ICInfracheck
HomeProductAppApplianceScenariosPricingDocsAboutContactDownload
Download

GDPR notice

GDPR and Data Rights

Last updated: July 29, 2026

Who is responsible for your data

For the Infracheck website, contact form, direct support messages, and information voluntarily sent to us, the data controller is ATG SERVICES S.R.L., CUI 50268922, registered office at Intrarea Guliver 13, Building 3, Apartment 640, Sector 6, Bucharest 060576, Romania.

You can contact the controller at email support or through the contact page. We have not appointed a data protection officer because our current processing activities do not require one under Article 37 GDPR.

Scope and roles

This notice applies when ATG SERVICES S.R.L. receives personal data through infracheck.app, email, product support, or a report that you intentionally share with us.

  • Android and Windows apps: diagnostic data stays on the device unless you intentionally share it or connect to an appliance you selected.
  • Self-hosted appliance: the customer or appliance operator controls the local telemetry and normally acts as controller for any personal data stored there.
  • Support: when a user or customer sends us a report, message, or diagnostic extract, ATG SERVICES S.R.L. processes that copy for support and communication purposes.

Website contact and support requests

We process your name, email address, company name if provided, selected interest, message, and any technical information you choose to include.

  • Purposes: replying to your request, providing product support, discussing a possible contract or partnership, preventing abuse, and keeping a limited support history.
  • Legal bases: steps requested before entering a contract under Article 6(1)(b) GDPR and our legitimate interests in answering inquiries, supporting users, and protecting the service under Article 6(1)(f) GDPR.
  • Retention: contact and support correspondence is normally retained for up to 24 months after the last relevant interaction. We may retain a limited record longer when required by law or needed to establish, exercise, or defend legal claims.

Please do not send passwords, appliance tokens, private keys, authentication codes, or personal data that is not necessary for your request.

Security and access data

When you access the website, infrastructure providers may process IP address, date and time, requested URL, browser or user-agent information, response status, and security signals needed to deliver and protect the website.

  • Purpose and legal basis: secure delivery, abuse prevention, troubleshooting, and service availability based on our legitimate interests under Article 6(1)(f) GDPR.
  • Retention: the contact-form rate limiter keeps an IP-based request history in server memory for up to one hour. Origin web access logs are normally rotated after 14 days. Security providers may apply their own documented retention periods.

Local diagnostics and appliance data

The current Infracheck apps do not send diagnostic telemetry to an Infracheck cloud analytics service. Network identifiers, scan history, pairing details, test results, and reports are processed locally or by the self-hosted appliance chosen by the user.

If an organization uses the appliance to monitor a workplace or customer network, that organization is responsible for its own lawful basis, transparency notices, access controls, retention rules, and data subject requests. ATG SERVICES S.R.L. does not become the controller of that appliance data merely because it publishes the software.

Recipients and service providers

Personal data is disclosed only when needed for the purposes described above. Recipients may include:

  • our website hosting and infrastructure providers;
  • our reverse proxy, DNS, and website security provider;
  • the transactional email provider used to deliver contact-form messages;
  • professional advisers or public authorities where disclosure is legally required;
  • GitHub, Google Play, or another external platform when you choose to follow a download or repository link.

Service providers act under their own legal terms or, where applicable, as processors under contractual data-protection obligations.

International transfers

Some infrastructure, security, email, repository, or app-distribution providers may process information outside the European Economic Area. Where GDPR transfer rules apply, transfers rely on an applicable adequacy decision, Standard Contractual Clauses, or another safeguard permitted by Chapter V GDPR.

Cookies and analytics

The current website does not use advertising cookies or third-party audience analytics. Essential infrastructure and security mechanisms may process request data without placing optional marketing cookies. If optional analytics or marketing technologies are introduced, this notice and the consent mechanism will be updated before activation.

Your GDPR rights

Depending on the circumstances, you may request:

  • access to your personal data and a copy of it;
  • correction of inaccurate or incomplete data;
  • deletion of data when the legal conditions are met;
  • restriction of processing;
  • data portability for processing based on consent or contract and carried out by automated means;
  • objection to processing based on legitimate interests;
  • withdrawal of consent at any time where consent is the legal basis, without affecting earlier lawful processing;
  • information about safeguards used for applicable international transfers.

We do not use personal data received through the website for solely automated decisions that produce legal or similarly significant effects, and we do not use it for profiling.

How to exercise your rights

Send your request to email support and describe the right you want to exercise. We may request proportionate information to verify your identity. We normally respond within one month, subject to the extensions and limitations permitted by GDPR. Requests are normally handled free of charge.

Right to complain

You may lodge a complaint with the Romanian supervisory authority, Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (ANSPDCP), or with the competent authority in your country of residence or work.

ANSPDCP: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania. See the official complaint information. The legal framework is available in the official GDPR text on EUR-Lex.

Children and sensitive data

Infracheck is not directed to children. We do not intentionally request special-category personal data through the website. Do not include health, biometric, political, religious, trade-union, or similarly sensitive information in support messages unless it is strictly necessary and you are legally authorized to disclose it.

Changes to this notice

We may update this notice when the product, providers, or legal requirements change. The revision date at the top identifies the current version.

PrivacyGDPRTermsData SafetySupport