Privacy Policy
This policy explains what personal data we process, why, for
how long, and what your rights are. It applies to the website maymoune.com, to the
platform maymoune.me and to the service Maymoune.
It is drafted pursuant to Regulation (EU) 2016/679 (“GDPR”), Law
no. 190/2018, and Law no. 506/2004.
1. Who is responsible
Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 — Intra-EU VAT: RO51472369
Registrul Comerțului: J2025016522009
Email: contact@sdravobiz.com
Sdravobiz is not required to appoint a data protection officer within the meaning
of Article 37 of the GDPR: its activity does not rely on large-scale processing
of sensitive data, nor on large-scale systematic monitoring of individuals.
Any request may be addressed to contact@sdravobiz.com, indicating “GDPR”
in the subject line.
2. Two situations to distinguish
This is the most important point of this policy.
Your own data, as a customer or visitor. We are the data controller for it.
This is the subject of Sections 3 to 8 below.
The data of your own users, collected within your application. You
are the data controller for it, and we act only as a processor, on
your instructions. This is the subject of Section 9.
3. What we process, and why
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Account, subscription, and billing — account creation, contract performance, invoices, accounting obligations | Last name, first name, company, address, email, telephone, VAT number, order and invoice history | Contract performance (art. 6.1.b) and legal obligation (art. 6.1.c) | Duration of the contract, then 10 years under Law no. 82/1991 |
| Provision of the service — back-office access, app creation and publication, technical logs, security | Credentials, IP address, connection and activity logs, configuration, domain, application identifiers | Performance of the contract (art. 6.1.b); legitimate interest for security (art. 6.1.f) | Duration of the contract, then 30 days; technical logs: 12 months |
| Payments — collection, fraud prevention, disputes and refunds | Billing information, history and transaction identifiers | Performance of the contract (art. 6.1.b); legitimate interest for anti-fraud (art. 6.1.f) | 10 years (accounting obligations) |
| Service emails — confirmation, invoice, access, expiration, incident, maintenance | Name, email, account identifier | Performance of the contract (art. 6.1.b) | Duration of the contract, then legal archiving |
| Support and customer relations | Name, email, content of communications, submitted screenshots | Performance of the contract (art. 6.1.b); legitimate interest for prospects (art. 6.1.f) | 3 years after the last exchange (customers); 13 months (prospects) |
| Newsletter and marketing information | Name, email, language, opens and clicks | Consent (art. 6.1.a); legitimate interest for customers regarding a similar service | Until withdrawal of consent, and no later than 3 years after the last interaction |
| Site audience measurement | Anonymized IP address, page views, duration, traffic source, device and browser | Consent (art. 6.1.a) for non-essential cookies; legitimate interest for anonymized measurements | 14 months |
| Legal obligations and litigation | Invoices, supporting documents, connection data | Legal obligation (art. 6.1.c); legitimate interest for legal defense | Applicable legal duration |
We do not make any fully automated decisions producing legal
effects concerning you, and we do not engage in advertising profiling.
4. We do not sell your data
Sdravobiz does not sell, rent, or transfer your personal data to third
parties for commercial purposes.
Your data is only shared with the service providers listed in Article 5, with competent administrative or judicial authorities upon legal request, and with our legal counsel in the event of dispute proceedings.
5. Our service providers
We use processors within the meaning of Article 28 of the GDPR, selected for their guarantees. This list is subject to change.
| Service Provider | Role | Location | Transfer safeguards |
|---|---|---|---|
| Stripe Payments Europe, Ltd | Online payment, anti-fraud | Ireland (EU), servers in the United States for the group | Standard Contractual Clauses + EU-US Data Privacy Framework |
| o2switch | Hosting of maymoune.com and maymoune.me | France (EU) | No transfer outside the EU |
| Application infrastructure (private cloud) | Hosting of client applications, databases, and content | France (EU) | No transfer outside the EU |
| Content Delivery Network | Delivery of pages and media | Global | Standard Contractual Clauses |
| Google Ireland Ltd (Analytics, Search Console) | Audience measurement and SEO monitoring | Ireland (EU), servers in the United States | Standard Contractual Clauses + EU-US Data Privacy Framework |
| FluentCRM (self-hosted) | Emails and newsletter | France (EU) | Not applicable — self-hosted |
| FluentCart / customer portal (self-hosted) | Orders, subscriptions, licenses | France (EU) | Not applicable — self-hosted |
| Apple, Google | App distribution on app stores | Global | Independent data controllers, under their own terms |
| Chartered accountant and legal advisors | Accounting and legal obligations | Romania | Service agreement, confidentiality clause |
The services you activate yourself in your application — payment, delivery,
video, notifications, artificial intelligence, analytics — are governed by their
own providers and their own terms.
6. Transfers outside the European Union
Some service providers may process data outside the European Economic
Area, primarily in the United States. These transfers are governed by the
safeguards of Chapter V of the GDPR: adequacy decision where available (notably
the EU-US Data Privacy Framework), standard contractual clauses adopted by the
European Commission, supplemented where appropriate with additional measures
(encryption, pseudonymisation).
