GraniteRelayForge
Legal Framework

Regulatory Alignment & Protocol Compliance

All policies apply to services delivered by GraniteRelayForge, registered at 800366, Str. Ionel Fernic nr. 29, bl. A7, sc. 3, et. 2, ap. 49, Galati, Romania.

Privacy Policy

Effective Date: 1 January 2026

Data Controller: GraniteRelayForge, 800366, Str. Ionel Fernic nr. 29, bl. A7, sc. 3, et. 2, ap. 49, Galati, Romania. Email: [email protected].

1. Scope and Definitions

This Privacy Policy governs the collection, processing, and storage of personal data by GraniteRelayForge ("Controller", "we", "us") in connection with the provision of digital engineering, software development, and consulting services. Terms used herein align with Regulation (EU) 2016/679 (General Data Protection Regulation — "GDPR").

"Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"). "Processing" means any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.

2. Categories of Personal Data Collected

We collect and process the following categories of personal data:

  • Identity Data: Full name, job title, company affiliation provided through contact forms or direct communication.
  • Contact Data: Email address, telephone number, postal address as provided voluntarily by the Data Subject.
  • Technical Data: IP address, browser type and version, operating system, referral URLs, and page interaction data collected automatically through standard web server logging.
  • Communication Data: Content of correspondence, project briefs, and feedback submitted through our contact channels.

3. Legal Bases for Processing

We process personal data exclusively under the following legal bases as defined in Article 6(1) GDPR:

  • Consent (Art. 6(1)(a)): Where you have given explicit consent for specific processing purposes, such as receiving marketing communications.
  • Contractual Necessity (Art. 6(1)(b)): Processing necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract.
  • Legitimate Interest (Art. 6(1)(f)): Processing necessary for our legitimate interests in operating and improving our services, provided such interests are not overridden by your fundamental rights.

4. Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Contact form submissions are retained for a maximum of 24 months from the date of submission. Contract-related data is retained for the duration of the contractual relationship plus 6 years in compliance with Romanian commercial record-keeping obligations.

5. Data Sharing and Transfers

We do not sell, rent, or trade personal data to third parties. Personal data may be shared with:

  • Technical service providers acting as processors (e.g., hosting infrastructure, email delivery services) who are bound by data processing agreements under Art. 28 GDPR.
  • Public authorities where disclosure is required by law or binding regulatory order.

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission or participation in adequacy decisions under Art. 45 GDPR.

6. Data Subject Rights

Under the GDPR, you have the following rights:

  • Right of Access (Art. 15): Obtain confirmation of whether we process your personal data and request a copy of such data.
  • Right to Rectification (Art. 16): Request correction of inaccurate personal data or completion of incomplete data.
  • Right to Erasure (Art. 17): Request deletion of your personal data where processing is no longer necessary or consent is withdrawn.
  • Right to Restriction (Art. 18): Request limitation of processing in specific circumstances.
  • Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
  • Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days of receipt.

7. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These measures include, but are not limited to: TLS encryption for data in transit, encrypted storage for data at rest, access controls with principle of least privilege, and regular security assessments.

8. Supervisory Authority

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the relevant supervisory authority. In Romania, the competent authority is the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucuresti, Romania.

Cookies Policy

Effective Date: 1 January 2026

Controller: GraniteRelayForge, 800366, Str. Ionel Fernic nr. 29, bl. A7, sc. 3, et. 2, ap. 49, Galati, Romania.

1. What Are Cookies

Cookies are small text files placed on your device by websites you visit. They serve to remember your preferences, analyse site performance, and support functional operations. Under the ePrivacy Directive (2002/58/EC) and GDPR, we are required to inform you of our cookie usage and obtain your consent for non-essential cookies.

2. Categories of Cookies We Use

  • Strictly Necessary Cookies: Essential for the operation of our website. These enable core functionality such as page navigation, session persistence, and security features. They cannot be disabled.
  • Functional Cookies: Remember your preferences (e.g., cookie consent choices) to provide a personalised experience. These are set only with your explicit consent.
  • Analytics Cookies: Collect anonymised information about how visitors interact with our website, including pages visited, time spent, and navigation patterns. These are set only with your explicit consent.

3. Specific Cookies Deployed

Cookie Purpose Duration Type
grf_cookie_consent Stores your cookie consent preference 12 months Strictly Necessary
session Maintains session state for server functionality 24 hours Strictly Necessary

4. Managing Cookie Preferences

When you first visit our website, a cookie consent banner allows you to accept or decline non-essential cookies. Your choice is stored locally in your browser and can be modified at any time by clearing your browser's local storage for this domain and revisiting the site.

You may also control cookies through your browser settings. Most browsers allow you to block or delete cookies. Note that disabling strictly necessary cookies may impair website functionality.

5. Third-Party Cookies

We do not currently deploy third-party tracking cookies. Should this policy change, we will update this document and re-request consent where required under the ePrivacy Directive.

Refund Policy

Effective Date: 1 January 2026

Provider: GraniteRelayForge, 800366, Str. Ionel Fernic nr. 29, bl. A7, sc. 3, et. 2, ap. 49, Galati, Romania.

1. General Principles

GraniteRelayForge provides professional digital engineering and consulting services. Due to the bespoke and service-based nature of our offerings, refunds are evaluated on a case-by-case basis in accordance with applicable Romanian and EU consumer protection legislation.

2. Milestone-Based Deliverables

For projects structured around defined milestones or sprint cycles, payment is tied to the completion and acceptance of each deliverable. If a deliverable materially fails to meet the specifications agreed in the project scope document, the client may request a review and potential partial refund for the affected milestone, provided:

  • The deficiency is documented in writing within 14 calendar days of deliverable receipt.
  • A reasonable remediation period of 21 calendar days is offered before any refund is processed.
  • The refund amount is proportionate to the scope of the identified deficiency relative to the total milestone value.

