Aopy
01Modules02Pricing03ROAS04About05Beta
Log in
01Modules02Pricing03ROAS04About05BetaLog in

Legal

Security

Every document that governs the Aopy platform, published in full rather than summarised. English is the canonical text. Written for a B2B service operated from Romania under EU law.

Documents

01Privacy Policy02Terms of Service03Cookie Policy04DPA05DPA Contacts06SMS Compliance07Data Deletion08Data Export09Sub-Processors10Data Processing Guidelines11SLA12Accessibility13Acceptable Use14Security

Easy Life Tech SRL

Șos. București-Ploiești, Nr. 15, Imobilul 2 — Spațiu Comercial, Etaj 5, Sector 1, București, România

CUI 54742254
Reg. Com. J2026033503008
EUID ROONRC.J2026033503008

privacy@aopy.com

English — canonicalLast updated 11 October 2026
In the print window, choose Save as PDF.
enro
1. Security Contact2. Reporting a Vulnerability3. Scope and Ground Rules4. How We Protect the Platform5. Incidents

1. Security Contact

Security at Easy Life Tech SRL, the company that builds and operates the Aopy platform (aopy.com and app.aopy.com), is the responsibility of Ioan Alexandru Busuioc, Chief Technology Officer (CTO). He is accountable for the security of the application, its databases and its infrastructure, and is the point of contact for security matters.

Security contact: security@aopy.com.

2. Reporting a Vulnerability

If you believe you have found a security vulnerability in Aopy, write to security@aopy.com. Please include:

  • the affected URL, endpoint or feature;
  • the steps needed to reproduce the issue, and what an attacker could gain from it;
  • how we can reach you if we have questions.

We read and acknowledge every report, investigate it, and tell you what we found. We ask that you give us a reasonable time to fix an issue before disclosing it publicly.

We do not run a paid bug-bounty programme.

3. Scope and Ground Rules

In scope: aopy.com, app.aopy.com and the services we operate behind them.

Out of scope: our customers' own shops and websites, and the systems of our sub-processors, which have their own reporting channels.

When you test, please:

  • use only accounts and data that are your own;
  • stop and report as soon as you can see data that belongs to someone else, and do not copy, keep or share it;
  • do not degrade the service: no denial-of-service testing, no bulk sending, no automated scanning at volume;
  • do not use social engineering or physical access against our staff, customers or providers.

4. How We Protect the Platform

The measures below include those described in our Data Processing Agreement and Privacy Policy:

  • Tenant isolation — every database table is scoped to a customer organisation and protected by PostgreSQL Row-Level Security, with JWT-based access context;
  • Encryption in transit — TLS on all connections, HTTPS enforced with HTTP Strict Transport Security;
  • Encryption at rest — at the infrastructure level; integration credentials and OAuth tokens are additionally encrypted at the application level with AES-256-GCM;
  • Authentication — passwords are stored only as salted hashes by a dedicated authentication service, and our application code never stores them; two-factor authentication (TOTP) can be turned on in account settings, and the sign-in form is protected against automated abuse;
  • Access controls — role-based permissions inside each organisation and an allowlist for administrative access;
  • Signed webhooks — inbound webhooks from payment and e-commerce platforms are accepted only after their signature is verified;
  • Audit trail — role changes, administrative actions, data exports and deletions are recorded in a log that users cannot edit;
  • Abuse limits — distributed rate limiting on our public APIs;
  • Browser protections — pages cannot be embedded in another site's frame;
  • Hosting — our primary database runs in the European Union. The providers we use are listed on the Sub-Processors page.

No system is perfectly secure, which is why we want to hear about any weakness you find.

5. Incidents

If we become aware of a personal data breach affecting data we process for a customer, we notify that customer without undue delay, as set out in section 11 of the Data Processing Agreement, and we act in accordance with our obligations under the GDPR.

If you are a customer and suspect unauthorised access to your account, write to support@aopy.com straight away.

Published by Easy Life Tech SRL. Questions: privacy@aopy.comBack to top
Request accessNow live
Aopy

One connected marketing system for e-commerce in Romania and the EU. Feed, creative, email and SMS on the same catalog.

contact@aopy.com

Product

ModulesPricingROASBeta

Company

AboutSign inContactPrivacy team

Legal

Terms of ServicePrivacy PolicyCookie PolicyAll documents

Easy Life Tech SRL

Șos. București-Ploiești, Nr. 15, Imobilul 2 — Spațiu Comercial, Etaj 5, Sector 1, București, România

CUI 54742254 · Reg. Com. J2026033503008 · EUID ROONRC.J2026033503008

2026 Easy Life Tech SRL. All rights reserved.ANPC — SALEU ODR