On this page
- The personal data we process, and why
- Cookies and similar technologies
- AI and automated decision-making
- Who we share personal data with
- International data transfers
- How long we keep personal data
- Your rights
- How we protect personal data
- Children
- Third-party links
- Changes to this Policy
- How to contact us
01 The personal data we process, and why
We collect only the personal data we need, and we always have a lawful basis under Article 6 of the GDPR for using it. The sections below are organised by the kind of relationship you have with us. Where data is not provided by you directly, we have noted the source.
A Visitors to our website
B Prospective clients and partners (and their representatives)
C Existing clients and partners (and their representatives)
D Newsletter and marketing contacts
E Suppliers and service providers (and their representatives)
F Job applicants
G Investors and their representatives
If you give us personal data about other people (for example, colleagues you name in correspondence), please make sure you are allowed to share it and that they know how we will use it, as described in this Policy.
↑ Back to top03 AI and automated decision-making
Building AI is what we do, so we want to be precise about how it relates to your personal data.
In the activities covered by this Policy, where we act as a data controller, we do not use AI to make automated decisions that produce legal effects concerning you or that similarly significantly affect you, within the meaning of Article 22 of the GDPR. Our website, marketing and relationship management do not subject you to that kind of automated decision-making.
The autonomous processing carried out by our DFTEs happens inside a client's environment, on the client's instructions, where the client is the data controller and we are the processor. That is governed by our Data Processing Agreement with the client, not by this Policy.
We design and operate our technology to align with the EU Artificial Intelligence Act (Regulation (EU) 2024/1689). Where a DFTE interacts directly with a person, we and our clients provide appropriate transparency that the interaction is with an AI system, consistent with that Regulation.
↑ Back to top05 International data transfers
We are based in Romania and prefer to keep personal data within the European Economic Area (EEA) wherever we can. Some of our service providers, however, may process data outside the EEA.
When that happens, we make sure the transfer is protected by an appropriate safeguard recognised under Chapter V of the GDPR. In practice this means one of the following:
- the country has been recognised by the European Commission as providing an adequate level of protection, or the recipient is certified under a recognised framework such as the EU-US Data Privacy Framework; or
- the transfer is governed by the European Commission's Standard Contractual Clauses, together with any additional measures needed to protect the data.
You can ask us for more information about the safeguards that apply using the contact details in Section 12.
↑ Back to top06 How long we keep personal data
We keep personal data only for as long as we need it for the purposes set out in this Policy, and then for any further period required by law. The main retention periods we apply are:
- Clients, partners and suppliers: for the duration of the relationship and afterwards for the relevant statutory limitation period. Accounting and tax records are kept for the periods required by Romanian law.
- Prospects and enquiries: for a limited period after our last meaningful contact, if no relationship is formed.
- Newsletter and marketing: until you unsubscribe or withdraw consent, after which we stop using your details for that purpose.
- Job applicants: for a limited period after the recruitment process ends, or longer where you have consented to be kept on file.
- Website and analytics data: for a limited period, as set out in our Cookie Policy.
The retention of personal data contained in client data that our DFTEs process is dealt with separately in the relevant Data Processing Agreement.
↑ Back to top07 Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Access - to be told whether we process your data and to receive a copy of it.
- Rectification - to have inaccurate data corrected and incomplete data completed.
- Erasure - to have your data deleted in certain circumstances, for example where it is no longer needed.
- Restriction - to limit how we use your data in certain circumstances.
- Objection - to object to processing based on our legitimate interests, and to object at any time to processing for direct marketing.
- Portability - to receive data you provided to us in a structured, commonly used, machine-readable format, or to have it sent to another controller.
- Withdraw consent - to withdraw any consent you have given, at any time, without affecting processing carried out beforehand.
To exercise any of these rights, contact us at privacy@outcome1.ai. We will respond within one month, and will tell you if we need longer because the request is complex. Exercising your rights is free, although we may charge a reasonable fee or decline to act if a request is manifestly unfounded or excessive.
If you have a concern about how we handle your personal data, we would like the chance to address it first. You also have the right to lodge a complaint with the Romanian supervisory authority, or to seek a remedy through the courts.
Romanian supervisory authority
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, Romania
Email: anspdcp@dataprotection.ro · Web: www.dataprotection.ro
08 How we protect personal data
We take appropriate technical and organisational measures to protect personal data against loss, misuse, and unauthorised access, alteration or disclosure, as required by Article 32 of the GDPR. These measures include access controls on a need-to-know basis, encryption of data in transit and at rest, careful selection of the providers we work with, and internal practices designed to keep data secure. We review and improve these measures as our business grows.
No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to present a risk to you, we will act in line with our legal obligations, including notifying the supervisory authority and, where required, the people affected.
↑ Back to top09 Children
Our website and services are intended for businesses and the professionals who work for them. They are not directed at children, and we do not knowingly collect the personal data of anyone under the age of 16, which is the age of digital consent under Romanian law. If you believe a child has provided us with personal data, please contact us and we will delete it.
↑ Back to top10 Third-party links
Our website may contain links to other websites that we do not operate. This Policy does not apply to those sites, and we are not responsible for their content or privacy practices. We encourage you to read the privacy notice of any website you visit.
↑ Back to top11 Changes to this Policy
We may update this Policy from time to time, for example to reflect changes in our services or in the law. When we do, we will post the updated version here and change the "last updated" date at the top. If the changes are significant, we will take reasonable steps to let affected clients and partners know, including as required by our agreements with them.
↑ Back to top12 How to contact us
If you have any questions about this Policy or about how we handle personal data, or if you want to exercise your rights, please get in touch:
SC OUTCOME1 SRL
Strada Bogdan Vodă, Nr. 61, Camera nr. 1, Etaj 1, Municipiul Constanța, Romania
Trade Registry no. J2026020067009 · CUI 54350340 · VAT RO54350340 · Share capital 1,000 RON · EUID ROONRC.J2026020067009 · DUNS 30-314-5078
Email: privacy@outcome1.ai