3. Pre-Service Consultations and Audits

Fees for scoping blueprints, system audits, and heuristic reviews are non-refundable once the service has been initiated, as these involve immediate resource allocation and intellectual output. If cancellation is requested before work commences, a full refund will be issued within 14 business days.

4. Cancellation by Client

Clients may cancel an engagement at any time by providing written notice. Refunds for prepaid services will be calculated as follows:

  • Before work commences: 100% refund of prepaid amounts.
  • During active sprint/work phase: Refund limited to the pro-rata portion of work not yet completed, minus a 15% administrative fee.
  • After delivery and acceptance: No refund applicable.

5. Cancellation by Provider

GraniteRelayForge reserves the right to terminate an engagement if the client materially breaches the terms of service, fails to provide required access or information, or engages in conduct that prevents service delivery. In such cases, refunds are calculated based on work completed and documented.

6. Refund Processing

Approved refunds are processed within 14 business days via the original payment method. Clients will receive written confirmation of the refund amount and processing timeline. Any currency conversion fees or banking charges incurred during the refund process are the responsibility of the client.

7. Dispute Resolution

In the event of a refund dispute, the parties agree to attempt good-faith resolution through direct communication. If no resolution is reached within 30 days, either party may refer the matter to the competent courts in Galati, Romania, or to the European Online Dispute Resolution platform (https://ec.europa.eu/odr).

Terms of Service

Effective Date: 1 January 2026

Provider: GraniteRelayForge, 800366, Str. Ionel Fernic nr. 29, bl. A7, sc. 3, et. 2, ap. 49, Galati, Romania. Email: [email protected]. Phone: +40 744 839 251.

1. Acceptance of Terms

By engaging GraniteRelayForge for digital engineering, software development, or consulting services ("Services"), you ("Client") agree to be bound by these Terms of Service. These terms constitute a legally binding agreement between the Client and GraniteRelayForge ("Provider"). If you do not agree to these terms, please do not engage our services.

2. Scope of Services

The specific scope, deliverables, timeline, and pricing for each engagement are defined in a separate Statement of Work ("SOW") or project proposal mutually agreed upon by both parties. These Terms of Service apply universally to all engagements unless explicitly superseded by the SOW.

3. Client Obligations

The Client agrees to:

  • Provide timely access to necessary systems, credentials, documentation, and personnel required for service delivery.
  • Designate a primary point of contact with decision-making authority for the engagement.
  • Review and provide feedback on deliverables within the timeframes specified in the SOW.
  • Ensure that all information provided to the Provider is accurate and does not infringe upon third-party rights.

4. Payment Terms

Unless otherwise specified in the SOW:

  • Invoices are issued upon completion of agreed milestones or at the commencement of each billing period.
  • Payment is due within 14 calendar days of invoice date.
  • Late payments incur a statutory interest rate of 8 percentage points above the ECB base rate per annum, as permitted under Directive 2011/7/EU on late payment in commercial transactions.
  • All prices are stated in Euros (€) and are exclusive of applicable VAT unless explicitly stated otherwise.

5. Intellectual Property

Upon full payment of all invoiced amounts, the Client receives a perpetual, non-exclusive, irrevocable license to use all deliverables produced under the engagement for their internal business purposes. The Provider retains ownership of pre-existing intellectual property, general methodologies, frameworks, and know-how developed independently of the specific engagement.

The Provider may, with the Client's prior written consent, use anonymised case studies, screenshots, and project summaries for portfolio and marketing purposes.

6. Confidentiality

Both parties agree to maintain the confidentiality of all proprietary information disclosed during the engagement. This obligation survives the termination of the agreement for a period of 3 years. Confidential information shall not include data that: (a) is or becomes publicly available through no fault of the receiving party; (b) was known to the receiving party prior to disclosure; (c) is independently developed without reference to the confidential information; or (d) is required to be disclosed by law or regulatory authority.

7. Limitation of Liability

To the maximum extent permitted by applicable law, GraniteRelayForge's total aggregate liability arising out of or in connection with any engagement shall not exceed the total fees paid by the Client under the relevant SOW during the 12-month period preceding the claim. In no event shall the Provider be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, business opportunities, or goodwill.

8. Data Processing

Where the Provider processes personal data on behalf of the Client in the course of service delivery, the parties shall enter into a separate Data Processing Agreement ("DPA") in compliance with Article 28 GDPR. The Provider implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as outlined in the Privacy Policy.

9. Termination

Either party may terminate an engagement with 30 calendar days' written notice. In the event of termination:

  • The Client shall pay for all work completed and accepted up to the termination date.
  • The Provider shall deliver all completed work products and reasonably cooperate in the transition of services.
  • Sections on Intellectual Property, Confidentiality, Limitation of Liability, and Governing Law survive termination.

10. Force Majeure

Neither party shall be liable for delays or failures in performance resulting from causes beyond reasonable control, including but not limited to: natural disasters, war, terrorism, pandemics, government actions, power failures, or internet infrastructure disruptions. The affected party shall promptly notify the other party and use reasonable efforts to mitigate the impact.

11. Governing Law and Jurisdiction

These Terms of Service are governed by the laws of Romania and the applicable regulations of the European Union. Any disputes arising from or in connection with these terms shall be submitted to the exclusive jurisdiction of the competent courts in Galati, Romania, without prejudice to the Client's right to bring proceedings in their country of residence under applicable consumer protection legislation.

12. Amendments

GraniteRelayForge reserves the right to amend these Terms of Service at any time. Material changes will be communicated to active clients via email at least 30 days before taking effect. Continued engagement after the effective date of amendments constitutes acceptance of the revised terms.