Time & attendance · for Romanian plants

TAI Pontaj: From card punches to a payroll-ready month.

  • Runs on your own server and reads the card or turnstile terminals you already use (checked in the audit).
  • Romanian rules built in — anomalies are flagged for a person to decide, never penalised automatically.
  • No fingerprints or face templates: card, PIN or QR. GDPR by design.

from €900 setup per site
+ €90/month care

Sample data · simulation The product, clickable: four roles, anomaly flags, an audit log and a payroll CSV — nothing leaves your browser.

The interactive demo needs JavaScript. It shows one sample month for Demo Plant SRL in four roles — Employee, Supervisor, HR and Auditor — with masked national ID numbers, anomaly flags, approvals, an audit log and a sample payroll CSV.

Demo Plant SRL, every name and every ID number here are fictional. The codes are examples; in an installation they follow your own rules.

How it works

From raw punches to payroll — four layers you can inspect.

  1. Raw punchesPunches arrive read-only from your card or turnstile terminals and are stored as received. A correction is a separate entry with who, when and why; the original stays.
  2. Rules you can readYour shifts, breaks, night hours (22:00–06:00)7, leave codes and Romanian public holidays — including the movable ones7 — applied as explicit rules you can read and change.
  3. One timesheet gridPer person, per day, per month. Anomalies are flagged for a person to decide: a punch on a leave day, a missing clock-out, night hours.
  4. Payroll exportThe month closes into the file your payroll or accountant already imports; its column layout is set up during installation.
  5. SealedNational ID numbers encrypted and masked, every reveal logged, supervisors see only their own team.

What's included · pricing

Flat price per site, by size band — no per-employee fee.

Start here

€120 pontaj audit

Send one month of terminal logs, your current pontaj and your payroll input file (pseudonymised is fine). In five working days: the differences, whether your terminals can be connected, and a fixed quote. Credited in full against setup.

€120credited in full against setup

Book the €120 pontaj audit

Group

200+ people or several sites

from€3,500setup

+ from €290/month care

Start with the audit

Setup includes

  • Installation on your server
  • Read-only connector to your terminals
  • Leave-code, shift, holiday and night-hour rules
  • Monthly export in your payroll's file layout
  • Employee import
  • Two training sessions (HR and supervisors)
  • The three GDPR templates

Care includes

  • Updates
  • A monthly health and backup-restore check
  • Holiday and code updates when the law changes
  • Remote support in business hours

Not included

  • Terminals, cards and turnstiles
  • The server and its operating-system licence

Founding plants — 2 places

Setup at 50%, the first three months of care at half price, care price fixed for 24 months. In return: a documented before-and-after, fifteen minutes a month, an honest review.

Apply for a founding place

Indicative prices in EUR · final offer in writing.

Not ready to share data? Let's talk

Tolga Şahin, founder of TAI Solutions

Who you'll be dealing with

Set up and maintained by one person you can call.

Nearly eight years in procurement, in IT since July 2025.

Three rules: a dry run before any data change · every figure traceable to a source · AI-built work always disclosed as AI-assisted.

For HR, legal and your director

The details — folded. Open only what you need.

Why now — what Romanian law asks for

Labour Code · EU Court · data authority

The law asks for a daily record. Excel turns it into a monthly rebuild.

Labour Code · art. 119 · 260

A daily record

Romanian employers must keep, at the workplace, a daily record of each employee's start and end times and show it to labour inspectors whenever asked.1 Missing it is a contravention fined 1,500–3,000 lei.2 Breaching the overtime rules is fined 1,500–3,000 lei for each person found working overtime.2

EU Court of Justice · C-55/18

Objective, reliable, accessible

The EU Court of Justice held that Member States must require employers to set up an objective, reliable and accessible system that measures each worker's daily working time.3

ANSPDCP · 2019 · 2026

How you record matters

How you record time is a risk of its own. In 2019 Romania's data protection authority fined an employer €5,000 for using employees' fingerprints for access to restricted areas when less intrusive means were available.4 In March 2026 it warned a company that planned face recognition for employee access although cards were already in use.5

TAI Pontaj is built for exactly this: the record the law asks for, from the cards you already use — and nothing more.

All 12 features — and how you can check each one

most of them in the demo above

01

Read-only connector to your card or turnstile terminals

Punches arrive by themselves; nothing is ever written to your devices.

How you can check Confirmed on your own terminals in the €120 audit, before you pay for setup.

02

Romanian rules built in: leave codes, night hours 22:00–06:00, public holidays including Easter and Rusalii

No custom coding for the basics.

How you can check Labour Code art. 125 and 1397 — and in the demo.

03

Monthly pontaj generated from punches, leave, approved overtime and holidays

HR stops retyping the month.

How you can check Demo: approve a month and export it.

04

Export in your payroll's file layout

Your accountant imports it without retyping.

How you can check Set up and tested against one past month of yours during installation.

