Privacy Policy

Version v1.3 · Last updated: 28 June 2026

1. Who we are

This Privacy Policy explains how PANCU DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ ("we", "us", "our"), a Romanian authorised natural person (P.F.A.), processes personal data in connection with the Simple Timesheeet service available at simpletimesheeet.eu ("Service").

  • Trade Register no.: F2025028391002 (Oficiul Registrului Comerțului de pe lângă Tribunalul Iași)
  • Unique Registration Code (CUI): 52275004
  • European Unique Identifier (EUID): ROONRC.F2025028391002
  • Main activity: NACE 6210 — custom software development
  • Contact: liorasaas@proton.me

2. What data we collect

Account data (via Clerk)

  • Full name
  • Email address
  • Authentication metadata (login timestamps, session identifiers, device and browser type)

Account data is collected when you register and is managed by our authentication provider, Clerk (see Section 4).

Timesheet data

  • Daily work hours (start time, end time, and break duration)
  • Public-holiday and time-off markers for each day
  • Monthly totals (total hours and overtime)

Collected when you use the Service to record time.

Technical and log data

  • IP address, browser type, operating system
  • Pages visited and timestamps
  • Error logs

Collected automatically when you interact with the Service.

Cookies

See the Cookie Policy section below for full details.

3. Why we collect it (legal basis)

Data categoryPurposeLegal basis (GDPR Art. 6)
Account dataAccount creation and authenticationContract performance (Art. 6(1)(b))
Timesheet dataCore service functionalityContract performance (Art. 6(1)(b))
Technical / log dataSecurity and service improvementLegitimate interests (Art. 6(1)(f))
Analytics cookiesUsage analyticsConsent (Art. 6(1)(a))
Necessary cookiesService operationContract / legitimate interests (Art. 6(1)(b)(f))

4. Who we share it with

We do not sell your personal data and we do not use it for advertising or AI-training purposes. We share data only with the following sub-processors, each engaged under a written Data Processing Agreement as required by GDPR Art. 28:

  • Clerk, Inc. — authentication provider. Processes your email address, name, and authentication metadata. Headquartered in the United States (see Section 5). Clerk Privacy Policy
  • Hetzner Online GmbH — cloud infrastructure provider. Hosts the application servers, database, and file storage on EU-based infrastructure (Germany / Finland). Hetzner Privacy Policy
  • Stripe Payments Europe, Ltd. — payment processor (Ireland). Receives your billing details (name, billing address, VAT/CUI where applicable) and processes card data directly; we do not store full card numbers. Used only if you subscribe to a paid plan. Stripe Privacy Center
  • Amazon Web Services EMEA SARL — transactional email delivery via AWS SES (Luxembourg). Receives the envelope address and content of service emails (account confirmations, password resets, support replies). AWS Privacy Notice
  • Google Ireland Limited — website and product analytics via Google Analytics 4. Loaded only after you accept analytics cookies. Receives pseudonymous usage data (pages viewed, approximate location from a truncated IP address, device and browser type). IP addresses are anonymised; Google Signals and ad personalisation are disabled. Google may process this data in the United States (see Section 5). Google Privacy Policy

The current sub-processor list is maintained internally as part of our Vendor DPA Register and is available on request. Material changes to this list will be reflected in this Privacy Policy.

5. International transfers

Clerk, Inc. is headquartered in the United States. Transfers of personal data to Clerk are governed by the EU-U.S. Data Privacy Framework (Clerk is self-certified) and, as a supplementary safeguard, by the Standard Contractual Clauses (SCCs) approved by the European Commission under GDPR Article 46(2)(c) and incorporated in Clerk's Data Processing Addendum.

Google Ireland Limited is the contracting entity for EU users, but Google Analytics data may be processed by Google LLC on servers in the United States. These transfers are governed by the EU-U.S. Data Privacy Framework (Google LLC is self-certified) and the Standard Contractual Clauses incorporated in Google's Ads Data Processing Terms. Analytics data is collected only after you consent, and you may withdraw consent at any time.

The remaining sub-processors named in Section 4 host or process personal data within the European Economic Area (Hetzner — Germany/Finland; Stripe Payments Europe — Ireland; AWS EMEA — Luxembourg).

