Personal Data Processing Notice (GDPR)

Last updated: 10.08.2026

The pontaj.eu platform processes your personal data (name, CNP, working hours, attendance, as well as technical information of the access device) in order to draw up time sheets and attendance conditions and to facilitate compliance with legal obligations regarding working time records.

The basis of the processing is the execution of the individual employment contract or an equivalent legal relationship and the fulfillment of the employer's legal obligations regarding the record of working time (art. 6 para. (1) letters b) and c) of Regulation (EU) 2016/679) and the positive national law (law 53/2003 on the Labor Code). The use of the platform is not imposed by the legislator, and the provider of these services (pontaj.eu provided by GlobalEX Software SRL, CUI 25202471) does not impose or compel the use of the platform in any way, the decision being of the companies to whom it offers such services, and the reasons that outline their decision concern the possibility of fulfilling these obligations in the situation of the large volumes of necessary registrations, the economic possibility of supporting such a service and the correct registration of these operations. The use of the pontaj.eu platform is not possible without the GDPR agreement, its functionalities being dependent on the collection of this data, but some of the services are optional. The present written will describe them in detail.

Geolocation (optional): if your employer activates the physical presence verification function in the immediate geographic area of the workplace, the application records your exact GPS position; the registration is done at the time of boarding, so pontaj.eu does not follow you continuously or according to a calendar, it does not establish travel routes, it does not locate you on request, but only at the time of boarding, to confirm your presence in the established perimeter. Depending on your device and in order to speed up the check-in process, the application prepares the GPS functions from the very moment you access the check-in menu (without asking your permission at that moment and without collecting coordinates), the actual collection of the position taking place only when the check-in button is pressed.
When tipping, your terminal first locally calculates the distance to the perimeter, just to be able to warn you instantly; afterwards, the coordinates are sent to the pontaj.eu server exclusively for the validation of the presence and for the prevention of fraud (validation cannot be based only on the calculation on the phone). The validation is carried out instantly, and the treatment of the coordinates depends on the result: in the situation where the staging is done from within the established perimeter, your GPS coordinates are used exclusively for this validation and are NOT stored, being deleted immediately after validation, so they do not end up being kept on the pontaj.eu server. In the situation where you try to call in from outside the workplace: a) if your employer does not allow calling in from outside the workplace, the call is not carried out and the coordinates are not stored; b) if the employer allows pick-up from outside the workplace, but uses the location function, the pick-up will be carried out, and the incident, together with the related coordinates, will be sent to the management; in the latter case, the coordinates are kept for a maximum of 21 days, regardless of whether or not they were previously read, after which they are automatically deleted.
How you know this function is used: if the employer activates this function for the workplace where you are associated (in the sense of carrying out the activity and not in the patrimonial sense), you will see a mention of this in your profile (the mention appears permanently), and the mobile terminal will ask you for location rights; this function is optional in relation to the possibility of the pontaj.eu platform to function, and accessing it is the prerogative of the employer; the data operator is your employer; the data are stored under security conditions and are not transmitted to third parties without a legal obligation (the operator's provision does not oblige pontaj.eu to transmit them). The reason for this processing is to ensure compliance with positive law by verifying fair registration and eliminating the risk of forgery.

Desktop application connection - Windows (does not run in the internet browser or on your phone but on a computer / laptop) Biometric data (fingerprint and/or facial recognition) - method established by the operator, with non-invasive alternative. The way in which boarding is carried out at a certain workplace - by fingerprint, by facial recognition or by proximity card (RFID) - the choice of mechanism arises from the manifestation of the option of the employer's management (the data operator), which configures it at the terminal level according to its own organizational needs, you following to comply with the active method at the workplace where you are associated (in the sense of carrying out the activity, and not in a patrimonial sense); in the situation where the method configured by the employer involves the processing of biometric data, the following applies, in conjunction and without the need for any additional action on your part.
The biometric representation - understood as a derived mathematical model ("template"), and in no way as an image, a photograph, a scan or a fingerprint or the face as such - is generated and retained exclusively locally, on the terminal related to the workplace, in a password-protected database, the values being, in turn, encrypted at the time of recording, so that even direct, unauthorized access to the database files would not allow their reading; consequently, these data do not leave the terminal under any circumstances and are not, have not been and are not to be outsourced to the pontaj.eu server.
The identification operation (respectively of matching between the pattern presented at the time of registration and the previously recorded patterns) is carried out fully and uninterruptedly on the terminal, it being the only one that performs the comparison and determines the identity, precisely to avoid any transfer of biometric data; what is subsequently communicated to the pontaj.eu server is limited to the elements strictly necessary to record the presence - respectively the associated employee, the time and place of work -, without ever transmitting the fingerprint or the face, and the correlation between a person and his biometric data is established and remains, in its entirety, at the local level. In addition, the technical identifiers used internally are randomly generated and do not consist of, incorporate or derive, in any case, from any element of the fingerprint or the face, so that, from any of the information that reaches the server, the biometric data cannot be recomposed, reconstructed or deduced, and the pontaj.eu server does not own and cannot obtain, in this way, the representation of your physical appearance.
Where the employer does not resort to the biometric modality or orders otherwise, RFID card bridging remains available, which does not require fingerprint or face processing. Biometric data are kept locally exclusively during the time you remain registered for attendance at the respective terminal, being deleted upon your disassociation or removal or upon deletion of the biometric registration; the operator of the data is your employer, the data being stored under security conditions and not being communicated to third parties in the absence of a legal obligation (a possible provision of the operator not being able to oblige pontaj.eu to transmit them).
The desktop application works with any of the 3 previously listed methods, but with only one at a time, so there will not be employees using rfid/face id/fingerprint simultaneously with employees using another method. The pontaj.eu platform can also be used in other methods, and its functionality is not conditioned by the use of this method.
The reason for this processing is to ensure compliance with positive law by verifying fair registration and eliminating the risk of forgery.
The desktop application is signed with a valid security certificate issued by Microsoft through the Microsoft Azure service.

