Privacy Policy
Last updated: 7 August 2026
This policy explains how personal data is handled across everything re:solved operates: our website, the mobile and platform applications we publish, and the AI agents we build and run for our clients.
It is written to be read, not to be survived. If anything here is unclear, email us at contact@re-solved.digital and we will explain it in plain terms.
1. Who we are
RE SOLVED DIGITAL SRL ("re:solved", "we", "us")
- Registered office: Str. Suceava nr. 7, cam. 1, 300015 Timișoara, Timiș County, Romania
- Trade Register number: J2024000794350
- Unique Registration Code (CUI): 49655070
- EUID: ROONRC.J2024000794350
- Contact for any privacy matter: contact@re-solved.digital
We are established in Romania and process personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian law.
2. Two different roles — read this first
re:solved handles personal data in two fundamentally different capacities. Which one applies determines who is responsible and who you should contact.
We are the controller when we decide why and how data is processed. This covers visitors to our website, people who contact us, our own clients and their staff contacts, and users of applications we publish for our own purposes. Section 3 applies.
We are the processor when we operate an AI agent on behalf of a business client. That client — the shop, clinic, law firm, installer or agency you are actually dealing with — decides why and how your data is processed. We act on their documented instructions. Section 4 applies.
One thing worth being explicit about: because re:solved publishes client-facing applications under its own developer accounts on the Apple App Store, Google Play and Meta platforms, we may appear as the publisher of an application whose data is controlled by our client. Being the publisher of record does not make us the controller of that data. Section 4 explains what this means for you in practice.
3. When re:solved is the controller
3.1 Website visitors
What we collect. Pages viewed, approximate location derived from IP address, device and browser type, referring source, and interaction data such as clicks and scroll behaviour. This comes from Google Analytics and Microsoft Clarity, which we use to understand how the site is used and where it is confusing. Microsoft Clarity records session replays and heatmaps.
Legal basis. Your consent, given through our cookie banner. Analytics and session-recording cookies are not set unless you accept them, and you can withdraw consent at any time through the cookie settings link in our footer. See Section 8.
Retention. Analytics data is retained for 14 months from collection.
3.2 People who contact us or book an audit
What we collect. Your name, email address, phone number, company name, and whatever you choose to tell us about your business and its operational problems — including anything you send us in a booking form, by email, or during an audit call.
Legal basis. Steps taken at your request prior to entering a contract (Art. 6(1)(b) GDPR), and our legitimate interest in responding to business enquiries and keeping a record of them (Art. 6(1)(f)).
Retention. 24 months from our last meaningful contact, unless the enquiry becomes a contract.
3.3 Clients and their staff contacts
What we collect. Contact details of the people we work with at a client business, correspondence, contractual and billing information, and the operational information needed to scope and run a deployment.
Legal basis. Performance of a contract (Art. 6(1)(b)), compliance with our legal obligations under Romanian accounting and tax law (Art. 6(1)(c)), and our legitimate interest in managing the relationship (Art. 6(1)(f)).
Retention. For the duration of the contract, then for the period required by Romanian accounting and tax legislation — currently 5 years for supporting accounting documents and 10 years for financial statements. Other correspondence is deleted within 3 years of the relationship ending.
3.4 Applications we publish for our own purposes
Where we publish an application under our own name and for our own purposes, the data we collect is limited to what the application needs to function — typically account identifiers, contact details and usage diagnostics. Any such application will state, at the point of collection, what it collects and why.
3.5 What we do not do
We do not sell personal data. We do not share it with advertising networks or data brokers. We do not use the content of client deployments to train AI models — ours or anyone else's — and we do not build cross-client datasets.
4. When re:solved is the processor: agents operated for clients
This section applies if you are a customer, patient, candidate, supplier or other contact of a business that uses an AI agent we built and operate.
4.1 You are dealing with our client, not with us
The business you are communicating with is the controller of your data. They decided to deploy the agent, they decide what it does, and they are responsible for having a lawful basis to contact you and to process your information. We process it on their instructions under a written data processing agreement that meets Article 28 GDPR.
4.2 You are talking to software
Where you interact with one of our agents by message, chat or email, you are interacting with an AI system, not a person. We require this to be disclosed at the point of contact, and every agent we operate provides a route to reach a human at the client business.
4.3 What the agent handles
Depending on the deployment, an agent may process:
- Contact details — name, phone number, email address
- Message content — the substance of WhatsApp, chat or email conversations, including anything you volunteer in them
- Operational records — bookings, appointments, enquiries, quotes, invoices and order references
4.4 Special category data
Some of our clients operate in healthcare, legal and other regulated fields. In those deployments, an agent may come into contact with special category data under Article 9 GDPR — for example health information you mention when booking an appointment — or with confidential legal information.
Where this happens:
- The client, as controller, is responsible for establishing a valid Article 9 condition (typically explicit consent, or a healthcare-related condition under Art. 9(2)(h)).
- We treat such deployments as elevated-risk: they run on infrastructure we control in the EU or on the client's own premises, with restricted access, and we require the client to complete a Data Protection Impact Assessment before go-live.
