Privacy Policy
This policy explains which personal data we process, why, for how long, and what your rights are. It applies to the clientvault.pro website, to the shop, customer account, support and community operated on sdravobiz.com, and to the Client Vault WordPress plugin.
It is written pursuant to Regulation (EU) 2016/679 (“GDPR”), Legea nr. 190/2018 and Legea nr. 506/2004.
1. Who is responsible
Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 · EU VAT: RO51472369
Registrul Comerțului: J2025016522009
Email: contact@sdravobiz.com
Sdravobiz is not required to appoint a data protection officer under Article 37 GDPR: its activity involves neither large-scale processing of sensitive data nor large-scale systematic monitoring of individuals.
Any request can be sent to contact@sdravobiz.com, with “GDPR” in the subject line.
2. Two situations to tell apart
This is the most important point of this policy, and it is also the main difference between Client Vault and an online service.
Your own data, as a customer or visitor of our website. We are the controller: contact requests, demos, account, order, invoice, licence, support, emails. This is covered in articles 3 to 9.
The data of your own clients, stored in your vault. Documents, records, messages, appointments and journeys are stored in the database and on the hosting of your WordPress site. They never pass through our servers, are never sent to us and are not accessible to us. You alone are the controller, and we are neither controller nor processor. This is covered in article 10.
3. What we process, and why
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Order, licence and invoicing: account creation, performance of the contract, invoices, accounting obligations | Name, first name, company, address, email, VAT number, order and invoice history, licence key | Performance of a contract (art. 6.1.b) and legal obligation (art. 6.1.c) | Term of the contract, then 10 years under Legea nr. 82/1991 |
| Activation management: licence check, site count, delivery of updates | Licence key, address of activated sites, product ID, installed version, activation and check dates | Performance of a contract (art. 6.1.b); legitimate interest in protection against unauthorised use (art. 6.1.f) | Term of the licence, then 3 years |
| Payments: collection, fraud prevention, disputes and refunds | Billing details, transaction history and identifiers | Performance of a contract (art. 6.1.b); legitimate interest in fraud prevention (art. 6.1.f) | 10 years (accounting obligations) |
| Service emails: confirmation, invoice, licence key, update availability, renewal date, security incident | Name, email, account ID | Performance of a contract (art. 6.1.b) | Term of the contract, then legal archiving |
| Contact form: answering your request | Name, first name, email, subject, message, language, IP address and date sent | Legitimate interest in answering requests (art. 6.1.f); pre-contractual steps (art. 6.1.b) | 13 months after the last exchange |
| Booking a demo | Name, email, chosen time slot, information entered in the booking form | Pre-contractual steps at your request (art. 6.1.b) | 13 months after the demo |
| Support and customer relations | Name, email, content of exchanges, screenshots and environment reports you send us | Performance of a contract (art. 6.1.b); legitimate interest for prospects (art. 6.1.f) | 3 years after the last exchange (customers); 13 months (prospects) |
| Client Vault community: access to the help space, posts and replies | Display name, email, content of published messages | Performance of a contract (art. 6.1.b); consent for publication (art. 6.1.a) | Duration of participation, then 12 months |
| Newsletter and product news | Name, email, language, opens and clicks | Legitimate interest (art. 6.1.f) for customers, about a similar product, and for professionals who write to us through the contact form, about their business; consent (art. 6.1.a) in other cases | Until you unsubscribe, and at most 3 years after the last interaction |
| Protecting forms against bots | IP address, browser characteristics, interaction signals | Legitimate interest in website security (art. 6.1.f) | Duration of the check, under the provider’s rules |
| Audience and advertising measurement | Cookie identifiers, pages viewed, duration, traffic source, device and browser | Consent (art. 6.1.a) | 13 months (Google Analytics); 90 days (Meta) |
| Legal obligations and disputes | Invoices, supporting documents, connection data | Legal obligation (art. 6.1.c); legitimate interest in legal defence | Applicable legal period |
You can unsubscribe from our information emails at any time, in one click, using the link included in each of them, or by writing to contact@sdravobiz.com. Service emails related to your licence continue to be sent while the contract is in force.
