Direct Consulting & Advertising SRL (CUI RO15938781) treats personal data protection as a strategic priority. This page summarizes our commitments regarding Regulation (EU) 2016/679 (GDPR) and Law 190/2018, both as a controller (data collected via the website) and as a processor (data processed for clients of the Elevio One platform).
1. Applied GDPR Principles
- Lawfulness, fairness, transparency — each processing has a documented legal basis and is clearly described in the Privacy Policy.
- Purpose limitation — data is used only for stated purposes.
- Data minimization — we collect only what is strictly necessary.
- Accuracy — we update and correct data upon request.
- Storage limitation — clearly defined retention periods.
- Integrity and confidentiality — encryption, access control, auditing.
- Accountability — complete documentation of processing activities (Record of Processing Activities according to Art. 30 GDPR).
2. Technical and Organizational Measures
Technical
- TLS 1.3 encryption for all communications.
- Encryption at rest for the database and stored files.
- Row-Level Security (RLS) — each client sees strictly their own organization's data.
- SHA-256 hashing for sensitive identifiers (e.g., IP addresses in anti-fraud logs).
- Daily encrypted backup, retained for 30 days.
- Continuous monitoring, security alerts, audit log.
- Periodic patching of dependencies (Dependabot policies / vulnerability scanning).
Organizational
- Non-Disclosure Agreement (NDA) for all collaborators.
- Access based on the "need-to-know" principle.
- Periodic training of the team on data protection.
- Procedure for notifying security incidents to ANSPDCP within 72 hours (Art. 33).
- Impact assessments (DPIA) for new high-risk processing (Art. 35).
3. Data Localization and Transfers
Data is stored in the European Union (data centers of our providers: Lovable Cloud / Supabase, proprietary SMTP infrastructure hosted in Romania).
For services where transfer to the US is unavoidable (e.g., Google Analytics, Meta Pixel — only with consent), we apply the EU-US Data Privacy Framework and/or Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR).
4. Data Subject Rights
Please refer to the "Your Rights" section of the Privacy Policy for the complete list (access, rectification, erasure, portability, objection, withdrawal of consent, ANSPDCP complaint).
For any request, write to dpo@elevioone.io. We respond within a maximum of 30 days.
5. Data Processing Agreement (DPA) for Clients
As a SaaS provider (Elevio One), we process personal data on behalf of our clients (accounting firms, entrepreneurs). For this processing, we sign a Data Processing Agreement (DPA) according to Art. 28 GDPR, an integral part of the service contract.
The DPA includes:
- Object, duration, nature, and purpose of processing.
- Categories of data and data subjects.
- Obligations and rights of the controller-client.
- List of sub-processors and the notification mechanism for their change.
- Applied security measures.
- Assistance with data subject requests.
- Notification of security incidents to the controller within 24 hours.
- Return or deletion of data at the end of the contract.
- Audit and compliance verification.
To receive the DPA in editable form (PDF + .docx), write to dpo@elevioone.io.
6. Sub-processors
The list of sub-processors with access to data is regularly updated and is part of the DPA. The main sub-processors are:
- Lovable Cloud / Supabase — database, authentication, edge functions (EU).
- DirectHosting — SMTP infrastructure for transactional emails (RO).
- Google LLC — analytics (only with consent).
- Meta Platforms Ireland Ltd. — marketing pixel (only with consent).
7. Data Protection Officer (DPO)
Single point of contact for any data protection matter: dpo@elevioone.io.
8. Supervisory Authority
National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, 010336
Email: anspdcp@dataprotection.ro
Web: www.dataprotection.ro