Data Processing Notice
1. Purpose of this notice
This Data Processing Notice is the information that Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (the "GDPR") require us to give you, set out in a formal way, and — in its second part — the terms under which the Operator processes personal data on behalf of the organisations that use the platform dunDesk (the "Platform"). It complements the Privacy Policy, which describes the same processing in everyday language; where the two differ, this notice prevails.
2. Controller and contact
Controller: Simplix QWERTY SRL, registered under no. 36902772, tax identification no. 36902772, registered office at Str. Scolii 64A, Plesesti, Berca, jud. Buzau (the "Operator").
Contact for data protection matters: the support tickets inside the Platform (signed-in users) or contact@simplix.ro. No data protection officer has been designated, the conditions of Article 37 GDPR not being met.
3. Categories of data, purposes and legal bases
| Data | Purpose | Legal basis |
| Identification and contact data (name, e-mail), credentials (hashed password), language and settings, roles and memberships | Creating and administering the account; authentication; delivering the Platform's features; service communications | Art. 6(1)(b) — performance of the contract |
| Security data (IP address, browser data, session identifiers, sign-in events, verification codes) | Securing accounts and the Platform; preventing abuse and fraud; diagnosing errors | Art. 6(1)(f) — legitimate interest in security and reliability; art. 6(1)(b) for authentication |
| Organisation (Workspace) data: identification, address, contact, members and roles | Administering the organisation's use of the Platform; invoicing | Art. 6(1)(b); art. 6(1)(c) for invoicing |
| Content uploaded or created by users | Hosting, displaying and processing it as the user and their organisation direct | Art. 6(1)(b); for third-party data in Content, the basis established by the organisation as controller |
| Payment data (plans, amounts, dates, invoices, provider identifiers — never full card numbers) | Processing purchases and subscriptions; accounting; tax obligations | Art. 6(1)(b); art. 6(1)(c) — accounting and tax law |
| Support data (tickets, messages, attachments) | Answering requests; keeping a record of the assistance given | Art. 6(1)(b); art. 6(1)(f) — record keeping |
| Consent records (document, version, date, address) | Demonstrating the consents and acceptances given (art. 7(1) GDPR) | Art. 6(1)(c) |
| Marketing preference and the data needed to send marketing e-mails (name, e-mail, language) | Sending information, news and offers about the Platform | Art. 6(1)(a) — consent, withdrawable at any time |
| Technical logs of requests | Operation, security and troubleshooting of the Platform | Art. 6(1)(f) |
Providing identification and contact data is necessary to create an account; without it the Platform cannot be used. Providing payment data is necessary for paid services. Marketing consent is optional and its absence has no effect on the service.
We do not process special categories of data (Article 9 GDPR) for our own purposes. Organisations that process such data through the Platform (for example health information of their members) do so as controllers and must have a lawful basis under Article 9.
No decision producing legal or similarly significant effects on you is taken solely by automated means (Article 22 GDPR).
4. Sources of the data
The data comes from you (registration, use of the Platform, purchases, tickets), from the organisation that invites you or registers you as its member, pupil or contact (which must inform you of it), and from our providers (for example the outcome of a payment from the payment processor).
5. Recipients
- The members and owners of the Workspaces you belong to, within that Workspace.
- Processors under Article 28 GDPR, bound by written contracts: hosting providers in the European Union; Stripe (payment processing); Cloudflare (content delivery network, file storage, protection of the Platform); GetStream.io (real-time features, where a service uses them); the e-mail delivery provider used for service and marketing messages.
- Public authorities, courts, legal and accounting advisers, where the law requires it or for the establishment, exercise or defence of legal claims.
- A legal successor of the Operator in respect of the Platform.
6. International transfers
The Platform is hosted in the European Union. Where a processor transfers personal data to a country outside the European Economic Area, the transfer is based on an adequacy decision of the European Commission (Article 45 GDPR) or on the standard contractual clauses adopted by the Commission (Article 46(2)(c) GDPR), supplemented where necessary; a copy of the applicable safeguards can be requested through a support ticket.
7. Retention periods
- Account, organisation data and Content: the life of the account, plus the grace period following a deletion request; then automatic deletion or anonymisation.
- Accounting and tax documents and the organisation identification they require: 10 years from the end of the financial year, under Romanian accounting law; organisations with payment history are kept anonymised for that period.
