AAopy

Aopy Platform

Data Processing Agreement

Last updated: 8 July 2026

1. Introduction and Definitions

This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service (the "Terms") concluded between Easy Life Tech SRL ("Aopy", the "Processor"), a company incorporated in Romania, CUI 54742254, Trade Register No. J2026033503008, EUID ROONRC.J2026033503008, with its registered office at Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania, and the customer identified in the applicable account registration (the "Customer", the "Controller"). It governs the processing of personal data carried out by Aopy on behalf of the Customer in connection with the Aopy platform (the "Service") and implements Article 28(3) of Regulation (EU) 2016/679 (the "GDPR").

Unless otherwise defined in this DPA, the terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in Article 4 GDPR. In addition:

  • "Contact Data" means the personal data relating to the Customer's contacts, subscribers and end customers that the Customer uploads to, collects through, or generates within the Service.
  • "Sub-processor" means any third party engaged by Aopy to process Contact Data on behalf of the Customer.
  • "Applicable Data Protection Law" means the GDPR, Romanian Law no. 190/2018 and any other legislation implementing or supplementing the GDPR that applies to the processing under this DPA.

2. Roles of the Parties

For the purposes of this DPA, the Customer acts as the controller of Contact Data and Aopy acts as the processor. Aopy processes Contact Data only on the Customer's documented instructions. The Customer's documented instructions consist of: (a) this DPA; (b) the Terms; and (c) the Customer's configuration and use of the Service, including the campaigns, automations, segments, integrations and settings the Customer creates or enables.

The Service is provided to businesses only. The Customer is responsible for the lawfulness of the Contact Data it processes through the Service, including establishing a valid legal basis and collecting any required consents, as further described in the Terms, the Acceptable Use Policy and the Data Processing Guidelines.

For personal data that Aopy processes for its own purposes — such as the Customer's account, billing and platform-usage data — Aopy acts as an independent controller. That processing is described in the Privacy Policy and falls outside the scope of this DPA.

3. Duration

This DPA takes effect when the Customer accepts the Terms and remains in force for as long as Aopy processes Contact Data on behalf of the Customer. Its obligations survive the termination or expiry of the Terms until Aopy has returned or deleted all Contact Data in accordance with Article 15.

4. Nature and Purpose of the Processing

Aopy processes Contact Data for the sole purpose of providing the Service to the Customer, namely:

  • sending email and SMS marketing communications to the Customer's contacts;
  • hosting and storing Contact Data and organising it into lists and segments;
  • executing marketing automations configured by the Customer;
  • recording and reporting delivery and engagement analytics (such as opens, clicks, deliveries, bounces and complaints);
  • maintaining suppression records so that unsubscribes and opt-outs are honoured.

The processing operations involved include the collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, analysis, restriction, erasure and destruction of Contact Data.

5. Categories of Data and Data Subjects

Categories of data subjects: the Customer's contacts, subscribers, customers and prospects whose personal data the Customer processes through the Service.

Categories of personal data:

  • Identification and contact details: names, email addresses, phone numbers.
  • Demographic details: date of birth, gender, city, county, country.
  • Consent and preference records: consent fields and subscription status.
  • Custom fields defined by the Customer.
  • Commerce data: order history, revenue and average order value associated with a contact.
  • Engagement data: email opens (timestamp, user agent, IP address), link clicks (timestamp, URL, tags, user agent, IP address), delivery, bounce and complaint events, and the device type and display size derived from the open pixel.
  • SMS data: delivery receipts and inbound opt-out (STOP) messages.

6. Prohibited Data

The Service is not designed for, and must not be used to process:

  • special categories of personal data within the meaning of Article 9 GDPR (such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, health data, or data concerning a person's sex life or sexual orientation);
  • personal data relating to criminal convictions and offences (Article 10 GDPR);
  • personal data of children under the age of 16;
  • data obtained from purchased, rented, harvested or appended contact lists, as further set out in the Acceptable Use Policy.

The Customer warrants that it will not upload or process such data through the Service. If Aopy becomes aware that prohibited data is being processed, it may delete the data concerned and suspend the affected processing in accordance with the Terms.

7. Processor Obligations

Aopy shall:

  1. process Contact Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by European Union or Romanian law — in which case Aopy will inform the Customer of that legal requirement before processing, unless the law prohibits such disclosure on important grounds of public interest;
  2. inform the Customer within 5 business days if, in Aopy's opinion, an instruction infringes the GDPR or other Applicable Data Protection Law; Aopy may suspend execution of the instruction concerned until it is confirmed or modified;
  3. ensure that all persons authorised to process Contact Data are bound by contractual or statutory obligations of confidentiality and receive access only to the extent needed to perform their role;
  4. implement and maintain the technical and organisational measures described in Article 8;
  5. assist the Customer as described in Articles 10, 11 and 12;
  6. make available the information necessary to demonstrate compliance, as described in Article 13;
  7. return or delete Contact Data as described in Article 15.

8. Security of Processing (Technical and Organisational Measures)

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for data subjects, Aopy implements the technical and organisational measures set out below (Article 32 GDPR). These measures may be updated from time to time, provided that the overall level of protection is not materially reduced.

MeasureImplementation
Tenant isolationEvery database table is scoped to the Customer's organisation and protected by PostgreSQL Row-Level Security; the access context is derived from authenticated JSON Web Tokens (JWT).
Encryption in transitTLS on all connections; HTTPS is enforced across the Service.
Encryption at restInfrastructure-level encryption at rest provided by our hosting providers; integration credentials and OAuth tokens are additionally encrypted at application level using AES-256-GCM.
Access controlRole-based permissions within each organisation, administrator allowlisting, and signed authentication for scheduled jobs and webhooks (HMAC signature verification on inbound webhooks).
AuditabilityAppend-only audit logs of consent records and legal acceptances.
Processing architectureMessage sending runs through a managed FIFO queue with isolated workers, avoiding shared mutable queue state.
Organisational measuresDocumented information-security management practices covering scope, risk treatment, supplier security and personnel security.

