Awarely Monitor
AwarelyMonitor
Legal center

Privacy Policy

MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ, trading as MONITOR AWARELY ("Company", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use the Awarely Monitor CVE monitoring service ("Service"). It is intended to help you understand our processing under Regulation (EU) 2016/679 (GDPR), Romanian Law 190/2018, and the cookie/storage rules implemented in Romania, including Law 506/2004.

Last Updated: July 29, 2026Effective Date: July 29, 2026

Privacy Summary

  • We collect only data necessary to provide the CVE monitoring service
  • Core service data for this deployment is hosted primarily in the EU
  • We never sell your personal data to third parties
  • You can use self-service tools for some requests, including export and account deletion
  • MONITOR AWARELY may act as controller or processor depending on the customer relationship and processing context
  • Some data may still be retained where law, security, or operations require it

1. Data Controller Information

Data ControllerMUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ (trading as MONITOR AWARELY) is the independent controller responsible for the personal data it collects and uses for its own account, security, compliance, and business operations through the Service.
Legal EntityPersoană Fizică Autorizată (PFA) registered under OUG 44/2008 in Romania
Legal NameMUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ
Trade RegisterRomanian Trade Register (ONRC) registration number: F2026008193001
Tax IdentifierCUI: 53962936 (Romanian clients) · EU VAT (VIES): RO54197611 (EU clients outside Romania)
Registered AddressBucurești, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România
LocationRomania, European Union
Contact Emailmonitor@awarely.ro (Data Protection inquiries)
Websitehttps://monitor.awarely.ro
Legal BasisWe process personal data under Article 6(1) GDPR based on: (a) contract performance, (b) legitimate interests, (c) legal obligations, and (d) consent where applicable.
Controller and Processor Role SplitMONITOR AWARELY may act either as independent controller or as processor, depending on the processing context. For organization customer service data handled on behalf of the customer, MONITOR AWARELY may act as processor under a signed DPA. For MONITOR AWARELY's own account management, authentication, security, fraud prevention, legal compliance, and direct billing records, MONITOR AWARELY acts as controller.
Billing ControllerMONITOR AWARELY acts as controller for the billing and invoice records under its control (direct B2B invoicing and subscription state). For in-app card purchases, Stripe and Link (Sold through Link, LLC) act as merchant of record and process payment data under their own privacy terms.

2. Personal Data We Collect

We collect only the minimum personal data necessary to provide our Service:

