This policy explains what personal data we process, for what purpose, on what legal basis, how long we keep it, who we share it with, and what rights you have over it.
Layro is used by several different kinds of people, and the data we process differs between them. Section 2 shows you which part of this document applies to you.
The terms we use. “Account holder” means the professional who creates an account; “invited client” means the person they invite to a project; “project” means the workspace containing phases, files, marks, comments and approvals. Legal terms — “controller”, “data subject”, “processing”, “legal basis” — carry the meaning given in Regulation (EU) 2016/679 (“GDPR”), and references to articles without further qualification are references to it.
1. Who we are
The controller of the personal data described in this policy is:
Layro S.R.L.
Registered office: Str. Pitar Moș nr. 27, et. 5, ap. 17, Sector 1, București, România
VAT number: RO44254027
Trade register: J2021008343401
Email: contact@layro.ro
For any question about your data, including to exercise the rights described in section 14, write to us at contact@layro.ro or through our Contact page. We have not designated a Data Protection Officer; requests are handled by the Layro team, within the time limits set out in section 14.
2. Who this policy is for
Layro is used by different kinds of people, and the data we process about each is different. This policy therefore addresses three categories of data subject:
- Site visitors — people browsing our public website at layro.ro (section 3);
- Account holders — the professionals who create an account at app.layro.ro and manage their projects there, such as architects, architecture practices and interior designers (section 4);
- Invited clients — the people an account holder invites into a project to review and approve drawings. Clients do not create an account and have no contract with us, but their data is processed by Layro (section 5).
This policy is publicly available without signing in, so that it can also be read by invited clients, who have no account through which to reach it.
People appearing in uploaded content. Project files may incidentally contain data about other people — someone caught in a site photograph, say, or a name in a drawing's title block. We have no direct relationship with these people and cannot contact them individually: it is the account holder who decides what to upload and who confirms, through our Terms & Conditions, that they are entitled to do so. If this describes you, write to us at contact@layro.ro and we will explain what data we hold and how you can exercise the rights in section 14.
3. Visitors to layro.ro
When you visit our public website, we process:
- Usage and technical data — pages visited, browser and device type, operating system, and an approximate location inferred from your IP address. This data is collected through PostHog, in one of two modes. By default — if you have not chosen yet, or if you declined the banner — measurement runs without storing or reading anything in your browser, and the identifier used is generated on PostHog’s server and changes daily, so we cannot recognise you from one visit to the next. This rests on legitimate interests and you may object at any time. If you accept the banner, we additionally store a random identifier in your browser, which shows us returning visitors, and we also capture clicks on page elements. We measure nothing at all if your browser sends a Do Not Track signal.
- Newsletter subscription data — if you subscribe to Layro news, we process the email address you enter and, if you choose to fill it in, your name. Subscription is confirmed by a validation email: the address joins the list only after you click the link in that message. We also keep the record of your consent — when you subscribed and the wording you agreed to. Details are in section 7.
Full details about cookies and similar technologies are in our Cookie Policy.
4. Account holders
To create and run your account in the application, we process:
- Identification and contact data — first name, last name and email address;
- Authentication data — your password stored only as a cryptographic hash (bcrypt); we have no access to your password in clear text. Alongside it, the temporary account activation and password reset codes, and your session tokens;
- Language preference — so we can show the interface and send emails in the language you chose;
- Your marketing choice — whether or not you agreed to receive Layro news, together with when you chose and the wording you agreed to. We keep this in order to be able to demonstrate consent, as Art. 7(1) GDPR requires;
- Subscription data — the plan you chose, the state of the subscription, the date of the next renewal or plan change, and the corresponding Stripe identifiers. We never receive or store your card details — those are entered directly into a secure page hosted by Stripe;
- The content you upload — projects, phases, folders, files and drawings, together with the marks, comments and approvals attached to them;
- Activity history — a record of what happened in a project (who uploaded a file, who added a mark, who approved a phase), together with the name of the person who acted and when;
- Technical logs — server and load balancer logs, containing IP addresses, request times and requested addresses. These are needed for security and for diagnosing faults.
