Confidențialitatea demonstrației
În vigoare din 25 august 2026 · Se referă exclusiv la demonstrația Chappa POS
Pe scurt:
- Nu îți cerem nimic. Fără cont, fără e-mail, fără nume, fără telefon, fără card. Demonstrația pornește dintr-un singur clic.
- Nu împărțim datele cu nimeni. Fără rețele de publicitate, fără instrumente de analiză ale altcuiva, fără brokeri de date, fără vânzare, fără schimb. Singurul terț implicat este furnizorul de găzduire, din Uniunea Europeană, care ține serverele pe care rulează totul.
- Analiza turului ghidat este a noastră și rămâne la noi. O folosim ca să vedem cum merge ghidul — unde se împotmolește lumea, ce capitole aleg oamenii, unde renunță. Atât.
- Cookie-urile sunt strict funcționale. Unul singur contează: el este autentificarea ta pe localul demo. Nu urmărește nimic și nu pleacă nicăieri.
- Totul se șterge. Localul demo și tot ce ai făcut în el dispar automat în aproximativ 24 de ore.
1. Cine suntem
Demonstrația Chappa POS este operată de CEAPA COOL SRL, societate înregistrată în România (nr. registrul comerțului J35/956/2023, CUI 47755081), cu sediul în Str. Diana 4, Et. 3, Ap. 16, Timișoara, România.
Suntem operatorul de date pentru prelucrările descrise aici. Pentru orice legat de datele tale, scrie-ne la office@ceapa.cool.
Această notă acoperă doar demonstrația. Aplicația Chappa pentru clienți are propria ei politică de confidențialitate, separată.
2. Ce nu îți cerem
Demonstrația nu are înregistrare și nu are formular. Nu îți cerem și nu primim de la tine: nume, adresă de e-mail, număr de telefon, adresă, date de facturare, date de card, act de identitate, cont pe o rețea socială. Nu există parolă pentru că nu există cont.
Datele pe care le vezi în localul demo — meniu, stocuri, personal, istoric de vânzări — sunt fictive, generate de noi pentru prezentare. Nu sunt ale nimănui.
3. Ce prelucrăm, concret
3.1 Localul demo
Când apeși „Continuă”, serverul clonează un local demonstrativ pentru tine și îl înregistrează cu: identificatorul localului, amprenta criptografică (SHA-256) a tokenului din cookie-ul tău, momentul creării, momentul expirării și adresa IP de la care s-a creat.
Tokenul în clar nu ajunge niciodată în baza noastră de date — stă doar în cookie-ul din browserul tău; serverul păstrează numai amprenta lui, ca să poată recunoaște cookie-ul fără să îl poată reconstitui.
Tot ce introduci în localul demo (comenzi, produse, recepții, rapoarte) rămâne în acel local și se șterge odată cu el.
Păstrare: aproximativ 24 de ore, apoi ștergere automată, definitivă, de către un proces care rulează din oră în oră.
3.2 Cookie-uri și date locale
Folosim exclusiv cookie-uri strict necesare pentru funcționarea serviciului. Nu avem cookie-uri de publicitate, de urmărire sau de profilare, nu avem pixeli și nu avem cookie-uri de la terți — motiv pentru care nu vezi nicio bannerul de consimțământ.
| Ce | La ce folosește | Cât |
|---|---|---|
demo_token | Este autentificarea ta pe localul demo: fără el, browserul tău nu poate fi recunoscut ca proprietarul localului. Este legat strict de acest subdomeniu și nu circulă către niciun alt site sau local. | Cât trăiește localul demo (~24h) |
| Cookie de sesiune | Ține sesiunea deschisă între cereri, cât timp ai fila deschisă. | Sesiunea |
Date locale în browser (localStorage) | Rămân pe dispozitivul tău și nu ne sunt trimise ca atare: nivelul grafic ales de test, capitolele bifate, vocea aleasă, unde ai rămas în tur, limba acestor pagini și confirmarea că ai acceptat termenii. | Până le ștergi tu |
3.3 Analiza turului ghidat
Turul ghidat este măsurat, iar măsurătoarea este a noastră, făcută de noi, pe serverele noastre. Nu folosim Google Analytics și niciun alt instrument extern. Nu există niciun script de la terți pe aceste pagini.
