1. Who We Are
Controller: Interactive Media Solutions S.R.L., CUI 37237457, Reg. Com. J18/241/2017, Str. 23 August nr. 1B, Târgu Jiu, Gorj, Romania. Privacy contact: privacy@brivio.ro. The supervisory authority is ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), www.dataprotection.ro.
2. Personal Data We Process as Controller
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email, phone, password hash, passkeys, avatar | You |
| Organization data | Company name, CUI, role, billing details | You / public registries |
| Usage data | Pages accessed, feature usage, device and browser info, IP address | Automatic |
| Payment data | Plan, invoices, partial card data (via payment processor) | You / processor |
| Support data | Tickets, emails, chat transcripts | You |
| Signature audit data | IP, timestamp, user agent, consents on the public signing page | Signatories |
| Marketing data | Newsletter subscription, preferences, consent records | You |
3. Purposes and Legal Bases
| Purpose | Legal basis (GDPR art. 6) |
|---|---|
| Providing the Service and managing your account | Contract performance — art. 6(1)(b) |
| Billing, accounting, fiscal reporting | Legal obligation — art. 6(1)(c) |
| Security, fraud prevention, audit logging | Legitimate interest — art. 6(1)(f) |
| Signature audit trail on public signing pages | Legitimate interest and legal obligation (evidence) |
| Product analytics (aggregated) | Consent — art. 6(1)(a), via cookie preferences |
| Marketing communications | Consent — art. 6(1)(a), withdrawable at any time |
| Legal claims and compliance requests | Legal obligation / legitimate interest |
4. Health Data, Workplace Monitoring and Mailbox Access
Some modules necessarily handle data that deserves separate explanation. Where your organisation uses them, your organisation is the controller of that data and Brivio processes it on your instructions under the Data Processing Agreement. What follows describes what the platform does, so that you can give your own employees the information Article 13 requires you to give them.
Health data in payroll (Article 9). Medical leave records hold the absence type, the medical certificate number, the period and the paid percentage, and payroll runs hold the corresponding sick-leave amounts and the FNUASS reimbursement claim. The absence type discloses a health-related fact about a named employee, so this is special-category data. The permitted ground is Article 9(2)(b) — obligations in the field of employment and social security — read with Romanian labour and social-insurance law; the corresponding Article 6 ground is compliance with a legal obligation. This data is transmitted to the Casa de Asigurări de Sănătate for reimbursement and, as a suspension reason code, to Inspecția Muncii and ANAF. It is retained for the statutory employment-record period and is not used for any other purpose. Certificates and medical fitness documents uploaded as employee documents are stored as files and are not read by us.
Employee and dependant national identification numbers. CNPs of employees, their dependants, day labourers and, where applicable, accommodated guests are stored encrypted, with only the last four digits held in the clear for identification in the interface. They are transmitted to the authorities that require them by law — REGES/REVISAL, ANAF and the health-insurance house. Article 87 GDPR and Romanian law govern their use; they are never used for profiling or marketing.
Driver working time and tachograph data. Where the transport module is used, driver cards and tachograph files are imported and produce activity records — driving, other work, availability, rest — and infringement records against the driving and rest-time limits. These are linked to an identified driver. The ground is compliance with a legal obligation under Regulation (EC) 561/2006 and Regulation (EU) 165/2014, together with the employer’s legitimate interest in road safety and in demonstrating compliance during a roadside or premises check.
Vehicle location. Where a telematics unit is connected, vehicle positions, speed, ignition state, odometer and fuel level are recorded and stored in our database. Where a driver is assigned to the vehicle, that is monitoring of an identified worker. The ground is the employer’s legitimate interest in vehicle security, dispatch and proof of delivery, balanced against the driver’s privacy. Two safeguards are built in: positions are automatically deleted after the retention period set in your transport settings, which defaults to 90 days, and a privacy mode is available that reduces location precision. Article 88 GDPR and Romanian labour law require you to inform your drivers in advance, to consult their representatives where they exist, and not to monitor outside working time; the platform does not do this for you.
