For consumers in Romania the Romanian version prevails.Versiunea in limba romana

Your Data Protection Rights

This page explains the rights you have over your personal data under the GDPR (Regulation (EU) 2016/679) and Legea nr. 190/2018, the Romanian law implementing it, and exactly how to use them with TRIIVON S.R.L. in relation to GPTpostLLM at https://app.oraglegpt.org.

It is written to be usable rather than to be complete for its own sake. If you want to know what we process and why, read Privacy Policy first. If you want your account or workspace erased, Data Deletion Policy is the specific procedure. This page is about the rights themselves and the mechanics of exercising them.

We apply the same process to everyone who asks, wherever they are.


1. First work out who holds your data

The answer to almost every practical question depends on which of two situations you are in. Check this before you write to anyone.

Situation A: the data is about your relationship with us. You hold an account with us, or you wrote to us, or you are billed by us. Here TRIIVON S.R.L. is the controller. We decide why and how that data is processed. Write to us and we answer.

Situation B: you are an individual whose data sits inside a business customer's workspace. A company uses GPTpostLLM and your personal data is in their content, their contact records or their workspace because they put it there. Here that company is the controller and TRIIVON S.R.L. is only the processor. They decide what happens to your data; we run the software.

Your questionWho to ask
"What data does TRIIVON S.R.L. hold about my account?"Us, at contact@oraglegpt.org
"Delete my GPTpostLLM account"Us. See Data Deletion Policy
"A company has my details in their GPTpostLLM workspace, remove them"That company first. See below
"Why did I receive a post mentioning me?"The company that published it

If you are in situation B and you write to us anyway, we will not ignore you. We will not answer on the substance, because we are not entitled to act on your data against the instructions of the controller, but we will tell you that, and where we can identify the controller we will pass your request on to them and tell you we have done so. GDPR art. 28 alin. (3) lit. e) requires us to assist them in answering you, and we do.

If the company does not respond to you, you can complain about that company to the supervisory authority in section 8, or to the authority in their own country.


2. Your rights, one by one

What each right means, and what it means specifically here.

Access (art. 15)

You may ask whether we process your personal data, and if so receive a copy of it together with the purposes, the categories of data, the recipients, the retention period, the source, and the existence of your other rights.

Here: if you hold an account, the fastest route is the export at Settings, Data Privacy in the application. It runs immediately and returns a signed archive covering 48 resource families. You do not need to ask permission or wait for us. Ask us if you want the surrounding information as well, or if you cannot sign in.

Rectification (art. 16)

You may have inaccurate personal data corrected, and incomplete data completed.

Here: most fields are editable in the application by you or by your workspace administrator, which is faster than asking us. Ask us for anything you cannot edit.

Erasure (art. 17)

You may have personal data erased where it is no longer necessary, where you withdraw the consent it relied on, where you object successfully, or where it was processed unlawfully.

Here: account erasure is requested through the API at POST /api/v1/privacy/deletion-requests. There is no account-deletion button on the Data Privacy screen, and we are telling you that rather than letting you hunt for one. There is a 30-day grace period enforced before erasure runs, which you can cancel during the window. Workspace closure has its own 30-day readable-and-exportable window, and the final erasure at the end of it is carried out by us as a commitment rather than by an automatic job. Export anything you want to keep before you start. The full mechanics, including what survives erasure because the law requires it, are in Data Deletion Policy.

Restriction of processing (art. 18)

You may require us to hold data but stop using it, for instance while a dispute about accuracy or a legitimate interest is resolved.

Here: we mark the records and stop processing them beyond storage, and we tell you when the restriction is lifted.

Portability (art. 20)

Where processing is based on consent or on a contract and is carried out by automated means, you may receive your data in a structured, commonly used, machine-readable format and transmit it elsewhere.

Here: the export in the application is designed for this. It is a ZIP archive with an .optenant extension containing manifest.json and records.json, with a SHA-256 digest of the payload and an HMAC signature over the manifest so you can verify it has not been altered. Stored credentials are never included, by design, because an export is not a place to put access tokens. Note that GPTpostLLM has no import or restore path, so an export is a readable copy of your data rather than something that can be loaded back into another workspace here.

Objection (art. 21)

You may object at any time to processing based on legitimate interests, on grounds relating to your situation. We must then stop unless we show compelling legitimate grounds that override your interests, or the processing is needed for legal claims.

Here: we run no advertising, no profiling for marketing and no third-party analytics, so the classic object-to-marketing case does not arise. Direct marketing objection is absolute where it applies (art. 21 alin. (3)): there is no balancing and we must stop.

Automated decisions and profiling (art. 22)

You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you.

Here: we make no such decisions. GPTpostLLM does not score, rank, profile or automatically decide anything about an individual with legal or similarly significant effect. If that ever changes, this page and Privacy Policy will say so before it does.

Where processing relies on your consent, you may withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing before you withdrew.

Here: consent-based processing is limited. Disconnecting a social account withdraws the authorisation for us to publish to it, and it can be done in the application. Where a workspace administrator enabled an optional integration or an AI provider using the workspace's own credentials, turning it off is done in that workspace.