We do not make any fully automated decision producing legal effects concerning you.
4. We do not sell your data
Sdravobiz does not sell, rent or transfer your personal data to third parties for commercial purposes.
Your data is only shared with the providers listed in article 5, with the competent administrative or judicial authorities upon lawful request, and with our advisers in the event of litigation.
5. Our providers
We use processors within the meaning of Article 28 GDPR, selected for their guarantees. This list may change.
| Provider | Role | Location | Transfer safeguards |
|---|---|---|---|
| Stripe Payments Europe, Ltd | Online payment, fraud prevention | Ireland (EU), servers in the United States for the group | Standard contractual clauses + EU-US Data Privacy Framework |
| o2switch | Hosting of the website, shop, customer account and licence server | France (EU) | No transfer outside the EU |
| Shop, licences and customer account (self-hosted) | Orders, subscriptions, licence keys, activations, invoices | France (EU) | Not applicable, self-hosted |
| Contact management, forms, appointments and emails (self-hosted) | Contact form, demo booking, service emails, newsletter | France (EU) | Not applicable, self-hosted |
| Support and community (self-hosted) | Support tickets, peer help space | France (EU) | Not applicable, self-hosted |
| Cloudflare, Inc. (Turnstile) | Protecting forms against bots | Global network, including the United States | Standard contractual clauses + EU-US Data Privacy Framework |
| Google Ireland Ltd (Analytics, Search Console) | Audience measurement and search monitoring | Ireland (EU), servers in the United States | Standard contractual clauses + EU-US Data Privacy Framework |
| Meta Platforms Ireland Ltd (Meta pixel) | Measuring the effectiveness of our ads | Ireland (EU), servers in the United States | Standard contractual clauses + EU-US Data Privacy Framework |
| Accountant and legal advisers | Accounting and legal obligations | Romania | Service contract, confidentiality clause |
None of these providers has access to the data you store with the plugin on your own site.
6. What the plugin sends to our servers
The plugin installed on your site communicates with our licence server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update checks.
On each of these occasions, and only then, your site sends exactly the following:
- the product ID;
- your licence key;
- the address of your site;
- the version number of the installed plugin;
- during licence checks, a single-use random value that prevents the response from being replayed.
Nothing else. In particular, the following are never sent: the documents stored in your vaults, the data of your clients and users, their email addresses, their messages, their appointments, their IP addresses, your settings, the content of your site, your administrator email address, the list of your plugins.
The plugin contains no telemetry and no usage statistics reporting.
Data sent to your webhooks, external backups, calendars and other tools goes from your server to the destinations you have entered yourself. It never passes through any server of the publisher.
7. Transfers outside the European Union
Our customer data is hosted in the European Union. The only transfers that may take place outside the European Economic Area concern our payment provider, the bot protection of our forms and our measurement tools, whose groups have infrastructure in the United States.
These transfers are governed by the safeguards of Chapter V GDPR: an adequacy decision where one exists (notably the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained on request at contact@sdravobiz.com.
The data you store with the plugin is not transferred by us in any way, since it never reaches us.
8. Your rights
You have the following rights (Articles 15 to 22 GDPR):
- access: find out whether we process data about you and obtain a copy;
- rectification: have inaccurate or incomplete data corrected;
- erasure: have it deleted, within the limits of our legal retention obligations;
- restriction: temporarily restrict processing;
- portability: receive your data in a structured, machine-readable format;
- objection: object to processing based on legitimate interest, and unconditionally to direct marketing;
- withdrawal of consent at any time, without affecting the lawfulness of earlier processing;
- instructions regarding your data after your death;
- complaint to a supervisory authority (article 13).
How to exercise them. By email to contact@sdravobiz.com (subject “GDPR”) or by post to our registered office. To prevent fraudulent requests, we may ask for proof of identity. We reply within one (1) month, which may be extended by two months depending on the complexity or number of requests (Article 12.3 GDPR).
If your documents or information are stored in the vault of a business using Client Vault and you wish to exercise your rights, please contact that business directly: it alone is the controller and it alone holds this data. We have no access to it and therefore can neither provide nor delete it.
