Privacy Policy
1. Who is responsible for your data
The controller of the personal data processed by BIMUtils ID (the "Service") is Simplix QWERTY S.R.L., registered under no. J10/25/2017, tax identification no. 36902772, Str. Școlii 64A, Pleșești, com. Berca, jud. Buzău, România ("we", "us"). For any question about your data, write to contact@simplix.ro.
The Service is the central account of the BIMUtils products. Each product you sign in to (a "Product") is a separate controller for the data it processes about you, under its own privacy policy. This policy covers only the Service.
2. What data we process
- Account data: your e-mail address and whether it is verified, your name, your preferred language, the status of your account and the dates it was created and changed.
- Security data: your password, stored only as a one-way hash (we never know it); your two-step verification settings and the secret of your authenticator app (stored encrypted); the public keys of your passkeys; the browsers you chose to trust; verification codes (stored only as hashes, for a short time).
- Session and sign-in data: your active sessions with the IP address, browser and device information, and the dates of sign-in and last activity; failed sign-in attempts used to protect your account against guessing.
- Product links: a random identifier assigned to you (the same for every Product, never your e-mail), the Products you have signed in to, and when you first and last used each.
- Consents: which version of our legal documents you accepted, when, and from which IP address and browser.
- Technical and audit logs: records of security-relevant actions on your account (sign-ins, password, e-mail and two-step changes, deletion requests) and technical error logs.
- Messages: the e-mails we send you (verification codes, security notices) and their delivery status.
We do not ask for and do not process special categories of data, payment data or the content you create in the Products.
3. Why we process it and on what legal basis
- To provide your account and sign you in to the Products — the performance of the contract with you (Article 6(1)(b) GDPR).
- To keep your account and the Products secure (verification codes, two-step verification, lockout after failed attempts, session management, audit logs) — our legitimate interest and yours in preventing unauthorised access (Article 6(1)(f) GDPR).
- To keep the Products you use current about your name, e-mail address and account status, and to ask them before your account is deleted — the performance of the contract (Article 6(1)(b) GDPR).
- To prove the consents you gave and to answer the authorities — our legal obligations (Article 6(1)(c) GDPR).
We do not use your data for advertising, we do not sell it and we do not build marketing profiles. We do not make decisions about you based solely on automated processing.
4. Who receives your data
- The Products you sign in to. When you sign in to a Product, it receives your random identifier, your e-mail address and whether it is verified, your name and your language. Afterwards it receives notices when these change, when your account is suspended or deleted, and when you sign out. A Product receives nothing about you until you sign in to it.
- Our service providers, who process data on our behalf under a contract and only on our instructions: the e-mail delivery provider (ZeptoMail by Zoho, EU data centre) and the providers of the servers that host the Service in the European Union.
- Authorities, where the law requires it.
We do not transfer your data outside the European Economic Area. If that ever becomes necessary, we will do so only with the safeguards the GDPR requires and will update this policy.
5. How long we keep it
- Account, security and Product-link data: as long as your account exists.
- Sessions: until you sign out, or at the latest after 14 days without activity or 90 days in total.
- Registrations never confirmed: deleted after 30 days.
- When you delete your account: after a grace period of 7 days, your account data is erased or anonymised, and the Products are told to do the same with theirs. Consent records and audit entries that we must keep to prove our compliance are kept in anonymised or minimised form for as long as the law requires.
- Technical logs: for a limited period, for security and troubleshooting, then deleted.
6. Your rights
You have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, and to receive it in a portable format. From your profile you can change your name and e-mail address, download your data ("Download my data"), see and end your sessions, and delete your account. For anything else, write to contact@simplix.ro; we answer within one month.
You also have the right to lodge a complaint with the supervisory authority — in Romania, the National Supervisory Authority for Personal Data Processing (ANSPDCP, www.dataprotection.ro) — or with the authority of the EU country where you live or work.
7. Cookies
The Service uses only cookies that are strictly necessary for it to work: the session cookie that keeps you signed in, and the short-lived cookies of the sign-in exchange with the Products. They contain no advertising or tracking and do not require your consent.
8. Security
We protect your data with encryption in transit (HTTPS), one-way hashing of passwords and codes, encryption of the secrets we must keep, access controls and logging. No system is perfectly secure; if a breach affects your data in a way that puts you at risk, we will tell you and the authority as the law requires.
9. Changes to this policy
We may update this policy when the Service or the law changes. Each version is numbered and dated, and the version you accepted is available from your profile. Important changes are announced in the Service.