Privacy Policy

Effective date and last updated: 1 August 2026

Policy version: 2026-08-01

1. Who we are

ELVPro is operated by:

  • SYNCDEV S.R.L.
  • Romanian Trade Register no.: J36/164/2014
  • CUI / fiscal identification code: 33129339
  • Registered office: Str. Fetițelor nr. 4, camera nr. 1, 820035 Tulcea, Tulcea, Romania
  • Email: hello@elvpro.eu
  • Privacy contact: dpa@elvpro.eu

For the processing described in this Privacy Policy, SYNCDEV S.R.L. ("SYNCDEV", "ELVPro", "we", "us") is the data controller unless Section 2 says otherwise.

SYNCDEV has not appointed a data protection officer because it has determined that the mandatory appointment criteria in Article 37 GDPR do not currently apply. Privacy questions and Data Subject requests should be sent to dpa@elvpro.eu.

2. Scope and allocation of roles

This Policy applies when you:

  • visit the central ELVPro presentation website;
  • contact SYNCDEV, request information or submit feedback;
  • start or complete an ELVPro yard signup;
  • act as an owner, employee, contractor or other authorised user of an ELVPro business account;
  • deal with SYNCDEV concerning a subscription, invoice, support request or security matter; or
  • otherwise interact directly with SYNCDEV.

ELVPro is not a marketplace. Each dismantler or used-parts yard operates its own website, inventory and customer relationships.

When a yard uses ELVPro to process the personal data of its website visitors, customers, prospective buyers, suppliers or staff for the yard's own purposes, the yard is normally the controller and SYNCDEV is its processor. That processing is governed by the yard's privacy notice and the ELVPro Data Processing Agreement ("DPA"). Requests about an order, enquiry, customer account, live chat, newsletter or other activity on a specific yard's storefront should normally be addressed to that yard.

SYNCDEV remains a separate controller for its own business-account administration, platform billing, direct support relationship, fraud prevention, legal compliance and defence of claims.

3. Personal data we process

Depending on how you interact with us, we may process the following categories.

3.1 Central website and native analytics

When you visit the central ELVPro website, our servers necessarily receive technical connection data such as your IP address, request time, requested resource, response status and browser information. Security logs may retain some of this data for a limited period.

Our first-party native analytics do not set an analytics cookie and do not retain the raw IP address in the analytics table. To count visits while reducing identifiability, the system:

  • combines the IP address, user-agent string, a yard/site identifier and a random salt that rotates daily;
  • stores the resulting daily pseudonymous hash and a short session hash;
  • removes query strings before storing page paths;
  • records the referrer host/source and campaign parameters, if present;
  • derives approximate country and city from the IP address;
  • derives coarse device type, browser, operating system and language; and
  • honours an enabled browser "Do Not Track" signal, and any objection you record through the "Privacy settings" control in the site footer.

The hash and the derived analytics remain personal data or pseudonymous personal data for GDPR purposes. They are not described as anonymous and are not used to follow you across unrelated websites or across different days.

3.2 Contact, demo and feedback communications

We may process your name, business email, company, subject, message, preferred language, the IP address used to submit the form, our replies and any information you choose to include. Please do not include special-category data or unrelated personal data.

3.3 Signup and business verification

During signup we may process:

  • your name, business email and a securely hashed password;
  • yard/company name, country, company or registration number and requested subdomain;
  • selected trial/plan information and preferred language/currency;
  • IP address, acceptance time and the version of the Terms accepted;
  • email-verification token/code records; and
  • company information returned by public or official verification sources such as ANAF or VIES.

The plaintext password and verification code are not retained by us.

3.4 Account and authorised-user data

We may process names, work contact details, roles and permissions, account status, password hash, multifactor-authentication configuration, security and recovery information, sign-in/activity information, settings, actions recorded in audit logs, and communications with account administrators.

If your employer or another organisation creates your user account, we receive this information from that organisation. That organisation may also be a controller for its own use of your work-account data.

3.5 Subscription, billing and fiscal data

We may process the customer's legal name, registered office and billing address, trade-register and VAT identifiers, billing contact, plan, billing period, discounts/referrals, subscription status, invoice and payment history, and tax information.

Subscription payments are processed through a payment provider. ELVPro may receive provider customer/payment references, payment status, card brand, last four digits and expiry information, but does not need to store the complete card number or card security code.

3.6 Support, operations and security

We may process support tickets, messages, attachments, feedback, incident details, authorised support impersonation records, system errors, request metadata, audit records, IP address, user agent and other information needed to diagnose an issue, secure the service or establish what happened. Support impersonation must be authorized, time-limited and logged.

3.7 Optional services

If enabled and used, we may receive:

  • identity-provider data from Google or Facebook sign-in, such as provider identifier, name, email and profile image;
  • limited information from a company/VAT verification service; and
  • service-provider identifiers and statuses from integrations used for billing or account administration.

