Skip to content
Romy

Privacy

Controller

Romy GmbH, Hohenzollernstraße 41, 80801 Munich, Germany

Email: info@getromy.com

This privacy policy applies to the website www.getromy.com. Use of the Romy product in your Microsoft environment is governed by separate privacy information and the data processing agreement concluded with your company.

Visiting the website

When you visit the website, technically necessary data transmitted by your browser is processed: IP address, date and time, requested address, browser type and operating system. This is required to deliver the website and keep it secure.

The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest is the secure and stable operation of the website. Technical logs are deleted automatically after 30 days.

Contact and demo requests

When you use the contact form, we process the details you provide (name, company, email address, number of employees and, optionally, your message) in order to respond to your request. The same applies when you email us. Form requests are delivered by email to our Microsoft 365 mailbox (for the provider, see the Hosting section).

The legal basis is Art. 6(1)(b) GDPR where your request is aimed at entering into a contract, and otherwise Art. 6(1)(f) GDPR. Our legitimate interest is responding to business enquiries. Providing the details is voluntary, but we cannot handle your request without them.

We delete your details once your request has been fully handled, unless statutory retention obligations apply.

No cookies, no tracking

We do not use cookies for analytics or advertising, nor any tracking or analytics services. Fonts are hosted locally; visiting the website does not open a connection to third-party servers such as Google.

If you switch between light and dark mode, your browser stores this choice locally (local storage). The information does not leave your device and only serves to keep the display you selected (Section 25(2) no. 2 TDDDG).

Hosting

The website is operated on Microsoft Azure in the Germany West Central region (Frankfurt am Main). The provider is Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland. A data processing agreement pursuant to Art. 28 GDPR is in place with Microsoft.

Data is stored in Germany. Access by Microsoft Corporation in the USA cannot be completely ruled out. Microsoft is certified under the EU-U.S. Data Privacy Framework, which is covered by an adequacy decision of the European Commission (Art. 45 GDPR); the EU Standard Contractual Clauses apply in addition.

Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). To exercise them, contact info@getromy.com.

You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.

Right to object

Where we process data on the basis of Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation (Art. 21 GDPR). We will then stop processing the data unless we can demonstrate compelling legitimate grounds or the processing serves the establishment, exercise or defence of legal claims.

Last updated

September 2026