Free onboarding for the first 10 accounting firms enrolled in July.Reserve your spot →

    GDPR Compliance

    Elevio One's commitment to personal data protection: principles, measures, rights, and data processing agreement (DPA) for clients.

    Last update: April 21, 2026

    Direct Consulting & Advertising SRL (CUI RO15938781) treats personal data protection as a strategic priority. This page summarizes our commitments regarding Regulation (EU) 2016/679 (GDPR) and Law 190/2018, both as a controller (data collected via the website) and as a processor (data processed for clients of the Elevio One platform).

    1. Applied GDPR Principles

    • Lawfulness, fairness, transparency — each processing has a documented legal basis and is clearly described in the Privacy Policy.
    • Purpose limitation — data is used only for stated purposes.
    • Data minimization — we collect only what is strictly necessary.
    • Accuracy — we update and correct data upon request.
    • Storage limitation — clearly defined retention periods.
    • Integrity and confidentiality — encryption, access control, auditing.
    • Accountability — complete documentation of processing activities (Record of Processing Activities according to Art. 30 GDPR).

    2. Technical and Organizational Measures

    Technical

    • TLS 1.3 encryption for all communications.
    • Encryption at rest for the database and stored files.
    • Row-Level Security (RLS) — each client sees strictly their own organization's data.
    • SHA-256 hashing for sensitive identifiers (e.g., IP addresses in anti-fraud logs).
    • Daily encrypted backup, retained for 30 days.
    • Continuous monitoring, security alerts, audit log.
    • Periodic patching of dependencies (Dependabot policies / vulnerability scanning).

    Organizational

    • Non-Disclosure Agreement (NDA) for all collaborators.
    • Access based on the "need-to-know" principle.
    • Periodic training of the team on data protection.
    • Procedure for notifying security incidents to ANSPDCP within 72 hours (Art. 33).
    • Impact assessments (DPIA) for new high-risk processing (Art. 35).

    3. Data Localization and Transfers

    Data is stored in the European Union (data centers of our providers: Lovable Cloud / Supabase, proprietary SMTP infrastructure hosted in Romania).

    For services where transfer to the US is unavoidable (e.g., Google Analytics, Meta Pixel — only with consent), we apply the EU-US Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR).

    4. Data Subject Rights

    Please refer to the "Your Rights" section of the Privacy Policy for the complete list (access, rectification, erasure, portability, objection, withdrawal of consent, ANSPDCP complaint).

    For any request, write to dpo@elevioone.io. We respond within a maximum of 30 days.

    5. Data Processing Agreement (DPA) for Clients

    As a SaaS provider (Elevio One), we process personal data on behalf of our clients (accounting firms, entrepreneurs). For this processing, we sign a Data Processing Agreement (DPA) according to Art. 28 GDPR, an integral part of the service contract.

    The DPA includes:

    • Object, duration, nature, and purpose of processing.
    • Categories of data and data subjects.
    • Obligations and rights of the controller-client.
    • List of sub-processors and the notification mechanism for their change.
    • Applied security measures.
    • Assistance with data subject requests.
    • Notification of security incidents to the controller within 24 hours.
    • Return or deletion of data at the end of the contract.
    • Audit and compliance verification.

    To receive the DPA in editable form (PDF + .docx), write to dpo@elevioone.io.

    6. Sub-processors

    The list of sub-processors with access to data is regularly updated and is part of the DPA. The main sub-processors are:

    • Lovable Cloud / Supabase — database, authentication, edge functions (EU).
    • DirectHosting — SMTP infrastructure for transactional emails (RO).
    • Google LLC — analytics (only with consent).
    • Meta Platforms Ireland Ltd. — marketing pixel (only with consent).

    7. Data Protection Officer (DPO)

    Single point of contact for any data protection matter: dpo@elevioone.io.

    8. Supervisory Authority

    National Supervisory Authority for Personal Data Processing (ANSPDCP)
    B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, 010336
    Email: anspdcp@dataprotection.ro
    Web: www.dataprotection.ro

    SEE LIVE DEMO

    Ready to close the month in 5–7 days?

    30-minute live demo · No commitment · Live in 5–7 business days. We get back to you within 24h.

    • Free onboarding for the first 10 firms in July 2026
    • Native integrations: SAGA, WinMentor, Pluriva, SAP
    • Data stored in the EU · GDPR compliant
    hello [at] elevioone.io +40 749 997 699
    1/2

    Leave us your contact

    Just 2 fields to start. The rest comes after.

    We reply within <2h on business daysNo card · No commitment · 30-min demo

    No spam. We only contact you for the demo. Data stored in the EU · GDPR.

    Newsletter

    Insights for accountants — no spam

    Subscribe and receive a unique 5% discount code for the Elevio One + CRMConnect integration.

    Double opt-in · GDPR compliant · Unsubscribe anytime in one click.