FiscAlert

Last updated: 26 August 2026 · Version 1.7

Privacy Policy

This Privacy Policy describes how we collect, use, store, and protect your personal data when you use our website and subscription service.

We are committed to compliance with Regulation (EU) 2016/679 (GDPR), Romanian Law No. 190/2018 on the Implementation of GDPR, and Law No. 506/2004 on the Processing of Personal Data in Electronic Communications.

1. Data Controller

MERTENS WOUTER PERSOANĂ FIZICĂ AUTORIZATĂ, Str. FERVENȚIA Nr. 60, Sat Dumbrăvița, Com. Dumbrăvița, Jud. Timiș, Romania. Contact us about privacy or data-protection matters at fiscalert.ro/contact.

2. Personal Data We Collect

2.1 Account data (collected at registration)

2.2 Fiscal entity data (provided by you after registration)

2.3 Document data (retrieved from ANAF on your behalf)

Fiscal documents (e-Factura XML, TVA declarations, SPV messages) retrieved from ANAF servers are cached in our database to avoid repeat queries. You may request deletion of cached documents at any time.

Dashboard and accounting packages. We store structured e-Factura metadata—company and counterparty names and CUIs, invoice number, direction, issue and due dates, currency, and totals—to calculate dashboard insights and prepare CSV/ZIP packages you request. Counterparty details may identify sole traders or other natural persons. This metadata is kept only for the current and previous calendar month. Original e-Factura XML/ZIP archives are not stored for the dashboard and are fetched from ANAF only when you request a ZIP package.

Forwarding documents by email. When you use Forward, we send the recipient you choose the selected original fiscal document and, if included, its AI summary and translation PDFs together with your optional note through our transactional-email processor, Brevo. These documents may contain a CNP and other personal or confidential fiscal data and leave the FiscAlert platform; verify that the recipient is authorised. If you choose to save a default recipient, we store that email address until you replace it or delete your account. Our audit log records the recipient address, document identifier and attachment names, but not attachment contents.

2.4 Billing data

Payment card details are handled exclusively by Stripe and never touch our servers. We store: Stripe customer ID, subscription ID, plan tier, invoice IDs, and invoice amounts for your billing history.

2.5 Technical data (collected automatically)

2.6 Audit log

We maintain an audit log of authentication events (login, logout, password reset), billing events (subscription created/changed/cancelled), and administrative actions. We retain the minimal audit record for up to 5 years to protect accounts, resolve billing disputes, demonstrate actions taken in the Service, and establish, exercise, or defend legal claims. This is separate from accounting records that we retain for the periods required by applicable Romanian accounting and tax law.

3. Legal Bases for Processing

PurposeLegal basis (GDPR Art. 6)
Providing the subscription serviceArt. 6(1)(b) — contract performance
Sending invoices and payment notificationsArt. 6(1)(c) — legal obligation
Application and billing audit logArt. 6(1)(f) — legitimate interests; Art. 6(1)(c) where a specific record is legally required
Security monitoring and abuse preventionArt. 6(1)(f) — legitimate interest
Consent-gated first-party acquisition analyticsArt. 6(1)(a) — consent; ePrivacy Art. 5(3)
Optional product tips and offers by emailArt. 6(1)(a) — express consent; Romanian Law 506/2004 Art. 12
Forwarding documents at your instructionArt. 6(1)(b) — contract performance
CNP processingApplicable Art. 6(1) basis for the requested service; Art. 87 GDPR and Law 190/2018 art. 4 safeguards

4. AI Processing (Document Translation & Summarisation)

When you request an AI translation, summary, or document answer, we send the requested complete PDF to the OpenAI API. PDF processing may include extracted text and page images, including CNP and other personal data present in the document. We apply the following safeguards:

5. Sub-Processors

Sub-processorPurposeLocationSafeguard
StripePayment processingEU (Ireland)SCCs + Stripe DPA
OpenAIAI document translation & summarisationUnited States and other processing locationsOpenAI DPA + SCCs
Brevo (Sendinblue SAS)Transactional email and requested document forwardingEU (France)Brevo DPA (GDPR Art. 28)
Render (Render Services, Inc.)Cloud infrastructure (servers, database)EU (Frankfurt)Render DPA + SOC 2 Type II

6. Data Retention

Data categoryRetention period
Account profile & entitiesUntil account deletion, then purged except for separately listed records that must remain
Cached ANAF documentsUntil account deletion or manual deletion, or automatically after 30 days
AI summaries, translations & document Q&AUntil account deletion or manual deletion, or automatically after 30 days
Document-check and alert-delivery metadata30 days
e-Factura dashboard invoice metadataCurrent and previous calendar month; removed automatically when older
Saved forwarding recipient addressUntil changed by you or account deletion
Stripe webhook payloadPayload removed after 30 days; minimal event and billing audit metadata retained for 5 years
Billing and application audit events5 years; IP address and user-agent removed after 30 days
Consumer withdrawal receipt & refund review5 years from receipt of the request
Access logs (IP, user-agent)30 days
Consent choice and first-/last-touch acquisition dataBrowser consent choice: up to 180 days; encrypted click identifier: 90 days; attribution and consented browser events: 180 days, or earlier on withdrawal/account deletion
Marketing email suppression HMACRetained after opt-out to honour the objection; removed after a new explicit opt-in or when no longer necessary
Session cookies24 hours (rolling)

7. Your Rights Under GDPR

You have the right to:

To exercise any right, email fiscalert.ro/contact. We will respond within 30 days. You may also lodge a complaint with the Romanian data protection authority (ANSPDCP) at www.dataprotection.ro.

8. Security Measures

9. International Transfers

Our primary infrastructure is located in the European Union. Where data is processed by sub-processors outside the EU (e.g., OpenAI, US), transfers are covered by Standard Contractual Clauses (SCCs) approved by the European Commission and supplementary technical measures.

10. Children

The Service is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has created an account, contact us and we will delete it promptly.

11. Changes to This Policy

We may update this policy. Material changes will be communicated by email at least 14 days before they take effect. Where the law requires consent for a change, we will ask for it separately.