Mailbox access. If you connect a mailbox, the platform reads it and stores messages in our database: sender and recipients, subject, the full message body and attachments. The Gmail authorisation we request also allows sending on your behalf; the Microsoft authorisation additionally covers files you hold in OneDrive or SharePoint. Message content can contain anything the correspondent chose to write, including health information about third parties. Where you enable automatic classification, the subject and the first part of the body are sent to the AI provider described in the AI Disclosure. Disconnecting the mailbox stops further synchronisation; deleting the account deletes the stored copies.
Litigation data. Company profiles and court-case monitoring reproduce information published on the courts’ own public portal, which can name natural persons as parties. Where a file concerns a criminal matter, this is Article 10 data and we process it only as published, only for the purpose of assessing a counterparty, and never to build a profile of an individual. We do not hold criminal record certificates; for transport managers we store only the date on which good repute was attested.
5. Automated Scoring and Profiling
Some features evaluate a business partner, a transaction or a document automatically and present the result to a human. We list them here so that the logic involved is visible, as Articles 13(2)(f) and 14(2)(g) GDPR require. Most concern companies rather than individuals, but a Romanian sole trader, an authorised natural person (PFA) or a named employee can be the subject, so we treat them all as profiling.
None of these produces a decision that has legal effects on a person, or similarly significantly affects them, without a human being able to intervene. The one automatic effect in the list — refusing to credit a self-referred affiliate commission — concerns a commercial reward, is reviewable by our team and can be contested by writing to privacy@brivio.ro.
Our legal basis is legitimate interest under Article 6(1)(f): preventing credit losses, detecting fraud and error, and meeting our own transport and anti-money-laundering duties. We have assessed that interest against the rights of the people concerned, taking into account that the outputs are advisory, that the underlying data is largely drawn from public registers, and that a human decides. You may object at any time under Article 21, and you may ask us for the reasoning behind any individual result.
| Activity | What it uses | What it produces | Consequence |
|---|---|---|---|
| Partner creditworthiness ("bonitate") | Public registry status (insolvency, dissolution, inactivity, VAT), publicly filed litigation, and your own payment history with that partner | A score from 0 to 100 and a green/amber/red band with the reasons that produced it, refreshed weekly and stored | Advisory only. It is shown next to the partner and does not block anything. Credit limits that do block are the ones you set yourself |
| Public company financial score | Balance-sheet series published by ANAF and ONRC | A score and an A–D class, calculated when the page is displayed and not stored | Informational display on a public company profile |
| Expense anomaly detection | Your own expense records — vendor, amount, VAT rate, category and date — against your last twelve months | A typed flag such as possible duplicate, unusual amount, unusual VAT or weekend entry, with a severity | Advisory. It appears in a review queue and can be dismissed; dismissal is recorded |
| Affiliate fraud detection | Click and signup records for the affiliate programme, including a hashed IP address, click velocity and whether the affiliate and the referred account are the same person | A score from 0 to 100 with a stated reason | A self-referral is refused automatically at the moment of attribution. Every other flag goes to a human queue, and confirming one reverses the commission |
| Transport counterparty risk | Carrier licence and CMR insurance data you enter, plus public registry status and published financials | A risk score with contributing factors and a low/medium/high band, stored on the subcontractor | Advisory. A high band asks for an explicit override before you assign a load; nothing is refused outright except a legal impossibility |
| Fuel and odometer anomaly detection | Refuelling records and odometer readings for a vehicle, which may be linked to the driver assigned at the time | A discrepancy notice, and for odometers a stored anomaly record | Advisory. It is acknowledged by a person and gates nothing |
| Engagement rate anomaly | Recorded hours, amounts billed and the planned rate on a professional-services engagement | A report of engagements billed away from plan, not stored | Advisory management reporting. No individual consequence |