Providing your name, email address and password is necessary to enter into and perform the contract: without them we cannot create your account. The remaining data arises from your actual use of the application.
5. Clients invited to a project
If you have been invited to view a project in Layro, we process:
- Your name, email address and language preference — supplied by the professional who invited you;
- Your invitation token, the time you were invited and the time you last opened the project — these are what let you in without an account or password;
- The content you create — the marks, comments and approvals you add to the project, together with your name and the time of each action, recorded in the project history.
Where your data came from. We did not obtain your name and email address from you directly, but from the professional running the project, at the moment they invited you. We tell you this under Art. 14 GDPR. It is they who decide whom to invite to a project; if you would rather not be invited, the most direct route is to tell them, but you can always come to us and use the rights in section 14 — including the right to object.
Who decides about your data. For the project data — the files, your markups, comments and approvals — the controller is the professional who invited you, and Layro acts as their processor: it handles that data solely on their instructions, under the Data Processing Agreement. If you want it deleted or corrected, the fastest route is to ask them directly. If you come to us, we pass the request on to them without delay.
We do not create an account for you and we never ask you for a password. Your access to the project works solely through the invitation link you received by email.
6. Legal bases for processing
Each of the activities described above rests on its own legal basis under Art. 6 GDPR:
| Processing | Legal basis | Explanation |
|---|---|---|
| Running an account, projects and files | Performance of a contract — Art. 6(1)(b) | This is the very service the account holder signed up for. |
| Billing and collecting the subscription through Stripe | Performance of a contract — Art. 6(1)(b), plus legal obligation — Art. 6(1)(c) | Accounting obligations require supporting documents to be kept for a period that outlasts the contract. |
| Client access to a project | Legitimate interests — Art. 6(1)(f) | The client has no contract with us. The legitimate interest is enabling the account holder to work with their own client. This is precisely why the client has the right to object under Art. 21. |
| Daily digest sent to account holders | Performance of a contract — Art. 6(1)(b) | It forms part of the contracted service. The Art. 21 right to object does not attach to contract-based processing, but the digest can still be stopped at any time (section 7). |
| Daily digest sent to invited clients | Legitimate interests — Art. 6(1)(f) | Here Art. 21 does apply: the client may object and we must stop sending. This is why every digest carries a way to unsubscribe. |
| Project activity ledger | Legitimate interests — Art. 6(1)(f) | Traceability of decisions in a project (who approved what, and when) is in the interest of both parties and prevents later disputes. |
| Transactional email (account activation, password reset, invitation, essential notices) | Performance of a contract — Art. 6(1)(b) or legitimate interests — Art. 6(1)(f) | These are necessary for the service to work. They are affected neither by unsubscribing from the daily digest nor by unsubscribing from marketing email. |
| Marketing email (Layro news, new features, offers) | Consent — Art. 6(1)(a), read with Art. 12 of Romanian Law no. 506/2004 | Sent only to people who expressly subscribed, through a box that is not pre-ticked. Consent can be withdrawn at any time, from the unsubscribe link in every message. Clients invited to a project never receive these messages. |
| Anonymous traffic measurement on the public website, with nothing stored on your device | Legitimate interests — Art. 6(1)(f) | Knowing whether the site is read and which sections are useful. Nothing is stored in the browser, no profiles are built, and the server-side identifier changes daily. You may object at any time (Art. 21). |
| Recognising returning visitors, via an identifier stored in the browser | Consent — Art. 6(1)(a) | Activated only after you accept the cookie banner, and withdrawable at any time. |
| Service security and technical logs | Legitimate interests — Art. 6(1)(f) | Preventing abuse, detecting incidents and diagnosing faults. |
| Retention of accounting documents | Legal obligation — Art. 6(1)(c) | Romanian Accounting Law no. 82/1991. |
7. The email we send you
Layro sends three kinds of message, on different terms: the daily digest, which gathers the activity in your projects; marketing email, which you receive only if you subscribed; and transactional email, which the service needs in order to work. The three are handled separately: stopping one does not stop the others.
