ElectricalVPF ERP
RO|EN

Privacy Policy

Last updated: 30 August 2026

This policy explains what personal data ElectricalVPF ERP collects, why, for how long, who else may see it, and what rights you have under Regulation (EU) 2016/679 ("GDPR"). The data controller is fully identified in the Legal Notice.

Contents
  1. Data controller
  2. What data we collect
  3. Legal basis for processing
  4. Who else sees your data (processors)
  5. International data transfers
  6. How long we keep data
  7. Your rights
  8. Data security
  9. Minors
  10. Changes to this policy
  11. Contact

1. Data controller

The data controller under GDPR is ION DORU-VALENTIN PERSOANĂ FIZICĂ AUTORIZATĂ — see full identification and contact details in the Legal Notice.

OWNER INPUT REQUIRED: at the current operating scale there is no legal obligation to appoint a Data Protection Officer under Art. 37 GDPR. Re-assess with a GDPR consultant if user volume/processing scale grows significantly (large-scale processing, systematic monitoring).

2. What data we collect

We only collect data strictly necessary to operate the account and the service, verified directly against the application's database structure:

2.1 Account data (required)

  • Full name
  • Email address
  • Password — stored exclusively as a bcrypt cryptographic hash, never in plain text

2.2 Profile data (optional)

  • Phone number
  • An avatar chosen from a fixed icon gallery (no file/image upload)

2.3 Billing data for your Pro subscription

Payments are processed entirely by Stripe. We never store or see your full card details — see section 4.

2.4 Data YOU enter about YOUR OWN clients

ElectricalVPF ERP is a management tool for electrical contracting businesses. Data about the clients, projects, quotes and invoices you enter into your account (your clients' names, addresses, contact details) is your own business data — you are the controller of that data towards your clients, while ElectricalVPF ERP acts as a processor for its technical storage/processing.

2.5 Technical data collected automatically

  • IP address and connection information — processed at the infrastructure level (Cloudflare, Render), for security and fraud/abuse prevention
  • Technical server logs, for debugging and security

We do not use cookies or tracking technologies for behavioural analytics or advertising — see the Cookie Policy for full detail.

3. Legal basis for processing (Art. 6 GDPR)

  • Contract performance (Art. 6(1)(b)): account creation, authentication, ERP functionality, Pro subscription billing.
  • Legitimate interest (Art. 6(1)(f)): account security, fraud prevention, technical logging, service reliability.
  • Legal obligation (Art. 6(1)(c)): retention of financial records (invoices) under Romanian tax law.
  • Consent (Art. 6(1)(a)): only where explicitly and separately requested (we never bundle GDPR consent with acceptance of the Terms & Conditions).

4. Who else sees your data (processors)

  • Neon — PostgreSQL database hosting (EU region — Frankfurt / eu-central-1)
  • Render — backend application hosting
  • Cloudflare — frontend hosting, content delivery network (CDN), anti-bot protection (Turnstile) at login/registration
  • Stripe — payment processing for the Pro subscription
  • SMTP2GO — transactional email delivery (account confirmation, password reset, invoices, payment notifications)

We do not sell or rent your data to third parties for marketing purposes.

5. International data transfers

The database (Neon) runs in an EU region. Some providers (Cloudflare, Stripe) are US-headquartered companies that may process data outside the EEA within their global networks. These transfers rely on the safeguards required by GDPR for international transfers (Standard Contractual Clauses), per each provider's own privacy documentation.

OWNER INPUT REQUIRED: confirm directly with Stripe and Cloudflare (their public Data Processing Addenda) the exact transfer mechanism in effect at launch, and link their DPAs here if applicable.

6. How long we keep data

  • Account data: for as long as the account is active, plus a reasonable period afterwards for safety backups.
  • Financial records (invoices): per the legal fiscal archiving period under Romanian law.
  • Password-reset/email-confirmation tokens: expire automatically (1 hour and 24 hours respectively) and are invalidated after first use.
OWNER INPUT REQUIRED: define and document the exact post-deletion retention period here (recommended: confirm the applicable legal archiving term for financial records with an accountant).

7. Your rights

Under GDPR, you have the right to:

  • Access — view your account data from Settings → Account & Security.
  • Rectification — correct your profile data directly in Settings.
  • Erasure — from Settings → Privacy → Delete Account.
  • Portability/Export — from Settings → Privacy → Export Data.
  • Object to processing based on legitimate interest.
  • Withdraw consent, at any time, without affecting the lawfulness of processing before withdrawal.

You may also exercise any of these rights directly by email, at the address in the Contact section below. We respond within the legal 1-month timeframe.

8. Data security

  • Passwords stored exclusively as bcrypt hashes.
  • Authentication via JWT token, transmitted only via HTTP header (no session cookies).
  • Encrypted HTTPS connection across all traffic.
  • Anti-bot verification (Cloudflare Turnstile) at login/registration, against automated attacks.

9. Minors

ElectricalVPF ERP is intended exclusively for professionals (sole traders, companies) and is not directed at minors. We do not knowingly collect data from individuals under 18.

10. Changes to this policy

We may update this policy periodically. Material changes will be communicated by posting on this page, with the updated date in the header.

11. Contact

For any question about your personal data or to exercise your GDPR rights, contact us at the address in the Legal Notice.

Back to ElectricalVPF ERP