1. Who we are
The controller of personal data processed through doxentriq.com (the "Website") and in connection with the Doxentriq open-source project is:
Alttab Profit SRL, trading as FirstIT
Address: Str. Doamna Oltea nr. 70, București, Romania
Tax identification code (CUI): RO17030480
Trade Register number: J2004020548403
Contact: office@firstit.ro · Phone: +40 723 286 813
We are not legally required to appoint a Data Protection Officer. Please send any question about this policy or your personal data to the privacy contact above.
This policy explains what personal data we process, why, on what legal basis, for how long, and what rights you have under Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and applicable Romanian law.
2. Scope
This policy covers:
- your visits to the Website;
- messages you send to us by email or phone about Doxentriq;
- security vulnerability reports you send us.
It does not cover data processed inside a Doxentriq installation that you or your organization run (see section 5). It also does not cover GitHub or other third-party websites linked from the Website (see section 6).
3. Data we process, purposes and legal bases
The Website is static. It has no user accounts, contact forms, newsletter, advertising or third-party tracking. It loads no external fonts, scripts or images. We process personal data only in these cases:
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Technical access logs: IP address, date and time, requested page, referrer, browser user agent, HTTP status and bytes transferred. Recorded automatically by the web server. | Delivering the Website, keeping it secure, preventing abuse and troubleshooting errors. | Our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR). | Up to 30 days. Longer only if needed to investigate a specific security incident. |
| Correspondence: your name, email address or phone number, the content of your message and any information you choose to include. | Answering your questions, handling requests about Doxentriq and preparing or providing services you ask for. | Steps at your request before entering into a contract, or performing a contract (Art. 6(1)(b)). Otherwise, our legitimate interest in replying (Art. 6(1)(f)). | As long as needed to handle your request, and up to 3 years after our last contact. Longer where Romanian tax or accounting law requires it. |
| Security reports: your contact details and the vulnerability information you send. | Investigating, fixing and coordinating disclosure of security issues, and crediting you if you wish. | Our legitimate interest in keeping Doxentriq and its users secure (Art. 6(1)(f)). | While the issue is handled, and up to 3 years afterwards. |
| Preferences stored in your browser: your cookie consent choice and selected color theme (see the Cookie Policy). | Remembering your choices. | Strictly necessary for the service you request (Art. 4(5) of Romanian Law no. 506/2004). | Stored only on your device. The consent choice lasts 12 months; the theme lasts until you clear your browser storage. We never receive these values. |
| Optional analytics: currently none. | If we enable it in the future: aggregated statistics about page visits. | Your consent (Art. 6(1)(a) GDPR and Law no. 506/2004). Without your consent, no analytics code loads. | Will be stated in the Cookie Policy before any tool is activated. |
| Data needed for legal compliance. | Meeting legal obligations, and establishing, exercising or defending legal claims. | Legal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f)). | For the period required by law or by the limitation period for the claim. |
You don't have to give us any personal data to use the Website. If you don't share your contact details, we simply can't reply to you.
4. What we don't do
- We don't sell, rent or trade personal data.
- We don't use advertising, profiling or cross-site tracking.
- We don't make decisions about you based solely on automated processing, as described in Art. 22 GDPR.
- We don't load third-party fonts, content delivery networks, social media plugins or embedded videos on the Website.
5. The Doxentriq software you install
Doxentriq is self-hosted, open-source software. When you or your organization install it, you are the controller of all personal data processed in that installation. This includes administrator accounts, application users, documents, logs and backups. FirstIT has no access to your installation and receives none of that data.
- No telemetry to FirstIT. The software doesn't send usage statistics or personal data to FirstIT or to doxentriq.com.
- AI providers you configure. If you connect an AI provider (for example OpenAI or Anthropic), Doxentriq sends that provider your chat messages and a redacted, application-specific context, using the credentials you supply. That processing is governed by your agreement with that provider. You are responsible for checking it meets your legal obligations.
- Other services you configure. The same applies to identity providers, DNS and certificate providers, and other external services you connect to your installation.
- Paid services. If FirstIT installs, supports or hosts Doxentriq for you and may access personal data as part of that work, a separate written agreement applies. Where required, it includes a data processing agreement under Art. 28 GDPR.
6. GitHub and other external websites
The Doxentriq source code is published on GitHub, and the Website links to GitHub and to firstit.ro. When you follow these links, the website you visit processes your data under its own privacy policy. For GitHub, see the GitHub General Privacy Statement. If you open issues, post discussions or submit pull requests on GitHub, that information is public and is processed by GitHub, Inc. We see and may respond to what you post there.
7. Recipients
We share personal data only when necessary and only with:
- the hosting provider that serves the Website;
- our email service provider, which hosts the office@firstit.ro mailbox;
- professional advisers such as lawyers and accountants, who are bound by confidentiality;
- public authorities, courts or law enforcement, where the law requires it.
Our service providers act as processors on our instructions, under contracts that meet Art. 28 GDPR.
8. International transfers
We aim to process personal data within the European Economic Area (EEA). Sometimes a service provider may process data outside the EEA. In that case, we make sure the transfer is protected by an adequacy decision of the European Commission (for example the EU–U.S. Data Privacy Framework for certified companies) or by Standard Contractual Clauses with appropriate additional measures. You can ask us for a copy of the relevant safeguards.
9. Security
We use appropriate technical and organizational measures to protect personal data. These include encrypted connections (HTTPS), access controls, the principle of least privilege and data minimization. No method of transmission or storage is completely secure. If a personal data breach is likely to put your rights and freedoms at risk, we will notify the supervisory authority and, where required, you.
10. Your rights
Under the GDPR, you have the right to:
- access your personal data and get a copy of it (Art. 15);
- rectification of inaccurate or incomplete data (Art. 16);
- erasure of your data in the cases set out in Art. 17;
- restriction of processing (Art. 18);
- data portability (Art. 20);
- object at any time to processing based on our legitimate interests (Art. 21);
- withdraw consent at any time, without affecting processing that took place before (Art. 7(3)). You can do this for cookies through the "Cookie settings" link in the footer;
- not be subject to a decision based solely on automated processing (Art. 22).
To exercise your rights, write to office@firstit.ro. We will reply within one month. If a request is complex, we may extend this by two more months and will tell you why. Exercising your rights is free of charge. If we have reasonable doubts about your identity, we may ask for information to confirm it.
11. Complaints
We'd appreciate the chance to address your concern first. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live, work or where the alleged infringement occurred. In Romania, the authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336 București, Romania
12. Children
The Website and Doxentriq are intended for businesses and professionals. They are not directed at children under 16, and we don't knowingly collect their personal data. If you think a child has sent us personal data, please contact us and we will delete it.
13. Changes to this policy
We may update this policy when our practices or legal requirements change. We will publish the new version on this page with a new "last updated" date. If changes are significant, we will make that clear on the Website.
14. Contact
For questions about this policy or your personal data, contact office@firstit.ro or write to Alttab Profit SRL, Str. Doamna Oltea nr. 70, București, Romania.