EXCLUSIVE Founders' Special Offer: 87% Off (Limited Spots)
04DAYS 03H 01MIN 07SEC
I want to try.

Privacy Policy

TABLE OF CONTENTS

This policy explains what personal data we process, why, for how long, and what your rights are. It applies to the sdravobiz.com website — its shop, its member area, its training courses, the Apogée Max program, its communities, and its support — as well as to the WordPress plugins we publish.

It is drafted pursuant to Regulation (EU) 2016/679 (“GDPR”), Law no. 190/2018, and Law no. 506/2004.

1. Who is responsible

Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 — EU VAT: RO51472369
Trade Register: J2025016522009
Email: contact@sdravobiz.com

Sdravobiz is not required to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR: its activity does not rely on large-scale processing of sensitive data, nor on large-scale systematic monitoring of individuals.

Any request may be sent to contact@sdravobiz.com, indicating “GDPR” in the subject line.

2. Two situations to distinguish

This is the most important point of this policy.

Your own data, as a customer, member, or visitor to our site. We act as the data controller: account, order, invoice, license, training, program, community, support, newsletter. This is covered in Articles 3 to 10.

The data you collect on your own site with our plugins. They are stored in the database of your WordPress site, on your hosting. They do not pass through any of our servers, are never transmitted to us, and are not accessible to us. You are the sole data controller, and we are neither controller nor processor. This is covered in Article 11.

3. What we process, and why

PurposeDataLegal basisRetention
Account and member area — account creation, authentication, access to subscribed servicesLast name, first name, email address, username, encrypted password, preferences, connection datesPerformance of the contract (art. 6.1.b)Duration of the account, then 12 months
Order, license and billing — performance of the contract, invoices, accounting obligationsLast name, first name, company, address, email, VAT number, order and invoice history, license keyPerformance of the contract (art. 6.1.b) and legal obligation (art. 6.1.c)Duration of the contract, then 10 years pursuant to Law no. 82/1991
Activation management — verification of license validity, website count, distribution of updatesLicense key, address of activated websites, product ID, installed version, activation and verification datesPerformance of the contract (art. 6.1.b); legitimate interest for protection against unauthorized use (art. 6.1.f)Duration of the license, then 3 years
Payments — collection, recurring debits, fraud prevention, disputes and refundsBilling details, transaction history and IDs, payment schedulePerformance of the contract (art. 6.1.b); legitimate anti-fraud interest (art. 6.1.f)10 years (accounting obligations)
Training courses — granting access, progress tracking, proof of commencement within the meaning of the refund policyPurchased training courses, opened lessons, viewed sequences, downloaded materials, dates and timestampsPerformance of the contract (art. 6.1.b); legitimate interest for proof (art. 6.1.f)Duration of access, then 3 years
Apogée Max — application and selectionIdentity, business activity, revenue bracket, description of the bottleneck, interview slot, interview notesPre-contractual measures (art. 6.1.b); legitimate interest for selection (art. 6.1.f)Accepted application: duration of the subscription, then 3 years. Rejected application: 12 months
Apogée Max — program participationAttendance at sessions, submitted work and documents, exchanges in the private area, session recordings (Article 6)Performance of the contract (art. 6.1.b)Duration of the subscription, then 12 months for exchanges, Article 6 for recordings
Communities — La Taverne and private areas: posts, replies, reactionsDisplay name, photo if uploaded, email, content of posted messagesPerformance of the contract (art. 6.1.b); consent for publication (art. 6.1.a)Duration of participation, then 12 months
Service emails — confirmation, invoice, license key, access provision, session invitation, renewal/expiry, security incidentName, email, account IDPerformance of the contract (art. 6.1.b)Duration of the contract, then statutory archiving
Support and customer relationsName, email, content of communications, screenshots and environment reports you providePerformance of the contract (art. 6.1.b); legitimate interest for prospective clients (art. 6.1.f)3 years after the last interaction (clients); 13 months (prospects)
Affiliate program — registration, tracking of referred visits and orders, commission payoutIdentity, email, billing details, tracking ID, referred visits and ordersPerformance of the contract (art. 6.1.b); legitimate interest for attribution and fraud prevention (art. 6.1.f)Duration of participation, then 10 years for accounting documents
Newsletter and product updatesName, email, language, opens and clicksConsent (art. 6.1.a); legitimate interest for customers regarding a similar productUntil consent is withdrawn, and at the latest 3 years after the last interaction
Website audience measurementAnonymized IP address, page views, duration, traffic source, device and browserConsent (art. 6.1.a) for non-essential cookies; legitimate interest for anonymized measurements14 months
Legal obligations and litigationInvoices, supporting documents, connection logsLegal obligation (art. 6.1.c); legitimate interest for legal defenseApplicable statutory period

We do not make any fully automated decisions producing legal effects concerning you, and we do not engage in advertising profiling. The selection of applications for Apogée Max is carried out by a human, based on the form and the interview.

