Privacy Policy — Scintilla

Last updated: [DATE] — Controller: SC BUCOVINA THE BEST SRL — Contact: [CONTACT EMAIL]

This policy describes how SC BUCOVINA THE BEST SRL (“Scintilla”, “we”) processes personal data in connection with the Scintilla platform. The Romanian version prevails in case of divergence.

1. Controller & Contact

Controller: SC BUCOVINA THE BEST SRL, CUI [CUI], Trade Register [J__/__/____], seat [SEAT CITY, COUNTY], Romania. Privacy contact: [CONTACT EMAIL]. For rights requests, email [CONTACT EMAIL] with subject “GDPR request”.

2. Data Categories

We process: account data (name, email, phone, identifiers); auth/session (credential hashes, tokens, access logs); chat messages within portals; booking/session records (times, duration, amounts); payment metadata — never full card data (only last 4, brand, outcome via the Reader’s gateway: PayPal/Stripe/Satispay); platform billing records (subscriptions, per-minute fees); technical logs (IP, user-agent, timestamp, errors) for security and diagnostics.

3. Purposes & Legal Basis

Purposes: service delivery (contract performance, Art. 6(1)(b) GDPR); billing and accounting/tax compliance (legal obligation, Art. 6(1)(c)); security, abuse prevention and diagnostics (legitimate interest, Art. 6(1)(f)); service communications and support; legal obligations (retention, authority requests). No profiling beyond service operation.

4. Roles: Controller / Processor

Scintilla is controller for platform account, billing, and platform-usage data. For Client personal data processed inside a Reader’s Portal (chats, bookings), the Reader is controller and Scintilla acts as processor on documented instructions; the DPA at [DPA URL] applies. Sub-processors and extra-EEA transfers are documented in the DPA.

5. Retention

Account data: until deletion request or account closure, then deleted/blocked per legal duties. Technical logs: 30 days (auto pruned). Chats and session records: kept for service delivery then deleted per retention schedule ([30] days after closure or on request). Billing data: kept for statutory periods (e.g. 5–10 years under Romanian law).

6. Your Rights

You have rights of access, rectification, erasure, restriction, portability, objection (Art. 15–21 GDPR), and to withdraw consent where given. To exercise, contact [CONTACT EMAIL]. You may lodge a complaint with ANSPDCP (Romania, www.dataprotection.ro) or your EU residence authority.

7. Cookies & Similar Technologies

We use only strictly necessary cookies/technologies for operation (language preference, session, security). No profiling/advertising cookies. Locale preference is via Paraglide cookie. Disabling technical cookies may break functionality.

8. Recipients & Transfers

Recipients: hosting/cloud providers, email (Resend), payment gateways configured by the Reader (direct Reader↔Client flow, never held by Scintilla), verification providers (Telnyx Verify for phone). Transfers outside the EEA only with adequate safeguards (SCCs).

9. Updates

Material changes notified by email or in-app notice [14] days before. Romanian version prevails. Contact: [SUPPORT EMAIL].