Data Usage Policy
Full GDPR compliance. Complete transparency and maximum protection for your personal data.
1. Identity of the Data Controller
In accordance with Regulation (EU) 2016/679 (GDPR), the controller of personal data is FIXLY TECHNOLOGY SRL, headquartered in Romania. This policy details how we process your personal data in compliance with applicable European and Romanian legislation.
- Controller name: FIXLY TECHNOLOGY SRL
- Tax ID (CUI): 47040460
- Trade Register No.: J2022000789071
- EUID: ROONRC.J2022000789071
- Registered office: Romania
- GDPR contact email: contact@codat.ro
- Data Protection Officer (DPO): We have not appointed a DPO, as our processing activities do not meet the criteria of Art. 37(1) GDPR (we are not a public authority, we do not carry out large-scale systematic monitoring, and we do not extensively process special categories of data).
- Supervisory authority: ANSPDCP (Romanian National Supervisory Authority for Personal Data Processing)
2. Categories of Personal Data Processed
We process the following categories of personal data in accordance with GDPR principles:
- Identification data: First name, last name, email address
- Authentication data: Password (securely stored via hashing)
- Contact data: Messages sent through the contact form
- Usage data: Verified IMEI codes, verification history
- Technical data: IP address, browser type, operating system
- Payment data: Information processed exclusively by Viva.com (we do not store card data)
- Preference data: Theme settings (light/dark mode)
3. Purposes and Legal Bases for Processing
We process your data based on the following legal bases under GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR): To provide IMEI verification services
- Consent (Art. 6(1)(a) GDPR): For non-essential cookies and marketing communications
- Legitimate interest (Art. 6(1)(f) GDPR): For platform security and service improvement
- Legal obligation (Art. 6(1)(c) GDPR): To comply with tax and accounting obligations
4. Your Rights Under GDPR
You have the following fundamental rights regarding your personal data:
- Right to be informed (Art. 13-14 GDPR): To know what data we collect and why
- Right of access (Art. 15 GDPR): To obtain a copy of the data processed
- Right to rectification (Art. 16 GDPR): To correct inaccurate data
- Right to erasure (Art. 17 GDPR): The right to be forgotten
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR)
- Right not to be subject to automated decision-making (Art. 22 GDPR)
- Right to lodge a complaint with ANSPDCP
5. Security and Protection Measures
We implement advanced technical and organizational measures to protect your data:
- SSL/TLS encryption for all data transmissions
- Secure password hashing (bcrypt)
- Continuous security monitoring
- Regular, secure backups
- Restricted data access on a need-to-know basis
- Regular security audits
- Staff training on data protection
6. Sharing Data with Third Parties
We do not sell your data. We only share data with essential service providers:
- IMEI database providers: To carry out verifications
- Viva.com: Payment processor (we have no access to card data)
- Vercel: Hosting and infrastructure
- Email services: For essential communications
- All providers are bound by strict confidentiality agreements
7. International Data Transfers
Some data may be transferred outside the EEA under the following conditions:
- European Commission adequacy decisions
- EU-approved standard contractual clauses (SCC)
- European Commission adequacy decisions and approved transfer mechanisms (e.g. the EU-U.S. Data Privacy Framework where applicable, standard contractual clauses)
- Explicit user consent
- All transfers comply with GDPR safeguards
8. Data Retention Period
We keep data only for as long as necessary:
- Account data: Until account deletion or 3 years of inactivity
- Verifications with an account: 2 years for verification history
- Verifications without an account: data is retained as needed to deliver the report (report access for 30 days)
- Contact data: 3 years for responses to inquiries
- Payment data: As required by tax legislation (10 years)
- Security logs: 1 year
- Cookies: In accordance with the Cookie Policy
9. Profiling and Automated Decisions
We do not use automated profiling or make automated decisions that significantly affect you. All decision-making processes involve human intervention.
10. Protection of Children
Our services are not intended for children under 16. We do not knowingly collect personal data from children under this age without parental consent.
11. Changes to This Policy
We reserve the right to update this policy. Significant changes will be communicated 30 days before they take effect.
12. Contact for GDPR Questions
To exercise your rights or ask questions about data processing:
- Email: contact@codat.ro
- Subject: GDPR Request
- Response guaranteed within a maximum of 30 days
- Identification required to verify your identity
- Free service for exercising your rights
13. Complete Legal Documents
For detailed information, consult our complete legal documents:
Full GDPR Compliance
This policy complies with all requirements of Regulation (EU) 2016/679 (GDPR) and applicable Romanian legislation. To exercise your rights or ask questions, contact us at contact@codat.ro.