- We do not process special category data through third-party AI model providers unless the client has specifically instructed us to and the arrangement is documented in the data processing agreement.
Please do not send us sensitive information you do not need to share. An agent handling a booking rarely needs your diagnosis.
4.5 Exercising your rights against a client deployment
Send your request to the business you are dealing with — they are the controller and they hold the decision. If you send it to us instead, we will forward it to them without undue delay and tell you that we have done so. We cannot delete or disclose a client's data on our own initiative.
5. Where data is stored and who else touches it
5.1 Hosting and infrastructure
Agent deployments run on infrastructure we operate in Romania and elsewhere in the European Union, or — where the client chooses the self-hosted option — on the client's own hardware, in which case the data never leaves their building.
5.2 AI model providers
This depends on the deployment, and it is a decision made per client:
- Self-hosted models. Some deployments run entirely on local models on infrastructure we or the client control. In those deployments, message content is not sent to any external AI provider.
- Third-party model providers. Other deployments call external AI services (such as OpenAI, Anthropic or Google) to generate responses. Where this is the case, message content is transmitted to that provider for the purpose of producing a reply. We contract with these providers on terms that prohibit the use of submitted data for model training, and where the provider is outside the EEA we rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
Clients are told which configuration applies to their deployment before go-live, and it is recorded in the data processing agreement.
5.3 Other recipients
| Recipient | Purpose | Location / safeguard |
|---|---|---|
| Google Ireland Ltd. (Google Analytics) | Website analytics | EU; onward transfers to the US under the EU–US Data Privacy Framework |
| Microsoft Ireland Operations Ltd. (Clarity) | Website session replay and heatmaps | EU; onward transfers to the US under the EU–US Data Privacy Framework |
| Meta Platforms Ireland Ltd. | WhatsApp Business Platform and Meta developer services, where a deployment uses them | EU; onward transfers under the EU–US Data Privacy Framework |
| Apple Inc. / Google LLC | App distribution, where we publish an application on their stores | US; EU–US Data Privacy Framework |
| Hosting, email delivery and productivity providers | Operating our own systems | EU, or safeguarded by Standard Contractual Clauses |
| Our accountants and, where necessary, legal advisers | Statutory and professional obligations | Romania |
We also disclose data where we are legally required to — for example to a court or a competent authority acting within its powers.
5.4 International transfers
Our default is that data stays in the EU. Where a transfer outside the EEA is unavoidable — principally to a third-party AI model provider or an app-store operator — we rely on an adequacy decision or on Standard Contractual Clauses, together with additional technical measures where the risk assessment calls for them. You can request a copy of the relevant safeguards from us.
6. Security
We apply access controls on a need-to-know basis, encryption in transit and at rest, separation between client environments, logging of administrative access, and regular review of who holds credentials. Deployments involving special category data are additionally isolated.
No system is perfectly secure, and we will not claim otherwise. If a personal data breach affecting our own controller-side processing occurs, we will notify the Romanian supervisory authority within 72 hours where the law requires it, and notify you directly where the breach is likely to result in a high risk to your rights. Where the breach concerns a client deployment, we notify the client without undue delay and support them in meeting their own obligations.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you and receive a copy
- Rectify data that is inaccurate or incomplete
- Erase your data where one of the grounds in Art. 17 applies
- Restrict processing in the circumstances set out in Art. 18
- Data portability — receive data you provided in a structured, machine-readable format
- Object to processing based on legitimate interests, including profiling
- Withdraw consent at any time, without affecting processing carried out before withdrawal
- Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not make such decisions.
To exercise any of these, email contact@re-solved.digital. We respond within one month, extendable by two further months for complex requests, in which case we will tell you why. There is no charge unless a request is manifestly unfounded or excessive.
Deleting your data from an application we publish. If you use an application we publish and want your account and associated data deleted, email contact@re-solved.digital with the subject line "Data deletion request" and the account identifier. Where we are the controller, we action it within 30 days. Where the application belongs to a client deployment, we forward the request to the controller within 5 working days and confirm to you that we have.
Complaints. You can lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, www.dataprotection.ro — or with the supervisory authority in your own country of residence. We would rather you came to us first, but that is your choice, not a condition.
8. Cookies and similar technologies
Our website uses:
- Strictly necessary cookies — required for the site to function and for remembering your cookie choices. Set without consent, as permitted by law.
- Analytics cookies — Google Analytics, to understand traffic and which content is useful.
- Session-replay cookies — Microsoft Clarity, to see where the interface confuses people.
Analytics and session-replay cookies are only set after you accept them in our cookie banner. You can change or withdraw your choice at any time via the cookie settings link in the site footer, and you can also block cookies in your browser settings — though parts of the site may then behave unpredictably.
9. Children
Our website, applications and services are directed at businesses, not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Changes to this policy
We update this policy when what we do changes. The "last updated" date at the top always reflects the current version. Where a change materially affects your rights, we will make it visible — through a notice on the website, or by email where we have a relationship with you.
11. Contact
Questions, requests, or complaints:
RE SOLVED DIGITAL SRL Str. Suceava nr. 7, cam. 1, 300015 Timișoara, Romania contact@re-solved.digital
