Legal
Every document that governs the Aopy platform, published in full rather than summarised. English is the canonical text. Written for a B2B service operated from Romania under EU law.
This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service (the "Terms") concluded between Easy Life Tech SRL ("Aopy", the "Processor"), a company incorporated in Romania, CUI 54742254, Trade Register No. J2026033503008, EUID ROONRC.J2026033503008, with its registered office at Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania, and the customer identified in the applicable account registration (the "Customer", the "Controller"). It governs the processing of personal data carried out by Aopy on behalf of the Customer in connection with the Aopy platform (the "Service") and implements Article 28(3) of Regulation (EU) 2016/679 (the "GDPR").
Unless otherwise defined in this DPA, the terms "personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given to them in Article 4 GDPR. In addition:
For the purposes of this DPA, the Customer acts as the controller of Contact Data and Aopy acts as the processor. Aopy processes Contact Data only on the Customer's documented instructions. The Customer's documented instructions consist of: (a) this DPA; (b) the Terms; and (c) the Customer's configuration and use of the Service, including the campaigns, automations, segments, integrations and settings the Customer creates or enables.
The Service is provided to businesses only. The Customer is responsible for the lawfulness of the Contact Data it processes through the Service, including establishing a valid legal basis and collecting any required consents, as further described in the Terms, the Acceptable Use Policy and the Data Processing Guidelines.
For personal data that Aopy processes for its own purposes — such as the Customer's account, billing and platform-usage data — Aopy acts as an independent controller. That processing is described in the Privacy Policy and falls outside the scope of this DPA.
This DPA takes effect when the Customer accepts the Terms and remains in force for as long as Aopy processes Contact Data on behalf of the Customer. Its obligations survive the termination or expiry of the Terms until Aopy has returned or deleted all Contact Data in accordance with Article 15.
Aopy processes Contact Data for the sole purpose of providing the Service to the Customer, namely:
The processing operations involved include the collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, analysis, restriction, erasure and destruction of Contact Data.
Categories of data subjects: the Customer's contacts, subscribers, customers and prospects whose personal data the Customer processes through the Service.
Categories of personal data:
The Service is not designed for, and must not be used to process:
The Customer warrants that it will not upload or process such data through the Service. If Aopy becomes aware that prohibited data is being processed, it may delete the data concerned and suspend the affected processing in accordance with the Terms.
Aopy shall:
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risks for data subjects, Aopy implements the technical and organisational measures set out below (Article 32 GDPR). These measures may be updated from time to time, provided that the overall level of protection is not materially reduced.
| Measure | Implementation |
|---|---|
| Tenant isolation | Every database table is scoped to the Customer's organisation and protected by PostgreSQL Row-Level Security; the access context is derived from authenticated JSON Web Tokens (JWT). |
| Encryption in transit | TLS on all connections; HTTPS is enforced across the Service. |
| Encryption at rest | Infrastructure-level encryption at rest provided by our hosting providers; integration credentials and OAuth tokens are additionally encrypted at application level using AES-256-GCM. |
| Access control | Role-based permissions within each organisation, administrator allowlisting, and signed authentication for scheduled jobs and webhooks (HMAC signature verification on inbound webhooks). |
| Auditability | Append-only audit logs of consent records and legal acceptances. |
| Processing architecture | Message sending runs through a managed FIFO queue with isolated workers, avoiding shared mutable queue state. |
| Organisational measures | Documented information-security management practices covering scope, risk treatment, supplier security and personnel security. |
The Customer grants Aopy a general written authorisation to engage Sub-processors for the processing of Contact Data. The current list of Sub-processors — including the purpose, data categories, location and transfer safeguard for each — is maintained at /sub-processors, which constitutes Aopy's canonical Sub-processor register.
Aopy will inform the Customer of any intended addition or replacement of a Sub-processor by updating the register and giving notice of the change. The Customer may object on reasonable, documented data-protection grounds within 5 business days of the notice. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected part of the Service in accordance with the Terms.
Aopy imposes on each Sub-processor, by way of contract, data protection obligations that are substantially equivalent to those set out in this DPA, and remains fully liable to the Customer for the performance of each Sub-processor's obligations, in accordance with Article 28(4) GDPR.
