Last updated: July 31, 2026
DOTUX SRL ("we") is the data controller for personal data processed through Scanly. Contact: contact@scanly.ro.
This policy complies with the EU GDPR and applicable Romanian data protection law.
Account data:
Document data:
Billing data:
Usage/technical data: login timestamps, IP address, basic error logs.
We do not collect data for advertising and do not sell personal data to third parties.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the core Service | Performance of a contract |
| Processing subscription payment | Performance of a contract |
| Essential emails (password reset) | Performance of a contract |
| Optional product update emails | Consent |
| Security, fraud prevention | Legitimate interest |
| Retaining certain tax/accounting records | Legal obligation |
We send document images to Google (Gemini API) for AI-based extraction. Google processes this data as our sub-processor under the Google APIs Terms of Service and its Data Processing Addendum. We use only the paid Gemini API tier, under which Google does not use submitted content to train or improve its models. Google may process this data on servers outside the European Economic Area (see section 8).
The sub-processors we use:
| Provider | What it processes | Processing location |
|---|---|---|
| Hostinger International Ltd. | Account data, the database, and uploaded documents | Frankfurt, Germany (EU) |
| Google Ireland Ltd. (Gemini API) | Document images submitted for automated extraction | Global, including outside the EEA |
| Stripe Payments Europe, Ltd. | Name, email, billing and payment data for subscriptions | Ireland (EU), with transfers to Stripe, Inc. (USA) |
| Resend, Inc. | Your email address, for transactional email delivery | USA |
We do not use your data to train AI models. Each document generates a single extraction request; we do not build training datasets from your documents.
Under GDPR, you have the right to:
To exercise these rights, contact contact@scanly.ro.
If we become aware of a data breach, we will notify affected users and the supervisory authority per GDPR (generally within 72 hours).
Your account data and documents are stored in the European Union (Frankfurt, Germany).
Some sub-processors do, however, process data outside the European Economic Area — in particular Google, for automated document extraction, Stripe, for payment processing, and Resend, for email delivery. For those transfers we rely on GDPR-recognized safeguards: the European Commission's Standard Contractual Clauses and, for certified US providers, the EU–US Data Privacy Framework (adequacy decision).
The Service is intended for adults managing an SRL or PFA. We do not knowingly collect data from individuals under 18.
The Service uses browser local storage for authentication and does not use third-party advertising cookies.
Material changes will be notified at least 14 days before taking effect.
Questions: contact@scanly.ro