05

Anomaly flags, not accusations

HR decides; the software never penalises anyone.

How you can check Demo: punch on a leave day, missing clock-out, night hours.

06

Morning roll-call for supervisors

Who is in, late or missing — people on leave are not marked absent.

How you can check Demo: switch to "Supervisor".

07

Shift and overtime planning with approval

Approved overtime lands in the timesheet by itself.

How you can check Demo: approve overtime as "Supervisor".

08

Leave requests with a visible balance

Employees see what they have left before they ask.

How you can check Demo: switch to "Employee".

09

Four roles: Employee · Supervisor · HR · Auditor

Each role sees only what it needs; supervisors see only their team.

How you can check Demo: switch roles.

10

National ID numbers (CNP) encrypted and masked

A copied database does not reveal ID numbers.

How you can check Demo: "Reveal" writes a line to the audit log.

11

Audit trail

Who did what and when — approvals, exports, ID reveals, permission changes.

How you can check Demo: live audit log panel.

12

Romanian, English and Turkish interface

Shop floor in Romanian, office in English, management in Turkish.

How you can check Demo: page language — RO · TR.

GDPR by design — what is built in, article by article

10 points · 3 templates

What is recorded — and on what legal basis

  1. Art. 5(1)(c)
    Only what the law asks for.

    Daily start and end times per employee — no photos, no location, no biometrics.

  2. Art. 9 · Art. 4(14)
    No biometric templates.

    The software never stores fingerprints or face templates. Card, PIN or QR.

  3. Art. 6(1)(c) · recital 43
    The right legal basis, pre-mapped.

    The record rests on your legal obligation under Labour Code art. 119 — not on employee consent, which is rarely freely given at work.

Who sees what — and how it is protected

  1. Art. 25(2)
    Private by default.

    Supervisors see only their own team; national ID numbers are hidden unless a role truly needs them.

  2. Art. 32(1)(a)
    Encryption where it matters.

    National ID numbers are encrypted at field level; revealing one takes a separate permission and is logged.

  3. Art. 5(2)
    Accountability.

    An audit trail of sensitive actions: logins, approvals, exports, ID reveals, permission changes.

Retention, employees' rights and contracts

  1. Art. 5(1)(e) · Art. 17
    Retention you set, deletion that happens.

    You set how long each record type is kept, with your DPO if you have one; TAI Pontaj applies it and logs each deletion. Reference point: accounting records, payroll included, are kept for 5 years (Law 82/1991, art. 25)6 — no period specific to attendance records was found.

  2. Art. 15
    Employees can see their own hours.

    In their own view; a full copy of their data can be exported by HR on request.

  3. Art. 22
    People decide, not the software.

    Anomalies are flags for a person; there are no automatic penalties and no AI scoring of people.

  4. Art. 28
    A processor contract before any access.

    If I access your data — for the audit or for maintenance — we sign a data processing agreement first; when we part, I delete or return the data.

Templates

  • Data processing agreement · Art. 28
  • DPIA template · Art. 35
  • Employee information notice · Art. 13

Every installation comes with three templates to adapt with your DPO or lawyer: a data processing agreement (GDPR Art. 28), a DPIA template (Art. 35) and an employee information notice (Art. 13). Templates, not legal advice.

You, the employer, remain the data controller and decide how the system is used. I help you meet your obligations; I can't meet them for you. Article numbers refer to the GDPR.8

What TAI Pontaj does not do

8 limits, on purpose
  • No fingerprints, face templates or clock-in photos stored by the software.
  • No location tracking.
  • No screen, keystroke, webcam or e-mail monitoring.
  • No AI scoring, ranking or "productivity" profiling of people — and no emotion detection, which is prohibited at work in the EU (AI Act, Art. 5(1)(f)).
  • No automatic penalties: a person always decides.
  • No selling or reuse of your data; I process it only on your written instructions.
  • No certification badge. GDPR certification is voluntary and applies to processing operations, not to software — I won't claim one.
  • No dependence on the internet to run: data stays on your server; only what you choose (for example e-mail notifications through your own mail server) leaves the building.

Brief for your director — one printable page

forward or print

TAI Pontaj on one page.

A summary you can forward or print. Every line comes from this page.

What it is
Time & attendance installed on your own server. It connects to the card or turnstile terminals you already use — confirmed in the audit — applies your shift, leave and overtime rules, and closes each month into the file your payroll already imports.
Why now
Romanian employers must keep, at the workplace, a daily record of each employee's start and end times and show it to labour inspectors whenever asked (Labour Code, art. 119(1)). Missing it is a contravention fined 1,500–3,000 lei (art. 260(1)(m)).
First step
The €120 audit: one month of terminal logs, your current pontaj and your payroll input file (pseudonymised is fine). In five working days: the differences, whether your terminals can be connected, and a fixed quote. Credited in full against setup.
Price
TAI Pontaj prices by site size
SizeSetupCare
Workshop · up to 50 people€900€90/month
Plant · 51–200 people€1,900€190/month
Group · 200+ people or several sitesfrom €3,500from €290/month

Flat price per site, by size band — no per-employee fee. Indicative prices in EUR · final offer in writing.

