Privacy notice
Last updated: 4 October 2026.
Who is responsible
The data controller for this website and the Kreastel application is:
Bogdan Parau, Cluj-Napoca, Romania
Contact: privacy@kreastel.eu
What Kreastel is, and what it never holds
Kreastel is a planning and oversight aid for people responsible for pharmacovigilance at marketing authorisation holders. It records dates, owners and statuses of regulatory obligations. It is designed never to receive, store or process individual case safety reports, patient data, reporter data or any other health data about identifiable people. Do not enter such data; the terms of service prohibit it.
What we process, why, and on what legal basis
1. Visiting the public pages (EURD list, calculator, information pages). Our hosting provider records the IP address, the page requested, the time, and browser information in server logs for security and operation, retained for a short period. Legal basis: legitimate interest in running a secure service (Art. 6(1)(f) GDPR). Page-view statistics are collected without cookies and without identifying visitors.
2. Requesting a beta code. We process the e-mail address, role, organisation size and free-text answer you give us, in order to assess the request and, if accepted, send a code. Legal basis: steps at your request prior to entering into a contract (Art. 6(1)(b)). Declined requests are anonymised after 90 days: the e-mail address and the free-text answer are emptied, and the role, the organisation size and the dates of the request and the decision are kept, so that we can say how many people asked and who they were by role. Accepted ones become part of the account record.
3. Using the application. We process your e-mail address (for sign-in by single-use link or code), the name of your workspace, the entries you make in the registers (product names, authorisation numbers, dates, partner organisations, commitment titles, names of people in the training register, KPI figures), the change log the application writes for every edit (user, time, old and new value), reminder-delivery records, and access logs. Legal basis: performance of the contract (Art. 6(1)(b)); for the change log and access logs, our legitimate interest and our customers' interest in an auditable record (Art. 6(1)(f)).
Where a workspace belongs to an organisation, that organisation is the controller of the register contents and Kreastel is its processor under the data processing agreement; this notice covers what we do as controller (accounts, logs, communications).
4. E-mails we send. Sign-in messages, reminders about upcoming obligations, notices about changes to the EURD list affecting your products, and service messages (security, terms, outages). No marketing e-mail without separate consent.
Where the data is
Application and database are hosted in the European Union (Frankfurt, Germany). Sub-processors and their roles are listed at kreastel.eu/security and updated when they change:
- Supabase (database, authentication) — EU region
- Vercel (application hosting) — EU region
- Resend (transactional e-mail)
No data is transferred outside the EU/EEA except where a sub-processor's standard contractual clauses provide for it; details on request.
How long we keep it
- Server logs: at most 30 days.
- Beta-code requests: declined requests are anonymised after 90 days, as described above, and the anonymised record is kept. Accepted ones are kept with the account.
- Account and workspace data: until you close your account. We then delete your account and workspaces within 30 days of your request.
- Change log: kept, and not deleted, including when a workspace is archived or closed. It is the record of who changed what and when, and it cannot be edited or deleted by anyone, including us: an oversight record that could be edited would not be one. Each entry holds the address of the person who made the change. If you ask for erasure, we tell you what the log holds about you and why it is kept.
Your rights
Access, rectification, erasure, restriction, portability and objection, as provided by the GDPR, by e-mail to privacy@kreastel.eu. You can export every register as CSV at any time from the application. You may complain to the Romanian supervisory authority (ANSPDCP, www.dataprotection.ro) or the authority of your own country.
Who can see workspace data
Only members of that workspace, according to their role. Kreastel staff do not access workspace contents except for support at the customer's request, limited to that workspace, and logged. See the security statement for detail.
Cookies
The application sets only the cookie needed to keep you signed in. The public pages set no cookies. No advertising or tracking cookies are used.
Changes
We will post changes here with a new date and, for material changes, notify account holders by e-mail.