Skip to content
eFacturaSPV

Legal

Privacy Policy

How we collect, use and protect your personal and fiscal data, in line with Regulation (EU) 2016/679 (GDPR).

Last updated: 9 August 2026

1. Data controller

The controller of the personal data processed through this service is NORTHDAN SOFT S.R.L. (referred to below as “eFacturaSPV”, “we”), registered in Str. Iuliu Maniu nr. 19C, Mun. Aiud, Jud. Alba, fiscal ID RO44282833, entered in the Trade Register under J2021000717015, which operates the website efacturaspv.ro and the application app.efacturaspv.ro.

2. What data we collect

We collect strictly the data needed to provide the service:

  • Account data (authentication). Your email address, used for passwordless sign-in via a one-time email link. We do not store passwords. We retain minimal technical session data (for example the time of sign-in).
  • Invoice data received from ANAF. For each invoice received through e-Factura / SPV we keep the original XML, the official PDF generated by ANAF, and the related metadata: supplier, fiscal ID, number and series, amounts (net, VAT, total), issue and due dates, and the ANAF transmission identifiers. This data may contain information about natural persons (for example sole-trader suppliers).
  • ANAF connection tokens and metadata. ANAF’s official tokens (access / refresh), the certificate serial and issuer, the roles, and the list of fiscal IDs the certificate is authorized for. The qualified certificate and USB token are used locally, once, at authorization — we do not receive or store them.
  • Data about the archive in Google Drive. Your Google connection tokens, the identifier of the archive folder you choose, and the name, identifier and location of the files archived there — needed to archive the invoices and to avoid uploading them twice. If you turn on the archive check, we also see the names and locations of the files you put in that folder yourself. What the app can see, and when, is set out in section 6.
  • Your customers' data (invoices you issue). When you issue invoices through the app we keep what you enter about the customer: company or personal name, address, fiscal ID (CUI/CIF) or personal ID (CNP) where the law requires it, email and payment terms, plus the documents issued. For this data you are the controller and we process it on your instructions, as a processor (see the DPA).
  • Bank statements you upload. The uploaded file and the transactions read from it — date, amount, currency, direction, description, bank reference and, where the statement contains them, the counterparty's name and IBAN. We use them to match payments to your invoices (see section 7).
  • Billing data (paid plans). Your company name or your name, fiscal ID (CUI/CIF), billing address, email, and your subscription and payment history — needed to manage the subscription and issue the fiscal invoice. Your card details never touch our servers: you enter them directly into Stripe’s secure hosted form.
  • Technical and operational data. Technical logs generated as the service runs, needed for security, troubleshooting and abuse prevention.

The data above is required in order for us to provide the service and, where stated, to meet legal obligations. Without it we cannot open the account or pull your invoices from SPV.

PurposeLegal basis (GDPR)
Creating the account, email-link sign-in, providing the application Art. 6(1)(b) — performance of a contract (the Terms of Service)
Pulling, displaying and managing invoices received from SPV Art. 6(1)(b) — performance of a contract
Archiving your invoices (XML/PDF) and keeping them for the statutory period. The archiving obligation is yours, as a company; we carry it out on your instructions Art. 6(1)(b) — performance of a contract, with Art. 28 for processing on your behalf
Issuing your invoices and transmitting them to SPV / e-Factura Art. 6(1)(b) — performance of the contract
Matching payments to invoices from the statement you upload Art. 6(1)(b) — performance of the contract; Art. 6(1)(f) — legitimate interest, for people appearing in the statement who are not your customers
Security, fraud prevention, technical logs Art. 6(1)(f) — legitimate interest
Service emails (sign-in link, essential notifications) Art. 6(1)(b) — performance of a contract
Managing the subscription and processing payments (via Stripe) Art. 6(1)(b) — performance of a contract
Issuing and retaining fiscal invoices (RO e-Factura) Art. 6(1)(c) — legal obligation (fiscal)
Checking a VAT number against the European Commission’s VIES register when you fill in your billing details Art. 6(1)(c) — legal obligation (applying the correct VAT treatment)
Populating the public company directory on this website with the fiscal IDs of the companies you save as customers (see section 4) Art. 6(1)(f) — our own legitimate interest, for a public directory of already-public data
Measuring visits and ads on the marketing website Art. 6(1)(a) — consent, which you can withdraw at any time

We do not use your fiscal data for marketing purposes, and we never sell it.

