IT Service Catalog

Privacy policy

Last updated: 21 August 2026 · Română

This document explains what personal data the IT Service Catalog application processes — on the web and in the Android and iOS versions — why it processes them, how long it keeps them, and what rights you have over them.

This application is an internal work tool. It is used with an account created by your organisation's administrator, to request IT services and follow the requests you have submitted. It is not intended for the general public and you cannot create an account in it yourself.

Who processes the data

The application is provided by [provider's legal name, registered office, company registration number] as a processor, on behalf of the organisation that granted you access and that is the controller of your data.

For questions about your data, write to [data protection contact address].

What data we process

The application processes only the data it needs in order to work.

Category What exactly Why
Identity Name, email address, internal user identifier and organisation identifier So we know who you are, what you are entitled to see, and on whose behalf a request is recorded
Authentication Username and password for classic sign-in; or the confirmation received from your organisation’s identity provider for federated sign-in So we can let you in. The password is sent to the server for verification and is not stored in the application
Activity The services you add to the cart, the beneficiary you name, the note attached to a request, and the history of requests you have submitted So we can process what you asked for and so you can see where it stands
Preferences The language you chose in the application So the application opens in the same language next time

What the application does NOT do

We list these explicitly, because their absence matters as much as the presence of everything else:

What is stored on your device

The application stores two things locally, both in its own storage area:

The application uses no tracking cookies and sets no cookies for other sites.

Who the data is shared with

The data reaches the OptimumDesk platform servers used by your organisation and stays there. The requests you submit become tickets visible to your organisation’s support team, who resolve them.

If your organisation uses federated sign-in, the identity exchange happens with its own identity provider — Active Directory, Entra or equivalent — under that organisation’s policies.

How long the data is kept

Requests and tickets are kept for as long as your organisation’s support activity and its legal archiving obligations require, that is [retention period set by the organisation]. Your working session disappears when you close the application.

How the data is protected

Your rights

Under the General Data Protection Regulation you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability and to object.

Because the application is an internal tool, such requests go to the controller — the organisation that granted you access — through its usual channels, or to the contact address above. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), or with the supervisory authority in your own country.

Deleting your account and data

Your account is created and removed by your organisation’s administrator; it cannot be deleted from within the application. To have your account or the associated data deleted, contact that administrator or use the contact address above.

Children

The application is intended solely for employees and collaborators of client organisations. It is not directed at people under 16 and does not knowingly collect data about them.

Changes

If we change this policy, we update the date at the top of the page. We recommend checking it from time to time.