Privacy Policy
Last updated: 28 August 2026
Who we are
This policy applies to the e-Romatrix application (e-Invoice and e-Transport). Operator: ROMATRIX SYSTEMS & TECHNOLOGIES SRL (VAT/CUI RO38271538, Trade Registry no. J02/1747/2017, EUID ROONRC.J02/1747/2017), registered office: Str. Mihai Viteazul nr. 1, et. Parter, ap. 13A, 317280 Sântana, Arad, Romania. Contact: office@romatrix.ro.
Data is stored in the databases and file locations configured for the installation (cloud or the customer’s server).
What we process
- Account data: user name, e-mail, password hash, language, roles/permissions, last sign-in.
- Company and partner data: name, tax ID, address, contact details, bank accounts, tax attributes.
- e-Invoice: issued/received invoice content, XML/PDF, SPV status, local or configured FTP archives.
- e-Transport: notifications (partner, carrier, vehicle, route, goods, documents), UIT code, SPV history and status.
- ANAF/JVS authorization: OAuth technical data and, if configured, certificates used to submit to SPV.
- Technical and audit logs (user, action, page, timestamp; IP/user-agent when needed).
- Activation and password-recovery e-mails; support messages you send to us.
We do not use analytics or marketing in this application.
Purposes & legal bases
- Providing the e-Invoice / e-Transport service and account administration — GDPR art. 6(1)(b) (contract).
- Submitting legally required invoices and transport declarations to ANAF/SPV — GDPR art. 6(1)(c) (legal obligation).
- IT security, abuse prevention, auditing — GDPR art. 6(1)(f) (legitimate interest).
- Support and communication (including e-mail) — art. 6(1)(b)/(f), as applicable.
Processors / recipients
- ANAF / Ministry of Finance (SPV, e-Invoice, e-Transport, JVS authorization), for the user company’s legal duties.
- Essential providers (hosting/infrastructure, SMTP), under GDPR art. 28 agreements where applicable.
- File storage configured by the customer (local disk and/or FTP), for XML/PDF archives.
Transfers outside the EEA
If applicable, we use Standard Contractual Clauses or equivalent safeguards.
Retention
- Accounts: duration of use + up to 12 months after closure.
- Operational data (companies, invoices, transports, files): for as long as the application is used and applicable legal/tax duties require.
- Technical/audit logs: 30–180 days (longer only for security incident investigation).
- Backups: rolling 30 days, if configured.
Your rights
Access, rectification, erasure, restriction, portability, objection, and not to be subject to solely automated decisions. Contact us at office@romatrix.ro. You may also lodge a complaint with ANSPDCP (Romania).