2.1 Account InformationEmail address, account identifier, display name, identity-provider type, and account profile or authentication claims needed to sign you in and connect you to the correct organization. Authentication is brokered through AWS Cognito using email/password, optional Google OAuth sign-in, or—where provisioned for an eligible organization—one customer-configured enterprise OIDC provider such as Microsoft Entra ID, Okta, or Google Workspace. Passwords are managed by Cognito or the external provider and are not stored by us in plain text.
2.2 External Identity-Provider DataIf you use Google sign-in or enterprise OIDC SSO, we receive the name, email address, stable provider/account identifier, provider type, and limited profile or authentication claims supplied and required for login and organization authorization. A profile-picture URL may be supplied by Google. We do not receive the password used at Google, Microsoft Entra ID, Okta, Google Workspace, or another customer-configured identity provider.
2.3 Billing InformationMONITOR AWARELY may process business contact details, subscription terms, invoice details, payment status, and accounting records under its own controller obligations. For in-app card purchases we additionally store the subscription status, billing period dates, and Stripe customer/subscription identifiers received from Stripe. Payment card details are entered exclusively on Stripe's hosted checkout and never reach MONITOR AWARELY systems.
2.4 Usage DataLogin and logout timestamps, audit events generated by the Service, and analytics events such as page views or general interaction data when you consent to analytics.
2.5 Technical Data and Browser StorageIP address, browser type, device information, request/security metadata, and browser-side storage used for authentication continuity, invite continuation, language preference, and dashboard visit hints.
2.6 Alert, Integration, and SSO ConfigurationEmail addresses; Slack, Microsoft Teams, and generic webhook URLs; browser-push subscription endpoints; Jira or Linear configuration; and enterprise OIDC domain, tenant, client, issuer, provider, and provisioning-status information that you choose to configure. OIDC client secrets and other integration credentials are write-only or otherwise treated as confidential configuration data and are intentionally excluded from self-service account-data exports, audit event details, and browser readback.
2.7 Communication DataContent of support requests and correspondence with our team. An in-app support request includes the message, account contact details, the page from which it was sent, and limited request metadata needed to handle the request.
2.8 Required and Optional DataAccount email and authentication data are required to create and secure an account. Information marked optional in the Service may be omitted, but some alerts, integrations, billing functions, support, or organization features will not work without the data they require. If legally required billing or identity information is not provided, we may be unable to enter into or perform the relevant transaction.
2.9 Sources of Personal DataWe obtain personal data directly from you; from an organization owner or administrator who invites or manages you; from Google when you choose Google sign-in; from the customer-configured enterprise OIDC provider when you use organization SSO; from Stripe/Link for subscription activation and support; and automatically from your browser, device, security logs, and your use of the Service.
2.10 Sensitive DataThe Service is not designed to receive special-category personal data, criminal-offence data, payment-card numbers, passwords, private keys, or other authentication secrets. Do not include such data in inventories, integration settings, or support messages unless we expressly request it or separately agree suitable safeguards in writing.

3. How We Use Your Data

We process your personal data for the following purposes:

3.1 Service ProvisionTo create and manage your account, provide access to the CVE monitoring dashboard, and deliver alerts.
3.2 Billing and Contract AdministrationTo manage subscription state, maintain billing or accounting records under our control, administer self-serve and direct contracts, and support payment-related customer service (legal basis: contract performance, legitimate interests, and legal obligations, as applicable).
3.3 Service ImprovementTo understand aggregated usage and improve the Service. Analytics cookies/Google Analytics rely on consent; non-cookie diagnostics and abuse prevention may rely on legitimate interests.
3.4 SecurityTo detect and prevent fraud, abuse, and security incidents (legal basis: legitimate interests and legal obligations).
3.5 Communication and SupportTo send service announcements, security alerts, team invitations, and respond to support requests (legal basis: contract performance or legitimate interests, depending on context). Support is handled on a best-effort basis and is not subject to a commercial SLA unless a separately negotiated written agreement expressly says otherwise; see the Terms.
3.6 Legal ComplianceTo comply with applicable laws, regulations, and legal processes (legal basis: legal obligations).
3.7 Legitimate InterestsWhere we rely on legitimate interests, those interests include operating and improving the Service, securing accounts and infrastructure, preventing fraud and abuse, administering business relationships, supporting users, maintaining evidence of transactions and consent, and establishing, exercising, or defending legal claims. We balance these interests against the rights and reasonable expectations of affected individuals.
3.8 Authorized Administrative AccessAuthorized MONITOR AWARELY technical and support administrators may access account, subscription, organization, and audit/event data only where necessary to provide and secure the Service, prevent fraud or abuse, investigate incidents, troubleshoot, provide support, comply with law, or establish, exercise, or defend legal claims. Access is limited by role and the need-to-know principle; it is not used for unrelated purposes.

4. Data Security Measures

We implement technical and organizational measures designed to protect personal data:

4.1 Encryption and Transport SecurityWe use transport security and vendor-provided security controls appropriate to the Service environment.
4.2 Access ControlsStrict role-based access controls limit who can access personal data.
4.3 Password SecurityPassword-based authentication is handled by Cognito. We do not store your password in plain text in our application code or database.
4.4 InfrastructureThe Service is hosted primarily on AWS infrastructure in the EU region used by this deployment.
4.5 MonitoringWe maintain logging, monitoring, and review processes proportionate to the Service.
4.6 Incident ResponseWe maintain incident-response procedures and assess notification obligations under GDPR and other applicable law on a case-by-case basis.

