This policy explains how Direct Consulting & Advertising SRL (CUI RO15938781), headquartered in Bd. Basarabia 98, etaj 1, Bucharest, Romania, as a personal data operator, processes the data of Users of the elevioone.io website and the Elevio One platform, in accordance with Regulation (EU) 2016/679 (GDPR) and Law 190/2018.
1. Data Operator
Direct Consulting & Advertising SRL
CUI: RO15938781
Headquarters: Bd. Basarabia 98, etaj 1, Bucharest, Romania
DPO / Data Protection Officer Email: dpo@elevioone.io
2. What data we collect
2.1 Data provided directly by you
- Newsletter: email address.
- Demo / lead / partners form: name, email, phone, company, optional number of clients and free message.
- ROI Calculator: operational parameters (number of documents, rates, times). This data is only saved if you choose to send the result via the demo form.
- Direct communications: the content of messages you send us by email.
2.2 Automatically collected data
- Technical data: IP address (stored hashed for anti-fraud protection), browser type, operating system, accessed pages, session duration, traffic source.
- Cookies and similar technologies: according to the Cookie Policy. Non-essential cookies are only loaded after your explicit consent.
3. Purposes and legal bases of processing
| Purpose | Data | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Response to demo / contact requests | Name, email, phone, company, message | Art. 6(1)(b) — pre-contractual measures |
| Sending newsletter | Art. 6(1)(a) — consent (double opt-in) | |
| Partner enrollment / referral | Name, email, phone, company | Art. 6(1)(b) — performance of partner contract |
| ROI Calculator (estimates) | Entered parameters | Art. 6(1)(f) — legitimate interest (providing useful tool) |
| Site security, abuse prevention | Hashed IP address, user-agent | Art. 6(1)(f) — legitimate interest |
| Analytics / usage statistics | Analytics cookies, anonymous events | Art. 6(1)(a) — consent |
| Marketing and remarketing | Marketing cookies (Meta Pixel) | Art. 6(1)(a) — consent |
| Legal obligations (fiscal, accounting) | Billing data | Art. 6(1)(c) — legal obligation |
4. Recipients and transfers
Your data may be accessed by the following processors:
- Lovable Cloud / Supabase (backend infrastructure, database, authentication, edge functions) — data stored in the EU.
- Own SMTP provider (DirectHosting / mail.elevioone.io) — for sending transactional emails and newsletters.
- Google LLC (Google Analytics) — only if you have accepted analytics cookies; anonymized IP.
- Meta Platforms Ireland Ltd. (Meta Pixel) — only if you have accepted marketing cookies.
- Public authorities — when we have a legal obligation to disclose data.
For transfers to the USA (Google, Meta), we rely on the EU-US Data Privacy Framework and/or Standard Contractual Clauses (SCC) approved by the European Commission, in accordance with Art. 46 GDPR.
5. Storage period
- Lead / demo: 24 months from the last interaction.
- Newsletter: until unsubscribe (link in each email).
- Partners: for the duration of the contractual relationship + 5 years (fiscal obligations).
- Security logs: 12 months.
- Cookies: according to the Cookie Policy.
- Billing data: 10 years (Fiscal Code).
6. Your rights (GDPR)
As a data subject, you have the following rights:
- Right of access (Art. 15) — a copy of the data we hold about you.
- Right to rectification (Art. 16) — correction of inaccurate data.
- Right to erasure / "right to be forgotten" (Art. 17).
- Right to restriction of processing (Art. 18).
- Right to portability (Art. 20) — receiving data in a structured format.
- Right to object (Art. 21) — especially for direct marketing.
- Right to withdraw consent at any time, without affecting the legality of prior processing.
- Right to lodge a complaint with the ANSPDCP (National Supervisory Authority for Personal Data Processing) — www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Bucharest.
To exercise any right, write to us at dpo@elevioone.io. We will respond within a maximum of 30 days.
7. Security
We apply technical and organizational measures to protect data: TLS 1.3 encryption in transit, encryption at rest, access control (Row-Level Security), log auditing, hashing for IP addresses, data minimization principle, data protection impact assessment (DPIA) where applicable.
8. Automated decisions
We do not make automated decisions that produce legal effects concerning you, without human intervention (Art. 22 GDPR).
9. Minors
The Elevio One website and platform are aimed at professionals (B2B) and are not intended for persons under 16 years of age. We do not knowingly collect data about minors.
10. Changes
This policy may be updated periodically. The current version is the one published on the Site, with the last update date mentioned above.