Privacy Policy
TABLE OF CONTENTS
- 1. Who is responsible
- 2. Two situations to distinguish
- 3. What we process, and why
- 4. We do not sell your data
- 5. Our service providers
- 6. Live sessions and their recordings
- 7. What our plugins send to our servers
- 8. Transfers outside the European Union
- 9. Your rights
- 10. Security
- 11. Your visitors’ data stays with you
- 12. Cookies
- 13. Minors
- 14. Complaints
- 15. Changes
- 16. Contact
This policy explains what personal data we process, why, for how long, and what your rights are. It applies to the sdravobiz.com website — its shop, its member area, its training courses, the Apogée Max program, its communities, and its support — as well as to the WordPress plugins we publish.
It is drafted pursuant to Regulation (EU) 2016/679 (“GDPR”), Law no. 190/2018, and Law no. 506/2004.
1. Who is responsible
Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 — EU VAT: RO51472369
Trade Register: J2025016522009
Email: contact@sdravobiz.com
Sdravobiz is not required to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR: its activity does not rely on large-scale processing of sensitive data, nor on large-scale systematic monitoring of individuals.
Any request may be sent to contact@sdravobiz.com, indicating “GDPR” in the subject line.
2. Two situations to distinguish
This is the most important point of this policy.
Your own data, as a customer, member, or visitor to our site. We act as the data controller: account, order, invoice, license, training, program, community, support, newsletter. This is covered in Articles 3 to 10.
The data you collect on your own site with our plugins. They are stored in the database of your WordPress site, on your hosting. They do not pass through any of our servers, are never transmitted to us, and are not accessible to us. You are the sole data controller, and we are neither controller nor processor. This is covered in Article 11.
3. What we process, and why
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account and member area — account creation, authentication, access to subscribed services | Last name, first name, email address, username, encrypted password, preferences, connection dates | Performance of the contract (art. 6.1.b) | Duration of the account, then 12 months |
| Order, license and billing — performance of the contract, invoices, accounting obligations | Last name, first name, company, address, email, VAT number, order and invoice history, license key | Performance of the contract (art. 6.1.b) and legal obligation (art. 6.1.c) | Duration of the contract, then 10 years pursuant to Law no. 82/1991 |
| Activation management — verification of license validity, website count, distribution of updates | License key, address of activated websites, product ID, installed version, activation and verification dates | Performance of the contract (art. 6.1.b); legitimate interest for protection against unauthorized use (art. 6.1.f) | Duration of the license, then 3 years |
| Payments — collection, recurring debits, fraud prevention, disputes and refunds | Billing details, transaction history and IDs, payment schedule | Performance of the contract (art. 6.1.b); legitimate anti-fraud interest (art. 6.1.f) | 10 years (accounting obligations) |
| Training courses — granting access, progress tracking, proof of commencement within the meaning of the refund policy | Purchased training courses, opened lessons, viewed sequences, downloaded materials, dates and timestamps | Performance of the contract (art. 6.1.b); legitimate interest for proof (art. 6.1.f) | Duration of access, then 3 years |
| Apogée Max — application and selection | Identity, business activity, revenue bracket, description of the bottleneck, interview slot, interview notes | Pre-contractual measures (art. 6.1.b); legitimate interest for selection (art. 6.1.f) | Accepted application: duration of the subscription, then 3 years. Rejected application: 12 months |
| Apogée Max — program participation | Attendance at sessions, submitted work and documents, exchanges in the private area, session recordings (Article 6) | Performance of the contract (art. 6.1.b) | Duration of the subscription, then 12 months for exchanges, Article 6 for recordings |
| Communities — La Taverne and private areas: posts, replies, reactions | Display name, photo if uploaded, email, content of posted messages | Performance of the contract (art. 6.1.b); consent for publication (art. 6.1.a) | Duration of participation, then 12 months |
| Service emails — confirmation, invoice, license key, access provision, session invitation, renewal/expiry, security incident | Name, email, account ID | Performance of the contract (art. 6.1.b) | Duration of the contract, then statutory archiving |
| Support and customer relations | Name, email, content of communications, screenshots and environment reports you provide | Performance of the contract (art. 6.1.b); legitimate interest for prospective clients (art. 6.1.f) | 3 years after the last interaction (clients); 13 months (prospects) |
| Affiliate program — registration, tracking of referred visits and orders, commission payout | Identity, email, billing details, tracking ID, referred visits and orders | Performance of the contract (art. 6.1.b); legitimate interest for attribution and fraud prevention (art. 6.1.f) | Duration of participation, then 10 years for accounting documents |
| Newsletter and product updates | Name, email, language, opens and clicks | Consent (art. 6.1.a); legitimate interest for customers regarding a similar product | Until consent is withdrawn, and at the latest 3 years after the last interaction |
| Website audience measurement | Anonymized IP address, page views, duration, traffic source, device and browser | Consent (art. 6.1.a) for non-essential cookies; legitimate interest for anonymized measurements | 14 months |
| Legal obligations and litigation | Invoices, supporting documents, connection logs | Legal obligation (art. 6.1.c); legitimate interest for legal defense | Applicable statutory period |
We do not make any fully automated decisions producing legal effects concerning you, and we do not engage in advertising profiling. The selection of applications for Apogée Max is carried out by a human, based on the form and the interview.
