Privacy Policy
Email: contact@holma.ro · Tel: +40 752 308 454
VAT / CUI: 39664292 · Trade Register No.: J08/1721/2018
This Privacy Policy explains how TESODA S.R.L. collects, uses, stores and protects the personal data of people who visit holma.ro, request information, enter into a contract or use the Holma application, equipment and services. The policy applies to users, clients and partners in the European Union and the European Economic Area.
1. Data controller
TESODA S.R.L., Str. Lemnarilor nr. 56, Brașov, Brașov County, Romania. E-mail: contact@holma.ro · Phone: +40 752 308 454. CUI: 39664292 · Trade Register No.: J08/1721/2018.
For contact, billing, account administration, support and security data, TESODA S.R.L. acts as controller. For data on guests, bookings, access and communications entered or synced by the client, TESODA S.R.L. may act as a processor, while the client remains the data controller. In that case, the relationship may be governed by a separate data processing agreement, in accordance with Article 28 GDPR.
2. The data we may collect
- first name, last name, role and company;
- e-mail address, phone number and billing data;
- information about properties, apartments, boilers, air conditioning units and other equipment;
- data on the contract, subscription, payments and invoices;
- messages, requests and communications with the Holma team;
- technical data, such as IP address, device type, browser and security logs;
- account usage data, configurations, commands, alerts, temperatures, equipment status and operating intervals;
- data about bookings and guests, when these are entered or synced by the client.
Holma does not seek to collect special categories of data, such as medical or biometric data, religious beliefs or political opinions.
3. Purposes and legal bases for processing
Providing Holma services — account creation, assessment, installation, setup, subscription activation, application operation, sending alerts, technical support and billing. Basis: performance of the contract or pre-contractual steps.
Communicating with clients and prospective clients — responding to requests, preparing offers, scheduling assessments or installations. Basis: legitimate interest and, where applicable, pre-contractual steps.
Compliance with legal obligations — accounting, taxation, archiving, handling complaints.
Security and service improvement — technical logs and usage information to prevent unauthorized access, identify errors, investigate incidents and improve the platform. Basis: legitimate interest.
Commercial communications — only where there is a legal basis, including consent where required. Unsubscribing is possible at any time.
4. Guest data
When the client enters or syncs data about guests, bookings, access or accommodated persons in Holma, the client determines the purposes of the processing and generally acts as the controller. TESODA S.R.L. processes this data to provide the service and in accordance with the client’s instructions.
- The client is responsible for informing the data subjects.
- The client must have a legal basis for collecting and using the data.
- The client is responsible for the accuracy of the data and for configuring the access of its users.
- The client must comply with the legal obligations regarding guest records and accommodation.
5. Data recipients
- providers of hosting, IT infrastructure and security services;
- providers of e-mail, communications and payment processing;
- accounting and invoicing providers;
- specialists and partners who carry out installation or technical support;
- legal, tax or security consultants;
- providers of the integrations enabled by the client;
- public authorities, where disclosure is required by law.
6. International transfers
For Holma’s core services, data is hosted in the European Union or the European Economic Area. If a secondary provider processes data outside the EEA, we will use a recognized legal mechanism, such as an adequacy decision, Standard Contractual Clauses or another mechanism permitted by the GDPR.
7. Retention period
- account data: for the duration of the contract and a reasonable period afterwards;
- contractual, accounting and tax data: in accordance with the applicable legal terms;
- commercial requests: as a rule, a maximum of 3 years from the last interaction;
- technical and security logs: limited and proportionate periods;
- data needed for disputes: until the expiry of the relevant legal terms.
8. Data security
- access control and role-based restriction of rights;
- user authentication;
- encryption of communications;
- backups and incident monitoring;
- security updates;
- confidentiality obligations for staff and collaborators.
No method of electronic transmission or storage can guarantee absolute security.
9. Rights of data subjects
Access; rectification; erasure (under the conditions of the law); restriction of processing; data portability; objection; withdrawal of consent; human intervention in the case of solely automated decisions, where applicable.
Requests are sent to contact@holma.ro. The data subject may lodge a complaint with the supervisory authority in the Member State of residence, place of work or where the alleged infringement took place, including the competent authority in Romania.
10. Cookies
Strictly necessary cookies may be used without consent, to the extent permitted by law. Analytics, advertising, profiling or third-party integration cookies will be enabled only after a valid choice is expressed, where the law requires it. The user must be able to accept, refuse, select categories and later withdraw consent as easily as it was given.
11. Changes to the policy
We may update this policy to reflect changes to the services, providers or legal requirements. The updated version will be published on the site together with the date of the last change.