Legal
Privacy policy
Last updated: 22 August 2026. This document explains what data we collect, why, how long we keep it and what rights you have over it.
1. The data controller
The controller of personal data collected through ngx.ro is BEST WEB SYSTEMS S.R.L., Bucharest, Sector 3, Str. Gura Făgetului 76-80, Romania, VAT number 52784580, J2025082412000.
For any request concerning your data, write to contact@ngx.ro.
2. What data we collect
- Contact details submitted through forms: name, company name, email address, phone number, type of workshop
- The content of the messages you send us
- Minimal technical data required to run the site (IP address, for abuse prevention)
- Aggregated visit statistics, only if you accepted analytics cookies
3. Why we use it (legal basis)
- To answer your requests and create a demo account — performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
- To prevent abuse of the forms — legitimate interest (Art. 6(1)(f) GDPR)
- For visit statistics — consent (Art. 6(1)(a) GDPR)
- To meet legal obligations where they apply — legal obligation (Art. 6(1)(c) GDPR)
4. How long we keep it
Data submitted through forms is kept for as long as needed to answer the request and, afterwards, for the duration of the commercial relationship. If no commercial relationship follows, the data is deleted within 12 months of the last interaction.
[LEGAL REVIEW REQUIRED] Retention periods must be aligned with applicable accounting and tax obligations.
5. Who we share it with
We do not sell or rent your data. We share it only with suppliers who help us operate the service (hosting, email delivery, abuse protection), acting as processors under data processing agreements.
6. Your customers' data
For the data you enter into the application about your own customers, you are the controller and we are the processor. That relationship is governed by a data processing agreement signed with your company.
7. Your rights
- The right of access to your data
- The right to rectification of inaccurate data
- The right to erasure ("the right to be forgotten")
- The right to restriction of processing
- The right to data portability
- The right to object to processing based on legitimate interest
- The right to withdraw consent at any time
- The right to lodge a complaint with the Romanian data protection authority (ANSPDCP)
8. Security
We apply technical and organisational measures to protect data: individual accounts with roles and permissions, optional two-factor authentication, account lockout after repeated sign-in attempts, an audit log of important actions and database backups.
[LEGAL REVIEW REQUIRED] Structurally reviewed, but requires validation by a legal adviser or data protection officer before publication.
Frequently asked questions
What about GDPR?
Your customers' data belongs to you. The application keeps a change history, allows export and deletion of data, and processing is governed by a data processing agreement signed with your company.
How secure is my data?
Access is per individual account, with roles and permissions, optional two-factor authentication, account lockout after repeated sign-in attempts and an audit log of important actions. Every significant change is recorded, with author and timestamp.
Is my data separated from other companies?
Yes. Each organisation has its own data — customers, vehicles, work orders, invoices, files — and a user only sees the organisations they belong to. If you run several locations you can keep separate organisations and switch between them from the header.