The daily digest
The daily digest gathers into a single message what happened in your projects the previous day: new files, marks, comments and approvals. Account holders receive it early in the morning and invited clients later in the morning. If nothing happened, no email is sent.
How to stop it. Every digest carries a way to unsubscribe at the bottom: simply reply to that email and we will stop the digest for that address. The messages also include the standard List-Unsubscribe header, which some email applications use to show an unsubscribe button.
Marketing email
If you expressly subscribed, we send you occasional news about Layro — new features, platform improvements and, from time to time, offers.
How you agree to it. By voluntarily ticking a dedicated box, when you create your account or in the subscription form on our website. The box is not pre-ticked, and it is not a condition of creating an account or of using the service: if you leave it unticked, Layro works exactly the same. When you subscribe through the form on our website, we first send you a confirmation email, and the address joins the list only after you click the link in it.
How to unsubscribe. Every message carries an unsubscribe link that works in a single click, without signing in and without having to write to us. If you have not received a message yet and want to withdraw your consent, write to us at contact@layro.ro. Withdrawal takes effect without delay and does not affect the lawfulness of messages sent beforehand.
Who never receives these messages. Clients invited to a project never receive marketing email from us. Their addresses are entrusted to us by the professional who invited them, solely for running the project, and our Data Processing Agreement forbids us from using them for our own marketing.
These messages are delivered through Brevo (section 9). We do not measure whether you open them and we do not track the links you click inside them.
Transactional email
Account activation, password resets, project invitations and essential service notices are necessary for Layro to work. They continue to be sent whether or not you stopped the daily digest or unsubscribed from marketing email.
8. How long we keep data
The periods below are the ones actually configured in our systems:
| Category of data | Retention period |
|---|---|
| Your account and its content (projects, files, marks, comments, approvals) | For as long as the account exists. Deleted when the account is deleted (section 13). |
| Unconfirmed registrations (accounts created but never activated by email) | Deleted automatically after 90 days. |
| Expired session refresh tokens | Deleted automatically 30 days after they expire. |
| Activity history and notifications | For the life of the project. Deleted when the project is deleted. |
| Invited clients’ data | For the life of the project they were invited to. Deleted when that project is deleted. |
| Accounting documents and invoices | 5 years, under Art. 25 of Romanian Accounting Law no. 82/1991, counted from 1 July of the year following the financial year. This legal obligation continues to apply after an account is deleted. |
| Application technical logs | 14 days. |
| Database backups | 5 days (section 11). |
| Previous versions of project files | Kept for as long as the file exists, so you can return to an earlier version. Deleted together with the file or the project. |
| Project cover image, once replaced | The replaced image is removed automatically after 30 days (section 11). |
| Website traffic analytics | A maximum of 12 months, in both measurement modes. |
| Email correspondence (questions, requests, proposals) | For as long as it takes to deal with it. Requests concerning your rights are kept for a further 3 years after resolution (section 19). |
| Newsletter subscription data | Until you unsubscribe or withdraw your consent. |
| The record of your consent to marketing email | 3 years after consent is withdrawn, so that we can demonstrate we obtained it validly, as the accountability duty in Art. 5(2) GDPR requires. |
| Suppression list (unsubscribed addresses) | An unsubscribed address is kept separately, on a suppression list, for as long as we send marketing email. This is the very mechanism that stops us from writing to you again by mistake; deleting it would have the opposite effect. |
9. Who we share data with
To operate, Layro relies on the providers below. They process data on our behalf under processing agreements concluded in accordance with Art. 28 GDPR, and cannot use it for their own purposes. We do not sell or rent data to anyone and we do not disclose it for advertising purposes.
