Privacy Policy — Zephren
Version 1.6.0 · In force since 19 August 2026.
1. Data Controller
ZEPHREN S.R.L., registered office at B-dul Libertății, no. 38, ap. 4, Bușteni, Prahova county, Romania. Company ID (CUI): 54561142 | Trade Registry: J2026027529009.
Data Protection Contact: legal@zephren.ro.
Data Protection Officer (DPO): ZEPHREN is not legally required to appoint a formal DPO under Art. 37 GDPR (fewer than 250 employees, and its core activity does NOT consist of large-scale systematic monitoring or processing of special categories of data). Nevertheless, we have designated a dedicated contact person for all GDPR requests, reachable at legal@zephren.ro, with a guaranteed response within 30 days (Art. 12(3) GDPR). Should ANSPDCP formally request the appointment of a certified DPO, we will comply within the indicated timeframe.
2. Categories of personal data processed
Zephren processes the following data categories:
- Auditor account data: email, password (stored as bcrypt hash), name, company, UI preferences.
- Auditor professional data: MDLPA certification number, category I/II, signature image, stamp image.
- End client data (audit subject) (entered by the auditor with the explicit consent of their client): name, surname, email, phone, building address, GPS coordinates, cadastral number, land registry, building photographs, utility bills.
- Project technical documentation uploaded for verification (project verification module): written and drawn documents — drawings, sections, technical reports, product datasheets. These may contain data concerning third parties, i.e. persons other than you (names and contact details of the developer, of the designers and of the economic operators, the construction address, the information in the drawing title block), as well as commercially sensitive information. You upload them in your capacity as a certified project verifier, under your contract with your client; they are transmitted to the AI model provider for analysis (see section 4) and are not stored on Zephren servers once the request has been processed.
- Project verification log: verification report number and date, project name, developer, designer, verified requirement. It is saved locally, in the browser of your device and — when you are signed in — it is also mirrored to your account on Supabase servers in the European Union, so that it survives a browser cleanup or a move to another computer. The mirror is visible only to you (row-level isolation, tied to your account), can be exported and is deleted together with your account. The local copy is erased automatically when a different account signs in on the same device and disappears if you clear the site data in your browser. The log may contain third-party data (developer, designer, construction address); for these you remain the controller and Zephren processes them as a processor, under the Article 28 GDPR agreement.
- Payment data: VAT ID (B2B Romania), VAT number (B2B EU), billing address. Card data is processed exclusively by Stripe and is not stored by Zephren.
- Technical data: IP address, user-agent, authentication logs and a device identifier — a randomly generated number created and kept in your browser, which tells your devices apart when projects are synchronised and, when the 7-day trial is started, serves to prevent abuse. It is not derived from the characteristics of your equipment and does not allow you to be recognised on other websites. All of these are processed for security and fraud prevention.
- Context of a report: when you submit a report through the feedback form, we automatically attach the page and step you were on, the application version, a few signals about what happened just before (no text written by you) and a screenshot. Sensitive fields — passwords, personal ID numbers, IBANs, the building address, the beneficiary, contact details — are blanked out before the screenshot is taken, so they never enter the image. The screenshot is shown to you before sending and you can decline it with a single click. We do NOT collect your IP address or location.
Zephren DOES NOT collect Personal Identification Numbers (CNP) through the application interface and does not store them in its database. If an MDLPA submission requires the CNP, the auditor enters it directly in the submission document, outside the application.
3. Processing purposes and legal grounds (Art. 6 GDPR)
- Contract performance (Art. 6(1)(b)) — providing energy calculation, CPE generation, audit reports, and project storage.
- Legal obligation (Art. 6(1)(c)) — fiscal document retention 10 years (Romanian Fiscal Code), eFactura ANAF transmission, compliance with Mc 001-2022 and Law 238/2024.
- Consent (Art. 6(1)(a)) — optional marketing communications; analytics cookies, storage on your device and identification of the person within analytics tools (see section 3.bis).
- Legitimate interest (Art. 6(1)(f)) — fraud prevention, information security, performance monitoring, and improving the calculator via anonymized usage statistics (document type, energy class, EP, building typology, county — without address, name or cadastral data).
3.bis What happens if you reject analytics cookies
The “Reject all” button in the cookie banner has a precise effect, which we prefer to state rather than let you assume:
- Nothing is stored on your device for analytics purposes — no cookie, no entry in your browser’s local storage — and nothing already stored there is read.
- You are not identified: no user profile is created, your account is not linked to the measured activity, and on a later visit you cannot be recognised as the same person.
- Error monitoring (Sentry) stays fully off — there, rejection means exactly what it appeared to mean before.
