Privacy Policy

Last updated: July 27, 2026

Who we are

Canovix serves Romanian public open data as a standardized REST API. This policy explains what personal data operating that service requires, and what we do with it. For anything this page doesn't answer, write to contact@canovix.ro.

What we collect

Your account. When you create an account we store your email address, a cryptographic hash of your password (argon2id — we never store, see, or can recover the password itself), whether the email is verified, and the account's creation date. Verification and password-reset emails are sent to the address you registered.

Your API keys. For each key we store an optional project label you choose, the key's plan, and a SHA-256 hash of the key — never the key itself, which is shown to you once and cannot be recovered by us.

Usage. To operate the service and show you your own dashboard we keep per-key request counts — per minute (rate limiting), per day (your usage chart), and per month (quotas) — and a timestamp of when each key was last used.

Server logs. Like any web service, our servers process IP addresses: signup, login, and key-minting requests are rate-limited per IP to prevent abuse, and standard server logs record requests (with a request id, path, and status) for debugging. Rate-limit counters are short-lived and expire automatically; logs are rotated and not used for profiling.

Cookies

The site sets exactly one cookie: canovix_session, which keeps you signed in to your account dashboard. It is strictly necessary for that feature, holds only an opaque random identifier (no personal data, no tracking), is HttpOnly (invisible to scripts), and is only ever sent to the account pages of this site. Strictly necessary cookies do not require a consent banner under the ePrivacy rules — which is why you don't see one.

We set no tracking or advertising cookies and run no third-party analytics. If you never sign in, no cookie is set at all.

What we don't do

We do not build profiles, do not sell or share your data with anyone, and do not use it for anything beyond running the service. There are no payment details — the free tier has no billing, and paid plans are currently arranged by email.

Legal bases and retention

We process account and usage data to provide the service you signed up for (performance of a contract, GDPR art. 6(1)(b)) and IP-based rate limiting and logs to keep the service available and abuse-free (legitimate interest, art. 6(1)(f)).

Account data is kept while the account exists. Deleting your account (see below) removes the account, all its API keys, and their usage records immediately and permanently. Revoked keys remain visible in your dashboard until the account is deleted.

The data we serve

The datasets behind the API are public information published by Romanian public institutions on data.gov.ro under their open licenses. We standardize the format and never add to the content. If you believe a served dataset contains personal data that should not be public, contact us and we will review it — and take it up with the publishing institution where appropriate.

Your rights

Under the GDPR you can ask what we hold about you, have it corrected, or have it deleted. Most of this is self-serve: your dashboard shows your data, and Delete account erases your account, keys, and usage records immediately — no email required. For anything else, write to contact@canovix.ro and we will respond within 30 days. You also have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP).

Changes to this policy

If this policy changes materially, we will update this page and the date above. The current version always lives at this address.