Privacy Policy
Last updated: February 2026
1. Data Controller
The data controller for this website is FINTEXIS SRL, a company registered in Romania (VAT: RO41362814, Reg: J2019002987237), with registered office in Ilfov, Romania. For any privacy-related inquiries, contact us at info@fintexis.com.
2. Data We Collect
We collect and process the following categories of personal data:
- Account Information: email address and password (hashed) when you create an account.
- Contact Form Submissions: name, email, organization, role, and message content submitted through our contact form.
- Usage Data: IP address (for geolocation-based language detection), browser type, pages visited, and access timestamps collected automatically by our hosting provider.
- Authentication Data: OAuth profile information (name, email, avatar) if you sign in through Google or GitHub.
3. Cookies & Storage
Our site uses the following cookies:
| Cookie | Purpose | Duration | Category |
|---|---|---|---|
| sb-access-token | Authentication session token | Session expiry | Essential |
| sb-refresh-token | Session renewal token | 7 days | Essential |
| preferred-locale | Stores your language preference | 1 year | Functional |
| cookie-consent | Stores your cookie preferences | 1 year | Essential |
4. Legal Basis for Processing
- Consent: for functional cookies and optional data processing (Art. 6(1)(a) GDPR).
- Contract Performance: for processing account data necessary to provide our services (Art. 6(1)(b) GDPR).
- Legitimate Interest: for security measures, fraud prevention, and site analytics (Art. 6(1)(f) GDPR).
5. Third-Party Processors
We use the following third-party service providers who may process your data:
- Vercel Inc. (USA) — Website hosting and edge delivery. Data processed: IP addresses, request logs.
- Supabase Inc. (USA) — Authentication and database services. Data processed: account information, session tokens.
All third-party processors are bound by Data Processing Agreements (DPAs) and comply with EU-US Data Privacy Framework or Standard Contractual Clauses.
6. Data Retention
Account data is retained for the duration of your active account. Contact form submissions are retained for up to 24 months. Usage logs are retained for up to 12 months. You may request deletion of your data at any time.
7. Your Rights Under GDPR
As a data subject under the GDPR, you have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Request erasure of your data (Art. 17)
- Restrict processing of your data (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time without affecting prior processing (Art. 7(3))
To exercise any of these rights, contact us at info@fintexis.com. We will respond within 30 days.
8. Supervisory Authority
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at www.dataprotection.ro, or with any other EU supervisory authority.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this page periodically.