Privacy Policy

    How we collect, use and protect personal data, and the rights you have over it, under the GDPR and Romanian law.

    Last updated01 July 2026
    Effective from01 July 2026
    Version1.0
    Applies tooutcome1.ai & our business operations

    SC OUTCOME1 SRL ("Outcome1.AI", "we", "us" or "our") is a company incorporated under Romanian law, with its registered office at Strada Bogdan Vodă, Nr. 61, Camera nr. 1, Etaj 1, Municipiul Constanța, Romania, registered with the Romanian Trade Registry under no. J2026020067009, sole registration code (CUI) 54350340, VAT identification number RO54350340, EUID ROONRC.J2026020067009 and a subscribed share capital of 1,000 RON. We build and operate Digital Full-Time Employees (DFTEs): autonomous AI agents that carry out defined roles for European businesses.

    Your privacy matters to us, and we treat it as a condition of doing business well rather than a formality. We process personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Romanian law, including Law no. 190/2018 (implementing the GDPR), Law no. 506/2004 (privacy in electronic communications) and Law no. 365/2002 (electronic commerce).

    Two roles, two documents. Read this first.

    This Privacy Policy explains how we handle personal data when we act as a data controller, meaning when we decide why and how data is processed. That covers visitors to our website, prospective and existing clients and partners and the people who represent them, anyone who contacts us, newsletter subscribers, job applicants, our suppliers, and investors.

    It does not cover the personal data our DFTEs process inside a client's own environment, on that client's instructions. In that setting the client is the data controller and we act only as a data processor. How we handle that data is governed by the Data Processing Agreement (DPA) we sign with each client and by the client's own privacy notice, not by this Policy. See Section 5 and our Data Processing Agreement.

    On this page
    1. The personal data we process, and why
    2. Cookies and similar technologies
    3. AI and automated decision-making
    4. Who we share personal data with
    5. International data transfers
    6. How long we keep personal data
    7. Your rights
    8. How we protect personal data
    9. Children
    10. Third-party links
    11. Changes to this Policy
    12. How to contact us

    01 The personal data we process, and why

    We collect only the personal data we need, and we always have a lawful basis under Article 6 of the GDPR for using it. The sections below are organised by the kind of relationship you have with us. Where data is not provided by you directly, we have noted the source.

    A Visitors to our website

    DataIP address, device and browser type, pages viewed, referring page, date and time of access, and similar technical and usage data collected through cookies and analytics.
    PurposeTo operate, secure and improve outcome1.ai, understand how it is used, and respond to enquiries you send us.
    Legal basisArt. 6(1)(f)Our legitimate interest in running and improving a secure website. Art. 6(1)(a)Your consent, for non-essential cookies and analytics.
    SourceCollected automatically when you visit.

    B Prospective clients and partners (and their representatives)

    DataName, business email, phone, job title, employer, and the content of demo requests, enquiries and our related correspondence.
    PurposeTo respond to your interest, arrange and run demonstrations and proofs of concept, prepare proposals, and take steps toward a possible agreement.
    Legal basisArt. 6(1)(b)Steps taken at your request before entering into a contract. Art. 6(1)(f)Our legitimate interest in developing business relationships in our sector.
    SourceFrom you, from the organisation you represent, or from public professional sources such as company websites.

    C Existing clients and partners (and their representatives)

    DataContact and identification details of the individuals who manage the relationship, account and access details, and correspondence relating to the services.
    PurposeTo deliver and support our services, manage the relationship, handle billing, and meet our legal and contractual obligations.
    Legal basisArt. 6(1)(b)Performance of our contract. Art. 6(1)(c)Compliance with legal obligations, such as accounting and tax. Art. 6(1)(f)Our legitimate interest in managing the relationship properly.
    SourceFrom you or from the client or partner organisation.

    D Newsletter and marketing contacts

    DataName and email address, and basic engagement data such as whether an email was opened.
    PurposeTo send you updates, insights and event invitations you have asked to receive.
    Legal basisArt. 6(1)(a)Your consent, which you can withdraw at any time using the unsubscribe link in any message or by contacting us. Withdrawing consent does not affect processing carried out before withdrawal.
    SourceFrom you, when you subscribe.

