TOLLRO
PRIVACY POLICY
TollRo Application
1. Introduction and Who We Are
This Privacy Policy describes how personal data collected from users of the TollRo mobile application (hereinafter referred to as "TollRo" or the "application"), developed for mobile operating systems, is processed, used, stored, and protected.The personal data controller is the National Company for Road Infrastructure Management S.A. (C.N.A.I.R. S.A.), headquartered at B-dul Dinicu Golescu no. 38, Sector 1, Bucharest, registered with the Trade Register under number J40/552/2004, Sole Registration Code RO 16054368.
Data processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR), Law no. 190/2018, and Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, as amended and supplemented.
2. Data We Collect
2.1. Account and Billing Data
When creating a user account and placing orders, we collect:
- Email address and password (passwords are stored in encrypted/hashed form);
- Vehicle identification data: registration plate number, country of registration, Vehicle Identification Number (VIN / chassis number), registration certificate number;
- Necessary billing details (full name/company name, Tax ID (CUI/CNP), address), based on the information provided by the user.
For bank card payments, processing is performed by CNAIR's authorized payment processor. TollRo retains only a minimal transaction dataset (internal transaction ID, first and last digits of the card number, transaction amount, and payment status). Full card numbers and security codes (CVV) are never stored by TollRo.
2.2. Location Data (GPS)
The TollRo application collects precise location data (GPS) from the mobile device exclusively while the route ticket feature is actively in use. Continuous collection occurs only during an active route, as the toll is calculated in real-time (live) based on the actual distance traveled. Outside of an active route, the application does not collect location data.
Location data is used for:
- Real-time calculation of the route ticket fee based on distance traveled;
- Determining the vehicle's position relative to the national road network and toll points (Fetești–Cernavodă bridges);
- Verifying and confirming passage/usage of toll infrastructure;
- Audit functionality — route-related location data is stored, queried, and viewed within the system's audit module.
2.3. Technical Data
To ensure application operation and security, we may collect device identifiers, operating system version, access logs, and application usage data.
3. Legal Basis for Processing
We process personal data based on the following legal grounds (Art. 6 GDPR):
- Performance of a contract — for issuing the rovinieta/toll (peaj), processing payments, and calculating real-time route ticket fees based on distance traveled (location collection during active routes);
- Legal obligation — for issuing tax documents and monitoring infrastructure usage;
- Consent — for email notifications regarding rovinieta expiration;
- Legitimate interest — for system security and fraud prevention.
4. Retention Period
Personal data is retained only for the period necessary to fulfill the purposes for which it was collected and in compliance with legal archiving obligations. As a general rule:
- Data related to rovinietas, tolls (peaj), and route tickets is retained until expiration, plus an additional period of 6 years, in accordance with applicable tax and statutory archiving obligations;
- Billing data is retained for the period mandated by tax legislation (6 years);
- Location data and audit module records are stored for the period strictly necessary to monitor toll infrastructure usage;
- In the event of litigation, relevant data may be retained until final resolution.
5. How We Use Data
Provided data is used exclusively for: paying usage and toll fees, issuing rovinietas and tolls (peaj), verifying rovinieta validity, checking passages at the Fetești–Cernavodă bridges, downloading order documents, sending expiration notifications, and—for location data—determining vehicle position, confirming passages, and audit functions.
We do not sell or rent personal data to third parties for marketing purposes.
6. Disclosure to Third Parties
Data may be disclosed to: CNAIR's authorized payment processor (for processing payment transactions).
7. Data Subject Rights
Under the GDPR, you have the right to access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, objection, and the right to withdraw consent at any time (without affecting the lawfulness of processing prior to withdrawal).
To exercise these rights, contact us at: roviniete@andnet.ro. You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP).
8. Data Security
We implement appropriate technical and organizational measures to safeguard data against unauthorized access, loss, or disclosure. CNAIR S.A. will never request account passwords via email or phone.
9. Policy Changes
We reserve the right to amend this Privacy Policy. Any changes become effective upon publication within the application and/or on the website. Continued use of the application constitutes acceptance of the updated version.
10. Contact
C.N.A.I.R. S.A. — B-dul Dinicu Golescu no. 38, Sector 1, Bucharest.
- Email: roviniete@andnet.ro / peaj@andnet.ro
- Phone: 021.264.33.44
