Privacy policy
We care about your data and your child's, so here is a plain explanation of what we collect, why, who we share it with, and what you can do about it. If anything is unclear, write to us — we answer.
1. Who we are
The controller of your personal data is:
- MINIVERS BABY SRL, trading as Sandivers
- CUI 55164353 · Reg. Com. J2026043540000
- Strada Luminii, Valea Lupului, Iași county, Romania
- Email: receptie@sandivers.ro
We are not legally required to appoint a Data Protection Officer, because we do not process data at large scale. For any question about personal data, the address above reaches us directly.
2. What we collect, and why
We collect only what we need in order to operate. Below is the complete list, by category.
Opening-list signup
- What
- Your email address. We also keep the consent wording you ticked and when. Your IP address is NOT stored as such — we keep only a derived code that cannot be turned back into your IP, so we can defend against automated signups.
- Why
- To email you once, when we open.
- Legal basis
- Your consent (Art. 6(1)(a) GDPR).
- Retention
- Until opening and at most 12 months after, or until you ask us to delete it.
Parent account
- What
- Name, email address, password (kept only in an irreversible cryptographic form — we do not know it and cannot read it) and, optionally, a phone number. We record when you accepted this policy and your last sign-in.
- Why
- So you can create and use your account, on the website and in the app.
- Legal basis
- Performance of our contract with you (Art. 6(1)(b) GDPR).
- Retention
- While your account is active. See section 7.
Child profile
- What
- Only a first name and an age band (for example 3–4 years). We do not ask for a surname, we do not ask for a date of birth, and we do not upload photographs.
- Why
- So reception knows who is coming to play and which zone suits them.
- Legal basis
- Performance of the contract (Art. 6(1)(b) GDPR). The profile is created by you, as parent or legal guardian.
- Retention
- While your account is active, or until you delete the profile.
Allergies and dietary needs
- What
- Free text, entered by you, only if you want to. See section 4 — this information has a stricter regime.
- Why
- Your child's safety at the bar and at parties.
- Legal basis
- Your separate, explicit consent (Art. 9(2)(a) GDPR). Without that tick, the system refuses to store it.
- Retention
- Until you delete it or withdraw consent.
Sign-in with Google, Apple or Facebook
- What
- If you choose this: the identifier the provider sends us, your email address and display name. We never receive your password from these providers.
- Why
- So you can sign in without a separate password.
- Legal basis
- Performance of the contract (Art. 6(1)(b) GDPR), at your request.
- Retention
- For as long as you keep that connection linked.
Sessions and devices
- What
- A session code (also stored in cryptographic form), the client type — web, iOS or Android — and when it was last used.
- Why
- To keep you signed in, and to let you sign out everywhere.
- Legal basis
- Performance of the contract and our legitimate interest in keeping accounts secure (Art. 6(1)(b) and (f) GDPR).
- Retention
- Until expiry or sign-out (30 days on the web, 180 in the app).
Visits, passes and points
- What
- Which pass you hold, visits remaining, when you came, which child came in, and points earned or spent.
- Why
- So passes and the points programme work, and so you can see your own history.
- Legal basis
- Performance of the contract (Art. 6(1)(b) GDPR).
- Retention
- While your account is active; payment-related records are kept as the law requires (section 7).
Payments and invoices
- What
- Amount, currency, method, status and invoice number. We do not store card details on our servers.
- Why
- So we can sell you a pass, issue the invoice and keep our accounts.
- Legal basis
- Performance of the contract and our legal, tax and accounting obligations (Art. 6(1)(b) and (c) GDPR).
- Retention
- The period required by Romanian tax and accounting law (section 7).
Party enquiries
- What
- Name, contact details and whatever you tell us about the event. You can ask for a quote without an account.
- Why
- So we can reply and prepare the party.
- Legal basis
- Performance of the contract or steps prior to it, at your request (Art. 6(1)(b) GDPR).
- Retention
- 12 months after the event or after the enquiry closes, if it does not become a booking.
Contact form messages
- What
- Your name, email address, optionally your phone number, the subject you chose and the message you wrote. We also keep a code derived from your IP address, to defend against automated submissions.
- Why
- To reply to you, and so we can check whether someone actually got an answer.
- Legal basis
- Your consent, ticked in the form (Art. 6(1)(a) GDPR), or pre-contractual steps if you're asking about a booking (Art. 6(1)(b)).
