Legal
Privacy Policy
Effective Date: 13/05/2026 Version: 3.0
SISKON SOFTWARE & AUTOMATION S.R.L.
PRIVACY POLICY (Website Visitors and Business Contacts)
This Privacy Policy describes how Siskon Software & Automation S.R.L. (“Siskon”, “we”, “us”, or “our”), a company incorporated under the laws of Romania with its registered office at Str. Turnului Nr.5, M.U.M. Building, Staircase 3, Floor 2, Office 5, 500152 Brașov, Romania, processes your personal data when you:
- visit our website,
- contact us by e-mail, phone or via online forms,
- apply for a position with us, request a quote, or submit a partnership inquiry,
- engage with us in other related ways, including any sales, marketing, or events.
Applicable law. As a controller established in Romania, our processing activities are governed by the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Romanian Law No. 190/2018 on the implementation of the GDPR. The competent supervisory authority in Romania is the National Supervisory Authority for Personal Data Processing (ANSPDCP).
Controller details:
Trade Register No.: J2024006055402
VAT (CIF): RO49803550
Registered Office: Str. Turnului Nr.5, M.U.M. Building, Staircase 3, Floor 2, Office 5, 500152 Brașov, Romania
Group context. We are part of the Siskon Group, whose parent company is Siskon Endüstriyel Otomasyon Sistemleri Sanayi ve Ticaret A.Ş., established in Türkiye. Where personal data is shared with the parent company or other group affiliates, we apply the safeguards described in Section 5.
Contact for privacy matters. For all privacy-related questions and requests, please contact us at [email protected] or by post to the address listed in Section 11.
1. What information do we collect?
Personal information you provide to us
In Short: We collect personal information that you voluntarily provide to us.
We collect personal information that you voluntarily provide when you express an interest in our products and services, when you participate in activities on our website, or otherwise when you contact us.
The personal data we collect may include:
- Identity data: name and surname,
- Contact data: business or personal e-mail address, phone number, postal address, country,
- Professional data (where you submit a job application or business inquiry): CV/résumé, employment history, qualifications, position, employer, references,
- Communication content: the content of messages you send us through contact forms, e-mail or phone.
Special categories of personal data
We do not actively request and we make every reasonable effort to avoid processing special categories of personal data under GDPR Article 9 (such as health, religious beliefs, biometric or political data). If you choose to share such information voluntarily, we will process it only on the basis of your explicit consent or another lawful basis.
Information automatically collected
In Short: Some information — such as your IP address and/or browser and device characteristics — is collected automatically when you visit our website.
We automatically collect certain information when you visit, use, or navigate our website. This information does not generally reveal your specific identity but may include device and usage information such as IP address, browser and device characteristics, operating system, language preferences, referring URLs, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our website and for our internal analytics.
The information we collect includes:
- Log and Usage Data. Service-related, diagnostic, usage and performance information our servers automatically collect when you access or use our website (date/time stamps, pages and files viewed, searches, features used, error reports).
- Device Data. Information about your device such as IP address, browser type, hardware model, internet service provider, operating system, and system configuration information.
- Location Data. Approximate location information derived from your IP address. We do not collect precise GPS location through our website.
- Cookies. We use cookies and similar tracking technologies. Strictly necessary cookies are placed on your device by default; for all other cookies (analytics, performance, marketing) we obtain your consent through our cookie banner. For details please see our separate EYS-PLC_RO-EN_Cookie Policy.
2. How do we process your information?
In Short: We process your information to provide, improve and administer our Services, communicate with you, comply with law, and protect our legitimate interests.
We process your personal data for a variety of reasons, including:
- To respond to your inquiries and provide the products and services you request,
- To establish and perform contracts to which you or your employer are a party,
- To evaluate job applications and manage recruitment processes,
- To improve, maintain and secure our website and prevent fraud or abuse,
- To send service-related and, with your consent, marketing communications,
- To comply with legal obligations and respond to lawful requests from public authorities,
- To establish, exercise or defend legal claims,
- Where strictly necessary, to protect the vital interests of any individual.
3. What legal bases do we rely on?
In Short: We process your personal data only when we have a valid legal basis under GDPR Article 6 (and, where applicable, Article 9).
We may rely on the following legal bases:
- Consent (Art. 6(1)(a)). Where you have given us specific consent, e.g. for marketing communications or non-essential cookies. You can withdraw consent at any time without affecting the lawfulness of prior processing.
- Contract (Art. 6(1)(b)). Where processing is necessary to enter into or perform a contract with you, or to take steps at your request prior to entering into a contract.
- Legal obligations (Art. 6(1)(c)). Where processing is necessary for compliance with our legal obligations under EU or Romanian law.
- Vital interests (Art. 6(1)(d)). Where processing is necessary to protect the vital interests of you or another person.
- Legitimate interests (Art. 6(1)(f)). Where processing is necessary for our legitimate interests (such as network and information security, fraud prevention, internal administration, group reporting) and not overridden by your fundamental rights and freedoms. You may obtain further information on the balancing test at any time on request.
