Privacy Policy

Last updated: 22 July 2026

This Privacy Policy explains how personal data is processed when you use the Vecto HR platform (SaaS application for human resources management), when you visit our website, and when we provide technical support and billing services. It applies together with the Data Processing Agreement (DPA), Terms and Conditions, and the GDPR rights page.

1. GDPR roles — who is responsible

Depending on the type of data and context, different entities act as data controller or processor under Regulation (EU) 2016/679 (GDPR):

  • Client company (your employer or the organization that subscribed to Vecto HR) is the data controller for employee and HR data entered in the application (personnel files, payroll, attendance, documents, etc.). The client decides what data is collected, for what purposes, and is responsible towards employees and other data subjects.
  • APPVECTO S.R.L. acts as data processor (sub-processor) for HR data processed in the application on behalf of the client, based on documented instructions and the DPA.
  • APPVECTO S.R.L. acts as an independent data controller for its own purposes regarding: user account and authentication data, subscription and billing, payments processed through Stripe, customer support, platform security, technical logs, website usage, and communications related to the Vecto HR service.

2. About APPVECTO S.R.L.

APPVECTO S.R.L., CUI 54906519, registered office: Strada Agricultorilor nr. 18, Subsol Tehnic, Spațiu Tehnic 2, 707085 Lunca Cetățuii, Iași, România.

General contact: contact@appvecto.com. Support: support@appvecto.com.

APPVECTO S.R.L. develops and operates the Vecto HR SaaS platform.

3. Categories of data collected

Depending on your relationship with the platform, we may process the following categories of data:

  • identification and contact data (name, email, phone, address);
  • employment and HR data entered by the client (job title, department, salary, seniority, contracts, leave, attendance, documents);
  • sensitive data where applicable and instructed by the client (e.g. national ID number/CNP, ID card details, IBAN, occupational health documents) — only if the client uploads or enters them for lawful HR purposes;
  • account and authentication data (user ID, role, password hash, session tokens, email verification status);
  • subscription and billing data (plan, billing period, invoices, Stripe customer and subscription identifiers);
  • payment-related metadata from Stripe (payment status, last four digits of card if provided by Stripe, billing address) — APPVECTO S.R.L. does not store full card numbers;
  • support and communication content (support tickets, emails, messages sent to us);
  • technical and security data (IP address, browser type, device information, access timestamps, audit events, error logs, CSRF and session cookies).

4. Purposes of processing

  • providing and operating the Vecto HR SaaS application;
  • human resources management, payroll, attendance, documents and reporting (on behalf of the client);
  • user authentication, authorization, and multi-tenant isolation between organizations;
  • subscription management, invoicing, and payment collection;
  • technical support and service communications;
  • security monitoring, fraud prevention, audit and incident response;
  • compliance with legal obligations and enforcement of our terms;
  • improving reliability and performance of the platform (aggregated or technical data, within the limits of current functionality).

5. Legal bases for processing

The applicable legal basis depends on the role and context:

  • For HR data processed on behalf of the client: the client determines the legal basis (typically Art. 6(1)(b) GDPR — performance of employment contract; Art. 6(1)(c) — legal obligations under labour, tax and social security law; Art. 9(2)(b) — health data for employment and social security, where applicable).
  • For platform account, billing and security data where APPVECTO S.R.L. is controller: Art. 6(1)(b) GDPR — performance of the subscription contract; Art. 6(1)(c) — legal obligations (e.g. accounting, tax records); Art. 6(1)(f) — legitimate interests in securing and improving the service, balanced against your rights;
  • For marketing communications (if any): consent, where required, which you may withdraw at any time.

6. HR and payroll data

Employee and HR data in Vecto HR is entered and controlled by the client organization. APPVECTO S.R.L. processes this data only to provide the contracted features (employee records, payroll calculation, payslips, time tracking, documents, reports, etc.) and only according to the client's instructions and the DPA.

If you are an employee, questions about HR data processing, access, rectification or erasure should generally be addressed to your employer (the data controller) at the email address of your employer or organization, as configured in the organization settings.

Certain fields such as CNP and IBAN may be stored using application-level encryption (AES-256-GCM) when configured in the deployment.

7. Organization administrators and users

Users invited by a client organization (administrators, HR staff, accountants, etc.) have accounts linked to that organization. We process their name, email, role, activity within the application, and authentication data to provide access and maintain security.

The client organization is responsible for granting and revoking access and for ensuring that users are informed about processing.

