Privacy policy
This policy explains which personal data SYSTHEMA ANALYTICS S.R.L., registered office at Mun. Deva, Str. Dragoș Vodă nr. 2, bl. D5, et. 1, ap. 3, jud. Hunedoara, cod 330034, Romania, tax identification number (CUI) 45945560, Trade Register no. J20/524/2022, e-mail [email protected] processes through the AMLTracer website and platform, for what purposes, and what rights you have, under Regulation (EU) 2016/679 (GDPR).
1. Two different roles
- Controller. For the data of website visitors, Platform users (the organisations’ accounts) and people who write to us, Systhema decides how the data are processed. This policy applies to those data.
- Processor. For the data of customers and other persons in the records of the organisations that use the Platform, the controller is the organisation concerned. We process those data only on its instructions, under the signed data processing agreement. If you are a customer of such an organisation, please contact the organisation directly to exercise your rights.
2. Which data we process
- Visitors: IP address, date and time of the request, the page accessed and the browser type, in the web server’s technical logs.
- Users: name, username, e-mail address, organisation and role, password (stored only in irreversible cryptographic form), the two-factor authentication key, the access schedule, notification preferences, and the log of actions in the Platform (sign-ins, data look-ups, decisions), with the IP address and time of each action.
- People who contact us: name, e-mail address and the content of the message.
3. Purposes and legal bases
- Operation and security of the website and the Platform, prevention of unauthorised access and investigation of incidents: our legitimate interest and that of our client organisations (Art. 6(1)(f) GDPR).
- Providing the service to the organisation you work for, managing the account and notifications: performance of the contract with the organisation and the legitimate interest in performing it (Art. 6(1)(b) and (f)).
- Keeping the audit trail of compliance activity, which organisations must be able to present to the authorities: the organisations’ legal obligations under Law no. 129/2019 and the legitimate interest in supporting them (Art. 6(1)(c) and (f)).
- Replying to messages: the legitimate interest in communicating with you.
We do not use the data for marketing, we do not sell them and we do not take automated decisions with legal effects on users based on them.
4. How long we keep the data
- Web server technical logs: 14 days.
- Account data: for the term of the contract with the organisation and afterwards for as long as necessary for the audit trail.
- Log of actions in the Platform: at least 5 years, the record-keeping period set by Law no. 129/2019, which may be extended under the law.
- Backups: overwritten periodically and kept encrypted.
5. Who we share data with
We use providers that process data on our behalf, under contractual confidentiality and security obligations:
- netcup GmbH (Germany): hosting of the server that runs the Platform;
- Cloudflare, Inc.: content delivery and attack protection network through which traffic to the website passes; transfers outside the EU are based on the EU–US Data Privacy Framework and standard contractual clauses;
- Sendinblue SAS (Brevo) (France): sending notification e-mails;
- RCS & RDS S.A. (Digi Storage) (Romania): storage of backups, encrypted before they leave our server so that the provider cannot read them.
Data may be disclosed to authorities where the law requires us to.
6. Security
We apply appropriate technical and organisational measures: encrypted connections, mandatory two-factor authentication, separation of data by organisation, minimal access to the organisations’ systems (read-only), identification data retrieved only on request and logged, encrypted backups and monitoring of server integrity.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing, objection and, where applicable, data portability. Some data cannot be erased before the end of their retention period when the law requires them to be kept (for example, the audit log of compliance activity). To exercise your rights, write to us at [email protected]; we reply within one month at the latest.
You also have the right to lodge a complaint with the Romanian data protection authority (ANSPDCP), B-dul G-ral Gheorghe Magheru nr. 28–30, sector 1, Bucharest, www.dataprotection.ro.
8. Cookies
We use only strictly necessary cookies. Details in the Cookie policy.
9. Changes
We may update this policy. The current version and its date are shown at the top of the page.
AML