Effective date: 8 September 2026

This notice explains how Krop System SRL handles personal data when you visit edfworkbench.com, download EDF Workbench, check for application updates, or contact the team through the Support form.

1. Who is responsible for the data?

Controller: Krop System SRL, Romania.

For a privacy request, use the Support form and select Privacy question. This route is also available to people who do not use EDF Workbench.

2. What this notice covers

This notice covers the public EDF Workbench website, installer and release-note downloads, the signed application-update feed, and the website Support form. It also describes the limited network information involved when EDF Workbench checks that feed.

Recording files and workspace information that you open locally are not collected through these website services. If your employer, research institution, healthcare organization, or another party provides a recording to you, that party may have its own privacy responsibilities and policies.

3. Information we process

Website, download, and update requests

When a browser or EDF Workbench requests a page, installer, release note, or update-feed file, the hosting infrastructure receives the information needed to deliver that request. Server logs may contain:

  • date and time of the request;
  • source IP address;
  • browser or HTTP user-agent information;
  • requested URL and response status; and
  • technical information needed to investigate delivery errors or abuse.

EDF Workbench does not add recording data, workspace data, credentials, telemetry, or an application-generated machine identifier to an update request. Automatic update checks are off by default and occur only if the user enables them; a manual check can be started from the application.

Support and feedback messages

If you use the Support form, we process your name, email address, selected category, message, and any EDF Workbench or Windows version you choose to provide. The message is emailed to the site administrator and is not stored as a WordPress form entry.

For abuse prevention, the form temporarily derives a keyed, non-reversible rate-limit value from the request IP address. The value is used only to limit repeated submissions and expires after approximately one minute.

Information you must not submit

Do not send patient recordings, patient or participant identifiers, recording names, signal samples, annotations, identifying screenshots, unnecessary full file paths, passwords, access tokens, or other confidential material. If you submit such information accidentally, contact us promptly through the Support form and request deletion.

4. Why we process information

We process the limited information described above for the following purposes:

  • deliver website pages, downloads, release notes, and signed update information;
  • protect the website and download infrastructure, prevent abuse, and investigate security events;
  • answer support, accessibility, compatibility, privacy, and product-feedback messages;
  • diagnose delivery or compatibility problems; and
  • establish, exercise, or defend legal claims and comply with applicable law.

Under the GDPR, these activities rely primarily on our legitimate interests in operating, securing, supporting, and improving EDF Workbench and its website. Where processing is necessary to meet a legal obligation, that obligation is the applicable legal basis. We do not use Support-form data for unrelated direct marketing.

5. Cookies, analytics, and tracking

The public website does not currently use advertising cookies, behavioral analytics, retargeting pixels, or browser fingerprinting. The Support form uses a security token to validate the submission; it is not used to track visitors. Authorized WordPress administrators may receive strictly necessary login and administration cookies when they sign in.

If non-essential analytics or another tracking technology is introduced later, this notice and any required consent controls will be updated before that technology is enabled.

6. Who may receive information

Access is limited to authorized Krop System SRL personnel and service providers that support website hosting, security, file delivery, and email delivery. These providers process information on our behalf or under their own legal obligations. We do not sell personal data or share it for targeted advertising.

Information may also be disclosed when reasonably necessary to comply with law, respond to a lawful authority, protect users or the service, or establish, exercise, or defend legal claims.

7. International transfers

Some infrastructure or email providers may process limited information outside Romania or the European Economic Area. Where GDPR transfer restrictions apply, we use an applicable adequacy decision or contractual and supplementary safeguards required by law. You may request further information through the privacy contact route above.

8. How long information is kept

  • Ordinary website, download, and update logs: normally no longer than 30 days.
  • Support and feedback correspondence: normally no longer than 12 months after the last substantive contact.
  • Support-form rate-limit value: approximately one minute.

Relevant records may be retained longer when necessary for an active security investigation, a legal obligation, or the establishment, exercise, or defense of legal claims. Provider backups may retain deleted information temporarily until the provider’s normal backup cycle expires.

9. Security

We use measures appropriate to the limited information processed, including HTTPS, access restrictions, server-side validation, a form security token, rate limiting, and signed application releases and update metadata. No internet service can guarantee absolute security, so please do not submit sensitive recording content through the website.

10. Your data-protection rights

Subject to the conditions and exceptions in applicable law, you may request access to, correction of, deletion of, or restriction of your personal data. You may object to processing based on legitimate interests and may request data portability where that right applies. If processing is based on consent, you may withdraw that consent without affecting earlier lawful processing.

We may need enough information to verify your identity before acting on a request. We will respond without undue delay and normally within one month, as required by the GDPR.

You may also lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), or with the competent authority in your country of residence or work.

11. Automated decisions

We do not use the information covered by this notice for automated decision-making or profiling that produces legal or similarly significant effects.

12. Changes to this notice

We may update this notice when the website, support process, update service, providers, or legal requirements change. The effective date at the top identifies the current version. Material changes will be highlighted on the website when appropriate.

13. Contact

Use the EDF Workbench Support form and select Privacy question. Include only the information needed to identify and answer your request.