Voltaraj · Legal

Privacy Policy

Version 1.0 · last updated: 11 August 2026

Language. This English text is a courtesy translation. The binding version is the Romanian one, published at voltaraj.com/privacy. In case of any discrepancy, the Romanian text prevails.

Business-to-business only. Voltaraj is addressed exclusively to legal entities. The personal data we process is, as a rule, that of the designated representatives of the legal entity (directors, authorised employees, contact persons). We do not address consumers and we do not build profiles of natural persons.

ALMA FINCONSULTING SRL
Str. Argentina nr. 33, Fl. 2, Ap. 1, Sector 1, Bucharest 011753, Romania
Trade Register: J/40/53570/2006 · VAT ID: RO18540518
Email: contact@mydesks.ro
Bank account: RO41 INGB 0000 9999 0157 6520 — ING BANK Suc. București

1. Who we are and how to contact us

ALMA FINCONSULTING SRL ("Voltaraj", "we") is a Romanian limited liability company operating the platform voltaraj.com and the application app.voltaraj.com — a power-market forecasting and financial modelling service for generation and storage projects.

We act as data controller for the personal data collected through our site, application and services.

Contact for data protection matters: contact@mydesks.ro (subject: "Data Protection").

We acknowledge requests within 5 working days and answer substantively within 30 calendar days.

2. Scope

This policy applies when the representative of a legal entity:

  • creates an account and uses the application (in a commercial capacity);
  • submits the contact form on the site;
  • purchases a subscription or an à la carte service;
  • receives the daily briefing or other email communications;
  • visits the public voltaraj.com pages.

The policy does not apply to third-party sites reachable through links on our platform.

3. What data we collect and why

3.1. Account and authentication

DataPurposeLegal basis
Username, email addressAccount creation, authentication, service communicationsPerformance of contract — Art. 6(1)(b) GDPR
Password, stored solely as a bcrypt hash with a per-password salt Secure authentication. The plaintext password is not stored and cannot be recovered.Performance of contract — Art. 6(1)(b)
TOTP secret (if you enable two-step verification)Two-factor authenticationLegitimate interest — Art. 6(1)(f)
Password reset codes, stored as hashes, with expiryPassword reset by emailPerformance of contract — Art. 6(1)(b)
Language preference, role, plan, account creation dateOperation of the application and the subscriptionPerformance of contract — Art. 6(1)(b)
Record of failed sign-in attempts (throttling key, count, timestamps) Throttling brute-force attacksLegitimate interest — Art. 6(1)(f)

3.2. Project data

DataPurposeLegal basis
Saved project parameters (capacities, CAPEX, OPEX, financing, site location) Resuming work, generating deliverables Performance of contract — Art. 6(1)(b)

By nature these are technical and commercial data of the organisation, not personal data. They are isolated per account: one user cannot see another's projects. The User is responsible for not entering personal data that the service does not require.

3.3. Billing and payment

DataPurposeLegal basis
Company name, VAT ID, billing addressIssuing a fiscally compliant invoice Legal obligation — Art. 6(1)(c)
Transaction reference and payment status from euPlătescProcessing the order, activating the subscriptionPerformance of contract — Art. 6(1)(b)

We do not store card data. Payments are processed exclusively by euPlătesc (PCI DSS certified, 3-D Secure). We receive only the transaction reference and its outcome.

3.4. Contact form

DataPurposeLegal basis
Name, company, email, phone, the message you writeAnswering the enquiry, preparing an offerPre-contractual steps — Art. 6(1)(b)
IP address and time of submissionLimiting abuse of the form (spam, repeated submissions)Legitimate interest — Art. 6(1)(f)

The message goes to an Operator mailbox. We do not add it to a marketing list and we do not pass it to anyone else.

3.5. Technical data

DataPurposeLegal basis
Server logs (IP address, request time, path, user agent)Security, abuse prevention, error diagnosisLegitimate interest — Art. 6(1)(f)

4. How we use the data

4.1. Providing the service: authentication, saving and retrieving projects, computing forecasts and indicators, generating deliverables, processing payment and issuing the invoice, delivering the daily briefing if you have enabled it.

4.2. Artificial intelligence — what does not happen. Forecasts and financial indicators are computed deterministically, by statistical and physical methods. A generative language model (OpenAI, optionally Anthropic) is used in exactly one place: phrasing the daily briefing in natural language, starting from figures already computed. What is sent to those providers is market and forecast figures only — not your name, not your email address, not your project parameters, not your account content. Your data is not used to train models, neither by us nor by those providers.

4.3. Security: we use IP addresses, authentication events and usage patterns to detect and prevent unauthorised access and abuse.

4.4. Legal compliance: we keep billing records in accordance with Romanian tax legislation (Fiscal Code; Accounting Act no. 82/1991).

4.5. Service improvement: we use aggregated, anonymised data on model accuracy. This concerns forecast performance against the realised price, not users. One client's project parameters are never shared with other clients.

4.6. Commercial communications: we send service-related communications to existing clients, in connection with the contracted service. For marketing communications proper we ask for separate consent, which you may withdraw at any time.