8. Payment and subscription data

Paid subscriptions are processed through Stripe. APPVECTO S.R.L. does not receive or store complete payment card numbers; card data is entered directly on Stripe's secure pages and processed by Stripe as an independent controller / payment processor.

We store Stripe identifiers (customer ID, subscription ID), billing status, plan tier, billing period, and invoice metadata necessary to manage your subscription. For payment issues, you may use the Stripe Customer Portal available from the application or contact support@appvecto.com.

9. Support and communications

When you contact us at contact@appvecto.com or support@appvecto.com, we process the information you provide to respond to your request, troubleshoot issues, and maintain correspondence records as needed for service quality and legal compliance.

Transactional emails (account verification, password reset, billing notifications, payslip delivery when enabled) are sent through the platform's default email provider (Resend) or through an email provider configured by the client (SMTP settings), as applicable.

10. Technical logs, security and audit

To protect the platform and demonstrate accountability, we process technical logs and security events, including:

  • authentication and session events;
  • audit records for sensitive actions (e.g. data exports, document access, configuration changes) where implemented;
  • application and infrastructure error logs;
  • IP addresses and request metadata for security and abuse prevention.

11. Cookies, local storage and web analytics

The website and application use cookies, local storage, and optional web analytics as follows:

Web analytics (optional): We use Vercel Web Analytics to measure usage and performance of the website and application. Vercel Web Analytics does not use cookies. It collects anonymized, aggregated data and uses a temporary hash identifier that is not used to track you across days or across websites. In Vecto HR, the Vercel Web Analytics script is loaded only after you explicitly accept analytics in the cookie consent banner (Accept all, or Customize with analytics enabled), even though the underlying Vercel technology is cookieless, because we treat usage measurement as non-essential. If you choose Essential only, disable analytics in Customize, or make no choice, the script is not loaded and no analytics events are sent.

  • strictly necessary cookies — authentication (httpOnly session), CSRF protection, language preference; required for the service to function and do not require consent;
  • local storage for consent preferences (localStorage key vecto-cookie-consent), used to remember your choices in the cookie banner;
  • we do not use marketing cookies or other non-essential tracking cookies.
  1. You can withdraw analytics consent at any time using Manage cookie preferences in the site footer (available on public pages), reopen the cookie banner, and choose Essential only or disable analytics in Customize.
  2. Withdrawal stops loading the Vercel Web Analytics script and transmission of future analytics events. Because Vercel Web Analytics does not use cookies, no analytics cookies are set or removed when you withdraw consent.
  3. Strictly necessary cookies remain active because they are required for the service to work.

12. Data recipients and sub-processors

Data may be disclosed to the following categories of recipients, subject to contract and applicable law:

  • authorized users of the client organization, according to their role;
  • persons or institutions the client is legally required or entitled to disclose data to (e.g. labour authorities, courts, banks for salary payments) — under the client's responsibility as controller;
  • Stripe — payment processing and subscription management;
  • Vercel — application hosting and, if you consent to analytics, Vercel Web Analytics for cookieless usage and performance measurement (loaded via the application SDK only after consent);
  • Neon — PostgreSQL database hosting;
  • Cloudflare R2 — document storage and backups;
  • Resend — platform default transactional email delivery.
  • An email provider configured by the client (SMTP) may be used by the organization for notifications; it is chosen and configured by the client and is not a mandatory sub-processor of APPVECTO S.R.L. except to the extent the client uses it through the platform.
  • We do not sell personal data. We do not integrate automatic invoicing with third-party tax platforms (FGO, SPV, ANAF, etc.) unless explicitly stated in a future version of the service.

13. International transfers

Some providers (sub-processors) may process data outside the European Economic Area, depending on the infrastructure used. Where required under the GDPR, transfers rely on appropriate safeguards under GDPR Chapter V (for example Standard Contractual Clauses, adequacy decisions, or other mechanisms permitted by law), as set out in the applicable contracts, DPAs, and provider documentation.

The list of sub-processors and transfer details are described in the DPA accepted by client organizations. APPVECTO S.R.L. does not represent that a specific transfer mechanism applies to every provider without documentary confirmation.

14. Retention periods

Retention depends on the data category, who is controller, and demonstrated legal terms. The product policy source is the application retention matrix (not a blanket five-year rule for all data).

Access credentials and sessions may be deleted immediately after a verified account-deletion request.