Where the data is
On your server, in your building. I connect only for agreed maintenance, and only after we have signed a data processing agreement (GDPR Art. 28).
Setup includes
Installation on your server · read-only connector to your terminals · leave-code, shift, holiday and night-hour rules · monthly export in your payroll's file layout · employee import · two training sessions (HR and supervisors) · the three GDPR templates.
Care includes
Updates · a monthly health and backup-restore check · holiday and code updates when the law changes · remote support in business hours.
Not included
Terminals, cards and turnstiles · the server and its operating-system licence.
What it does not do
No fingerprints, face templates or clock-in photos stored · no location tracking · no screen, keystroke, webcam or e-mail monitoring · no AI scoring of people · no automatic penalties — a person always decides.
Who you'll deal with
Tolga Şahin — one person who sets it up, trains HR and supervisors, and maintains it — in Romanian, English or Turkish.

Sources: Labour Code (Law 53/2003), art. 119(1) and art. 260(1)(m) — legislatie.just.ro · Regulation (EU) 2016/679 (GDPR), Art. 28 — eur-lex.europa.eu. General information, not legal advice.

Tolga Şahin · +40 752 494 070 · tolga@taisolutions.net

More questions — retention, DPIA, AI Act, consent

7 answers
How long must we keep attendance records?

I found no retention period in Romanian law that is specific to attendance records. Accounting records and supporting documents, payroll included, are kept for 5 years from 1 July of the year after the financial year ends (Law 82/1991, art. 25).6 Unpaid-wage claims can be brought within 3 years (Labour Code art. 268(1)(c)). You set the retention per record type, with your DPO if you have one; TAI Pontaj applies it.

Do we need a DPIA?

It depends on your scale and setup. The Romanian authority's list requires one for large-scale, systematic monitoring of employees by automated means, among other cases.10 The package includes a DPIA template; whether you need a full DPIA is your decision as controller, after seeking your DPO's advice where one is designated (GDPR Art. 35(2)).

Is this an AI system under the EU AI Act?

TAI Pontaj applies rules that people write and can read; it does not score or profile people. AI used to monitor and evaluate workers is high-risk under the AI Act, with obligations from 2 December 2027.9 That is one reason TAI Pontaj has no AI scoring of people.

Do employees have to consent?

The attendance record rests on your legal obligation (GDPR Art. 6(1)(c) with Labour Code art. 119), not on consent. Employees must still be informed (GDPR Art. 13); the notice template covers that.

Can employees see their own hours?

Yes, in their own view. HR can export a full copy of an employee's data on request (GDPR Art. 15).

Is there an official approval for attendance software?

Not that I could find: neither the labour inspectorate nor the data protection authority runs an approval scheme for it, and I won't claim one.

Who will we be dealing with?

Me, Tolga Şahin: one person who sets it up, trains HR and supervisors, and maintains it — in Romanian, English or Turkish.

Sources (10)

legislatie.just.ro · eur-lex · dataprotection.ro

FAQ

Before you ask

Do we need new hardware?

Usually not, if your card or turnstile terminals keep a readable log. The €120 audit checks this on your own terminals before you commit. If they can't be read, I'll tell you, and what the options are.

Will it work with our payroll software?

If your payroll program or accountant imports a file, the monthly export is set up in that file's column layout during installation and tested against one of your past months. The audit looks at your current payroll input file first; if your program cannot import a file, I'll tell you there.

Where is the data?

On your server, in your building. I connect only for agreed maintenance, and only after we have signed a data processing agreement (GDPR Art. 28).

Our terminals use fingerprints or faces. Can we keep them?

TAI Pontaj never stores fingerprints or face templates; it works with card, PIN or QR. If a terminal verifies faces or fingerprints, that biometric processing happens in the terminal and stays your responsibility as controller — and the Romanian authority has acted against biometric systems at work where less intrusive means existed.4 5 In the audit we look at switching the terminal to card or PIN.

What do we show the labour inspector?

The daily record the law asks for: each person's start and end times, per day and per month — exportable to Excel or CSV at any time. The Auditor role gives read-only access. There is no official approval scheme for attendance software, and I won't claim one.

What happens if we stop?

Your data is already on your server, and everything exports to Excel or CSV at any time. When we part, I delete or return anything I hold (GDPR Art. 28(3)(g)).

Answers are general information, not legal advice. You remain the data controller. More questions ↑

Start with one month of your own data.

Send one month of terminal logs and your current pontaj — pseudonymised is fine. In five working days you'll see the differences, whether your terminals connect, and a fixed quote. €120, credited in full against setup. Before I look at any personal data, we sign a short data processing agreement.

Not sure yet? Let's talk