Privacy Policy
Last updated: August 11, 2026
1. Who is responsible, and in which role
TIMPIA S.R.L., operating as Noda Energy ("Noda", "we", "us"), publishes this notice. It covers the public website (noda.energy), the demo booking flow, the trial surface at trial.noda.energy, and the Noda workspace at app.noda.energy.
- Company: TIMPIA S.R.L., operating as Noda Energy
- Legal form: Societate cu răspundere limitată (S.R.L.), a limited liability company incorporated in Romania
- Registered office: Str. Zizinului nr. 6, bl. 40, sc. A, et. 5, ap. 15, camera 3, Brașov 500414, Romania
- Operating address: Coresi Business Campus, Str. Zaharia Stancu nr. 6, Brașov, Romania
- Trade Register: J08/2046/2023
- EU VAT: RO53544402
- Email: [email protected]
- Phone: +40 787 578 482
We act in two different roles, and the distinction matters:
- Controller for account data, authentication data, billing data, audit and security logs, booking and enquiry submissions, and cookie and consent records. We decide why and how these are processed.
- Processor for the project material you submit for screening — site geometry, coordinates, capacity, your written questions and notes, and any documents you upload. You decide what to submit and why. We process it on your instructions in order to produce your report.
We have not appointed a Data Protection Officer, because Article 37(1) GDPR does not require one for our processing. Data protection matters go to the address above.
2. What we process
As controller:
- Account data: first name, last name, work email, phone, company name, role, locale
- Authentication data: password hash, token version, last login timestamp, and the subject identifier from any single sign-on provider you use
- Billing data: customer and subscription identifiers. Your billing address, your VAT number and your invoices are held by our payment provider and read live from it when you open the billing page; we do not keep our own copy
- Credit ledger: credits granted, held, consumed and returned, with the site and run they relate to
- Site assistant messages — Art. 6(1)(f) legitimate interest in answering questions about the product, and Art. 6(1)(b) where the exchange leads to a contract.
- Profile image — Art. 6(1)(b), so that colleagues on the same account can tell each other apart.
- Cookie and consent choices — stored in your own browser, not on our servers.
- Legal acceptance records: your name, email, organisation, IP address, timestamp and document version, recorded when you accept an agreement in the platform
- Audit and security logs: IP address, user agent, timestamps, authentication and administrative events
- Booking and enquiry submissions: name, work email, company, and free text you send us
- Cookie and consent records: language preference, consent choices, consent timestamp
- Profile image: the avatar you upload, if you upload one
- Website analytics events: page views with referrer, campaign parameters, user agent, language, time zone and screen size, recorded with an anonymised IP address
- Site assistant messages: what you type into the assistant on the public website
As processor, on your instructions:
- Project material: site polygon and coordinates, project type, requested capacity, the screening questions you select or write, project notes, and uploaded documents
Uploaded documents may contain personal data about third parties — landowners, operator staff, signatories. Where that is so, you remain the controller for it and are responsible for the notice and lawful basis owed to those people. We process it only to produce your report.
3. Why, and on what legal basis
- Account, authentication, credits and delivery of the service — Art. 6(1)(b) contract. Required to operate the subscription you entered into.
- Billing, invoicing and tax records — Art. 6(1)(c) legal obligation. Romanian Law 82/1991 on accounting, Article 319 of the Fiscal Code, Council Directive 2006/112/EC, and Romanian e-Invoicing rules.
- Legal acceptance records — Art. 6(1)(c) and Art. 6(1)(f). Accountability under Article 7(1) and Article 5(2) GDPR, and evidence that an agreement was entered into.
- Audit and security logs — Art. 6(1)(f) legitimate interests. Security, abuse prevention and accountability under Article 32. The balancing favours processing: business users, minimal data, expected behaviour, short retention.
- Booking and enquiry submissions — Art. 6(1)(b) pre-contractual steps where you are asking to use the product, otherwise Art. 6(1)(f) for answering business correspondence.
- Non-essential cookies and website analytics — Art. 6(1)(a) consent. Set only after you opt in, and withdrawable at any time. In the signed-in workspace, product analytics run under Art. 6(1)(f) legitimate interest in operating and improving the Service; you may opt out at any time with no effect on the Service.
- Project material — processed on your documented instructions under Article 28. We do not determine its purposes.
Our legitimate interests assessments are documented and available on request from [email protected].
Providing account and billing data is a contractual requirement. Without it we cannot open an account or invoice you.
4. Who receives your data
We use the sub-processors listed on the Sub-processors page, which names each company, what it receives, where it processes, and the transfer mechanism. That page is the authoritative list and is dated against the software build it describes.
