Last updated: 2026-06-18
This policy explains what personal data we collect through the Fonetix platform, why we use it, and your rights. Data controller: [NUME LEGAL COMPANIE / COMPANY LEGAL NAME], [ADRESĂ SEDIU / REGISTERED ADDRESS].
Your data may be accessed by your employer (for progress and compliance reports) and by our service providers acting as processors: the identity-verification provider (Didit), the face-verification service (Amazon Web Services – Rekognition, EU region), hosting and e-mail. We do not sell your data.
Account and activity data are kept while your account is active and for a reasonable period afterwards for legal obligations. Biometric data follows the "Biometric Data" notice. Exact periods: [RETENTION PERIODS].
You have the rights described on the "GDPR" page (access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaint to the supervisory authority).
We use encryption in transit and at rest, access control and logging. No system is 100% secure, but we apply appropriate technical and organisational measures.
For questions or data requests: [EMAIL CONTACT / CONTACT EMAIL]. Data Protection Officer (DPO): [EMAIL DPO / DPO EMAIL].