Privacy Policy

Last updated: 26 Ianuarie 2026

1. Introduction

HOSTLIFE DIGITAL SRL ("Data Controller"), headquartered at Str. Vidin 37, 805300 Tecuci, Galați, Romania, VAT ID 52638053, respects the privacy of your personal data.

This policy describes how we collect, use, and protect personal data in accordance with the General Data Protection Regulation (GDPR - EU Regulation 2016/679).

2. Personal Data We Collect

Identification data

  • Full name
  • Email address
  • System role (operator, administrator)
  • Profile photo (optional)

Contact data

  • Phone number
  • Email address

Billing data

  • Company name
  • VAT number (CUI/CIF)
  • Registration number
  • Billing address
  • Payment history

Technical data

  • IP address
  • User Agent (browser/device)
  • GPS coordinates (with your consent, for automatic location detection)

Activity data

  • Check-in history
  • Messages exchanged with operators
  • Attachments (CMR, document photos)
  • Time spent in each operation stage

3. Processing Purposes

  • Providing digital check-in service for warehouses
  • Account management and user authentication
  • Payment processing and fiscal invoice generation
  • Real-time communication between drivers and warehouse operators
  • Generating reports and analytics for operations optimization
  • Providing technical support and customer assistance
  • Continuous improvement of our services
  • Compliance with legal obligations (invoice retention per Tax Code)

4. Legal Basis for Processing

Contract performance (Art. 6.1.b GDPR)

We process data necessary to provide contracted services: digital check-in, real-time communication, dock management.

Legal obligation (Art. 6.1.c GDPR)

We retain billing data according to Romanian fiscal legislation (Tax Code - 10 years).

Legitimate interests (Art. 6.1.f GDPR)

We collect technical data for system security, fraud prevention, and service improvement.

Consent (Art. 6.1.a GDPR)

For GPS coordinates and marketing communications, we request your explicit consent, which you can withdraw at any time.

5. Data Sharing with Third Parties

We work with the following trusted partners to provide our services:

Supabase - Database and authentication (EU servers - Frankfurt, Germany)
Stripe - Secure payment processing (PCI DSS certified)
SmartBill - Compliant fiscal invoice generation (Romania)
Vercel - Hosting and global distribution (CDN)

We do not sell or share your personal data with third parties for marketing purposes.

6. International Data Transfers

Some data may be transferred outside the European Economic Area (EEA) to our partners. In such cases, we apply appropriate safeguards, including standard contractual clauses approved by the European Commission, to ensure an equivalent level of data protection.

7. Data Retention Period

Tip dateDurată
User account dataDuration of active account + 30 days after deletion
Billing data10 years (per Romanian Tax Code)
Check-in and operation data2 years or per contractual terms
Technical data (IP, logs)6 months
Attachments (CMR, photos)1 year after operation completion

After retention periods expire, data is automatically deleted or anonymized.

8. Your Rights

Under GDPR, you have the following rights regarding your personal data:

Right of access

You can request a copy of all personal data we hold about you.

Right to rectification

You can correct inaccurate or incomplete data in your account.

Right to erasure

You can request deletion of your data ("right to be forgotten"), except for data retained per legal obligations.

Right to restriction

You can limit how we process your data in certain circumstances.

Right to portability

You can receive your data in a structured, commonly used, and interoperable format.

Right to object

You can object to processing based on legitimate interests.

Right to withdraw consent

You can withdraw consent at any time, without affecting the lawfulness of prior processing.

If you believe your rights are not being respected, you can file a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) - www.dataprotection.ro

9. Data Security

We implement technical and organizational measures to protect your data:

  • Encryption in transit (TLS/SSL) for all communications
  • Row Level Security (RLS) for data isolation between organizations
  • Secure authentication with bcrypt password hashing
  • Continuous monitoring and auditing of data access
  • Automatic backups and disaster recovery procedures
  • Restricted access based on the "need-to-know" principle

10. Cookies and Similar Technologies

We use essential cookies for platform operation (authentication, user session, language preferences). We do not use advertising tracking cookies or third-party profiling cookies.

11. Children's Data

Logistiq services are intended exclusively for users aged 16 years or older. We do not knowingly collect personal data from individuals under this age. If you discover that a minor has provided personal data, please contact us for deletion.

12. Policy Changes

We may update this policy periodically to reflect changes in our practices or legal requirements. We will notify you of significant changes via email or by displaying a banner on the platform. The last update date is shown at the top of this page.

13. Contact

For any questions regarding your personal data or to exercise your GDPR rights, you can contact us:

Data Controller

HOSTLIFE DIGITAL SRL

VAT ID: 52638053

Reg. No.: J20/7592/5001

Str. Vidin 37, 805300 Tecuci, Galați, Romania

We will respond to requests within 30 calendar days.