Last updated: 26 August 2026 · Version 1.7
Privacy Policy
This Privacy Policy describes how we collect, use, store, and protect your personal data when you use our website and subscription service.
We are committed to compliance with Regulation (EU) 2016/679 (GDPR), Romanian Law No. 190/2018 on the Implementation of GDPR, and Law No. 506/2004 on the Processing of Personal Data in Electronic Communications.
1. Data Controller
MERTENS WOUTER PERSOANĂ FIZICĂ AUTORIZATĂ, Str. FERVENȚIA Nr. 60, Sat Dumbrăvița, Com. Dumbrăvița, Jud. Timiș, Romania. Contact us about privacy or data-protection matters at fiscalert.ro/contact.
2. Personal Data We Collect
2.1 Account data (collected at registration)
- Email address — used for login, transactional emails, and support.
- Password — stored as an argon2id hash. We never store or transmit the plaintext password.
- Preferred language — stored to localise the interface and AI translations.
- Display name (optional) — displayed in the UI only.
2.2 Fiscal entity data (provided by you after registration)
- CUI (Romanian fiscal code) — a public business identifier. We use it to query the ANAF SPV system on your behalf.
- CNP (Cod Numeric Personal, Romanian personal identification number) — treated as national identification data under Article 87 GDPR and Law 190/2018 Article 4. We store CNP AES-256 encrypted at rest using pgcrypto. A deterministic HMAC index is maintained for lookup; plaintext CNP never appears in application logs or error traces.
2.3 Document data (retrieved from ANAF on your behalf)
Fiscal documents (e-Factura XML, TVA declarations, SPV messages) retrieved from ANAF servers are cached in our database to avoid repeat queries. You may request deletion of cached documents at any time.
Dashboard and accounting packages. We store structured e-Factura metadata—company and counterparty names and CUIs, invoice number, direction, issue and due dates, currency, and totals—to calculate dashboard insights and prepare CSV/ZIP packages you request. Counterparty details may identify sole traders or other natural persons. This metadata is kept only for the current and previous calendar month. Original e-Factura XML/ZIP archives are not stored for the dashboard and are fetched from ANAF only when you request a ZIP package.
Forwarding documents by email. When you use Forward, we send the recipient you choose the selected original fiscal document and, if included, its AI summary and translation PDFs together with your optional note through our transactional-email processor, Brevo. These documents may contain a CNP and other personal or confidential fiscal data and leave the FiscAlert platform; verify that the recipient is authorised. If you choose to save a default recipient, we store that email address until you replace it or delete your account. Our audit log records the recipient address, document identifier and attachment names, but not attachment contents.
2.4 Billing data
Payment card details are handled exclusively by Stripe and never touch our servers. We store: Stripe customer ID, subscription ID, plan tier, invoice IDs, and invoice amounts for your billing history.
2.5 Technical data (collected automatically)
- Session cookie (
connect.sid) — strictly necessary for authentication. - IP address — retained in access logs for up to 30 days for security and abuse prevention.
- User-agent string — retained for 30 days for debugging.
2.6 Audit log
We maintain an audit log of authentication events (login, logout, password reset), billing events (subscription created/changed/cancelled), and administrative actions. We retain the minimal audit record for up to 5 years to protect accounts, resolve billing disputes, demonstrate actions taken in the Service, and establish, exercise, or defend legal claims. This is separate from accounting records that we retain for the periods required by applicable Romanian accounting and tax law.
3. Legal Bases for Processing
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the subscription service | Art. 6(1)(b) — contract performance |
| Sending invoices and payment notifications | Art. 6(1)(c) — legal obligation |
| Application and billing audit log | Art. 6(1)(f) — legitimate interests; Art. 6(1)(c) where a specific record is legally required |
| Security monitoring and abuse prevention | Art. 6(1)(f) — legitimate interest |
| Consent-gated first-party acquisition analytics | Art. 6(1)(a) — consent; ePrivacy Art. 5(3) |
| Optional product tips and offers by email | Art. 6(1)(a) — express consent; Romanian Law 506/2004 Art. 12 |
| Forwarding documents at your instruction | Art. 6(1)(b) — contract performance |
| CNP processing | Applicable Art. 6(1) basis for the requested service; Art. 87 GDPR and Law 190/2018 art. 4 safeguards |
4. AI Processing (Document Translation & Summarisation)
When you request an AI translation, summary, or document answer, we send the requested complete PDF to the OpenAI API. PDF processing may include extracted text and page images, including CNP and other personal data present in the document. We apply the following safeguards:
- Only the document you explicitly select for the requested AI feature is sent.