When you are the controller and when we are

For the data inside your company’s invoices — your customers, your suppliers, the amounts — you are the controller, and we process it only on your instructions, as a processor. The terms are in the data processing agreement.

We are the controller for: your account and sign-in, your subscription and the invoices we issue to you, the security of the service, measurement on the marketing website, the data in uploaded bank statements, and the public company directory. There, the processing is ours to answer for, and we answer to you for it.

4. Who receives the data

Authorities, which answer for the data themselves

  • ANAF. The Romanian tax authority is the source of the invoices you receive and the recipient of the ones you issue. We connect through ANAF’s official authorization, with no middleman. For the SPV / e-Factura system ANAF is a controller in its own right and answers for that processing itself — it does not work for us and we cannot instruct it. When you look up a company or save a customer, we send that company’s fiscal ID to ANAF’s public service to find out whether it is VAT-registered and active.
  • The European Commission (VIES). When you enter a VAT number from another European Union country in your billing details, we send it to the Commission’s VIES service to check that it is valid. Without this check we cannot apply the correct VAT treatment.

Providers that process data for us

Each works under a data processing agreement and only for the purpose below:

  • Google (Google Drive). Storage chosen and controlled by you: PDFs are archived in your own Google Drive account, in the folder you choose. These files stay under your control. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
  • Stripe (payments). Stripe Payments Europe, Ltd. processes card payments for the paid plans. Card details are entered directly into Stripe’s hosted form and never touch our servers.
  • Resend. Provider for delivering transactional emails (the sign-in link and essential notifications). It processes your email address for this purpose.
  • Hetzner Online GmbH (hosting). The infrastructure on which the application and database run, on servers in the European Union (Germany).
  • Cloudflare (CDN / DNS). Traffic delivery and protection for the website and the application. It receives your IP address and your browser’s requests.
  • Google (fonts, in the application). The application at app.efacturaspv.ro loads its fonts from Google, which therefore receives your IP address when you open its pages. The marketing website serves them from our own domain, so it does not.
  • Google (measurement on the marketing website). Only if you accepted in the cookie banner, Google Analytics and Google Ads receive your IP address, the pages you open and, if you arrived from an ad, the code in that link. Nothing from the application and no invoice ever reaches them. Details and how to withdraw are in section 12.

Where you send the data

The app can automatically send your invoice data to a web address you configure, so you can pull it into another program. It runs only if you set it up, it sends to the address you give it, and from the moment the data arrives there it is your responsibility. You can stop or delete it at any time in the app.

Beyond the above, data may only be disclosed to authorities that request it under the law and to our own advisers (for example an accountant or lawyer), where necessary.

The public company directory

On this website we publish profile pages for Romanian companies, built from public data: name, fiscal ID, registration number, status, filed financial statements. When you save or edit a customer in the app, that company’s fiscal ID enters the list we build the directory from, and that company’s page may appear publicly and in search engines.

Two things matter here. First, we publish only data that is already public about the company — never your invoices, the amounts, your commercial terms, or the fact that the company is your customer. Second, this is processing in our own interest, not something done on your instructions: we answer for it as controller, not you. If you represent a company and want its page taken down, write to [email protected] and we will remove it.

5. Subscriptions, payments and billing

For paid plans, payments are processed by Stripe Payments Europe, Ltd., acting as a processor. You enter your card details directly into Stripe’s secure hosted form — they never touch our servers. We process your billing details (name, fiscal ID, address) to manage the subscription — art. 6(1)(b) GDPR, performance of a contract — and to issue the fiscal invoice — art. 6(1)(c) GDPR, legal obligation.

For every payment we automatically issue a compliant RO e-Factura fiscal invoice, submitted to ANAF’s SPV; you can view and download it (XML / PDF) in the app. Issued invoices and the related billing data are retained for 5 years, counted from 1 July of the year following the one in which they were drawn up, under the Romanian Accounting Act no. 82/1991 as amended by Act no. 36/2023. This retention survives account deletion.

6. Google Drive access

The app has two kinds of access to your Drive. The first comes with connecting it; the second you switch on yourself and can switch off at any time.

