Language. This English text is a courtesy translation. The binding version is the Romanian one, published at voltaraj.com/privacy. In case of any discrepancy, the Romanian text prevails.
Business-to-business only. Voltaraj is addressed exclusively to legal entities. The personal data we process is, as a rule, that of the designated representatives of the legal entity (directors, authorised employees, contact persons). We do not address consumers and we do not build profiles of natural persons.
1. Who we are and how to contact us
ALMA FINCONSULTING SRL ("Voltaraj", "we") is a Romanian limited liability company operating the
platform voltaraj.com and the application app.voltaraj.com — a
power-market forecasting and financial modelling service for generation and storage projects.
We act as data controller for the personal data collected through our site, application and services.
Contact for data protection matters: contact@mydesks.ro (subject: "Data Protection").
We acknowledge requests within 5 working days and answer substantively within 30 calendar days.
2. Scope
This policy applies when the representative of a legal entity:
- creates an account and uses the application (in a commercial capacity);
- submits the contact form on the site;
- purchases a subscription or an à la carte service;
- receives the daily briefing or other email communications;
- visits the public voltaraj.com pages.
The policy does not apply to third-party sites reachable through links on our platform.
3. What data we collect and why
3.1. Account and authentication
| Data | Purpose | Legal basis |
|---|---|---|
| Username, email address | Account creation, authentication, service communications | Performance of contract — Art. 6(1)(b) GDPR |
| Password, stored solely as a bcrypt hash with a per-password salt | Secure authentication. The plaintext password is not stored and cannot be recovered. | Performance of contract — Art. 6(1)(b) |
| TOTP secret (if you enable two-step verification) | Two-factor authentication | Legitimate interest — Art. 6(1)(f) |
| Password reset codes, stored as hashes, with expiry | Password reset by email | Performance of contract — Art. 6(1)(b) |
| Language preference, role, plan, account creation date | Operation of the application and the subscription | Performance of contract — Art. 6(1)(b) |
| Record of failed sign-in attempts (throttling key, count, timestamps) | Throttling brute-force attacks | Legitimate interest — Art. 6(1)(f) |
3.2. Project data
| Data | Purpose | Legal basis |
|---|---|---|
| Saved project parameters (capacities, CAPEX, OPEX, financing, site location) | Resuming work, generating deliverables | Performance of contract — Art. 6(1)(b) |
By nature these are technical and commercial data of the organisation, not personal data. They are isolated per account: one user cannot see another's projects. The User is responsible for not entering personal data that the service does not require.
3.3. Billing and payment
| Data | Purpose | Legal basis |
|---|---|---|
| Company name, VAT ID, billing address | Issuing a fiscally compliant invoice | Legal obligation — Art. 6(1)(c) |
| Transaction reference and payment status from euPlătesc | Processing the order, activating the subscription | Performance of contract — Art. 6(1)(b) |
We do not store card data. Payments are processed exclusively by euPlătesc (PCI DSS certified, 3-D Secure). We receive only the transaction reference and its outcome.
3.4. Contact form
| Data | Purpose | Legal basis |
|---|---|---|
| Name, company, email, phone, the message you write | Answering the enquiry, preparing an offer | Pre-contractual steps — Art. 6(1)(b) |
| IP address and time of submission | Limiting abuse of the form (spam, repeated submissions) | Legitimate interest — Art. 6(1)(f) |
The message goes to an Operator mailbox. We do not add it to a marketing list and we do not pass it to anyone else.
3.5. Technical data
| Data | Purpose | Legal basis |
|---|---|---|
| Server logs (IP address, request time, path, user agent) | Security, abuse prevention, error diagnosis | Legitimate interest — Art. 6(1)(f) |
4. How we use the data
4.1. Providing the service: authentication, saving and retrieving projects, computing forecasts and indicators, generating deliverables, processing payment and issuing the invoice, delivering the daily briefing if you have enabled it.
4.2. Artificial intelligence — what does not happen. Forecasts and financial indicators are computed deterministically, by statistical and physical methods. A generative language model (OpenAI, optionally Anthropic) is used in exactly one place: phrasing the daily briefing in natural language, starting from figures already computed. What is sent to those providers is market and forecast figures only — not your name, not your email address, not your project parameters, not your account content. Your data is not used to train models, neither by us nor by those providers.
4.3. Security: we use IP addresses, authentication events and usage patterns to detect and prevent unauthorised access and abuse.
4.4. Legal compliance: we keep billing records in accordance with Romanian tax legislation (Fiscal Code; Accounting Act no. 82/1991).
4.5. Service improvement: we use aggregated, anonymised data on model accuracy. This concerns forecast performance against the realised price, not users. One client's project parameters are never shared with other clients.
4.6. Commercial communications: we send service-related communications to existing clients, in connection with the contracted service. For marketing communications proper we ask for separate consent, which you may withdraw at any time.
5. Automated decision-making
We do not take automated decisions producing legal effects concerning you. The Platform produces estimates and indicators; all business, investment or financing decisions belong to your organisation.
