1. Who the controller is
The data controller is NOVOGROUP SYSTEMS S.R.L., the operator of the Verifi service. For any GDPR request, including requests from owners whose data appears in a report, write to [email protected].
2. Data collected from customers and visitors
We may collect the following data:
- email for delivery, account sign-in and transactional communications;
- surname, first name and billing address;
- company details if you request an invoice for a company;
- phone number and technical data needed for security and fraud prevention, where requested during the payment process;
- cadastral number, address, parcel, coordinates or other details about the property being checked;
- the CUI and the reason selected for checking a company;
- requests relating to support, returns, the guarantee or GDPR rights;
- when you access the website, Cloudflare, as the DNS, CDN/reverse proxy and security provider, automatically processes technical request metadata, which may include the IP address, date and time, requested host and path, method and response code, device or browser information and routing data.
We do not request the CNP as a separate input. If an official ANCPI document contains a CNP, the pipeline may process it temporarily to extract data, after which it masks it; the full CNP is not displayed in the report. We do not collect card details; these are processed by the payment processor.
In the secure contact request form in Verifi AI, we collect name, email, optional phone number, a summary of the request and necessary operational metadata, including an opaque reference, the category and submission time.
If you ask to be notified when parcel identification through ANCPI is working again, your address is used for a single service recovery email; this is not a sign-up for general marketing and can be stopped through the global unsubscribe option. The address is not placed in the Verifi AI transcript.
3. Data about owners and people associated with companies
For some services, we may process data about the property owner: name, owner type, company CUI, entries in ANAF, ONRC, BPI, Portal Just and ICCJ, and land register data. This data is not collected from the owner, but from public or official sources.
The legal basis is Art. 6(1)(f) GDPR, legitimate interest: checking a property's risks before a transaction, financing, valuation or advice. The full notice for owners is at verifi.ro/proprietari.
Owners can submit an objection to [email protected], including a reference to the property. This notice addresses Art. 14 GDPR for data obtained from sources other than the data subject.
For the company report, we may process the names, roles, published shareholdings and professional connections of directors, shareholders, beneficial owners or other people associated with the company, from registers and commercial sources consulted on a one-off basis. We do not use these people for marketing and do not publish freely accessible profiles. The Art. 14 notice is at verifi.ro/persoane-firme.
4. Purposes and legal bases
| Scop | Date | Temei |
|---|---|---|
| Property identification | address, cadastral number, coordinates | Art. 6(1)(b) or Art. 6(1)(f) GDPR |
| Company identification and analysis | CUI, public company data, context of the check | Art. 6(1)(b) or Art. 6(1)(f) GDPR |
| Report ordering and delivery | email, name, order identifier, report | art. 6(1)(b) GDPR |
| Payment and fraud prevention | billing details, payment confirmation, technical security data | Art. 6(1)(b), Art. 6(1)(f), tax obligations |
| Facturare | tax data | Art. 6(1)(c) GDPR, Accounting Law no. 82/1991 |
| Owner analysis | owner data from public registers | art. 6(1)(f) GDPR |
| Securitate | technical data, security logs, technical events | art. 6(1)(f), art. 32 GDPR |
| Aggregated network-level HTTP measurement | request totals, data transfer, estimated visits and hourly intervals | Art. 6(1)(f) GDPR — legitimate interest in usage, performance and availability; minimised data, no behavioural profile |
| Abandoned checkout recovery | email, name, basket, status, interaction with the reminder and suppression status | for sending: soft opt-in under Article 12(2) of Law No. 506/2004, interpreted in light of Article 13(2) of Directive 2002/58/CE and CJEU C-654/23; for temporary storage, draft management and the suppression register: Article 6(1)(f) GDPR, legitimate interest; no more than two emails to continue the order, with an option to opt out |
| Post-delivery feedback | customer email, order | art. 6(1)(f) GDPR |
| Casa Verde waiting list | consent, Art. 6(1)(a) GDPR | |
| Cookie preferences | preferences and technical identifiers | consent where applicable and Law no. 506/2004 |
For this measurement, Verifi uses Cloudflare HTTP Traffic Analytics on traffic already passing through Cloudflare for delivery and security. Cloudflare may process request metadata in network logs, including the IP address, host, path and browser information. Verifi's integration does not request raw logs, IP addresses, URL paths, query parameters, browser identifiers, User-Agent, referrers or digital fingerprints; it requests only totals and groupings by hourly interval. The 'visits' metric is a Cloudflare estimate and is not presented as a count of people or unique users.
Conversations with Verifi AI and the artefacts displayed are used for service delivery, support, safety, quality, and product and commercial analysis. Verifi AI may explain and recommend Verifi products based on the user's question. Google Cloud Vertex AI processes requests to generate responses. In F1, Verifi does not use conversations to train models.