A copy of these safeguards can be obtained upon request at contact@sdravobiz.com.
7. Your rights
You have the following rights (Articles 15 to 22 of the GDPR):
- access : know whether we process data concerning you and obtain a copy of it;
- rectification : have inaccurate or incomplete data corrected;
- erasure : obtain their deletion, within the limits of our legal retention obligations;
- restriction : temporarily restrict processing;
- portability : receive your data in a structured and machine-readable format;
- objection : object to processing based on legitimate interest, and unconditionally to commercial prospecting;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing;
- post-mortem directives on the fate of your data;
- complaint with a supervisory authority (Article 10).
How to exercise them. By email to contact@sdravobiz.com (subject “GDPR”) or by
mail to our registered office. To prevent any fraudulent communication, we
may request proof of identity. We respond within one (1)
month, extendable by two months in case of complexity or the number of requests
(Article 12.3 of the GDPR).
8. Security
We implement appropriate technical and organizational measures as provided for
by Article 32 of the GDPR, including: connection encryption (HTTPS/TLS),
payments processed by a PCI-DSS Level 1 certified provider, strict access
control and strong authentication for administrator accounts, access
logging, regular backups, continuous security updates, awareness training for
persons with access to data, and contractual confidentiality commitments with
our subcontractors.
No system can guarantee absolute security. In the event of a data breach
likely to result in a risk to your rights and freedoms, we notify
the ANSPDCP within seventy-two (72) hours and inform you directly when the
risk is high (Articles 33 and 34 of the GDPR).
9. Your users’ data, in your application
This article applies to personal data that you collect, as a
customer, through your application and your back office: your
users’ accounts, orders, bookings, registrations, messages, usage statistics.
You are the data controller. You determine the purposes and means,
define the legal bases and retention periods, inform your users,
collect the necessary consents — particularly for cookies, trackers and
notifications — publish your own privacy policy and respond to
the exercise of their rights.
We are a data processor within the meaning of Article 28 of the GDPR. As such:
- we process this data solely on your documented instructions, solely for the purposes of providing the service: hosting, application execution, backups, technical support at your request, security;
- we do not use them for our own purposes, do not analyze them, do not commercialize them, and do not transfer them;
- our authorized personnel are subject to an obligation of confidentiality and only access your data in case of technical necessity or upon your request;
- we implement the security measures of Article 8;
- we reasonably assist you in your obligations regarding security, breach notification, impact assessment, and responding to requests from your users;
- we notify you without undue delay of any data breach affecting your installation;
- we may use the sub-processors listed in Article 5, for which we remain responsible to you; any material change to this list will be notified to you and you may object to it on legitimate grounds;
- at the end of the contract, your data is recoverable for thirty (30) days then permanently deleted, subject to our legal retention obligations.
The data is hosted in France, in a GDPR-compliant private cloud. Only
content delivery relies on a global network.
This article constitutes a data processing agreement within the meaning of Article 28.3 of the GDPR
between you and Sdravobiz S.R.L. It supplements the
General Terms and Conditions of Sale, of which it forms an integral part.
10. Cookies
A cookie is a small file placed on your device during your visit. We use
few of them.
| Category | Tool | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Strictly necessary | WordPress Session (wordpress_*) |
Authentication, security | Session / 30 days | Legitimate interest — without consent |
| Strictly necessary | Language preference (pll_language) |
Display language | 12 months | Legitimate interest — without consent |
| Strictly necessary | Light / dark theme preference | Display comfort | Persistent (local storage) | Legitimate interest — without consent |
| Audience measurement | Google Analytics (_ga, _ga_*) |
Anonymized statistics | 13 months | Consent |
| Functional / marketing | FluentCRM (fcrm_*) |
Email open and click tracking | 12 months | Consent |
During your first visit, a banner allows you to accept, refuse, or configure cookies that are not strictly necessary. You can modify your preferences at any time via the “Manage my cookies” link at the bottom of each page.
Refusing non-essential cookies does not prevent access to the site or consultation of its content.
11. Minors
The website and the service are not intended for minors under sixteen (16) years of age.
We do not knowingly collect their data without the consent of the holder of parental responsibility (Article 8 of the GDPR). If we discover such data, we delete it without delay. Any request may be sent to contact@sdravobiz.com.
If your application is aimed at a minor audience, it is your responsibility, as data controller, to implement the required verification and parental consent collection measures.
12. Complaints
If you believe that the processing of your data is non-compliant, you can contact the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro — anspdcp@dataprotection.ro — +40 318 059 211
If you reside in another Member State, you may also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).
13. Modifications
We may modify this policy to reflect legal, regulatory, technical, or contractual developments. The applicable version is the one published on the date of your visit. In the event of a substantial modification, we will notify you via a banner on the site or by email if you are a customer.
14. Contact
Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR) — contact@maymoune.com (service and support)
https://maymoune.com/en/accueil/
Last updated: September 2, 2026