| Provider | What they do for us | Where the data is stored |
|---|---|---|
| Amazon Web Services EMEA SARL (Luxembourg) | Hosts the application, the database, uploaded files and technical logs. | Frankfurt region (eu-central-1), Germany. The content delivery network, however, operates from locations worldwide — see section 10. |
| Stripe Payments Europe, Ltd. (Ireland) | Processes payments and manages subscriptions. Card details are entered directly with Stripe and never reach our servers. | European Union, with an onward transfer to Stripe, Inc. in the United States — see section 10. |
| Hostinger | Hosts our public website at layro.ro and provides the email service through which we send transactional email and the daily digest. | European Union. |
| Brevo (Sendinblue SAS, France) | Delivers marketing email to subscribers and keeps the subscriber list and the suppression list. It receives subscribers’ names and email addresses, not project content. | European Union. |
| KEEZ EXPERT ACCOUNTANT S.R.L. (Romania) | Issues invoices and keeps our accounting records. It receives billing data, not project content. | Romania. |
| PostHog (EU Cloud) | Measures traffic on our public website at layro.ro — anonymously and with nothing stored on your device where there is no consent, with a stored identifier where you accepted. It is not used in the app.layro.ro application. | Frankfurt, Germany. |
Beyond these providers, we may disclose data to public authorities where we are under a legal obligation to do so, and to our professional advisers (lawyers, accountants), strictly as necessary and under a duty of confidentiality.
10. Transfers outside the European Economic Area
Your data is stored in the European Union. There are nonetheless two situations in which data may travel outside the EEA, which we flag explicitly:
- Stripe. We contract with Stripe Payments Europe, Ltd., an Irish company, which transfers data to its parent company Stripe, Inc. in the United States. The transfer relies on the Standard Contractual Clauses adopted by the European Commission, supplemented by Stripe, Inc.’s participation in the EU-US Data Privacy Framework, for which the Commission has issued an adequacy decision.
- The content delivery network (CDN). The application is served through a delivery network operated by AWS, with servers in locations worldwide. To deliver pages quickly, a request arriving from outside Europe may be served by a server located outside the EEA, and the IP address and the requested page pass through that server. The database and the files themselves remain stored exclusively in Germany. This transfer relies on the Standard Contractual Clauses included in our processing agreement with AWS.
You can obtain a copy of the safeguards we rely on by writing to us at contact@layro.ro.
11. Backups
We take backups so the service can be restored after an incident:
- The database — automated backups kept for 5 days, after which they are overwritten;
- Replaced images — when an image is overwritten in storage, such as a project cover, the previous version is kept for a further 30 days and then removed automatically. Previous versions of project files do not go through this mechanism: they are held as files in their own right, for as long as the file exists (section 8).
There is something important to understand about deletion: erasing data from the live system does not rewrite backups that have already been taken. These are sealed archives that cannot be selectively edited without destroying their integrity. Deleted data therefore remains in backups until the periods above elapse, after which it ages out on its own. During that window the backups are not used for any purpose other than restoring the service after an incident, and if a restore were to bring back data you had deleted, we delete it again.
12. Security
- Traffic between your device and our servers is encrypted (HTTPS/TLS);
- The database is stored encrypted, and access to it is restricted to the application’s internal network;
- Passwords are stored only as bcrypt hashes, generated individually for each password; we cannot read them and cannot recover them;
- Uploaded files are reachable only through signed links with a limited lifetime;
- Sessions use short-lived, revocable access tokens;
- The activity history is cryptographically chained, so that any retroactive change to a record can be detected.
If a personal data breach occurs that is likely to affect your rights, we notify the ANSPDCP within 72 hours under Art. 33 GDPR, and inform you directly where the risk is high, under Art. 34.
13. What happens when you delete an account or a project
Deletion in Layro is real, not merely hiding the data:
- Deleting your account immediately cancels the subscription, then deletes the account, your projects, the files in storage, notifications, and the activity history entries for the projects you acted in. We do not keep a pseudonymised copy of them;
- Deleting a project deletes its files, marks, comments, approvals, activity history and notifications, along with the data of the clients invited to that project;
- The exception is accounting documents, which the law requires us to keep for 5 years, and backups already taken, which age out on their own as described in section 11.
If you are an invited client. Two different things need distinguishing.
The account holder withdrawing your access. The account holder can withdraw your access to the project at any time. If you never opened the project and added nothing, your record is deleted outright. If you took part, your access is revoked but your record and contributions stay in the project, so the approval history remains intelligible to both sides. Withdrawing access is therefore not an erasure of your data.
