pepcheck.ro // romanian law 129/2019 · reporting entities · official public sources a product of Systhema · AMLTracer™ · SMSI RO/EN
PepCheck due diligence · PEP

Privacy policy

GDPR compliance (Regulation (EU) 2016/679) · last updated 11 October 2026

This policy describes how SYSTHEMA ANALYTICS SRL collects, uses and protects your personal data, in accordance with the GDPR and the applicable Romanian legislation.

1. Data controller

SYSTHEMA ANALYTICS SRL

  • Tax ID (CUI): 45945560
  • Registered office: Deva, Str. Dragoș Vodă nr. 2, bl. D5, ap. 3, Hunedoara County, postcode 330033, Romania
  • E-mail: hello@systhema.ro
  • Website: pepcheck.ro

1.1. PepCheck’s role (controller)

PepCheck acts as data controller within the meaning of Art. 4(7) GDPR for all data processed within the platform, including:

  • User account data (name, e-mail, organisation)
  • Data aggregated from public sources (ANAF, MFP, ONRC, OpenSanctions, ECRIS)
  • The risk scores calculated by the platform
  • Summaries generated by artificial intelligence
  • Access logs, audit trail and check history

As controller, SYSTHEMA ANALYTICS SRL decides the purposes and means of processing within the platform and is responsible for compliance with the GDPR.

1.2. The User’s role (independent controller)

PepCheck users are independent data controllers for any further use of the information obtained through the platform in their own AML/KYC compliance processes. This means that:

  • The user decides independently how to use the information obtained
  • The user is responsible for its own decisions based on this information
  • The user must comply with its own GDPR and AML requirements (Law 129/2019)
  • PepCheck bears no responsibility for decisions the user takes based on the information provided

The relationship between PepCheck and the User is not a controller–processor relationship. PepCheck does not process data on the user’s behalf, but provides its own information service. Each party acts as an independent controller for the processing it carries out.

2. Personal data collected

2.1. Identification data

  • First and last name
  • E-mail address
  • Phone number
  • Personal identification number (CNP) (optional, administrators only)
  • Position and department (optional)

2.2. Organisation data

  • Company name
  • Tax ID (CUI/CIF)
  • Registered office address
  • Billing address
  • Legal representative’s details
  • Organisation logo (optional)

2.3. Usage data

  • History of PEP searches carried out
  • Reports generated
  • Data checked (name, date of birth, nationality)
  • Timestamps of operations
  • Usage statistics

2.4. Technical data

  • IP address
  • Browser type and version
  • Operating system
  • Device type (desktop, mobile, tablet)
  • Session cookies
  • Access logs

2.5. Payment data

  • Billing information (processed by third-party providers)
  • Payment history
  • We do NOT store full bank card details

3. Purposes of processing

3.1. Providing the services

  • Creating and managing your account
  • Carrying out the PEP checks you request
  • Generating reports and certificates
  • Managing the subscription and invoicing
  • Technical support and customer assistance

Legal basis: performance of the contract (Art. 6(1)(b) GDPR)

3.2. Legal compliance

  • Compliance with Law 129/2019 on the prevention of money laundering
  • Archiving reports for audit
  • Keeping records as required by tax legislation
  • Responding to requests from competent authorities

Legal basis: legal obligation (Art. 6(1)(c) GDPR)

3.3. Security

  • Protection against fraud
  • Detecting and preventing unauthorised access
  • Monitoring suspicious activity
  • Audit trail for compliance

Legal basis: legitimate interest (Art. 6(1)(f) GDPR)

3.4. Improving the services

  • Statistical analysis of usage (anonymised data)
  • Developing new features
  • Performance optimisation

Legal basis: legitimate interest (Art. 6(1)(f) GDPR)

3.5. Communications

  • Service notifications (updates, maintenance)
  • Invoices and tax documents
  • Alerts when you approach the search limit
  • Newsletter (only with explicit consent)

Legal basis: consent or legitimate interest (Art. 6(1)(a) or (f) GDPR)

4. Retention periods

We apply the principle of data minimisation (Art. 5(1)(c) GDPR). We keep data only as long as strictly necessary for the purpose of the processing.