Personal data processed inside tenant-selected AI, vehicle-catalogue, courier, payment, invoicing, chat, order or storefront features is normally Customer Personal Data governed by the DPA and the yard's privacy notice.

4. Where the data comes from

We receive personal data:

  • directly from you;
  • from the business customer that authorises your account;
  • automatically from your device and use of the service;
  • from payment, identity and communications providers you use;
  • from public or official business registers and VAT-validation services; and
  • from another person who contacts us and legitimately identifies you in a business matter.

If you give us another person's data, you must be authorized to do so and must give that person any notice required by law.

We use personal data only when a legal basis applies.

a) Taking steps at your request and performing a contract — Article 6(1)(b) GDPR

  • processing a signup by a sole trader or other individual contracting in their own name;
  • creating and administering that person's account;
  • providing the selected trial or paid service;
  • processing subscription billing and contract communications; and
  • providing requested support.

b) Legitimate interests — Article 6(1)(f) GDPR

  • providing and administering business accounts for customer personnel who are not personally party to our contract;
  • responding to business inquiries and managing customer relationships;
  • first-party, pseudonymous and cookieless audience measurement;
  • service security, access control, fraud/abuse prevention, debugging and incident investigation;
  • keeping proportionate audit evidence, improving reliability and enforcing the Terms;
  • establishing, exercising or defending legal claims; and
  • anonymized or properly aggregated service and business reporting.

Our relevant interests are operating a secure and useful B2B SaaS service, understanding aggregate use, protecting customers and defending legal rights. We apply minimisation, rotating identifiers, limited access and retention limits. You may object as explained in Section 10. For the cookieless audience measurement you can object directly and immediately, using the "Privacy settings" control in the site footer; no explanation is required and the objection is honoured both in the page and on our server.

c) Legal obligation — Article 6(1)(c) GDPR

  • accounting, invoicing and tax records;
  • responding to competent authorities where legally required;
  • meeting data-protection, cybersecurity and other statutory duties; and
  • retaining evidence required by applicable law.

d) Consent — Article 6(1)(a) GDPR

  • optional marketing email where consent is required;
  • optional non-essential cookies or similar technologies; and
  • any other purpose clearly identified when we ask for consent.

Consent can be withdrawn at any time as easily as it was given, without affecting processing already carried out lawfully.

Where Romanian Law no. 506/2004 permits marketing to an existing customer concerning our own similar services, we may rely on that limited rule only if we gave a clear, simple and free opt-out when collecting the address and in every message.

6. Whether data is required

Fields identified as required during signup or billing are necessary to verify the business, form or administer the contract, secure the account or issue a valid invoice. If you do not provide them, we may be unable to create the account, enter the contract, take payment or provide the requested feature.

Optional profile, marketing and preference data is not required for the core service.

7. Recipients and disclosures

We do not sell personal data.

Where necessary and lawful, data may be disclosed to:

  • Hetzner, for production hosting, storage, daily infrastructure backups and DNS in Germany;
  • Brevo, used as the SMTP relay for service, account and support email;
  • Stripe, for ELVPro subscription payments;
  • SmartBill, for fiscal invoices issued by SYNCDEV;
  • Google or Meta/Facebook, when you choose the corresponding social-login option;
  • OpenAI, Anthropic or Google Gemini, where an enabled AI feature requires the selected provider;
  • RapidAPI and the relevant API publisher, where an enabled vehicle/parts reference feature requires them;
  • professional advisers, auditors and insurers bound by confidentiality;
  • competent courts, tax, regulatory, supervisory, law-enforcement or other public authorities when legally required;
  • a purchaser or successor in a genuine corporate transaction, subject to appropriate confidentiality and data-protection measures; and
  • the ELVPro customer that administers your business account.

Processors may act only under contract and on documented instructions. Further information on ELVPro sub-processors, purposes, locations and transfer safeguards appears in Annex 3 of the DPA and may also be requested at dpa@elvpro.eu.

Payment, courier, invoicing, analytics and advertising integrations configured for a yard's own storefront are contracted directly by that yard. SYNCDEV provides the technical connection and sends data only on the yard's instruction. Those providers may act as the yard's processor or as a separate controller, and their own terms and privacy information apply.

8. International transfers

We prefer EEA processing where reasonably available, but we do not claim that all data remains in Germany or in the EEA unless the production provider register confirms it.

If personal data is transferred outside the EEA to a country without an applicable European Commission adequacy decision, we use an appropriate Chapter V GDPR mechanism, normally the European Commission Standard Contractual Clauses, together with a transfer-risk assessment and supplementary measures where required. Where a recipient validly participates in the EU-US Data Privacy Framework, that adequacy decision may be used for covered data and services.