De ce: ca să știm dacă ghidul își face treaba. Unde se blochează lumea, ce pas e prea lung, ce capitole interesează, la ce pas se renunță, dacă vocea ajută sau deranjează. Fără asta, un tur cu zeci de pași este o cutie neagră și nu îl putem îmbunătăți.
Ce se înregistrează:
- un identificator de vizită generat aleator de browserul tău, păstrat local 24 de ore — nu conține nimic despre tine și nu te leagă de altceva;
- momentele de început și de sfârșit ale vizitei, adresa IP și antetul User-Agent (browserul și sistemul de operare, așa cum le anunță el);
- de unde ai venit: pagina care te-a trimis și adresa pe care ai intrat, inclusiv parametrii de campanie din ea (
utm_*și similare), dacă există; - context tehnic: rezoluția ecranului, dimensiunea ferestrei, limba, fusul orar și nivelul grafic ales de testul de la început;
- parcursul: capitolele bifate, vocea aleasă, pașii afișați, cât ai stat pe fiecare, unde ai apăsat „mai departe”, unde ai renunțat, timpul cât fila a fost efectiv vizibilă, și paginile prin care a trecut turul.
Ce nu se înregistrează: nu urmărim ce faci în afara acestui site, nu combinăm datele cu alte surse, nu construim profiluri de persoană și nu folosim nimic din toate acestea pentru publicitate.
Păstrare: 400 de zile de la ultima activitate a vizitei, apoi ștergere automată. O pâlnie se citește pe sezoane; peste atât nu ne mai spune nimic.
3.4 Securitate și prevenirea abuzului
Demonstrația este deschisă oricui, fără cont — ceea ce înseamnă că trebuie să ne apărăm de folosirea ei abuzivă. Pentru asta:
- Limitare la creare. Fiecare creare de local demo este consemnată cu adresa IP și momentul, ca să nu se poată crea la nesfârșit de la aceeași adresă. Păstrare: 2 zile.
- Registru de securitate. Sistemul înregistrează automat semnalele tehnice care indică o încercare de manipulare sau de acces neautorizat: adresa IP, ruta cererii, localul, ce anume s-a declanșat, momentul — plus, separat și marcate explicit ca neverificate, informațiile pe care le declară browserul despre el însuși. Înregistrările sunt înlănțuite criptografic și semnate, ca să poată fi verificate ulterior. Păstrare: cât este necesar pentru constatarea, exercitarea sau apărarea unui drept.
- Dovada acceptării termenilor. La pornirea demonstrației păstrăm momentul acceptării, versiunea termenilor acceptată, adresa IP și antetul User-Agent. Păstrare: 12 luni.
- Jurnale de server. Ca orice server web, ale noastre consemnează cererile primite (adresă IP, moment, rută, cod de răspuns) pentru funcționare, diagnosticare și securitate. Păstrare: pe termen scurt, în mod obișnuit sub 30 de zile.
Accesul poate fi blocat automat, pe baza acestor semnale. Blocarea privește accesul la o demonstrație gratuită și nu produce efecte juridice asupra ta; dacă ești blocat pe nedrept, scrie-ne și verificăm manual.
3.5 Vocea ghidului
Dacă alegi un tur cu voce, browserul tău descarcă fișiere audio pregătite dinainte. Nu îți cerem microfonul, nu înregistrăm nimic și nu ascultăm nimic. Se consemnează doar dacă o replică a fost redată integral sau întreruptă — parte din analiza de la 3.3.
4. Ce nu facem
- Nu vindem, nu închiriem și nu facem schimb cu datele tale.
- Nu avem parteneri de publicitate și nu afișăm reclame.
- Nu folosim instrumente de analiză, de hărți de căldură, de înregistrare a sesiunii sau de raportare a erorilor aparținând altcuiva.
- Nu îți citim poziția GPS și nu cerem permisiuni de localizare.
- Nu te urmărim pe alte site-uri și nu primim date despre tine de la alte site-uri.
- Nu luăm decizii automate cu efecte juridice asupra ta.
