing attacks, detecting fraud, protecting system integrity — including bot protection via reCAPTCHA Enterprise and error monitoring via Sentry)
- Statistical traffic analysis to improve our services (anonymised where technically possible)
- Transactional follow-up in the relationship with active customers (status notifications, messages relating to contracts in progress)
- Defending against potential legal disputes and recovering receivables
For every processing activity based on legitimate interest we have carried out a balancing test and concluded that our legitimate interests are not overridden by the rights and freedoms of the data subjects. You have the right to object to this processing at any time (see the section on Your rights).
4.4. Consent (art. 6 para. 1 letter a GDPR)
- For placing non-essential cookies (analytics, marketing)
- For sending the NeuroAI newsletter, upon explicit subscription through the form on the website (double opt-in: the subscription becomes active only after confirmation via the email you receive)
- For any processing that goes beyond the initial purposes, communicated separately
Consent can be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal. The main mechanism: click the "Cookie preferences" link in the footer of any page — the banner reappears showing your current choice and you can change it with one click. Alternatively, delete the site's cookies from your browser and the banner will reappear on your next visit. As a last resort, you can request the withdrawal in writing at [email protected].
For the newsletter, consent is withdrawn with one click on the "Unsubscribe" link in the footer of any edition — with immediate effect. Alternatively, you can write to us at [email protected].
4.5. Special note — employee data in OutOfDesk
For employee data processed in OutOfDesk on behalf of the employer, the employee's consent is NOT a valid legal basis. The employment relationship involves a power imbalance between employer and employee, and the practice of the Romanian supervisory authority (ANSPDCP) confirms that the correct basis is the performance of the employment contract (art. 6 para. 1 letter b GDPR) or the employer's legal obligation to keep records of working time (art. 6 para. 1 letter c GDPR, read together with art. 119 of the Romanian Labour Code). Responsibility for establishing the correct legal basis rests entirely with the employer customer.
5. Recipients of the data (sub-processors and third parties)
We do NOT sell, rent or transfer your personal data to third parties for commercial purposes. We disclose data strictly to the providers that enable us to operate, and to public authorities upon documented legal requests.
Our current sub-processors are:
- Stripe (Stripe Payments Europe Limited, Dublin, Ireland; with secondary processing by Stripe, Inc., United States, certified under the EU-U.S. Data Privacy Framework) — processes online card payments for the PDF guides and OutOfDesk subscriptions. Stripe receives card details directly from the buyer (Stripe Elements embedded in the checkout pages); NeuroAI Advance S.R.L. neither receives nor stores those details. Stripe acts as an independent Controller for banking compliance (PCI-DSS Level 1 certified), anti-fraud and anti-money-laundering obligations. Details: https://stripe.com/privacy
- Oblio Software S.R.L. (Romania) — automatic issuing of electronic tax invoices and their transmission to SPV/ANAF (the Romanian tax authority's system) through the native Stripe integration on the payment flow. Receives: name, billing details, order value and product description. Details: https://www.oblio.eu/termeni
- Resend (Resend, Inc., United States) — delivers transactional emails (order confirmations, download links for PDF guides, OutOfDesk notifications, AI Readiness Calculator results, replies to leads) and the newsletter editions; Resend also stores the subscriber list (email address and subscription status) and operates the unsubscribe link
- Cloudflare (Cloudflare, Inc., EU infrastructure for this application) — hosts the website front-end and the related serverless functions (DNS, CDN, firewall, DDoS protection, Pages Functions and the KV store for the cookie consent audit trail)
- Render (Render Services, Inc., United States) — hosts the backend API for the contact form and other server-side functions
- Firebase / Google Cloud (Google LLC, United States) — hosts the backend of the OutOfDesk application (authentication, the Firestore database, serverless functions, file storage)
- Google Analytics 4 (Google LLC, United States) — anonymised traffic analysis, with Google Consent Mode v2 in Advanced mode (see section 7.2 for details)
- Google reCAPTCHA Enterprise (Google LLC, United States) — bot protection for the OutOfDesk application, via Firebase App Check. Collects technical signals (IP address, device signature, browser interactions) to distinguish real users from bots
- Sentry (Functional Software, Inc. d/b/a Sentry, EU infrastructure for NeuroAI Advance S.R.L. projects) — collects error and performance reports from the OutOfDesk application and from the backend functions (URL, error message, stack trace, user agent, request identifier and, where applicable, an anonymised user identifier). Used exclusively for debugging and operational monitoring
- Competent public authorities (ANAF, ANSPDCP, courts, Police) — exclusively upon documented legal requests
The complete, up-to-date list of sub-processors, together with their processing locations and GDPR certifications, can be requested at any time at [email protected].
