Privacy policy

This policy covers the nordopsmeteo.ro site, the web application at app.nordopsmeteo.ro and the NordOps Meteo mobile application for Android.

Last updated: 4 September 2026

Data controller

The NordOps Meteo service is operated by SC Nordops Solutions SRL, with its registered office at str. Canalului 22, Dej, Cluj county, Romania, tax identification number 48063682, registered with the Romanian Trade Register under number J12/1907/2023. For any question about your personal data, write to contact@nordopsmeteo.ro. We answer within 30 days at the latest, the deadline set by the GDPR.

What this policy covers

Three surfaces, with the same controller and the same database:

  • The public site nordopsmeteo.ro, which presents the product and carries the contact form.
  • The web application app.nordopsmeteo.ro, which holds your account, stations, alerts, irrigation and invoices.
  • The mobile application NordOps Meteo for Android, which offers the same field functions plus notifications.

What we collect

We collect only what is needed to deliver the service and to issue invoices. We do not buy data from other sources and we do not profile you.

  • The contact form: name, farm, email, phone and your message. Alongside them we store the IP address and the browser user agent, so that we can stop automated submissions.
  • Your account: email, name, phone, role within the company, the moment you accepted the terms, and the date of your last sign-in. The password is never stored in clear text, only as a hash.
  • Company details, for invoicing: legal name, tax identification number, trade register number, address, city, county and postal code.
  • Issued invoices: series, number, amounts and the fiscal details as they stood at the moment of issue, kept unalterable, as accounting law requires.
  • Push notifications: the device token issued by Google, the platform, the application version and the language. The token identifies the app installation, not the phone and not the person.
  • Location photographs: the image you upload. EXIF metadata, including the GPS coordinates the phone writes automatically, is stripped before storage, so the photo reaches us without it.
  • Sensor measurements: temperature, humidity, rainfall and the other values, tied to your company stations. They are not personal data, but they are readable only by your company users.

What we do not collect

  • The location of your phone. The mobile application does not request the location permission and contains no code that would read it.
  • Card details. Card payment happens entirely at Stripe; the card number never passes through our servers and never reaches our database.
  • Analytics, advertising trackers or third-party cookies. Neither the site nor the applications contain any audience measurement tool or any ad network.
  • Contacts, gallery photographs, the microphone, or any other data on your phone.

Legal basis

Every processing operation rests on one of the grounds in article 6 of the GDPR:

  • Performance of the contract for the account, service delivery, alerts and support.
  • Legal obligation for invoicing, e-Factura reporting and the retention of accounting documents.
  • Legitimate interest for platform security, blocking automated form submissions, and answering commercial enquiries.
  • Consent for push notifications, which you switch on yourself inside the application and can switch off at any time.

Who we share data with

We do not sell data and we pass it to nobody for marketing. We share it only with the providers the service depends on, each within the limits of its role:

  • Google (Firebase Cloud Messaging) delivers notifications to the phone. It receives the device token and the notification text.
  • Stripe processes the card payment and holds the card details.
  • ANAF receives invoices issued to companies established in Romania, through the SPV e-Factura system. This is a legal obligation.
  • Cloudflare Turnstile checks the contact form against automated submissions.
  • Our email provider sends transactional messages: invitations, password resets, alerts and invoices.
  • Telegram, only if you choose that channel for alerts.
  • Hetzner hosts the servers and the object storage.

Where data is stored

The servers and the object storage are located in the European Union. Some of the providers above, Google and Stripe, are companies established in the United States; transfers to them rely on the European Commission adequacy decision for the EU-US Data Privacy Framework, or on standard contractual clauses.

How long we keep it

  • The account and company details for as long as the contractual relationship lasts, plus the period in which claims may still be raised.
  • Invoices and accounting documents for 10 years, the term set by Romanian accounting law. These cannot be deleted on request.
  • Contact form enquiries until we archive or delete them, usually once the commercial discussion is closed.
  • Notification tokens until you sign out, uninstall the application, or Google tells us the token is no longer valid.

Push notifications

The mobile application asks for the notification permission the first time you open the alerts screen, not at installation. If you decline, the rest of the application works normally. You can switch notifications off at any time from Settings, and the device token is deleted from our servers at that moment. Signing out deletes it automatically.

Security

  • All traffic between the applications and the server is encrypted with TLS.
  • Passwords are stored only as hashes, using a function designed to resist dictionary attacks.
  • Sessions use time-limited tokens, held on the phone in the operating system secure storage.
  • Location photographs are served through signed URLs that expire; invoices travel only through authenticated routes.
  • The administration console and the client application use different tokens, which are not interchangeable.

Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw your consent where the processing relies on it. Write to contact@nordopsmeteo.ro.

  • If our answer does not satisfy you, you may address the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), Bd. General Gheorghe Magheru 28-30, Bucharest, or anspdcp.ro.

Deleting your account

You can request deletion of your account by writing to contact@nordopsmeteo.ro from the address you registered with. We delete the account, the profile data and the notification tokens within 30 days at the latest. Issued invoices remain, because accounting law obliges us to keep them for 10 years; they are no longer tied to an active account.

Changes to this policy

If we change this policy we update the date at the top of the page. For changes that affect you directly we also notify you by email.