Aopy Platform
Data Processing Guidelines
Last updated: 8 July 2026
1. Purpose of This Guide
This guide is for our customers — the businesses that use Aopy to send email and SMS marketing. When you upload contact lists and send campaigns through the Service, you are the data controller for that contact data, and data-protection law places specific duties on you. This page explains those duties in practical terms and shows you how the platform's built-in tools help you meet them.
Two things this guide is not:
- It is not legal advice. It is general educational material. Your obligations depend on your specific situation, and you should consult your own legal adviser for advice on your processing activities.
- It is not a contract. The binding terms governing how Aopy processes personal data on your behalf are in the Data Processing Agreement (DPA), which forms part of our Terms of Service. If anything in this guide appears to conflict with the DPA, the DPA prevails.
2. Your Role vs. Ours
The GDPR distinguishes between the controller (who decides why and how personal data is processed) and the processor (who processes data on the controller's behalf). For the contact data you bring to the platform, you are the controller and Easy Life Tech SRL ("Aopy") is your processor.
| You (the Controller) | Aopy (the Processor) |
|---|---|
| Decide what contact data to collect and why | Processes contact data only on your documented instructions (your platform configuration and the DPA) |
| Ensure you have a valid lawful basis — usually consent — before sending marketing messages | Provides consent fields, opt-out handling, and suppression mechanics to help you honor your obligations |
| Inform your subscribers about your processing (your privacy notice) | Discloses its own infrastructure and sub-processors so you can inform them accurately |
| Respond to your subscribers' data-protection requests | Supplies self-service tools (contact export, contact deletion) and assists you as set out in the DPA |
| Keep your account and team access secure on your side | Secures the platform: tenant isolation, encryption in transit, access controls |
Aopy also acts as a controller in its own right for a narrower set of data — your account data, billing data, and our website visitors' data. That processing is described in our Privacy Policy, not here.
3. Lawful Basis — How to Choose
Every processing of personal data needs a lawful basis under Article 6 GDPR. For email and SMS marketing, the analysis in Romania is stricter than the GDPR alone, because the Romanian ePrivacy law — Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector — requires prior consent before sending commercial communications by email or SMS. In practice:
- Consent (Art. 6(1)(a) GDPR) is the safe default for marketing email and SMS. Collect it before the first message, keep proof of it, and stop when it is withdrawn.
- A narrow exception may apply to your existing customers: contact details obtained directly from a customer in the context of a sale may, under conditions, be used to market your own similar products or services — provided the customer was given a clear, free and simple way to refuse at the time of collection and in every subsequent message. The exact scope of this exception is a legal judgment; confirm with your adviser before relying on it.
- Legitimate interests (Art. 6(1)(f) GDPR) may support ancillary processing of data you already lawfully hold — for example, segmenting your own customer base or analysing campaign performance. It does not override the prior-consent requirement for the sending of the marketing message itself.
Note that a work email address that identifies a person (for example, a name-based address at a company domain) is still personal data. Whatever basis you choose, document your reasoning — you must be able to demonstrate it (Art. 5(2) GDPR, accountability).
4. Collecting Valid Consent
For consent to be valid under the GDPR it must be freely given, specific, informed and unambiguous — and you must be able to prove it (Art. 7 GDPR). Practical rules that keep your list clean:
- No pre-ticked boxes. Consent requires a clear affirmative act. Silence, inactivity or a pre-checked box is not consent.
- Keep it separate. Do not bundle marketing consent into your terms and conditions or make it a hidden condition of an unrelated service.
- Name the channels. Say clearly that the person is signing up for marketing by email, by SMS, or both. Consent to one channel is not consent to the other.
- Record everything. Keep who consented, when, how (which form or flow), and the exact wording they saw. On request, you must be able to produce this proof — our Acceptable Use Policy allows us to ask you for it.
- Double opt-in is strongly recommended. A confirmation email in which the subscriber actively verifies their address gives you the strongest possible proof of consent and keeps mistyped or malicious sign-ups off your list.
Importing existing lists: only import contacts whose provenance you can document — when, where and how each contact consented (or the documented basis you rely on). Purchased, rented, harvested or "appended" lists are prohibited on Aopy — see the Acceptable Use Policy — and sending to them is both a compliance risk for you and a deliverability risk for everyone.
5. Transparency Duties
As a controller you must inform your subscribers about your processing (Arts. 13–14 GDPR). Your own privacy notice — presented at or near the point where you collect their data — should tell them at least:
- who you are (your identity and contact details);
- why you process their data (marketing communications) and on what legal basis (typically consent);
- that you use a marketing-platform provider acting as your processor — you may name Aopy (Easy Life Tech SRL) or describe the category of provider, and you may link to our sub-processor register for the underlying infrastructure;
- how long you keep their data;
- their rights — access, rectification, erasure, restriction, portability, objection, withdrawal of consent — and how to exercise them, including the right to complain to a supervisory authority;
- how to unsubscribe at any time.
