🔒

Privacy Policy

Last updated: March 2026

1. Introduction

IDAVA Global is committed to protecting your personal data. This Privacy Policy explains what information we collect, how we use it, and what rights you have in relation to it.

This policy applies to all personal data collected through our website (idava.global), our job application portal, our customer portal (for iStoma/iClinic clinic accounts), and our doctor collaboration portal, in compliance with the General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — and applicable Romanian data protection law.

This policy applies to the following categories of users:

  • Visitors — anyone browsing the public website
  • Job Applicants — individuals applying for positions through our recruitment portal
  • Clinic Customers — clinics and dental practices with an active iStoma/iClinic subscription
  • Collaborating Doctors — medical professionals linked to a clinic using our platform

2. Data Controller

The data controller responsible for your personal data is:

IDAVA Solutions SRL
Strada Costache Bălăcescu, Nr. 22, Sector 1, București, România
CUI: RO30410797 | Reg. com: J2022020674403
Email: hi@idava.global

3. What Data We Collect

3.1 Visitor Data

When you browse our website, we may collect:

  • IP address and approximate location (country/city level)
  • Browser type and version
  • Pages visited and time spent on each page
  • Referral source

If you submit a message through our contact form, we also collect your name, email address, and the content of your message.

3.2 Job Applicant Data

When you apply for a position through our recruitment portal, we collect:

  • Full name, email address, phone number
  • City and country of residence
  • LinkedIn profile URL
  • Cover letter and CV / Resume file (PDF)
  • Preferred contact channel (WhatsApp or Telegram)
  • Desired salary (in RON)
  • Work experience level
  • Assessment responses (recruitment questionnaire, psychological evaluation, IQ test, technical test)
  • Application date and stage reached in the recruitment process
  • One-time PIN used for email verification
  • Onboarding documents uploaded after acceptance (e.g. identity documents, contracts) — PDF format only

3.3 Clinic Customer Data

When a clinic accesses the Customer Portal, we process:

  • Admin account code and password (stored as MD5 hash)
  • Company name, CUI (tax ID), registration number
  • Company address, county, city
  • Legal representative name and capacity
  • Email address and phone number
  • IBAN and bank name
  • Contract ID, application type, subscription details
  • Invoice history and payment status
  • Payment transaction data (processed via Netopia)
  • Temporary authentication tokens for desktop auto-login

3.4 Collaborating Doctor Data

When a doctor accesses the Doctor Portal, we process:

  • Full name, email address, phone number, date of birth
  • Password (stored as MD5 hash)
  • List of associated clinics and clinic-specific credentials
  • Medical stamp code (cod parafă)
  • Prescription series and sequence numbers
  • Fiscal unit name, fiscal code, registration number, address
  • Prescription history including patient name, age, diagnosis code, and prescribed medications
  • Digital signature image (base64, used for prescription generation)

3.5 Cookie and Session Data

We use the following types of cookies and session technologies:

Name Type Purpose Duration
ASP.NET_SessionId Session Maintains server-side session state for the current browsing session Session (closes with browser)
cp_type Persistent — Authentication Stores the account type (clinic or doctor) for the "Keep me signed in" feature 1 year
cp_id Persistent — Authentication Stores the account identifier for automatic re-authentication 1 year
cp_token Persistent — Authentication Stores a hashed authentication token for automatic re-authentication 1 year
cp_consent Functional Records your cookie consent preference 1 year

The persistent authentication cookies (cp_type, cp_id, cp_token) are only set when you explicitly check the "Keep me signed in" option at login. They are marked HttpOnly and Secure, meaning they cannot be accessed via JavaScript and are only transmitted over encrypted HTTPS connections. They are deleted immediately upon logout.

We do not use advertising cookies, cross-site tracking cookies, or sell any cookie data to third parties.

3.6 reCAPTCHA Data

Our login pages use Google reCAPTCHA v2 to protect against automated abuse. When you interact with reCAPTCHA, Google may collect your IP address and behavioral data. This is subject to Google's Privacy Policy.

4. How We Use Your Data

Purpose Applies To Legal Basis
Processing and evaluating job applications Applicants Legitimate interest / Pre-contractual steps
Email verification during application Applicants Legitimate interest
Storing candidate profiles in our internal CRM Applicants Legitimate interest
Communicating about application status Applicants Legitimate interest / Consent
Preventing duplicate applications within 12 months Applicants Legitimate interest
Onboarding document collection for accepted candidates Accepted Applicants Pre-contractual / Contractual steps
Authentication and session management (Customer Portal) Clinic Customers Contract performance
Displaying financial statements, invoices and subscription status Clinic Customers Contract performance
Processing online payments via Netopia Clinic Customers Contract performance
Desktop auto-login via temporary token Clinic Customers Contract performance / Legitimate interest
Authentication and session management (Doctor Portal) Collaborating Doctors Contract performance / Legitimate interest
Displaying prescriptions and clinic associations Collaborating Doctors Contract performance
Generating prescription PDFs Collaborating Doctors Contract performance / Legal obligation
Responding to contact form messages Visitors Legitimate interest / Consent
Fraud prevention via reCAPTCHA All authenticated users Legitimate interest

We do not use your data for marketing purposes, and we do not sell your data to any third party.

