FiscAlert

Last updated: 26 August 2026 · Version 1.5

Data Processing Agreement

This Data Processing Agreement ("DPA") supplements and forms part of the FiscAlert Terms of Service between MERTENS WOUTER PERSOANĂ FIZICĂ AUTORIZATĂ, Str. FERVENȚIA Nr. 60, Sat Dumbrăvița, Com. Dumbrăvița, Jud. Timiș, Romania, CUI 51598945, ONRC F2025011913004 ("Data Processor") and you, the subscribing customer ("Data Controller").

This DPA applies where you, as a business or professional, use FiscAlert to process your personal data or your clients or businesses whose CUI or CNP you enter into the Service. It is intended to satisfy Article 28 GDPR, which requires a written agreement when a controller engages a processor.

1. Definitions

Terms not defined here have the meanings given in Regulation (EU) 2016/679 (GDPR) and Romanian Law 190/2018.

2. Subject Matter and Nature of Processing

FiscAlert processes personal data to:

3. Duration

Processing continues while the controller uses the Service and for the retention periods described in the Privacy Policy. Cancelling a subscription does not itself delete the account; account deletion can be requested through Settings, after which data is deleted, anonymised, or retained as described in the Privacy Policy.

Structured e-Factura dashboard metadata is retained only for the current and previous calendar month and is then automatically deleted. Original e-Factura XML/ZIP archives are not stored for the dashboard and are fetched from ANAF only when the controller requests a ZIP package.

4. Types of Personal Data

5. Categories of Data Subjects

6. Controller Obligations

The controller warrants that:

7. Processor Obligations

FiscAlert (as processor) will:

8. Sub-processors

The controller provides general authorisation for FiscAlert to engage the sub-processors listed in the Privacy Policy (Stripe, OpenAI, Brevo, and the infrastructure provider). We will give reasonable advance notice of intended additions or replacements, allowing the controller to object on reasonable data-protection grounds. Equivalent data-protection obligations are imposed on each sub-processor.

For OpenAI API: when the controller requests translation, summary, or a document answer, the requested complete PDF is sent to OpenAI. PDF processing may include extracted text and page images, including CNP and other personal data present in the document. OpenAI does not use API data to train models unless we explicitly opt in, and may retain prompts and outputs in abuse-monitoring logs for up to 30 days, or longer where required by law or reasonably necessary to protect its services or third parties.

9. International Transfers

Where personal data is transferred to sub-processors outside the European Economic Area (e.g., OpenAI, US), transfers are covered by Standard Contractual Clauses (Commission Decision 2021/914) and appropriate supplementary measures.

10. National Identification Data (CNP)

CNP is processed under the Article 6 lawful basis selected by the controller, subject to Article 87 GDPR and Law 190/2018 Article 4. The processor applies enhanced technical safeguards: AES-256 encryption at rest, deterministic HMAC index, and no logging of plaintext CNP in application logs or error traces.

11. Governing Law

This DPA is governed by Romanian law. Disputes shall be resolved by the courts of Timișoara, Romania.

12. Signed DPA for Corporate Customers

The terms above constitute a binding DPA upon account creation (click-through acceptance of the Terms of Service). Corporate customers requiring a wet-ink or qualified e-signature version should contact fiscalert.ro/contact to discuss the required format.