Privacy Policy
Preamble
This Privacy Policy informs users of the site https://clientvault.pro/en/ (hereinafter the “Site”) and clients of the Client Vault plugin (hereinafter the “Data Subjects”) about the processing methods of their personal data by the company Sdravobiz S.R.L., as the data controller.
It is drafted in accordance with Regulation (EU) 2016/679 of April 27, 2016 (GDPR), Law no. 190/2018 (Romanian law implementing the GDPR), and Law no. 506/2004 on data processing in the electronic communications sector.
Article 1 — Data Controller
The data controller for information collected via the Site is:
- Company Name: Sdravobiz S.R.L.
- Legal Form: Societate cu Răspundere Limitată (S.R.L.)
- Registered Office: Strada Trandafirilor 51, 307220 Giroc, Romania
- CUI / Unique Registration Code: RO51412367
- Registration at the Trade Register: J2025016522009
- VAT Number (RO): RO51412367
- Contact Email: contact@clientvault.pro
- Website: https://clientvault.pro/en/
Article 2 — Data Protection Officer (DPO)
Sdravobiz S.R.L. is not required to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR, as its activities do not fall under the scenarios provided for in this article: its core activities consist neither of large-scale processing of sensitive data nor of systematic and large-scale monitoring of individuals.
Any request regarding personal data may nevertheless be sent to contact@clientvault.pro, by mentioning “GDPR” in the subject line to facilitate processing.
Article 3 — Purposes, legal bases, and data categories
Sdravobiz S.R.L. processes the personal data of Data Subjects for the following purposes:
3.1 Sale and performance of the Contract
- Purpose: Processing of Orders, issuance of invoices, delivery of the license key, management of the client account and technical support.
- Legal basis: Performance of a contract to which the Data Subject is a party (Article 6.1.b GDPR); legal obligation (Article 6.1.c GDPR) for accounting and tax obligations.
- Data categories: surname, first name, postal address, email address, intra-community VAT number if applicable, identifier of the activated WordPress site, order and invoice history, support exchanges.
- Retention period: for the duration of the contractual relationship and for ten (10) years after the end of the relationship under Romanian accounting obligations (Legea nr. 82/1991 on accounting). Support data: three (3) years after the last exchange.
3.2 Payment management
- Purpose: Payment collection, anti-fraud verification, dispute management, and refunds.
- Legal basis: Performance of the contract (Article 6.1.b GDPR); legitimate interest of the data controller regarding fraud prevention (Article 6.1.f GDPR).
- Data categories: Billing details, transaction history, technical transaction identifiers. No banking data (card number, CVV) is stored by Client Vault; this data is collected and processed directly by the payment service provider Stripe (see Article 4).
- Retention period: Ten (10) years for accounting obligations.
3.3 Transactional communication
- Purpose: Sending emails related to the Order (confirmation, invoice, license key, Product update notifications, license expiration).
- Legal basis: Performance of the contract (Article 6.1.b GDPR).
- Data categories: Last name, first name, email address, license identifier.
- Retention period: For the duration of the contractual relationship, followed by legal archiving.
3.4 Newsletter and marketing communication
- Purpose: Sending commercial information, product news, usage tips, and promotional offers.
- Legal basis: Explicit consent of the Data Subject (Article 6.1.a GDPR) collected at the time of registration, or legitimate interest for existing customers regarding a similar product (Article 13 of Directive 2002/58/EC as transposed by Article 12 para. 3 of Legea nr. 506/2004).
- Categories of data: surname, first name, email address, communication language, potential behavioral data (visited pages, email opens and clicks).
- Retention period: until consent is withdrawn, and no later than three (3) years after the last active interaction (open, click, visit).
- Right of withdrawal: the Data Subject may withdraw their consent at any time via the unsubscribe link present in every email or by writing to contact@clientvault.pro.
3.5 Audience measurement and Site improvement
- Purpose: Statistical analysis of traffic, optimization of the user journey, measurement of marketing and SEO performance.
- Legal basis: Consent (Article 6.1.a GDPR) for tools placing non-strictly necessary cookies; legitimate interest for strictly anonymized audience measurement.
- Categories of data: IP address (anonymized), session identifier, visited pages, visit duration, traffic source, device and browser type.
- Tools: Google Analytics 4, Google Search Console (see Article 4 for transfers).
- Retention period: in accordance with GA4 settings, generally fourteen (14) months for user data.
3.6 Customer support and relationship management
- Purpose: Responding to inquiries, handling complaints, and tracking satisfaction.
- Legal basis: Performance of a contract (Article 6.1.b GDPR) or legitimate interest (Article 6.1.f GDPR) for non-client contacts.
- Data categories: Last name, first name, email, content of communications, and screenshots provided by the Data Subject.
