Legal

Ultron — Privacy Policy

Ultron privacy policy: how we handle personal data.

Effective / last updated: 10 August 2026

Controller

CROITORU GABRIEL PFA (Romanian authorized sole trader), CUI 45933816, Trade Register no. F40/1475/2022, B-dul Bucureștii Noi 136, parter, ap. 5, Sector 1, București, România. Privacy contact: [email protected], +40 746 572 184. We have not appointed a separate data protection officer; for any privacy request, contact the controller directly using the details above.

What we process, why, and on what basis

  • Site and security logs: IP address, date/time, requested URL (with report access keys redacted), response code, user agent, and technical diagnostics. Purpose: service delivery, debugging, and abuse or incident prevention. Basis: legitimate interests in operating a secure, reliable service (GDPR Art. 6(1)(f)).
  • Contact and quote requests: name, email, phone, organization, message, and project details you provide. Purpose: responding, quoting, and preparing or performing a contract. Basis: pre-contract steps at your request or contract performance (Art. 6(1)(b)), and where applicable legitimate interests in handling business communications (Art. 6(1)(f)).
  • Site Doctor: submitted public-site origin and hostname, pseudonymized/encrypted client and target identifiers, publicly available response data, technical evidence, screenshots, audit report, site-control-verification status, and a high-entropy report access key. Site-control verification is technical and does not establish legal ownership. Purpose: performing the requested assessment, providing access, capacity limiting, and security. Basis: performance of the requested service/contract (Art. 6(1)(b)) and legitimate security interests (Art. 6(1)(f)).
  • Optional search-provider connection: only if you expressly start it and prove control of the site: Google Search Console or Bing Webmaster properties, query, page, traffic, indexing, crawl, and sitemap data, selected property, short-lived OAuth/API credentials, and the imported snapshot. Purpose: one-time SEO enrichment. Basis: providing the requested service (Art. 6(1)(b)); Google OAuth permission can separately be revoked in the Google account. Credentials are encrypted server-side.
  • Payment and billing: Stripe processes full card details, billing name and address, email, tax ID, fraud-prevention signals, and the assessed public hostname in the customer-facing payment and invoice descriptions. Ultron stores Stripe object IDs, a support reference, amounts, currency, country, tax and payment status, policy versions, and consent timestamps; it retrieves fresh invoice/receipt links when requested and does not store those links, the full card number, CVC, or raw webhook body. Basis: contract performance (Art. 6(1)(b)), accounting/tax legal obligations (Art. 6(1)(c)), and legitimate fraud-prevention interests (Art. 6(1)(f)).
  • Cookies and first-party browser storage: The browser may retain dismissal of the necessary-storage notice, the selected language, Site Doctor remediation selections, and an Ops Guardian dismissal preference. These records support necessary functions or remember an interaction requested on the device; they are not used for analytics or marketing. The Cookie Policy lists each key, its accessibility, lifetime, and deletion behavior.
  • Consumer withdrawal: full name, order reference, confirmation email, request content, date and time, handling status, and durable-receipt delivery status. Purpose: exercising and documenting consumer rights, handling any refund, and defending legal claims. Basis: contract performance and legal obligation.

Data sources and whether provision is required

We receive data directly from you, your browser/device, the submitted public website, and Stripe, Google, or Bing when you choose to connect them. Contact fields are voluntary but may be needed to respond. Without the target URL, technical identifiers, and marked payment details, we cannot provide Site Doctor or the purchase. Do not provide special-category data, another person’s credentials, or secret URLs.

Recipients and processors

Data is accessible only to those who need it to operate Ultron or meet legal obligations. Where applicable, we use:

  • hosting, database, backup, and infrastructure providers (currently DigitalOcean infrastructure);
  • Cloudflare for content delivery, network security, and, when enabled, Turnstile abuse protection;
  • Stripe for payments, tax, invoicing, and payment-fraud prevention;
  • Google or Microsoft/Bing only for a one-time provider import that you initiate;
  • email, accounting, legal, or public-authority recipients where communication, contract, or law requires it.
  • Mailtrap (Railsware Products Studio LLC) for transactional withdrawal receipts and operator notifications; no marketing messages are sent through this flow.

We do not sell personal data or disclose it for a third party’s independent marketing.

International transfers

Some global providers may process data outside the European Economic Area. In those cases we rely on adequacy decisions, European Commission standard contractual clauses, and supplementary measures where needed. Each provider’s notice describes locations and safeguards.

Retention

  • Site Doctor reports, screenshots, audit evidence, and optional search snapshots: 30 days from creation by default, then automated deletion.
  • Google/Bing connection state and encrypted short-lived credentials: for the minutes needed to connect, no more than 30 minutes; then deleted or made unusable.
  • Pseudonymous abuse-limiting identifiers: until the applicable minute/hour rate-limit window ends, plus a short technical margin.
  • Application and security logs: the shortest period needed for troubleshooting and abuse prevention, determined by regular rotation; necessary portions may be isolated longer for a confirmed incident, legal claim, or authority request.
  • Contact and quote correspondence: for the relationship and normally up to 3 years after the last substantive communication, unless a legal claim or contract justifies longer retention.
  • Purchase, invoice, and tax-supporting records: 5 years calculated from 1 July of the year following the end of the financial year in which they were created, under Romanian accounting law. A specific record is retained longer only while an active legal hold or dispute requires it.
  • Withdrawal requests and delivery/handling evidence: for the applicable limitation period and longer only where a legal dispute or statutory accounting record requires it.

Security and report links

We use technical and organizational measures including TLS, access controls, pseudonymization, short-lived provider credentials, and automated deletion. No online system is risk-free. A report link is itself an access key: anyone who has it can view the report until expiry, so keep it confidential and do not publish it.

Automated decisions and children

Site Doctor produces an automated technical assessment, but does not make solely automated decisions about you with legal or similarly significant effects and does not create marketing profiles. The service is not directed to children; anyone under 18 should enter a paid contract only through a parent or legal representative.

Your rights

Subject to legal conditions, you may request access, rectification, erasure, restriction, and portability; object to processing based on legitimate interests; and withdraw consent prospectively at any time. You may complain to Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP) or the authority where you live/work. To exercise rights, email the privacy contact; we may proportionately verify identity and the scope of the request. www.dataprotection.ro.

Changes

We update this notice when services or legal requirements change. A material change will be marked by the date and, where its impact warrants, a prominent notice. At purchase, we record the privacy version accepted.