⚠️ DRAFT — pending legal counsel review. Last reviewed 2026-05-12. See
pending-legal-counsel-reviewfor the scope of pending redlines. This document is the working draft for the V1 closed beta; the V1.5 public-launch version will be reviewed by Romanian data-protection counsel before going live.
Privacy Policy
Version: 1.5-draft · Last reviewed: 2026-05-12
This policy explains what data we collect through Nodex (marketing site nodex.nodera.ro and application app.nodex.nodera.ro), why we collect it, who we share it with, and what rights you have under Regulation (EU) 2016/679 (GDPR) and applicable Romanian law.
Data Controller
The current operator of the Nodex service is Andrei Buliga Persoană Fizică Autorizată (PFA), tax ID (CUI) 54243750, registered office at Strada General Petre Popovăț 57, et. 1, ap. 11, Sector 6, Bucharest, Romania. Dedicated data protection contact: privacy@nodex.nodera.ro. Founder contact: andrei.buliga@nodera.studio.
Upon incorporation of Nodex SRL (planned mid-2026), the operator will transfer to the new legal entity with 30 days' prior notice to all active users, pursuant to GDPR Art. 13 and the terms below.
Data we collect
Marketing site (nodex.nodera.ro)
| Category | Example | Source | | -------------------------------- | -------------------------------------------------------------------------------- | --------------- | | Cookieless analytics (Plausible) | pageviews, traffic source, country, device (aggregate, no persistent identifier) | navigation | | Waitlist form | email, segment (SMB / accountant / sole-trader), UTM parameters | user-submitted | | Turnstile token (Cloudflare) | ephemeral anti-bot challenge token, strictly necessary | form submission |
Application (app.nodex.nodera.ro)
| Category | Example | | ------------------ | ------------------------------------------------------------------ | | Account | email, bcrypt password hash (Supabase Auth), display name | | Organization | name, tax ID (CUI), IBAN, registered office | | Fiscal data | invoices issued/received, line items, trial balance, SAGA mappings | | Expense OCR | uploaded images/PDFs, extracted supplier data (name, CUI, totals) | | Audit log | action UUID, user, timestamp, mutation type | | Push notifications | subscription endpoint, VAPID public key |
Purposes and legal basis
| Data category | Purpose | Legal basis (GDPR Art. 6) | | -------------------------------------------------------------------- | ----------------------------------------------------- | ---------------------------------------------------------------------------------------- | | Account, organization | Provision of SaaS service | Art. 6(1)(b) — contract performance | | Fiscal data, audit log | Romanian fiscal compliance (e-Factura, SAF-T) | Art. 6(1)(c) — legal obligation (Law 82/1991 Art. 25; GEO 89/2025; ANAF Order 2634/2015) | | Security (Turnstile, rate limiting, in-app session replay post-auth) | Fraud and abuse prevention | Art. 6(1)(f) — legitimate interest | | Marketing waitlist | Beta launch notification | Art. 6(1)(a) — explicit consent on submission | | Expense OCR (Mistral) | Extracting supplier data from user-uploaded documents | Art. 6(1)(b) — contract performance | | AI categorization (Vertex) | Suggesting accounting categories (V1.5+) | Art. 6(1)(b) + 6(1)(f) |
Sub-processors
All sub-processors are EU-resident. No data transfers outside the EEA for EU users and no Standard Contractual Clauses (SCCs) are required for V1.5.
| Sub-processor | Role | Region | Transfer mechanism |
| --------------------- | ------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------ |
| Supabase Cloud Pro | Postgres + Auth + Realtime | Ireland (AWS eu-west-1) (source: simplebackups.com/blog/gdpr-compliant-supabase-backup) | EU only, no SCC |
| Cloudflare R2 | Fiscal document archive with indefinite Object Lock | EU jurisdiction | EU only, no SCC |
| Hetzner | Application hosting (Coolify, NestJS monolith) | Germany (Frankfurt) | EU only, no SCC |
| Resend | Transactional email | Germany | EU only, no SCC |
| Stripe Direct | Payment processing — Test Mode in V1; Live Mode at V1.5 launch | Ireland (Stripe Payments Europe Ltd.) for EU customers; United States for non-EU customers (disclosed explicitly) | EU: SPEL as Processor; non-EU: SCCs + Data Privacy Framework |
| Mistral La Plateforme | Document OCR (mistral-ocr-2512) — no training on input | Paris, France | EU only, no SCC |
| Google Vertex AI | LLM categorization (active in V1.5; scaffolded in V1) | Frankfurt, europe-west4 | EU only, no SCC (Vertex EU region-locked) |
| Sentry (Functional Software) | Error monitoring — technical telemetry, scrubbed of personal data (CUI / IBAN / email / IP / cookie / authorization header removed before send) | Frankfurt (EU region, de.sentry.io) | EU only, no SCC |
| PostHog, Inc. | Product analytics + masked session replay — pseudonymous usage telemetry, scrubbed of personal data (CUI / IBAN / email / IP removed before send; inputs + text masked in replay) | Frankfurt (EU region, eu.i.posthog.com, AWS eu-central-1) | EU only; legal basis Art 6(1)(f) legitimate interest (LIA); Art 21 opt-out via Settings → Preferences (/settings/preferences) |
Sub-processor change notice: 14 days prior, with right to object and terminate (see DPA).