Type of dataRetention periodReason
User account dataTerm of the contract + 90 daysManaging the contractual relationship; allows reactivation in case of error
PEP and due diligence search history90 days from the searchConsulting recent results. The user downloads the PDF report and archives it according to its own legal obligations
Generated reports (PDF)90 days from generationLater download. The 5-year archiving obligation (Law 129/2019) rests with the user, not the platform
Generated AI summaries90 days from generationLater consultation; included in the PDF report downloaded by the user
Access logs (IP, user agent)6 monthsSecurity, intrusion detection, debugging
Audit trail (user actions)6 monthsTraceability of operations for security
Invoices and tax documents10 yearsLegal tax obligation (Romanian Tax Code)
Session cookiesUntil the browser is closedPlatform operation (authentication, CSRF)
Preference cookies6 monthsRemembering preferences (cookie consent, theme)

Important for users (non-bank lenders, reporting entities): Law 129/2019 requires reporting entities to keep KYC/AML documentation for 5 years. This obligation rests with the user, not with the PepCheck platform. We recommend downloading and archiving PDF reports immediately after they are generated.

After the periods expire: data are deleted automatically or irreversibly anonymised. Deletion is carried out by automated processes that run periodically.

5. Recipients of the data

5.1. Service providers (processors)

  • OpenSanctions (OpenSanctions Datenbanken GmbH, Germany, EU): PEP and sanctions data; receives the names searched
  • Hosting: netcup GmbH, Germany (EU)
  • E-mail: Postmark (ActiveCampaign, LLC, USA): sending the platform’s e-mails
  • Backup: Digi Storage (RCS & RDS S.A., Romania): backups encrypted before they leave the server
  • AI summary: Anthropic, PBC (USA): only for organisations that have enabled the AI summary option; receives the public data of the company analysed, including the names of its directors
  • Visit statistics: Google Analytics (Google Ireland Limited, EU; Google LLC, USA): only on the pepcheck.ro presentation page, not in the platform

All processors have GDPR contracts and appropriate security measures.

5.2. Public authorities

  • ANAF (for tax obligations)
  • ANSPDCP (the Romanian data protection authority)
  • Criminal investigation bodies (on legal request)
  • The National Office for Prevention and Control of Money Laundering (ONPCSB)

5.3. International transfers

The platform’s data are stored in the European Union: the servers are in Germany and the backups in Romania.

Three providers may process data outside the European Economic Area: Postmark (e-mails), Anthropic (only for the AI summary option) and Google (visit statistics for the presentation page). Transfers take place on the basis of the standard contractual clauses adopted by the European Commission or, where applicable, the EU–US Data Privacy Framework.

6. Your rights (GDPR)

Right of access (Art. 15)

You can request a copy of your personal data. We reply within 30 days; the first reply is free of charge.

Right to rectification (Art. 16)

You can correct inaccurate or incomplete data directly from My profile.

Right to erasure (Art. 17)

You can request the deletion of your data, except for data needed for legal compliance.

Right to data portability (Art. 20)

You can receive your data in a structured format (CSV, JSON) for transfer.

How do you exercise these rights?

Requests can be sent to: hello@systhema.ro

The request must include:

  • The right you wish to exercise
  • Your identification details (name, e-mail linked to the account)
  • Proof of identity (copy of ID card or passport — for your protection)

Legal response time

We will reply within 30 calendar days at most from receiving the request (Art. 12(3) GDPR). In highly complex cases or with a large number of requests, the period may be extended by a further 60 days, with prior notice to you.

Limitation or refusal

In certain situations, the rights may be limited under Art. 12–23 GDPR, including:

  • Legal obligations to keep data (for example invoicing, tax compliance)
  • The establishment, exercise or defence of legal claims
  • Requests that are manifestly unfounded or excessive (Art. 12(5) GDPR)

If we refuse, you will receive written reasons and information on your right to lodge a complaint with ANSPDCP (the Romanian National Supervisory Authority for Personal Data Processing).