4. We do not sell your data

Sdravobiz does not sell, rent, or transfer your personal data to third parties for commercial purposes.

Your data is only disclosed to the service providers listed in Section 5, to competent administrative or judicial authorities upon legal requisition, and to our legal counsel in the event of contentious proceedings.

5. Our service providers

We use subcontractors within the meaning of Article 28 of the GDPR, selected for their guarantees. This list is subject to change.

Service ProviderRoleLocationTransfer Safeguards
Stripe Payments Europe, LtdOnline payments, subscriptions, anti-fraudIreland (EU), servers in the United States for the groupStandard Contractual Clauses + EU-US Data Privacy Framework
o2switchHosting of the website, store, member area, communities, and license serverFrance (EU)No transfer outside the EU
Store, licenses, training courses, communities, and support (self-hosted)Orders, subscriptions, license keys, activations, invoices, progress, tickets, community help areasFrance (EU)Not applicable — self-hosted
Contact and email management (self-hosted)Service emails, newsletterFrance (EU)Not applicable — self-hosted
Google Ireland Ltd (Google Meet)Broadcasting and recording of live Apogée Max sessionsIreland (EU), servers in the United StatesStandard Contractual Clauses + EU-US Data Privacy Framework
o2switchHosting of training videos and session recordingsFrance (EU)No transfer outside the EU
Google Ireland Ltd (Analytics, Search Console)Audience measurement and SEO monitoringIreland (EU), servers in the United StatesStandard Contractual Clauses + EU-US Data Privacy Framework
Chartered accountant and legal advisorsAccounting and legal obligationsRomaniaService agreement, confidentiality clause

None of these service providers have access to the data you collect with our extensions on your own site.

6. Live sessions and their recordings

Apogée Max live sessions are recorded, and the recordings are made available to program members in the member area. A participating member therefore appears in video and audio in these recordings, and may share information about their business.

  • Legal basis: performance of the contract for making the recordings available to program members (Article 6.1.b); separate written consent for any promotional or public use (Article 6.1.a).
  • Recipients: exclusively program members, for the duration of availability. Recordings are neither published, sold, nor shared with third parties.
  • Retention: no fixed duration. A recording remains available for as long as the Publisher makes it available to members, and may be deactivated or deleted at any time, without notice. Your right to erasure (Article 9) remains open at all times.
  • Your choices: you can participate with your camera turned off, request before the session that your case not be addressed on screen, and withdraw at any time, for the future, any consent given for promotional use.
  • Erasure: you can request the removal of a segment concerning you. When the technical removal of a segment within a collective recording is not possible without infringing on the rights of other participants, we remove the entire recording from availability.

Members are also bound, under Article 35 of the General Terms and Conditions of Sale, by an obligation of confidentiality regarding what is said within the group, and are prohibited from recording or rebroadcasting a session.

7. What our extensions send to our servers

An extension installed on your site communicates with our license server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update searches.

On each of these occasions, and on these occasions only, your site transmits exactly the following items:

  • the product identifier;
  • your license key;
  • your site address;
  • the version number of the installed extension;
  • a single-use nonce, intended to prevent response replay.

And nothing else. In particular, the following are never transmitted: the data you collect, the email addresses of your contacts, their responses, their IP addresses, your statistics, your settings, your site content, your administrator email address, your PHP or WordPress version, the list of your extensions.

Our extensions contain no telemetry, no reporting of usage statistics, and no tracking upon installation. When an extension offers a diagnostic screen, the description of your technical environment that it displays remains on your site and is only transmitted if you manually copy it into a support message.

Exchanges with your third-party tools, webhooks/API endpoints, discussion channels, and external calendars originate from your server to the destinations you have configured yourself. They do not pass through any of our servers.

8. Transfers outside the European Union

Our customer data is hosted in the European Union. The only transfers likely to occur outside the European Economic Area concern our payment provider, our audience measurement tools, and the videoconferencing tool for live sessions, whose parent companies have infrastructure in the United States. Training videos and session recordings are hosted in France.

These transfers are governed by the guarantees of Chapter V of the GDPR: adequacy decisions where they exist (notably the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained upon request at contact@sdravobiz.com.

The data you collect with our extensions is not subject to any transfer on our part, since it never reaches us.

9. Your rights

You have the following rights (Articles 15 to 22 of the GDPR):

  • access: know whether we are processing data concerning you and obtain a copy of it;
  • rectification: have inaccurate or incomplete data corrected;
  • erasure: obtain its deletion, within the limits of our legal retention obligations;
  • restriction: temporarily restrict processing;
  • portability: receive your data in a structured, machine-readable format;
  • objection: object to processing based on legitimate interest, and unconditionally to commercial prospecting;
  • withdrawal of consent at any time, without affecting the lawfulness of prior processing;
  • post-mortem directives regarding the handling of your data;
  • complaint to a supervisory authority (Article 14).