6. How long we keep it

We apply the GDPR storage-limitation principle (Art. 5(1)(e)) and retain personal data only for as long as needed for the purposes set out in Section 3:

  • Account data: retained for the duration of your account. Upon account deletion, account data is permanently erased without undue delay. You can request a copy of your data before deletion (see Section 7).
  • Timesheet data: retained for the duration of your account. On account deletion, timesheet records are removed. Where your use of the Service requires retention for working-time evidence under Codul Muncii Art. 119 or Directive 2003/88/EC, you remain responsible for exporting your timesheet data via the application before deleting your account.
  • Technical and log data: retained no longer than necessary for the purposes set out in Section 3 and removed on a regular basis. Security-relevant logs may be retained longer where strictly necessary for the investigation of a specific incident.
  • Cookie consent records: your in-browser consent preference (cc_cookie) expires approximately 6 months after it is set or last refreshed; after this period you will be prompted to re-confirm. A pseudonymous server-side record of each consent decision (categories selected, policy version, timestamp) is retained no longer than necessary to demonstrate compliance with GDPR Art. 7(1) and is removed on a regular basis. The record contains no direct identifier (no name, email, or account ID) and is not linkable to your account.
  • Billing and accounting records: if you subscribe to a paid plan, invoices and related accounting records are retained for 10 years as required by Romanian Law no. 82/1991 on accounting. This retention period applies even after account deletion and overrides the erasure request to the extent strictly necessary to comply with this statutory obligation.

After the retention periods above expire, data is irreversibly deleted or fully anonymised, unless we are legally required to retain it longer (e.g. response to a binding legal order).

7. Your rights under GDPR

As a data subject you have the following rights:

  • Right of access (Art. 15) — request a copy of the data we hold about you
  • Right to rectification (Art. 16) — request correction of inaccurate data
  • Right to erasure (Art. 17) — request deletion of your data, subject to the statutory retention obligations described in Section 6
  • Right to restriction (Art. 18) — request that we limit how we process your data
  • Right to data portability (Art. 20) — receive your data in a machine-readable format
  • Right to object (Art. 21) — object to processing based on legitimate interests
  • Right to withdraw consent (Art. 7(3)) — withdraw analytics cookie consent at any time via the Cookie Preferences link in the footer

You can update your name, email, and timesheet entries directly in Account Settings, and you can delete your account from Account Settings. For all other requests (access, portability, restriction, objection), please contact us at liorasaas@proton.me. We respond to verified requests within 30 days as required by GDPR Art. 12(3).

You also have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP) at www.dataprotection.ro.

8. Automated decision-making

We do not use your personal data for solely automated decision-making within the meaning of GDPR Art. 22, including profiling. The Service performs deterministic calculations on your time entries (e.g. weekly totals, overtime sums) but does not make any decisions about you that produce legal or similarly significant effects without human involvement.

9. Data Protection Officer

Given the size and nature of our processing activities, we are not required to appoint a Data Protection Officer under GDPR Art. 37. Privacy enquiries should be directed to the controller at liorasaas@proton.me.

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure, including:

  • Encryption in transit (TLS 1.2+) for all client/server and inter-service traffic
  • Encryption at rest for database and object storage on Hetzner infrastructure
  • Multi-factor authentication available for all user accounts via Clerk
  • Hashed credentials (we never store passwords in clear text; password handling is managed by Clerk)
  • Principle of least privilege for administrative access to production systems
  • Regular review of sub-processors and their security posture

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by GDPR Art. 33 and, where the risk is high, will inform you without undue delay (Art. 34).

11. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated by updating the version number and "Last updated" date at the top of this page. Continued use of the Service after a material change constitutes acceptance. Each consent decision you record is captured with the policy_version in effect at that time — both in your browser (in the cc_cookie) and as a pseudonymous server-side record retained under Section 6.

12. Contact

PANCU DANIEL PERSOANĂ FIZICĂ AUTORIZATĂ
Trade Register no.: F2025028391002 · CUI: 52275004 · EUID: ROONRC.F2025028391002
Email: liorasaas@proton.me


Cookie Policy

Part of the Privacy Policy · v1.3 · 28 June 2026

What are cookies?

Cookies are small text files stored on your device when you visit a website. They help the website function correctly and, where you consent, provide usage information.

Categories we use

CategoryPurposeCan be disabled?
NecessarySession management, security tokens, storing your cookie consent preferenceNo — required for the Service to function
AnalyticsUsage statistics and performance monitoringYes — via the cookie consent banner

Specific cookies in use

NameProviderCategoryExpiryPurpose
__sessionClerkNecessarySessionAuthentication session token
__client_uatClerkNecessary1 yearUser authentication state
cc_cookieSimple TimesheeetNecessary6 monthsStores your cookie consent preference
_gaGoogle AnalyticsAnalytics2 yearsDistinguishes unique visitors (set only after you accept analytics cookies)
_ga_*Google AnalyticsAnalytics2 yearsMaintains session state for the GA4 property (set only after you accept analytics cookies)

Managing preferences

You can update your cookie preferences at any time by clicking "Manage cookie preferences" in the footer of any page. You can also clear cookies through your browser settings, though this may affect Service functionality, in particular authentication.