Legal
Every document that governs the Aopy platform, published in full rather than summarised. English is the canonical text. Written for a B2B service operated from Romania under EU law.
This guide is for our customers — the businesses that use Aopy to send email and SMS marketing. When you upload contact lists and send campaigns through the Service, you are the data controller for that contact data, and data-protection law places specific duties on you. This page explains those duties in practical terms and shows you how the platform's built-in tools help you meet them.
Two things this guide is not:
The GDPR distinguishes between the controller (who decides why and how personal data is processed) and the processor (who processes data on the controller's behalf). For the contact data you bring to the platform, you are the controller and Easy Life Tech SRL ("Aopy") is your processor.
| You (the Controller) | Aopy (the Processor) |
|---|---|
| Decide what contact data to collect and why | Processes contact data only on your documented instructions (your platform configuration and the DPA) |
| Ensure you have a valid lawful basis — usually consent — before sending marketing messages | Provides consent fields, opt-out handling, and suppression mechanics to help you honor your obligations |
| Inform your subscribers about your processing (your privacy notice) | Discloses its own infrastructure and sub-processors so you can inform them accurately |
| Respond to your subscribers' data-protection requests | Supplies self-service tools (contact export, contact deletion) and assists you as set out in the DPA |
| Keep your account and team access secure on your side | Secures the platform: tenant isolation, encryption in transit, access controls |
Aopy also acts as a controller in its own right for a narrower set of data — your account data, billing data, and our website visitors' data. That processing is described in our Privacy Policy, not here.
Every processing of personal data needs a lawful basis under Article 6 GDPR. For email and SMS marketing, the analysis in Romania is stricter than the GDPR alone, because the Romanian ePrivacy law — Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector — requires prior consent before sending commercial communications by email or SMS. In practice:
Note that a work email address that identifies a person (for example, a name-based address at a company domain) is still personal data. Whatever basis you choose, document your reasoning — you must be able to demonstrate it (Art. 5(2) GDPR, accountability).
For consent to be valid under the GDPR it must be freely given, specific, informed and unambiguous — and you must be able to prove it (Art. 7 GDPR). Practical rules that keep your list clean:
Importing existing lists: only import contacts whose provenance you can document — when, where and how each contact consented (or the documented basis you rely on). Purchased, rented, harvested or "appended" lists are prohibited on Aopy — see the Acceptable Use Policy — and sending to them is both a compliance risk for you and a deliverability risk for everyone.
As a controller you must inform your subscribers about your processing (Arts. 13–14 GDPR). Your own privacy notice — presented at or near the point where you collect their data — should tell them at least:
Keep your notice where subscribers can find it, and link it from your sign-up forms. If you materially change what you do with subscriber data, update the notice and, where needed, refresh consent.
Every recipient has the right to opt out of your marketing at any time, and the platform enforces the mechanics for you:
Opt-outs also arrive through other doors: a reply to your email, a message to your support team, a request in person. Honor them all. Update the contact's status in the platform, and mirror the opt-out in any other system you use — an opt-out given to you once is valid everywhere.
Some data must never be uploaded to the platform. Under the DPA and the Acceptable Use Policy, you must not upload or process through Aopy:
If you discover that prohibited data has been uploaded to your account, delete it and contact privacy@aopy.com if you need assistance.
Your subscribers can exercise their GDPR rights against you, the controller — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You generally must respond within one month (Art. 12 GDPR). The platform gives you the tools to serve most requests yourself:
If a data subject contacts Aopy directly about data on your list, we will not answer in your place: we will refer the request to you and assist you as set out in the DPA. For requests concerning data for which Aopy is itself the controller (account data, website data), our own data deletion and data export forms apply.
We secure the platform — tenant isolation, encryption in transit, access controls — but the security of your account is a shared responsibility. Weak account hygiene is one of the most common causes of data incidents. Follow these practices:
A Data Protection Impact Assessment (DPIA) is a structured risk analysis the GDPR requires before starting processing that is likely to result in a high risk to individuals (Art. 35 GDPR). Sending routine newsletters to your own opted-in subscriber list does not normally require one. Indicators that your planned use might:
The Romanian supervisory authority (ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, www.dataprotection.ro) publishes guidance on the kinds of processing operations that require a DPIA — check it when in doubt, and consult your legal adviser. Where you carry out a DPIA covering processing performed through Aopy, we will provide reasonable assistance as set out in the DPA.
We want compliant senders — it protects your subscribers, your brand, and the deliverability of everyone on the platform.
Related documents: Data Processing Agreement · Privacy Policy · Sub-processors · Acceptable Use Policy · SMS Compliance · Cookie Policy
This guide is published in English and Romanian. In the event of any inconsistency or difference in interpretation between the two versions, the English version prevails.