You asking us to erase your data. If you ask us to erase your data, your name and email address are replaced, everywhere they appear, with a neutral marker, and your access is permanently revoked. From that point we can no longer contact you, and what remains cannot identify you.
What remains is only the contributions themselves and the fact that someone acted, together with the time they acted — nothing that identifies you. We keep that under Art. 17(3)(e) GDPR: an approval history with records missing could no longer serve to establish, exercise or defend a legal claim, for you or for the account holder. If you nonetheless consider that these records should not be kept either, write to us at contact@layro.ro and we will look at your situation.
14. Your rights
As a data subject you have the following rights. They apply equally to account holders and to invited clients:
- Right of access (Art. 15) — to find out what data we hold about you and receive a copy of it;
- Right to rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed;
- Right to erasure (Art. 17) — to have your data deleted, within the limits described in sections 11 and 13;
- Right to restriction of processing (Art. 18) — to limit processing while a dispute is being resolved;
- Right to data portability (Art. 20) — to receive the data you provided to us in a structured, commonly used, machine-readable format;
- Right to object (Art. 21) — to object to processing based on our legitimate interests. This right matters particularly for invited clients, whose project access and daily digest both rest on legitimate interests. If you object to receiving the daily digest, we stop it;
- Right to withdraw consent (Art. 7) — for processing based on consent. Withdrawing is as easy as giving consent was, and does not affect the lawfulness of processing carried out beforehand. For marketing email, click the unsubscribe link in any message you received. For the visitor identifier stored in your browser, use , in the footer of every page.
You can exercise any of these rights by writing to us at contact@layro.ro. We respond within one month of receiving your request, a period we may extend by two further months for complex requests, in which case we will tell you within the first month. Exercising your rights is free of charge. We may ask you for further information to satisfy ourselves that the request really comes from you.
15. Cookies and similar technologies
Our public website measures traffic anonymously, storing nothing on your device, and stores a visitor identifier only with your consent. The app.layro.ro application uses no analytics cookies; it stores in your browser only what is strictly necessary to keep you signed in and to remember your chosen language. Full details, including the exact list of what is stored and how to change your choice, are in our Cookie Policy.
16. Automated decision-making and profiling
Layro does not take automated decisions producing legal effects concerning you or similarly significantly affecting you within the meaning of Art. 22 GDPR, and does not subject you to profiling. If we introduce features involving such processing, we will update this policy and inform you before they go live.
17. Children
Layro is a service intended for professional use by professionals and their clients. It is not directed at minors and we do not knowingly collect data from them. If you become aware that a child has provided us with personal data, write to us at contact@layro.ro and we will delete it.
18. Changes to this policy
We may update this policy when the service changes or when new legal requirements arise. The date of the last update is shown at the top of the page. Where a change is significant — a new purpose of processing, or a new recipient — we will tell you in advance by email or through a message in the application, before the change takes effect.
19. Correspondence, complaints and contact
When you write to us. If you contact us at contact@layro.ro — whether with a question about the service, a request concerning your rights, or a partnership proposal — we process your name, your email address and the content of your message, together with any attachments. The basis is our legitimate interest in replying to people who contact us (Art. 6(1)(f)), and where the message concerns entering into a contract, Art. 6(1)(b). We keep correspondence for as long as it takes to deal with it; for requests concerning the rights in section 14, we keep it for a further 3 years after resolution, so we can show that we responded, as required by the accountability obligation in Art. 5(2) GDPR. Our email service is provided by Hostinger (section 9).
If you are unhappy with how we handle your data, please contact us first at contact@layro.ro — in most cases we can resolve the matter directly. You do, however, have the right to lodge a complaint with the supervisory authority at any time:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, cod poștal 010336, București
Email: anspdcp@dataprotection.ro
If you live or work in another European Union member state, you may equally approach the supervisory authority there — Art. 77 GDPR lets you lodge your complaint with the authority in the state of your habitual residence, the state where you work, or the state where the alleged infringement took place.
You also have the right to bring proceedings before the competent courts.