How to exercise them. By email to contact@sdravobiz.com (subject “GDPR”) or by post to our registered office. To prevent fraudulent communications, we may request proof of identity. We will respond within one (1) month, which may be extended by two months in the event of complex or numerous requests (Article 12.3 of the GDPR).

Two limitations to keep in mind. Messages you have posted in a community are part of collective discussions: deleting them removes your content and anonymizes your display name, but does not delete responses from other members. Additionally, recordings of group sessions are subject to the specific rules set out in Article 6.

If you have filled out a form on the website of a company using one of our extensions and wish to exercise your rights regarding this information, please contact that company directly: they alone are the data controller, and they alone hold this data. We have no access to it and therefore cannot provide it to you or delete it.

10. Security

We implement appropriate technical and organizational measures as provided for in Article 32 of the GDPR, including: connection encryption (HTTPS/TLS), payments processed by a PCI-DSS Level 1 certified service provider, strict access control and strong authentication for administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our subcontractors.

The update archives served by our server are cryptographically sealed and signed, and their signature is verified by your site prior to installation.

No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 of the GDPR).

11. Your visitors’ data stays with you

This section is addressed to you, as a customer of one of our extensions, regarding the individuals whose data you collect on your own website.

11.1 You are the sole data controller

This data is stored in tables within your own WordPress database, on your hosting. We do not receive it, host it, access it, and cannot restore it.

You alone determine the purposes and means of the processing. It is your responsibility to inform your visitors, define your legal bases and retention periods, publish your own privacy policy, collect the necessary consents, and respond to the exercise of rights. Regarding this data, we are neither a data controller nor a data processor: we provide you with software, not a data processing service.

11.2 What the documentation for each extension specifies

The exact list of stored data, cookies placed on your visitors’ devices, and tools provided to you — exporter, eraser, configurable retention period, suggested policy text — can be found in the privacy policy on each product’s website and in its documentation. Please refer to it to draft your own.

Important note common to our extensions: when a retention period setting exists, its default value triggers no automatic purge. Without action on your part, the collected data — including IP addresses — is retained indefinitely. Set this value upon installation.

11.3 The only case where we see your data

If you provide us, in the context of support, with a screenshot, an export, or access to your site, we may be exposed to your visitors’ data. We then act as a data processor, based on your specific and documented instruction, solely for the duration necessary to process your request. These items are deleted upon closing the ticket, and no later than the three (3) year retention period for support exchanges.

We recommend that you anonymize your screenshots before sending them to us. The same recommendation applies to documents you share during an Apogée Max session.

12. Cookies

CategoryNamePurposeDurationLegal basis
Strictly necessarywordpress_logged_in_*Authentication to the member area and session securitySessionLegitimate interest — without consent
Strictly necessarywp-settings-*Your display preferences in the member area12 monthsLegitimate interest — without consent
Strictly necessarycookieadmin_consentRemembers your cookie choices12 monthsLegitimate interest — without consent
Strictly necessaryfluent_cart_*Cart and order in progressSessionLegitimate interest — without consent
Functionalfluent_theme_modeLight or dark display mode12 monthsConsent
Functionalfunnelcart:orientationDisplay orientation of the checkout funnel12 monthsConsent
Audience measurement_ga, _ga_ZP2XQQE0J9Google Analytics: traffic statistics13 monthsConsent
Marketingf_affAffiliate tracking: remembers the partner who referred you30 daysConsent
Marketingfc_utm_dataSource of your visit (campaign, origin), to attribute your order30 daysConsent

During your first visit, a banner allows you to accept, decline, or configure non-strictly necessary cookies. You can modify your preferences at any time via the “Manage my cookies” link at the bottom of each page. Refusing non-essential cookies does not prevent access to the site, viewing its content, or accessing the services you have subscribed to.

Cookies placed by our extensions on our clients’ websites are set by their website, under their domain name: it is up to them to declare them. They are described in the privacy policy of each product’s website.

13. Minors

Our website, products, training courses, and support program are intended for an adult audience and are not meant for minors. We do not knowingly collect their data. If we discover such data, we delete it without delay.

14. Complaints

If you believe that the processing of your data is non-compliant, you may contact the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro — anspdcp@dataprotection.ro — +40 318 059 211

If you reside in another Member State, you may also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).

15. Changes

We may update this policy to reflect legal, regulatory, technical, or contractual developments. The applicable version is the one published on the date of your visit. In the event of a substantial change, we will inform you via a banner on the site or by email if you are a client.

16. Contact

Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR)
https://sdravobiz.com/en/

See also: General Terms and Conditions of Sale — Legal Notice

Last updated: September 3, 2026