Legal
Privacy policy
Effective and last updated: 30 August 2026
We collect only the personal data needed to operate our website, provide accounts and licences, sell and support our software, understand our audience, and meet our legal obligations.
1. Scope
This policy applies to Robisonic websites, customer accounts, direct purchases, licence and activation services, support communications, and desktop applications published by Robisonic, including StorageFox. It does not govern websites, stores, or services operated independently by third parties.
It covers customer registration, direct checkout, app-store purchases, analytics, authentication, cookies, marketing, advertising technologies, licensing, and other processing described below. Some processing depends on the services, settings, products, stores, or choices involved in your interaction with us.
2. Controller and contact details
The data controller is S.C. ROBISONIC S.R.L., a company registered in Romania under CIF 53832766 and trade register number J2026008505002. In this policy, “Robisonic”, “we”, “us”, and “our” refer to that company.
For privacy questions, requests, or complaints, email office@robisonic.com. We have not appointed a data protection officer. Privacy enquiries are handled through the contact address above.
3. Data we collect and where it comes from
The data collected depends on which services you use. We may process the following categories:
- Identity and contact data: name, username, email address, telephone number, postal or billing address, country or region, company name, job title, and contact preferences.
- Account and authentication data: account identifier, password hash, authentication tokens, verification status, sign-in timestamps, recovery information, multi-factor authentication status, and identifiers received from a sign-in provider.
- Purchase and billing data: products purchased, order and transaction identifiers, price, currency, payment status, billing address, tax country, VAT or tax identifier, invoices, refunds, and chargeback information.
- Licence data: licence key or entitlement, product and edition, activation status, issue and expiry dates where applicable, activation count, and the store or channel through which the licence was obtained.
- Device and activation data: a machine identifier or a derived and pseudonymised device fingerprint, operating system, app version, device name where supplied, IP address, activation timestamps, and information needed to enforce device limits and prevent abuse.
- Website and technical data: IP address, date and time, requested URL, referrer, browser, operating system, device type, screen size, language, approximate country, cookie or consent identifiers, and security or diagnostic events.
- Usage and analytics data: page views, session duration, navigation paths, campaign parameters, downloads, button interactions, conversions, and aggregated audience statistics.
- Communications: messages, support requests, survey answers, reviews, attachments, and records of our responses.
- Marketing and advertising data: subscription status, campaign engagement, advertising identifiers, cookie identifiers, inferred interests or audience segment, and opt-in or opt-out records.
- Preference and participation data: language, region, display choices, saved settings, beta or research participation, promotion entries, referrals, and product feedback.
- Public and business data: public reviews or posts, business contact details, employer or organisation, and information made available through professional or public sources.
We receive data directly from you when you register, purchase, activate a licence, change settings, enter a promotion, answer a survey, submit a review, join a beta programme, contact us, or consent to optional technologies. We receive other data automatically from your browser, device, or Robisonic app.
We may receive data indirectly from payment providers, banks, app stores, authentication providers, distributors, resellers, affiliates, referral partners, fraud-prevention or identity-verification services, advertising and marketing partners, publicly available sources, and organisations whose representative or employee interacts with us.
We may combine data across your account, purchases, licences, devices, support history, website activity, and marketing preferences where necessary for the purposes and legal bases described below. We do not combine data in a way that is incompatible with those purposes.
Please do not send sensitive personal data, passwords, complete payment-card numbers, or app content in a support message unless we specifically request information through an appropriate secure channel.
