Last updated: 15 August 2026
Privacy policy
Document based on a standard GDPR template (Gruparea Juristilor Digitali), adapted concretely to the data CAP APP collects and stores. It will be reviewed by a lawyer before the first paying-client contract. For GDPR requests (access, portability, erasure) or specific questions: support@cleanthes-apps.com.
1. Data controller
The data controller for website visitors, for client-organization representatives and for account data in the app is Cleanthes Apps SRL. VAT ID, trade registry and address appear on invoices and in the site footer. Contact for any GDPR request: support@cleanthes-apps.com (reply within 30 calendar days).
Data Protection Officer (DPO) contact: same address support@cleanthes-apps.com with subject "DPO — GDPR request".
2. Two distinct roles
For website data and account data (name, email, phone, organization, billing, logs), Cleanthes Apps SRL acts as data controller.
For employee data entered in the app by the client organization, the organization is the controller and Cleanthes Apps SRL acts as processor (art. 28 GDPR), strictly following the organization's instructions and the DPA accepted at registration.
3. What we collect and store, concretely
Personal employee data: email, first name, last name, employee code (internal identifier).
Role and organization data: job title, department, factory, role level (L1/L2/L3).
Skill data: level (0-4) per skill in the competency matrix — behavioural performance data, NOT special-category data under art. 9 GDPR.
Legal courses: ISCIR, DSP, ANRE, ITM — issue date, expiry date, certificate number, trainer.
Audit trail (immutable log): IP address, user-agent, device ID (where applicable, e.g. shopfloor tablet), timestamp on every create / modify / delete / validate action (required for IFS, IATF 16949, ISO 22000 compliance).
Billing data (BillingContact): company name, VAT ID, legal address, billing email, contact phone. Card data is processed through Stripe and is not stored in our databases — we only keep the token returned by Stripe.
On the marketing website we use no tracking cookies and no third-party resources (no Google Fonts, no Analytics). When you fill in the demo form, the data (name, organization, email, phone, employee count, message) is sent via your email client and processed solely to reply to your request.
4. Sub-processors
We work with a small number of sub-processors, all contractually bound to confidentiality and GDPR standards:
Cloudflare, Inc. — DNS + CDN + website hosting (Cloudflare Pages). EU servers (Frankfurt / Amsterdam). Public DPA, ISO 27001 and SOC 2 certifications. Purpose: page delivery and DDoS protection.
Stripe Payments Europe, Ltd. (Ireland) — card processing, tokenisation. PCI-DSS Level 1. Public DPA, EU–US Data Privacy Framework active for US infrastructure. Purpose: subscription and invoice payments.
SMTP provider for transactional email (welcome, expiry reminders, notifications) — gazduire.net (Romania) or AWS SES (eu-west-1, Ireland). Purpose: email delivery.
Sentry.io — application error monitoring, configured not to send personal data (scrubbing enabled). Purpose: reliability.
Anthropic / OpenAI — planned for the in-app AI assistant feature (under development). When activated, this entry will list location and specific DPA and will require explicit organization consent.
The full list with roles and locations is part of the DPA. Changes are notified to client organizations at least 30 days in advance, with a right to object.
5. Legal basis for processing
We process data on the following bases (art. 6 GDPR):
(a) Contract performance — account and role data necessary for the app to work for each contracted employee.
(b) Legal obligation — legal courses (ISCIR / DSP / ANRE / ITM), audit trail for IFS/IATF compliance, invoices for the Romanian Fiscal Code.
(c) Legitimate interest — security audit trail (IP, user-agent) to prevent fraud and unauthorized access.
(d) Pre-contractual steps or legitimate interest — replying to demo and support requests.
We do not sell personal data. We do not profile for advertising. We do not use personal data to train public AI models.
6. Retention periods
Aligned with Documentatie-Tehnica section 7.10 and Romanian legal obligations:
Inactive employee — 5 years after deactivation (seniority + leave calculation under RO Labour Code). After 5 years: soft delete + anonymisation of identifying fields.
Audit trail (immutable log) — 7 years, IFS / IATF requirement for training traceability.
Legal courses (ISCIR / DSP / ANRE) — until expiry + 3 years (ITM ex-post inspection window).
Invoices and fiscal documents — 10 years (RO Fiscal Code, art. 25).
Support correspondence — up to 3 years.
Account data (non-invoice) — for the contract duration plus 30 days export window, then hard delete.
7. International transfers
Primary data is stored in the European Union. Sub-processors that process data outside the EEA (Stripe and Cloudflare have US infrastructure) are covered by adequate safeguards: adequacy decisions (including the EU–US Data Privacy Framework, in force since July 2023) and standard contractual clauses (SCC).
8. Your rights (art. 15-22 GDPR)
You have the following rights, exercisable by writing to support@cleanthes-apps.com (reply within 30 days):
Access (art. 15) — you can view your own data in the app via /auth/me and /skill-matrix?self=true. On request we can also provide a full export report.
Portability (art. 20) — JSON export via the API, directly from the app ("Export my data" button).
Rectification (art. 16) — the user asks the organization admin to edit the data; the admin is the de-facto controller for employee data.
Erasure (art. 17) — soft delete on contract termination + anonymisation after 5 years (RO legal retention for the contractual relationship).
Restriction (art. 18), objection (art. 21), consent withdrawal — on request, processed within 30 days.
You also have the right to lodge a complaint with the Romanian data protection authority (ANSPDCP) — www.dataprotection.ro.
9. Security
We apply technical and organizational measures: per-organization data isolation at the database level (row-level security verified by automated multi-tenant tests), TLS 1.3 in transit, EU hosting, authentication via short-lived JWT + refresh rotation, immutable audit log, daily backups with a documented restore procedure, and role-based access control (RBAC). Our staff's access to data is strictly limited, logged and exposed in the client organization's audit trail.
10. Employee data in the app
Employees wishing to exercise GDPR rights over their data in the app should first contact the employing organization — the organization is the controller. On the organization's instructions, Cleanthes Apps SRL provides the required technical support (export, rectification, erasure). If an employee contacts us directly at support@cleanthes-apps.com, we redirect them to their organization and assist technically on request.
11. Cookies and local storage
See the Cookies Policy for details. In short: we do not use tracking cookies; in the app we store two items in sessionStorage — cap_token (session JWT) and cap_user (local user metadata) — cleared automatically when the tab closes.
12. Policy changes
We will update this policy when needed; the current version and update date are shown on this page. Material changes are announced by email or in-app, at least 30 days before they take effect.
Documents available on request
For B2B evaluations we can send by email the following legal and trust materials. Versions are updated periodically; check the changelog on each document.