Data Export and Switching Register

Effective date and last updated: 1 August 2026

Register version: 2026-08-01

This Register is the online information that Regulation (EU) 2023/2854 (the Data Act) requires a provider of data processing services to keep available, and it forms part of the ELVPro Terms of Service. It describes how a Customer moves its data out of ELVPro — on its own, at any time, or as part of switching to another provider — what can be exported and in what shape, what cannot, and what safeguards apply to governmental access requests concerning non-personal data held in the Union.

Provider: SYNCDEV S.R.L., Romanian Trade Register no. J36/164/2014, CUI 33129339, Str. Fetițelor nr. 4, camera nr. 1, 820035 Tulcea, Romania. General contact hello@elvpro.eu; data protection dpa@elvpro.eu.

1. Starting an export, a switch or a deletion

  • Export, at any time: sign in and use Data Export in the yard administration. No notice, no request and no approval are needed, and nothing has to be terminated first.
  • Switching to another provider or to an on-premises setup: write to hello@elvpro.eu stating the intended switch and the target date. We acknowledge in writing and confirm the transitional period.
  • Deletion: requested by the yard owner from the account section. It is a separate, explicitly confirmed action — terminating, cancelling or downgrading does not delete anything.

2. Notice, transitional and retrieval periods

  • Notice period: a maximum of two months, as permitted by Article 25(2)(a) of the Data Act. A shorter notice is accepted at the Customer's choice.
  • Transitional period: 30 calendar days, running from the end of the notice period. Where switching within that period is technically unfeasible, we will say so in writing within 14 working days of the request, give reasons, and propose an extended period, which cannot exceed seven months.
  • Retrieval period: at least 30 calendar days after the transitional period ends, during which the export functions remain available.
  • Erasure: after the retrieval period, and once deletion is confirmed, the tenant and its active data are purged or irreversibly anonymised. See section 7.

The service continues in full during the notice and transitional periods, at the agreed plan and price, and the security measures in Annex 2 of the DPA continue to apply. We do not degrade, throttle or restrict a Customer because it has announced a switch.

3. Assistance during switching

Included in the subscription: the self-service exports below, written answers about structure, formats and the meaning of fields, and reasonable co-operation with the Customer's chosen destination provider. Substantial bespoke work — writing a transformation into another vendor's schema, or operating the import at the destination — is professional-services work, quoted in advance, and is never a condition of getting the data out.

4. Register of exportable data, structures and formats

a) Complete account export — ZIP

Yard administration → Data Export → Complete account export. Built asynchronously and offered as a download. Its structure:

  • manifest.json — the yard identity (id, name, slug, plan), the build time in ISO 8601, and the list of tables included.
  • database/<table>.ndjson — one file per table, newline-delimited JSON, UTF-8, one object per row with the database column names as keys. Covers the tenant record itself; every table scoped to the yard (parts, vehicles, orders and order lines, customers and member accounts, inquiries, chat conversations, reservations and carts, invoices, returns and withdrawals, shipments, promotions, blog posts and pages, media galleries, analytics page views and rollups, consent records, API tokens and request logs, ELV compliance and treatment records, staff users, audit entries); the media-library rows for every media-bearing model; and the child tables that hang off a parent record rather than off the yard.
  • files/<path> — every file in the account's storage: uploaded images and their generated conversions, documents, certificates and attachments, at their original relative paths.

Identifiers are exported exactly as stored, so relationships survive: primary keys keep their values and foreign keys (yard_id, part_id, vehicle_id, order_id and so on) continue to point at them. Media rows carry the model type, model id and file name that resolve to the corresponding entry under files/. Timestamps are exported in the stored database format, in UTC. Monetary values are exported as the stored decimal amount together with their currency column; no rounding or conversion is applied on export.

b) Operational spreadsheets — XLSX

Orders, parts inventory and inquiries, each as a flat spreadsheet with human-readable headers. Intended for review and for loading into general-purpose tools, not as the complete record.

c) Personal-data exports — JSON

A structured JSON export of everything held about one person: for a storefront customer or member (self-service, and on the yard's behalf when it answers a data-subject request), and for a staff user. These answer requests under Articles 15 and 20 GDPR.

d) Compliance registers — CSV / XLSX

The operational register and the recovery and mass-balance report export in the shape the applicable end-of-life vehicle reporting rules expect.

e) Continuous interfaces

  • Partner REST API (Business plan and above): token-authenticated JSON read access to the account's catalogue and operational data, with a per-yard rate limit and a request log.
  • Product feeds: generated catalogue feeds for marketplaces and comparison services, in the formats those services accept.
  • Newsletter subscribers: a list export from the newsletter section.