9. Sub-Processors

The Customer grants Aopy a general written authorisation to engage Sub-processors for the processing of Contact Data. The current list of Sub-processors — including the purpose, data categories, location and transfer safeguard for each — is maintained at /sub-processors, which constitutes Aopy's canonical Sub-processor register.

Aopy will inform the Customer of any intended addition or replacement of a Sub-processor by updating the register and giving notice of the change. The Customer may object on reasonable, documented data-protection grounds within 5 business days of the notice. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected part of the Service in accordance with the Terms.

Aopy imposes on each Sub-processor, by way of contract, data protection obligations that are substantially equivalent to those set out in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations, in accordance with Article 28(4) GDPR.

10. Assistance with Data Subject Rights

Taking into account the nature of the processing, Aopy assists the Customer, insofar as this is possible, through appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making).

The Service provides self-service tools that support this assistance:

  • contact-level export and deletion functions available in the platform;
  • an unsubscribe link automatically included in every marketing email, which records the opt-out and updates the contact's status without any further action by the Customer;
  • automated SMS opt-out: recipients who reply STOP or DEZABONARE are opted out automatically, and suppressed phone numbers are stored in normalised (E.164) form and irreversibly hashed (SHA-256) on the suppression list;
  • public request forms at /data-deletion and /data-export.

If a data subject submits a request directly to Aopy that concerns processing carried out on the Customer's behalf, Aopy will forward the request to the Customer without undue delay and will not respond on its own initiative, other than to direct the data subject to the Customer.

11. Personal Data Breach Notification

Aopy will notify the Customer without undue delay after becoming aware of a personal data breach affecting Contact Data. To the extent the information is available, the notification will describe: (a) the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (d) a contact point where more information can be obtained.

Aopy will preserve evidence relating to the breach, take reasonable steps to contain and remediate it, and provide reasonable cooperation to enable the Customer to meet its own notification obligations under Articles 33 and 34 GDPR. Aopy's notification of a breach is not an acknowledgement of fault or liability.

12. Data Protection Impact Assessments and Prior Consultation

Taking into account the nature of the processing and the information available to it, Aopy will provide the Customer with reasonable assistance in carrying out data protection impact assessments (Article 35 GDPR) and prior consultations with the supervisory authority (Article 36 GDPR), where these relate to the processing of Contact Data through the Service.

13. Audit

Aopy will make available to the Customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.

Audits are subject to the following conditions: (a) no more than one audit per calendar year, unless an audit is required by a supervisory authority or follows a personal data breach affecting Contact Data; (b) at least 10 business days' prior written notice; (c) conducted during normal business hours and without unreasonably disrupting Aopy's operations; (d) subject to appropriate confidentiality undertakings, including in respect of other customers' data; and (e) at the Customer's cost.

Aopy may first respond to an audit request by providing documentation of its information-security management practices and, where available, independent reports or attestations. If this documentation reasonably answers the Customer's questions, an on-site inspection may not be necessary.

14. International Data Transfers

Aopy processes and stores Contact Data primarily within the European Union. Certain Sub-processors process limited data in the United States or other third countries; where they do, the transfers rely on an adequacy decision of the European Commission or on the Commission-approved Standard Contractual Clauses ("SCCs"), as identified per Sub-processor in the register at /sub-processors.

AI features and US providers. Optional AI image-generation features use United States-based AI providers, which process image-generation prompts only — no Contact Data. An organisation-level setting allows the Customer to disable all AI image generation through US providers, giving the Customer direct control over these transfers.

Customer-directed transfers. Where the Customer connects an optional integration (for example Meta, TikTok, Google, Shopify or WooCommerce), data flows to that provider on the Customer's instruction, and the Customer is responsible, as controller, for the lawfulness of the resulting transfer.

15. Return and Deletion of Data

During the term, the Customer may export Contact Data at any time using the export tools available in the Service.

Upon termination or expiry of the Terms, the Customer has a 30-day export window in which to retrieve Contact Data. After this window, Aopy will delete the Contact Data processed on the Customer's behalf within 90 days of termination, unless European Union or Romanian law requires further storage (for example, fiscal record-keeping obligations), in which case the data concerned remains protected under this DPA and is isolated from any further processing.

Account deletion initiated by the Customer during the term is subject to a 30-day reversible grace period, after which deletion proceeds as described above.

16. Liability

Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms, except to the extent such limitations are not permitted by mandatory law.

As between the parties and vis-à-vis data subjects, liability is allocated in accordance with Article 82 GDPR: each party is liable for the damage caused by processing that infringes the obligations specifically directed to it, and a party that has paid full compensation may claim back from the other party the part of the compensation corresponding to that party's share of responsibility (Article 82(5) GDPR).

17. Order of Precedence

In the event of a conflict between this DPA and the Terms (or any other agreement between the parties) concerning the processing of personal data, this DPA prevails. For all other matters, the Terms apply.

18. Governing Law

This DPA is governed by Romanian law, consistent with the governing-law clause of the Terms, without prejudice to the directly applicable provisions of the GDPR and any mandatory data protection law.

The competent supervisory authority in Romania is ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, www.dataprotection.ro.

19. Language and Contact

This DPA is drawn up in English, with a Romanian translation provided for convenience. In the event of any inconsistency between the two versions, the English version prevails.

Questions about this DPA may be addressed to privacy@aopy.com. See also the DPA Contact Details page.