Forecasts and indicators are indicative estimates, not binding determinations. We do not assess individuals, assign credit scores or profile natural persons.
6. Who we share data with
We do not sell personal data. We share strictly what is necessary, with the providers below, each acting as processor or independent controller as the case may be.
| Provider | What it receives | Purpose | Location / safeguards |
|---|---|---|---|
| Hetzner | All hosted data (servers) | Hosting the application and databases | European Union |
| euPlătesc | Billing data, transaction reference | Card payment processing, 3-D Secure | Romania · PCI DSS certified |
| FGO.ro | Billing data | Issuing the invoice and filing it in e-Factura (ANAF) | Romania |
| Resend | Email address and the content of the message sent | Delivering service emails (account confirmation, password reset, briefing) | USA · Standard Contractual Clauses (Decision 2021/914/EU) |
| OpenAI (default) / Anthropic (optional) | Market and forecast figures only. No personal data. | Phrasing the daily briefing in natural language | USA · Standard Contractual Clauses |
What no longer appears in the table above: the site's typefaces are hosted on our own server, not loaded from an external provider. Displaying a public page makes your browser contact no third party.
Legal disclosures: we may disclose data to competent authorities where the law requires it. Where permitted, we notify the affected user.
Business transfers: in the event of a merger or acquisition, data may be transferred to the successor entity, with at least 30 days' prior notice.
7. International transfers
Data is stored on servers in the European Union.
Transfers to the United States providers listed in section 6 (Resend and the language-model provider) rely on the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 and, where applicable, on the EU–US Data Privacy Framework.
The relevant contractual documents are available on request.
8. How long we keep data
| Category | Period | Basis |
|---|---|---|
| Active account data | For the duration of the contract + 3 years | Performance of contract; limitation periods |
| Saved projects and deliverables | For the life of the account; deleted on request | Performance of contract |
| Billing data and accounting supporting documents | 5 years | Legal obligation — Romanian Accounting Act no. 82/1991, art. 25 |
| Contact form messages | 24 months from the last correspondence | Legitimate interest (record of the commercial relationship) |
| Password reset codes | Until expiry (hours) | Security |
| Record of failed sign-in attempts | Until the lockout expires | Security |
| Server logs | 90 days | Operational security |
On request we delete all data early, except that for which we have a legal retention obligation (billing, accounting).
9. Your rights
- Access (Art. 15) — what data we hold about you;
- Rectification (Art. 16) — correcting inaccurate data;
- Erasure (Art. 17) — except billing data subject to a legal retention obligation;
- Restriction (Art. 18) — temporarily blocking processing;
- Portability (Art. 20) — receiving your data in a structured format;
- Objection (Art. 21) — to processing based on legitimate interest;
- Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of prior processing.
How to exercise them: send your request to contact@mydesks.ro with the subject "Data Rights Request". We acknowledge within 5 working days and answer within 30 calendar days.
Right to lodge a complaint:
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, Bucharest
www.dataprotection.ro ·
anspdcp@dataprotection.ro
10. Security
Transport: all traffic to the site and the application is encrypted (HTTPS/TLS).
Passwords: stored solely as bcrypt hashes, with a per-password salt. We cannot read your password and cannot recover it — we can only reset it.
Authentication: optional two-step verification (TOTP, RFC 6238), progressive throttling of failed attempts, short-lived reset codes stored as hashes.
Isolation: account data and projects are separate from market data and are keyed per user; administrative roles are distinct from user roles.
Data breaches: we notify ANSPDCP within 72 hours of becoming aware, and affected users, in accordance with Art. 33–34 GDPR.
11. Cookies and tracking
The public voltaraj.com pages use no analytics, advertising or cross-site tracking cookies. There is no Google Analytics, there are no tracking pixels, there is no behavioural advertising. That is why you see no cookie banner: we have nothing to ask you to accept.
The public pages load no third-party resource: the typefaces are hosted on our own server. Visiting a page transmits your IP address to nobody but us.
The application (app.voltaraj.com) uses strictly necessary session mechanisms to keep you signed in while you use it. These serve no analytics or marketing purpose and require no consent.
12. Children's privacy
The service is addressed exclusively to legal entities and is not intended for persons under 18. We do not knowingly collect data from minors.
13. Changes to this policy
For substantial changes we notify users by email at least 30 days before they take effect. The version and date appear in the header and footer of this page; previous versions are available on request.
14. Contact
ALMA FINCONSULTING SRL — data protection
Email: contact@mydesks.ro (subject: "Data Protection")
Str. Argentina nr. 33, Fl. 2, Ap. 1, Sector 1, Bucharest 011753, Romania
Drafted in accordance with the GDPR (Regulation (EU) 2016/679), Romanian Law no. 190/2018 and Regulation (EU) 2024/1689 (AI Act).
ALMA FINCONSULTING SRL · CUI RO18540518 · J/40/53570/2006 · contact@mydesks.ro