5. Automated decision-making

We do not take automated decisions producing legal effects concerning you. The Platform produces estimates and indicators; all business, investment or financing decisions belong to your organisation.

Forecasts and indicators are indicative estimates, not binding determinations. We do not assess individuals, assign credit scores or profile natural persons.

6. Who we share data with

We do not sell personal data. We share strictly what is necessary, with the providers below, each acting as processor or independent controller as the case may be.

ProviderWhat it receivesPurposeLocation / safeguards
HetznerAll hosted data (servers)Hosting the application and databasesEuropean Union
euPlătescBilling data, transaction referenceCard payment processing, 3-D SecureRomania · PCI DSS certified
FGO.roBilling dataIssuing the invoice and filing it in e-Factura (ANAF)Romania
ResendEmail address and the content of the message sentDelivering service emails (account confirmation, password reset, briefing) USA · Standard Contractual Clauses (Decision 2021/914/EU)
OpenAI (default) / Anthropic (optional)Market and forecast figures only. No personal data.Phrasing the daily briefing in natural languageUSA · Standard Contractual Clauses

What no longer appears in the table above: the site's typefaces are hosted on our own server, not loaded from an external provider. Displaying a public page makes your browser contact no third party.

Legal disclosures: we may disclose data to competent authorities where the law requires it. Where permitted, we notify the affected user.

Business transfers: in the event of a merger or acquisition, data may be transferred to the successor entity, with at least 30 days' prior notice.

7. International transfers

Data is stored on servers in the European Union.

Transfers to the United States providers listed in section 6 (Resend and the language-model provider) rely on the Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 and, where applicable, on the EU–US Data Privacy Framework.

The relevant contractual documents are available on request.

8. How long we keep data

CategoryPeriodBasis
Active account dataFor the duration of the contract + 3 years Performance of contract; limitation periods
Saved projects and deliverablesFor the life of the account; deleted on requestPerformance of contract
Billing data and accounting supporting documents5 yearsLegal obligation — Romanian Accounting Act no. 82/1991, art. 25
Contact form messages24 months from the last correspondence Legitimate interest (record of the commercial relationship)
Password reset codesUntil expiry (hours)Security
Record of failed sign-in attemptsUntil the lockout expires Security
Server logs90 daysOperational security

On request we delete all data early, except that for which we have a legal retention obligation (billing, accounting).

9. Your rights

  • Access (Art. 15) — what data we hold about you;
  • Rectification (Art. 16) — correcting inaccurate data;
  • Erasure (Art. 17) — except billing data subject to a legal retention obligation;
  • Restriction (Art. 18) — temporarily blocking processing;
  • Portability (Art. 20) — receiving your data in a structured format;
  • Objection (Art. 21) — to processing based on legitimate interest;
  • Withdrawal of consent (Art. 7(3)) — at any time, without affecting the lawfulness of prior processing.

How to exercise them: send your request to contact@mydesks.ro with the subject "Data Rights Request". We acknowledge within 5 working days and answer within 30 calendar days.

Right to lodge a complaint:
The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, Bucharest
www.dataprotection.ro · anspdcp@dataprotection.ro

10. Security

Transport: all traffic to the site and the application is encrypted (HTTPS/TLS).

Passwords: stored solely as bcrypt hashes, with a per-password salt. We cannot read your password and cannot recover it — we can only reset it.

Authentication: optional two-step verification (TOTP, RFC 6238), progressive throttling of failed attempts, short-lived reset codes stored as hashes.

Isolation: account data and projects are separate from market data and are keyed per user; administrative roles are distinct from user roles.

Data breaches: we notify ANSPDCP within 72 hours of becoming aware, and affected users, in accordance with Art. 33–34 GDPR.

The public voltaraj.com pages use no analytics, advertising or cross-site tracking cookies. There is no Google Analytics, there are no tracking pixels, there is no behavioural advertising. That is why you see no cookie banner: we have nothing to ask you to accept.

The public pages load no third-party resource: the typefaces are hosted on our own server. Visiting a page transmits your IP address to nobody but us.

The application (app.voltaraj.com) uses strictly necessary session mechanisms to keep you signed in while you use it. These serve no analytics or marketing purpose and require no consent.

12. Children's privacy

The service is addressed exclusively to legal entities and is not intended for persons under 18. We do not knowingly collect data from minors.

13. Changes to this policy

For substantial changes we notify users by email at least 30 days before they take effect. The version and date appear in the header and footer of this page; previous versions are available on request.

14. Contact

ALMA FINCONSULTING SRL — data protection
Email: contact@mydesks.ro (subject: "Data Protection")
Str. Argentina nr. 33, Fl. 2, Ap. 1, Sector 1, Bucharest 011753, Romania

Voltaraj Privacy Policy — version 1.0 — 11 August 2026 · courtesy translation; the Romanian version prevails
Drafted in accordance with the GDPR (Regulation (EU) 2016/679), Romanian Law no. 190/2018 and Regulation (EU) 2024/1689 (AI Act).
ALMA FINCONSULTING SRL · CUI RO18540518 · J/40/53570/2006 · contact@mydesks.ro