Keep your notice where subscribers can find it, and link it from your sign-up forms. If you materially change what you do with subscriber data, update the notice and, where needed, refresh consent.
6. Unsubscribe and Opt-Out
Every recipient has the right to opt out of your marketing at any time, and the platform enforces the mechanics for you:
- Email: the platform automatically inserts a unique, per-send unsubscribe link into every marketing email. The link works without a login, is processed immediately, and updates the contact's status so they are excluded from future marketing sends. Never remove, hide or obscure this link — doing so violates the Acceptable Use Policy and the law.
- SMS: recipients who reply STOP or DEZABONARE are opted out automatically. Opted-out phone numbers are normalized and stored in hashed form on a suppression list so they stay excluded even if re-imported. See our SMS Compliance page for details.
Opt-outs also arrive through other doors: a reply to your email, a message to your support team, a request in person. Honor them all. Update the contact's status in the platform, and mirror the opt-out in any other system you use — an opt-out given to you once is valid everywhere.
7. Prohibited Data
Some data must never be uploaded to the platform. Under the DPA and the Acceptable Use Policy, you must not upload or process through Aopy:
- Special categories of personal data (Art. 9 GDPR): data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation.
- Data relating to children under 16. The Service is a business-to-business tool and marketing databases on Aopy must not contain children's data.
- Purchased, rented, harvested or scraped contact lists, or any list whose provenance and consent you cannot document.
- Data you have no lawful basis to process — including contacts who have previously opted out.
If you discover that prohibited data has been uploaded to your account, delete it and contact privacy@aopy.com if you need assistance.
8. Data Subject Requests
Your subscribers can exercise their GDPR rights against you, the controller — access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. You generally must respond within one month (Art. 12 GDPR). The platform gives you the tools to serve most requests yourself:
- Access / portability: export an individual contact's profile and associated data from your audience.
- Rectification: edit the contact's fields directly in your audience.
- Erasure: delete the contact from your audience. Deletion removes the contact from your active audience and from all further sending; residual copies are erased in accordance with the retention and deletion terms of the DPA.
- Objection / withdrawal of consent: set the contact's status to unsubscribed (or let the automatic opt-out mechanics in section 6 do it).
If a data subject contacts Aopy directly about data on your list, we will not answer in your place: we will refer the request to you and assist you as set out in the DPA. For requests concerning data for which Aopy is itself the controller (account data, website data), our own data deletion and data export forms apply.
9. Security on Your Side
We secure the platform — tenant isolation, encryption in transit, access controls — but the security of your account is a shared responsibility. Weak account hygiene is one of the most common causes of data incidents. Follow these practices:
- Use a strong, unique password for your Aopy account — never one reused from another service — and store it in a password manager.
- One person, one account. Never share logins. Invite each team member individually and assign the least-privileged role that lets them do their job.
- Off-board promptly. When someone leaves your team, remove their access the same day.
- Treat integration credentials and API keys as secrets. Credentials for the integrations you connect (for example, your store or advertising accounts) grant access to real data — do not paste them into chats, tickets or shared documents.
- Handle exports carefully. Exported files contain personal data. Store them securely, share them only with people who need them, and delete them when no longer needed.
- Watch for phishing. Aopy will never ask you for your password by email.
10. When You Need a DPIA
A Data Protection Impact Assessment (DPIA) is a structured risk analysis the GDPR requires before starting processing that is likely to result in a high risk to individuals (Art. 35 GDPR). Sending routine newsletters to your own opted-in subscriber list does not normally require one. Indicators that your planned use might:
- large-scale evaluation, scoring or profiling of individuals — for example, extensive behavioural profiling across combined data sources;
- systematic monitoring of individuals;
- processing of sensitive data or data of a highly personal nature;
- processing data of vulnerable persons, including children;
- combining or matching datasets from multiple sources in ways people would not expect;
- using innovative technologies with uncertain privacy impact.
The Romanian supervisory authority (ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, www.dataprotection.ro) publishes guidance on the kinds of processing operations that require a DPIA — check it when in doubt, and consult your legal adviser. Where you carry out a DPIA covering processing performed through Aopy, we will provide reasonable assistance as set out in the DPA.
11. Questions
We want compliant senders — it protects your subscribers, your brand, and the deliverability of everyone on the platform.
- Platform questions (how to use consent fields, exports, deletion, unsubscribe settings): support@aopy.com
- Data-protection questions (the DPA, sub-processors, data subject requests): privacy@aopy.com
Related documents: Data Processing Agreement · Privacy Policy · Sub-processors · Acceptable Use Policy · SMS Compliance · Cookie Policy
12. Language
This guide is published in English and Romanian. In the event of any inconsistency or difference in interpretation between the two versions, the English version prevails.