- Requests set provider-side application response storage to disabled; encrypted FiscAlert caches may retain the output to provide the feature.
- OpenAI does not use API data to train models unless we explicitly opt in. OpenAI may retain prompts and outputs in abuse-monitoring logs for up to 30 days, or longer where required by law or reasonably necessary to protect its services or third parties.
5. Sub-Processors
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe | Payment processing | EU (Ireland) | SCCs + Stripe DPA |
| OpenAI | AI document translation & summarisation | United States and other processing locations | OpenAI DPA + SCCs |
| Brevo (Sendinblue SAS) | Transactional email and requested document forwarding | EU (France) | Brevo DPA (GDPR Art. 28) |
| Render (Render Services, Inc.) | Cloud infrastructure (servers, database) | EU (Frankfurt) | Render DPA + SOC 2 Type II |
6. Data Retention
| Data category | Retention period |
|---|---|
| Account profile & entities | Until account deletion, then purged except for separately listed records that must remain |
| Cached ANAF documents | Until account deletion or manual deletion, or automatically after 30 days |
| AI summaries, translations & document Q&A | Until account deletion or manual deletion, or automatically after 30 days |
| Document-check and alert-delivery metadata | 30 days |
| e-Factura dashboard invoice metadata | Current and previous calendar month; removed automatically when older |
| Saved forwarding recipient address | Until changed by you or account deletion |
| Stripe webhook payload | Payload removed after 30 days; minimal event and billing audit metadata retained for 5 years |
| Billing and application audit events | 5 years; IP address and user-agent removed after 30 days |
| Consumer withdrawal receipt & refund review | 5 years from receipt of the request |
| Access logs (IP, user-agent) | 30 days |
| Consent choice and first-/last-touch acquisition data | Browser consent choice: up to 180 days; encrypted click identifier: 90 days; attribution and consented browser events: 180 days, or earlier on withdrawal/account deletion |
| Marketing email suppression HMAC | Retained after opt-out to honour the objection; removed after a new explicit opt-in or when no longer necessary |
| Session cookies | 24 hours (rolling) |
7. Your Rights Under GDPR
You have the right to:
- Access — request a copy of your personal data (use Settings → Account → Download data export).
- Rectification — correct inaccurate data via Settings → Profile.
- Erasure — delete your account and all associated data (Settings → Account → Delete account). Fiscal audit logs are exempt.
- Portability — download your data in machine-readable JSON format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — disable analytics or promotional email at any time in privacy settings; every marketing email also provides unsubscribe. For CNP processing, remove the CNP from entity settings. Prior lawful processing is not affected.
To exercise any right, email fiscalert.ro/contact. We will respond within 30 days. You may also lodge a complaint with the Romanian data protection authority (ANSPDCP) at www.dataprotection.ro.
8. Security Measures
- Passwords hashed with argon2id (OWASP 2024 parameters).
- CNP encrypted with AES-256 via pgcrypto; key managed separately from data.
- External network traffic is encrypted with TLS 1.2+ (HTTPS enforced); browser-to-local-bridge traffic stays on the loopback interface.
- Database encrypted at rest.
- Rate limiting on all authentication endpoints.
- Access to production systems restricted to authorised personnel according to least-privilege principles.
9. International Transfers
Our primary infrastructure is located in the European Union. Where data is processed by sub-processors outside the EU (e.g., OpenAI, US), transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission and supplementary technical measures.
10. Children
The Service is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.
11. Changes to This Policy
We may update this policy. Material changes will be communicated by email at least 14 days before they take effect. Where the law requires consent for a change, we will ask for it separately.