Retention periods
| Category | Duration | Legal basis |
| ------------------------------------ | ------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Audit log (append-only) | 5 years | Law 82/1991 Art. 25 (as amended by Law 36/2023) — sources: legislatie.just.ro/Public/DetaliiDocument/1576 and contabun.ro/2023/03/01/termenul-de-pastrare-a-statelor-de-salarii-modificari-aduse-prin-legea-nr-362023/ |
| Fiscal documents in R2 (Object Lock) | 10 years | Law 82/1991 Art. 25 (historical version, applicable to documents issued through 31.12.2022) — sources: legislatie.just.ro/Public/DetaliiDocument/224183; accace.ro/pastrarea-si-arhivarea-documentelor-financiar-contabile/ + MFP Order 2634/2015 for specific document classes |
| AI invocation logs (Mistral, Vertex) | 12 months | Legitimate interest — debugging, abuse detection |
| marketing_waitlist rows | Deleted within 90 days of beta promotion, OR within 18 months if never promoted | Consent + minimization |
| Supabase Auth session cookies | 7 days rolling | Strictly necessary for authentication |
| Push notification subscriptions | Duration of subscription + 30-day grace period | Explicit consent |
| inbound_documents (OCR expenses) | 7-day soft-delete → R2 hard-delete | Minimization |
Your data rights
Under GDPR you have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure / "right to be forgotten" (Art. 17) — detailed below
- Portability (Art. 20)
- Object (Art. 21) — to legitimate-interest processing
- Restriction (Art. 18)
Requests: privacy@nodex.nodera.ro · DPO: dpo@nodex.ro. Response within 30 days per Art. 12 GDPR.
Customer data erasure (Art. 17 GDPR)
Nodex implements a four-tier flow for Art. 17 GDPR erasure requests concerning customers stored in your organisation:
Tier 1 — Soft-delete (reversible). The customer record is tombstoned and removed from active lists. An organisation Owner or Admin can restore it.
Tier 2 — Art. 17 GDPR erase (irreversible). The fields notes, phone, email, address line 1, and address line 2 are permanently nulled. This action cannot be undone. Only an Owner or Admin may trigger it.
What is erased vs. what is retained:
| Data | Action | Legal basis | | ------------------------------------- | -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Notes, phone, email, detailed address | Permanently erased | No retention obligation; not denormalized onto issued invoices | | Name, tax ID (CUI), country | Retained | Denormalized onto issued invoice headers; protected by Romanian Law 82/1991 Art. 25 (5-year accounting-document retention) + GDPR Art. 17(3)(b) (legal obligation) | | Issued invoices (PDF + UBL XML) | Retained | GDPR Art. 17(3)(b) + Art. 17(3)(e) (establishment, exercise, or defence of legal claims); R2 Object Lock archive | | Audit log rows | Retained for 5 years | Romanian Law 82/1991 Art. 25 + GDPR Art. 17(3)(b)+(e); rows contain no PII by construction (UUIDs only) |
Tier 3 — Restore (blocked after Art. 17 erase). Once the Art. 17 tier is applied, restoration is architecturally impossible.
Tier 4 — Hard purge (Owner-only, zero invoices). Physically deletes the database row. Only available when the customer has no issued invoices.
External-registry validation cache. Cached validation data from external registries is evicted at the time of Art. 17 erase. The international validation cache is active in V1.5 with response caches keyed per source: ANAF 24h, VIES 1h, Companies House 24h, Pappers 7d, GLEIF 7d, Vertex AI (LLM) 30d. The eviction sweep covers every key indexed against the erased customer.
