IT Service Catalog
Privacy policy
Last updated: 21 August 2026 · Română
This document explains what personal data the IT Service Catalog application processes — on the web and in the Android and iOS versions — why it processes them, how long it keeps them, and what rights you have over them.
This application is an internal work tool. It is used with an account created by your organisation's administrator, to request IT services and follow the requests you have submitted. It is not intended for the general public and you cannot create an account in it yourself.
Who processes the data
The application is provided by [provider's legal name, registered office, company registration number] as a processor, on behalf of the organisation that granted you access and that is the controller of your data.
For questions about your data, write to [data protection contact address].
What data we process
The application processes only the data it needs in order to work.
| Category | What exactly | Why |
|---|---|---|
| Identity | Name, email address, internal user identifier and organisation identifier | So we know who you are, what you are entitled to see, and on whose behalf a request is recorded |
| Authentication | Username and password for classic sign-in; or the confirmation received from your organisation’s identity provider for federated sign-in | So we can let you in. The password is sent to the server for verification and is not stored in the application |
| Activity | The services you add to the cart, the beneficiary you name, the note attached to a request, and the history of requests you have submitted | So we can process what you asked for and so you can see where it stands |
| Preferences | The language you chose in the application | So the application opens in the same language next time |
What the application does NOT do
We list these explicitly, because their absence matters as much as the presence of everything else:
- it contains no behavioural analytics, tracking or advertising tools;
- it does not share data with third parties for marketing purposes;
- it does not access location, camera, microphone, contacts, calendar, files or the list of installed applications;
- it does not use advertising identifiers;
- it does not build profiles and does not make automated decisions about you.
What is stored on your device
The application stores two things locally, both in its own storage area:
- Your working session — the authentication token and the profile details shown in the interface. It is cleared when you close the application or the browser tab, and when you sign out.
- The language you chose — a single value, unrelated to your identity.
The application uses no tracking cookies and sets no cookies for other sites.
Who the data is shared with
The data reaches the OptimumDesk platform servers used by your organisation and stays there. The requests you submit become tickets visible to your organisation’s support team, who resolve them.
If your organisation uses federated sign-in, the identity exchange happens with its own identity provider — Active Directory, Entra or equivalent — under that organisation’s policies.
How long the data is kept
Requests and tickets are kept for as long as your organisation’s support activity and its legal archiving obligations require, that is [retention period set by the organisation]. Your working session disappears when you close the application.
How the data is protected
- all communication is encrypted, over HTTPS;
- access is granted only with an account created by your organisation’s administrator;
- each user sees only the data of the organisation they belong to;
- the session expires on its own and is renewed only while you are working.
Your rights
Under the General Data Protection Regulation you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability and to object.
Because the application is an internal tool, such requests go to the controller — the organisation that granted you access — through its usual channels, or to the contact address above. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), or with the supervisory authority in your own country.
Deleting your account and data
Your account is created and removed by your organisation’s administrator; it cannot be deleted from within the application. To have your account or the associated data deleted, contact that administrator or use the contact address above.
Children
The application is intended solely for employees and collaborators of client organisations. It is not directed at people under 16 and does not knowingly collect data about them.
Changes
If we change this policy, we update the date at the top of the page. We recommend checking it from time to time.