Privacy Policy
Effective date: 1 June 2026  ·  Version 1.0

This Privacy Policy explains how GridVisio collects, uses, and protects your personal data. We are committed to your privacy and comply with the EU General Data Protection Regulation (GDPR) and Romanian data protection law.

Contents

  1. Who We Are
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing
  5. Third-Party Processors
  6. Data Retention
  7. Data Security
  8. Your GDPR Rights
  9. Cookies
  10. Children's Privacy
  11. International Transfers
  12. Changes to This Policy
  13. Contact and Complaints

1. Who We Are

GridVisio operates the coverage mapping platform available at gridvisio.com. For the purposes of GDPR, GridVisio acts as the data controller for personal data collected during account registration and platform use.

For data you upload to the platform (such as subscriber records), GridVisio acts as a data processor on your behalf, and you remain the data controller responsible for that data.

Contact: [email protected]

2. Data We Collect

2.1 Account data

When you register, we collect your name, email address, and password (stored as a hashed value — we never store plain-text passwords). If you subscribe to a paid plan, billing and payment details are collected by Stripe on our behalf — we only receive a payment token and last-4 card digits.

2.2 Usage data

We collect data about how you use the Service, including pages visited, features used, and actions taken. This is used to improve the Service and diagnose technical issues.

2.3 Subscriber data (data you upload)

You may upload subscriber records, network topology data, geographic coordinates, and other business data to the platform. This data belongs to you. We process it only to provide the Service as described in Section 3.

2.4 Technical data

We automatically collect IP address, browser type and version, operating system, referring URL, and session timestamps for security, fraud prevention, and service optimisation purposes.

2.5 Communications

If you contact us by email, we retain a record of that correspondence including your email address and the content of the message.

3. How We Use Your Data

PurposeData usedLegal basis
Providing and operating the ServiceAccount data, subscriber data, usage dataContract performance
Processing payments and managing subscriptionsAccount data, payment dataContract performance
Sending transactional emails (password reset, billing, notifications)Email addressContract performance
Responding to support requestsAccount data, communicationsLegitimate interests
Improving and developing the ServiceUsage data, technical data (aggregated/anonymised)Legitimate interests
Security, fraud prevention, and abuse detectionTechnical data, account dataLegitimate interests / Legal obligation
Complying with legal obligationsAs required by applicable lawLegal obligation

We do not sell your personal data to third parties. We do not use your data for advertising or profiling purposes.

4. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases under Article 6 of the GDPR:

5. Third-Party Processors

We share data with the following trusted third-party processors. Each is subject to appropriate data processing agreements and maintains their own security standards.

ProcessorPurposeLocationPrivacy policy
Stripe, Inc.Payment processing and subscription managementUSA (EU data transfer safeguards apply)stripe.com/privacy
Hetzner Online GmbHCloud hosting and infrastructureGermany (EU)hetzner.com
Resend, Inc.Transactional email deliveryUSA (EU data transfer safeguards apply)resend.com
Google LLCMaps API for geographic visualisationUSA (EU data transfer safeguards apply)policies.google.com
Cloudflare, Inc.DNS, CDN, and DDoS protectionUSA (EU data transfer safeguards apply)cloudflare.com

We do not authorise any processor to use your data for their own purposes beyond providing services to us.

6. Data Retention

7. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by GDPR Article 33-34.

8. Your GDPR Rights

As a data subject under the GDPR, you have the following rights:

Right of access (Art. 15)

Request a copy of the personal data we hold about you.

Right to rectification (Art. 16)

Request correction of inaccurate or incomplete personal data.

Right to erasure (Art. 17)

Request deletion of your personal data where there is no compelling reason for continued processing.

Right to restriction (Art. 18)

Request that we restrict processing of your data in certain circumstances.

Right to data portability (Art. 20)

Receive your data in a structured, machine-readable format. Use the export tools in the Service or contact us.

Right to object (Art. 21)

Object to processing based on legitimate interests. We will cease unless we have compelling legitimate grounds.

Right to withdraw consent

Where processing is based on consent, withdraw at any time without affecting prior processing.

Right to lodge a complaint

Lodge a complaint with the Romanian supervisory authority (ANSPDCP) or your local EU supervisory authority.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. We may need to verify your identity before processing your request.

Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)dataprotection.ro

9. Cookies

GridVisio uses the following cookies:

CookiePurposeDurationType
Session cookieMaintains your authenticated sessionSession / 2 hoursStrictly necessary
CSRF tokenSecurity — prevents cross-site request forgerySessionStrictly necessary
PreferencesRemembers UI preferences (map type, filter state)1 yearFunctional

We do not use advertising cookies or third-party tracking cookies. The Google Maps API may set its own cookies for map functionality — these are governed by Google's privacy policy.

Strictly necessary cookies cannot be disabled as they are required for the Service to function. You may disable functional cookies through your browser settings, but this may affect your experience.

10. Children's Privacy

The Service is not directed at children under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us at [email protected] and we will delete it promptly.

11. International Data Transfers

Some of our third-party processors are located outside the European Economic Area (EEA), including in the United States. Where we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:

Our primary hosting infrastructure (Hetzner) is located in Germany and your data is stored within the EU by default.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice in the Service at least 14 days before the changes take effect. The current version is always available at gridvisio.com/privacy. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

13. Contact and Complaints

For any privacy-related questions, requests to exercise your rights, or concerns about how we handle your data:

GridVisio
Email: [email protected]
Website: gridvisio.com

If you are not satisfied with our response, you have the right to lodge a complaint with the Romanian data protection authority:

ANSPDCP
B-dul Magheru 28-30, Sector 1, Bucharest
dataprotection.ro
[email protected]