Privacy Policy
Version dated 31 August 2026.
Brief: PlanHub is a Romanian business software platform operated by BELETAGE S.R.L. We do not sell personal data, use it for advertising, or place marketing cookies. Data is shared with external systems only when required to provide a feature selected by the customer.
1. Data controller and contact
BELETAGE S.R.L., Str. Albac no. 2, sc. 1, ap. 1, Cluj-Napoca, Cluj County, Romania, VAT number RO30290445, Trade Register number J12/1545/2012.
Privacy and data protection contact: contact@planhub.ro.
For personal data entered by a customer about its own clients, employees and collaborators, that customer is the controller and BELETAGE S.R.L. acts as processor, solely to provide PlanHub according to the customer's instructions.
2. Personal data we process
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address and password hash | Account creation, authentication and support | Performance of the service contract |
| Company identity, fiscal address, VAT and trade register data | Company setup, billing, documents and e-Factura | Contract and legal obligations |
| Project, client, collaborator and document data uploaded by users | Project management, collaboration, document storage and qualified electronic signing | Contract |
| Issued and received invoices, payments, bank accounts and transactions | Accounting records and reconciliation, only when the customer enables those functions | Contract and explicit bank authorisation |
| ANAF e-Factura and SPV data | Sending, receiving and archiving fiscal documents selected by the customer | Contract, authorisation and legal obligations |
| IP address, browser and device information, session and security logs | Security, abuse prevention and technical diagnostics | Legitimate interest |
| Support access performed by PlanHub administrators | Customer support, with access purpose, time and operator recorded in an audit log | Legitimate interest |
3. Recipients and service providers
- ANAF, for e-Factura and SPV functions explicitly connected by the customer.
- ANCPI, when the customer orders a land book extract.
- Enable Banking and the customer's bank, for read-only account information, balances and transactions, only after the customer signs consent in the bank's application. PlanHub cannot move funds.
- Brevo, for transactional emails such as account confirmations, invitations and notifications.
- Netopia Payments, for card payments. Full card details do not pass through PlanHub.
- Cloudflare, for DNS and the anti-bot check used at registration.
- Google, for the mobile application only: it delivers push notifications to the device and receives a device identifier for that purpose. The notification carries a count, never a document name.
We do not sell personal data, disclose it for behavioural advertising, or use advertising trackers. Transfers outside the European Economic Area, where applicable, use the safeguards required by the GDPR.
4. Hosting and security
Primary application data and backups are hosted on infrastructure controlled by BELETAGE S.R.L. in Romania. Connections use HTTPS. Each customer organisation is isolated at database level. Passwords are stored only as cryptographic hashes. Support access is logged and expires automatically.
The PlanHub Semnare desktop application uses the qualified certificate connected to the user's own computer. The private key and PIN do not leave the signature device.
5. Retention
- Account and company data: while the account is active and during the deletion grace period.
- Invoices and accounting records: 10 years, as required by Romanian law.
- Technical and registration security logs: up to 12 months.
- Operational backups: 30 days, with one monthly recovery point retained for up to one year.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interest. The application also provides a direct account export and a deletion process with a seven-day cancellation period.
Send requests to contact@planhub.ro. We answer within 30 days. You may also contact the Romanian National Supervisory Authority for Personal Data Processing at dataprotection.ro.
7. Cookies
PlanHub uses only cookies and local storage required for authentication, security and the selected application functions. The public website does not use advertising or behavioural analytics cookies.
8. The mobile application
The PlanHub mobile application does one thing: it shows the documents awaiting your signature and lets you approve them. It is not a second interface to the platform.
It requests exactly three permissions from the device: internet access, use of the fingerprint (or screen lock code), and permission to display notifications. It does not request location, contacts, files, camera or microphone.
- Account. Email and password are used only to sign you in to the same account you have on the platform. The session stays on the device, encrypted with a key held in its hardware.
- Documents awaiting you. The application reads their names, who sent them, and the cryptographic digest you sign. Document contents are not downloaded to the device.
- Approval key. It is created inside the device hardware. The private part never leaves it and cannot be used without your fingerprint or screen lock code. Only the public part reaches us, and it is what lets us verify what you approved.
- Notifications. So the device can learn that something needs signing, a notification identifier issued by Google is linked to your account. The notification carries no content: it states only how many documents are waiting, never which ones, so a project name never appears on a locked screen.
If notifications are suppressed by battery optimisation, the application checks for itself every fifteen minutes whether something new has arrived. It remembers on the device only the identifiers of documents it has already announced, so it does not alert you twice for the same thing.
On sign-out the session is deleted from the device and the periodic check stops. The approval key remains on the device until you replace it or uninstall the application; without a valid session it cannot be used for anything.
9. Changes
Material changes are announced by email at least 15 days before they take effect. The current version and date are always published on this page.