Data from the Verifi AI contact form is used only to respond to the support or contact request made by the user and is not used for marketing. The form fields and summary are not sent to Gemini, copied into the assistant transcript or included in anonymous analytics events. The notification to the operator deliberately excludes form data and the summary: it contains only the opaque reference, category, time and a link to the admin area. The email provider and the team's inbox receive none of the form fields or the summary; only authorised staff can view the details in the admin area.
5. Recipients and processors
We use the following categories of providers:
- Netopia, the primary option displayed at checkout for card payments, and Revolut, the alternative option; actual availability is as shown at payment;
- Resend for transactional emails;
- Hetzner for hosting;
- Cloudflare for DNS, CDN/reverse proxy, security and HTTP Traffic Analytics; Cloudflare acts as a processor for Customer Logs made available to Verifi, while its privacy policy states a separate role for certain Network Data generated and used to operate its own network;
- Google Cloud Vertex AI for processing the requests needed to generate Verifi AI responses;
- technical services for application administration;
- the accounting firm selected by the controller;
- geocoding and map providers for address searches, with data minimisation;
- commercial company data providers, used on a one-off basis for the report ordered.
ANCPI, ANAF, ONRC, BPI, Portal Just, ICCJ and other registers are public sources or separate controllers, not Verifi processors within the meaning of Art. 28 GDPR.
6. International transfers
We aim to keep data processing within the European Economic Area. If a provider involves access or storage outside the EEA, we use data processing agreements, standard contractual clauses and/or other mechanisms provided for in Art. 44-49 GDPR.
Cloudflare is a global company based in the United States and states that it stores information primarily in the United States and the European Economic Area. Transfers subject to GDPR are covered by Cloudflare's data processing agreement, standard contractual clauses and other applicable contractual safeguards; additional localisation options depend on the plan contracted.
7. Retention
The main retention periods are:
- preview lite: 7 days;
- abandoned checkout snapshot, including email, name and basket: a maximum of 30 days;
- paid reports: 12 months of online access plus 3 years in the contractual archive;
- orders: 5 years;
- invoices and accounting documents: 10 years;
- sign-in links: 20 minutes;
- account sessions: up to 30 days;
- report access links: 7 days;
- technical security data: 90 days, except in the event of incidents;
- conversations with Verifi AI and the artefacts displayed: 90 days;
- contact requests submitted through Verifi AI, encrypted separately: three years;
- GDPR, support, returns or guarantee requests: 3 years;
- objections from owners: as long as necessary to comply with the request, with periodic review.
When a customer enters their email address directly to continue a Verifi order, we inform them at the point of collection that we may send no more than two emails about the order they have started, and give them the option to object before saving. This limited use is based on the soft opt-in exception in Article 12(2) of Law No. 506/2004: it concerns only our own similar services and requires a clear, simple and free way to object both when the address is obtained and in every message.
This legal classification takes into account the CJEU judgment in C-654/23, Inteligo Media, which clarified the concept of an existing customer relationship and the fact that Article 13(2) of Directive 2002/58/CE may also cover a service provided without a separate payment. Verifi's emails, limited to no more than two, concern only the order already started; they do not subscribe the customer to a newsletter or general campaigns.
The customer can stop reminders easily and free of charge when the address is collected or through the unsubscribe link in each message. The link opens a scanner-safe flow and does not change the preference merely through automated access; the customer explicitly confirms the action on the page. Opting out flags the current campaign and preserves existing global suppressions; we do not re-enrol the address in another campaign. This blocks order recovery emails and marketing messages to that address, regardless of the draft. Transactional messages required after an order is completed — for example payment confirmation, processing and delivery — are separate, are not blocked by this suppression and are sent separately. The snapshot is physically deleted no later than 30 days after the last activity.
Verifi's Cloudflare HTTP Traffic Analytics integration does not enable Logpush and does not copy raw HTTP logs or aggregates into its own database. The internal dashboard queries only the last 30 minutes and the last 24 hours on demand, and the result is not persisted after display. The source data processed by Cloudflare remains subject to the retention periods and criteria in the data processing agreement, plan and Cloudflare account configuration.
For access and deletion relating to Verifi AI conversations, write to [email protected]. The 90-day period may be extended where there is a legal retention obligation or an applicable legal hold.
8. Your rights
You have the rights provided for in Art. 15-21 GDPR: access, rectification, erasure, restriction, portability, objection and withdrawal of consent where processing is based on consent.
We respond within a maximum of one month under Art. 12(3) GDPR, with the possibility of a lawful extension in complex cases. For customers, identity verification is proportionate, usually through the order email address. For owners, we request a reference to the property, not an identity card copy by default.
10. Security
We apply measures in accordance with Art. 32 GDPR: secure connections, access control, restricted internal access, security logging and monitoring, secure tokens and measures to protect against abuse.
11. ANSPDCP
You can lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal: B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, dataprotection.ro, [email protected].