Privacy Policy
Last updated: 30 August 2026
This policy explains what personal data ElectricalVPF ERP collects, why, for how long, who else
may see it, and what rights you have under Regulation (EU) 2016/679 ("GDPR"). The data controller
is fully identified in the Legal Notice.
1. Data controller
The data controller under GDPR is ION DORU-VALENTIN PERSOANĂ FIZICĂ AUTORIZATĂ —
see full identification and contact details in the
Legal Notice.
OWNER INPUT REQUIRED: at the current operating scale there is no legal
obligation to appoint a Data Protection Officer under Art. 37 GDPR. Re-assess with a GDPR
consultant if user volume/processing scale grows significantly (large-scale processing,
systematic monitoring).
2. What data we collect
We only collect data strictly necessary to operate the account and the service, verified directly
against the application's database structure:
2.1 Account data (required)
- Full name
- Email address
- Password — stored exclusively as a bcrypt cryptographic hash, never in plain text
2.2 Profile data (optional)
- Phone number
- An avatar chosen from a fixed icon gallery (no file/image upload)
2.3 Billing data for your Pro subscription
Payments are processed entirely by Stripe. We never store or see your full card details — see
section 4.
2.4 Data YOU enter about YOUR OWN clients
ElectricalVPF ERP is a management tool for electrical contracting businesses. Data about the
clients, projects, quotes and invoices you enter into your account (your clients' names,
addresses, contact details) is your own business data — you are the controller
of that data towards your clients, while ElectricalVPF ERP acts as a processor for its technical
storage/processing.
2.5 Technical data collected automatically
- IP address and connection information — processed at the infrastructure level (Cloudflare,
Render), for security and fraud/abuse prevention
- Technical server logs, for debugging and security
We do not use cookies or tracking technologies for behavioural analytics or advertising — see the
Cookie Policy for full detail.
3. Legal basis for processing (Art. 6 GDPR)
- Contract performance (Art. 6(1)(b)): account creation, authentication, ERP
functionality, Pro subscription billing.
- Legitimate interest (Art. 6(1)(f)): account security, fraud prevention,
technical logging, service reliability.
- Legal obligation (Art. 6(1)(c)): retention of financial records (invoices)
under Romanian tax law.
- Consent (Art. 6(1)(a)): only where explicitly and separately requested (we
never bundle GDPR consent with acceptance of the Terms & Conditions).
4. Who else sees your data (processors)
- Neon — PostgreSQL database hosting (EU region — Frankfurt / eu-central-1)
- Render — backend application hosting
- Cloudflare — frontend hosting, content delivery network (CDN), anti-bot
protection (Turnstile) at login/registration
- Stripe — payment processing for the Pro subscription
- SMTP2GO — transactional email delivery (account confirmation, password
reset, invoices, payment notifications)
We do not sell or rent your data to third parties for marketing purposes.
5. International data transfers
The database (Neon) runs in an EU region. Some providers (Cloudflare, Stripe) are US-headquartered
companies that may process data outside the EEA within their global networks. These transfers
rely on the safeguards required by GDPR for international transfers (Standard Contractual
Clauses), per each provider's own privacy documentation.
OWNER INPUT REQUIRED: confirm directly with Stripe and Cloudflare (their public
Data Processing Addenda) the exact transfer mechanism in effect at launch, and link their DPAs
here if applicable.
6. How long we keep data
- Account data: for as long as the account is active, plus a reasonable
period afterwards for safety backups.
- Financial records (invoices): per the legal fiscal archiving period under
Romanian law.
- Password-reset/email-confirmation tokens: expire automatically (1 hour and
24 hours respectively) and are invalidated after first use.
OWNER INPUT REQUIRED: define and document the exact post-deletion retention
period here (recommended: confirm the applicable legal archiving term for financial records with
an accountant).
7. Your rights
Under GDPR, you have the right to:
- Access — view your account data from Settings → Account & Security.
- Rectification — correct your profile data directly in Settings.
- Erasure — from Settings → Privacy → Delete Account.
- Portability/Export — from Settings → Privacy → Export Data.
- Object to processing based on legitimate interest.
- Withdraw consent, at any time, without affecting the lawfulness of
processing before withdrawal.
You may also exercise any of these rights directly by email, at the address in the Contact section
below. We respond within the legal 1-month timeframe.
8. Data security
- Passwords stored exclusively as bcrypt hashes.
- Authentication via JWT token, transmitted only via HTTP header (no session cookies).
- Encrypted HTTPS connection across all traffic.
- Anti-bot verification (Cloudflare Turnstile) at login/registration, against automated
attacks.
9. Minors
ElectricalVPF ERP is intended exclusively for professionals (sole traders, companies) and is not
directed at minors. We do not knowingly collect data from individuals under 18.
10. Changes to this policy
We may update this policy periodically. Material changes will be communicated by posting on this
page, with the updated date in the header.
For any question about your personal data or to exercise your GDPR rights, contact us at the
address in the Legal Notice.