3. How to make a request

Write to contact@oraglegpt.org. That is the only address you need. Romanian or English, either is fine, and we answer in the language you write in.

Put "data protection request" in the subject line, and include:

  1. Which right you are exercising, in your own words. You do not need to cite an article and a request is not invalid because you cite the wrong one.
  2. The email address or account the request relates to. This is usually the single most useful piece of information, because it is what we search on.
  3. Enough to locate the data if you do not have an account with us: where you think your data came from, and the name of the company whose workspace it may be in.
  4. How you want the answer delivered.

A postal request works too, to TRIIVON S.R.L. at Bucharest, Sector 4, Sos. Giurgiului nr. 131, Bloc 1, Scara 2, Etaj 9, Apartament 65, postal code 040665, Romania, and a request made in a support conversation counts. It does not have to be on a form. We do not require you to use a template, create an account, or pay anything.


4. How we check that the request is really yours

We have to be sure we are not handing your data to somebody else, and art. 12 alin. (6) lets us ask for what is necessary to confirm who you are. It does not let us demand more than that, and we do not.

What we normally do: if you write from the email address on the account, that is usually enough on its own. If the request is a sensitive one, we may ask you to confirm it from within a signed-in session, or answer a question about the account that only the account holder would know, for example when it was created or what workspaces it belongs to.

What we do not do: we do not ask you to send a scan of an official document, a national identification number, a photograph of yourself, or a selfie holding a document. Collecting extra sensitive data in order to protect your data is self-defeating, and Legea nr. 190/2018 art. 4 places specific conditions on processing a national identification number in any event.

If we genuinely cannot identify you from the information you give, we will tell you what is missing and why, rather than refuse silently. If we still cannot identify you, art. 11 alin. (2) means arts. 15 to 20 may not apply, and we will say so and explain.


5. How long we take

One month from receipt of your request (art. 12 alin. (3)). In practice most requests are answered well inside that.

We may extend by up to two further months where the request is complex or where you have made a number of requests. If we do, we will tell you within the first month, and we will tell you the reason rather than just the new date.

If we do not act on your request, we will tell you within one month why not, and inform you that you may complain to the supervisory authority and seek a judicial remedy (art. 12 alin. (4)).

Since the Service sends no email of any kind, every answer you receive from us is written by a person from the company mailbox. That is slower than an automated system on a good day and considerably more useful on a bad one.


6. What it costs

Nothing. Information and action under arts. 15 to 22 are provided free of charge (art. 12 alin. (5)).

The only exception in the Regulation is a request that is manifestly unfounded or excessive, in particular because of its repetitive character. In that case we may charge a reasonable fee reflecting our administrative costs, or refuse to act. If we ever rely on that, we must demonstrate why the request is manifestly unfounded or excessive, we will explain our reasoning to you in writing, and you keep every route in section 8 to challenge it.


7. What we cannot do for you

This section exists because the honest answer to some requests is that we are the wrong party, and sending you round in a circle helps nobody.

We cannot act against a social platform on your behalf. If you want data deleted from Facebook, Instagram, Threads, TikTok or any other platform, or you want to know what one of them holds about you, you must go to that platform directly.

The reason is structural rather than a matter of policy. Every connector in GPTpostLLM is publish-only. The product cannot read comments, mentions, direct messages, replies or any inbox from any platform. It cannot fetch analytics or insights. It cannot like, repost, edit, delete or moderate anything. Our access to your social account extends to sending a post to it and recording whether that succeeded, and that is genuinely the whole of it. We could not retrieve your data from a platform for you even if you asked us to, because we hold no access that would let us. Each platform publishes its own data protection contact and its own request process, and that is the route that works.

We cannot overrule a business customer about data in their workspace. See section 1.

We cannot restore data after erasure. There is no import or restore path in GPTpostLLM, and erasure is meant to be final. Export first.


8. Complaining, and going to court

If you are not satisfied with how we have handled your personal data or your request, you have the following routes and you may use them whether or not you have complained to us first. We would prefer you to raise it with us at contact@oraglegpt.org, but nothing requires you to.

Complaint to the supervisory authority (art. 77). You may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement. The competent authority for TRIIVON S.R.L. is:

ItemDetail
AuthorityAutoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
AddressB-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, cod poștal 010336, București, România
Emailanspdcp@dataprotection.ro
Websitehttps://www.dataprotection.ro

The authority must inform you of the progress and outcome of your complaint, including the possibility of a judicial remedy under art. 78.

Judicial remedy against the authority (art. 78). You have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning you, and where the authority does not handle your complaint or does not inform you of its progress within three months.

Judicial remedy against us (art. 79). You have the right to an effective judicial remedy against a controller or processor, independently of any complaint to a supervisory authority. Proceedings may be brought before the courts of the Member State where we are established, or before the courts of the Member State where you have your habitual residence.

Compensation (art. 82). If you have suffered material or non-material damage as a result of an infringement, you have the right to receive compensation.

Consumer disputes that are not about personal data, for example about a purchase or the quality of the Service, follow a different route, which is set out in Consumer Rights and Dispute Resolution.


9. Where the rest of the detail is

For anything on this page, write to contact@oraglegpt.org.