GDPR and data security policy

Last updated: 10 August 2026

1. Who is responsible for what

For your account data — name, email, preferences, access logs — WEB LOFT S.R.L. is the controller.

For the fiscal documents we read from SPV on your behalf, WEB LOFT S.R.L. is a processor. They are not our data; we process them solely on the authorisation you grant at ANAF, and only in order to alert you.

The privacy policy describes what we collect and why. This document describes how we keep it safe and what happens when something goes wrong.

2. Technical measures

All traffic is encrypted in transit (TLS). The site is not available over unencrypted HTTP.

ANAF access tokens are encrypted at rest with AES-256-GCM, under a key kept separate from the application key. An ANAF token opens a company's entire fiscal file, so it has to survive a key rotation independently and be revocable on its own.

XML documents downloaded from SPV are kept on a private disk that the web server never serves directly. They are reachable only through an authenticated request, checked against the tax ids you monitor.

Passwords are stored as hashes, never in plain text. You can enable two-factor authentication or a passkey.

3. Who else has access

The hosting provider running the application and the database.

The transactional email provider that carries the alerts. It sees the recipient address and the alert content.

The payment processor, for transactions. We neither receive nor store your card details.

The browsers' push notification services (Google, Mozilla, Apple), which carry the encrypted notification to your device. The content is not readable by them.

Google Analytics, only if you accept analytics cookies.

We do not sell data, do not rent it, and do not use it for advertising.

4. How long we keep it

Archived documents: for your plan's retention period, after which the file is deleted automatically. The row stays in the list, so you can still see the document existed.

Account data: until you delete your account, plus the periods tax and accounting law require for payment records.

ANAF call logs: kept because, holding the keys to a client's fiscal file, we must be able to say what we read and when.

5. Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent where processing rests on it.

You can disconnect SPV at any time from a button; we destroy the tokens locally and ask ANAF to invalidate the authorisation.

For anything concerning your data, write to , for the attention of Ciprian Mihalache. We answer within one month.

You may also contact Romania's data protection authority, ANSPDCP (dataprotection.ro), at any time.

6. Security incidents

If a breach occurs that poses a risk to your rights, we notify the supervisory authority within 72 hours of becoming aware of it.

If the risk is high, we tell you directly as well, at your account address, without undue delay.

7. Transfers outside the EU

The application and the database run inside the European Union.

The analytics and push notification providers may process data outside the European Economic Area, under the standard contractual clauses approved by the European Commission.

8. Data protection officer

We have not appointed a data protection officer. Our activity does not fall into the cases where the regulation requires one: we are not a public authority, the processing does not involve large-scale systematic monitoring of individuals, and we do not process special categories of data at scale.

Data requests are handled by Ciprian Mihalache, at .