Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains what personal data S.C. Metis IT&Software S.R.L. ("we", "us") processes when you use NameOnTop (the "Service"), why, and what rights you have. We act as data controller for the data described here.
1. What data we process
The Service is built around data that is predominantly PUBLIC company data: brand names, website domains, business categories, markets and languages, competitor names — information about companies, not private individuals.
About you as a user we process: your email address (sign-in, notifications), your UI language, workspace membership and role, and technical data needed to run and secure the Service (IP address for rate limiting and abuse prevention, first-party usage events such as pages viewed and scans run). We do not use third-party advertising cookies.
Payments are processed by Stripe; we receive subscription status and invoicing details but never store your full card number.
2. Stored AI answers
When a scan runs, we store the answers returned by third-party AI models. These transcripts contain publicly available information generated by third parties about companies and markets. We do not guarantee the accuracy of statements generated by third-party AI models — we measure and report them.
Stored AI answers are retained for 12 months and then deleted automatically.
3. Why we process it (legal bases)
We process data to perform our contract with you (running scans, showing reports, billing), on the basis of our legitimate interest in securing and improving the Service (rate limiting, abuse prevention, aggregated product analytics), and to comply with legal obligations (accounting, tax). Where consent is required — for example for optional communications — we ask for it separately and you can withdraw it at any time.
4. Subprocessors
We use the following subprocessors to operate the Service:
- Supabase — database and file storage (EU region)
- Vercel — application hosting and delivery
- OpenAI — AI model queries (scan answers)
- Anthropic — AI model queries (scan answers and analysis)
- Perplexity — AI model queries (scan answers)
- Stripe — payments, invoicing and VAT
- ZeptoMail (Zoho) — transactional email
- Cloudflare — bot protection (Turnstile)
- Inngest — background job orchestration
5. International transfers
Some subprocessors process data outside the European Economic Area (for example US-based AI providers). Where that happens, transfers rely on adequacy decisions such as the EU-US Data Privacy Framework or on Standard Contractual Clauses.
6. Retention and account deletion
If you delete your account, your brands, prompts and reports are deleted within 30 days. Stored AI answers are deleted after at most 12 months regardless of account status. Billing records are kept for the period required by Romanian accounting law. Aggregated, non-identifying statistics may be retained.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing based on legitimate interest;
- receive your data in a portable format;
- lodge a complaint with a supervisory authority — in Romania, ANSPDCP (dataprotection.ro).
8. Cookies
The Service uses only functional cookies: a session cookie (vz_session) to keep you signed in, a locale cookie (NEXT_LOCALE) to remember your language, and Cloudflare Turnstile for bot protection on public forms. Our usage analytics are first-party and are not shared with advertising networks.
9. Data processing agreement (agencies)
If you use the Agency plan and process client data through the Service, we act as your processor for that data. A standard data processing agreement template is available for download below; the signed English version prevails over any translation.
10. Changes to this policy
We will update this policy when our processing changes, and notify you of material changes by email or in the app. The English version is the authoritative version.
11. Contact
For any privacy request (access, deletion, questions), contact us at the details in the company block below. We answer within 30 days as required by the GDPR.
Download the DPA template (PDF)
Company details
S.C. Metis IT&Software S.R.L.
CUI RO46338515 · Reg. Com. J2022000382407
Str. Râmnicu Vâlcea nr. 8, cam. 1, et. 8, ap. 809, Sector 3, București
technical.med.dgc@gmail.com · (0730) 740 522