VIP offer Lifetime license from €699 €399 Claim my seat

Privacy Policy

This policy explains which personal data we process, why, for how long, and what your rights are. It applies to the clientvault.pro website, to the shop, customer account, support and community operated on sdravobiz.com, and to the Client Vault WordPress plugin.

It is written pursuant to Regulation (EU) 2016/679 (“GDPR”), Legea nr. 190/2018 and Legea nr. 506/2004.

1. Who is responsible

Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 · EU VAT: RO51472369
Registrul Comerțului: J2025016522009
Email: contact@sdravobiz.com

Sdravobiz is not required to appoint a data protection officer under Article 37 GDPR: its activity involves neither large-scale processing of sensitive data nor large-scale systematic monitoring of individuals.

Any request can be sent to contact@sdravobiz.com, with “GDPR” in the subject line.

2. Two situations to tell apart

This is the most important point of this policy, and it is also the main difference between Client Vault and an online service.

Your own data, as a customer or visitor of our website. We are the controller: contact requests, demos, account, order, invoice, licence, support, emails. This is covered in articles 3 to 9.

The data of your own clients, stored in your vault. Documents, records, messages, appointments and journeys are stored in the database and on the hosting of your WordPress site. They never pass through our servers, are never sent to us and are not accessible to us. You alone are the controller, and we are neither controller nor processor. This is covered in article 10.

3. What we process, and why

PurposeDataLegal basisRetention
Order, licence and invoicing: account creation, performance of the contract, invoices, accounting obligationsName, first name, company, address, email, VAT number, order and invoice history, licence keyPerformance of a contract (art. 6.1.b) and legal obligation (art. 6.1.c)Term of the contract, then 10 years under Legea nr. 82/1991
Activation management: licence check, site count, delivery of updatesLicence key, address of activated sites, product ID, installed version, activation and check datesPerformance of a contract (art. 6.1.b); legitimate interest in protection against unauthorised use (art. 6.1.f)Term of the licence, then 3 years
Payments: collection, fraud prevention, disputes and refundsBilling details, transaction history and identifiersPerformance of a contract (art. 6.1.b); legitimate interest in fraud prevention (art. 6.1.f)10 years (accounting obligations)
Service emails: confirmation, invoice, licence key, update availability, renewal date, security incidentName, email, account IDPerformance of a contract (art. 6.1.b)Term of the contract, then legal archiving
Contact form: answering your requestName, first name, email, subject, message, language, IP address and date sentLegitimate interest in answering requests (art. 6.1.f); pre-contractual steps (art. 6.1.b)13 months after the last exchange
Booking a demoName, email, chosen time slot, information entered in the booking formPre-contractual steps at your request (art. 6.1.b)13 months after the demo
Support and customer relationsName, email, content of exchanges, screenshots and environment reports you send usPerformance of a contract (art. 6.1.b); legitimate interest for prospects (art. 6.1.f)3 years after the last exchange (customers); 13 months (prospects)
Client Vault community: access to the help space, posts and repliesDisplay name, email, content of published messagesPerformance of a contract (art. 6.1.b); consent for publication (art. 6.1.a)Duration of participation, then 12 months
Newsletter and product newsName, email, language, opens and clicksLegitimate interest (art. 6.1.f) for customers, about a similar product, and for professionals who write to us through the contact form, about their business; consent (art. 6.1.a) in other casesUntil you unsubscribe, and at most 3 years after the last interaction
Protecting forms against botsIP address, browser characteristics, interaction signalsLegitimate interest in website security (art. 6.1.f)Duration of the check, under the provider’s rules
Audience and advertising measurementCookie identifiers, pages viewed, duration, traffic source, device and browserConsent (art. 6.1.a)13 months (Google Analytics); 90 days (Meta)
Legal obligations and disputesInvoices, supporting documents, connection dataLegal obligation (art. 6.1.c); legitimate interest in legal defenceApplicable legal period

You can unsubscribe from our information emails at any time, in one click, using the link included in each of them, or by writing to contact@sdravobiz.com. Service emails related to your licence continue to be sent while the contract is in force.