- Retention
- 12 months after the conversation closes. Deleted immediately if you delete an account on the same address.
Security log (sign-in activity)
- What
- For every account action — creating an account, a successful sign-in, a failed sign-in, a password reset request, an email confirmation — we record when it happened, what it was, the IP address it came from and the browser type. Here we keep the IP address itself rather than a derived code: if someone is attacking accounts, a code tells us nothing about what else that address did. We never record the password that was typed, right or wrong.
- Why
- So we can stop automated account creation and password guessing, temporarily lock an account that is under attack, and reconstruct what happened if something does go wrong.
- Legal basis
- Our legitimate interest in keeping the service secure (art. 6(1)(f) GDPR). It is in your interest too — without it we could not defend your account.
- Retention
- 12 months, then deleted automatically. The record of failed attempts used for the temporary lock is deleted after 24 hours.
Account deletion requests
- What
- The email address deletion was requested for, when it was requested and when it was carried out. The confirmation link is only ever stored as a cryptographic fingerprint, and that is erased as soon as it's used.
- Why
- To verify the request, and to be able to show we completed it.
- Legal basis
- Our legal obligation to act on requests about your rights (Art. 6(1)(c) GDPR).
- Retention
- 3 years, as evidence the request was handled. Only the address and those two dates remain, nothing else.
Withdrawal requests (the 14-day form)
- What
- Your name, email address, phone if you give one, the order number if you fill it in, which pass, and — if you choose to write one — your reason. We also keep when you sent it, the language of the page, and a code derived from your IP address, to defend against automated submissions. The reason is optional: the law does not require you to explain why you are withdrawing.
- Why
- So we can process the withdrawal and the refund, and so we can show when you told us — the 14 days in which we owe you the money run from that date.
- Legal basis
- Performance of the contract and the legal obligation arising from OUG 34/2014 (Art. 6(1)(b) and (c) GDPR).
- Retention
- 3 years after it is settled, together with the credit note, as evidence that we refunded. If you delete your account sooner we remove the name, phone and reason and keep only the row with the dates and amounts — see the section on account deletion.
Technical and security logs
- What
- Records of significant account actions (for example an erasure request) and server logs.
- Why
- So we can investigate problems and abuse.
- Legal basis
- Our legitimate interest in keeping the service secure and working (Art. 6(1)(f) GDPR).
- Retention
- At most 12 months.
Website traffic measurement
- What
- For each page opened: the page address, the time, the language, whether the browser is a phone or a computer, the site you came from if there was one, and your approximate area — country, county and roughly the town. We also record presses on the page's main buttons. Your IP address is not stored — we use a code derived from it that changes every night, so we cannot follow you from one day to the next. The location is looked up on our own server, not at an outside service. No cookies and no outside tool. See section 8.
- Why
- So we know whether people are finding the site and what interests them, ahead of opening.
- Legal basis
- Our legitimate interest in understanding whether the site is useful (Art. 6(1)(f) GDPR). You can object at any time.
- Retention
- 90 days. Only anonymous per-day totals remain.
We do not ask for your national ID number, we do not ask for card details, we do not use advertising tracking, and we do not buy data about you from anyone else.
3. Children's data
We treat children's data more carefully than adults', and the best way to protect it is to collect as little as possible.
- A child's profile is created by you, from your parent or guardian account. Children do not have accounts with us.
- We ask for only a first name and an age band. No surname, no date of birth, no address, no photographs.
- A child's data is visible only to you and to the colleagues who need it to do their job at reception.
- We never send marketing to children and never build marketing profiles from their data.
- You can delete a child's profile from your account at any time, and the deletion is immediate.
4. Allergy information
Allergies and dietary needs are, in legal terms, health data — a special category with stricter protection. So:
- Filling this in is entirely optional. The account works exactly the same without it.
- We store it only if you tick the separate consent box. If you type something in the field and don't tick, the system refuses to save it and explains why.
- We also record when you gave that consent.
- We use it strictly for your child's safety — at the bar and at parties. Nothing else.
- You can delete it or withdraw consent at any time, from your account.
This information reaches the colleagues who prepare food and drink. If your child's allergy is severe, please also tell us in person — a field in an app is no substitute for a conversation.