Counterparty validation (V1.5) — DRAFT
This section is in DRAFT form and will be reviewed by legal counsel before the public V1.5 launch. See
.claude/tech-debt/pending-legal-counsel-review.md. The content is sufficient for the V1 closed beta.
The counterparty-validation engine verifies the fiscal identity of entities you transact with, before they are persisted as customers or extracted from inbound documents.
Lawful basis: Art. 6(1)(f) GDPR (legitimate interest — see the documented Legitimate Interest Assessment (LIA) in our technical ADR docs/ArchitecturalDecisions/CounterpartyValidation.md § 5.1), coupled with the fiscal obligations imposed by Romanian Law 82/1991 Art. 25 (5-year retention of accounting supporting documents), Council Directive 2006/112/EC Art. 138 (intra-community supplies — requires a valid VIES VAT ID), and ANAF Order 8/2022 Art. 5(1) (e-Factura — requires a valid CUI).
Data processed: ONLY public identifiers of the legal entity — VAT ID, trade registry number, IBAN, legal name. We do NOT transmit personal data of a natural person to external registries (no email, no phone, no address of the controller of a PFA / sole trader — only the trade name + tax-side identifier).
Recipients (external processors):
- VIES (European Commission, EU) — intra-community VAT validation.
- Companies House (UK Government, UK) — entities registered in the United Kingdom.
- Recherche-Entreprises (Direction interministérielle du numérique, FR) — entities registered in France.
- ARES (Ministerstvo financí ČR, CZ) — entities registered in Czechia.
- ANAF (Romanian National Agency for Fiscal Administration, RO) — entities registered in Romania.
- GLEIF (Global Legal Entity Identifier Foundation, EU) — cross-border anchor (LEI code).
- Pappers (Pappers Politiques SAS, FR — paid Pro+/Business tier) — enriched DE/FR/EU-8 data.
- Vertex AI (Google, EU
europe-west4) — grounding-or-discard LLM enrichment (an ungrounded LLM response is discarded entirely).
Retention:
validation_invocations(validation telemetry — SHA-256 hashes of the request + response, NOT cleartext) — 12 months, then automatically purged.- Response cache (Redis) — TTL from 1h (VIES — flaky-by-design) to 30d (Vertex AI grounded), depending on source.
- Audit log (
validation.lookup/.search/.enrich/.revalidate/validation_cache.evicted_for_erasure) — 5 years per Romanian Law 82/1991 Art. 25, free of personal data (UUIDs + ISO country codes + provider slugs + closed-enum status only).
Your rights:
- Right to object (Art. 21) — when the counterparty is a natural person (PFA / sole trader / freelancer), you may request soft-deletion of the customer (Tier 1 above), which pauses automatic revalidation.
- Right to erasure (Art. 17) — Art. 17 erasure of a customer cascades into validation cache eviction (
validation_cache.evicted_for_erasureaction in the audit log).validation_invocationshistory is retained for 12 months for storage-minimization purposes under Art. 5(1)(e), then automatically purged.
Compliance Warranty boundary. We faithfully report exactly what the authoritative source returned. We do not warrant that the entity is solvent, that it is not on an international sanctions list, that data from foreign registries is accurate or up-to-date, or that the absence of a record means non-existence. See our dedicated Compliance Warranty page.
Supervisory authority. If you believe processing of your data infringes GDPR, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) — www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, anspdcp@dataprotection.ro. We ask that you contact dpo@nodex.ro first; we are required to respond within 30 days.
Partner creditworthiness check (Bonitate) — DRAFT
This section is DRAFT and will be reviewed by Romanian data-protection counsel before the feature is enabled in production. See
.claude/tech-debt/pending-legal-counsel-review.md.
The partner creditworthiness check (Bonitate) gives you, on your explicit request, a risk indicator (green / amber / red) for a counterparty, based on public data — fiscal status, registration state, company age, CAEN code, and published arrears. The check runs ONLY when you act (a click on "Check partner") — it never fires automatically on opening an invoice or a page.
Data controller: Nodex SRL (see the Data controller section above).
Data sources:
- ANAF v9 (
webservicesp.anaf.ro, the Romanian National Tax Agency, RO) — VAT status, registration state, legal form, registration date, CAEN code. - The ANAF published-debtors list published on data.gov.ro under the Open Government Licence — Romania (OGL-ROU) — published-arrears bracket. Source: data.gov.ro, under OGL-ROU.
