Legal

Privacy policy

Effective and last updated: 30 August 2026

We collect only the personal data needed to operate our website, provide accounts and licences, sell and support our software, understand our audience, and meet our legal obligations.

1. Scope

This policy applies to Robisonic websites, customer accounts, direct purchases, licence and activation services, support communications, and desktop applications published by Robisonic, including StorageFox. It does not govern websites, stores, or services operated independently by third parties.

It covers customer registration, direct checkout, app-store purchases, analytics, authentication, cookies, marketing, advertising technologies, licensing, and other processing described below. Some processing depends on the services, settings, products, stores, or choices involved in your interaction with us.

2. Controller and contact details

The data controller is S.C. ROBISONIC S.R.L., a company registered in Romania under CIF 53832766 and trade register number J2026008505002. In this policy, “Robisonic”, “we”, “us”, and “our” refer to that company.

For privacy questions, requests, or complaints, email office@robisonic.com. We have not appointed a data protection officer. Privacy enquiries are handled through the contact address above.

3. Data we collect and where it comes from

The data collected depends on which services you use. We may process the following categories:

  • Identity and contact data: name, username, email address, telephone number, postal or billing address, country or region, company name, job title, and contact preferences.
  • Account and authentication data: account identifier, password hash, authentication tokens, verification status, sign-in timestamps, recovery information, multi-factor authentication status, and identifiers received from a sign-in provider.
  • Purchase and billing data: products purchased, order and transaction identifiers, price, currency, payment status, billing address, tax country, VAT or tax identifier, invoices, refunds, and chargeback information.
  • Licence data: licence key or entitlement, product and edition, activation status, issue and expiry dates where applicable, activation count, and the store or channel through which the licence was obtained.
  • Device and activation data: a machine identifier or a derived and pseudonymised device fingerprint, operating system, app version, device name where supplied, IP address, activation timestamps, and information needed to enforce device limits and prevent abuse.
  • Website and technical data: IP address, date and time, requested URL, referrer, browser, operating system, device type, screen size, language, approximate country, cookie or consent identifiers, and security or diagnostic events.
  • Usage and analytics data: page views, session duration, navigation paths, campaign parameters, downloads, button interactions, conversions, and aggregated audience statistics.
  • Communications: messages, support requests, survey answers, reviews, attachments, and records of our responses.
  • Marketing and advertising data: subscription status, campaign engagement, advertising identifiers, cookie identifiers, inferred interests or audience segment, and opt-in or opt-out records.
  • Preference and participation data: language, region, display choices, saved settings, beta or research participation, promotion entries, referrals, and product feedback.
  • Public and business data: public reviews or posts, business contact details, employer or organisation, and information made available through professional or public sources.

We receive data directly from you when you register, purchase, activate a licence, change settings, enter a promotion, answer a survey, submit a review, join a beta programme, contact us, or consent to optional technologies. We receive other data automatically from your browser, device, or Robisonic app.

We may receive data indirectly from payment providers, banks, app stores, authentication providers, distributors, resellers, affiliates, referral partners, fraud-prevention or identity-verification services, advertising and marketing partners, publicly available sources, and organisations whose representative or employee interacts with us.

We may combine data across your account, purchases, licences, devices, support history, website activity, and marketing preferences where necessary for the purposes and legal bases described below. We do not combine data in a way that is incompatible with those purposes.

Please do not send sensitive personal data, passwords, complete payment-card numbers, or app content in a support message unless we specifically request information through an appropriate secure channel.