Basic access: only the files we put there

When you connect Google Drive, you allow us to work only with the files and folders created by the app or picked by you through Google’s own file picker. All the rest of your Drive stays invisible to us: we cannot search it, we cannot list it, and we do not know what else is there.

  • We write invoice PDFs and XMLs into the folder you choose, arranged by month (2026.03 and so on), and within each month separately Vanzari for what you issue and Achizitii for what you receive. Monthly exports go into _export.
  • We read the name, identifier and location of the files we put there, so we never upload the same invoice twice and can find them again if you move or rename them.
  • The files live in your Google account and stay there after you delete your account with us.
  • You can revoke access at any time, from the app or from your Google account settings.

Extended access: the archive check

Basic access has a limit: we cannot see the files you put in the archive folder yourself, so we cannot check whether your archive is complete. To make that possible, we ask you to share the archive folder with the app’s robot account, exactly as you would share a folder with a colleague. Whether you do is your call.

If you do, here is what changes, without nuance:

  • The robot sees everything in that folder, including subfolders and files put there by you or anyone else, not only the ones the app put there. It sees the name, size, date and location of every file.
  • We never read what is inside the files, and we delete nothing — neither the robot nor the app.
  • If you grant it Viewer, the robot only looks. If you grant it Editor, it can additionally move files from one subfolder to another inside the archive, when the same month has ended up split across two folders and they need to be merged. They remain your files, in your account.
  • The sharing can be withdrawn at any time from Google Drive, straight from the folder, without going through the app. After that the archive check stops working, but the rest of the service runs normally.

7. Bank statements you upload

Payment matching starts from a file you upload: the statement you download from your banking app (PDF, MT940, camt.053 or CSV). We do not connect to your bank — we never ask for or receive banking credentials, we do not see your live balance, and we cannot initiate payments.

For statement data we are the controller, because it describes payments into your account as recorded in our app, not the documents you issue.

  • What we keep. The uploaded file as you gave it to us, plus what we read from it: your account IBAN, the statement period, the opening and closing balances, and each transaction with its date, amount, currency, direction, description, bank reference and, where the statement contains them, the counterparty’s name and IBAN.
  • What we use it for. To match payments to your invoices. Normally we propose the match and you confirm it. If you turn on automatic confirmation — it is off until you switch it on — the app marks the invoice as paid by itself, but only when the amount matches exactly and there is a single possible invoice; in any other case it still proposes it to you.
  • Counterparty data. It stays inside the matching: it never appears in exports, in data sent to other programs, in emails, or in another company in the app. The rule is checked automatically on every change to the program, so it does not depend on anyone remembering it. It governs what leaves the app; database backups naturally contain everything the database holds.
  • What we remember after you confirm. When you confirm that an IBAN belongs to a customer, we remember it for future matching. It is deleted together with that customer, and when you delete the statements.
  • What you can delete. From Settings → Connections you can delete uploaded statements and their transactions at any time. The button deletes all of the company’s statements, not just one, and with them go the learned IBANs and the column layout we had remembered for your CSV files.
  • What survives the deletion. Payments you confirmed stay on their invoices, because they are accounting records. From the statement they keep only the bank, the booking date and the bank reference — not the counterparty’s name and not their IBAN.

8. If your data reached us from someone else

This section is for you if you have no account with us and never gave us any data, but your name is in our system anyway. That happens in two situations.

  • You are a supplier and issued an invoice to one of our customers. The invoice reaches our customer through the ANAF system, and we pull it from there on their behalf. From it we hold your company or personal name, your fiscal ID, your address, your bank details if you put them on it, and the number, amounts and description of the goods or services.
  • You appear in a bank statement uploaded by one of our customers. From the statement we hold your name and IBAN as the bank wrote them, plus the amount and the payment description.

We use this data only so that our customer can keep their records: to see and archive the invoices they receive and to know what has been paid. We build no profile of you, we send you no marketing, and we sell this data to no one.

We cannot write to each of you individually. The data comes from invoices and statements, often without a valid contact address, and a company may receive thousands of invoices a year; attempting to contact every supplier and every person in a statement individually would take a disproportionate effort. The GDPR provides for exactly this case, in Art. 14(5)(b), on condition that the information is made public — which is what this section is for.