7. Security measures

7.1. Technical measures

  • Encryption: all connections use HTTPS (SSL/TLS)
  • Passwords: stored with Argon2 hashing (industry standard)
  • Firewall: network-level protection
  • Backup: automatic daily copies, encrypted
  • Monitoring: intrusion detection 24/7
  • Updates: security patches applied promptly

7.2. Organisational measures

  • Restricted access: authorised staff only
  • Confidentiality: employees sign confidentiality clauses
  • Audit: periodic review of access and logs
  • Training: continuous training in security and the GDPR

7.3. In the event of a security breach

Under Art. 33–34 GDPR:

  • We notify ANSPDCP within 72 hours of discovery
  • We notify you without undue delay if there is a high risk
  • We describe the nature of the breach and the measures taken

8. Cookies

Cookies are small text files stored on your device to improve the user experience.

TypePurposeDuration
EssentialAuthentication, session, securitySession
FunctionalUser preferences (language, theme)12 months
SecurityCSRF protection, rate limitingSession
AnalyticsGoogle Analytics (_ga, _ga_*): aggregated visit statistics, only on the presentation page and only with your consentUp to 2 years

We do NOT use marketing or advertising cookies. On the presentation page, the Google Analytics script loads even without consent, but without cookies: Google receives the IP address and anonymous visit signals. Analytics cookies are set only if you accept them in the cookie window.

9. Minors

The PepCheck platform is intended exclusively for adult users (18+) acting in a professional or organisational capacity.

We do NOT knowingly collect data from persons under 18.

10. Automated processing, profiling and decisions (Art. 22 GDPR)

10.1. Automated processing — acknowledgement and classification

The platform uses automated processing to generate indicative indicators and scores from public data. We acknowledge that this processing may amount to a form of profiling within the meaning of Art. 4(4) GDPR, as it involves the automated evaluation of aspects relating to legal persons (and, indirectly, to the natural persons associated with them).

However, Art. 22 GDPR does not apply, because:

  • The automated processing has no legal effects and does not significantly affect the data subjects
  • The platform takes no automated decisions — it generates only indicative indicators
  • The final decision always belongs to a human user (the organisation’s compliance officer)
  • No customer is accepted, rejected or escalated automatically by the platform

10.2. The risk score (0–100)

  • The score is generated automatically from public data (ANAF, MFP, ONRC) and is an indicative measure
  • The algorithm is fully transparent — every point is explained and can be checked by the user
  • The score is not an AML/KYC assessment and must not be used as the sole decision criterion
  • The user has the right to challenge the score and to ask for further explanations

10.3. The AI summary

  • The summary generated by artificial intelligence is purely informative
  • It is not a legal, financial or compliance opinion
  • The user has the right to request human intervention and to challenge any information

10.4. PEP and sanctions checks

  • PEP checks return potential matches from public databases (OpenSanctions)
  • The platform issues no verdicts — it only determines whether matches exist
  • Interpretation and the final decision rest with the qualified user

10.5. Your rights regarding automated processing

  • The right to obtain explanations of the logic of the scoring algorithm
  • The right to challenge a score or result and to request a re-check
  • The right to request human intervention in the assessment of information
  • The right to object to profiling, under Art. 21 GDPR

11. Changes to this policy

  • We reserve the right to update this policy
  • Significant changes will be communicated by e-mail
  • The date of the last update is shown at the top of the document
  • We recommend reviewing this policy periodically

12. Contact — data protection

For any question about data protection:

  • E-mail: hello@systhema.ro
  • Subject: “GDPR – [type of request]”
  • Address: Str. Dragoș Vodă nr. 2, bl. D5, ap. 3, Deva, Hunedoara, Romania

Response time: at most 30 calendar days (Art. 12(3) GDPR)

Our commitment

SYSTHEMA ANALYTICS SRL is committed to protecting the confidentiality and security of your personal data, fully respecting the requirements of the GDPR and the applicable Romanian legislation.

Terms and conditions · GDPR rights · User manual (in Romanian)