We do not make any fully automated decision producing legal effects concerning you.

4. We do not sell your data

Sdravobiz does not sell, rent or transfer your personal data to third parties for commercial purposes.

Your data is only shared with the providers listed in article 5, with the competent administrative or judicial authorities upon lawful request, and with our advisers in the event of litigation.

5. Our providers

We use processors within the meaning of Article 28 GDPR, selected for their guarantees. This list may change.

ProviderRoleLocationTransfer safeguards
Stripe Payments Europe, LtdOnline payment, fraud preventionIreland (EU), servers in the United States for the groupStandard contractual clauses + EU-US Data Privacy Framework
o2switchHosting of the website, shop, customer account and licence serverFrance (EU)No transfer outside the EU
Shop, licences and customer account (self-hosted)Orders, subscriptions, licence keys, activations, invoicesFrance (EU)Not applicable, self-hosted
Contact management, forms, appointments and emails (self-hosted)Contact form, demo booking, service emails, newsletterFrance (EU)Not applicable, self-hosted
Support and community (self-hosted)Support tickets, peer help spaceFrance (EU)Not applicable, self-hosted
Cloudflare, Inc. (Turnstile)Protecting forms against botsGlobal network, including the United StatesStandard contractual clauses + EU-US Data Privacy Framework
Google Ireland Ltd (Analytics, Search Console)Audience measurement and search monitoringIreland (EU), servers in the United StatesStandard contractual clauses + EU-US Data Privacy Framework
Meta Platforms Ireland Ltd (Meta pixel)Measuring the effectiveness of our adsIreland (EU), servers in the United StatesStandard contractual clauses + EU-US Data Privacy Framework
Accountant and legal advisersAccounting and legal obligationsRomaniaService contract, confidentiality clause

None of these providers has access to the data you store with the plugin on your own site.

6. What the plugin sends to our servers

The plugin installed on your site communicates with our licence server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update checks.

On each of these occasions, and only then, your site sends exactly the following:

  • the product ID;
  • your licence key;
  • the address of your site;
  • the version number of the installed plugin;
  • during licence checks, a single-use random value that prevents the response from being replayed.

Nothing else. In particular, the following are never sent: the documents stored in your vaults, the data of your clients and users, their email addresses, their messages, their appointments, their IP addresses, your settings, the content of your site, your administrator email address, the list of your plugins.

The plugin contains no telemetry and no usage statistics reporting.

Data sent to your webhooks, external backups, calendars and other tools goes from your server to the destinations you have entered yourself. It never passes through any server of the publisher.

7. Transfers outside the European Union

Our customer data is hosted in the European Union. The only transfers that may take place outside the European Economic Area concern our payment provider, the bot protection of our forms and our measurement tools, whose groups have infrastructure in the United States.

These transfers are governed by the safeguards of Chapter V GDPR: an adequacy decision where one exists (notably the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained on request at contact@sdravobiz.com.

The data you store with the plugin is not transferred by us in any way, since it never reaches us.

8. Your rights

You have the following rights (Articles 15 to 22 GDPR):

  • access: find out whether we process data about you and obtain a copy;
  • rectification: have inaccurate or incomplete data corrected;
  • erasure: have it deleted, within the limits of our legal retention obligations;
  • restriction: temporarily restrict processing;
  • portability: receive your data in a structured, machine-readable format;
  • objection: object to processing based on legitimate interest, and unconditionally to direct marketing;
  • withdrawal of consent at any time, without affecting the lawfulness of earlier processing;
  • instructions regarding your data after your death;
  • complaint to a supervisory authority (article 13).

How to exercise them. By email to contact@sdravobiz.com (subject “GDPR”) or by post to our registered office. To prevent fraudulent requests, we may ask for proof of identity. We reply within one (1) month, which may be extended by two months depending on the complexity or number of requests (Article 12.3 GDPR).

If your documents or information are stored in the vault of a business using Client Vault and you wish to exercise your rights, please contact that business directly: it alone is the controller and it alone holds this data. We have no access to it and therefore can neither provide nor delete it.

