Legal

Privacy Notice

Version: v3-2026-08 Effective date: 17 August 2026

This Privacy Notice explains how NOVACORE AI S.R.L. collects, uses, discloses, protects and retains personal data through this website.

It applies to website visitors, people who contact us, representatives of prospective business customers and individuals who submit data-protection requests.

Additional privacy information may be provided if you enter a commercial relationship, complete customer or end-use verification, apply for a position or use a future service involving different processing activities.

1. Who is responsible for your data

The data controller is:

NOVACORE AI S.R.L. Registered office: București, Sector 3, Strada Nerva Traian, Nr. 27–33, Birou 6, Scara B, Etaj 1, Romania CUI: 55427301 Trade Register number: J2026049856006 EUID: ROONRC.J2026049856006 Email: office@novacoresoftai.com Additional email: info@novacoresoftai.com Telephone: +40 722 396 299

2. Data-protection contact

NOVACORE AI has not appointed a Data Protection Officer as of the effective date of this notice.

We periodically assess whether the appointment of a Data Protection Officer is required under Article 37 GDPR as our activities and processing operations develop.

Data-protection questions and requests may be sent to office@novacoresoftai.com with the subject Data Protection Request.

3. Personal data we process

Contact and business inquiries

When you submit a contact form or communicate with us, we may process:

  • name
  • business or personal email address
  • telephone number, if provided
  • organisation
  • role or position, if provided
  • country and industry, if provided
  • subject of the inquiry
  • message content
  • preferred language
  • correspondence and follow-up records
  • submission date and technical status
  • an idempotency or anti-duplication value associated with the request.

Infrastructure and compute inquiries

If your inquiry concerns GPU capacity, dedicated servers, hosting or related infrastructure, we may additionally process:

  • requested service or platform category
  • general workload description
  • intended sector and purpose
  • anticipated capacity or term
  • hosting, security or data-location requirements
  • other information you choose to provide.

This initial information helps us evaluate the inquiry and determine whether further technical or end-use review is required.

If the inquiry progresses, we may provide separate privacy information for customer verification, beneficial-ownership documentation, sanctions screening and end-use assessment.

Data-protection requests

When you exercise a data-protection right, we may process:

  • your name and email address
  • the right you wish to exercise
  • details included in your request
  • information needed to locate relevant records
  • correspondence and response
  • evidence of identity or authority, where reasonably necessary
  • dates, decisions and completion status.

We do not request identity documents through the general website form. If identity verification is reasonably required, we will explain what is needed and provide an appropriate channel.

Server and security logs

When you access the website, our hosting and security infrastructure may automatically process:

  • IP address
  • request date and time
  • requested URL or resource
  • HTTP method and response status
  • browser or user-agent information
  • referral information where supplied
  • network and security events
  • rate-limiting and abuse-prevention information
  • application and server errors.

Language preference

If you select a language, the website stores nc-lang in your browser’s local storage. It contains only en or ro.

This value is described in the Cookie and Local Storage Policy. It is not automatically transmitted to our server as a cookie.

4. Sources of personal data

We generally obtain personal data:

  • directly from you
  • from the organisation you represent
  • automatically from your browser or device when it communicates with our server
  • from correspondence generated during our interaction.

If a business relationship progresses to formal verification, information may also be checked against public registers, official sanctions sources or information supplied by authorised verification providers. Where required, additional privacy information will be provided.

6. Is providing data mandatory?

Fields marked as required must be completed for us to receive and assess the relevant request.

If required information is not provided, we may be unable to:

  • respond to the inquiry
  • identify the relevant records
  • assess the proposed service
  • verify authority to act for another person
  • process a data-protection request.

Optional fields may be left blank.

Acknowledging that you have read this notice is not consent to processing. We do not rely on that acknowledgement as the legal basis for responding to your inquiry.

7. Special-category and highly sensitive data

The website is not designed to collect special categories of personal data, criminal-conviction data, passwords, private keys, financial credentials, classified information or other highly sensitive material.

Please do not submit such information through a general form.

If sensitive information is genuinely necessary for a future engagement, an appropriate process and secure channel must first be agreed.

8. Children

This website and its business services are not directed to children.

We do not knowingly request personal data from children through the website. If you believe that a child has submitted personal information, contact us so we can assess and take appropriate action.

9. Direct marketing

Submitting an inquiry does not automatically subscribe you to marketing communications.

We do not currently use website inquiry data for behavioural advertising or sell it to data brokers.

If we introduce a newsletter or other direct-marketing activity, we will provide the required information and choice at the point of collection.

10. Retention

We retain personal data only for as long as reasonably necessary for the relevant purpose, subject to legal, contractual and dispute-related requirements.

Inquiries that do not result in a commercial relationship

Inquiry and related correspondence records are scheduled for deletion 24 months after receipt.

Contract-related communications

If an inquiry results in a contract, relevant records are retained for the duration of the relationship and afterwards for the periods required by applicable Romanian commercial, accounting, fiscal and limitation rules.

Data-protection requests

Requests and response records are retained for 36 months after completion so that we can demonstrate how the request was handled and address related questions or claims.

Server and security logs

Standard server and security logs are retained for up to 12 months, unless a shorter operational period applies or longer preservation is necessary for an identified incident, investigation, legal hold or claim.

Local language preference

The nc-lang value remains in browser local storage until it is changed or removed through browser controls.