6. Transfers of data outside the European Union
Some of the service providers listed above (Google LLC for Firebase / Analytics / reCAPTCHA Enterprise, Resend, Render) are established in the United States. Cloudflare is a US company, but for this application we use its European Union infrastructure; Sentry likewise runs on EU infrastructure for our projects. Stripe processes payments through Stripe Payments Europe Limited (Ireland), with primary data held in the European Union; part of the fraud processing and support may be replicated at Stripe, Inc. (USA), certified under the EU-U.S. Data Privacy Framework. Oblio is a Romanian company and billing data remains in Romania. For transfers that leave the EU, NeuroAI Advance S.R.L. relies on the appropriate safeguards provided for by the GDPR:
- Standard Contractual Clauses (SCC) approved by the European Commission through Implementing Decision (EU) 2021/914
- The EU-U.S. Data Privacy Framework, for DPF-certified providers (Google LLC is DPF-certified)
- Additional technical measures: encryption in transit (TLS 1.2+), encryption at rest for sensitive data, role-based access control
For OutOfDesk, Firebase authentication data and part of the operational data may be stored on Google servers in the United States, with the safeguards described above. Some Firebase services (Authentication, Analytics) do not yet offer storage exclusively within the European Union; NeuroAI Advance S.R.L. will update this policy as those options become available.
You can request full details about the storage locations of each category of data by writing to [email protected].
8. How long we keep the data
We keep personal data strictly for as long as necessary for the purposes for which it was collected, or for as long as the law requires:
- Contact form data: 24 months from the last interaction, then automatic deletion
- Leads and answers from the AI Readiness Calculator: 24 months from submission, then automatic deletion (or immediately upon request)
- Orders, invoices and other accounting documents: for the period required by tax and accounting legislation
- Active OutOfDesk account: for the whole duration of the subscription, plus 30 days for data export after termination
- Deactivated OutOfDesk account: complete deletion 30 days after termination, except for data kept to meet legal obligations (invoices)
- Website and backend access logs: maximum 6 months
- Analytics data (Google Analytics 4): maximum 14 months
- Sentry error reports: maximum 90 days
- Cookie consent audit trail: 30 months (see 7.4)
- Newsletter subscription: until you unsubscribe (the address remains flagged "unsubscribed" so that your choice is respected); proof of consent is kept for 30 months from confirmation
- Email correspondence: until the purpose of the communication has been fulfilled, then archived for a maximum of 36 months
After these periods expire, the data is irreversibly deleted or, where technically more appropriate, fully anonymised (so that it can no longer be associated with an identifiable person).
9. Your rights under the GDPR
You have the following rights, exercisable free of charge upon a simple written request by email to [email protected]:
- The right of access (art. 15 GDPR) — to find out what personal data we hold about you, the purposes of processing, the recipients and the retention period, and to receive a copy
- The right to rectification (art. 16 GDPR) — to have inaccurate or incomplete data corrected
- The right to erasure / the "right to be forgotten" (art. 17 GDPR) — under the conditions provided by law
- The right to restriction of processing (art. 18 GDPR) — in specific situations (e.g. you contest the accuracy of the data)
- The right to data portability (art. 20 GDPR) — to receive your data in a structured, commonly used and machine-readable format (CSV, JSON)
- The right to object (art. 21 GDPR) — for processing based on legitimate interest and for direct marketing
- The right not to be subject to automated decision-making (art. 22 GDPR) — NeuroAI Advance S.R.L. does not make solely automated decisions producing legal effects
- The right to withdraw consent — at any time, without affecting the lawfulness of processing carried out before the withdrawal
- The right to lodge a complaint with the supervisory authority
We respond to requests within 30 calendar days, with a possible extension of up to 60 further days for complex requests, in accordance with art. 12 para. 3 GDPR.
The supervisory authority in Romania: the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, email [email protected], website www.dataprotection.ro.
