LO

Privacy Policy

Version 1.0 · Last updated: 31 July 2026

This policy describes how [de completat: denumirea completa a societatii] processes the personal data of users of the LAND OS platform, in accordance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and with Romanian Law no. 190/2018.

It applies to all visitors and account holders, whatever plan they have contracted.

1. The controller

Controller
[de completat: denumirea completa a societatii]
Registered office
[de completat: sediul social]
Fiscal identification code
[de completat: cod unic de inregistrare]
Data protection contact
[de completat: adresa de email pentru cereri GDPR]

The Operator has not appointed a data protection officer, as it does not fall within the situations set out in art. 37(1) of the Regulation. Data protection requests are addressed to the contact above and answered within 30 days.

2. Categories of data processed

Identification and contact data
Name, email address, and the phone number optionally provided in requests to providers.
Authentication data
The cryptographically derived value of the password and session identifiers. The plaintext password is not stored and is not known to the Operator.
Account data
Declared role, contracted plan, available credits, account creation date and last sign-in date.
Usage data
Watched plots, saved perimeters, generated reports, searches and saved filters.
Technical data
IP address, browser type and version, operating system, request time and requested page, retained in server logs.
Billing data
The data needed to issue invoices and the payment history. Card data is not collected and never reaches the Operator servers.
Third-party data entered by the user
Records in the CRM module, in respect of which the user is the controller and the Operator of the platform is the processor.

3. Purposes and legal bases

PurposeData categoriesLegal basisStorage period
Creating and administering the accountIdentification, authentication, accountArt. 6(1)(b), performance of the contractFor the life of the account, plus 30 days after deletion
Providing the platform functionsUsage, technicalArt. 6(1)(b), performance of the contractFor the life of the account
Notifications about watched plotsIdentification, usageArt. 6(1)(b), performance of the contractUntil watching is switched off
Invoicing and accounting recordsIdentification, billingArt. 6(1)(c), legal obligation10 years, under Accounting Law no. 82/1991
Platform security and abuse preventionTechnical, authenticationArt. 6(1)(f), legitimate interest12 months for access logs
Sending requests to service providersIdentification, contact, plot contextArt. 6(1)(b), performance of the contract3 years from the last interaction
Commercial communicationsIdentification, contactArt. 6(1)(a), consentUntil consent is withdrawn
Defending a legal claimAll relevant categoriesArt. 6(1)(f), legitimate interestThe applicable limitation period

The legitimate interest relied on is maintaining the security of the service, preventing abusive use of resources, and defending the Operator rights. The user may object to processing based on legitimate interest, under art. 8.

4. Processing within the artificial intelligence functions

To generate reports, the data of the analysed plot is transmitted to the language model provider, acting as processor.

The user name, email address and other identifying data are not transmitted to the model provider. The transmitted content is not used by the provider to train its models.

The user is responsible for personal data they voluntarily include in the text of a question, and is advised not to enter such data.

Generated reports are stored in the user account and can be deleted by them at any time.

5. Automated decision-making

The platform automatically calculates price estimates, confidence scores, risk scores and market signals. These calculations concern land, not people, and produce no legal effects on the user nor similarly significantly affect them.

No profiling is carried out for marketing purposes and no automated decisions are taken about access to the service, other than technical rate limits applied uniformly to all users.

6. Recipients of the data

Data may be disclosed to the following categories of recipient, strictly as necessary for the stated purposes:

  • the infrastructure hosting provider, within the European Union;
  • the transactional email service provider;
  • the language model provider used for reports;
  • the payment processor, acting as an independent controller;
  • professional service providers to whom the user addresses a quote request;
  • accounting and legal advisers, under a duty of confidentiality;
  • public authorities, where there is a legal obligation to disclose.

A data processing agreement under art. 28 of the Regulation is in place with each processor. Data is not sold and is not made available to third parties for advertising purposes.

7. Transfers outside the European Economic Area

The primary infrastructure and the database are located within the European Union.

The language model provider and, where applicable, the payment processor may process data in the United States of America. Those transfers rely on the standard contractual clauses adopted by the European Commission through Implementing Decision (EU) 2021/914 and, where applicable, on the adequacy decision concerning the EU-US Data Privacy Framework.

A copy of the applicable safeguards may be requested at [de completat: adresa de email pentru cereri GDPR].

8. Rights of the data subject

Under art. 15 and following of the Regulation, the data subject has the following rights:

Right of access
To obtain confirmation of processing and a copy of the data.
Right to rectification
To have inaccurate data corrected and incomplete data completed.
Right to erasure
To have data erased, under the conditions of art. 17.
Right to restriction
To obtain restriction of processing, under the conditions of art. 18.
Right to portability
To receive the data in a structured, commonly used and machine-readable format.
Right to object
To object at any time to processing based on legitimate interest, and to processing for direct marketing.
Right to withdraw consent
Without affecting the lawfulness of processing carried out before withdrawal.
Right to lodge a complaint
With the National Supervisory Authority for Personal Data Processing, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, or before the competent court.

Requests are sent to [de completat: adresa de email pentru cereri GDPR] and answered within one month, extendable by two months for complex requests, with prior notice to the applicant.

Exercising these rights is free of charge. Manifestly unfounded or excessive requests may attract a reasonable fee or be refused, under art. 12(5) of the Regulation.

9. Account deletion

Account deletion can be requested from the account section or by email.

On deletion, identification data, watchlists, perimeters, reports and CRM records are removed within 30 days.

Financial and accounting documents are retained for 10 years and technical security logs for 12 months, on the basis of legal obligations. Those records are not used for any other purpose.

Aggregated and anonymised data, from which identity can no longer be reconstructed, may be retained for market statistics.

10. Security measures

The Operator applies technical and organisational measures appropriate to the risk, including:

  • encrypted transmission of communications;
  • storage of passwords in cryptographically derived form, with a unique salt per account;
  • session identifiers stored as cryptographic digests, in cookies carrying the HttpOnly and SameSite attributes;
  • role-based access control and separation of development and production environments;
  • logging of administrative operations;
  • periodic backups with restore testing.

In the event of a personal data breach presenting a risk to the rights and freedoms of data subjects, the Operator notifies the supervisory authority within 72 hours and informs the data subjects where the risk is high, under art. 33 and 34 of the Regulation.

11. Minors

The service is not directed at persons under 16, and creating an account requires having reached that age.

If it is found that the data of a person under 16 has been collected without the consent of the holder of parental responsibility, it is deleted without delay.

12. Changes to this policy

This policy may be updated. Substantial changes are communicated to the email address associated with the account at least 30 days before they take effect.

The date of the last update is shown in the document header.