4. Purposes and legal bases
| Purpose | Typical data | GDPR legal basis |
|---|---|---|
| Provide the website and protect it against misuse | Request, device, security, and log data | Legitimate interests, Article 6(1)(f) |
| Create and secure an account | Identity, contact, authentication, and security data | Contract, Article 6(1)(b), and legitimate interests |
| Process purchases, invoices, refunds, and taxes | Contact, billing, transaction, and tax data | Contract, Article 6(1)(b), and legal obligation, Article 6(1)(c) |
| Issue, activate, validate, and protect licences | Account, purchase, licence, device, activation, and IP data | Contract and legitimate interests in preventing fraud and unauthorised use |
| Provide support and answer enquiries | Contact, account, purchase, licence, device, and communication data | Contract, steps requested before contract, and legitimate interests |
| Manage settings, surveys, beta programmes, reviews, referrals, and promotions | Identity, contact, preference, participation, and communication data | Contract, consent, and legitimate interests, depending on the activity |
| Measure and improve the website | Usage, analytics, device, and approximate location data | Consent, Article 6(1)(a), where required; otherwise legitimate interests after an appropriate assessment |
| Send requested marketing | Contact, preference, purchase, and engagement data | Consent or another basis permitted by applicable electronic-marketing law |
| Measure or personalise advertising | Cookie, device, usage, conversion, and advertising data | Consent, Article 6(1)(a) |
| Detect fraud, chargebacks, abuse, and security threats | Account, transaction, licence, IP, device, authentication, and security data | Legitimate interests and legal obligations |
| Send essential service communications | Contact, account, purchase, licence, and security data | Contract, legal obligation, and legitimate interests |
| Comply with law and defend legal claims | Any data relevant to the obligation or claim | Legal obligation and legitimate interests |
Where we rely on legitimate interests, those interests include delivering and securing our services, preventing fraud, enforcing licence terms, answering users, improving reliability, and protecting our legal rights. We consider the necessity and impact of the processing and do not rely on this basis where your rights and interests override ours.
5. Website, analytics, and cookies
Server logs
Our hosting infrastructure processes technical request data to deliver, secure, and troubleshoot the website. This may include IP address, request time, requested page, referrer, browser or device information, and diagnostic or security events.
Umami analytics
We use a self-hosted Umami tracker to understand visits and improve the website. It may process page URL and title, referrer, browser language, screen size, browser, operating system, device type, approximate country, session information, and events such as downloads or button interactions. Standard Umami operates without analytics cookies and generates a session identifier from technical request information. We do not intentionally send names, email addresses, licence keys, payment details, or free-text form contents to Umami.
The Umami script is not requested or executed unless you select “Allow analytics” in our cookie banner. You can withdraw that permission at any time through “Cookie settings” in the footer.
Cookie categories
- Strictly necessary: security, load balancing, checkout continuity, authentication, session management, fraud prevention, and remembering privacy choices. These cannot normally be disabled through our site because the requested service would not work.
- Preferences: language, display, region, and other optional settings.
- Analytics: audience measurement, page performance, navigation, and conversion statistics.
- Advertising: campaign measurement, frequency controls, audience creation, and personalised or contextual advertising.
Non-essential cookies and similar technologies are used only after the required consent. The live cookie settings interface identifies the active providers, purposes, cookie names, and durations. You can accept or reject categories with equal ease and change your choice later. Browser controls can also delete or block cookies, although blocking necessary cookies may prevent sign-in or checkout from working.
We store your analytics choice in your browser’s local storage under robisonic-cookie-consent for up to 180 days. This is strictly necessary to remember and apply your privacy selection across pages.
6. Accounts and authentication
When you register, we process the information needed to create, authenticate, recover, and secure your account and to associate purchases and licences with it. Required fields are marked. If required information is not provided, we may be unable to create the account or provide account-based services.
Passwords will be stored as cryptographic hashes rather than readable passwords. Authentication cookies or tokens will keep you signed in and protect account actions. Security logs may record sign-in attempts, IP addresses, device or browser information, password resets, and suspicious activity.
If you choose a third-party sign-in provider, that provider will process your interaction under its own privacy terms and may send us an account identifier, email address, name, or other information you approve. We will identify available providers at the point of sign-in.
We may associate multiple purchases, store entitlements, licence keys, and devices with one account. Account settings may allow you to review profile information, purchase history, licences, active devices, privacy choices, and marketing preferences.