- Retention period: three (3) years after the ticket is closed for clients, thirteen (13) months for prospects.
3.7 Compliance with legal obligations
- Purpose: Retention of invoices, accounting records, and connection logs in the event of a judicial request.
- Legal basis: Legal obligation (Article 6.1.c GDPR).
- Retention period: in accordance with applicable Romanian legal obligations (generally ten years for accounting and tax matters).
Article 4 — Sub-processors and recipients
To provide the service, Client Vault S.R.L. uses sub-processors within the meaning of Article 28 of the GDPR, selected for their guarantees regarding data protection. The list below is subject to change.
| Sub-processor | Service rendered | Data processed | Location | Transfer safeguards |
|---|---|---|---|---|
| Stripe Payments Europe, Ltd | Online payment, anti-fraud | Identity, email, transaction, card data (at Stripe only) | Ireland (EU); US servers for Stripe Inc. group | Standard Contractual Clauses + EU-US Data Privacy Framework |
| o2switch | Site and database hosting | All Site data | France (EU) | No transfer outside the EU |
| Google Ireland Ltd (Analytics 4, Search Console) | Audience measurement, SEO tracking | Anonymized IP, technical identifiers, behavior | Ireland (EU); US servers | Standard Contractual Clauses + EU-US Data Privacy Framework |
| FluentCRM (self-hosted) | Newsletter and marketing email management | Email, name, email behavior | Hosted at o2switch (EU) — no transfer to third parties | Not applicable (self-hosted) |
| FluentCart (self-hosted) | Order and license management | Identity, address, transactions, licenses | Hosted at o2switch (EU) — no transfer to third parties | Not applicable (self-hosted) |
| Accountant / legal counsel | Accounting and legal obligations | Billing data | Romania | Service contract, confidentiality clause |
Sdravobiz S.R.L. does not sell, rent, or lease the personal data of Data Subjects to third parties for commercial purposes.
Data may be disclosed to:
- competent Romanian administrative or judicial authorities, upon legal request;
- in the event of litigation, legal counsel and court-appointed officials acting on behalf of Sdravobiz.
Article 5 — Data transfers outside the European Union
Certain subcontractors listed in Article 4 may process or store data in countries located outside the European Economic Area (notably the United States for Stripe Inc. and Google LLC).
These transfers are governed by the safeguards provided in Chapter V of the GDPR:
- Adequacy decision from the European Commission when the country benefits from such a decision (notably the EU-US Data Privacy Framework for certified organizations in the United States);
- Standard Contractual Clauses (SCCs) adopted by the European Commission, supplemented where necessary by additional measures (encryption, pseudonymization);
- Binding Corporate Rules (BCR) where they exist within the subcontractor’s group.
A copy of these safeguards can be obtained upon request at contact@clientvault.pro.
Article 6 — Rights of the Data Subjects
In accordance with Articles 15 to 22 of the GDPR and Law no. 190/2018, every Data Subject has the following rights:
- Right of access (Article 15 GDPR): obtain confirmation that your personal data is being processed and obtain a copy of it;
- Right to rectification (Article 16 GDPR): have inaccurate or incomplete data corrected;
- Right to erasure (Article 17 GDPR), known as the “right to be forgotten”: obtain the deletion of data, within the limits of legal retention obligations;
- Right to restriction of processing (Article 18 GDPR): temporarily restrict processing in certain circumstances;
- Right to portability (Article 20 GDPR): receive your data in a structured, commonly used, and machine-readable format, or have it transmitted to another controller;
- Right to object (Article 21 GDPR): object to processing based on legitimate interests for reasons relating to your particular situation; object unconditionally to processing for direct marketing purposes;
- Right to withdraw consent at any time when processing is based on consent (Article 7.3 GDPR), without this withdrawal affecting the lawfulness of processing carried out prior to it;
- Right not to be subject to automated decision-making producing legal effects or significantly affecting the individual (Article 22 GDPR);
- Right to define directives regarding the fate of your data after your death, in accordance with applicable national law;
- Right to lodge a complaint with the competent supervisory authority (cf. Article 11).
Procedures for exercising rights
These rights may be exercised by email at contact@clientvault.pro (mentioning “GDPR” in the subject line) or by postal mail to the registered office of Sdravobiz S.R.L. indicated in Article 1.
For security reasons and to avoid any fraudulent communication, Sdravobiz may request proof of identity before responding to a request, in compliance with the principle of data minimization. A response will be provided within one (1) month of receipt of the request, which may be extended by two months depending on the complexity or the number of requests (Article 12.3 GDPR).
