Privacy Policy
Last updated: 21 September 2026
This Privacy Policy explains how AITEST S.R.L. ("MacDuty", "we", "us"), registration number J2024035731001, tax identification number 50782124, registered at Strada Constanței nr. 15, Bloc E1, Sc. D, Et. 3, Ap. 59, Năvodari, Constanța County, Romania, collects and uses personal data when you visit our website or use our services. We are the data controller for the processing described here.
Contact for privacy matters: [email protected]
1. What we collect
When you order or hold an account: your name, email address, billing address, company name and VAT identification number where applicable, and your account credentials. Payment card details are collected and processed directly by our payment provider; we never receive or store your full card number.
When you use the service: the IP addresses and network identifiers assigned to you, connection and traffic metadata (volumes, port statistics, timestamps), power and provisioning events, and console access sessions. We use this to operate the service, to bill correctly, and to investigate abuse.
When you contact support: the content of your messages, tickets and any information you choose to share with us.
When you use the contact form: the name, email address and message you type, and a bot check by Cloudflare Turnstile, which sees your IP address and how the page behaved in your browser. It sets no advertising cookie and does not track you across sites; it is what keeps the form usable, so it runs without asking, on our legitimate interest in not being flooded (Art. 6(1)(f)).
When you visit our website: server logs including IP address, browser type, and pages requested, and, with your consent where it is required, measurement data collected through Google Analytics.
Fraud prevention: our payment provider may carry out risk checks on orders and share the outcome with us.
Where your order came from: if you reached us through a link carrying campaign parameters (UTM values) or an advertising click identifier, we keep those values in a first-party cookie for 90 days and record them on your order, together with the first page you visited and the site that sent you. This is our own record of what led to the contract; it is not used to profile you and does not depend on your cookie choice.
2. What we do not have access to
We do not access the contents of your Mac, your files, your credentials, or your workloads. You hold administrative control of the machine. Our staff will only access your Mac where you ask us to for support purposes, where it is strictly necessary to maintain or restore the service, or where we are required to by law or a competent authority. Where we access it for support, we record that access and it appears in your ticket history.
3. Why we process it, and on what legal basis
- To provide the service you ordered, to provision your Mac, and to give you support, performance of a contract (Art. 6(1)(b) GDPR).
- To take payment, issue invoices, and keep accounting records, contract and legal obligation (Art. 6(1)(b) and (c)).
- To keep the network secure, prevent fraud and abuse, and protect our IP reputation and other customers, legitimate interests (Art. 6(1)(f)).
- To respond to lawful requests from authorities, legal obligation (Art. 6(1)(c)).
- To send you service notices such as maintenance, incidents, renewals and payment issues, contract. These are not marketing and you cannot opt out of them while you hold an account.
- To send you occasional product news, consent (Art. 6(1)(a)), which you may withdraw at any time.
3.5. Cookies and consent
The site needs a small amount of storage to work at all: your theme, your currency, your session when you are signed in, the security checks our payment provider runs, and, for 90 days, the campaign link that brought you (so we can record on your order what led to it). That storage is strictly necessary and is not subject to consent.
Beyond that we use Google Analytics. In the European Economic Area, the United Kingdom and Switzerland nothing of that kind is loaded until you choose: the first time you visit, a bar asks, and refusing is one click, the same size as accepting. Elsewhere it loads unless you turn it off.
You can change your choice at any time with Cookie settings, at the foot of every page. Your choice is stored in your own browser, for a year, and is never sent to us.
With your consent, we report to Google what was bought (an order number, the product and the net amount, never your name, email address, company, address or IP address) so that we can measure which pages and campaigns lead to orders and, if we advertise, so that Google Ads can count them. Google acts as our processor for this. Renewals and refunds of an order are reported the same way, and only when the order itself was; an order placed while consent was refused is never reported, then or later.
4. How long we keep it
- Account and contact data: for the life of your account and for 3 years afterwards.
- Invoices and accounting records: 10 years, as required by Romanian law.
- Network and connection logs: 90 days, unless retained longer for an ongoing abuse or security investigation, or where required by law.
- Support correspondence: 3 years.
- Data on your Mac: erased on termination, in accordance with the retention periods set out in our Terms of Service. Erasure is secure and irreversible.
5. Who we share it with
We share personal data only with processors and partners who need it to deliver the service:
- our payment provider, for payments, invoicing and fraud prevention;
- our email delivery provider, for transactional messages;
- our hosting, monitoring, bot-protection and analytics providers;
- our accountant and, where necessary, our legal advisers;
- competent authorities, where we are legally required to disclose.
Each processor is bound by a data processing agreement. We do not sell personal data and we do not share it for advertising purposes.
6. Where your data is
Our facility, our Macs, and any snapshots taken of them are located in Romania, within the European Union. Where a processor operates outside the EU or EEA, the transfer is covered by an adequacy decision of the European Commission or by Standard Contractual Clauses. Details of the processors we use are available on request.
7. When we act as your processor
If you process personal data on your Mac, you are the controller of that data and we act as your processor in respect of the hosting infrastructure. A data processing agreement under Article 28 GDPR is available on request and, once signed, governs that processing, including our obligations on security, sub-processors, and assistance with data subject requests.
8. Your rights
Under the GDPR you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to receive your data in a portable format, and to withdraw consent where processing is based on it. Where you object to processing based on our legitimate interests, we will stop unless we have compelling grounds that override your interests.
To exercise any of these rights, write to [email protected]. We respond within one month. We may ask you to confirm your identity first.
If you believe we have handled your data unlawfully, you may complain to the Romanian supervisory authority, ANSPDCP (www.dataprotection.ro), or to the authority in your country of residence.
9. Security
We apply appropriate technical and organisational measures, including physical access control to our facility, network segmentation between customers, encrypted administrative access, restricted internal access on a need-to-know basis, and logging of administrative actions. Your Mac is dedicated to you and is not shared with other customers. Security of the operating system and of anything you install on the Mac remains your responsibility.
If a personal data breach occurs that is likely to result in a risk to your rights, we notify the supervisory authority within 72 hours and inform you without undue delay where the risk is high.
10. Automated decision-making
We do not make decisions with legal or similarly significant effects about you by automated means alone. Automated fraud screening may flag an order for manual review; a person makes the final decision, and you may contact us to contest the outcome.
11. Children
Our services are directed at businesses and professionals and are not intended for anyone under 16. We do not knowingly collect data from children.
12. Changes
We may update this policy. Material changes will be notified by email at least 15 days before they take effect, and the date at the top of this page always reflects the current version.