Privacy Policy
Last updated: July 27, 2026
Who we are
Canovix serves Romanian public open data as a standardized REST API. This policy explains what personal data operating that service requires, and what we do with it. For anything this page doesn't answer, write to contact@canovix.ro.
What we collect
Your account. When you create an account we store your email address, a cryptographic hash of your password (argon2id — we never store, see, or can recover the password itself), whether the email is verified, and the account's creation date. Verification and password-reset emails are sent to the address you registered.
Your API keys. For each key we store an optional project label you choose, the key's plan, and a SHA-256 hash of the key — never the key itself, which is shown to you once and cannot be recovered by us.
Usage. To operate the service and show you your own dashboard we keep per-key request counts — per minute (rate limiting), per day (your usage chart), and per month (quotas) — and a timestamp of when each key was last used.
Server logs. Like any web service, our servers process IP addresses: signup, login, and key-minting requests are rate-limited per IP to prevent abuse, and standard server logs record requests (with a request id, path, and status) for debugging. Rate-limit counters are short-lived and expire automatically; logs are rotated and not used for profiling.
What we don't do
We do not build profiles, do not sell or share your data with anyone, and do not use it for anything beyond running the service. There are no payment details — the free tier has no billing, and paid plans are currently arranged by email.
Legal bases and retention
We process account and usage data to provide the service you signed up for (performance of a contract, GDPR art. 6(1)(b)) and IP-based rate limiting and logs to keep the service available and abuse-free (legitimate interest, art. 6(1)(f)).
Account data is kept while the account exists. Deleting your account (see below) removes the account, all its API keys, and their usage records immediately and permanently. Revoked keys remain visible in your dashboard until the account is deleted.
The data we serve
The datasets behind the API are public information published by Romanian public institutions on data.gov.ro under their open licenses. We standardize the format and never add to the content. If you believe a served dataset contains personal data that should not be public, contact us and we will review it — and take it up with the publishing institution where appropriate.
Your rights
Under the GDPR you can ask what we hold about you, have it corrected, or have it deleted. Most of this is self-serve: your dashboard shows your data, and Delete account erases your account, keys, and usage records immediately — no email required. For anything else, write to contact@canovix.ro and we will respond within 30 days. You also have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP).
Changes to this policy
If this policy changes materially, we will update this page and the date above. The current version always lives at this address.