🇷🇴 Română · 🇬🇧 English

Your GDPR rights — Zephren

How to exercise the rights guaranteed by EU Regulation 2016/679 (GDPR) and Law 190/2018 (RO).

1. Who is responsible?

Data controller: ZEPHREN S.R.L. (CUI 54561142, J2026027529009), registered office B-dul Libertății nr. 38 ap. 4, Bușteni, Prahova county, Romania.

Natural person whose data is processed (data subject): you — an MDLPA-certified energy auditor or the end client of an audit (property owner, beneficiary of renovation works).

Person responsible for data protection (informal DPO): legal@zephren.ro. (Zephren is not required to appoint a formal DPO under Art. 37 GDPR, but we treat GDPR correspondence with the highest priority.)

2. Your full rights

The GDPR guarantees you 7 fundamental rights. All are exercised free of charge and we respond within a maximum of 30 days (with a 2-month extension only for complex requests, under Art. 12).

Art. 15Access

You have the right to obtain confirmation that we process your data and to receive a copy of that data together with information about the purposes, categories, recipients and retention periods.

Example: “I want a complete export of all the data you hold about me, in JSON format.”

Art. 16Rectification

You have the right to obtain the correction of inaccurate data or the completion of incomplete data, without undue delay.

Self-serve in Settings → Account → Profile for email, name and company. For other fields, please contact us.

Art. 17Erasure (“right to be forgotten”)

You have the right to ask us to erase your data under certain conditions (data no longer necessary, withdrawal of consent, objection to processing, etc.).

Exception: tax invoices are retained for 10 years under the Fiscal Code art. 25 para. (1). We partially anonymise them (removing personal data beyond the legally required minimum).

Art. 18Restriction of processing

You have the right to ask us to temporarily stop processing your data (e.g. you contest its accuracy or the processing is unlawful but you do not want erasure).

Example: “Is the data about my audits correct? Please stop processing it until I have verified it.”

Art. 20Portability

You have the right to receive your data in a structured, commonly used and machine-readable format (JSON or CSV), in order to transmit it to another controller if you wish.

Useful if you migrate to other EPC software — we provide a complete JSON export of your projects + auditor settings.

Art. 21Objection

You have the right to object to processing based on legitimate interest or for direct marketing purposes. For direct marketing, the objection is absolute.

Example: unsubscribe from the MDLPA newsletter directly via the link in the email, or notify us at legal@zephren.ro.

Art. 22Automated decisions, including profiling

You have the right not to be subject to a decision based solely on automated processing that produces legal effects.

Zephren does NOT make automated decisions with legal effect about you (we do not block your account automatically, we do not refuse services by algorithm). Technical calculations (energy class, EPC) are assisted by a human auditor — the auditor signs and certifies.

3. How to submit a request

You have 3 options available:

  1. Direct email: legal@zephren.ro — we confirm receipt within 72 hours, complete within 30 days.
  2. Pre-filled form (below) — generates an email with the recommended structure, which you can send with a single click.
  3. Directly in your Zephren account (for authenticated users) — Settings → Security → GDPR requests (implementation in progress in the Cloud-First Sprint).

4. GDPR request form

The click will open your email application with the pre-filled message. Check the recipient address (legal@zephren.ro) and press Send.

5. Our obligations (Art. 12 GDPR)

  • Response deadline: 30 days from receipt of the request (extension of up to 2 months with prior notice, only for complex requests — e.g. multi-project export)
  • Response format: same as the request channel (email for email requests)
  • Free of charge: the first request is always free. For manifestly unfounded or excessive (repetitive) requests we may charge a reasonable fee or refuse, with justification
  • Identification: we may request additional information to confirm your identity (e.g. account email confirmation)
  • Reasons for refusal: if we refuse a request, we inform you of the reason and of your right to lodge a complaint with ANSPDCP

6. Our sub-processors

To provide the Service, we transmit data to 13 sub-processors (Vercel, Supabase, Stripe, Anthropic, Cloudflare, Resend, Sentry, PostHog, UptimeRobot, Gotenberg, Microsoft, SmartBill, Google). All have a DPA signed under Art. 28 GDPR.

See the full list in the Privacy Policy, section 4 →

7. International transfers

Some of the sub-processors are established outside the EEA (e.g. Vercel, Supabase US-region optional, Anthropic US, Sentry US). Transfers are carried out on the basis of the Standard Contractual Clauses (SCC) adopted by the European Commission (Decision 2021/914) and, where applicable, the EU-US Data Privacy Framework (DPF) certification.

All the details are listed comprehensively in the Privacy Policy. For specific objections to transfers to a particular jurisdiction, please contact us.

8. Complaint to the supervisory authority

If you are not satisfied with the way we handle your request, you have the right to lodge a complaint with the Romanian national supervisory authority:

ANSPDCP — the Romanian National Supervisory Authority for Personal Data Processing

You also have the right to a judicial remedy (Art. 79 GDPR) — the competent courts are those of your habitual residence (user) or those of the controller's registered office (RO).

9. Related information

Last updated: 27 May 2026. Document provided as is. For legal interpretation we recommend consulting a lawyer specialised in GDPR. In case of any discrepancy, the Romanian version prevails.

Folosim cookies

Folosim cookie-uri esențiale pentru funcționarea aplicației (sesiune, preferințe). Cu acordul dumneavoastră adăugăm cookie-uri de analiză (PostHog EU, Sentry) și de marketing (GDPR Art. 7).

Dacă refuzați, nu se scrie și nu se citește nimic pe dispozitivul dumneavoastră — nici cookie-uri, nici stocare locală — iar monitorizarea erorilor (Sentry) rămâne complet oprită. Continuăm totuși să numărăm, agregat, vizitele și acțiunile din aplicație, fără să vă identificăm, fără profil de utilizator și fără să vă putem recunoaște la o vizită următoare. Detalii și temeiul juridic în Politica de confidențialitate și în Politica de cookie-uri.