Privacy policy
What data we collect, why, how long we keep it and who receives it. Includes your rights under the General Data Protection Regulation and how to exercise them.
Versiunea 1.1 · în vigoare de la 06.09.2026
> This is a translation of the Romanian text, provided for convenience. In case > of any difference of meaning, the Romanian version prevails, as the language > in which the contract is concluded.
Who processes the data
The Comunicate.top platform is operated by SC ARC MEDIASOFT SRL. For any question about your data, write to contact@comunicate.top.
What data we collect and why
**Account data** — email address, name, password in irreversibly hashed form, preferred language. Without these we cannot create the account. Basis: performance of the contract.
**Organisation data** — company name, tax and billing details, bank details for publishers. We use them to issue invoices and make payments. Basis: performance of the contract and legal tax obligations.
**Site credentials** — the user name and application password for the WordPress sites you register. They are encrypted with AES-256-GCM and never appear in readable form in the interface, in logs or in reports. We use them solely to publish the articles you order. Basis: performance of the contract.
**Content** — the articles, images and documents you upload. They stay yours; we store them and transmit them to the sites you choose.
**IP address** — we record it at sign-in, when terms are accepted, and in the audit log of important operations. We use it to be able to prove who did what and when, and to discourage abuse. The address is turned into a country and city **locally, on our own server**, using the GeoLite2 databases; we send it to no external service for that. Basis: legitimate interest in the security of the platform and, for the acceptance of terms, the obligation to be able to prove consent.
**Consent for news and offers** — if you tick at registration that you want to receive them, we keep the tick and the moment of it. The box starts empty: a pre-ticked box is not valid consent. Basis: your consent, art. 6(1)(a) GDPR. You may withdraw it at any time from your account's notification settings, with no consequence for your account or your orders; withdrawal does not affect messages sent before it. Notifications about your own orders do not depend on this tick.
**Audit log** — what changed, by whom, when, and from what address. Necessary so that we can answer questions about money and about published content. Basis: legitimate interest and legal obligations.
What we do NOT do
We use no tracking cookies and have no behavioural analytics tools. The only cookie is the session cookie, needed to keep you signed in. We do not sell data, do not carry out advertising profiling, and take no automated decisions with legal effects on you.
Who we pass data to
**The sites you choose yourself** — the article, images and SEO metadata reach them through the WordPress API. Without that there is no publication.
**The payment provider** — the minimum data needed to process payments. We do not store card numbers; they never reach our servers.
**The email provider** — the address and the content of transactional messages.
**Authorities** — only where the law obliges us, and only what is requested.
How long we keep it
Account data for as long as the account exists, plus 30 days after deletion. Financial and audit records are kept for 10 years, as tax law requires. Acceptances of terms are kept for as long as they could matter in a dispute: a deleted acceptance would be destroyed evidence. Content already published on third-party sites is no longer under our control; deletion there has to be requested separately.
Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection, under the GDPR. Write to contact@comunicate.top and we answer within 30 days at the latest. If you are dissatisfied, you may address the Romanian National Supervisory Authority for Personal Data Processing (dataprotection.ro).
Deleting your account has one limit that is fair to know in advance: we cannot delete the financial and audit records the law obliges us to keep, nor the acceptances of terms.
Security
Passwords are stored with attack-resistant derivation functions, not reversibly encrypted. Site credentials are encrypted with keys kept separately from the database. All traffic travels over HTTPS. Administrative access is restricted by role and leaves a trace in the audit log.
Changes
When we change this policy, we publish a new version and ask you to confirm it at your next sign-in. The old version stays archived; your acceptance is tied to the exact version you read.
Pentru întrebări despre datele tale: contact@comunicate.top
Read next