Privacy Policy
Version 2.1, in force from 8 September 2026
This policy explains what personal data we process when you use AutoRize, why we process it, who we share it with, and what rights you have over it. It is written in accordance with Regulation (EU) 2016/679 (GDPR) and Law 190/2018, and forms part of the platform Terms & Conditions.
1. Data controller
The controller of your data is FOI STUDIO SRL, tax identification number (CUI) 35853663, registered with the Romanian Trade Register under no. J2016000465266, registered office at Str. Tudor Vladimirescu nr. 65, ap. 6, 540014 Târgu Mureș, Mureș County, Romania. You can write to us at any time at contact.autorize@gmail.com.
We are not legally required to appoint a data protection officer. Questions about data processing can be sent to the same address and are answered by us directly.
2. What data we collect
Account data: your name, email address and, if you sign in with Google, the basic details of your Google profile. Project data: what you enter about the designer, the beneficiary, the land, and the works. Files: the documents you upload, such as urbanism certificates, land registry extracts, drawings, or scanned identity documents.
Technical data: usage logs, IP address, browser type, and events recording use of the artificial intelligence features. We also keep a log of significant actions within a project, so that changes to a dossier can be reconstructed.
3. Other people whose data you enter
A permitting dossier contains, by its nature, data about people other than you: the beneficiary of the works, including their name, personal numeric code and address, and details of neighbours taken from the land registry extract. We process these solely to complete your documents.
When you enter or upload such data, you are the one determining the purpose of processing it, and we act as processor. You confirm that you have a legal basis for passing that data to us. If you use AutoRize professionally, we can provide a data processing agreement on request.
4. Purposes and legal bases
We process data to generate the documents you request, to administer your account, to respond to your enquiries, and to keep the platform secure and working. The primary basis is performance of the contract between us, that is providing the service you asked for, under art. 6(1)(b) GDPR.
For platform security, abuse prevention, and improving the service we rely on our legitimate interest, under art. 6(1)(f). For usage statistics and the support chat we rely on your consent, under art. 6(1)(a), which you can withdraw at any time. Where the law requires us to retain certain data, the basis is legal obligation, under art. 6(1)(c).
5. Processing with artificial intelligence
To extract data from the files you upload and to draft the narrative sections of documents, we send the content of those files and the project data to artificial intelligence providers, who act as processors. We currently use OpenAI as the primary provider and Google, through the Gemini model, as a fallback when the first request fails.
This data is sent strictly for the processing you request. Under the API terms of these providers, the content sent is not used to train their models. We do not use your data to train models of our own, and we do not sell it to anyone.
6. Who we share data with
We do not sell your data. We share it only with the providers we need in order to operate: Amazon Web Services, for hosting, file storage, and sending transactional email through the SES service; OpenAI and Google, for the artificial intelligence processing described above; Google, for website usage statistics and, if you choose it, for sign-in; Crisp, for the support chat; and Mailchimp, which receives your email address when you create your account or sign in through Google.
Each receives only the data its function requires. We may also disclose data to authorities where the law obliges us to. If we add or replace a provider, we update this list at the same time.
7. Where data is stored, and transfers outside the EEA
The application, the database, the files you upload, and the generated documents are hosted in the European Union, in the Frankfurt region (eu-central-1) of Amazon Web Services. Transactional email is sent from the same region.
The artificial intelligence providers, the usage statistics, and the support chat involve transfers to the United States. Those transfers rely on the standard contractual clauses adopted by the European Commission or, where applicable, on the adequacy decision covering the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply.
8. How long we keep data
We keep account data for as long as your account exists. Projects, uploaded files, and generated documents remain stored until you delete them or delete your account; we do not remove them automatically after a period, because a permitting file can run over several years.
Events recording use of the artificial intelligence features are deleted automatically after twelve months. Database backups are kept for at most sixty days, after which they expire automatically. Where the law requires a longer period for particular categories of data, we observe it.
9. Deleting your account
You can delete your account at any time from your account settings. On deletion we remove the projects, uploaded files, and generated documents belonging to you, together with the corresponding files in storage, and the account record is anonymised: the email address, name, and password are replaced so that the remaining record can no longer identify you.
Deletion cannot be undone, so download anything you want to keep beforehand. Copies already held in backups disappear as those backups expire, within the period given above.
10. Security
Access to data is restricted to the purposes described in this policy. Traffic to the platform is encrypted, files are held in private storage that cannot be reached publicly, and administrative access to the server running the application uses the infrastructure provider access mechanisms rather than passwords.
No system is perfectly secure. If a personal data breach occurs that is likely to affect your rights, we will inform you and notify the supervisory authority within the time limits set by the GDPR.
11. Automated decisions
Documents are generated automatically, and some fields are filled in by artificial intelligence models. This is not an automated decision producing legal effects concerning you within the meaning of art. 22 GDPR: the result is a document subject to your review, not a decision taken about you.
We do not profile you and we do not take automated decisions about access to the service.
12. Cookies and similar technologies
We use strictly necessary cookies for authentication, for keeping your session, and for protection against forged requests. The platform cannot work without them. We additionally use Google Analytics 4 for website usage statistics and Crisp for the support chat, each of which sets its own cookies.
The statistics and chat scripts load only after you accept them in the banner shown on your first visit. If you choose Reject all, they are not loaded at all. Your choice is stored for six months, after which we ask again, and you can change it at any time from the Cookie settings link in the footer of every page on autorize.ro.
13. Your rights
You have the right of access to your data, and rights to rectification, erasure, restriction of processing, portability, and objection, as well as the right to withdraw consent at any time where processing is based on it. Withdrawal does not affect processing carried out beforehand.
You can exercise these rights by writing to contact.autorize@gmail.com. We reply within one month of receiving your request, a period we may extend by two months for complex requests, in which case we will tell you. You can also request your data directly from your account settings, with the Request your data button; once we have processed the request, you receive a download link and a verification code by email.
14. Complaints
If you believe we are processing your data unlawfully, please write to us first so that we can put it right.
You have, in any event, the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing, at B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest, or with the supervisory authority of the state where you habitually reside.
15. Changes to this policy
We may update this policy when the service, the providers we use, or legal requirements change. The updated version is published on this page, together with the date it takes effect.
If a change is significant, for example adding a new processing purpose, we will tell you before it takes effect.
16. Contact
For any question about your data, write to us at contact.autorize@gmail.com. The full identification details of the controller are in section 1.