PINROM respects your privacy. This policy explains what personal data may be processed when you visit this website, use the application support portal, or contact us by email.
1. Data controller
This website and the support portal are operated by PINROM S.R.L. For privacy-related questions or requests, contact us at [email protected].
2. Website technical data
When you access this website, technical access logs may be created automatically. Depending on the request and network configuration, these logs may include:
- IP address, including IPv4 or IPv6 addresses;
- date and time of the request;
- visited page, path, or requested file;
- HTTP method and response status;
- browser or user-agent information;
- referrer information, when supplied by the browser;
- approximate country code supplied by Cloudflare.
Technical logs are used for website security, abuse prevention, troubleshooting, availability monitoring, and operational debugging.
3. Support portal data
When you submit a request through the PINROM support portal, we may process:
- the selected PINROM application;
- the type of support request;
- the content of your message;
- your email address, when voluntarily provided;
- the application version and build number;
- an optional Support Code;
- an optional attachment in JSON, ZIP, or plain-text format;
- minimal submission metadata, such as a randomly generated request identifier, submission time, application, request type, whether an email address was supplied, whether an attachment was supplied, and email delivery status.
The support database does not store the message content or the email address itself. These are included in the support email sent to the configured PINROM mailbox.
4. Security and anti-abuse processing
The support portal applies automated security controls designed to prevent spam, duplicate submissions, excessive requests, and malicious uploads. These controls may use:
- short-lived session and CSRF identifiers;
- submission timing checks;
- an invisible honeypot field;
- request limits associated with a pseudonymous IP identifier;
- request limits associated with a pseudonymous email identifier, when an email address is supplied;
- a pseudonymous identifier derived from normalized message content for duplicate detection;
- strict file-size, file-type, MIME, and file-signature validation.
These pseudonymous identifiers are created using keyed cryptographic hashing and are stored without the original email address, IP address, or message content in the anti-abuse database.
Anti-abuse decisions may temporarily prevent a support request from being accepted. They are used only for security and service protection and are not used for advertising, behavioural profiling, or decisions that produce legal or similarly significant effects.
5. Attachments
Optional support attachments are stored in a private server directory and are not published through a public URL. Stored filenames are replaced with randomly generated server-side filenames.
ZIP archives are not automatically extracted or executed. Attachments are used only to investigate and respond to the relevant support request.
6. Email correspondence
If you contact us by email or provide an email address through the support portal, we process the information necessary to read, manage, investigate, and respond to your request. This may include your email address, name if provided, message content, attachments, and subsequent correspondence.
7. Purposes and legal bases
Technical logs and anti-abuse identifiers are processed based on PINROM's legitimate interest in protecting the website, support portal, applications, infrastructure, and users from abuse and security incidents.
Support requests and correspondence are processed in order to respond to your request, provide application support, investigate technical problems, take steps requested before entering into a contract, manage an existing contractual or business relationship, and maintain necessary business communications.
Depending on the circumstances, the applicable legal basis may be your consent, steps taken at your request before entering into a contract, performance of a contract, compliance with a legal obligation, or PINROM's legitimate interests in providing support and managing its services and communications.
8. Retention periods
- Website technical access logs are retained for up to approximately 6 months and are then automatically rotated and deleted.
- Support portal anti-abuse events are retained for up to 7 days.
- Optional support attachments are retained for up to 90 days.
- Minimal support submission metadata is retained for up to 180 days.
- Email correspondence is retained only as long as reasonably necessary for support, project discussion, contractual, accounting, dispute, security, or legal purposes.
Data may be retained for a longer period where this is necessary to establish, exercise, or defend legal claims, comply with a legal obligation, investigate abuse, or protect the security of PINROM's systems and users.
9. Cookies and similar technologies
PINROM does not currently use marketing or advertising cookies on this website.
The support portal uses an essential, secure, HTTP-only session cookie to provide CSRF protection, preserve short-lived form state, and display the submission result. This cookie is not used for advertising or cross-site tracking.
10. Service providers
PINROM uses Cloudflare for DNS, security, network routing, website delivery, and access through the Cloudflare network. Cloudflare may process technical network information required to provide these services.
Support messages and email correspondence may be transmitted, routed, and stored using Google email services and Cloudflare Email Routing. These providers process data according to their respective service terms and privacy obligations.
11. Data security
PINROM applies technical and organisational safeguards intended to protect personal data and support submissions. These include encrypted HTTPS transport, secure session cookies, CSRF protection, request limiting, input validation, restricted private storage, non-public attachment paths, restricted server permissions, and automatic retention cleanup.
No method of transmission or storage is completely risk-free. You should therefore avoid submitting information that is not necessary for the support request.
12. Your rights
Under applicable data protection law, you may have the right to request access, rectification, erasure, restriction of processing, objection to processing, and data portability, where applicable. Where processing is based on consent, you may also withdraw that consent without affecting processing carried out before withdrawal.
To exercise your rights, contact us at [email protected]. We may need to request reasonable information to verify your identity before responding.
13. Supervisory authority
If you believe your personal data rights have not been respected, you may lodge a complaint with the Romanian data protection authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, available at dataprotection.ro.
14. Changes to this policy
This policy may be updated when the website, support portal, applications, service providers, retention practices, technical setup, or legal requirements change. The current revision date is displayed at the top of this page.