5. Data Sharing, Sub-processors, and International Transfers

We share personal data only with trusted partners necessary to provide the Service:

5.1 AWS (Infrastructure and Transactional Email)Amazon Web Services hosts our infrastructure. This deployment is configured primarily in the EU (Frankfurt, eu-central-1). AWS services process account, authentication, configuration, audit, and Service data as needed for hosting and security. Amazon SES is the active transactional-email delivery service for CVE alerts, team invitations, scheduled reports, and account notifications. SES receives sender and recipient addresses, subject, message content, and delivery events required to send, suppress hard-bouncing or complaining recipients, and monitor delivery reputation. AWS provides these services under its contractual terms and data-processing commitments.
5.3 AWS Cognito (Authentication)Amazon Cognito handles user authentication and identity management for sign-in, session handling, and related account flows.
5.4 Google Analytics (Analytics)Google LLC provides analytics services WITH YOUR CONSENT ONLY (via Cookiebot). We use GA4 for aggregated analytics, with no advertising features intentionally enabled in this site code. Google may process analytics data under Google's applicable terms and international transfer mechanisms.
5.5 External Identity Providers (Authentication)Google provides optional consumer/social sign-in. Eligible organization customers may instead configure one enterprise OIDC provider such as Microsoft Entra ID, Okta, or Google Workspace. We receive only the identity and limited authentication/profile claims described in Section 2.2 and never the external-provider password. The provider and organization customer control assignments, MFA and their own processing under the terms that apply between them; AWS Cognito brokers the resulting sign-in to the Service.
5.6 Cookiebot (MONITOR AWARELY Site/App Consent)Usercentrics A/S (Cookiebot), Denmark, manages cookie and storage consent for MONITOR AWARELY's own site/app operation. Cookiebot stores consent choices and related compliance records according to its service configuration and legal documentation.
5.7 Slack (MONITOR AWARELY Support Workflow)An in-app support request is sent to a MONITOR AWARELY-configured private Slack destination so it can be handled. Slack Technologies Limited and/or the applicable Slack/Salesforce entities receive the message, account contact details, page, and limited request metadata included in the support request. Do not include passwords, API keys, payment-card data, or unnecessary sensitive data. Slack states that its default hosting location is the United States unless eligible data-residency settings apply, and that relevant transfers rely on its DPA and applicable safeguards.
5.8 Customer-Configured External DestinationsYou may configure alert delivery or ticket creation to external destinations, including browser-push subscription endpoints, Microsoft Teams, generic webhooks, Jira, and Linear. Enabling an integration or browser-push delivery instructs us to transmit the relevant configured content to that destination. You are responsible for ensuring that you are authorised to configure the destination and for the privacy, security, and contractual settings of the destination service.
5.9 Customer Processor ArrangementsFor organization customers, MONITOR AWARELY may process customer account, usage, alert, audit, and support data on the customer's behalf in order to provide the Service. Where applicable, those processor-side obligations are governed by the relevant customer contract and any signed DPA.
5.10 Stripe and Link (Payments)If you subscribe by card in the app, checkout is operated by Stripe, Inc. under its Managed Payments program, with Link (Sold through Link, LLC) as merchant of record. Stripe/Link process your payment, billing address, and any business name/VAT ID you enter at checkout for payment processing, fraud prevention, tax compliance, receipts/invoices, and post-purchase support, under the Stripe Privacy Policy (stripe.com/privacy) and Link's terms. Card details are collected directly on their hosted checkout and never reach our systems. We receive from Stripe only what we need to activate your plan: subscription status, billing period dates, and customer/subscription identifiers. Stripe entities may process data outside the EEA under Chapter V GDPR transfer mechanisms.
5.11 Legal RequirementsWe may disclose personal data when required by law, court order, or government request, or where necessary to protect our legal rights.
5.12 Business TransfersWe may disclose relevant data in connection with a merger, acquisition, or sale of assets, with appropriate data protection safeguards and notice to you where required.
5.13 No Sale of DataWe do NOT sell, rent, or trade your personal data to third parties for marketing or advertising purposes.

