v2.4 · in force from 2026-04-12 · SICKW.COM
IMEI API PRO S.R.L., Str. Saturn, Nr. 24, Strejnicu, Prahova, Romania, Trade Register J29/2697/2022, VAT RO46841982, is the data controller for the personal data described here. Contact for data protection matters: contact@sickw.com.
| Data | Why | Legal basis | Kept for |
|---|---|---|---|
| E-mail address, password hash | To create and secure your account | Performance of contract | Life of the account + 3 years |
| IP address and approximate location (city/region/country) at registration and login | Fraud prevention, abuse detection, tax evidence of place of supply | Legitimate interest; legal obligation (VAT) | 3 years; invoicing data 10 years |
| Company name, address, VAT number (if supplied) | Invoicing and VAT treatment | Legal obligation | 10 years (Romanian accounting law) |
| Payment records: amount, currency, gateway, transaction reference | Accounting and dispute handling | Legal obligation | 10 years |
| Order history: identifiers submitted, service used, result, timestamp, cost | To deliver the service, support, and billing disputes | Performance of contract | Life of the account + 3 years |
| Telegram or WhatsApp handle (if you link one) | Notifications you asked for | Consent | Until you unlink it |
| Support messages | To answer you | Legitimate interest | 3 years |
| Server and security logs | Security, debugging, abuse investigation | Legitimate interest | 12 months |
3.1 We treat IMEI and serial numbers as technical device identifiers. We do not link them to an identified or identifiable person, and we do not attempt to determine who owns a device.
3.2 Where a source returns data that could relate to a person, we pass it through as received and do not build profiles from it.
3.3 You warrant that you have a lawful reason to submit each identifier you send us.
We share only what is necessary, with:
• Data sources and API providers — the identifier you submitted, to obtain the result.
• Payment providers — Stripe, Mollie and Revolut, according to the method you choose.
They are independent controllers for the payment itself.
• Infrastructure — our hosting provider and Cloudflare (CDN, WAF, DDoS protection).
• E-mail delivery — Amazon SES.
• Accountants and auditors, and public authorities where the law requires it.
We do not sell personal data and we do not use it for advertising.
Some providers above process data outside the EEA (principally the United States). Those transfers rely on the European Commission's Standard Contractual Clauses or, where applicable, an adequacy decision. A copy of the safeguards is available on request.
Under the GDPR you may ask for: access to your data, correction, erasure, restriction of processing, portability, and you may object to processing based on our legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting what was done before.
Write to contact@sickw.com. We answer within one month. You can also complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority where you live.
Note that we cannot erase invoicing data before the statutory retention period ends, and closing your account does not remove records we must keep for tax purposes.
Passwords are stored hashed, never in plain text. Traffic is encrypted in transit (HTTPS). Access to production data is restricted to the people who need it. We keep audit logs of administrative actions.
We use a session cookie to keep you logged in, and technical cookies set by Cloudflare for security and abuse prevention. These are strictly necessary and are not used for tracking or advertising. We do not run third-party advertising or analytics cookies.
We may update this policy. The version and date are shown at the top. Material changes are notified by e-mail or in the panel.