Privacy policy
Last updated: 9 August 2026
1. Controller and contact
The data controller is WEB LOFT S.R.L., Str. Buzoeni nr. 14, bl. M33, sc. 1, et. 7, ap. 45, Sector 5, București, 051195, România, tax identification number 44674942.
For anything concerning your personal data, write to , for the attention of Ciprian Mihalache.
2. Our two roles — and why it matters
For your account data (name, email, password, preferences, access logs) we are the controller.
For the fiscal documents we read from SPV on your behalf we are a processor. They are not our data; we process them solely on the authorisation you grant, and solely to send you the alerts you asked for.
That distinction is not a formality: it means we do not use the contents of your documents for anything else, do not analyse them in aggregate, and do not make them available to anyone else.
3. What we process
Account data: name, email address, password stored as a hash, language and notification preferences.
The ANAF authorisation: access and refresh tokens, stored encrypted with a dedicated key kept separate from the rest of the application. We do not store your digital certificate and have no access to it.
Metadata about SPV documents: ANAF identifier, tax identification number, type, date, and the description ANAF supplies. On plans with an archive, the invoice XML as well.
An access log: every call we make to ANAF — which tax id, which endpoint, when, with what outcome. We do not keep response bodies in that log.
Minimal technical data: IP address and browser agent, in server logs.
4. Basis and purpose
We process account data to perform the contract — that is, to provide the service you asked for.
We process SPV documents on the explicit authorisation you grant through ANAF, strictly to generate alerts.
We keep the access log on the basis of our legitimate interest in being able to show what we accessed and when, and in detecting abuse.
5. How long we keep it
Account data, for as long as the account exists. When you delete it we remove it, except what the law requires us to keep.
Archived XML files, according to your plan's retention, then deleted automatically. The record that the document existed remains.
ANAF tokens are destroyed the moment you ask to disconnect.
6. Who we share with
With ANAF, in the sense that we query them on your behalf, with your authorisation.
With the email provider through which we send your alerts, and with your browser's push notification service if you enable it. Push notifications carry only the company and the fact that a document appeared — never amounts or counterparties.
With our hosting provider. We do not sell data and do not use it for advertising.
7. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection under the GDPR. Write to and we will answer within 30 days at most.
You have the right to lodge a complaint with the Romanian data protection authority, ANSPDCP, at www.dataprotection.ro.
8. Security
ANAF tokens are encrypted with AES-256-GCM, using a key that is not the application key, so it can be rotated and revoked independently.
XML files are stored on a private disk, reachable only through your authenticated account and never directly from the web.
No measure is absolute. If a breach affects your data we will tell you and notify ANSPDCP within the legal deadlines.