6. Data Retention

We retain personal data only as long as necessary:

6.1 Account DataRetained while your account is active. After an account deletion request, access is removed and data under our control is reviewed for deletion, anonymization, restriction, or retention where required by law, security, fraud-prevention, or operational needs.
6.2 Billing and Accounting RecordsInvoices stored in MONITOR AWARELY’s invoice storage are configured to expire after 2,557 days (approximately seven years). Other billing and accounting records are retained for the period required by applicable tax, accounting, limitation, and legal-record obligations. A current schedule can be requested from monitor@awarely.ro.
6.3 Service Audit, Activity, and Report RecordsService audit records are configured with a 90-day retention period for Free/Starter-tier records and 365 days for Pro-tier records. Generated report records and report storage are configured for 365 days. Login and logout events have a 12-month retention target. DynamoDB TTL deletion is asynchronous, so physical deletion can occur after the configured expiry time.
6.4 In-App Support MessagesThe in-app history keeps at most 10 support messages and removes messages older than 30 days when the history is normalised. A support request can also create a Service audit record, which follows the applicable audit-retention period. Records held by email or third-party support destinations may have separate retention under their relevant service configuration and legal terms.
6.5 Amazon SES Transactional Email RecordsAmazon SES processes delivery events and maintains account-level suppression records for hard bounces and complaints. MONITOR AWARELY does not enable SES open or click tracking. CloudWatch retains aggregate delivery and reputation metrics according to the active AWS log and metric-retention configuration. You may request the current operational configuration from monitor@awarely.ro.
6.6 Consent RecordsCookie and analytics consent records are retained for as long as needed to document consent choices and comply with applicable law, subject to the active Cookiebot configuration.
6.7 Backup DataBackup and recovery copies may persist for limited periods before overwrite or deletion according to the operational setup in use at that time.
6.8 Online Withdrawal RecordsThe online withdrawal function records the consumer name, organization and contract identifiers, statement, request and processing timestamps, refund and cancellation result, and technical request identifier. This record is retained for up to three years to provide the confirmation, prevent duplicate processing, demonstrate compliance, resolve disputes, and establish, exercise, or defend legal claims; separate tax and payment records may follow longer mandatory periods.
6.9 Trial-Eligibility MarkerWhen an account is deleted we store a pseudonymous marker recording that the email address has already used a free trial, together with the date. The marker is a keyed cryptographic hash (HMAC-SHA256) of the email address; the address itself is not stored in the marker and cannot be recovered from it. It is kept for 90 days, after which it expires and a free trial becomes available again. Its only purpose is to prevent repeated trials obtained by deleting and re-creating an account, which section 3.5 of the Terms of Service prohibits. The legal basis is our legitimate interest in preventing abuse of the Service (Art. 6(1)(f) GDPR). Deletion is by DynamoDB TTL, which is asynchronous, so physical removal can occur after the 90-day expiry; the marker stops having any effect at the 90-day mark regardless. It never blocks registration — an account can always be created; only the free trial is not granted a second time.
6.10 Legal-Acceptance Proof and Shared ContributionsAfter account deletion, the version and server timestamp proving acceptance of the Terms and acknowledgement of this Privacy Policy are restricted and retained for up to three years, then made eligible for automatic deletion. This limited record supports contract administration, dispute handling, and the establishment, exercise, or defence of legal claims; its necessity is subject to review and it is not used for marketing. Personal integration credentials and personal push subscriptions are deleted. Notes and remediation-history entries that must remain as shared organization evidence no longer display the departing person’s identifier or email and are marked “Deleted user”.

7. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

7.1 Right of Access (Art. 15)Request a copy of your personal data we process. You can download your data from Settings > Privacy & Data, including account profile, subscription metadata, and billing history metadata we process.
7.2 Right to Rectification (Art. 16)Request correction of inaccurate personal data through your account settings or by contacting us.
7.3 Right to Erasure (Art. 17)Request deletion of your personal data ("right to be forgotten"). Settings > Privacy & Data > Delete Account removes sign-in access and initiates our cleanup workflow for data under our control, subject to lawful retention exceptions.
7.4 Right to Restriction (Art. 18)Request restriction of processing in certain circumstances.
7.5 Right to Portability (Art. 20)Receive your data in a structured, machine-readable format (JSON). Available via Settings > Privacy & Data. Export includes billing metadata under MONITOR AWARELY's control.
7.6 Right to Object (Art. 21)Object to processing based on legitimate interests, including profiling.
7.7 Automated Decision-Making (Art. 22)We do not make decisions based solely on automated processing that significantly affect you.
7.8 Right to Withdraw ConsentWhere processing is based on consent, you may withdraw it at any time through Cookiebot or the relevant consent control we make available.

8. Exercising Your Rights

To exercise your data protection rights:

Self-ServiceSome rights can be exercised directly through Settings > Privacy & Data in your account, including data export and account deletion.
Email RequestSend a request to monitor@awarely.ro with subject line "GDPR Request".
Payment and Billing ScopeFor billing records and payment-related data requests, contact MONITOR AWARELY at monitor@awarely.ro.
B2B Processor ScopeOrganization customers may also contact us regarding processor-side support under a signed DPA where MONITOR AWARELY handles customer service data on the organization's behalf.
VerificationWe may need to verify your identity before processing requests to protect your data.
Response TimeWe aim to respond within one month. Where GDPR permits an extension, we will inform you accordingly.
No FeeExercising your rights is free. We may charge a reasonable fee for manifestly unfounded or excessive requests.
Supervisory AuthorityYou have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at www.dataprotection.ro.

9. Cookies, Tracking, and Consent Management

We use Cookiebot (by Usercentrics A/S) to manage cookie consent in compliance with GDPR and the ePrivacy Directive:

9.1 Consent-First ApproachNon-essential cookies are NOT set until you provide explicit consent via the Cookiebot consent banner. You can change your preferences at any time by clicking the cookie icon or visiting cookie settings.
9.2 Essential Cookies / Storage (Always Active)Required for authentication, session continuity, invite acceptance continuity, security, and basic operation of the Service. These cannot be disabled if you want to use authenticated parts of the Service. Legal basis under GDPR depends on the relevant processing purpose; storage rules follow the applicable cookie/storage laws.
9.3 Functional Cookies / Storage (Consent Required)Preference storage used to remember items such as language choice and dashboard visit hints is enabled only after the relevant consent category is granted. Legal basis: consent.
9.4 Analytics Cookies (Consent Required)Google Analytics 4 cookies help us understand how you use the Service to improve it. The site code does not intentionally enable Google advertising features. You must consent before analytics resources are loaded. Legal basis: consent.
9.5 No Advertising/Marketing CookiesWe do NOT use advertising, retargeting, or cross-site tracking cookies. We do not participate in advertising networks.
9.6 Cookie / Storage DetailsStorage used on this site may include: Cookiebot consent records, authentication/session-related items, invite-continuation items, and preference/analytics items. Analytics storage is loaded only under the Cookiebot statistics consent category. Specific vendor names, keys, and durations may change over time as the implementation evolves.
9.7 Google Analytics Consent ControlsCookiebot controls whether Google Analytics resources are loaded based on your consent choices. If you decline statistics consent, Google Analytics should not be loaded by the site code.
9.8 Consent RecordsCookiebot stores consent records for compliance purposes. The exact fields and retention depend on Cookiebot configuration and applicable law.