9. Security
We implement the appropriate technical and organisational measures provided for in Article 32 GDPR, including: encrypted connections (HTTPS/TLS), payments handled by a PCI-DSS level 1 certified provider, strict access control and strong authentication on administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our processors.
The responses of our licence server and the update archives are cryptographically signed, and your site verifies the signature before use or installation.
No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 GDPR).
10. Your clients’ data stays with you
This article is addressed to you, as a customer, regarding the people whose data you store in Client Vault.
10.1 You alone are the controller
This data is stored in your own WordPress database and on your hosting. We do not receive it, host it, view it or restore it.
You alone determine the purposes and means of processing. It is up to you to inform your clients, define your legal bases and retention periods, publish your own privacy policy, collect the necessary consents and respond to requests to exercise rights. For this data, we are neither controller nor processor: we provide you with software, not a processing service.
10.2 What the plugin stores on your site
So that you can reuse it in your own policy, here is what Client Vault stores on your site:
- your clients’ and users’ accounts: name, email and the profile information you enter;
- documents stored in the vaults, encrypted on your server;
- messages, comments, notes, cards, links and content exchanged in the vaults;
- appointments and, depending on your use, progress through journeys;
- an audit log of actions performed: author, action, date and IP address.
10.3 What the plugin provides
- An exporter and an eraser registered with WordPress’s native tools: export and erasure requests you handle from the “Tools” screen of your site include the data stored by the plugin.
- Encryption of uploaded files, with a key kept outside the database.
- Temporary, single-use download links.
10.4 What is up to you
- Describe in your privacy policy the data listed in 10.2, its purposes, legal bases and retention periods.
- Do not store special categories of data within the meaning of Article 9 GDPR without a suitable legal basis and appropriate security measures.
- Declare the third-party content you embed in your vaults (videos, calendars, external forms): it is loaded directly by your users’ browsers from those services.
- Check what the tools you send this data to (webhooks, contact management, external backups) do with it: these transfers are processing for which you are responsible.
10.5 The only case where we see your data
If, as part of support, you send us a screenshot, an export or access to your site, we may be exposed to your clients’ data. We then act as a processor, on your one-off documented instruction, only for as long as needed to handle your request. These items are deleted when the ticket is closed, and at the latest within the three (3) years for which support exchanges are kept.
We recommend that you anonymise your screenshots before sending them to us.
11. Cookies
11.1 On our website
| Category | Tool | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Strictly necessary | WordPress session (wordpress_*) | Authentication, security | Session / 30 days | Legitimate interest, no consent |
| Strictly necessary | Language preference (pll_language) | Display language | 12 months | Legitimate interest, no consent |
| Strictly necessary | Cloudflare Turnstile | Telling humans from bots on forms | Duration of the check | Legitimate interest, no consent |
| Audience measurement | Google Analytics (_ga, _ga_*) | Traffic statistics | 13 months | Consent |
| Advertising measurement | Meta pixel (_fbp) | Measuring the effectiveness of our ads | 90 days | Consent |
| Functional / marketing | Email tracking (fcrm_*) | Opens and clicks on our emails | 12 months | Consent |
You can accept or refuse non-essential cookies at any time. Refusing them prevents neither access to the website nor viewing its content.
11.2 What the plugin sets in your users’ browsers
The plugin sets no cookie of its own in your users’ browsers. It uses your site’s WordPress login session.
12. Minors
Our website and product are not intended for minors under sixteen (16). We do not knowingly collect their data without the consent of the holder of parental responsibility (Article 8 GDPR). If we discover such data, we delete it without delay.
13. Complaints
If you believe that the processing of your data does not comply with the rules, you can contact the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro · anspdcp@dataprotection.ro · +40 318 059 211
If you live in another Member State, you can also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).
14. Changes
We may change this policy to reflect legal, regulatory, technical or contractual developments. The applicable version is the one published on the date you read it. In the event of a substantial change, we will inform you by a banner on the website or by email if you are a customer.
15. Contact
Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR) · contact@clientvault.pro (questions about Client Vault)
https://clientvault.pro
Last updated: 28 September 2026