- Aggregate measurement continues: we still count visits and actions in the application (which pages are opened, where a flow is abandoned, which usability errors occur), so that we know what works and what needs fixing.
Technically this is possible because the analytics provider (PostHog, EU Cloud Frankfurt) computes on its own servers a temporary hash-based identifier, derived from elements of your request (IP address, user agent) and from a value that rotates daily. The hash serves only to avoid counting the same session twice on the same day; it is never returned to your device and does not allow tracking across days or across sites.
Legal basis, in two distinct layers. The obligation to obtain consent for cookies comes from Art. 5(3) of the ePrivacy Directive 2002/58/EC, transposed in Romania by Art. 4 para. (5) of Law no. 506/2004, and covers the storing of information in the user’s terminal equipment and the gaining of access to information already stored there. The cookieless mode does neither, so that obligation does not apply to it. What remains is the processing of the hash on the provider’s servers, which is carried out on the basis of legitimate interest, Art. 6(1)(f) GDPR — our interest in knowing how our own product is used, with minimal impact on you precisely because you are not identifiable. This is the same basis we rely on for our own visit counter.
You may object at any time to this processing based on legitimate interest (Art. 21 GDPR) by writing to legal@zephren.ro. Independently of that, if your browser sends the Do Not Track signal, we honour it and measure nothing at all.
4. Recipients (sub-processors)
Data is transmitted to the following sub-processors that have signed (or are about to sign) Data Processing Agreements (DPA) according to GDPR Art. 28:
- Vercel Inc. (US + AWS EU regions) — application hosting and serverless functions.
- Supabase Inc. (US + AWS EU configurable) — authentication, PostgreSQL database, storage.
- Stripe Payments Europe Ltd. (Ireland) — payment processing, subscriptions, invoicing.
- Anthropic Inc. (California, US) — AI assistant, OCR for invoices/CPE, automatic document import and, in the project verification module, analysis of the project documents you upload (drawings, sections, technical reports — including the third-party data and the commercial information they contain, as described in section 2). Under Anthropic commercial terms for the API, the content submitted is not used to train models and is deleted within a maximum of 30 days. Transmission takes place only upon your explicit upload action; if the documentation contains personal data of third parties, you are the one who establishes the basis for that disclosure in the legal relationship with your client.
- Cloudflare Inc. (US + EU edge — Frankfurt, Amsterdam) — DNS, Turnstile bot protection at forms, Web Application Firewall.
- Resend Inc. (US, EU-west-1 Ireland infrastructure) — transactional and marketing email delivery (account confirmations, payment notifications, support, newsletter). We use open and click tracking (an invisible pixel and redirected links) to measure deliverability and engagement, on the basis of legitimate interest (Art. 6(1)(f) GDPR). You can block open tracking by disabling image loading in your email client and unsubscribe at any time from any marketing email (unsubscribe link in every email).
- Sentry Inc. (US, Irish jurisdiction DPA) — real-time application error monitoring; personal data is automatically scrubbed before transmission (CNP, email, phone, IBAN are masked).
- PostHog Inc. (EU Cloud, Frankfurt) — product analytics and session recordings to improve user experience; all inputs are masked (passwords, emails, VAT IDs). If you accepted analytics cookies, the processing includes cookies and identification of your account; if you rejected them, it runs in the cookieless mode described in section 3.bis — no storage on your device, no profile and no link to your account.
- UptimeRobot (Cyprus) — uptime monitoring of public endpoints (only public URLs, no user data).
- Gotenberg (Render Inc.) (US/EU infra) — DOCX → PDF document conversion (optional, only if the user does not use the Microsoft Office Online alternative).
- Microsoft Corp. (US) — optional, for DOCX preview via Office Online. Can be disabled (the application uses Gotenberg alternatively).
- SmartBill (Intelligent IT SRL) (Romania) — electronic invoicing + eFactura ANAF transmission.
- Google LLC (US) — web fonts, optional OAuth authentication, Workspace for communications at @zephren.ro addresses.
- PVGIS (Joint Research Centre EU), OpenMeteo (Germany) — public climate and solar data.
International transfers to entities outside the EU/EEA are carried out based on one of the following safeguards, in order of preference:
- (a) EU-US Data Privacy Framework (DPF) adequacy decision of 10 July 2023 — for US sub-processors actively certified on dataprivacyframework.gov/list (Anthropic, Vercel, Sentry, Microsoft, Google, Cloudflare and Resend are certified).
- (b) Standard Contractual Clauses (SCC) adopted by EC Decision 2021/914, Module 2 (controller → processor), for non-EU sub-processors without DPF certification.