5. Cine primește datele
Nimeni. Nu transmitem datele descrise aici către niciun terț, cu următoarele două excepții, inevitabile:
| Cine | De ce |
|---|---|
| Furnizorul de găzduire | Serverele pe care rulează demonstrația și baza ei de date sunt găzduite într-un centru de date din Uniunea Europeană. Furnizorul acționează ca persoană împuternicită, pe baza unui contract, strict pe instrucțiunile noastre, și nu folosește datele în scopuri proprii. |
| Autoritățile competente | Numai atunci când legea ne obligă, sau atunci când constatăm o faptă de natura celor descrise în Termenii demonstrației și sesizăm organele de urmărire penală. |
6. Unde stau datele
Serverele sunt operate de noi și se află în Uniunea Europeană. Nu transferăm date în afara Spațiului Economic European. Toate conexiunile sunt criptate TLS; tokenul demo este păstrat pe server doar ca amprentă criptografică; copiile de siguranță ale bazei de date sunt accesibile exclusiv administratorilor noștri.
7. Temeiuri juridice (GDPR)
| Prelucrare | Temei |
|---|---|
| Crearea și funcționarea localului demo, cookie-urile strict necesare | Executarea acordului pe care îl accepți la pornirea demonstrației — art. 6(1)(b) GDPR. Pentru cookie-urile strict necesare, excepția de la art. 41 din Legea nr. 506/2004. |
| Analiza turului ghidat | Interesul nostru legitim de a înțelege și de a îmbunătăți propriul produs de prezentare — art. 6(1)(f). Măsurătoarea este proprie, nu este împărtășită și nu servește publicității. |
| Securitate, prevenirea abuzului, registrul de securitate, dovada acceptării | Interesul nostru legitim de a ne proteja sistemele, de a preveni folosirea abuzivă a unui serviciu gratuit deschis oricui și de a putea constata, exercita sau apăra un drept — art. 6(1)(f), respectiv art. 9(2)(f) unde este cazul. |
Ai dreptul de a te opune prelucrărilor întemeiate pe interesul legitim; vezi articolul 9.
8. Cât păstrăm
| Ce | Cât |
|---|---|
| Localul demo și tot conținutul lui | ~24 de ore, apoi ștergere automată |
| Consemnarea IP pentru limitarea creărilor | 2 zile |
| Analiza turului ghidat | 400 de zile de la ultima activitate |
| Dovada acceptării termenilor | 12 luni |
| Registrul de securitate | Cât este necesar pentru constatarea, exercitarea sau apărarea unui drept |
| Jurnale de server | În mod obișnuit sub 30 de zile |
9. Drepturile tale
Ai dreptul de acces, rectificare, ștergere, restricționare, portabilitate și dreptul de a te opune prelucrărilor întemeiate pe interesul legitim (art. 15–22 GDPR). Scrie-ne la office@ceapa.cool și răspundem în cel mult o lună.
O precizare onestă. Pentru că demonstrația nu îți cere niciun fel de identificare, în mod normal nu te putem găsi în datele noastre pornind de la numele sau adresa ta de e-mail — nu le avem. Ca să îți putem regăsi înregistrările, trimite-ne identificatorul de vizită: îl găsești în browser, în localStorage, sub cheia chappa_guide_sid, pe acest domeniu. Cu el ștergem sau îți arătăm exact rândurile tale. Fără el, articolul 11 GDPR ne permite să nu obținem informații suplimentare doar pentru a te identifica — dar tot poți șterge singur localul demo, închizându-l și lăsându-l să expire, și poți șterge oricând datele locale din browserul tău.
Ai dreptul de a depune plângere la Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, București — dataprotection.ro.
10. Copii
Demonstrația se adresează profesioniștilor din industria ospitalității și nu este destinată persoanelor sub 16 ani. Nu colectăm cu bună știință date de la copii.
11. Modificări
Dacă schimbăm ceva în modul în care prelucrăm datele, actualizăm această pagină și data de la începutul ei. Versiunea aplicabilă este cea publicată aici la momentul vizitei tale.
12. Contact
CEAPA COOL SRL, Str. Diana 4, Et. 3, Ap. 16, Timișoara, România — office@ceapa.cool
Demo Privacy Notice
Effective 25 August 2026 · Covers the Chappa POS demonstration only
The short version:
- We ask you for nothing. No account, no email, no name, no phone number, no card. The demo starts on a single click.