4. Purposes and legal bases

PurposeTypical dataGDPR legal basis
Provide the website and protect it against misuseRequest, device, security, and log dataLegitimate interests, Article 6(1)(f)
Create and secure an accountIdentity, contact, authentication, and security dataContract, Article 6(1)(b), and legitimate interests
Process purchases, invoices, refunds, and taxesContact, billing, transaction, and tax dataContract, Article 6(1)(b), and legal obligation, Article 6(1)(c)
Issue, activate, validate, and protect licencesAccount, purchase, licence, device, activation, and IP dataContract and legitimate interests in preventing fraud and unauthorised use
Provide support and answer enquiriesContact, account, purchase, licence, device, and communication dataContract, steps requested before contract, and legitimate interests
Manage settings, surveys, beta programmes, reviews, referrals, and promotionsIdentity, contact, preference, participation, and communication dataContract, consent, and legitimate interests, depending on the activity
Measure and improve the websiteUsage, analytics, device, and approximate location dataConsent, Article 6(1)(a), where required; otherwise legitimate interests after an appropriate assessment
Send requested marketingContact, preference, purchase, and engagement dataConsent or another basis permitted by applicable electronic-marketing law
Measure or personalise advertisingCookie, device, usage, conversion, and advertising dataConsent, Article 6(1)(a)
Detect fraud, chargebacks, abuse, and security threatsAccount, transaction, licence, IP, device, authentication, and security dataLegitimate interests and legal obligations
Send essential service communicationsContact, account, purchase, licence, and security dataContract, legal obligation, and legitimate interests
Comply with law and defend legal claimsAny data relevant to the obligation or claimLegal obligation and legitimate interests

Where we rely on legitimate interests, those interests include delivering and securing our services, preventing fraud, enforcing licence terms, answering users, improving reliability, and protecting our legal rights. We consider the necessity and impact of the processing and do not rely on this basis where your rights and interests override ours.

5. Website, analytics, and cookies

Server logs

Our hosting infrastructure processes technical request data to deliver, secure, and troubleshoot the website. This may include IP address, request time, requested page, referrer, browser or device information, and diagnostic or security events.

Umami analytics

We use a self-hosted Umami tracker to understand visits and improve the website. It may process page URL and title, referrer, browser language, screen size, browser, operating system, device type, approximate country, session information, and events such as downloads or button interactions. Standard Umami operates without analytics cookies and generates a session identifier from technical request information. We do not intentionally send names, email addresses, licence keys, payment details, or free-text form contents to Umami.

The Umami script is not requested or executed unless you select “Allow analytics” in our cookie banner. You can withdraw that permission at any time through “Cookie settings” in the footer.

Cookie categories

  • Strictly necessary: security, load balancing, checkout continuity, authentication, session management, fraud prevention, and remembering privacy choices. These cannot normally be disabled through our site because the requested service would not work.
  • Preferences: language, display, region, and other optional settings.
  • Analytics: audience measurement, page performance, navigation, and conversion statistics.
  • Advertising: campaign measurement, frequency controls, audience creation, and personalised or contextual advertising.

Non-essential cookies and similar technologies are used only after the required consent. The live cookie settings interface identifies the active providers, purposes, cookie names, and durations. You can accept or reject categories with equal ease and change your choice later. Browser controls can also delete or block cookies, although blocking necessary cookies may prevent sign-in or checkout from working.

We store your analytics choice in your browser’s local storage under robisonic-cookie-consent for up to 180 days. This is strictly necessary to remember and apply your privacy selection across pages.

6. Accounts and authentication

When you register, we process the information needed to create, authenticate, recover, and secure your account and to associate purchases and licences with it. Required fields are marked. If required information is not provided, we may be unable to create the account or provide account-based services.

Passwords will be stored as cryptographic hashes rather than readable passwords. Authentication cookies or tokens will keep you signed in and protect account actions. Security logs may record sign-in attempts, IP addresses, device or browser information, password resets, and suspicious activity.

If you choose a third-party sign-in provider, that provider will process your interaction under its own privacy terms and may send us an account identifier, email address, name, or other information you approve. We will identify available providers at the point of sign-in.

We may associate multiple purchases, store entitlements, licence keys, and devices with one account. Account settings may allow you to review profile information, purchase history, licences, active devices, privacy choices, and marketing preferences.

7. Purchases and payments

Direct purchases and Stripe

Stripe provides payment processing and fraud-prevention services for direct sales. Stripe may collect your name, email, billing address, tax information, IP address, device information, payment method details, purchase amount, and transaction data. Stripe may act as our processor for parts of payment processing and as an independent controller for activities it determines, such as regulatory compliance, fraud prevention, and operation of its own services.

Payment-card and bank details are entered into Stripe-controlled payment fields and are processed by Stripe and the relevant banks or payment networks. We generally receive limited information such as payment status, payment method type and last digits, transaction identifier, billing details, tax information, refunds, and fraud indicators rather than the complete card number. See the Stripe Privacy Policy.