- (c) Transfer Impact Assessment (TIA) documented per EDPB Recommendations 01/2020 (post Schrems II — CJEU C-311/18), with supplementary measures where necessary. TIAs are available on request via legal@zephren.ro.
5. Data retention period
- Active auditor account: for the contract duration + 3 years of inactivity.
- Audit projects + CPE: 10 years (professional archiving obligation), then anonymization (name, email, phone, address are replaced with "[ANONYMIZED]").
- Invoices and fiscal records: 10 years (Romanian Fiscal Code).
- Access logs: 12 months.
- Feedback form submissions: 24 months after the report is closed. Attached screenshots are deleted with them.
- AI assistant conversations: 6 months.
- Marketing data (consent): until consent withdrawal.
- 7-day trial device identifier: 90 days from the end of the trial, after which it is deleted automatically. The trial record itself remains (start date, end date, the certification number you declared), without the identifier. The basis for this period is Art. 5(1)(e) GDPR: the purpose for which it was collected — preventing trial abuse — is exhausted once the trial ends.
- Record of certification numbers used for a trial: kept for an indefinite period, but with no link to you. When your account is deleted, the account identifier is removed from that record and only the certification number and the date it was used remain. The basis is Art. 17(3)(e) GDPR — retention remains necessary for the establishment or exercise of a legal claim, here our right not to grant a second free trial to the same certification number.
The periods that are applied automatically — access logs, AI assistant conversations and the trial device identifier — are enforced by a weekly run, so the actual deletion may take place up to seven days after the period has elapsed.
6. Data subject rights (Art. 15-22 GDPR)
You have the right to:
- Access (Art. 15) — obtain a copy of the data we hold about you. Direct download from "Settings → My Data" in the application.
- Rectification (Art. 16) — edit incorrect data directly from your account.
- Erasure / "Right to be forgotten" (Art. 17) — request account deletion and data anonymization from "Settings → Delete account".
- Restriction of processing (Art. 18) — during the resolution of a complaint.
- Portability (Art. 20) — full export in JSON or XML format.
- Objection (Art. 21) — to processing based on legitimate interest or marketing.
- Complaint to ANSPDCP — www.dataprotection.ro.
Exercising your rights is free of charge, within a maximum of 30 days from the request. Send the request to legal@zephren.ro.
6.bis Automated decisions and artificial intelligence (Art. 22 GDPR + AI Act 2024/1689)
ZEPHREN does NOT make automated decisions with legal effect or similarly significant impact on you (Art. 22 GDPR). All artificial intelligence functions (invoice/CPE OCR, envelope suggestions, narrative report generation, chat assistant) are ASSISTIVE — the output is reviewed and signed manually by the MDLPA-certified auditor, who assumes full professional responsibility for the final result.
Per EU Regulation 2024/1689 (AI Act) Art. 50, we explicitly inform you:
- AI functions are visually labeled with "🤖 AI-assisted" in the interface.
- Outputs may contain inaccuracies; human review is mandatory before use in official documents (CPE, audit).
- The AI model provider has a DPA signed per Art. 28 GDPR and does NOT train models on data submitted via the API.
- Further details in the internal "AI Use Policy", available on request via legal@zephren.ro.
7. Security measures
- Mandatory TLS 1.2+ encrypted transmission.
- At-rest encryption on Supabase servers (AES-256).
- Row-Level Security (RLS) — users can access exclusively their own data.
- JWT authentication with automatic refresh.
- Rate limiting and CORS allowlist on all API endpoints.
- Strict Content Security Policy (CSP), HSTS, X-Frame-Options DENY.
- Anomaly monitoring (Sentry) with alerts in case of security incident.
- Checking your chosen password against public lists of breached passwords, using thek-anonymity method: the password never leaves your device. Its cryptographic hash is computed locally, and only the first five characters of that hash are sent to the third-party service (Have I Been Pwned) — not enough to reconstruct the password or to identify you. The service returns every hash starting with those five characters (hundreds of them), and the match is performed in your browser. As with any web request, the service sees your device's IP address. The check is purely informative: it does not block account creation, and its result is neither transmitted nor stored.
8. Breach notification
In case of a security breach with risk to your rights, Zephren notifies ANSPDCP within 72 hours (Art. 33 GDPR) and, if there is high risk, also the affected data subjects (Art. 34 GDPR) by email.
9. Minors
The Service is intended exclusively for professionals (MDLPA-certified energy auditors or those in the certification process). We do not knowingly collect data about minors under 16.
10. Changes to this policy
We may update this Privacy Policy. Material changes will be announced by email and by displaying a re-consent banner in the application at least 30 days before applying them.
11. Contact
Privacy questions: legal@zephren.ro.
ZEPHREN S.R.L., Bd. Libertății nr. 38, Bușteni, Romania.