Taking into account the nature of the processing, Aopy assists the Customer, insofar as this is possible, through appropriate technical and organisational measures, in fulfilling the Customer's obligation to respond to data subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection and rights relating to automated decision-making).
The Service provides self-service tools that support this assistance:
If a data subject submits a request directly to Aopy that concerns processing carried out on the Customer's behalf, Aopy will forward the request to the Customer without undue delay and will not respond on its own initiative, other than to direct the data subject to the Customer.
Aopy will notify the Customer without undue delay after becoming aware of a personal data breach affecting Contact Data. To the extent the information is available, the notification will describe: (a) the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects; and (d) a contact point where more information can be obtained.
Aopy will preserve evidence relating to the breach, take reasonable steps to contain and remediate it, and provide reasonable cooperation to enable the Customer to meet its own notification obligations under Articles 33 and 34 GDPR. Aopy's notification of a breach is not an acknowledgement of fault or liability.
Taking into account the nature of the processing and the information available to it, Aopy will provide the Customer with reasonable assistance in carrying out data protection impact assessments (Article 35 GDPR) and prior consultations with the supervisory authority (Article 36 GDPR), where these relate to the processing of Contact Data through the Service.
Aopy will make available to the Customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
Audits are subject to the following conditions: (a) no more than one audit per calendar year, unless an audit is required by a supervisory authority or follows a personal data breach affecting Contact Data; (b) at least 10 business days' prior written notice; (c) conducted during normal business hours and without unreasonably disrupting Aopy's operations; (d) subject to appropriate confidentiality undertakings, including in respect of other customers' data; and (e) at the Customer's cost.
Aopy may first respond to an audit request by providing documentation of its information-security management practices and, where available, independent reports or attestations. If this documentation reasonably answers the Customer's questions, an on-site inspection may not be necessary.
Aopy processes and stores Contact Data primarily within the European Union. Certain Sub-processors process limited data in the United States or other third countries; where they do, the transfers rely on an adequacy decision of the European Commission or on the Commission-approved Standard Contractual Clauses ("SCCs"), as identified per Sub-processor in the register at /sub-processors.
AI features and US providers. Optional AI image-generation features use United States-based AI providers, which process image-generation prompts only — no Contact Data. An organisation-level setting allows the Customer to disable all AI image generation through US providers, giving the Customer direct control over these transfers.
Customer-directed transfers. Where the Customer connects an optional integration (for example Meta, TikTok, Google, Shopify or WooCommerce), data flows to that provider on the Customer's instruction, and the Customer is responsible, as controller, for the lawfulness of the resulting transfer.
During the term, the Customer may export Contact Data at any time using the export tools available in the Service.
Upon termination or expiry of the Terms, the Customer has a 30-day export window in which to retrieve Contact Data. After this window, Aopy will delete the Contact Data processed on the Customer's behalf within 90 days of termination, unless European Union or Romanian law requires further storage (for example, fiscal record-keeping obligations), in which case the data concerned remains protected under this DPA and is isolated from any further processing.
Account deletion initiated by the Customer during the term is subject to a 30-day reversible grace period, after which deletion proceeds as described above.
Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms, except to the extent such limitations are not permitted by mandatory law.
As between the parties and vis-à-vis data subjects, liability is allocated in accordance with Article 82 GDPR: each party is liable for the damage caused by processing that infringes the obligations specifically directed to it, and a party that has paid full compensation may claim back from the other party the part of the compensation corresponding to that party's share of responsibility (Article 82(5) GDPR).
In the event of a conflict between this DPA and the Terms (or any other agreement between the parties) concerning the processing of personal data, this DPA prevails. For all other matters, the Terms apply.
This DPA is governed by Romanian law, consistent with the governing-law clause of the Terms, without prejudice to the directly applicable provisions of the GDPR and any mandatory data protection law.
The competent supervisory authority in Romania is ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, www.dataprotection.ro.
This DPA is drawn up in English, with a Romanian translation provided for convenience. In the event of any inconsistency between the two versions, the English version prevails.
Questions about this DPA may be addressed to privacy@aopy.com. See also the DPA Contact Details page.