We use transaction data to complete orders, deliver licences, issue invoices and credit notes, calculate or verify VAT and other taxes, process refunds and disputes, reconcile accounts, detect fraud, and meet consumer-protection, accounting, sanctions, and tax obligations. Stripe or another checkout provider may process an incomplete checkout for fraud prevention, technical recovery, or a permitted cart reminder.

Third-party app stores

Our apps are also distributed through Microsoft Store, Apple App Store, Mac App Store, and other software stores and distributors. Those providers independently process account, browsing, payment, purchase, download, device, licensing, update, rating, review, fraud, and support data under their own policies.

They may provide Robisonic with limited purchase and entitlement information, such as product, country, order or receipt identifier, purchase status, refund, and a store-specific customer or device identifier. We use that information to validate purchases, provide licences and support, reconcile payments, and prevent fraud. Review the privacy notice presented by the store you use, including the Microsoft Privacy Statement or Apple App Store & Privacy.

8. Licensing and applications

Licence services

Robisonic apps may contact our licence service to issue, activate, validate, deactivate, recover, or enforce a licence. The service may receive an email or account identifier, licence key or entitlement, product and version, a machine identifier or derived fingerprint, operating system, IP address, activation status, and timestamps.

We use licence data to perform the software contract, maintain entitlements across permitted devices, prevent duplicate or fraudulent use, troubleshoot activation, and protect the service. Where feasible, device identifiers will be hashed, pseudonymised, or otherwise limited to what is necessary for licensing.

Local app content

Our desktop apps are designed to process their working data locally. They do not submit the contents of your files, projects, scans, or documents to Robisonic servers. Only information needed for accounts, purchases, licensing, activation, security, and support is transmitted, unless an online feature clearly explains different processing before you enable it.

Our apps do not use local app content for advertising, profiling, or AI training. If you choose to attach app content, logs, screenshots, or diagnostic files to a support request, we process what you send only to handle that request and related security or legal issues.

9. Support and other communications

If you contact us, we receive the information you provide, such as your name, email address, account or licence details, message, and attachments. We use it to answer enquiries, provide technical or purchase support, discuss projects, investigate security issues, or manage our relationship with you.

Providing information is voluntary, but we may be unable to respond or provide requested support without contact details and enough information to understand the request.

10. Marketing, surveys, and advertising

If you ask to receive product news, offers, or newsletters, we may use your email address, name, preferences, purchase history, and engagement data to send relevant communications. You can unsubscribe through the link in each marketing email or by contacting us. Withdrawing marketing consent does not affect service messages about purchases, security, licences, or material account changes.

We may personalise marketing based on products owned, account settings, region, previous interactions, and campaign engagement. Where electronic-marketing rules allow communications to existing customers without separate consent, we will provide a clear opt-out when details are collected and in every message.

We may invite users to optional surveys, reviews, beta programmes, or feedback sessions. The invitation will explain what data is requested and whether responses may be published. Participation is voluntary.

We use advertising technologies through which advertising partners may process cookie identifiers, IP address, browser or device information, pages viewed, ad interactions, campaign and conversion data, and approximate location. They may use that data to measure campaigns or create audience segments. Advertising and cross-site tracking that require consent remain disabled unless you opt in. Advertising partners are identified in the cookie settings or this policy.

11. Who receives data?

We do not sell personal data. Depending on the service used, we may disclose only the necessary data to:

  • hosting, infrastructure, database, content-delivery, security, backup, and email providers;
  • analytics providers, including Umami;
  • payment providers, including Stripe, banks, card networks, and fraud-prevention providers;
  • app stores and distributors, including Microsoft and Apple;
  • authentication, customer-support, licence-management, marketing, and advertising providers;
  • Robisonic affiliates or group companies involved in operating the same services, subject to this policy and appropriate access controls;
  • resellers, referral partners, and business partners where needed to fulfil a transaction, attribute a referral, or run an activity you joined;
  • accountants, auditors, insurers, lawyers, and other professional advisers;
  • courts, regulators, tax authorities, law enforcement, or other public bodies where disclosure is legally required; and
  • a purchaser, investor, or successor in a merger, financing, reorganisation, sale of assets, insolvency, or similar transaction, subject to confidentiality and appropriate safeguards.

Providers acting as processors may use data only on documented instructions, for the agreed service, and under contractual confidentiality, security, deletion, and data-protection obligations. Providers that determine their own purposes act as independent controllers and explain that processing in their own privacy notices.