Article 7 — Data security
Sdravobiz S.R.L. implements appropriate technical and organizational measures to ensure the security and confidentiality of personal data, in accordance with Article 32 of the GDPR, including:
- encryption of connections to the Site (HTTPS / TLS);
- encryption of payments (Stripe, PCI-DSS Level 1 compliant);
- strict access control to information systems (strong authentication on administrator accounts);
- logging of access to sensitive data;
- regular database backups;
- regular security updates for software and plugins;
- training and awareness for individuals with access to data;
- contractual confidentiality commitments with subcontractors.
In the event of a personal data breach likely to result in a risk to the rights and freedoms of the Data Subjects, Client Vault undertakes to notify the breach to the ANSPDCP within seventy-two (72) hours and, where applicable, to inform the Data Subjects directly, in accordance with Articles 33 and 34 of the GDPR.
Article 8 — Cookies and trackers
8.1 Definition
A cookie is a small file placed on the user’s device when visiting the Site. It is used, in particular, to store preferences, authenticate the session, measure audience, or offer personalized content.
8.2 Cookies used on the Site
| Category | Cookie / tool | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Strictly necessary | WordPress session (wordpress_*) | Authentication, security | Session / 30 days | Legitimate interest (without consent) |
| Strictly necessary | Polylang language preference (pll_language) | Display language | 12 months | Legitimate interest (without consent) |
| Strictly necessary | Light / dark theme preference | User comfort | Persistent (localStorage) | Legitimate interest (without consent) |
| Audience measurement | Google Analytics 4 (_ga, _ga_*) | Anonymized statistics | 13 months | Consent |
| Marketing / functional | FluentCRM tracking (fcrm_*) | Email open and click tracking | 12 months | Consent |
8.3 Consent management
During the first visit to the Site, a consent banner allows the user to accept, refuse, or configure cookies that are not strictly necessary, in accordance with Article 5.3 of Directive 2002/58/EC and Article 4 of Law no. 506/2004.
The user may modify their preferences at any time via the “Manage my cookies” link accessible at the bottom of each page of the Site.
Refusing cookies that are not strictly necessary does not prevent access to the Site or the consultation of its content, but may alter certain auxiliary features (audience measurement, personalized recommendations).
Article 9 — Protection of minors
The Site and the Product are not intended for minors under sixteen (16) years of age. Sdravobiz S.R.L. does not knowingly collect personal data concerning minors under sixteen (16) years of age without the prior consent of the holder of parental responsibility, in accordance with Article 8 of the GDPR.
If Sdravobiz discovers that it has collected such data without consent, it will proceed to delete it without delay. Any holder of parental responsibility may send a deletion request to contact@clientvault.pro.
Article 10 — Data processed by the Client Vault plugin at the Client’s premises
The Client Vault Product is designed to be installed on the Client’s WordPress server. In this context:
- Sdravobiz S.R.L. has no access to the personal data processed by the Client through the Product (documents uploaded by end users, exchanges between the Client and their own clients, etc.). Sdravobiz is neither a data controller nor a data processor for this data.
- The Client is the sole data controller within the meaning of the GDPR for the data they collect and process via their installation of the Product. It is their responsibility to define the purposes, legal bases, retention periods, and security measures, and to fulfill their obligations regarding information and the respect of data subjects’ rights for their own users.
- The Product only transmits to Sdravobiz the data strictly necessary for license verification (license key, activation domain, installed version) and for delivering updates. This data is processed for the performance of the Contract (Article 3.1).
Sdravobiz remains available to Clients who wish to document, for example via a Privacy Notice Plugin intended for their own users, the exact scope of data exchanged with Sdravobiz as part of the licensing mechanism.
Article 11 — Complaints to the supervisory authority
Any Data Subject who believes that the processing of their personal data does not comply with regulations may lodge a complaint with the Romanian supervisory authority:
National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru no. 28-30, sector 1, Bucharest, postal code 010336
Website: https://www.dataprotection.ro
Email: anspdcp@dataprotection.ro
Phone: +40.318.059.211
Data subjects residing in another EU Member State may also file a complaint with their national supervisory authority (e.g., the CNIL in France, the AEPD in Spain, the Garante per la protezione dei dati personali in Italy, the CNPD in Portugal, the BfDI in Germany, etc.).
Article 12 — Changes to the Privacy Policy
Sdravobiz S.R.L. reserves the right to modify this Privacy Policy at any time to reflect legal, regulatory, technical, or contractual developments.
The applicable version is the one published on the Site on the date of access. In the event of a substantial change, Sdravobiz commits to informing data subjects by any appropriate means (banner on the Site, email for clients).
The last update date is indicated at the bottom of this document.
Article 13 — Contact
For any questions regarding this Privacy Policy or the exercise of rights provided by the GDPR:
Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
Email: contact@clientvault.pro
Site: https://clientvault.pro/en/
Document effective as of May 1, 2026. Last updated: May 1, 2026.