Backups

Deleted records may remain in protected backups for a limited overwrite cycle. Backup copies are not restored for ordinary use and remain subject to access restrictions and scheduled replacement.

A record may be retained for longer where required by law, an investigation, a legal hold or the establishment, exercise or defence of legal claims.

11. Recipients and service providers

Access to personal data is limited according to role and need.

Data may be processed by or disclosed to:

  • authorised NOVACORE AI personnel
  • website and database hosting providers
  • email and communications providers
  • IT maintenance and security providers
  • professional advisers, such as legal or accounting advisers
  • verification providers, if a commercial review progresses
  • competent authorities, courts or other parties where disclosure is legally required
  • a purchaser, investor or successor in connection with a legitimate corporate transaction, subject to appropriate safeguards.

Current provider categories

Hosting: The website and its database use infrastructure supplied by Hostinger.

Email delivery: Contact notifications and subsequent correspondence are handled through the company’s email provider.

Processors may use only the information needed to provide the relevant service and are subject to applicable contractual and data-protection requirements.

We do not sell personal data and do not disclose it for third-party behavioural advertising.

12. International transfers

The primary website and database environment is configured for hosting within the European Union.

We review the locations and transfer arrangements of relevant providers and their subprocessors. If personal data is transferred outside the European Economic Area, we will use a lawful transfer mechanism where required, such as:

  • an adequacy decision
  • Standard Contractual Clauses
  • another mechanism permitted by Chapter V GDPR

together with supplementary safeguards where appropriate.

You may contact us for information about the transfer safeguards relevant to your data.

This section must be updated if provider locations or subprocessor arrangements change.

13. Security

We apply technical and organisational measures selected according to the nature, scope, context and risks of the processing.

These may include:

  • access controls
  • least-privilege permissions
  • authentication safeguards
  • encrypted transport
  • protected storage and backups
  • logging and monitoring
  • rate limiting
  • vulnerability and patch management
  • change control
  • incident-response and recovery procedures
  • confidentiality obligations.

No online service can guarantee absolute security. If you believe you have identified a vulnerability, follow the process described on our Security page.

14. Automated decision-making

We do not use website data to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you.

Technical controls may automatically filter spam, limit abusive requests or identify potential security events. Material decisions regarding inquiries or rights requests are reviewed by a person.

15. Your rights

Subject to the conditions and exceptions in the GDPR, you may have the right to:

  • receive information about the processing
  • obtain confirmation that we process your data
  • access your personal data
  • correct inaccurate or incomplete data
  • request erasure
  • request restriction of processing
  • object to processing based on legitimate interests
  • receive certain data in a structured, commonly used and machine-readable format where the portability right applies
  • withdraw consent at any time where processing is based on consent, without affecting prior lawful processing
  • lodge a complaint with a competent supervisory authority
  • not be subject to a qualifying decision based solely on automated processing.

The right to data portability generally applies where processing is automated and based on consent or contract. It does not automatically apply to processing based on legitimate interests.

Rights are not absolute. An applicable legal obligation, overriding legitimate ground, third-party right or need to establish, exercise or defend a legal claim may affect the response.

16. Exercising your rights

You may submit a request:

  • through the website’s data-rights form; or
  • by emailing office@novacoresoftai.com.

Use the subject Data Protection Request and describe the right or information concerned.

We normally respond within one month of receiving a valid request. Where permitted by GDPR, this period may be extended by up to two additional months because of complexity or number of requests. If extended, we will inform you within the initial month and explain the reason.

Requests are normally handled free of charge. Where a request is manifestly unfounded or excessive, particularly because it is repetitive, we may charge a reasonable fee or refuse to act, as permitted by law.

We may request information reasonably necessary to confirm identity or authority. We will not request more information than necessary for verification.

Requests are reviewed and answered by a person.

17. Complaints

Please contact us first if you believe your data has been handled incorrectly. We will review the concern and seek to address it appropriately.

You also have the right to lodge a complaint with:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP B-dul G-ral. Gheorghe Magheru 28–30 Sector 1, 010336 București, Romania Telephone: +40 31 805 9211 Email: anspdcp@dataprotection.ro Website: www.dataprotection.ro

You may also be entitled to contact another competent supervisory authority, particularly in the country of your habitual residence, place of work or the alleged infringement.

18. Cookies and browser storage

The website does not currently set analytics, advertising or tracking cookies.

It stores a language preference in browser local storage when you select Romanian or English. Details are provided in the Cookie and Local Storage Policy.

19. Changes to this notice

We may update this notice when our website, providers, services, legal obligations or processing activities change.

The current version and effective date will be published at the top of the page. Material changes will be highlighted where appropriate.

Where technically implemented, the privacy-notice version presented when an inquiry is submitted is recorded with that inquiry.

20. Contact

Privacy questions may be sent to:

NOVACORE AI S.R.L. Email: office@novacoresoftai.com Subject: Data Protection Request Telephone: +40 722 396 299 Registered office: București, Sector 3, Strada Nerva Traian, Nr. 27–33, Birou 6, Scara B, Etaj 1, Romania

Exercise your data rights

Submit a request below. We do not ask for identity documents through this website. A person reviews every request and responds within one month.

We reply to this address. Use the address you contacted us from, where possible.

Build your next critical system on a stronger foundation.

Tell us what you need to build, modernise or operate. We will respond with a technical point of view, not a sales pitch.