1. Who processes the data, and in what capacity
Eva-Accounting is a platform used by accounting firms and companies to keep their records. GDPR roles are divided as follows:
| Data category | Controller | Processor |
|---|---|---|
| Accounting, financial and payroll data of client companies (business partners, employees, documents, tax returns) | The client company and/or the accounting practice that uploads and administers it | CESIRO TRADING SRL — hosts and processes it solely on the customer’s instructions, under the Article 28 agreement |
| Platform account data (users, email, role, access log, subscription billing, support correspondence) | CESIRO TRADING SRL | Our infrastructure providers, within the limits of the contracts in place |
Contact details of the platform controller: CESIRO TRADING SRL, tax ID 37705493, J01/685/2017, Str. Theodor Pallady 5, Alba Iulia, jud. Alba, România, email [email protected].
If you are an employee, customer or supplier of a company that uses Eva-Accounting and you wish to exercise your rights over your data, address that company first (it is the controller). We can point you in the right direction and we assist the controller in answering, but we cannot dispose of its data on our own.
2. Categories of data processed
2.1. Platform account data (where we are the controller)
- Identification and contact: first and last name, email address, phone (optional), company and job title, interface language.
- Authentication: password stored as a cryptographic hash (never in clear text), session tokens, two-step authentication elements, sign-in history.
- Billing data: company name, tax ID, registered office, subscription plan, issued invoices, payments.
- Technical and log data: IP address, browser type, date and time of access, pages and operations performed, error messages — for security, troubleshooting and traceability.
- Correspondence: messages sent to support and our replies.
2.2. Data inside company records (where we are a processor)
- Business partners: name, tax ID/personal numeric code, address, bank accounts, contact persons, balances and transaction history.
- Employees: name, personal numeric code, address, identity document details, employment contract data, job title and occupational code, salary, bonuses, deductions, timesheets, leave, dependants, bank account, data needed for the D112 return — including, where the law requires it, special categories of data (for example sick leave certificates or disability status, processed under Article 9(2)(b) GDPR for employment and social security obligations).
- Documents: incoming and outgoing invoices, receipts, bank statements, journal entries, delivery notes, goods receipt notes, attached files.
- Returns and tax files: D300, D390, D394, D100, D101, D205, D112, D406/SAF-T, e-invoices (UBL, CIUS-RO).
- Imported data from a previous accounting program (SAGA) or from connected online stores (orders, delivery addresses, buyers’ billing details).
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and administering the account, providing platform features, technical support | Art. 6(1)(b) — performance of the contract |
| Subscription invoicing, our own accounting records and archiving | Art. 6(1)(c) — legal obligation (Accounting Law no. 82/1991, Fiscal Code) |
| Hosting and processing customers’ accounting data | Art. 28 GDPR — on the controller’s instructions (the company/practice) |
| Platform security, fraud and abuse prevention, access logs, backups | Art. 6(1)(f) — legitimate interest (protecting the system and customer data) |
| Improving the service based on error reports and aggregated statistics | Art. 6(1)(f) — legitimate interest |
| Commercial communication about new features, if you subscribe to it | Art. 6(1)(a) — consent, withdrawable at any time |
| Defending a legal claim, responding to requests from authorities | Art. 6(1)(c) and (f) |
We take no automated decisions with legal effect on you and we do not carry out profiling for marketing purposes.
4. Recipients of the data
We neither sell nor rent data. We disclose it only to:
- ANAF — when you submit returns or electronic invoices through the Virtual Private Space, using your own authorisation. You initiate the transmission; we only prepare and send the file.
- Banks — when importing account statements or, where the feature is enabled, through PSD2 interfaces, based on the consent you give your bank.
- The e-commerce platforms you connect (WooCommerce/WordPress, Spree) and, where applicable, couriers and payment processors — only for your own orders and deliveries.
- Infrastructure providers: the provider’s own servers, hosted in the European Union; Cloudflare as reverse proxy, DDoS protection and TLS termination; the OnlyOffice document editing service operated on our own infrastructure.
- Professional advisers (accountant, auditor, lawyer) and, upon a lawful request, public authorities, within the limits of the law.
All processors we work with are contractually bound to confidentiality and to security measures at least equivalent to ours. An up-to-date list of sub-processors is available on request and in the data processing agreement.
