Aopy Platform
Privacy Policy
Last updated: 22 July 2026
1. Who We Are
Easy Life Tech SRL ("Aopy", "we", "us", "our") is a company incorporated in Romania, registered with the Trade Register under no. J2026033503008, fiscal identification code (CUI) 54742254, EUID ROONRC.J2026033503008, with its registered office at Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania.
We operate the Aopy platform (the "Service"), a business-to-business (B2B) email and SMS marketing platform available at aopy.com and app.aopy.com. This Privacy Policy explains how we collect, use, disclose and protect personal data when you visit our websites, create an account, or use the Service.
Our two roles. For the personal data described in this Policy — your account data, billing data and data generated by your use of our websites — we act as a data controller. For contact data that our customers upload to the Service in order to run their own marketing campaigns ("Contact Data"), the customer is the data controller and we act as a data processor on the customer's behalf. Processing in our processor role is governed by our Data Processing Agreement, not by this Policy. If you have received an email or SMS sent through Aopy by one of our customers, that customer is responsible for the lawfulness of the communication; please direct requests to them first — we assist them in responding, as required by the Data Processing Agreement.
2. Data Controller and Contact Details
The data controller for the processing described in this Policy is Easy Life Tech SRL, Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania.
Data protection enquiries and requests to exercise your rights are handled by our Privacy Team at privacy@aopy.com. For general support, contact support@aopy.com.
3. What Data We Collect
a) Data you provide to us.
- Account data — when you sign up we collect your full name, company name, company website, email address and a password (managed through our authentication provider, Supabase Auth), whether you register as an agency, the versions of the Terms of Service and this Privacy Policy you accepted, and your marketing opt-in choice.
- Billing data — payments are processed by Stripe. We store only Stripe reference identifiers (customer, subscription, payment-method and invoice IDs) and a masked card reference (card brand and last four digits). We never store full card numbers.
- Public pages — if you join the waiting list on our public ROAS calculator page, we collect your email address and your marketing opt-in choice only.
b) Data collected automatically.
- Legal-acceptance records — when you accept our terms or policies, we record your IP address, browser user-agent and a timestamp in an append-only log, so that we can evidence what was accepted and when.
- Cookies — strictly necessary cookies are always set. On our public marketing pages (including the ROAS Calculator), analytics (Google Analytics 4) and marketing (Meta Pixel, TikTok Pixel) cookies are set only if you grant the matching category in our cookie banner, and never on the app dashboard. See our Cookie Policy for the full cookie table.
- Technical data — our hosting and content-delivery provider processes request metadata (including IP address and user-agent) to serve the Service, and our error-monitoring provider processes error traces with partial request metadata so that we can diagnose faults.
c) Data we process on behalf of our customers (processor role). Our customers upload and generate the following data about their own contacts; the customer is the controller of this data:
- Contact Data — email addresses, phone numbers, names, demographic attributes (date of birth, gender, city/county/country), consent fields, custom fields, commerce statistics (orders, revenue, average order value) and engagement counters.
- Engagement events — per-contact email opens (timestamp, user-agent, IP address), link clicks (timestamp, URL, tags, user-agent, IP address), delivery, bounce and complaint events, and device type and display size derived from the open tracking pixel; SMS delivery receipts and inbound STOP messages.
4. Legal Bases for Processing
Where we act as controller, we process personal data on the following legal bases under Regulation (EU) 2016/679 (the "GDPR"):
- Performance of a contract (Art. 6(1)(b) GDPR) — creating and administering your account, providing the Service, and managing billing and subscriptions.
- Legitimate interests (Art. 6(1)(f) GDPR) — our legitimate interests in keeping the Service secure, improving the product, preventing fraud and abuse, and evidencing acceptance of our legal terms. You may object to processing based on legitimate interests at any time (see Section 7).
- Legal obligation (Art. 6(1)(c) GDPR) — retaining invoices and fiscal records as required by Romanian tax and accounting law.
- Consent (Art. 6(1)(a) GDPR) — sending you our own marketing communications and setting non-essential cookies. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
5. How We Use Your Data
The table below maps our processing purposes to their legal bases:
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service (account management, campaign sending, dashboards, support) | Contract (Art. 6(1)(b)) |
| Billing, invoicing and subscription management via Stripe | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for fiscal records |
| Securing the Service, preventing fraud and abuse (including rate limiting and access controls) | Legitimate interests (Art. 6(1)(f)) |
| Recording your acceptance of legal terms (IP address, user-agent, timestamp) | Legitimate interests (Art. 6(1)(f)) — evidencing acceptance |
| Diagnosing errors and improving the product | Legitimate interests (Art. 6(1)(f)) |
| Sending you our own marketing communications (only if you opted in) | Consent (Art. 6(1)(a)) |
| Complying with legal obligations (tax, accounting, responding to lawful requests) | Legal obligation (Art. 6(1)(c)) |
We do not sell personal data. We do not use your personal data for automated decision-making that produces legal effects concerning you or similarly significantly affects you.
6. Data Retention
We retain personal data for the following periods:
| Data category | Retention period |
|---|---|
| Account data | Life of the account, plus a 30-day grace period after account deletion is requested (during which the deletion can be reversed) |
| Contact Data processed on behalf of customers | Until the customer deletes it or the customer's contract ends; post-termination deletion is governed by the Data Processing Agreement |
| Email and SMS engagement events | 36 months on a rolling basis |
| Invoices and fiscal records | 10 years, as required by Romanian accounting law |
| Server and security logs | 12 months |
When a retention period expires, we delete or irreversibly anonymise the data. You may request deletion of your data at any time via the Data Deletion Request form or by emailing privacy@aopy.com.