7. Purchases and payments
Direct purchases and Stripe
Stripe provides payment processing and fraud-prevention services for direct sales. Stripe may collect your name, email, billing address, tax information, IP address, device information, payment method details, purchase amount, and transaction data. Stripe may act as our processor for parts of payment processing and as an independent controller for activities it determines, such as regulatory compliance, fraud prevention, and operation of its own services.
Payment-card and bank details are entered into Stripe-controlled payment fields and are processed by Stripe and the relevant banks or payment networks. We generally receive limited information such as payment status, payment method type and last digits, transaction identifier, billing details, tax information, refunds, and fraud indicators rather than the complete card number. See the Stripe Privacy Policy.
We use transaction data to complete orders, deliver licences, issue invoices and credit notes, calculate or verify VAT and other taxes, process refunds and disputes, reconcile accounts, detect fraud, and meet consumer-protection, accounting, sanctions, and tax obligations. Stripe or another checkout provider may process an incomplete checkout for fraud prevention, technical recovery, or a permitted cart reminder.
Third-party app stores
Our apps are also distributed through Microsoft Store, Apple App Store, Mac App Store, and other software stores and distributors. Those providers independently process account, browsing, payment, purchase, download, device, licensing, update, rating, review, fraud, and support data under their own policies.
They may provide Robisonic with limited purchase and entitlement information, such as product, country, order or receipt identifier, purchase status, refund, and a store-specific customer or device identifier. We use that information to validate purchases, provide licences and support, reconcile payments, and prevent fraud. Review the privacy notice presented by the store you use, including the Microsoft Privacy Statement or Apple App Store & Privacy.
8. Licensing and applications
Licence services
Robisonic apps may contact our licence service to issue, activate, validate, deactivate, recover, or enforce a licence. The service may receive an email or account identifier, licence key or entitlement, product and version, a machine identifier or derived fingerprint, operating system, IP address, activation status, and timestamps.
We use licence data to perform the software contract, maintain entitlements across permitted devices, prevent duplicate or fraudulent use, troubleshoot activation, and protect the service. Where feasible, device identifiers will be hashed, pseudonymised, or otherwise limited to what is necessary for licensing.
Local app content
Our desktop apps are designed to process their working data locally. They do not submit the contents of your files, projects, scans, or documents to Robisonic servers. Only information needed for accounts, purchases, licensing, activation, security, and support is transmitted, unless an online feature clearly explains different processing before you enable it.
Our apps do not use local app content for advertising, profiling, or AI training. If you choose to attach app content, logs, screenshots, or diagnostic files to a support request, we process what you send only to handle that request and related security or legal issues.
9. Support and other communications
If you contact us, we receive the information you provide, such as your name, email address, account or licence details, message, and attachments. We use it to answer enquiries, provide technical or purchase support, discuss projects, investigate security issues, or manage our relationship with you.
Providing information is voluntary, but we may be unable to respond or provide requested support without contact details and enough information to understand the request.
10. Marketing, surveys, and advertising
If you ask to receive product news, offers, or newsletters, we may use your email address, name, preferences, purchase history, and engagement data to send relevant communications. You can unsubscribe through the link in each marketing email or by contacting us. Withdrawing marketing consent does not affect service messages about purchases, security, licences, or material account changes.
We may personalise marketing based on products owned, account settings, region, previous interactions, and campaign engagement. Where electronic-marketing rules allow communications to existing customers without separate consent, we will provide a clear opt-out when details are collected and in every message.
We may invite users to optional surveys, reviews, beta programmes, or feedback sessions. The invitation will explain what data is requested and whether responses may be published. Participation is voluntary.
We use advertising technologies through which advertising partners may process cookie identifiers, IP address, browser or device information, pages viewed, ad interactions, campaign and conversion data, and approximate location. They may use that data to measure campaigns or create audience segments. Advertising and cross-site tracking that require consent remain disabled unless you opt in. Advertising partners are identified in the cookie settings or this policy.