- We share your data with no one. No ad networks, no one else's analytics tools, no data brokers, no selling, no trading. The only third party involved is our hosting provider, in the European Union, which runs the servers everything sits on.
- The guided-tour analytics are ours and they stay with us. We use them to see how the tour is doing — where people get stuck, which chapters they pick, where they give up. That is all.
- The cookies are strictly functional. Only one really matters: it is your authentication to the demo venue. It tracks nothing and goes nowhere.
- Everything is deleted. The demo venue and everything you did in it disappear automatically within about 24 hours.
1. Who we are
The Chappa POS demonstration is operated by CEAPA COOL SRL, a company registered in Romania (trade register no. J35/956/2023, fiscal code CUI 47755081), with its registered office at Str. Diana 4, Et. 3, Ap. 16, Timișoara, Romania.
We are the data controller for the processing described here. For anything related to your data, write to us at office@ceapa.cool.
This notice covers the demonstration only. The Chappa consumer app has its own, separate privacy policy.
2. What we do not ask you for
The demonstration has no sign-up and no form. We neither ask for nor receive from you: name, email address, phone number, address, billing details, card details, identity document, or a social account. There is no password because there is no account.
The data you see inside the demo venue — menu, stock, staff, sales history — is fictitious, generated by us for the demonstration. It belongs to no one.
3. What we process, specifically
3.1 The demo venue
When you press “Continue”, the server clones a demonstration venue for you and registers it with: the venue identifier, the cryptographic fingerprint (SHA-256) of the token in your cookie, the time of creation, the time of expiry, and the IP address it was created from.
The token itself never reaches our database — it lives only in the cookie in your browser; the server keeps only its fingerprint, so it can recognise the cookie without being able to reconstruct it.
Everything you enter in the demo venue (orders, products, receipts, reports) stays in that venue and is deleted with it.
Retention: about 24 hours, then automatic, permanent deletion by a process that runs every hour.
3.2 Cookies and local data
We use strictly necessary cookies only. We have no advertising, tracking or profiling cookies, no pixels and no third-party cookies — which is why you see no consent banner.
| What | What it does | How long |
|---|---|---|
demo_token | This is your authentication to the demo venue: without it, your browser cannot be recognised as its owner. It is bound strictly to this subdomain and travels to no other site or venue. | The lifetime of the demo venue (~24h) |
| Session cookie | Keeps the session open between requests while your tab is open. | The session |
Local browser data (localStorage) | Stays on your device and is not sent to us as such: the graphics level picked by the opening test, the chapters you ticked, the voice you chose, where you left off in the tour, the language of these pages, and the record that you accepted the terms. | Until you clear it |
3.3 Guided-tour analytics
The guided tour is measured, and the measurement is ours, done by us, on our own servers. We do not use Google Analytics or any other external tool. There is no third-party script on these pages.
Why: so we know whether the tour is doing its job. Where people get stuck, which step runs too long, which chapters interest people, at which step they give up, whether the voice helps or gets in the way. Without it, a tour of dozens of steps is a black box and we cannot improve it.
What is recorded:
- a visit identifier generated at random by your browser and kept locally for 24 hours — it contains nothing about you and links you to nothing else;
- the start and end times of the visit, the IP address and the User-Agent header (the browser and operating system as it announces them);
- where you came from: the referring page and the address you entered on, including any campaign parameters in it (
utm_*and similar), if present; - technical context: screen resolution, window size, language, time zone, and the graphics level chosen by the opening test;
- your path: the chapters ticked, the voice chosen, the steps shown, how long you spent on each, where you pressed “next”, where you gave up, how long the tab was actually visible, and the pages the tour passed through.
What is not recorded: we do not follow what you do outside this site, we do not combine the data with other sources, we do not build profiles of individuals, and we use none of it for advertising.
Retention: 400 days from the visit's last activity, then automatic deletion. A funnel is read across seasons; beyond that it tells us nothing.
3.4 Security and abuse prevention
The demonstration is open to anyone, with no account — which means we have to defend it against abuse. To that end:
- Creation limits. Every demo-venue creation is logged with the IP address and the time, so that an unlimited number cannot be created from the same address. Retention: 2 days.
