Legal
Every document that governs the Aopy platform, published in full rather than summarised. English is the canonical text. Written for a B2B service operated from Romania under EU law.
Easy Life Tech SRL ("Aopy", "we", "us", "our") is a company incorporated in Romania, registered with the Trade Register under no. J2026033503008, fiscal identification code (CUI) 54742254, EUID ROONRC.J2026033503008, with its registered office at Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania.
We operate the Aopy platform (the "Service"), a business-to-business (B2B) email and SMS marketing platform available at aopy.com and app.aopy.com. This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our websites, create an account, or use the Service.
Our two roles. For the personal data described in this Policy — your account data, billing data and data generated by your use of our websites — we act as a data controller. For contact data that our customers upload to the Service in order to run their own marketing campaigns ("Contact Data"), the customer is the data controller and we act as a data processor on the customer's behalf. Processing in our processor role is governed by our Data Processing Agreement, not by this Policy. If you have received an email or SMS sent through Aopy by one of our customers, that customer is responsible for the lawfulness of the communication; please direct requests to them first — we assist them in responding, as required by the Data Processing Agreement.
The data controller for the processing described in this Policy is Easy Life Tech SRL, Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania.
Data protection enquiries and requests to exercise your rights are handled by our Privacy Team at privacy@aopy.com. For general support, contact support@aopy.com.
a) Data you provide to us.
b) Data collected automatically.
c) Data we process on behalf of our customers (processor role). Our customers upload and generate the following data about their own contacts; the customer is the controller of this data:
Where we act as controller, we process personal data on the following legal bases under Regulation (EU) 2016/679 (the "GDPR"):
The table below maps our processing purposes to their legal bases:
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service (account management, campaign sending, dashboards, support) | Contract (Art. 6(1)(b)) |
| Billing, invoicing and subscription management via Stripe | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for fiscal records |
| Securing the Service, preventing fraud and abuse (including rate limiting and access controls) | Legitimate interests (Art. 6(1)(f)) |
| Recording your acceptance of legal terms (IP address, user-agent, timestamp) | Legitimate interests (Art. 6(1)(f)) — evidencing acceptance |
| Diagnosing errors and improving the product | Legitimate interests (Art. 6(1)(f)) |
| Sending you our own marketing communications (only if you opted in) | Consent (Art. 6(1)(a)) |
| Complying with legal obligations (tax, accounting, responding to lawful requests) | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data. We do not use your personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you.
We retain personal data for the following periods:
| Data category | Retention period |
|---|---|
| Account data | Life of the account, plus a 30-day grace period after account deletion is requested (during which the deletion can be reversed) |
| Contact Data processed on behalf of customers | Until the customer deletes it or the customer's contract ends; post-termination deletion is governed by the Data Processing Agreement |
| Email and SMS engagement events | 36 months on a rolling basis |
| Invoices and fiscal records | 10 years, as required by Romanian accounting law |
| Server and security logs | 12 months |
When a retention period expires, we delete or irreversibly anonymise the data. You may request deletion of your data at any time via the Data Deletion Request form or by emailing privacy@aopy.com.
Under the GDPR you have the following rights in relation to personal data for which we are the controller:
How to exercise your rights. Email privacy@aopy.com or use the self-service forms at Data Deletion and Data Export. Requests are logged, your identity is verified, and we respond within one month, as required by Art. 12 GDPR.
If you received a message sent through Aopy by one of our customers: every marketing email sent through the Service carries an unsubscribe link, and marketing SMS can be stopped by replying STOP or DEZABONARE. For access, deletion or other requests concerning that data, contact the sender (the controller); we assist them in fulfilling such requests under the Data Processing Agreement.
Complaints. You have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, Romania — www.dataprotection.ro — or with the supervisory authority of your habitual residence or place of work.
Our primary infrastructure is located in the European Union: application data is stored with Supabase and Amazon Web Services in Ireland, and SMS messages for the Romanian market are delivered through a provider located in Romania.
Some of our sub-processors process data in the United States — including our email delivery failover provider, our error-monitoring provider, our payment provider and the control plane of our hosting provider. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an applicable adequacy decision as the transfer safeguard.
AI image generation and US providers. The Service includes an optional AI image-generation feature that uses a US-based provider (OpenAI). Only image-generation prompts are sent to this provider — never Contact Data. Each customer organisation can disable this US-based AI processing entirely through an organisation-level setting; when the setting is disabled, no data is sent to this provider.
We use a limited set of vetted service providers (sub-processors) to operate the Service — including infrastructure, email delivery, database and authentication, hosting, payments, rate limiting, error monitoring, SMS delivery and optional AI image generation. The complete, up-to-date register — including each provider's purpose, the data involved and its processing location — is published at Sub-Processors.
We update that page when we add or replace a sub-processor. For customers, the notice and objection mechanism for sub-processor changes is set out in the Data Processing Agreement.
Where you connect optional third-party integrations to your account (such as Meta, TikTok, Google Ads/GA4, Shopify or WooCommerce), data flows to those providers on your instruction, under their own terms and privacy policies.
Google user data (Google Merchant Center). If you connect your Google Merchant Center account, Aopy's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request a single scope, auth/content, and use it only to (a) read your own Merchant Center account ID, in order to confirm and store the connection, and (b) create and update product listings in your own Merchant Center account, and only when you explicitly trigger an export in Aopy. We store only your Merchant Center account ID and the OAuth access and refresh tokens, encrypted at rest with AES-256-GCM. We do not use Google user data for advertising, we do not sell it, and we do not transfer it to third parties except as needed to provide this feature at your instruction or where required by law. We never access Google data belonging to any account other than the one you connect. You can revoke access at any time by disconnecting Google inside Aopy, or from your Google Account permissions page.
We apply technical and organisational measures appropriate to the risk of the processing, including:
No system is perfectly secure; if we become aware of a personal data breach affecting your data, we will act in accordance with our GDPR obligations, including notification where required.
The Service is a business-to-business platform and is not directed at children. We do not knowingly collect personal data from persons under the age of 16, and our customers are contractually prohibited from uploading Contact Data relating to persons under 16. If you believe a child's data has been provided to us, contact privacy@aopy.com and we will delete it.
We may update this Policy from time to time. Each version of the Policy is identified by a version date, and your acceptance of it is recorded. If we make material changes, we will notify you by email or by a prominent notice in the platform, and where the changes require it, you will be asked to review and re-accept the updated Policy before continuing to use the Service. The "Last updated" date at the top of this page reflects the most recent revision.
For questions about this Policy or about how we handle personal data, contact our Privacy Team at privacy@aopy.com. For general support, contact support@aopy.com.
Postal address: Easy Life Tech SRL, Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania.
This Policy is drawn up in English and in Romanian. The English version is the canonical version: in the event of any inconsistency between the two language versions, the English version prevails.