Privacy notice
We sell not touching your data.
The website is no different
No cookies, no analytics, no profiling. Here is exactly what reaches us, why, for how long, and what this notice deliberately does not cover.
Last updated 18 September 2026.
The short version
This website sets no cookies. It runs no analytics, no tracking pixels, no advertising tags and no session recording. Nothing you read here is profiled, and we cannot tell one visitor from another. The only personal data that reaches us is what you deliberately send: a demo request, or an email.
One thing we are fixing
Fonts are currently loaded from Google’s servers, which means your IP address reaches Google when a page loads. We are moving to self-hosted fonts. Until that ships, it is disclosed in section 04 below rather than left out.
01
Who is responsible for your data
The controller is INVENTIFF SOFT S.R.L., Strada Sebeșului nr. 1, ap. 1, Baia Mare, Maramureș County, Romania, trade register J24/627/2018, CUI 39298507.
For anything about your personal data, write to [email protected] or to [email protected]. We answer within 30 days, and usually much sooner.
02
What we process, and why
Demo requests
The form on the demo page asks for your name, work email, organisation, role and what you would like to see. It does not store anything on this website: submitting it opens your own email client with the answers filled in, so the request reaches us as an ordinary email that you sent. We use it to prepare and hold the demo, and to reply to you.
Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR). Retention: for as long as the conversation is live, and then with our commercial correspondence.
Email and other correspondence
If you write to us, we keep the message and our reply so the conversation makes sense later. Legal basis: our legitimate interest in answering people who contact us (Art. 6(1)(f)).
Server logs
The web server records the request: IP address, time, the page requested, the referring page and the browser string. These are used to keep the site running and to see abuse or attacks, never to build a profile. Legal basis: legitimate interest in the security and availability of the site (Art. 6(1)(f)). Retention: 14 days.
What we do not do
No advertising, no profiling, no automated decision-making, no selling or sharing of your details with anyone for their own purposes, and no newsletter you did not ask for.
04
Who else is involved
Two third parties sit in the path of a page load, and no others.
Cloudflare, Inc. (United States)
Proxy, TLS and caching in front of the site. It processes request metadata, including your IP address, to deliver the page and to filter attacks. Transfers outside the EU rest on the EU–US Data Privacy Framework and on standard contractual clauses.
Google (Google Fonts)
The typeface is currently requested from fonts.googleapis.com and fonts.gstatic.com, so your IP address reaches Google when a page loads. No cookie is set by this. We are replacing it with a self-hosted copy of the font, after which no request will leave for Google at all.
Beyond those two: no analytics provider, no advertising network, no marketing platform, no chat widget, no embedded video, no social plugins.
05
What this notice does not cover
This is the part people usually ask about first, so it is worth being plain.
If you run Provbl, your documents never reach us. The platform is installed in your own infrastructure. Your files, your index, your users and their questions stay inside that deployment. We do not receive them, we cannot read them, and there is no copy of them on our side to disclose, export or be compelled to hand over.
For that content you are the controller. We are not a processor of it by virtue of the software running. Where our team supports or operates your deployment, what we may and may not access is set out in the written agreement between us, not in this notice.
The technical side of that boundary is described on the security page, and a one-page data-flow record naming the exact model, region and retention setting ships with every deployment for your register of processing activities.
06
Your rights
Under the GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable format, and object to processing we base on legitimate interest. Exercising any of them is free and costs you nothing but an email.
Write to [email protected]. If we get it wrong, you can complain to the Romanian supervisory authority:
- Authority
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Address
- B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, Romania
- Website
- www.dataprotection.ro
If you are in another EU country you may complain to your own authority instead.
07
Changes to this notice
If what we do with data changes, this page changes with it and the date at the top moves. We do not make quiet edits: anything that affects you materially will be stated in the section it belongs to.