5. Data Retention

  • Active job applicants: for the duration of the recruitment process
  • Unsuccessful applicants: up to 12 months from the date of last application
  • Accepted applicants / employees: for the duration of the employment relationship and as required by Romanian labor law thereafter
  • Clinic customer data: for the duration of the active contract and up to 5 years thereafter, as required by Romanian accounting and fiscal law
  • Invoice and payment records: 10 years as required by Romanian fiscal law
  • Doctor portal data: for the duration of the active collaboration agreement
  • Prescription data: as required by applicable Romanian medical and pharmaceutical law
  • Authentication cookies (Keep me signed in): up to 1 year, or until logout
  • Contact form messages: up to 12 months from the date of receipt

You may request deletion of your data at any time (see Section 8), subject to applicable legal retention obligations.

6. Data Sharing and Third-Party Processors

Your personal data is processed internally and stored in our secure systems. We share data with the following third-party processors only to the extent necessary to deliver our services:

Processor Purpose Applies To
iClinic CRM (crm.iclinic.ro) Central CRM for storing and managing candidate profiles, clinic accounts, doctor accounts, invoices, prescriptions, and all portal-related data All authenticated users
Netopia Payments Processing online card payments for clinic subscriptions Clinic Customers
Google reCAPTCHA Bot and abuse prevention on login and registration forms All authenticated users
WhatsApp (Meta) Automated recruitment conversations via WhatsApp bot Applicants (WhatsApp channel)
Telegram Automated recruitment conversations via Telegram bot Applicants (Telegram channel)
Email service provider Delivery of PIN verification emails during application and doctor registration Applicants, Doctors

All third-party processors act under appropriate data processing agreements and are required to maintain appropriate technical and organizational security measures. We do not share your data with any third party for advertising or marketing purposes.

We may also disclose your data where required by law, such as in response to a valid legal request from competent Romanian or EU authorities.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Encrypted data transmission (HTTPS / TLS) for all communications
  • Passwords stored exclusively as one-way MD5 hashes — never in plain text
  • Authentication cookies set as HttpOnly and Secure, inaccessible to JavaScript
  • Server-side session management with automatic timeout after inactivity
  • Temporary authentication tokens (for desktop auto-login) that expire after 30 minutes
  • Role-based access controls — clinic accounts cannot access doctor data and vice versa
  • Access controls limiting internal data access to authorized personnel only

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (ANSPDCP) within 72 hours and, where required, affected individuals without undue delay.

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of access (Art. 15) — Request a copy of the personal data we hold about you
  • Right to rectification (Art. 16) — Request correction of inaccurate or incomplete data
  • Right to erasure (Art. 17) — Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations
  • Right to restriction of processing (Art. 18) — Request that we limit how we use your data
  • Right to data portability (Art. 20) — Request your data in a structured, machine-readable format
  • Right to object (Art. 21) — Object to processing based on legitimate interest
  • Right to withdraw consent (Art. 7) — Where processing is based on consent, withdraw it at any time without affecting prior processing
  • Right not to be subject to automated decisions (Art. 22) — Request human review of any automated processing that significantly affects you

To exercise any of these rights, contact us at: hi@idava.global

We will respond to your request within 30 days. In complex cases this may be extended by a further 2 months, with notification.

We may need to verify your identity before processing your request. We will not charge a fee for reasonable requests, but may charge a reasonable fee or refuse manifestly unfounded or excessive requests.

9. International Data Transfers

Your data is processed primarily within the European Union. Where data is transferred outside the EU/EEA (for example, through Google reCAPTCHA or WhatsApp/Meta), such transfers are carried out under appropriate safeguards, including Standard Contractual Clauses (SCCs) approved by the European Commission or adequacy decisions where applicable.

10. Supervisory Authority

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Romanian data protection authority:

ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București
Website: www.dataprotection.ro
Email: anspdcp@dataprotection.ro

You also have the right to lodge a complaint with the supervisory authority in your country of residence or place of work.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our processing activities, applicable law, or operational practices. The updated version will be indicated by a revised "Last updated" date at the top of this page.

For significant changes that affect your rights or how we process your data, we will make reasonable efforts to notify you directly (for example, by email where we hold your address) before the changes take effect. We encourage you to review this policy periodically.

12. Contact Us

For any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data, please contact:

IDAVA Solutions SRL
Strada Costache Bălăcescu, Nr. 22, Sector 1, București, România
Email: hi@idava.global

© 2026 IDAVA Solutions. All rights reserved.

Privacy Policy | Terms of Service

Cookie Preferences

By clicking "Accept all cookies", you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts.

Cookie Settings