4. We do not sell your data
Sdravobiz does not sell, rent, or transfer your personal data to third parties for commercial purposes.
Your data is only disclosed to the service providers listed in Section 5, to competent administrative or judicial authorities upon legal requisition, and to our legal counsel in the event of contentious proceedings.
5. Our service providers
We use subcontractors within the meaning of Article 28 of the GDPR, selected for their guarantees. This list is subject to change.
| Service Provider | Role | Location | Transfer Safeguards |
|---|---|---|---|
| Stripe Payments Europe, Ltd | Online payments, subscriptions, anti-fraud | Ireland (EU), servers in the United States for the group | Standard Contractual Clauses + EU-US Data Privacy Framework |
| o2switch | Hosting of the website, store, member area, communities, and license server | France (EU) | No transfer outside the EU |
| Store, licenses, training courses, communities, and support (self-hosted) | Orders, subscriptions, license keys, activations, invoices, progress, tickets, community help areas | France (EU) | Not applicable — self-hosted |
| Contact and email management (self-hosted) | Service emails, newsletter | France (EU) | Not applicable — self-hosted |
| Google Ireland Ltd (Google Meet) | Broadcasting and recording of live Apogée Max sessions | Ireland (EU), servers in the United States | Standard Contractual Clauses + EU-US Data Privacy Framework |
| o2switch | Hosting of training videos and session recordings | France (EU) | No transfer outside the EU |
| Google Ireland Ltd (Analytics, Search Console) | Audience measurement and SEO monitoring | Ireland (EU), servers in the United States | Standard Contractual Clauses + EU-US Data Privacy Framework |
| Chartered accountant and legal advisors | Accounting and legal obligations | Romania | Service agreement, confidentiality clause |
None of these service providers have access to the data you collect with our extensions on your own site.
6. Live sessions and their recordings
Apogée Max live sessions are recorded, and the recordings are made available to program members in the member area. A participating member therefore appears in video and audio in these recordings, and may share information about their business.
- Legal basis: performance of the contract for making the recordings available to program members (Article 6.1.b); separate written consent for any promotional or public use (Article 6.1.a).
- Recipients: exclusively program members, for the duration of availability. Recordings are neither published, sold, nor shared with third parties.
- Retention: no fixed duration. A recording remains available for as long as the Publisher makes it available to members, and may be deactivated or deleted at any time, without notice. Your right to erasure (Article 9) remains open at all times.
- Your choices: you can participate with your camera turned off, request before the session that your case not be addressed on screen, and withdraw at any time, for the future, any consent given for promotional use.
- Erasure: you can request the removal of a segment concerning you. When the technical removal of a segment within a collective recording is not possible without infringing on the rights of other participants, we remove the entire recording from availability.
Members are also bound, under Article 35 of the General Terms and Conditions of Sale, by an obligation of confidentiality regarding what is said within the group, and are prohibited from recording or rebroadcasting a session.
7. What our extensions send to our servers
An extension installed on your site communicates with our license server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update searches.
On each of these occasions, and on these occasions only, your site transmits exactly the following items:
- the product identifier;
- your license key;
- your site address;
- the version number of the installed extension;
- a single-use nonce, intended to prevent response replay.
And nothing else. In particular, the following are never transmitted: the data you collect, the email addresses of your contacts, their responses, their IP addresses, your statistics, your settings, your site content, your administrator email address, your PHP or WordPress version, the list of your extensions.
Our extensions contain no telemetry, no reporting of usage statistics, and no tracking upon installation. When an extension offers a diagnostic screen, the description of your technical environment that it displays remains on your site and is only transmitted if you manually copy it into a support message.
Exchanges with your third-party tools, webhooks/API endpoints, discussion channels, and external calendars originate from your server to the destinations you have configured yourself. They do not pass through any of our servers.
8. Transfers outside the European Union
Our customer data is hosted in the European Union. The only transfers likely to occur outside the European Economic Area concern our payment provider, our audience measurement tools, and the videoconferencing tool for live sessions, whose parent companies have infrastructure in the United States. Training videos and session recordings are hosted in France.
These transfers are governed by the guarantees of Chapter V of the GDPR: adequacy decisions where they exist (notably the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained upon request at contact@sdravobiz.com.
The data you collect with our extensions is not subject to any transfer on our part, since it never reaches us.
9. Your rights
You have the following rights (Articles 15 to 22 of the GDPR):
- access: know whether we are processing data concerning you and obtain a copy of it;
- rectification: have inaccurate or incomplete data corrected;
- erasure: obtain its deletion, within the limits of our legal retention obligations;
- restriction: temporarily restrict processing;
- portability: receive your data in a structured, machine-readable format;
- objection: object to processing based on legitimate interest, and unconditionally to commercial prospecting;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing;
- post-mortem directives regarding the handling of your data;
- complaint to a supervisory authority (Article 14).