You have the same rights as anyone else: to know what data we hold about you, to correct it, to ask for its erasure, and to object to the processing. Write to [email protected] and we will usually reply within one month. One thing should be said upfront: we cannot delete the invoices, because the law requires our customer to keep them and we hold them on their behalf. If you object, we can instead restrict the processing to what archiving strictly requires, and statement data we can delete.

9. International transfers

Your invoices, documents and company data are hosted on servers in the European Union (Germany). Some providers may process certain data in the United States as well:

  • Google, Stripe and Cloudflare — under the European Commission’s adequacy decision for the EU-US Data Privacy Framework (Implementing Decision (EU) 2023/1795), to which these companies are certified. The Commission found that the United States ensures an adequate level of protection for certified companies, so no additional safeguard is needed.
  • Resend — on the basis of the standard contractual clauses adopted by the European Commission, set out in our data processing agreement with them.

You can obtain a copy of these safeguards by writing to [email protected].

10. How long we keep data, and what happens when you delete

  • Invoices (XML, PDF, metadata): kept for as long as the company exists in the app. The 5-year archiving duty, counted from 1 July of the year following the one in which they were drawn up (Accounting Act no. 82/1991, as amended by Act no. 36/2023), is your company’s; we hold the documents for it. When you delete the company you download the full archive first, then we delete them for good. The XML remains the legal original: ANAF keeps it downloadable from SPV for roughly 60 days, after which it archives it and releases it only on request.
  • Fiscal invoices we issued to you, and billing data: the same 5 years, including after account deletion. These are the documents our own taxes are based on.
  • Account data (email, sessions): kept while the account is active. What happens on deletion is described below.
  • ANAF and Google tokens: kept until disconnection or revocation, after which they are invalidated. We keep them encrypted.
  • Bank statements and their transactions: kept until you delete them from Settings → Connections or until the company is deleted. Payments you confirmed stay on their invoices, as accounting records.
  • Technical logs: we keep them for as long as the service runs and review them periodically. We have not yet set a fixed deletion period; when we do, we will write it here.

What happens when you delete your account

We delete everything tied to your access: sessions, sign-in data, the ANAF authorization, the Google Drive connection, and your membership of companies. Your name and email address are replaced with a meaningless identifier that does not lead back to you.

The company and its invoices stay — they are the company’s documents, which it has to keep for the statutory period, regardless of who still has an account. If you want them gone too, delete the company first, with its archive downloaded, and only then the account.

We cannot delete the account while you have an active subscription; cancel it first.

What happens when you delete a company

A company with no fiscal documents is deleted entirely, together with its received invoices, statements, connections and the rest of its data.

A company holding issued invoices, receipts, payments or other documents is deleted in two steps: you download the full archive first — XML, PDF, receipts, the payment record and the series register — then you confirm by typing the company name. After that we can neither recover nor correct (credit-note) any document.

The 5-year retention duty is your company’s, not ours; the downloaded archive takes its place.

What stays with us after deletion: the record of the operation — who asked for it, when, how many documents were deleted and on which series, plus the fingerprint of the archive we handed over. Never the content of the documents. We keep it for 6 years so we can show, if it is ever disputed, that the deletion was made at your request. Data leaves the backups with their ordinary rotation, within 10 days at most, and a restore does not bring deleted companies back.

You can still bring such a company to a complete stop: disconnect the ANAF certificate in Settings → ANAF integration, and nothing is pulled or sent in its name any more.

PDFs archived in your own Google Drive stay with you in both cases — they live in your account, not ours.

11. Your rights (data subject)

As a data subject, you have the following rights under the GDPR:

  • Access — to know what data we process about you and to receive a copy.
  • Rectification — to correct inaccurate or incomplete data.
  • Erasure (“the right to be forgotten”) — within the limits of our legal archiving obligations.
  • Restriction of processing in certain situations.
  • Portability — to receive your data in a structured, commonly used, machine-readable format. The bulk-download feature (a ZIP of XML/PDF) already helps you here.
  • Objection — to processing based on legitimate interest.
  • Withdrawal of consent, where processing is based on consent, without affecting the lawfulness of earlier processing.

You can exercise your rights by writing to [email protected]. We usually respond within one month.