Purpose: assessing a counterparty's risk before issuing an invoice, recording a customer, or sending an e-Factura.
Lawful basis: GDPR Art. 6(1)(f) (legitimate interest — see the per-purpose Legitimate Interest Assessment (LIA) documented in the Bonitate technical ADR). For legal-entity counterparties, the public identifiers processed are not personal data.
Data processed: only public legal-entity identifiers — CUI, fiscal status, registration state, age, CAEN code, published-arrears bracket. We do not send a natural person's personal data to external sources.
Recipients (external processors): none beyond ANAF / data.gov.ro above — the verdict and explainability panel are computed internally, with no LLM enrichment.
Retention:
counterparty_checks+counterparty_signals(the individual check + its pillars) — 90 days, then automatically purged.risk_indicators(the de-identified aggregate indicator, only public CUI + verdict + month) — 18 months, then automatically purged.counterparty_objections(the Art. 21 objection — see below) — retained as long as needed to handle the request and to evidence compliance.
Your rights (Art. 15-22): you have the rights of access, rectification, erasure, restriction, portability, and objection (Art. 21) — material here because the basis is legitimate interest (f). The right to object is available directly in the app, via the disclosure below.
Sole trader (PFA / ÎI / ÎF) — personal data
When the counterparty is a natural person operating as a PFA / Individual Enterprise / Family Enterprise, the public data shown (including published arrears) may be personal data. In that case we show a dedicated notice under Law 129/2018 and GDPR Art. 6(1)(f), with an objection (Art. 21) affordance: you can file an objection directly in the app or by contacting contact@nodex.ro within 30 days for re-evaluation. PFA detection is conservative (we show the notice whenever there is any doubt).
Supervisory authority
You have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) — www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, anspdcp@dataprotection.ro. For requests specific to customer-data erasure under Art. 17 GDPR, please contact dpo@nodex.ro first — we are required to respond within 30 days before you escalate to ANSPDCP.
Cookies
Full detail in the Cookie Policy. In short: the marketing site uses no consent banner because it relies exclusively on cookieless analytics (Plausible) and a strictly necessary Cloudflare Turnstile cookie on the waitlist form — exempt under ePrivacy Directive Art. 5(3).
International transfers
For V1.5: no transfers outside the EEA for EU customers. Stripe may process data of non-EU customers in the United States — this is explicitly disclosed in the Terms.
Changes
Material changes to this policy will be notified 45 days before they take effect, by email and in-app banner. Minor changes (clarifications, corrections) take effect upon publication.
PDF→UBL converter (free public tool)
The free converter at nodex.nodera.ro/convertor-pdf-ubl lets anyone upload a Romanian invoice PDF and receive a CIUS-RO 2.1 UBL XML + the extracted JSON by email. Nodex SRL is the operator.
Data processed: your email address, the PDF file contents, your IP (SHA-256 salted hash — the raw IP never enters our database), browser user-agent, request timestamp.
Purposes and legal bases:
- Generating and emailing the UBL — GDPR Art. 6(1)(b) (processing necessary for the performance of a pre-contractual request made by you) combined with Romanian Law 506/2004 Art. 12 (transactional email, no separate opt-in required).
- Anti-abuse (rate-limit, non-invasive fingerprinting) — GDPR Art. 6(1)(f) (legitimate interest — defending the service from bots and abuse).
- Marketing follow-up (only if you tick the optional checkbox) — GDPR Art. 6(1)(a) + Romanian Law 506/2004 Art. 12 (express opt-in consent).
Processors (sub-processors): Mistral AI (OCR, La Plateforme Paris EU), Cloudflare Turnstile (EU edge), Resend (email delivery — US East + EU West routing; tech-debt V1.5 tracks the strict-EU residency migration), Hetzner (Germany), Upstash (EU).
Retention: PDF only in memory during processing (max 1 hour via Redis TTL); email + consent flag in a Redis hash with 1-hour TTL then auto-deleted; audit metadata (jobId, page count — never email, never filename, never extracted CUI) 5 years per Romanian Law 82/1991 Art. 25; marketing subscription — until you withdraw consent via the unsubscribe link in every email.
Immediate deletion: the /convertor-pdf-ubl/sterge?token=... link in the delivery email (V1.5; for V1 the data auto-deletes within 1 hour).
Contact
privacy@nodex.nodera.ro · Andrei Buliga PFA, CUI 54243750, Strada General Petre Popovăț 57, et. 1, ap. 11, Sector 6, Bucharest, Romania.