1. Parties and subject matter
The controller is the customer: the company or accounting practice that opens the account and uploads data into the platform. The processor is CESIRO TRADING SRL, tax ID 37705493, Str. Theodor Pallady 5, Alba Iulia, jud. Alba, România.
By accepting the Terms of Service you also enter into this agreement, which governs the processing of personal data carried out by the provider on the controller’s behalf within the Eva-Accounting service. It applies automatically to every customer, with no separate signature required; on request we will also sign it on paper or electronically.
2. Details of processing (Art. 28(3))
| Element | Description |
|---|---|
| Subject matter | Provision of the Eva-Accounting platform for accounting, payroll, tax reporting and connected commerce. |
| Duration | For the term of the subscription, plus the export window and the expiry of backups. |
| Nature and purpose | Storage, structuring, computation, generation of documents and reporting files, transmission to recipients designated by the controller (ANAF, banks, stores), backups, technical support. |
| Types of data | Identification and contact data, employment contract and payroll data, personal numeric codes, bank accounts, financial and transaction data, the content of uploaded documents, usage logs. Occasionally special categories (health data from medical certificates, disability status) processed solely for employment law obligations. |
| Categories of data subjects | Employees of the controller and of client companies, directors and contact persons, customers and suppliers (individuals or representatives), buyers from connected online stores. |
3. The processor’s obligations
- Processing only on instructions. We process data only on the controller’s documented instructions. The Terms of Service, the configuration you set in the platform and the operations you trigger from the interface constitute instructions. If Union or Romanian law requires additional processing, we inform you beforehand unless the law forbids such notice.
- Confidentiality. Staff with access to data are bound by contractual confidentiality obligations that survive the end of employment.
- Security. We apply the technical and organisational measures set out in section 4.
- Sub-processors. We use them only under the conditions in section 5.
- Assistance with data subject rights. We provide search, export, correction, anonymisation and deletion features so that the controller can answer the requests it receives. If a data subject contacts us directly, we refer them to the controller and inform you.
- Assistance with Articles 32–36. We supply the information needed for data protection impact assessments and for consulting the supervisory authority, in so far as it concerns the platform.
- Deletion or return on termination. As set out in section 7.
- Information and audit. As set out in section 8.
4. Technical and organisational measures
- Encryption: all traffic over HTTPS/TLS; server disks are encrypted; backups are encrypted.
- Access control: named accounts, roles with least necessary privilege, two-step authentication available, passwords stored as salted cryptographic hashes.
- Customer isolation: each company has its own data space; company membership is verified on every request, both in the web interface and in the programming interface, and a user’s access is limited to the portfolio assigned to them.
- Traceability: audit log for sign-ins, document changes and administrative operations; who, what, when.
- Availability: regular backups, tested by restore; service monitoring; test environments separated from production, with anonymised test data.
- Network security: edge filtering, rate limiting, DDoS protection, security updates applied regularly.
- Organisation: staff training, incident management procedures, records of processing activities, strict need-to-know for support access.
Measures may be improved over time; they will not be reduced below the level described here for the term of the contract.
5. Sub-processors
The controller gives general authorisation for the use of sub-processors. The current categories are:
| Sub-processor | Role | Location |
|---|---|---|
| The data centre provider hosting the platform servers | Hosting, storage, connectivity | European Union |
| Cloudflare | Reverse proxy, TLS termination, DDoS protection, filtering | Global network, under Standard Contractual Clauses |
| OnlyOffice document editing service | Document editing, operated on the provider’s infrastructure | European Union |
| Transactional email provider | Sending notifications and system messages | European Union |
With each sub-processor we conclude a contract imposing data protection obligations equivalent to those in this agreement. We give you at least 30 days’ notice before adding or replacing a sub-processor. Within that period you may object on reasoned grounds; if we cannot find a reasonable alternative, you may terminate the affected service without penalty.
6. Personal data breach notification
- We notify you without undue delay and within 48 hours at the latest of becoming aware of a personal data breach affecting you, so that you can meet your own 72-hour notification duty towards the authority.
- The notification covers: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and contact details.
- If the information is not complete at the outset, we provide it in phases without delaying the first notification.
- We document all incidents internally and make the documentation available to the controller on request.
7. Deletion or return of data
- During the contract you may export your data at any time, in open formats, from the platform.
- On termination you have 30 days to export. On request we can provide a complete archive of the company’s database.
- After that period we delete the data from live systems within 30 days, and from backups as those expire, within at most 90 days.
- Excepted is data we are legally required to keep (for example our own billing documents) and data needed to establish or defend a legal claim; that data remains stored in isolation, with restricted access.
- On request we confirm deletion in writing.
8. Audit and verification
- We make available to the controller the information needed to demonstrate compliance with Article 28 GDPR: a description of technical measures, internal policies, and summarised security test results.
- The controller may request an audit at most once a year — or whenever an incident affecting it has occurred — with reasonable notice, during business hours, either itself or through an independent auditor who is not a competitor of the provider and who signs a confidentiality undertaking.
- An audit must not compromise other customers’ security: no access is granted to other controllers’ data or to shared components that would expose such data.
- Audit costs are borne by the controller, unless the audit finds a material non-compliance attributable to the provider.
9. International transfers
Processing takes place in the European Union. Transfers outside the EU/EEA are limited to those described in the Privacy Policy (the Cloudflare network) and rely on the Standard Contractual Clauses approved by the European Commission. We will not introduce a new transfer without informing the controller beforehand.
10. Liability and final clauses
- Each party is responsible for its own obligations under the GDPR. The liability limitations in the Terms of Service also apply to this agreement, to the extent permitted by law.
- The controller warrants that it has a legal basis for the data it uploads, that it has informed the data subjects, and that the instructions it gives the processor comply with the law.
- In case of conflict between this agreement and the Terms of Service, this agreement prevails as regards personal data processing.
- The agreement is governed by Romanian law and European Union law.
For a signed copy of this agreement or a detailed list of sub-processors, write to [email protected].
Provider identity
- Company
- CESIRO TRADING SRL
- Tax ID
- 37705493
- Trade Register
- J01/685/2017 (EUID ROONRC.J1/685/2017)
- Registered office
- Str. Theodor Pallady 5, Alba Iulia, jud. Alba, România
- [email protected]
- Platform
- Eva-Accounting — https://acc.eva-org.com