How to exercise them. By email to contact@sdravobiz.com (subject “GDPR”) or by post to our registered office. To prevent fraudulent communications, we may request proof of identity. We will respond within one (1) month, which may be extended by two months in the event of complex or numerous requests (Article 12.3 of the GDPR).
Two limitations to keep in mind. Messages you have posted in a community are part of collective discussions: deleting them removes your content and anonymizes your display name, but does not delete responses from other members. Additionally, recordings of group sessions are subject to the specific rules set out in Article 6.
If you have filled out a form on the website of a company using one of our extensions and wish to exercise your rights regarding this information, please contact that company directly: they alone are the data controller, and they alone hold this data. We have no access to it and therefore cannot provide it to you or delete it.
10. Security
We implement appropriate technical and organizational measures as provided for in Article 32 of the GDPR, including: connection encryption (HTTPS/TLS), payments processed by a PCI-DSS Level 1 certified service provider, strict access control and strong authentication for administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our subcontractors.
The update archives served by our server are cryptographically sealed and signed, and their signature is verified by your site prior to installation.
No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 of the GDPR).
11. Your visitors’ data stays with you
This section is addressed to you, as a customer of one of our extensions, regarding the individuals whose data you collect on your own website.
11.1 You are the sole data controller
This data is stored in tables within your own WordPress database, on your hosting. We do not receive it, host it, access it, and cannot restore it.
You alone determine the purposes and means of the processing. It is your responsibility to inform your visitors, define your legal bases and retention periods, publish your own privacy policy, collect the necessary consents, and respond to the exercise of rights. Regarding this data, we are neither a data controller nor a data processor: we provide you with software, not a data processing service.
11.2 What the documentation for each extension specifies
The exact list of stored data, cookies placed on your visitors’ devices, and tools provided to you — exporter, eraser, configurable retention period, suggested policy text — can be found in the privacy policy on each product’s website and in its documentation. Please refer to it to draft your own.
Important note common to our extensions: when a retention period setting exists, its default value triggers no automatic purge. Without action on your part, the collected data — including IP addresses — is retained indefinitely. Set this value upon installation.
11.3 The only case where we see your data
If you provide us, in the context of support, with a screenshot, an export, or access to your site, we may be exposed to your visitors’ data. We then act as a data processor, based on your specific and documented instruction, solely for the duration necessary to process your request. These items are deleted upon closing the ticket, and no later than the three (3) year retention period for support exchanges.
We recommend that you anonymize your screenshots before sending them to us. The same recommendation applies to documents you share during an Apogée Max session.
12. Cookies
| Category | Name | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Strictly necessary | wordpress_logged_in_* | Authentication to the member area and session security | Session | Legitimate interest — without consent |
| Strictly necessary | wp-settings-* | Your display preferences in the member area | 12 months | Legitimate interest — without consent |
| Strictly necessary | cookieadmin_consent | Remembers your cookie choices | 12 months | Legitimate interest — without consent |
| Strictly necessary | fluent_cart_* | Cart and order in progress | Session | Legitimate interest — without consent |
| Functional | fluent_theme_mode | Light or dark display mode | 12 months | Consent |
| Functional | funnelcart:orientation | Display orientation of the checkout funnel | 12 months | Consent |
| Audience measurement | _ga, _ga_ZP2XQQE0J9 | Google Analytics: traffic statistics | 13 months | Consent |
| Marketing | f_aff | Affiliate tracking: remembers the partner who referred you | 30 days | Consent |
| Marketing | fc_utm_data | Source of your visit (campaign, origin), to attribute your order | 30 days | Consent |
During your first visit, a banner allows you to accept, decline, or configure non-strictly necessary cookies. You can modify your preferences at any time via the “Manage my cookies” link at the bottom of each page. Refusing non-essential cookies does not prevent access to the site, viewing its content, or accessing the services you have subscribed to.
Cookies placed by our extensions on our clients’ websites are set by their website, under their domain name: it is up to them to declare them. They are described in the privacy policy of each product’s website.
13. Minors
Our website, products, training courses, and support program are intended for an adult audience and are not meant for minors. We do not knowingly collect their data. If we discover such data, we delete it without delay.
14. Complaints
If you believe that the processing of your data is non-compliant, you may contact the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro — anspdcp@dataprotection.ro — +40 318 059 211
If you reside in another Member State, you may also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).
15. Changes
We may update this policy to reflect legal, regulatory, technical, or contractual developments. The applicable version is the one published on the date of your visit. In the event of a substantial change, we will inform you via a banner on the site or by email if you are a client.
16. Contact
Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR)
https://sdravobiz.com/en/
See also: General Terms and Conditions of Sale — Legal Notice
Last updated: September 3, 2026