7. Your Rights
Under the GDPR you have the following rights in relation to personal data for which we are the controller:
- Access (Art. 15) — obtain confirmation of whether we process your data and receive a copy of it;
- Rectification (Art. 16) — have inaccurate data corrected and incomplete data completed;
- Erasure (Art. 17) — have your data deleted where there is no longer a legal ground to keep it;
- Restriction of processing (Art. 18) — limit how we use your data in certain circumstances;
- Data portability (Art. 20) — receive the data you provided to us in a structured, commonly used, machine-readable format;
- Objection (Art. 21) — object to processing based on our legitimate interests, and to direct marketing at any time;
- Withdrawal of consent — withdraw any consent you have given, at any time, with effect for the future;
- No solely automated decisions (Art. 22) — not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
How to exercise your rights. Email privacy@aopy.com or use the self-service forms at Data Deletion and Data Export. Requests are logged, your identity is verified, and we respond within one month, as required by Art. 12 GDPR.
If you received a message sent through Aopy by one of our customers: every marketing email sent through the Service carries an unsubscribe link, and marketing SMS can be stopped by replying STOP or DEZABONARE. For access, deletion or other requests concerning that data, contact the sender (the controller); we assist them in fulfilling such requests under the Data Processing Agreement.
Complaints. You have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, Romania — www.dataprotection.ro — or with the supervisory authority of your habitual residence or place of work.
8. International Data Transfers
Our primary infrastructure is located in the European Union: application data is stored with Supabase and Amazon Web Services in region eu-west-1 (Ireland), and SMS messages for the Romanian market are delivered through a provider located in Romania.
Some of our sub-processors process data in the United States — including our email delivery failover provider, our error-monitoring provider, our payment provider and the control plane of our hosting provider. Where personal data is transferred outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses (SCCs) or an applicable adequacy decision as the transfer safeguard.
AI image generation and US providers. The Service includes an optional AI image-generation feature that uses US-based providers (Google Gemini and OpenAI). Only image-generation prompts are sent to these providers — never Contact Data. Each customer organisation can disable this US-based AI processing entirely through an organisation-level setting; when the setting is disabled, no data is sent to these providers.
9. Sub-Processors and Service Providers
We use a limited set of vetted service providers (sub-processors) to operate the Service — including infrastructure, email delivery, database and authentication, hosting, payments, rate limiting, error monitoring, SMS delivery and optional AI image generation. The complete, up-to-date register — including each provider's purpose, the data involved and its processing location — is published at Sub-Processors.
We update that page when we add or replace a sub-processor. For customers, the notice and objection mechanism for sub-processor changes is set out in the Data Processing Agreement.
Where you connect optional third-party integrations to your account (such as Meta, TikTok, Google Ads/GA4, Shopify or WooCommerce), data flows to those providers on your instruction, under their own terms and privacy policies.
10. Security
We apply technical and organisational measures appropriate to the risk of the processing, including:
- Multi-tenant isolation — every database table is scoped to a customer organisation and protected by PostgreSQL Row-Level Security, with JWT-based access context;
- Encryption in transit — TLS on all connections (HTTPS enforced);
- Encryption at rest — at the infrastructure level; integration credentials and OAuth tokens are additionally encrypted at the application level with AES-256-GCM;
- Access controls — role-based permissions, an administrative allowlist, and signed authentication for scheduled jobs and webhooks (HMAC signature verification on inbound webhooks);
- Audit trails — append-only logs of consent and legal acceptances;
- Resilient sending architecture — message queues with no shared mutable state;
- Organisational measures — documented information-security management practices covering scope, risk treatment, supplier security and personnel security.
No system is perfectly secure; if we become aware of a personal data breach affecting your data, we will act in accordance with our GDPR obligations, including notification where required.
11. Cookies
Strictly necessary cookies are always set: a first-party cookie storing your cookie-consent choices and the authentication session cookie set by our auth provider. On our public marketing pages (including the ROAS Calculator), we also use Google Analytics 4 for analytics and the Meta Pixel and TikTok Pixel for marketing — set only once you grant the matching category ("analytics" or "marketing") in our cookie banner, and never on the app dashboard. The functional category remains declared for potential future use; any activation will require your renewed consent.
Full details, including the exact cookie table and how to manage your preferences, are in our Cookie Policy.
12. Children
The Service is a business-to-business platform and is not directed at children. We do not knowingly collect personal data from persons under the age of 16, and our customers are contractually prohibited from uploading Contact Data relating to persons under 16. If you believe a child's data has been provided to us, contact privacy@aopy.com and we will delete it.
13. Changes to This Policy
We may update this Policy from time to time. Each version of the Policy is identified by a version date, and your acceptance of it is recorded. If we make material changes, we will notify you by email or by a prominent notice in the platform, and where the changes require it, you will be asked to review and re-accept the updated Policy before continuing to use the Service. The "Last updated" date at the top of this page reflects the most recent revision.
14. Contact
For questions about this Policy or about how we handle personal data, contact our Privacy Team at privacy@aopy.com. For general support, contact support@aopy.com.
Postal address: Easy Life Tech SRL, Șos. București-Ploiești, Nr. 15, Imobilul 2 - Spațiu Comercial, Etaj 5, Sector 1, București, Romania.
15. Language
This Policy is drawn up in English and in Romanian. The English version is the canonical version: in the event of any inconsistency between the two language versions, the English version prevails.