- Security register. The system automatically records technical signals indicating an attempt at tampering or unauthorised access: IP address, request route, venue, what was triggered, and when — plus, separately and explicitly marked as unverified, whatever the browser asserts about itself. The records are cryptographically chained and signed so they can be verified afterwards. Retention: as long as necessary for the establishment, exercise or defence of a legal claim.
- Proof that the terms were accepted. When the demonstration starts we keep the time of acceptance, the version accepted, the IP address and the User-Agent header. Retention: 12 months.
- Server logs. Like every web server, ours record incoming requests (IP address, time, route, response code) for operation, diagnostics and security. Retention: short, normally under 30 days.
Access may be blocked automatically on the basis of these signals. Blocking concerns access to a free demonstration and produces no legal effects on you; if you are blocked wrongly, write to us and we will check by hand.
3.5 The tour's voice
If you choose a tour with narration, your browser downloads pre-recorded audio files. We do not ask for your microphone, we record nothing and we listen to nothing. All that is logged is whether a line played in full or was cut short — part of the analytics under 3.3.
4. What we don't do
- We do not sell, rent or trade your data.
- We have no advertising partners and show no ads.
- We use no third-party analytics, heat-mapping, session-recording or crash-reporting tools.
- We do not read your GPS position and ask for no location permissions.
- We do not track you across other sites and receive no data about you from other sites.
- We make no automated decisions producing legal effects on you.
5. Who receives the data
No one. We disclose the data described here to no third party, with the following two unavoidable exceptions:
| Who | Why |
|---|---|
| Our hosting provider | The servers running the demonstration and its database are hosted in a data centre in the European Union. The provider acts as a processor, under contract, strictly on our instructions, and does not use the data for its own purposes. |
| Competent authorities | Only where the law requires it, or where we establish an act of the kind described in the Demo Terms of Use and report it to the criminal-prosecution authorities. |
6. Where the data lives
The servers are operated by us and located in the European Union. We do not transfer data outside the European Economic Area. All connections use TLS encryption; the demo token is stored on the server only as a cryptographic fingerprint; database backups are accessible only to our administrators.
7. Legal bases (GDPR)
| Processing | Basis |
|---|---|
| Creating and running the demo venue, strictly necessary cookies | Performance of the agreement you accept when starting the demonstration — art. 6(1)(b) GDPR. For strictly necessary cookies, the exemption in art. 41 of Romanian Law no. 506/2004. |
| Guided-tour analytics | Our legitimate interest in understanding and improving our own demonstration product — art. 6(1)(f). The measurement is first-party, is not shared, and serves no advertising purpose. |
| Security, abuse prevention, the security register, proof of acceptance | Our legitimate interest in protecting our systems, preventing abuse of a free service open to anyone, and being able to establish, exercise or defend a legal claim — art. 6(1)(f), and art. 9(2)(f) where applicable. |
You have the right to object to processing based on legitimate interest; see section 9.
8. How long we keep things
| What | How long |
|---|---|
| The demo venue and all its contents | ~24 hours, then automatic deletion |
| The IP record used for creation limits | 2 days |
| Guided-tour analytics | 400 days from last activity |
| Proof that the terms were accepted | 12 months |
| Security register | As long as necessary to establish, exercise or defend a legal claim |
| Server logs | Normally under 30 days |
9. Your rights
You have the rights of access, rectification, erasure, restriction and portability, and the right to object to processing based on legitimate interest (arts. 15–22 GDPR). Write to us at office@ceapa.cool and we will answer within one month.
One honest caveat. Because the demonstration asks you for no identification at all, we normally cannot find you in our data starting from your name or email address — we do not have them. To let us locate your records, send us your visit identifier: you will find it in your browser, in localStorage, under the key chappa_guide_sid, on this domain. With it we can delete or show you exactly your rows. Without it, art. 11 GDPR allows us not to acquire additional information solely to identify you — but you can still delete the demo venue yourself, by closing it and letting it expire, and you can clear your browser's local data at any time.
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest — dataprotection.ro.
10. Children
The demonstration is aimed at hospitality professionals and is not intended for people under 16. We do not knowingly collect data from children.
11. Changes
If we change anything about how we process data, we update this page and the date at the top of it. The applicable version is the one published here at the time of your visit.
12. Contact
CEAPA COOL SRL, Str. Diana 4, Et. 3, Ap. 16, Timișoara, Romania — office@ceapa.cool