Skip to content
SkyRosterBook a discovery call

Legal · 23 September 2026

Privacy notice

This notice covers the public SkyRoster website and enquiries to JLG Consulting. Customer rostering data is governed separately by the customer agreement and data processing agreement.

Who is responsible

J.L.G. Consulting S.R.L., Romania, is the controller for this website's enquiry handling. Contact address: Str. Iuliu Maniu 7, Z Wing, 3rd floor, 061072, Bucharest, Sector 6, Romania. CUI: 15732578; VAT: RO15732578.

For privacy requests, write to contact@skyroster.com with “Privacy” in the subject, or call +40 21 315 64 39. This is the company contact; it is not a claim that a statutory data protection officer has been appointed.

Information, purposes and legal bases

Enquiries and offer requests. We process your contact details, organisation, country, sector, message and any offer configuration you submit so that we can answer you, arrange a discussion and prepare an offer. Email is needed to reply; the form identifies required fields. Optional fields help us understand your request. Do not send employee rosters, health information, credentials or other confidential operational data through these forms; we can arrange a suitable transfer after agreeing the purpose and safeguards.

The proposed legal basis is our legitimate interest in responding to business enquiries and managing prospective customer relationships. Where you personally request steps towards a contract, those steps may instead rely on Article 6(1)(b) GDPR. The company reviewer must confirm the applicable basis and legitimate-interest assessment before activation. Sending an enquiry does not subscribe you to a newsletter.

Security and delivery. The website and its providers process technical request information, such as IP address, browser information, timestamps, security-verification tokens and delivery status, to operate the site, prevent abuse and investigate faults. The proposed basis is the legitimate interest in providing and protecting the service, with collection and retention limited to that purpose.

Local tools and preferences. Theme preferences and saved self-check or matcher selections are held in your browser. The offer builder stores configuration in its URL; copied links can reveal quantities and commercial selections to anyone receiving them. Browser tools do not need your name to calculate a result. The storage and cookies notice explains these features and how to reset them.

Booking. Choosing “Book a discovery call” opens Microsoft Bookings. Details you enter there are processed for scheduling under the information shown by that service. It is separate from submitting a website form.

Who receives information

Authorised JLG Consulting staff receive enquiries. The implementation uses Microsoft Azure for hosting, Notion for enquiry records, Twilio SendGrid for notification email and Cloudflare Turnstile for abuse prevention. Microsoft Bookings handles appointment requests when you choose it. Optional Cloudflare Web Analytics is enabled only when configured; current storage details are described in the cookies notice.

Before launch, the company must verify the actual provider accounts, processing agreements, retention settings and data locations, including any subprocessors or remote access outside the EEA. Where transfers outside the EEA occur, an applicable adequacy decision or appropriate safeguards, such as approved standard contractual clauses and any necessary supplementary measures, must cover them. A copy or explanation of applicable safeguards can be requested from our privacy contact. EU website hosting alone does not establish that every provider processes data only in the EU.

We may disclose relevant information to professional advisers or authorities where required by law or necessary to establish, exercise or defend legal claims. Access should be limited to the information needed for that purpose. This website does not sell enquiry information or use it for automated decisions producing legal or similarly significant effects.

Retention and your rights

Retention proposal for approval: remove inactive sales enquiries 24 months after the last meaningful interaction, unless an ongoing procurement process or legal claim justifies longer retention. Keep routine website security logs for 30 days, with specific incident evidence retained only as needed to investigate and resolve the incident. Customer contracts, invoices and legally required records follow the applicable statutory retention schedule. Provider logs and backups must be checked against this schedule before the final notice is approved; these periods are proposed controls, not a claim that automatic deletion already operates.

You may request access, correction, erasure or restriction of processing, and object to processing based on legitimate interests. Where the statutory conditions apply, you may request data portability. If a separate activity relies on consent, you may withdraw it at any time without affecting earlier lawful processing. These rights are subject to applicable conditions and legal retention duties.

Send a request to our privacy contact. We may request proportionate identity verification, and normally respond within one month; lawful extensions must be explained. You can complain to Romania's ANSPDCP or your competent supervisory authority. Contacting us first is optional.

Changes will be dated on this page. The legal framework is the General Data Protection Regulation; this draft must be matched to the company's actual processing records before publication.