If you believe your rights have been infringed, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP):

If you live or work in another European Union or European Economic Area country, you may equally approach the supervisory authority there. You may also go to court.

12. Cookies

On the marketing website, until you press a button in the cookie banner we store and read nothing on your device beyond your choice itself, and the page contacts no other service — not even for fonts, which we serve ourselves.

With your consent, and only then, we run:

  • Visit measurement. Google Analytics counts visits and the pages you open, and receives your IP address. Its cookies (_ga, _ga_*) last up to 24 months.
  • Ad measurement. We keep the code from the ad link you opened (gclid, fbclid and similar) in your browser and send it to Google Ads, so we know which ad brings customers. Withdraw your consent and we erase them immediately.
  • Personalized ads. Lets Google show you our ads tailored to you after you visit the site.

Choose “Essential only” and none of these load. In the application we use a session cookie, needed to keep you signed in. You can change or withdraw your choice at any time from the cookie preferences on the site; the full list, with durations, is in our Romanian Cookie Policy.

13. Security

Each company’s data is kept separate from every other company’s, sign-in works by email with no password to remember, the connection tokens for ANAF and Google are stored encrypted, and internal access to data is limited to what is strictly necessary. No system is perfect; if you suspect an incident, please notify us urgently.

14. Contact and data protection officer

We have not appointed a data protection officer. We are not required to: we do not monitor people on a large scale and we do not process special categories of data. Questions about data processing and requests concerning your rights are handled directly by us, at [email protected]. Accountants who process their clients’ invoices through eFacturaSPV can also consult the data processing agreement (DPA).

15. Changes to this policy

We may update this policy as the service evolves or as legal requirements change. We will mark the date of the last update at the top of the page and, for significant changes, notify you by email or in the app.

Frequently asked questions

Privacy questions

What can the app see in my Google Drive?
To begin with, only the files it puts there — the rest of your Drive stays invisible to it. If you turn on the archive check, you share your archive folder with the app’s robot account, and it can then see everything inside that folder, including files you put there yourself. It sees the name, size and location of each file; we never read what is inside them. You can withdraw the sharing at any time, straight from Google Drive.
Do you store my USB token or qualified certificate?
No. The qualified certificate and USB token are used once, locally in your browser, at the moment you authorize ANAF. We never receive, store, or reconstruct the certificate. After authorization we use only ANAF’s official tokens (90-day access / 365-day refresh), which we rotate and keep encrypted.
What invoice data do you keep?
For each invoice received from SPV we keep the original XML (the legal original), a PDF generated by ANAF’s own service, and the related metadata (supplier, fiscal ID, number, amounts, dates). This is needed to display and manage your invoices and for the archiving the law requires of you. Data is isolated per company.
Do you connect to my bank?
No. You download the statement from your banking app and upload it to eFacturaSPV. We never ask for or receive your banking credentials, we do not see your live balance, and we cannot initiate payments. We use the transactions in the file to match payments to your invoices, and you can delete uploaded statements at any time from Settings → Connections.
Can I delete my account and all my data?
You can disconnect ANAF and Google Drive at any time, and request account deletion by writing to [email protected]. Deleting your account removes your access and your sign-in data, and replaces your name and email address with a meaningless identifier. The company’s invoices and fiscal documents stay in the account — they are the company’s documents, which it has to keep for 5 years, and we hold them for it while the company exists in the app. You delete a company separately, with its documents: download the full archive first, then confirm the deletion. PDFs in your own Google Drive stay with you, in your account. Full details in section 10.
Do you transfer my data outside the EU/EEA?
Your invoices and company data sit on servers in the European Union. Google, Stripe and Cloudflare may process some data in the United States under the European Commission’s adequacy decision for the EU-US Data Privacy Framework; Resend relies on the standard contractual clauses. See section 9.

Fiscal data handled like a custodian.

Connect ANAF once; the archive stays in your own Google Drive. See how we protect data.

Free to start · data stays in your own Google Drive

Start free

No card · your first company stays free

Start

Each option starts exactly what it says. Anything you leave unticked does not start. You can change your mind at any time.

Strictly necessary

They remember the choice you make here, so we stop asking, and keep you signed in to the app. The site does not work without them.

Cannot be turned off