9. Security

We implement the appropriate technical and organisational measures provided for in Article 32 GDPR, including: encrypted connections (HTTPS/TLS), payments handled by a PCI-DSS level 1 certified provider, strict access control and strong authentication on administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our processors.

The responses of our licence server and the update archives are cryptographically signed, and your site verifies the signature before use or installation.

No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 GDPR).

10. Your clients’ data stays with you

This article is addressed to you, as a customer, regarding the people whose data you store in Client Vault.

10.1 You alone are the controller

This data is stored in your own WordPress database and on your hosting. We do not receive it, host it, view it or restore it.

You alone determine the purposes and means of processing. It is up to you to inform your clients, define your legal bases and retention periods, publish your own privacy policy, collect the necessary consents and respond to requests to exercise rights. For this data, we are neither controller nor processor: we provide you with software, not a processing service.

10.2 What the plugin stores on your site

So that you can reuse it in your own policy, here is what Client Vault stores on your site:

  • your clients’ and users’ accounts: name, email and the profile information you enter;
  • documents stored in the vaults, encrypted on your server;
  • messages, comments, notes, cards, links and content exchanged in the vaults;
  • appointments and, depending on your use, progress through journeys;
  • an audit log of actions performed: author, action, date and IP address.

10.3 What the plugin provides

  • An exporter and an eraser registered with WordPress’s native tools: export and erasure requests you handle from the “Tools” screen of your site include the data stored by the plugin.
  • Encryption of uploaded files, with a key kept outside the database.
  • Temporary, single-use download links.

10.4 What is up to you

  • Describe in your privacy policy the data listed in 10.2, its purposes, legal bases and retention periods.
  • Do not store special categories of data within the meaning of Article 9 GDPR without a suitable legal basis and appropriate security measures.
  • Declare the third-party content you embed in your vaults (videos, calendars, external forms): it is loaded directly by your users’ browsers from those services.
  • Check what the tools you send this data to (webhooks, contact management, external backups) do with it: these transfers are processing for which you are responsible.

10.5 The only case where we see your data

If, as part of support, you send us a screenshot, an export or access to your site, we may be exposed to your clients’ data. We then act as a processor, on your one-off documented instruction, only for as long as needed to handle your request. These items are deleted when the ticket is closed, and at the latest within the three (3) years for which support exchanges are kept.

We recommend that you anonymise your screenshots before sending them to us.

11. Cookies

11.1 On our website

CategoryToolPurposeDurationLegal basis
Strictly necessaryWordPress session (wordpress_*)Authentication, securitySession / 30 daysLegitimate interest, no consent
Strictly necessaryLanguage preference (pll_language)Display language12 monthsLegitimate interest, no consent
Strictly necessaryCloudflare TurnstileTelling humans from bots on formsDuration of the checkLegitimate interest, no consent
Audience measurementGoogle Analytics (_ga, _ga_*)Traffic statistics13 monthsConsent
Advertising measurementMeta pixel (_fbp)Measuring the effectiveness of our ads90 daysConsent
Functional / marketingEmail tracking (fcrm_*)Opens and clicks on our emails12 monthsConsent

You can accept or refuse non-essential cookies at any time. Refusing them prevents neither access to the website nor viewing its content.

11.2 What the plugin sets in your users’ browsers

The plugin sets no cookie of its own in your users’ browsers. It uses your site’s WordPress login session.

12. Minors

Our website and product are not intended for minors under sixteen (16). We do not knowingly collect their data without the consent of the holder of parental responsibility (Article 8 GDPR). If we discover such data, we delete it without delay.

13. Complaints

If you believe that the processing of your data does not comply with the rules, you can contact the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro · anspdcp@dataprotection.ro · +40 318 059 211

If you live in another Member State, you can also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).

14. Changes

We may change this policy to reflect legal, regulatory, technical or contractual developments. The applicable version is the one published on the date you read it. In the event of a substantial change, we will inform you by a banner on the website or by email if you are a customer.

15. Contact

Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR) · contact@clientvault.pro (questions about Client Vault)
https://clientvault.pro

Last updated: 28 September 2026