Operator and contact details
The data operator is your employer. The Data Protection Officer (DPO), where appointed, will be communicated to you by your employer. The agent providing the platform is GlobalEX Software SRL (CUI 25202471), which processes the data exclusively based on the documented instructions of the operator, according to art. 28 GDPR.

Categories of technical data of the device
For operation, security and notification delivery, the application processes: device identifier, operating system model and version, application version, IP address at login and a push notification token. The app detects and flags location spoofing (fake GPS) attempts to prevent tipping fraud.

Push notifications (Firebase / Google)
To deliver notifications (reminders, requests, tasks), the app uses Google's Firebase Cloud Messaging service. The device token is transmitted to Google as a proxy, which may involve a transfer outside the EEA, made with appropriate safeguards (standard contractual clauses / applicable privacy framework).

Recipients
The data can be accessed by: the platform proxy (GlobalEX Software SRL) and its technical sub-proxies (hosting/infrastructure provider, push notification provider); public authorities (e.g. Labor Inspectorate, ANAF, courts) only on the basis of a legal obligation. The data is not sold or passed on to other third parties. The agents of GlobalEX Software SRL do not access the platform in the sense of following a subject, but strictly in the key of ensuring the functionality and / or improving the platform.

International transfer / hosting
The data is hosted in the European Union. Live data backups are also carried out within the EU. The only potential transfer outside the EEA is related to the push notification service (Google), carried out with adequate safeguards and backups, but the providers of these services are always reputable providers such as, but not limited to, Microsoft, Apple, Google, Amazon, Synology.

Main Data Retention
The data from attendance and conditions (name, CNP, hours, attendance) are kept for the duration of the employment relationship and subsequently for the period imposed by the legal archiving obligations [eg. according to Law 53/2003 and the National Archives Law no. 16/1996]. GPS coordinates: maximum 21 days (above). By way of exception, GlobalEX Software may not keep the data prior to the termination of the contractual relations or in the event of exceeding the payment terms by one month from the date of the invoice.

CNP / NIF (national identifier)
The personal numerical code is processed on the basis of the legal obligations of the employer, respecting the additional guarantees provided by Law no. 190/2018.

Automated Decisions
Blocking punting outside the perimeter is a technical control; no automatic decisions are made with legal effects on you in the sense of art. 22 GDPR.

Biometrics (if applicable)
Biometric data are data of a special character (art. 9) and are processed only on the basis of explicit consent, with a non-biometric timekeeping alternative available (currently existing: timekeeping on the web / timekeeping in dedicated mobile applications).

About Apps
The mobile application can store locally, on the device (in the application memory), the data necessary for offline operation; they are deleted on uninstallation.
The desktop application may store biometric identifiers locally on the device (in application memory). They can be deleted by you from the delete menu (password 1234 - it is not a security password but is added strictly to give you time to realize that you are in the delete menu) and, in the absence of a contrary option of the administrator (it is set from another menu, and here a non-public password is required, its role is not to ensure a time of introspection), they will be automatically deleted when your individual employment contract will be set as terminated in the pontaj.eu platform

Withdrawal of Consent
Irrespective of the administrator's choice regarding the timekeeping method, the use of any platform of pontaj.eu is conditioned by the expression of your consent (GDPR). For reasons of legal symmetry, all applications enjoy methods of withdrawing previously expressed consent. These options will typically be grouped (without GlobalEX Software being obligated to do so) in the My Account section for the web and mobile applications and the Documents section for the desktop application. If you are unable to access these methods, you can contact your employer and he will forward your requests to us, or you can contact GlobalEX Software (https://pontaj.eu/contact) and we will contact your administrator within a maximum of 1 (one) month.

Your rights (art. 15-22)
access, rectification, deletion, restriction, opposition and portability, through a written request addressed to the employer. You have the right to file a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP).

Version and Changes:
This information is in force from 01.08.2026. Changes will be communicated through the application before they take effect.