1. Who we are
This Privacy Policy explains how personal data is handled in connection with AgencySpot (the "Service"), a platform for software agencies operated by:
We process personal data in accordance with Regulation (EU) 2016/679 ("GDPR") and applicable Romanian data protection law.
2. Controller vs. processor
Our role depends on the data in question:
- We act as controller for account and registration data, billing data, website visitor data, and communications you send us (e.g. support requests, pilot enquiries).
- We act as processorfor the content your organisation puts into its workspace — for example employee records, leave data, candidate profiles, client contacts and project information ("Customer Data"). For this data, your organisation is the controller and decides why and how it is processed. If you have questions about Customer Data in a workspace, please contact the organisation that runs that workspace first.
3. Data we collect
Data you provide (as controller)
- Account data: name, work email address, password (stored hashed), role, workspace and company name, profile photo if added.
- Billing data: company details, VAT number, billing address, invoicing history. Card payments are handled by our payment provider; we do not store full card numbers.
- Communications: messages you send via email or in-product forms, including pilot and demo requests.
Data collected automatically
- Usage and log data: IP address, browser type, device information, pages viewed, actions taken and timestamps, used for security, debugging and product improvement.
- Cookies and similar technologies — see section 11.
Customer Data (as processor)
- Whatever your organisation and its members store in the Service: HR and leave records, recruiting candidates and CVs, client and lead details, project and time-tracking information.
4. How and why we use data
- To provide, operate and secure the Service, including authentication and access control;
- to set up and manage workspaces, subscriptions and billing;
- to respond to support requests and communicate about the Service, including pilot programmes;
- to monitor performance, fix bugs and improve features, using aggregated or pseudonymised data where possible;
- to detect, prevent and investigate fraud, abuse and security incidents;
- to comply with legal obligations, such as accounting and tax rules;
- with your consent, to send product news and marketing emails — you can opt out at any time.
Customer Data is processed only on documented instructions from the controller organisation, as needed to provide the Service, and never for our own marketing.
5. Legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the Service, accounts, billing | Performance of a contract — Art. 6(1)(b) |
| Security, fraud prevention, product improvement | Legitimate interests — Art. 6(1)(f) |
| Invoicing, accounting, tax | Legal obligation — Art. 6(1)(c) |
| Marketing communications, non-essential cookies | Consent — Art. 6(1)(a) |
6. Sharing and subprocessors
We do not sell personal data. We share personal data only with:
- Service providers (subprocessors) that help us run the Service — such as cloud hosting, email delivery, payment processing and error monitoring — under contracts that meet GDPR Art. 28 requirements. A current list of subprocessors is available on request at info@mobiversal.com.
- Professional advisers and authorities where required by law or to protect our legal rights;
- A successor entity in the event of a merger, acquisition or asset sale, subject to this policy.
7. International transfers
We aim to host and process personal data within the European Economic Area. Where a subprocessor processes data outside the EEA, we ensure an adequate level of protection through an adequacy decision of the European Commission or the European Commission's Standard Contractual Clauses, with supplementary measures where needed.
8. Retention
- Account data: for the life of your account and up to 12 months after closure, unless a longer period is required by law.
- Billing records: as required by Romanian accounting and tax legislation (generally 5–10 years).
- Customer Data: for as long as the workspace exists; after termination, it is available for export for at least 30 days and then deleted from production systems, with residual copies removed from backups on their normal rotation cycle.
- Log data: typically no longer than 12 months, unless needed for an ongoing security investigation.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls and role-based permissions, workspace isolation in our multi-tenant architecture, logging and monitoring, and regular backups. No system is perfectly secure; if we become aware of a personal data breach affecting you or your workspace, we will notify you and the competent authority as required by GDPR Arts. 33–34.
10. Your rights
Where we act as controller, you have the right to access, rectify and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent at any time (without affecting prior processing). To exercise these rights, email info@mobiversal.com. We respond within one month, extendable as permitted by the GDPR.
You also have the right to lodge a complaint with a supervisory authority, in particular the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, Bucharest, www.dataprotection.ro, or the authority in your country of residence.
Where we act as processor, we will refer your request to the controller organisation and assist it in responding, as required by GDPR Art. 28.
11. Cookies
The Service and our website use:
- Strictly necessary cookies for authentication, session management and security — these do not require consent;
- Preference cookies that remember settings such as language or interface options;
- Analytics cookies, only with your consent, to understand how the Service is used and improve it.
You can manage non-essential cookies through the cookie banner or your browser settings. Blocking strictly necessary cookies may prevent the Service from functioning.
12. Children
The Service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18 as a controller. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top shows the latest revision. For material changes we will notify you by email or in-app notice before the changes take effect.
14. Contact
For any privacy question or request, contact us at info@mobiversal.com or by post at Mobiversal SRL, Str. Thurzó Sándor nr. 40, Oradea, Bihor, Romania.