Two things about that list deserve to be said plainly here.
Report generation uses an external model provider. To produce a screening report, the site geometry, coordinates, requested capacity, the questions and notes you wrote, and relevant content extracted from the documents you upload are sent to our model routing provider and the model operator behind it. Your name, your email address and your company name are not included in what is sent — the request carries an opaque run identifier instead. Our agreement with the routing provider prohibits retention of request content and prohibits training on it, and passes the same prohibition to the model operator. The instruction is also set on every request and re-applied on every retry. We can show you both the signed agreement and the configuration. Details, including the companies and the safeguards, are on the Sub-processors page.
The system reads public sources at run time. During a screening the agent queries public web, map and geospatial sources chosen at run time to answer your questions — grid operator publications, planning and environmental registers, map tiles, solar and wind datasets. These requests carry the site coordinates and search terms derived from your questions. The system is not restricted to a fixed list of hosts: it may contact any public source it judges relevant to your questions. Because those sources are chosen during the run, we describe them as a category and cannot publish an exhaustive list of every host contacted.
We also disclose data where we are legally required to, and to professional advisers under confidentiality. Where a law, court or regulator requires us to disclose material you submitted, we tell you first wherever we are lawfully able to. We do not sell personal data and we do not use your project material to train models for other customers.
5. International transfers
Hosting, storage and the database for the Noda workspace are in Germany. Some sub-processors are established outside the EEA, principally in the United States, with the exceptions set out on the Sub-processors page.
Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses of 4 June 2021 (Implementing Decision (EU) 2021/914), and, where the recipient is certified, on the EU-US Data Privacy Framework adequacy decision of 10 July 2023 (Implementing Decision (EU) 2023/1795). The transfer basis for each recipient is recorded on the Sub-processors page.
You may request a copy of the relevant safeguards from [email protected].
6. How long we keep it
| Category | Retention | Reason |
|---|---|---|
| Invoices, billing records, VAT identifiers | 5 years, calculated from 1 July of the year following the financial year | Article 25 of Romanian Law 82/1991, as amended by Law 36/2023 |
| Account and authentication data | For the life of the account; anonymised on closure or on request | Contract performance, then Article 5(1)(e) storage limitation |
| Project material and generated reports | For the life of the account, or until you ask us to delete it | You may need to return to a screening; deletion on request is honoured within 30 days |
| Legal acceptance records | For the life of the account plus the limitation period for the agreement | Evidence of consent and contract formation |
| Security and audit logs | 12 months | Legitimate interest, balanced against storage limitation |
| Booking and enquiry submissions | 24 months from the last interaction | Business correspondence, documented legitimate interest |
| Credit ledger | Retained with billing records | Financial record of what was purchased and consumed |
The table above is what we apply; deletion runs on request rather than on a scheduled job. The periods above are the maximum periods we apply as policy, and deletion is carried out by hand — on your request, or when an account is closed. You should know exactly what that does and does not remove. Closing an account detaches your name and email from it and ends access. Deletion on request is complete: documents, reports, sites and runs are all removed. Only the accounting and tax records we are legally required to keep are held back, and we tell you precisely what was kept and why. If you want your project material removed, write to [email protected] and we will delete it within 30 days and confirm.
Project material and reports remain available for at least 30 days after termination so that you can export them. They are not deleted automatically after that either; deletion is on request.
7. Security of processing
Article 32 GDPR requires measures appropriate to the risk. These are the ones we operate today, stated so that you can assess them rather than take them on trust.
- Credential handling. Passwords are stored as bcrypt hashes, never in plain text. Sessions use signed tokens with a per-account version that lets us invalidate every existing session immediately.
- Tenant isolation. Sites, runs, reports and documents are scoped to the owning account and enforced on every request, so that one customer's material cannot be served to another.
- Private object storage. Uploaded project documents are held in a private bucket that refuses anonymous access.
- Rate limiting on authentication and run creation.
- Audit logging of authentication, administrative and legal-acceptance events.
- Encryption, in both states. Traffic to and from the platform is encrypted in transit with TLS on every host, including between our own services. Data at rest is encrypted on the storage that holds the database and the object store, using strong industry-standard algorithms. Keys are held by us and are not shared with any sub-processor.
- Location. The platform, its database and its object storage run on dedicated servers in Germany.
- Access control. Production access is limited to named administrators.
Two things worth saying plainly.
- Keep your own copy of anything you upload. Noda is a screening platform, not a document management system, and it is not designed to be your archive of record. Your originals should live where the rest of your project documentation lives.