| Sanctions screening | Official EU, UN, UK and OFAC lists matched by exact company identifier | A match record against a company profile | Displayed on the public company profile. Individuals are excluded from this matching, and no politically-exposed-person screening is performed |
| Tender fit assessment | Your organisation’s activity codes and the published text of a public tender notice, evaluated by a language model | A fit score from 0 to 100 with a written rationale, stored on the tender | Advisory. It is requested by you and ranks opportunities; it decides nothing |
6. Retention Periods
| Data | Retention | Reason |
|---|---|---|
| Account data | Duration of account + 3 years | Limitation periods for claims |
| Invoices and fiscal records | 10 years (5 years for records after Law 36/2023 harmonization, per document type) | Accounting Law 82/1991, Fiscal Code |
| Audit logs | 5 years | Security, evidence |
| Signature audit trails | 10 years from signing | Evidence of contract execution |
| Support tickets | 3 years after closure | Service quality, claims |
| Marketing consents | Until withdrawal + 3 years proof | Accountability |
| Backups | Rolling 35 days | Disaster recovery |
| Cookie consent record | 24 months | Proof of consent (art. 7(1) GDPR) |
| Campaign attribution cookie | 90 days | Consent; measuring which campaigns work |
7. Recipients and Sub-processors
We share personal data only with: (a) sub-processors listed on the Sub-processors page (hosting, email delivery, payments, error monitoring, AI infrastructure); (b) public authorities where legally required (e.g., ANAF for e-Factura transmissions you initiate); (c) professional advisors under confidentiality. We never sell personal data.
8. Cookies and Similar Technologies
We use cookies and equivalent storage (localStorage, sessionStorage) in four categories: strictly necessary, functional, analytics and marketing. Only the strictly necessary category runs without your permission — everything else stays blocked until you allow it, and stops if you withdraw.
Your choice is stored for 6 months across brivio.ro and its subdomains, so one decision covers the whole platform. You can change or withdraw it at any time from the cookie icon at the bottom of any page; withdrawal takes effect immediately and deletes the cookies in the categories you removed.
Because art. 7(1) requires us to be able to demonstrate consent, we keep a record of each decision for 24 months: the date, the policy version, the categories chosen, the site, your browser's user-agent and an irreversible hash of your IP address. We never store the address itself.
Error monitoring (Sentry) runs without cookies and without consent, as a legitimate interest under art. 6(1)(f): it is how we detect breakdowns and security problems. Session replay, which records how a page was used, is separate and runs only with analytics consent. You may object to legitimate-interest processing at any time under art. 21.
On the sign-in page we load Google's identity library so you can use "Continue with Google". That is authentication you asked for and is treated as strictly necessary; on all other pages the same prompt appears only with functional consent.
The full list of cookies, their purposes and lifetimes is in our Cookie Policy at /cookies.
9. International Transfers
Data is hosted in the European Union. Where a sub-processor processes data outside the EEA, we rely on adequacy decisions or Standard Contractual Clauses with supplementary measures. Details per provider are on the Sub-processors page.
10. Your Rights
Submit requests via the GDPR page's request form or at privacy@brivio.ro. We respond within one month, extendable by two months for complex requests.
- Access (art. 15) — obtain a copy of your personal data.
- Rectification (art. 16) — correct inaccurate data.
- Erasure (art. 17) — deletion where no legal retention duty applies.
- Restriction (art. 18) and objection (art. 21), including to legitimate-interest processing.
- Portability (art. 20) — receive your data in a structured, machine-readable format; the Service provides self-service export.
- Withdraw consent at any time, without affecting prior processing.
- Complaint to ANSPDCP (www.dataprotection.ro) or your local supervisory authority.
11. Security Measures
We apply technical and organizational measures including encryption in transit (TLS) and at rest, tenant isolation at the organization boundary, role-based access control, hash-chained append-only audit logs, passkey/two-factor authentication, and regular backups. See the Security page for our posture and vulnerability disclosure process.
12. Children
The Service is intended for business use and not directed at children under 16. We do not knowingly process children's data.
13. Changes to this Policy
Material changes are notified via email or in-product notice before taking effect. The version and effective date are shown at the top of this page.
In case of divergence between language versions, the Romanian version prevails.