Confirmed financial-accounting records (e.g. payslips and invoices classified as such) may be retained until the end of five years counted from 1 July of the year following the financial year, then deleted only when eligible and not under legal hold.

Employment contracts, medical certificates, unclassified timesheets/leave records and unattributable legacy storage objects are restricted pending legal review — we do not invent a purge term.

Backups follow the platform backup configuration; restored systems re-apply tombstones before access is restored. Legal hold can block backup expiry for relevant categories.

  • Immediate deletion: access account, sessions, eligible temporary exports/imports/branding objects.
  • Anonymization: selected personal documents under controller instruction; email/audit metadata minimized.
  • Confirmed retention then deletion: classified payroll/accounting documents and invoices.
  • Controller approval required: employee HR profile erasure (EMPLOYEE_ERASURE).
  • Legal review / restricted: personnel file, contracts, medical/leave without confirmed term, unclassified timesheets, legacy R2 objects.
  • Legal hold and PARTIAL_FAILED block any claim of completed erasure.

15. Rights of data subjects

Under the GDPR you may have the following rights, subject to conditions and exceptions in law: access, rectification, erasure, restriction, data portability, objection, and not to be subject to solely automated decision-making with significant effects.

Practical guidance for employees is available on the page Your rights regarding personal data.

16. How to submit GDPR requests

APPVECTO S.R.L. does not currently have a designated Data Protection Officer (DPO). Use the privacy contact contact@appvecto.com (or support@appvecto.com) for platform-level requests. Do not use a fabricated DPO address. A DPO will be appointed if and when required by applicable law.

We distinguish three workflows: ACCOUNT_DELETE (access account), EMPLOYEE_ERASURE (HR data — employer decides as controller), and ORG_CLOSURE (organization closure with grace period and retention stages).

General response deadline: one month from receipt (GDPR Art. 12), with a possible motivated extension of up to two further months. Silence does not mean automatic HR erasure.

  1. For employee / HR data: contact your employer (the client data controller) at the email address of your employer or organization, as configured in the organization settings.
  2. For account, billing, or platform data where APPVECTO S.R.L. is controller: email contact@appvecto.com or support@appvecto.com, describing your request and account details so we can verify your identity.
  3. If we act as processor, we forward requests to the relevant client organization unless we are authorized to respond directly.
  4. Request statuses you may see: WAITING_CONTROLLER, RETAINED_LEGAL, PARTIAL_FAILED, GRACE_PERIOD, PROCESSING, COMPLETED. COMPLETED is declared only after verified stages — never while legal hold, incomplete R2/Stripe/email checks, or uncleared retention categories remain.
  5. We respond within the time limits set by the GDPR for valid requests where APPVECTO S.R.L. acts as controller.

17. Complaints to ANSPDCP

If you believe your rights have been violated, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

Official website: https://www.dataprotection.ro — complaints section: https://www.dataprotection.ro/?page=Plangeri_pagina_principala — address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania.

You may also seek a judicial remedy. APPVECTO S.R.L. is not the legal representative of your employer.

18. Data security

We implement technical and organizational measures appropriate to the risk, including:

  • encryption of selected sensitive fields (e.g. CNP, IBAN) at application level where used;
  • role-based access control and logical separation between client organizations (multi-tenant architecture);
  • authenticated sessions (httpOnly cookies) and CSRF protection for mutating requests;
  • audit logging for relevant security and compliance events;
  • infrastructure hosted with reputable cloud providers and access restricted to authorized personnel.

19. Changes to this policy

We may update this Privacy Policy to reflect legal, technical, or business changes. The current version is indicated by the "Last updated" date at the top of this page. Material changes may be communicated through the application or by email where appropriate.

Continued use of the service after publication of an updated policy constitutes acceptance where permitted by law; for material changes affecting client organizations, we will seek to provide reasonable notice.

20. Contact

For questions about this policy or platform-level data processing where APPVECTO S.R.L. is controller:

APPVECTO S.R.L., CUI 54906519, Strada Agricultorilor nr. 18, Subsol Tehnic, Spațiu Tehnic 2, 707085 Lunca Cetățuii, Iași, România.

Email: contact@appvecto.com | Support: support@appvecto.com.

For employee data processed in Vecto HR, contact your organization's HR administrator. Privacy contact (no DPO currently designated): contact@appvecto.com.

GDPR rights

Privacy Policy · Terms and conditions · GDPR rights · DPA Agreement ·

Privacy Policy | Vecto HR | Vecto HR