Tech Coach

Privacy Policy

Updated: 3 July 2026

This policy explains what personal data we process through the techcoach.ro and thetechcall.com sites (the “Tech Coach” brand), on what legal basis, who we share it with, how long we keep it, and your rights. We keep it plain and honest. It is not legal advice, but it reflects our actual practice.

Who we are (the data controller)

The data controller is SAPIO ARTIFICIAL INTELLIGENCE SYSTEMS SRL, a company registered in Romania with the Trade Register under no. J40/17363/2021, sole registration code (CUI) RO45038625, with its registered office at Bucharest, Romania.

Tech Coach is the technology-coaching practice run by Vlad Tudor, operated through this company. For any question about your data, write to privacy@sapio.ro.

We have not appointed a Data Protection Officer (DPO), because we do not carry out large-scale or special-category processing that would legally require one. The privacy contact point is the address above.

What we collect

Meet & Greet or workshop sign-up: your name, email address, and the brief you submit (field, role, technology used, business stage, the decision or problem you describe). Your consent ticks (event participation and, optionally, marketing) are recorded too.

Scheduling: the date and time you pick for the call, handled through Cal.com.

Payments: if you buy a package, the payment is processed by Stripe; we receive the payment confirmation and the billing data we need (we do not store your card number — it stays with Stripe).

Minimal technical data: a Cloudflare Turnstile token to prevent abuse on form submission, IP addresses in technical form (including hashes for rate-limiting), plus standard server logs generated by the infrastructure.

Administration: if you are a team member logging into the admin panel, we use your Google account via NextAuth solely for authentication.

Why, and on what legal basis

We process your data for the purposes below, each with its corresponding legal basis under Art. 6 GDPR:

Who we disclose it to (processors)

To run the service we use a small set of providers (processors / sub-processors), each contractually bound to protect the data. Note: Meet & Greet confirmations and reminders are sent by Cal.com (not by the site).

International transfers

The main database (Neon) is in the European Union (the eu-central-1 region), so your core data stays in the EU. Some of the providers above are in the United States. For those transfers we rely on the European Commission’s Standard Contractual Clauses (SCC) and/or the EU-US Data Privacy Framework, where the provider is certified. You can request a copy of the applicable safeguards by writing to the privacy address.

How long we keep it

Contact / CRM records (leads, briefs, bookings): 24 months after the last interaction, then anonymised or deleted. You can request earlier deletion or anonymisation at any time.

Payment / invoicing records: kept as required by Romanian accounting and tax law (up to 10 years). These records survive contact deletion, as they are a separate legal obligation.

Server logs: a short operational period (typically 30–90 days), at the infrastructure level.

Your rights

Under the GDPR you have the right to: access your data; rectification; erasure (the “right to be forgotten”); restriction of processing; data portability; objection to processing based on legitimate interest; and to withdraw consent at any time (for example for marketing), without affecting the lawfulness of processing before withdrawal.

You can exercise any of these rights by writing to privacy@sapio.ro. We respond within the time limits set by law (usually within one month).

You have the right to lodge a complaint with the supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral Gheorghe Magheru 28-30, Sector 1, București, anspdcp.ro.

Cookies

We use only essential cookies (admin authentication and a Turnstile token on interaction) and no tracking or advertising cookies. Full details are in the Cookie Policy.

Security

We use reputable providers, encrypted connections (HTTPS) and restricted access to the CRM data. No measure is perfect, but we treat your data with the care we would expect for our own.

Changes

We may update this policy as the service evolves. The current version, with its update date, is always the one published here.

Contact

For any question about your data or this policy: privacy@sapio.ro.