1. Introduction
At myreputaition, the privacy of your data is a priority. This Privacy Policy explains what types of data we collect, why we collect it, how we use it, and what rights you have regarding it, in accordance with Regulation (EU) 2016/679 (GDPR).
The policy applies to all our services, including the websites. www.myreputaition.com, qr.myreputaition.com and any Additional Services contracted.
By using our platforms or services, you confirm that you have read and understood how myreputaition processes your data.
2. Who We Are
The platform is operated by [Legal Name of the Company], a commercial company with its registered office at [Registered Office Address], registered with the Trade Register under no. [Jxx/xxxx/xxxx], unique registration code [CUI] (hereinafter referred to as the “Company,” “myreputaition,” “we”).
You can contact us for any questions related to data privacy at: Email: contact@myreputaition.com
3. What Data We Collect
We only collect the information strictly necessary to provide our services and ensure the proper functioning of the platform.
a) End-User Data (the individuals who provide reviews)
When you scan a QR code and choose to sign in with your Google account, we collect:
- Your full name (as it appears in your Google account)
- Email address
- Profile picture (if available)
- Technical information about the reward (voucher code, generation date, etc.)
b) Business Owner Data (Clients)
If you are a business owner and create an account, we collect:
- Identification and contact information: First name, last name, email address, phone number
- Authentication data: Email address, password (stored encrypted)
- Business information: Company name, Google Maps location link, CUI (for invoicing)
- Billing and payment data: Information needed to issue invoices. Note: Card information is collected and processed exclusively by our third-party payment processor; we do not store this information.
If a Client contracts additional services (e.g., Google Business Profile setup, professional photography), we may collect:
- Detailed business information: Physical address, phone numbers, business descriptions, opening hours, needed to set up the Google Business profile
- Visual content: Photos and/or videos of the location, products, or team, produced by us or our collaborators (we ensure that no identifiable individuals are captured without their consent)
c) Automatically Collected Data (Technical Data)
When you access any of our platforms, we may automatically collect technical information such as:
-
IP address,
-
browser type and version,
-
operating system,
-
pages visited and session duration,
-
date and time of access.
d) Cookie-uri
We use essential cookies for the functioning of the platform and, occasionally, analytics cookies (Google Analytics or similar services).
More details in our page for Cookies.
4. Purposes for Using Data
- For End-Users: Validation of review authenticity and management (delivery) of rewards (vouchers)
- For Business Owners:
- Creation and management of accounts on the platform
- Processing payments for Subscriptions and Additional Services.
- Delivery of contracted Services (QR code generation, review tracking, AI-generated review responses)).
- Delivery of Additional Services (e.g., GBP profile creation, photo materials delivery)
- Issuing invoices and other fiscal documents.
- For all users:
- Providing technical support and responding to inquiries.
- Improving functionality and security of services (technical analysis, error detection).
- Compliance with legal obligations.
We do not send newsletters or use your data for direct marketing campaigns without your explicit and separate consent.
5. Legal Basis for Data Processing
We process data based on the following legal grounds (under GDPR):
- Performance of a contract (Art. 6(1)(b) GDPR): Processing data for Business Owner or delivering Services and Additional Services. Processing End-User email to deliver the promised voucher.
- Consent (Art. 6(1)(a) GDPR): When an End-User chooses to sign in with their Google account.
- Legitimate interest (Art. 6(1)(f) GDPR): For platform security, error diagnostics, and fraud prevention.
- Legal obligation (Art. 6(1)(c) GDPR): To comply with fiscal and accounting legislation.
6. How We Store and Protect Data
-
All data is transmitted encrypted via secure connections (HTTPS).
-
Passwords are stored in encrypted form (hash + salt).
-
Access to data is limited to authorized personnel.
-
Our hosting providers comply with GDPR security standards.
7. Data Retention
We retain data only as long as necessary for the purposes it was collected.
-
Business login data is retained as long as the account remains active.
-
Data of users leaving reviews is kept during the validation and voucher delivery process, and afterwards for historical validation.
-
Technical logs and cookies may be retained indefinitely for diagnostics and security.
You can request access, correction, or deletion of your personal data at any time by contacting us at contact@myreputAItion.com
8. Data Disclosure
We do not sell or share your data with third parties for commercial purposes. We may share data only with:
- Hosting provider and IT service providers
- Payment processors, for processing Subscription payments
- AI service providers, to generate suggested review responses (data sent is usually public reviews)
- Analytics service providers (e.g., Google Analytics), in aggregate form
- Third-party collaborators (e.g., photographers, consultants), only to provide contracted Additional Services and under a confidentiality agreement
- Public authorities, only when legally required.
9. International Data Transfers
To provide our Services, certain data may be transferred outside the European Union (EU) or European Economic Area (EEA), mainly to the United States.
This occurs when using services such as Google (for Google Business Profile API and authentication), AI service providers and Payment processors (which may have servers in the USA).
We ensure these transfers are legally protected. We rely on one of the following GDPR-recognized safeguards:
- Adequacy decisions (e.g., EU-US Data Privacy Framework)
- Standard Contractual Clauses (SCCs) approved by the European Commission, signed with the respective providers.
10. Your Rights
Under GDPR, you have the following rights:
- Right to access your data.
- Right to correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”).
- Right to restrict processing.
- Right to data portability.
- Right to object to processing (in certain circumstances).
- Right to lodge a complaint with ANSPDCP (Romanian Data Protection Authority).
To exercise these rights, contact us at contact@myreputaition.com.
11. External Links
Our platforms may include links to other websites (e.g., Google Maps).
We are not responsible for the content or privacy policies of those sites.
We recommend reviewing the privacy policies of any service you access.
12. Policy Changes
We may update this policy periodically.
Any changes will be posted on this page along with the date of the latest update.
13. Contact
For further questions regarding data protection, you can write to us at contact@myreputaition.com.
14. Supervisory Authority
If you believe your data is not being processed correctly, you can file a complaint with:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Adresă: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
Site: www.dataprotection.ro