10. International Data Transfers

The Service is configured to use AWS eu-central-1 for primary application processing. Third-party providers and customer-configured destinations can process data under their own service arrangements. Where a transfer outside the EU/EEA is applicable, we will use an applicable Chapter V GDPR transfer mechanism and provide current information on request:

10.1 Primary Application RegionThe repository configuration and deployment documentation identify AWS Frankfurt (eu-central-1) as the primary application region. This does not mean that every provider or customer-configured destination processes data solely in the EU.
10.2 AWSAWS provides infrastructure and authentication services for the Service. Current AWS processing and transfer information is governed by the applicable AWS contractual documentation.
10.3 Amazon SESTransactional email is submitted to Amazon SES in eu-central-1. Current AWS processing locations, subprocessors, and transfer safeguards are governed by the applicable AWS contractual documentation.
10.4 GoogleGoogle provides optional sign-in and, only with statistics consent, analytics resources. Current Google processing and transfer information is governed by the applicable Google contractual and privacy documentation.
10.5 Cookiebot, Slack, Customer Identity Providers, and DestinationsCookiebot manages consent. Slack receives in-app support requests and may process relevant data in the United States and other locations. Customer-configured identity providers and integrations such as Slack, Microsoft Teams, Jira, Linear, or generic webhooks can receive or release data when configured by you. Their processing locations and transfer mechanisms are governed by their applicable terms, the customer relationship with them, and your configuration.
10.6 Stripe and Link (Payments)For in-app card purchases, Stripe and Link process payment data as merchant of record. Stripe entities may process data outside the EEA; transfers are governed by Stripe's Chapter V GDPR transfer mechanisms and contractual documentation.
10.7 Current Transfer InformationInternational transfer mechanisms and vendor commitments can change over time. You may contact us if you need the current information relevant to your data.
10.8 Your RightsYou can request information about specific transfer mechanisms used for your data by contacting monitor@awarely.ro.

11. Children's Privacy

Age RequirementThe Service is not intended for children under 16 years of age.
No Knowing CollectionWe do not knowingly collect personal data from children under 16.
Parental NoticeIf you believe a child has provided us with personal data, please contact us immediately and we will delete it.

12. Changes to This Policy

NotificationWe may notify you of material changes via email and/or prominent notice on the Service before they take effect, especially where those changes materially affect how we process personal data.
ReviewWe encourage you to review this policy periodically. The "Last Updated" date indicates when the policy was last revised.
Continued UseWhere the law requires renewed consent or another specific acceptance mechanism, we will rely on that mechanism instead of assuming acceptance from continued use alone.

13. Security Incident Notification

GDPR ComplianceWhere GDPR Article 33 or other applicable law requires it, we will notify the competent supervisory authority within the legally required timeframe.
User NotificationIf a breach is likely to result in high risk to your rights and freedoms, we will notify you directly without undue delay.
Incident DetailsNotifications will include the nature of the breach, likely consequences, and measures taken or proposed.

14. Contact Us

For privacy-related questions, data protection inquiries, or to exercise your GDPR rights:

MUNTEANU C. D. MIHAI PERSOANĂ FIZICĂ AUTORIZATĂ

Trading as: MONITOR AWARELY

ONRC: F2026008193001 · CUI: 53962936 · EU VAT (VIES): RO54197611

București, Sector 1, Bulevardul Bucureștii Noi, Nr. 136, Cod poștal 012366, România

Data Protection Contact

monitor@awarely.ro

Romania, European Union

Romanian Data Protection Authority (ANSPDCP): www.dataprotection.ro

Organization customers may request our standard DPA for processor-side service data handling where relevant to their use case.

For our complete terms of use, please review our Terms and Conditions.

For refunds and cancellations, please review our Refund Policy.

For organization customer processor terms, please review our Data Processing Agreement.