You may ask for information about the applicable safeguard by emailing dpa@elvpro.eu. Commercially confidential information may be redacted.

9. Retention

We keep personal data only as long as needed for its purpose, then delete or irreversibly anonymize it unless a legal hold applies. Our operational retention schedule applies the following limits:

  • uncompleted signup: no longer than 48 hours after expiry of the pending-signup record, except a minimal anti-abuse/security record where justified;
  • contact/demo correspondence: up to 24 months after the last meaningful contact, unless a customer relationship or dispute requires longer;
  • business account and contract-administration data: for the contract and normally up to three years after it ends for claims and accountability, with earlier deletion of data no longer needed;
  • invoices, accounting registers and supporting documents: for the statutory period. Under Article 25 of Romanian Accounting Law no. 82/1991, the general current period is five years calculated from 1 July of the year following the financial year in which the documents were prepared; a longer period applies only where another law, an authority or a documented legal hold requires it;
  • raw first-party analytics: no more than 24 months, with shorter periods used where configured; aggregated statistics may be retained for up to 24 months or irreversibly anonymized;
  • visitor consent-choice evidence: up to 24 months, then deleted or renewed where legally justified;
  • security, access and API logs containing personal data: normally up to 12 months, with shorter operational logs removed earlier and longer retention only for a documented incident or claim;
  • AI/catalogue request and response payloads processed on behalf of a yard: normally up to 90 days when payload logging is enabled; associated usage/security metadata normally up to 12 months;
  • live-chat content processed for a yard: up to 12 months after the last activity unless the yard configures a shorter lawful period;
  • Hetzner infrastructure backups: seven rolling daily restore points; application-level pre-deletion or recovery backups, where created, are retained for no more than 90 days;
  • consent, deletion and audit evidence: only the minimized information needed to demonstrate compliance or reapply erasure after a restore, for the applicable accountability/claims period.

Retention is enforced through scheduled deletion or anonymization tasks. Data preserved for an incident, dispute, authority request or other documented legal hold is isolated, access-restricted and deleted when that reason ends.

10. Your rights

Subject to the conditions and exceptions in the GDPR, you may:

  • obtain confirmation and access to your personal data (Article 15);
  • correct inaccurate or incomplete data (Article 16);
  • request erasure (Article 17);
  • request restriction of processing (Article 18);
  • receive data you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller (Article 20);
  • object to processing based on legitimate interests (Article 21);
  • object at any time and without giving reasons to direct marketing;
  • withdraw consent at any time (Article 7(3)); and
  • not be subject to a decision based solely on automated processing that has legal or similarly significant effects, where Article 22 applies.

Account holders can download a complete structured JSON export of the personal data associated with their account. Uploaded files are supplied separately where applicable. Send any additional request to dpa@elvpro.eu. Please identify the ELVPro account or interaction concerned. We may request proportionate information to verify identity and authority. We normally respond within one month. For a complex request or multiple requests, the GDPR permits an extension of up to two further months; if so, we will explain the extension within the first month.

Requests are normally free. A reasonable fee or refusal is permitted only where a request is manifestly unfounded or excessive, particularly because it is repetitive, as allowed by the GDPR.

For data controlled by a particular yard, please contact that yard first. SYNCDEV will assist the yard as required by the DPA.

11. Complaints

You may complain to the supervisory authority in the Member State of your habitual residence, place of work or the alleged infringement.

In Romania, the authority is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)

We encourage you to contact us first so we can try to resolve the issue, but this is not a condition of your right to complain.

12. Security

We use technical and organizational measures proportionate to risk, including access controls, role-based permissions, logical tenant separation, password hashing, multi-factor authentication for privileged platform access, encryption in transit, encryption of selected sensitive fields and integration credentials at rest, logging of sensitive administrative actions, validation and request protections, and controlled erasure workflows.

No system is completely secure. Account users must protect their credentials, enable multi-factor authentication where offered, give staff only the permissions they need and notify us promptly of suspected compromise.

13. Automated decisions and AI

ELVPro may enforce configured plan limits or flag operational/compliance items automatically. SYNCDEV does not use personal data covered by this Policy to make solely automated decisions about individuals that produce legal or similarly significant effects.

AI features produce drafts or suggestions for a human user to review. They must not autonomously publish listings, send messages or make legal, employment, credit or similarly significant decisions about a person.

14. Children

ELVPro's central service is intended for professionals and authorized business users aged 18 or over, not for children. A yard that sells to or collects data from minors through its own storefront is responsible for the appropriate legal basis, notices and age-related safeguards.

15. Changes

We may update this Policy to reflect legal, provider or service changes. We will publish the new version and effective date. Material changes affecting account users will be notified through the service or by email before they take effect where required.

16. Contact

Privacy questions and rights requests: