Privacy Policy
Last updated: June 26, 2026
ACTE123 is an independent, volunteer-maintained platform. We are committed to protecting your privacy. This policy explains what data we collect, why, and how we protect it.
In Brief
- Your preferences and plan data are stored in your browser and account.
- User accounts are optional, for features like saved plans.
- Usage analytics only with your explicit consent.
- We never sell your personal data.
- You can request deletion of all your data at any time.
- If you collaborate with an organization, its members see only the plans and documents you share in relation to that organization; our administrators may briefly access your account for support, and every such session is logged.
1. Who We Are
ACTE123 is an independent community project, not affiliated with any government entity. The platform is operated as a volunteer initiative. For any questions regarding data protection, you can contact us at [email protected].
2. Data Collected Without an Account
When you use the platform without creating an account, we collect minimal data:
- Technical essentials: browser type, device type, anonymized IP, country-level location (legitimate interest, GDPR Art. 6(1)(f))
- Consent preferences: your cookie and analytics choices, stored in your browser (localStorage)
- Local storage: your language preference, stored as a cookie for up to 1 year
- Usage analytics: page views and interactions via PostHog, only with your explicit consent (GDPR Art. 6(1)(a))
- Server access logs: IP address, user agent, requested URL, timestamp β retained briefly for security and abuse detection
3. Data Collected With an Account
If you create an account, we additionally collect:
- Account information: email address and password (encrypted via Supabase Auth) (GDPR Art. 6(1)(b) β contract execution)
- Authentication data: login timestamps, session tokens, device details
- Plan data: procedures selected, documents uploaded, requirement progress, saved plans
- Language preference: synced to your account for cross-device consistency
4. How We Use Your Data
We process your data for the following purposes:
- Service provision: platform operation and security (legitimate interest)
- Account management: authentication, saved plans, progress tracking (contract execution)
- Platform improvement: usage analytics to improve the experience (consent-based only)
- Essential communications: security alerts, terms updates (legitimate interest)
- Legal compliance: applicable laws and regulations
5. Legal Basis for Processing
We process your data under the following GDPR legal bases:
- Legitimate interest (Art. 6(1)(f)): service operation, security, fraud prevention
- Contract performance (Art. 6(1)(b)): account features and requested services
- Consent (Art. 6(1)(a)): analytics cookies β withdrawable at any time via Cookie Settings
- Legal obligation (Art. 6(1)(c)): compliance with applicable laws and regulations
6. Data Sharing and Service Providers
We never sell, rent, or share your personal data with third parties for marketing purposes. We use the following service providers to operate the platform, all bound by data protection agreements:
- Supabase: authentication, database, and file storage (EU-hosted)
- PostHog: usage analytics, only with your consent (EU hosting available)
- Vercel: hosting and deployment (US)
- Resend: transactional email delivery β notifications and account emails only, never marketing (US)
7. Organizations and Shared Access
ACTE123 offers an optional organizations feature that lets a business β for example a law firm, HR agency, notary office, accounting firm, or real-estate agency β prepare and manage administrative procedures together with the people it serves. If you take part in an organization (as its client or as one of its members), the following applies to your data:
- Scoped visibility: the members of an organization can see only the plans and documents you hold in relation to that organization β the plans created within or linked to it, and the documents you choose to share with it. Your personal plans, and any plans linked to a different organization, stay private and are not visible to them.
- One organization per plan: each plan can be linked to at most one organization, so a plan shared with one organization is never exposed to another.
- Member roles: an organization's members have roles (owner, administrator, employee) that determine what they may do with these plans; all members of that organization can view the plans linked to it.
- Independent controller: an organization that uses ACTE123 to serve you is a separate data controller for its own purposes and is responsible for how it handles your data β we recommend reviewing that organization's own privacy information too.
- Legal basis: performing the service you requested (GDPR Art. 6(1)(b)) and the organization's legitimate interest in serving its clients (Art. 6(1)(f)).
8. Administrative Access for Support
To investigate problems, keep the service secure, and help you when you ask for support, our administrators may occasionally need to access your account on your behalf. This access is tightly controlled:
- Time-limited: each support session automatically expires after one hour.
- Authorized and signed: access is restricted to our administrators and protected by a cryptographically signed session.
- Logged and visible to you: every session is recorded β who accessed your account and when β and these records are included in your data export, so you can see them at any time (right of access, GDPR Art. 15).
- Purpose-bound: we use this access only to operate, secure, and support the service (legitimate interest, GDPR Art. 6(1)(f)), never for marketing or unrelated purposes.
9. Data Retention
We keep data only as long as necessary:
- Local storage / cookies: until you clear your browser or change preferences
- Account data: retained while your account is active; deleted within 30 days of a deletion request
- Analytics data: 12 months, then automatically deleted or anonymized
- Server access logs: up to 90 days for security, then automatically deleted
10. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access (Art. 15): request a copy of your personal data
- Right to rectification (Art. 16): request correction of inaccurate data
- Right to erasure (Art. 17): request deletion of your data ("right to be forgotten")
- Right to restriction (Art. 18): request limitation of processing
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interest
- Right to withdraw consent (Art. 7(3)): withdraw analytics consent at any time via Cookie Settings
- Right to lodge a complaint: file a complaint with the Romanian supervisory authority (ANSPDCP) at anspdcp.ro
- How to exercise your rights: email us at [email protected], or use the self-service Data Export and Account Deletion tools in your account settings. We respond within 30 days (Art. 12(3)). We have not appointed a Data Protection Officer, as our processing does not require one (Art. 37).
11. Data Security
We implement appropriate technical and organizational measures to protect your data. All connections use TLS/SSL encryption. Passwords are encrypted via Supabase Auth. Access is restricted to authorized maintainers only. Our infrastructure is hosted by established providers (Supabase, Vercel) with their own security certifications.
12. International Data Transfers
Some of our service providers β in particular Vercel (hosting) and Resend (transactional email), which are based in the United States β may process data outside the EU/EEA. Where this occurs, transfers are protected by EU Commission-approved Standard Contractual Clauses (SCCs) and additional technical safeguards, in compliance with GDPR Chapter V.
13. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or similarly significant impact on you.
14. Children's Privacy
This platform is not directed at children under 16 years of age. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us immediately.
15. Cookies
We use three categories of cookies: Essential (authentication, security β always active), Functional (language and theme preferences β with your consent), and Analytics (PostHog β with your consent). You can manage your preferences at any time via Cookie Settings in the footer. No analytics data is collected without your explicit consent.
16. Changes to This Policy
We may update this policy from time to time. Material changes will be posted on this page with an updated date.
17. Supervisory Authority
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania. Website: anspdcp.ro
18. Contact
For questions about this Privacy Policy, to exercise your GDPR rights, or to request data deletion, please contact us at: