Această politică este furnizată în limba engleză, care este versiunea autoritară și obligatorie.
This Privacy Policy explains how personal data is processed in connection with the ActON platform (“Service”), operated by Share IT Smart S.R.L., Romania.
01Scope (B2B Context)
ActON is provided exclusively in a business-to-business (B2B) context. Personal data is processed primarily in a professional capacity, in connection with organizational use of the Service in industrial and manufacturing environments. The Service is not intended for consumer use.
02Data Controller
- Company: Share IT Smart S.R.L.
- Registered office: Arad, Arad County, Romania
- Email: gdpr@share-it-smart.com
- Supervisory Authority: ANSPDCP – Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (www.dataprotection.ro).
03Roles and Responsibilities
- Customers act as data controllers for maintenance content, equipment data, and personnel data entered into the Service.
- Share IT Smart S.R.L. acts as data processor for such customer content.
- AI, payment, and infrastructure providers act as sub-processors, engaged under contractual safeguards.
- Customers are responsible for ensuring a valid legal basis for processing personnel and operational data through the Service, and for informing their personnel accordingly.
04Data We Process
Account & Technical Data
- Name and email address
- Company / organization name
- Login credentials (securely hashed)
- IP address, browser and device data
- Session identifiers and login timestamps
Maintenance Data (as provided by customers)
- Equipment and asset registries organized by production line
- Maintenance records, work orders and tasks
- Technical documents (e.g. PDF manuals) uploaded for AI-assisted extraction of maintenance intervals and spare parts
- Knowledge-base content and comments
- Personnel / assignee information and operational attendance data, used strictly for routing and assigning maintenance tasks
05Legal Basis for Processing (GDPR Art. 6)
| Purpose | Legal Basis |
|---|---|
| Service delivery (CMMS, PM scheduling, task and work-order management) | Contract performance |
| AI-assisted extraction from technical documents | Contract performance / Legitimate interests |
| Personnel and attendance data for task routing | Customer responsibility / Legitimate interests |
| Account security and authentication | Legitimate interests |
| Operational communications | Contract performance |
| Payment processing (via Polar as Merchant of Record) | Contract performance |
| Analytics and service improvement | Legitimate interests |
| Audit logging and compliance | Legal obligation |
| Marketing communications | Consent (opt-in) |
06AI Processing & Limitations
ActON uses AI technologies to extract maintenance data from technical documents, structure tasks, and answer knowledge-base queries. The primary AI provider (Anthropic / Claude API) is engaged as a sub-processor in a “no-training” mode.
Privacy-by-design safeguards:
- Customer data is not used to train AI models
- No profiling or evaluation of individuals
- No autonomous maintenance, operational, or safety decision-making
- Operational attendance data is used solely for task routing — never for HR, payroll, working-time compliance, or performance evaluation
AI-generated outputs are provided as decision-support only and must be reviewed by a qualified user before any reliance.
07Sub-processors
Share IT Smart engages the following categories of sub-processors under contractual safeguards in accordance with GDPR Article 28:
- AI processing: Anthropic (Claude API), in “no-training” mode
- Payment processing: Polar Software, Inc., acting as Merchant of Record, which may use Stripe as a downstream payment infrastructure provider
- Cloud hosting and infrastructure providers
Where Share IT Smart acts as a data processor, processing is carried out under a data processing agreement (GDPR Art. 28) concluded with the customer. Payment-related processing by Polar and Stripe is additionally governed by Polar’s Data Processing Addendum. An up-to-date list of sub-processors is made available to customers on request.
08Personnel & Attendance Data
Where the customer enters personnel information or operational attendance data, such data is processed strictly to route and assign maintenance tasks to available personnel.
The customer, as data controller, is responsible for establishing a valid legal basis and for informing the affected personnel. Share IT Smart does not use this data for employee monitoring, HR decisions, payroll, or performance evaluation.
09Data Retention
| Data Type | Retention |
|---|---|
| Account data | Until account deletion + 30 days |
| Maintenance content, documents and tasks | Until deleted by the customer or end of contract |
| Uploaded technical documents (after extraction) | Retained as part of the knowledge base until deleted by the customer |
| Audit logs | 7 years |
| Session data | Automatic expiry (hours) |
| Backups | Rolling retention, then automatic deletion |
Upon account termination, data remains subject to contractual obligations and applicable law until deleted or exported by the customer.
10International Data Transfers
Certain sub-processors (including the AI provider and payment providers) may process data outside the European Economic Area, including in the United States.
Safeguards include:
- Standard Contractual Clauses (SCCs)
- EU–U.S. Data Privacy Framework certification, where applicable
- Encryption in transit and at rest
- Purpose limitation and data minimization
11Data Subject Rights
Under GDPR, data subjects may exercise rights of access, rectification, erasure, portability, objection, and withdrawal of consent (where applicable).
- Customer users: via account settings or gdpr@share-it-smart.com
- External data subjects (e.g. personnel): requests may be forwarded to the relevant customer acting as data controller
Where Share IT Smart acts solely as data processor, fulfillment of rights is subject to customer instructions.
12Security Measures
Appropriate technical and organizational measures are in place, including:
- Encryption at rest and in transit
- Secure password hashing and multi-factor authentication
- Role-based access control
- Tenant data isolation
- Audit logging and security monitoring
- Information security management aligned with ISO/IEC 27001:2022
13Children's Data
The Service is not intended for individuals under 16 years of age. We do not knowingly process children’s personal data.
14Changes
This Privacy Policy may be updated periodically. Material changes will be communicated via application notice or email where required.
15Contact & Complaints
- Company: Share IT Smart S.R.L.
- Email: gdpr@share-it-smart.com
- Country: Romania
- Platform: acton-now.com
Data subjects may lodge complaints with ANSPDCP (www.dataprotection.ro).