5. Transfers outside the European Union
Data is stored on servers located in the European Union. As a rule we do not transfer data outside the EU/EEA.
The only routine exception is traffic passing through the global Cloudflare network (reverse proxy and protection), where content may be transiently processed at the nearest point of presence. This transfer relies on the Standard Contractual Clauses approved by the European Commission and, where applicable, on the EU–US Data Privacy Framework. If in the future we use a service that entails further transfers (for example an artificial intelligence processor), we will update this policy before enabling the feature.
6. How long we keep data
| Category | Retention |
|---|---|
| Supporting documents and accounting registers of the companies | The periods set by Accounting Law no. 82/1991 and its implementing rules — as a rule 5 years, and 5 years for payroll statements (the employer must still be able to prove service length and income over the long term; registers and annual financial statements are kept for 10 years) |
| Invoices and our own accounting records | 10 years from the end of the financial year |
| Platform account data | For the duration of the contract + 3 years (general limitation period) |
| Technical and security logs | Normally 12 months, longer only if an incident requires it |
| Backups | Rotation of at most 90 days; deletion from the live database propagates when the backup expires |
| Support correspondence | 3 years |
On termination you have 30 days to export; afterwards data is deleted or anonymised, except what the law obliges us to keep.
7. Your rights
Under Articles 15–22 GDPR you have the right:
- of access — to learn whether we process your data and to receive a copy;
- to rectification — to correct inaccurate or incomplete data;
- to erasure (“right to be forgotten”) — within the limits of statutory retention obligations;
- to restriction of processing — in the cases set out in the Regulation;
- to portability — to receive your data in a structured, commonly used, machine-readable format; the platform offers export in open formats;
- to object — to processing based on legitimate interest;
- to withdraw consent at any time, without affecting the lawfulness of prior processing;
- not to be subject to automated decisions with significant effects.
Requests go to [email protected]. We answer within one month of receipt, extendable by two months for complex requests, with notice to you. For data where we are only a processor, we forward the request to the controller (the company or practice) and assist it in answering.
Complaint to the supervisory authority
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):
- B-dul G-ral Gheorghe Magheru 28–30, sector 1, postal code 010336, Bucharest, Romania
- Phone: +40 318 059 211 · Fax: +40 318 059 602
- Email: [email protected] · Web: www.dataprotection.ro
You may also bring the matter before the courts.
8. Data security
- Fully encrypted traffic (HTTPS/TLS) between the browser and the platform; certificates are renewed automatically.
- Passwords are stored as salted cryptographic hashes, never in clear text; two-step authentication is available.
- Company isolation — each company has its own data space; access is verified on every request, both in the interface and in the programming interface.
- Internal access on a strict need-to-know basis, with logging of administrative operations.
- Regular backups, tested by restore; test environments kept separate from production.
- Security updates applied to platform components and to the operating system.
- Network-level protection (filtering, rate limiting, DDoS protection through Cloudflare).
In the event of a personal data breach that presents a risk, we notify ANSPDCP within 72 hours and inform affected customers without undue delay.
9. Cookies
The portal uses only cookies strictly necessary for it to work (session, language, selected company). We use no advertising or behavioural analytics cookies. The full list is in the Cookie Policy.
10. Children
The service is not aimed at minors and we do not knowingly collect children’s data through platform accounts. Under Article 8 GDPR and Romanian Law no. 190/2018, the minimum age for giving one’s own consent in the information society is 16 in Romania. Children’s data may appear in customers’ payroll records (for example dependants); there the controller is the employer and the basis is a legal obligation.
11. Data protection contact
We are not legally required to appoint a Data Protection Officer, but we have designated a contact person for all data protection matters. Write to [email protected] with “GDPR” in the subject line, or to the postal address in the section below.
12. Changes to this policy
We update this policy whenever the way we process data changes. The last-updated date is shown in the page header. Important changes are communicated by email or through an in-app notice.
Provider identity
- Company
- CESIRO TRADING SRL
- Tax ID
- 37705493
- Trade Register
- J01/685/2017 (EUID ROONRC.J1/685/2017)
- Registered office
- Str. Theodor Pallady 5, Alba Iulia, jud. Alba, România
- [email protected]
- Platform
- Eva-Accounting — https://acc.eva-org.com