4. When and with whom do we share your personal data?
In Short: We may share your personal data with selected third parties in specific situations described below.
We may share your personal data in the following situations:
- Service providers and processors. With IT, hosting, e-mail, cloud, cybersecurity, analytics, professional services and similar third-party providers acting under our written instructions and a data processing agreement.
- Group affiliates. With our parent company in Türkiye and other group affiliates (including in Estonia) for HR, customer/project management and group reporting purposes, where necessary and subject to appropriate safeguards.
- Business partners and customers. Where required to perform a contract or pre-contractual measures requested by you.
- Legal authorities and advisers. With courts, regulators (including ANSPDCP), law enforcement, lawyers, auditors and other advisers where necessary to comply with legal obligations or protect our rights.
- Business transfers. In connection with, or during negotiations of, any merger, sale of assets, financing or acquisition of all or part of our business.
5. International transfers of personal data
In Short: We may transfer personal data outside the European Economic Area, subject to appropriate safeguards.
Personal data may be transferred to our parent company Siskon Endüstriyel Otomasyon Sistemleri Sanayi ve Ticaret A.Ş. in Türkiye and to cloud / SaaS providers that may process data outside the EEA. As Türkiye is currently not the subject of an adequacy decision under GDPR Article 45, such transfers are made on the basis of Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) supplemented by appropriate technical and organisational measures, or, where applicable, on the basis of derogations under Article 49 (e.g. performance of a contract, your explicit consent, establishment or defence of legal claims).
You may request a copy of the safeguards we have put in place by contacting us at [email protected].
6. How long do we keep your information?
In Short: We keep your information only for as long as necessary for the purposes set out in this Privacy Policy or as required by law.
Specific retention periods are determined by reference to the purposes of processing and the requirements of applicable Romanian and EU laws (including commercial, tax, labour and accounting legislation). When we have no ongoing legitimate business need to process your personal data, we will delete or anonymise it, or, if this is not possible (for example because the data has been stored in backup archives), we will securely store and isolate it from any further processing until deletion is possible.
7. How do we keep your information safe?
In Short: We protect your personal data through a system of organisational and technical security measures aligned with ISO/IEC 27001 and ISO/IEC 27701.
We have implemented appropriate technical and organisational measures designed to protect the security of any personal data we process, including access controls, encryption in transit, secure development practices, vendor management and incident response procedures. However, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure; we cannot warrant absolute security. Transmission of personal data to and from our website is at your own risk.
8. Do we collect information from minors?
In Short: We do not knowingly collect or solicit data from children under 16 years of age.
Our services are directed to professionals and adults. If we learn that we have collected personal data from a person under 16 without verified parental consent, we will deactivate the relevant record and take reasonable measures to delete such data. If you believe we may hold information about a person under 16, please contact us at [email protected].
9. Your rights under GDPR
Subject to the conditions and limitations set out in GDPR, you have the following rights:
- Access (Art. 15) — to obtain confirmation as to whether we process your personal data and a copy of the data,
- Rectification (Art. 16) — to have inaccurate or incomplete data corrected,
- Erasure (Art. 17) — to have your personal data deleted in certain circumstances,
- Restriction (Art. 18) — to restrict our processing of your personal data,
- Data portability (Art. 20) — to receive your personal data in a structured, commonly used and machine-readable format,
- Objection (Art. 21) — to object to processing based on legitimate interests, and to direct marketing at any time,
- Not to be subject to automated decision-making (Art. 22) producing legal or similarly significant effects,
- Withdraw consent at any time, where processing is based on consent (without affecting the lawfulness of prior processing).
Exercising your rights. You may submit a request by contacting us at [email protected] or by post to the address in Section 11. We will respond to your request within one (1) month of receipt; this period may be extended by two further months where necessary, taking into account the complexity and number of requests.
Lodging a complaint. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, www.dataprotection.ro, or with the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
10. Controls for Do-Not-Track features
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature you can activate to signal your privacy preference not to have your online browsing activity monitored. At this stage no uniform technology standard for recognising and implementing DNT signals has been finalised. As a result, we do not currently respond to DNT browser signals. If a standard is adopted in the future that we must follow, we will inform you in a revised version of this Privacy Policy.
11. How can you contact us about this notice?
If you have questions or comments about this Privacy Policy, please contact us:
Controller: Siskon Software & Automation S.R.L.
Registered office: Str. Turnului Nr.5, M.U.M. Building, Staircase 3, Floor 2, Office 5, 500152 Brașov, Romania
Trade Register No.: J2024006055402
VAT (CIF): RO49803550
E-mail: [email protected]
Supervisory Authority: ANSPDCP – www.dataprotection.ro
12. Updates to this notice
We may update this Privacy Policy from time to time to remain compliant with relevant laws. The updated version will be indicated by an updated “Revised” date and will be effective as soon as it is accessible. Where the changes are material, we will notify you by prominently posting a notice on the website or by sending you a direct notification.
Effective date: 13.05.2026 Version: 3.0