- We answer security questions in writing. We will complete your security questionnaire, walk your team through the architecture, and put anything you need into the data processing agreement. Ask at [email protected].
8. Personal data breaches
Where we are controller and a breach is likely to result in a risk to your rights and freedoms, we notify the Romanian supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, under Article 33. Where the risk is high, we notify affected people directly under Article 34.
Where we act as processor for your project material, we notify you without undue delay after becoming aware of a breach affecting it,, with the information you need to make your own Article 33 assessment. We treat "becoming aware" as the point at which any of our people actually knows, and we do not wait for certainty before telling you.
We also tell you, on the same basis, about any breach affecting your users' accounts or credentials even though we are controller for those, and about any breach at one of our sub-processors that affects your material. An initial notification is sent within 24 hours even if it is incomplete, and supplemented as we learn more.
9. Your rights
Under the GDPR you may request:
- Access to the personal data we hold about you (Art. 15)
- Rectification of inaccurate data (Art. 16)
- Erasure where the conditions are met (Art. 17). Billing data retained under tax law cannot be deleted before that five-year period expires.
- Restriction of processing (Art. 18)
- Portability of data you provided, in a structured, machine-readable format (Art. 20)
- Objection to processing based on legitimate interests (Art. 21)
- Withdrawal of consent at any time, without affecting processing already carried out (Art. 7(3))
Write to [email protected]. We respond within one month of receiving your request, as Article 12(3) requires. Where a request is complex or you have made several, we may extend by up to two further months and will tell you within the first month, with the reason.
If you are exercising rights over material a customer of ours submitted, we act only as processor. We will tell you that we hold the material for an undisclosed customer, forward your request to them within three business days, and assist them in responding. We do not identify our customer to you without their consent, and we do not answer for them.
Where we rectify, erase or restrict personal data at your request, we tell each recipient it was disclosed to, unless that proves impossible or disproportionate, and we tell you who those recipients were if you ask (Article 19).
You may lodge a complaint with the Romanian supervisory authority, Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, [email protected], +40 318 059 211, or with the authority where you live or work. The step-by-step procedure is on our Data Rights page.
10. Automated processing and AI
Noda uses artificial intelligence to produce preliminary grid and project screening reports. A report is generated end to end by the system. No Noda engineer reviews it before you receive it, and it is advisory: the assessment it feeds is yours. Every finding carries an evidence class, assumptions are marked rather than hidden, and the report states where data was missing.
The system does not take decisions producing legal effects concerning you, or similarly significantly affecting you, within the meaning of Article 22 GDPR. Reports assess energy projects, not people. You can ask how a report was produced at [email protected].
Transparency information required by Article 50 of the EU AI Act (Regulation (EU) 2024/1689) is on the AI Disclosure page.
11. Cookies and analytics
Essential cookies keep you signed in and remember your language and consent choices. The identifiers we set, what each one does and how long it lives are listed on the Cookie Policy page.
On the public website, analytics run when you accept them in the banner.
In the workspace, product analytics start when you sign in and are limited to interaction events. Session recording is switched off. If you want your account excluded from product analytics, write to [email protected] and we will exclude it, with no effect on the Service.
Analytics are hosted in the European Union. Session recording is switched off. We do not record your screen, and no recording of a customer session exists.
What we do collect is interaction telemetry: which page you opened, which button or control you used, when a run started and finished, and whether an action succeeded or returned an error. Each event carries the page, the control, a timestamp and your account identifier. It does not carry your screen, your keystrokes, the contents of a form, the text of a document, or the geometry of a site. One exception: where you submit the access-request or booking form on the public website, the analytics identifier is the email address you typed rather than a random id. We use it to see which parts of the product are used and where they fail, and for nothing else. The events sit with our analytics provider in the European Union under a signed data processing agreement. Any customer can ask us to exclude its whole organisation, and we will do it on request with no effect on the Service. Browser error reports are also sent to our error-reporting provider — from the browser, and from our own servers and background workers, where any handled error becomes an event. We turn off that provider's automatic collection of personal data and strip authorisation headers before sending.
12. Children
Noda is a business product. It is not directed at children and we do not knowingly process the personal data of anyone under 16. If you believe a child has provided us with personal data, write to [email protected] and we will delete it.
13. Changes to this notice
We update this notice when our processing changes. The date at the top is the date of the current version. Where a change materially affects you, we tell account holders by email before it takes effect. Sub-processor changes follow the notice period set out on the Sub-processors page.