Data should be collected deliberately.
This source provides technical controls, not operator-specific legal advice. Replace every placeholder after a Romanian GDPR review.
Controller and contact
[OPERATOR LEGAL NAME], [REGISTERED ADDRESS], privacy contact [EMAIL].
Data processed
Account identifiers, transaction references, selected terminal, quote snapshot, CAS status evidence, reward ledger, masked network-risk signals, security alerts and operator audit records. CAS and regulated identity systems may process additional data outside this application.
Purposes and retention
Operate requested transactions, prevent fraud, reconcile rewards, support customers, meet legal obligations and defend claims. Define retention periods with counsel and configure deletion/export procedures accordingly.
Security design
CAS credentials stay server-side. Claim proofs and voucher fingerprints are keyed hashes. Sensitive event and audit context uses application encryption. Public leaderboards require explicit opt-in and masked names.
Your rights
Document access, correction, restriction, objection, portability and deletion workflows, including exceptions required by financial-record and AML obligations.