10. Data security
We implement technical and organisational measures proportionate to the risk in order to protect personal data against unauthorised access, loss, alteration or destruction:
- TLS 1.2+ encryption on all connections between the client, the front-end, the backend and the sub-processors
- Encryption at rest for the OutOfDesk database (Firestore) and for file storage
- Role-based access control and strong-password authentication for administrators
- Regular backups of operational data, tested for restore
- Monitoring of access logs and of abnormal behaviour
- Data breach notification procedure: assessment within 24 hours, notification to the ANSPDCP within a maximum of 72 hours where a risk is present, notification of the data subjects where the risk is high (arts. 33-34 GDPR)
No method of transmission over the Internet or of electronic storage is 100% secure. We make commercially reasonable efforts to protect the data, but we cannot guarantee absolute security. In the event of a security breach affecting us, you will be notified in accordance with our legal obligations.
11. Artificial intelligence and your data
NeuroAI Advance S.R.L. is an artificial intelligence consultancy and we ourselves use AI models in our day-to-day work. To stay consistent with our public positioning and with the transparency requirements of Regulation (EU) 2024/1689 (the EU AI Act, art. 50 applicable from 2 August 2026), we state explicitly what we do and do not do with your data.
11.1. What we do NOT do with your data
- We do not use personal data collected through the website, the contact form, the AI Readiness Calculator or email correspondence as training data for our own or third-party AI models
- We do not send personal data to external language models (ChatGPT, Claude, Gemini, Copilot, etc.) without a separate written agreement with you or with your employer
- We do not run automated profiling that produces legal effects concerning you or similarly significantly affects you (art. 22 GDPR)
- We do not sell profiles, AI scores, insights or other data derivatives to third parties
11.2. What we do with AI internally
- We use AI assistants (LLMs) for research, drafting proposals, writing technical articles and managing internal workflows, working on public data or on our own company's internal data — not on your personal data
- The AI Readiness Calculator uses a deterministic, rule-based scoring algorithm, NOT a generative AI model — your answers are scored against an internally documented grid, and the insights displayed are generated from those scores, with no call to any external LLM
- In custom B2B consulting, audit or training projects where the work involves sending data to an external AI model (for example, automation on your own data), we first sign a separate Data Processing Agreement and operate strictly on your written instructions (Processor role, art. 28 GDPR — see section 2)
11.3. Compliance with the EU AI Act
Art. 50 of the EU AI Act (transparency of interactions with AI systems, labelling of AI-generated or AI-manipulated content, disclosure of deepfakes) applies from 2 August 2026. NeuroAI Advance S.R.L. applies the following measures:
- Technical articles published at https://neuroai.ro/ai-news that include passages generated or substantially assisted by AI are explicitly labelled as such, under human editorial oversight
- If we activate a chatbot or a conversational AI assistant on the website, you will be clearly informed before the first interaction that you are talking to an AI system and not to a person
- Our scoring or decision-support systems do not make automated decisions producing legal effects concerning you without documented human validation
12. Minors
NeuroAI Advance S.R.L. services are not intended for persons under 16. We do not knowingly collect personal data from minors. If you become aware that a minor has sent us personal data, contact us at [email protected] for immediate deletion.
For OutOfDesk, used in a professional B2B context, compliance with the legal minimum working age (15 for light work with parental consent, 16 for full employment, under the Romanian Labour Code) rests entirely with the employer customer.
13. Changes to this policy
We reserve the right to update this Privacy Policy to reflect changes in legislation or in our practices. Any substantial change will be notified through:
- A visible notice on the website on your first visit after the change
- An email to users with an active OutOfDesk account or with recent orders of digital products
- An update of the "Last updated" date in the page header
Previous versions of the policy are available on request at [email protected]. We encourage you to check this page periodically to stay informed about changes.
14. Contact
For any question about the processing of personal data, to exercise your GDPR rights or to report a data protection issue, you can reach us via:
- Email: [email protected]
- Phone: +40 736 495 817
We respond to every request within the statutory period of 30 calendar days, with a possible extension of a further 60 days for complex requests, in accordance with art. 12 para. 3 GDPR. For requests received at [email protected], receipt is confirmed within a maximum of 48 working hours.
If you are not satisfied with our answer, you always have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru nr. 28-30, Sector 1, 010336 Bucharest, email [email protected], website www.dataprotection.ro.
This policy reflects the current practices of NeuroAI Advance S.R.L. and is updated as our products and sub-processors evolve. Previous versions of the policy are available on request at [email protected].