1. Who we are
The website czrsoftware.ro, the client portal and the CZR Software products are operated by ENEFRIG SPECIAL PRODUCT SRL, Str. Petre Puican nr. 13, Caracal, Olt County, Romania, registered with the Trade Register under no. J2020000801287, tax ID 43340189, owner of the CZR Software brand. We are the controller of the data described below. For any question about your data, write to contact@czrsoftware.ro.
2. What data we process and why
We process only the data needed for each of the situations below.
- Visiting the site: the server logs keep the IP address, the requested page, the time and the browser type. We use them for security, abuse prevention and traffic statistics that we compute ourselves from the logs (legitimate interest, Art. 6(1)(f) GDPR). We keep them for at most 30 days.
- The contact form and package requests: name, email, phone, company, the system you use, the message, the page the request came from, plus the IP address and browser kept for bot protection. We use them to reply and prepare the requested offer (steps taken at your request prior to a contract, Art. 6(1)(b)). We keep them for at most 2 years after the last exchange.
- The client portal: name, email, password (stored only as a hash), company, client type, billing data (tax ID, trade register number, address), phone, preferred language and notification preferences. We use them for the account, licences, invoices and support (performance of the contract, Art. 6(1)(b)). We keep them as long as the account exists.
- Product licences (CZR CRM, CZR ERP): the licence key, the number of activations, a technical fingerprint of the computer running the application (stored as a hash, with no data about the computer’s contents), the label you give it, the date of the last check and the licence events (activation, validation, deactivation) with the IP address. We use them to activate and verify the licence and to prevent misuse (contract and legitimate interest). We keep them for the life of the licence plus 3 years.
- Payments: cards are processed by Stripe; we receive only your Stripe customer identifier, the amount, the currency and the payment status. Invoices are issued through SmartBill on the billing data in your account (legal obligation, Art. 6(1)(c)). Billing documents are kept for the period required by tax and accounting law.
- Support tickets: subject, description, messages and the licence they refer to. We use them to resolve the request (contract) and keep them as long as the account exists.
- The portal activity log: important actions in the account (logins, data changes, activations) with date, IP address and browser. We use it for security and to clarify disputes (legitimate interest) and keep it for at most 2 years.
- Emails: account confirmation, notifications about licences and tickets, our replies. They are sent from no-reply@czrsoftware.ro or contact@czrsoftware.ro through Hostinger’s email service.
- Calls to 0373 801 828: our AI receptionist answers, running on the CZR Voice platform. The call is recorded and transcribed, and your number, the message you leave and the transcript reach our team so that we can call you back. The receptionist announces the recording at the start of the call. The legal basis is our legitimate interest in answering your request, respectively steps taken at your request prior to a contract. The audio recording is deleted after at most 90 days; the transcript and the message after at most 12 months.
We use no data for advertising and sell it to nobody. We make no automated decisions with legal effects on you.
3. Cookies and third-party requests when pages load
The site uses only essential cookies: the session, form protection (CSRF), your cookie preference and the “remember me” option in the portal. At the moment we use no analytics or marketing cookies; if we add them, we will ask for your consent through the cookie banner. Details are in the cookie policy.
When pages load, your browser requests fonts from Google Fonts and libraries from the unpkg.com and jsDelivr content delivery networks; their servers receive your IP address and the usual technical data of a web request. On the payment page, Stripe loads its own components.
4. Who receives data
We pass data only to the providers we need to run the service, each for its own part:
- Hostinger (hosting of the site and portal on servers in Germany, plus the email service).
- Stripe (card payment processing, USA; transfer based on standard contractual clauses and the EU–US Data Privacy Framework).
- SmartBill (issuing and keeping invoices, Romania).
- For calls to the AI receptionist: the CZR Voice platform, also operated by us, with its providers — Twilio (telephony), ElevenLabs (voice and transcription) and the language model providers Anthropic and OpenAI, all in the USA, under standard contractual clauses.
- Google (Google Fonts), Cloudflare and Fastly (the content delivery networks of the libraries), for the technical requests described in section 3.
We pass data to authorities only under a legal obligation. For data in the systems of clients we work on in projects, we act as a processor, on the client’s instructions and under the contract or data processing agreement signed with them.
5. How long we keep data
- Server logs: at most 30 days.
- Contact and offer requests: at most 2 years after the last exchange.
- Portal account data and tickets: as long as the account exists; when the account is closed we delete them, except for documents the law requires us to keep.
- Licence data: for the life of the licence plus 3 years.
- Invoices and payment documents: the period required by tax and accounting law.
- Audio recordings of calls to the receptionist: at most 90 days; transcripts and messages: at most 12 months.
6. Your rights
You have the right of access to your data, rectification, erasure, restriction of processing, portability and objection to processing based on legitimate interest. You exercise them by emailing contact@czrsoftware.ro; we reply within 30 days. In the portal you can change your account and billing data yourself.
If you believe we have processed your data incorrectly, you can contact the Romanian National Supervisory Authority for Personal Data Processing (www.dataprotection.ro) or the courts.
7. Security
The site and the portal work exclusively over encrypted connections (HTTPS). Passwords are stored only as hashes, access to data is limited to the people who need it, portal actions are logged and backups are encrypted. Card data never reaches our servers.
8. Minors and changes
Our services are aimed at companies and professionals; we knowingly collect no data of persons under 18.
When we change something in this policy, we update the version date above. Important changes are announced to portal clients by email.