5. Known technical limitations

Stated plainly, because a switching register that lists only what works is not one.

  • The account export is a data export, not a turnkey restore. It is complete and machine-readable, but no importer is supplied for another vendor's platform and none is implied.
  • There is no automated push or live migration to a destination provider. The Customer, or its new provider, performs the import.
  • Integration credentials (payment gateway, courier, invoicing and AI provider keys) are encrypted at rest and are exported in their encrypted form. They are not usable outside ELVPro and must be re-entered at the destination.
  • Data held by the Customer's own third-party providers — payment-gateway transactions, courier consignments and labels, documents issued by an invoicing provider — belongs to relationships the Customer contracts directly, and must be retrieved from them.
  • The search index is derived from the catalogue and rebuilt on demand. It is not exported, because everything it is built from is.
  • The daily analytics salt is deliberately not exported. It rotates every 24 hours and is what prevents visitor hashes from being correlated across days; exporting it would defeat the minimisation the analytics depends on.
  • Very large accounts produce large archives. Where a single download is impractical we arrange a supported transfer, rather than reducing what is exported.
  • Only the two most recent account exports are retained, for the backup retention period. Download the archive and keep it somewhere you control.

6. Charges

Standard self-service exports are not charged, on any plan. For switching charges, Article 29 of the Data Act applies: until 12 January 2027, any reduced switching charge may not exceed the direct costs we incur and must be disclosed in advance; from that date, no switching charges are imposed where Article 29 applies. Professional-services work under section 3 is separate from switching charges and is agreed in advance.

7. Deletion at the end of the process

An approved permanent deletion enters a reversible grace period of 30 days by default, during which the Customer may cancel it. After that, active data is deleted or irreversibly anonymised. Data in infrastructure backups expires with the backup cycle — seven rolling daily restore points, and application-level pre-deletion archives within 90 days — rather than being restored into live use, and erasure instructions recorded after a backup date are reapplied following any restore. Fiscal and end-of-life vehicle compliance records are retained only for the period the law requires, isolated and access-restricted, after which identifiers are removed or the record is deleted. Confirmation of completed deletion is provided on request.

8. Support, contact and escalation

  • Export and switching questions: hello@elvpro.eu.
  • Personal-data and data-subject questions: dpa@elvpro.eu.
  • If a request is not handled properly, the free complaints process in section 24 of the Terms applies. Nothing in it prevents the Customer from bringing proceedings or contacting a competent authority.

9. Governmental access to non-personal data (Data Act Article 28)

Where an authority of a third country requests, or seeks the transfer of, non-personal data held in the Union through ELVPro, the following applies.

  • Where the data is: the production server, database, file storage, DNS and infrastructure backups are operated by Hetzner Online GmbH in Germany. The service is provided from the European Union by a Romanian company, subject to Romanian and Union law.
  • Which jurisdictions can reach it: Romania and Germany, both Member States. No third-country provider holds the core service's non-personal data. Optional features a Customer chooses to enable — AI providers, the vehicle and parts catalogue — may involve recipients outside the EEA; those are listed, with their location and transfer basis, in Annex 3 of the DPA.
  • Safeguards: we transfer or give access to non-personal data in response to a third-country authority only where the request rests on an international agreement in force between that country and the Union or a Member State or, in the absence of such an agreement, only after assessing whether the request is specific, reasoned, proportionate and open to review, and whether complying with it would conflict with the law of the Union or of Romania.
  • Challenge: where a request conflicts with Union or Member State law we do not comply on the basis of the request alone. Where the law permits, we seek the view of the competent national body, ask the requesting authority to proceed through the applicable mutual-assistance or international-agreement route, and challenge the request before the competent court.
  • Minimisation: if disclosure ultimately becomes lawful and unavoidable, we disclose the minimum permissible and record what was disclosed, to whom, and on what basis.
  • Notification: the affected Customer is informed before disclosure wherever the law allows, and as soon as the law allows otherwise, so that it can exercise its own rights.
  • Currency of this information: this page is where the relevant jurisdiction and safeguard information is kept up to date. It is reviewed whenever the hosting arrangement, the provider register or the applicable law changes, and the version above is updated accordingly.

10. Changes

Material changes to this Register are notified under section 23 of the Terms, and the effective date and version above are updated. Earlier versions are available on request from hello@elvpro.eu.