5. Who we share data with
We do not sell data to anyone. We share it only with the providers we need in order to operate, and they may use it only for us:
- Hetzner Online GmbH (Germany) — hosts our server, in a data centre in Finland. The data stays in the European Union.
- Google Ireland Limited — Google Workspace, for email. The emails we send you, and your replies to receptie@sandivers.ro, pass through Google's services.
- Cloudflare — hosts only the DNS zone for sandivers.ro, translating the site name into our server's address. Your traffic with our site does not pass through Cloudflare.
- Google, Apple or Meta — only if you choose to sign in with one of those accounts. Verification happens between our server and that provider.
- Public authorities — only where the law requires it, for example reporting invoices to the Romanian tax authority (ANAF).
- Our accountant — for financial records, within our legal obligations.
Online payments and automated invoicing are not active yet. When we switch them on, we will update this policy before we start processing payments, and those providers will appear in the list above.
6. Transfers outside the European Union
Our server and database are in the European Union. Some of the providers above — Google, Cloudflare, Apple, Meta — belong to groups with a United States presence, and some technical operations may take place there.
Where that happens, the transfer relies on the mechanisms the GDPR provides: the European Commission's adequacy decision for the EU–US Data Privacy Framework, or the Commission's standard contractual clauses together with additional technical safeguards.
7. How long we keep data
- Account data — while the account is active.
- After you ask us to delete your account — we close it immediately, cancel your sessions and active passes, and remove the data we are not legally required to keep. Financial records remain, because the law obliges us to keep them.
- Financial and tax records — the period required by Romanian accounting and tax law, generally between 5 and 10 years depending on the document.
- The opening-list signup — until opening and at most 12 months after.
- Sessions, reset and confirmation links — these expire on their own: a reset link in 60 minutes, a confirmation link in 48 hours.
- Technical logs — at most 12 months.
- Traffic measurement — individual records are deleted automatically after 90 days. Only the per-day totals remain (how many pages, how many visitors), and there is nothing about any person in those.
9. How we protect data
- All traffic with the site is encrypted (HTTPS).
- Passwords go through a modern cryptographic function built specifically for passwords (argon2id). We do not keep your password in readable form and cannot recover it — which is why we reset it rather than send it to you.
- Session codes and reset links are also stored in cryptographic form, not as text.
- Server access is by cryptographic key only, behind a firewall, with protection against repeated sign-in attempts.
- We take daily backups of the database.
- Colleagues cannot reach what they don't need: the staff area is separate from customer accounts, with distinct roles and permissions.
No measure is an absolute guarantee. If a breach occurs that puts your rights at risk, we will notify you and the authority within the deadlines the GDPR sets.
10. Your rights
Under the GDPR you have the right:
- of access — to know what data we hold about you and receive a copy;
- to rectification — to correct anything wrong or incomplete;
- to erasure — to ask us to delete data, so far as we are not legally required to keep it;
- to restriction — to ask us to stop using it temporarily;
- to portability — to receive your data in a format you can take elsewhere;
- to object — to object to processing based on our legitimate interest;
- to withdraw consent at any time, where processing rests on it. Withdrawal does not affect what was lawfully done before.
You can exercise several of these yourself, immediately, from your account: change your details, delete a child's profile, withdraw consent for marketing emails, sign out of every device, or request deletion of your account.
For the rest, write to receptie@sandivers.ro. We reply within one month at the latest. If a request is complex we will tell you and say how much longer we need. We do not charge a fee.
11. If you are not satisfied
Write to us first — it is usually quicker. But you always have the right to complain to the supervisory authority:
- The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
- B-dul General Gheorghe Magheru 28–30, Sector 1, 010336 Bucharest, Romania
- Web: www.dataprotection.ro
You may also go to court.
12. Automated decisions
We do not make automated decisions with significant effects on you, and we do not build behavioural profiles. Bonus points are calculated by a simple, published rule, not by an algorithm that assesses you.
13. Changes
Sandivers is a new project and still being built. When we add something that changes how we use data — online payments, bookings, an app — we update this policy before that feature launches.
The last-updated date and version are shown at the top of this page. If a change is significant and you have an account with us, we will tell you by email.
14. Contact
For any question about personal data: receptie@sandivers.ro, or write to MINIVERS BABY SRL, Strada Luminii, Valea Lupului, Iași county, Romania.