    E Suppliers and service providers (and their representatives)

    DataContact and identification details of the individuals we deal with, and information needed to manage the engagement and payments.
    PurposeTo receive services, manage the engagement, and meet our legal obligations.
    Legal basisArt. 6(1)(b)Performance of our contract with you or your organisation. Art. 6(1)(c)Compliance with legal obligations. Art. 6(1)(f)Our legitimate interest in managing our suppliers.
    SourceFrom you or from the supplier organisation.

    F Job applicants

    DataThe information in your application: name, contact details, CV, education, work history, qualifications, and our notes from the recruitment process.
    PurposeTo assess your application and manage recruitment. With your consent, we may keep your details to consider you for future roles.
    Legal basisArt. 6(1)(b)Steps taken at your request before a possible employment relationship. Art. 6(1)(f)Our legitimate interest in assessing suitability. Art. 6(1)(a)Your consent, where we retain your details for future opportunities.
    SourceFrom you, or from a recruiter acting for you.

    G Investors and their representatives

    DataName, contact details, organisation, and correspondence relating to our funding, including access to materials we share for due diligence.
    PurposeTo manage our fundraising and investor relationships and to meet related legal and reporting obligations.
    Legal basisArt. 6(1)(f)Our legitimate interest in raising and managing investment. Art. 6(1)(b)Steps toward, or performance of, an investment agreement. Art. 6(1)(c)Compliance with legal obligations.
    SourceFrom you or the organisation you represent.

    If you give us personal data about other people (for example, colleagues you name in correspondence), please make sure you are allowed to share it and that they know how we will use it, as described in this Policy.

    ↑ Back to top

    02 Cookies and similar technologies

    Our website uses cookies and similar technologies. Strictly necessary cookies make the site work and do not require your consent. Non-essential cookies, such as analytics and preference cookies, are used only with your consent, which we ask for through our cookie banner and which you can change or withdraw at any time.

    This reflects Law no. 506/2004, which implements the EU ePrivacy Directive in Romania. For the full list of cookies we use, their purpose and how long they last, please see our Cookie Policy.

    ↑ Back to top

    03 AI and automated decision-making

    Building AI is what we do, so we want to be precise about how it relates to your personal data.

    In the activities covered by this Policy, where we act as a data controller, we do not use AI to make automated decisions that produce legal effects concerning you or that similarly significantly affect you, within the meaning of Article 22 of the GDPR. Our website, marketing and relationship management do not subject you to that kind of automated decision-making.

    The autonomous processing carried out by our DFTEs happens inside a client's environment, on the client's instructions, where the client is the data controller and we are the processor. That is governed by our Data Processing Agreement with the client, not by this Policy.

    We design and operate our technology to align with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). Where a DFTE interacts directly with a person, we and our clients provide appropriate transparency that the interaction is with an AI system, consistent with that Regulation.

    ↑ Back to top

    04 Who we share personal data with

    We do not sell personal data. We share it only where there is a clear reason to, and with appropriate safeguards in place. The categories of recipient are:

    • Service providers acting on our behalf. Providers of hosting and cloud infrastructure, IT and security, email and communications, customer relationship management, analytics, and similar operational tools. They act as our processors under written contracts that meet Article 28 of the GDPR, and may use the data only as instructed by us.
    • Professional advisors. Our lawyers, accountants, auditors and other advisors, where they need the information to provide their services.
    • Authorities. Courts, regulators and public authorities, where we are required to disclose information by law or to establish, exercise or defend legal claims.
    • Parties to a corporate transaction. Where we raise investment or undergo a reorganisation, merger or acquisition, relevant information may be shared with the parties involved and their advisors, under confidentiality.

    The list of specific providers we use is maintained internally and kept current. Where a provider also processes personal data on behalf of our clients as part of delivering a DFTE, that provider appears in the sub-processor list attached to the relevant Data Processing Agreement, which is the governing document for that processing.

    ↑ Back to top

    05 International data transfers

    We are based in Romania and prefer to keep personal data within the European Economic Area (EEA) wherever we can. Some of our service providers, however, may process data outside the EEA.