International transfers

Some providers may process data outside Romania or the European Economic Area. Where GDPR requires it, transfers use a European Commission adequacy decision, standard contractual clauses, binding corporate rules, or another lawful mechanism, with supplementary safeguards where appropriate. You may contact us for information about the safeguards relevant to your data.

12. Retention and security

We retain personal data only for the shortest period reasonably needed for the purpose, taking account of account and licence duration, user choices, security, legal limitation periods, and tax, accounting, consumer-protection, and regulatory duties.

Data categoryTypical retention criterion
Account and profileWhile the account is active, then for a limited deletion and backup period unless legal retention applies
Purchases, invoices, and tax recordsFor the statutory accounting, tax, consumer-protection, and claims periods
Licence and entitlement recordsFor the life of the licence and as needed afterwards to restore purchases, enforce terms, prevent fraud, or resolve claims
Machine activation recordsWhile an activation or related licence is active, followed by a limited anti-abuse and dispute period
Security and server logsNormally for a short operational period, extended only for an incident, investigation, or legal requirement
Umami analyticsAccording to the configured analytics retention period, normally no longer than 24 months before deletion or aggregation
Support and general correspondenceUntil the request and related follow-up are complete, then as needed for service history, security, or legal claims
Marketing dataUntil consent is withdrawn or you object, with a minimal suppression record retained to respect the opt-out
Consent recordsAs needed to demonstrate and manage consent and for the applicable legal claims period

When a retention period ends, data is deleted, anonymised, or isolated from normal use until secure deletion from backups. Third-party controllers apply their own retention schedules.

Security

We use proportionate technical and organisational measures designed to protect personal data, including access controls, least-privilege administration, encrypted transport, password hashing, software updates, backups, monitoring, and contractual controls for providers where appropriate. No internet transmission or storage system can be guaranteed completely secure.

If a personal-data breach creates a risk to individuals, we will document and notify it to the competent authority within the period required by law. Where the breach is likely to create a high risk, we will also notify affected individuals without undue delay.

13. Your data-protection rights

Subject to the conditions and exceptions in the GDPR, you may:

  • ask whether we process your data and receive access to it;
  • correct inaccurate data and complete incomplete data;
  • request erasure where there is no continuing lawful reason to retain the data;
  • restrict processing in the circumstances provided by law;
  • receive data you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller;
  • object to processing based on legitimate interests, including profiling based on those interests;
  • object at any time to direct marketing;
  • withdraw consent at any time without affecting processing already carried out lawfully; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, subject to GDPR exceptions.

Advertising personalisation or audience selection may involve profiling, but we do not make solely automated decisions about you that produce legal or similarly significant effects. You can reject or withdraw consent for advertising technologies.

To exercise a right, email office@robisonic.com. We may request information needed to verify your identity and protect the account. We normally respond within one month. A complex request or multiple requests may allow an extension of up to two further months, in which case we will explain the delay within the first month.

Requests are normally free. We may charge a reasonable fee or refuse a request only where the GDPR permits it, such as where a request is manifestly unfounded or excessive. If we cannot comply, we will explain why and describe your complaint options.

Complaints

You may contact us so we can try to resolve your concern. This does not limit your right to complain at any time to the Romanian National Supervisory Authority for Personal Data Processing, known as ANSPDCP, or to the supervisory authority in the EU country where you live or work.

14. Children

Our website, accounts, and apps are intended for a general audience and are not directed to children. We do not knowingly collect personal data from a child who cannot lawfully provide consent. If consent is required and the user is below the applicable digital-consent age, consent must be given or authorised by a parent or legal guardian. Contact us if you believe a child has provided data improperly so we can investigate and delete it where required.

15. External links and third-party services

Our website and apps may link to websites and services we do not operate. Their privacy notices govern activity after you leave our service. A link does not make Robisonic responsible for the third party’s content, security, or privacy practices.

16. Changes to this policy

We review this policy as our products, website, providers, and legal obligations change. Updates will be posted at this URL and the revision date will change. If a change materially affects registered users or requires a new choice, we will provide additional notice through the account, app, email, or consent interface as appropriate and request consent where required.

17. Contact us

Questions about this policy, our processing, or your rights can be sent to office@robisonic.com.

S.C. ROBISONIC S.R.L.
CIF 53832766
Trade register: J2026008505002
Romania