12. Retention and security
We retain personal data only for the shortest period reasonably needed for the purpose, taking account of account and licence duration, user choices, security, legal limitation periods, and tax, accounting, consumer-protection, and regulatory duties.
| Data category | Typical retention criterion |
|---|---|
| Account and profile | While the account is active, then for a limited deletion and backup period unless legal retention applies |
| Purchases, invoices, and tax records | For the statutory accounting, tax, consumer-protection, and claims periods |
| Licence and entitlement records | For the life of the licence and as needed afterwards to restore purchases, enforce terms, prevent fraud, or resolve claims |
| Machine activation records | While an activation or related licence is active, followed by a limited anti-abuse and dispute period |
| Security and server logs | Normally for a short operational period, extended only for an incident, investigation, or legal requirement |
| Umami analytics | According to the configured analytics retention period, normally no longer than 24 months before deletion or aggregation |
| Support and general correspondence | Until the request and related follow-up are complete, then as needed for service history, security, or legal claims |
| Marketing data | Until consent is withdrawn or you object, with a minimal suppression record retained to respect the opt-out |
| Consent records | As needed to demonstrate and manage consent and for the applicable legal claims period |
When a retention period ends, data is deleted, anonymised, or isolated from normal use until secure deletion from backups. Third-party controllers apply their own retention schedules.
Security
We use proportionate technical and organisational measures designed to protect personal data, including access controls, least-privilege administration, encrypted transport, password hashing, software updates, backups, monitoring, and contractual controls for providers where appropriate. No internet transmission or storage system can be guaranteed completely secure.
If a personal-data breach creates a risk to individuals, we will document and notify it to the competent authority within the period required by law. Where the breach is likely to create a high risk, we will also notify affected individuals without undue delay.
13. Your data-protection rights
Subject to the conditions and exceptions in the GDPR, you may:
- ask whether we process your data and receive access to it;
- correct inaccurate data and complete incomplete data;
- request erasure where there is no continuing lawful reason to retain the data;
- restrict processing in the circumstances provided by law;
- receive data you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller;
- object to processing based on legitimate interests, including profiling based on those interests;
- object at any time to direct marketing;
- withdraw consent at any time without affecting processing already carried out lawfully; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to GDPR exceptions.
Advertising personalisation or audience selection may involve profiling, but we do not make solely automated decisions about you that produce legal or similarly significant effects. You can reject or withdraw consent for advertising technologies.
To exercise a right, email office@robisonic.com. We may request information needed to verify your identity and protect the account. We normally respond within one month. A complex request or multiple requests may allow an extension of up to two further months, in which case we will explain the delay within the first month.
Requests are normally free. We may charge a reasonable fee or refuse a request only where the GDPR permits it, such as where a request is manifestly unfounded or excessive. If we cannot comply, we will explain why and describe your complaint options.
Complaints
You may contact us so we can try to resolve your concern. This does not limit your right to complain at any time to the Romanian National Supervisory Authority for Personal Data Processing, known as ANSPDCP, or to the supervisory authority in the EU country where you live or work.
14. Children
Our website, accounts, and apps are intended for a general audience and are not directed to children. We do not knowingly collect personal data from a child who cannot lawfully provide consent. If consent is required and the user is below the applicable digital-consent age, consent must be given or authorised by a parent or legal guardian. Contact us if you believe a child has provided data improperly so we can investigate and delete it where required.
15. External links and third-party services
Our website and apps may link to websites and services we do not operate. Their privacy notices govern activity after you leave our service. A link does not make Robisonic responsible for the third party’s content, security, or privacy practices.
16. Changes to this policy
We review this policy as our products, website, providers, and legal obligations change. Updates will be posted at this URL and the revision date will change. If a change materially affects registered users or requires a new choice, we will provide additional notice through the account, app, email, or consent interface as appropriate and request consent where required.
17. Contact us
Questions about this policy, our processing, or your rights can be sent to office@robisonic.com.
S.C. ROBISONIC S.R.L.
CIF 53832766
Trade register: J2026008505002
Romania