- Consent records: for as long as needed to demonstrate the consent; after the deletion of the account, in a form reduced to the proof itself.
- Support tickets: the life of the account; anonymised afterwards.
- Technical logs: 90 days, except entries needed to investigate a security incident.
- Verification codes, download links, pending requests: from minutes to a few days.
8. Your rights and how to exercise them
You have the rights of access (art. 15), rectification (art. 16), erasure (art. 17), restriction of processing (art. 18), data portability (art. 20) and objection (art. 21), the right to withdraw a consent at any time without affecting the lawfulness of the processing carried out before the withdrawal (art. 7(3)), and the right to lodge a complaint with a supervisory authority (art. 77) — in Romania, the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, www.dataprotection.ro — or with the authority of the Member State of your residence.
The Platform automates the exercise of most of these rights. From the Privacy section of your profile page you can, without any request to us:
- obtain a complete export of your data (access and portability) — generated automatically and delivered as a password-protected link sent to your e-mail;
- request the deletion of your account (erasure) — confirmed with a code sent to your e-mail, then executed automatically after a grace period during which you may cancel; personal data is deleted, and where a record must be kept by law (accounting) or for another person's rights, it is anonymised so that it no longer identifies you;
- see and manage your consents: the documents and versions you accepted, their exact text, and the marketing consent, which you can withdraw with one click;
- rectify your identification data and settings directly.
Rights that the profile page does not cover (restriction, objection, questions about a specific processing) are exercised through a support ticket or at contact@simplix.ro. We answer within one month of receipt; where a request is complex or numerous, the period may be extended by two further months, of which we inform you. Requests are free of charge, unless manifestly unfounded or excessive.
9. Security measures
Pursuant to Article 32 GDPR, the Operator applies measures appropriate to the risk, including: encryption of data in transit; storage of passwords only as salted cryptographic hashes; role-based access control and separation between organisations; access to private files controlled by ownership rules; logging of security-relevant and administrative actions; protected download links with a limited lifetime for data exports; regular updates and backups; contractual obligations on processors. Personal data breaches are handled under Articles 33 and 34 GDPR.
10. Processing on behalf of organisations (processor terms)
When an organisation (a "Workspace", the "Customer") uses the Platform to process personal data of its own members, pupils, customers or contacts, the Customer is the controller of that data and the Operator acts as its processor. The following terms, which the Customer accepts by using the Platform for such processing, constitute the contract required by Article 28(3) GDPR:
- Subject matter and duration: the hosting and processing of the personal data the Customer enters into the Platform, for as long as the Customer's Workspace exists.
- Nature and purpose: storage, organisation, display, transmission and deletion of the data as needed to provide the Platform's features the Customer uses.
- Types of data and data subjects: those the Customer chooses to process — typically identification and contact data of its members, pupils, customers or contacts, and the Content relating to them.
- Instructions: the Operator processes the data only on the Customer's documented instructions, which are the Customer's configuration and use of the Platform and these terms; the Operator informs the Customer if an instruction appears to infringe the GDPR.
- Confidentiality: persons authorised by the Operator to process the data are bound by confidentiality.
- Security: the Operator implements the measures described in section 9.
- Sub-processors: the Customer gives general authorisation for the sub-processors listed in section 5 and for their replacement; the Operator informs the Customer of intended changes through the Platform, giving it the opportunity to object within 30 days.
- Assistance: the Operator assists the Customer, by the Platform's features and where needed through support, in responding to data subjects' requests and in meeting the Customer's obligations under Articles 32 to 36 GDPR.
- Breaches: the Operator notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data.
- Deletion: at the end of the service, the Customer's data is deleted or anonymised by the Platform's deletion mechanisms, except where the law requires its retention.
- Audit: the Operator makes available the information necessary to demonstrate compliance and allows for audits, conducted reasonably, on prior notice and at the Customer's cost, no more than once a year unless a breach occurred.
- The Customer's duties: the Customer warrants that it has a lawful basis for the processing, that it has informed the data subjects (including, where minors are involved, obtained the consent of parents or legal guardians where the law requires it), and that its instructions comply with the law.
11. Changes
This notice is versioned; the current version is published on the Platform and the version you accepted is available on your profile page. Material changes are notified and, where required, submitted for renewed acceptance.