    When that happens, we make sure the transfer is protected by an appropriate safeguard recognised under Chapter V of the GDPR. In practice this means one of the following:

    • the country has been recognised by the European Commission as providing an adequate level of protection, or the recipient is certified under a recognised framework such as the EU-US Data Privacy Framework; or
    • the transfer is governed by the European Commission's Standard Contractual Clauses, together with any additional measures needed to protect the data.

    You can ask us for more information about the safeguards that apply using the contact details in Section 12.

    ↑ Back to top

    06 How long we keep personal data

    We keep personal data only for as long as we need it for the purposes set out in this Policy, and then for any further period required by law. The main retention periods we apply are:

    • Clients, partners and suppliers: for the duration of the relationship and afterwards for the relevant statutory limitation period. Accounting and tax records are kept for the periods required by Romanian law.
    • Prospects and enquiries: for a limited period after our last meaningful contact, if no relationship is formed.
    • Newsletter and marketing: until you unsubscribe or withdraw consent, after which we stop using your details for that purpose.
    • Job applicants: for a limited period after the recruitment process ends, or longer where you have consented to be kept on file.
    • Website and analytics data: for a limited period, as set out in our Cookie Policy.

    The retention of personal data contained in client data that our DFTEs process is dealt with separately in the relevant Data Processing Agreement.

    ↑ Back to top

    07 Your rights

    Under the GDPR you have the following rights in relation to your personal data:

    • Access - to be told whether we process your data and to receive a copy of it.
    • Rectification - to have inaccurate data corrected and incomplete data completed.
    • Erasure - to have your data deleted in certain circumstances, for example where it is no longer needed.
    • Restriction - to limit how we use your data in certain circumstances.
    • Objection - to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing.
    • Portability - to receive data you provided to us in a structured, commonly used, machine-readable format, or to have it sent to another controller.
    • Withdraw consent - to withdraw any consent you have given, at any time, without affecting processing carried out beforehand.

    To exercise any of these rights, contact us at privacy@outcome1.ai. We will respond within one month, and will tell you if we need longer because the request is complex. Exercising your rights is free, although we may charge a reasonable fee or decline to act if a request is manifestly unfounded or excessive.

    If you have a concern about how we handle your personal data, we would like the chance to address it first. You also have the right to lodge a complaint with the Romanian supervisory authority, or to seek a remedy through the courts.

    Romanian supervisory authority

    Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)

    B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, Romania

    Email: anspdcp@dataprotection.ro · Web: www.dataprotection.ro

    ↑ Back to top

    08 How we protect personal data

    We take appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, alteration or disclosure, as required by Article 32 of the GDPR. These measures include access controls on a need-to-know basis, encryption of data in transit and at rest, careful selection of the providers we work with, and internal practices designed to keep data secure. We review and improve these measures as our business grows.

    No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to present a risk to you, we will act in line with our legal obligations, including notifying the supervisory authority and, where required, the people affected.

    ↑ Back to top

    09 Children

    Our website and services are intended for businesses and the professionals who work for them. They are not directed at children, and we do not knowingly collect the personal data of anyone under the age of 16, which is the age of digital consent under Romanian law. If you believe a child has provided us with personal data, please contact us and we will delete it.

    ↑ Back to top

    11 Changes to this Policy

    We may update this Policy from time to time, for example to reflect changes in our services or in the law. When we do, we will post the updated version here and change the "last updated" date at the top. If the changes are significant, we will take reasonable steps to let affected clients and partners know, including as required by our agreements with them.

    ↑ Back to top

    12 How to contact us

    If you have any questions about this Policy or about how we handle personal data, or if you want to exercise your rights, please get in touch:

    SC OUTCOME1 SRL

    Strada Bogdan Vodă, Nr. 61, Camera nr. 1, Etaj 1, Municipiul Constanța, Romania

    Trade Registry no. J2026020067009 · CUI 54350340 · VAT RO54350340 · Share capital 1,000 RON · EUID ROONRC.J2026020067009 · DUNS 30-314-5078

    Email: privacy@outcome1.ai