TABLE OF CONTENTS
- 1. Who is responsible
- 2. Two distinct situations
- 3. What we process, and why
- 4. We do not sell your data
- 5. Our service providers
- 6. What the plugin sends to our servers
- 7. Transfers outside the European Union
- 8. Your rights
- 9. Security
- 10. Your visitors’ data stays with you
- 11. Cookies
- 12. Minors
- 13. Complaints
- 14. Modifications
- 15. Contact
This policy explains what personal data we process, why, for how long, and what your rights are. It applies to the funnelcart.pro website, the shop and customer portal operated on sdravobiz.com, and the FunnelCart WordPress plugin.
It is drafted in accordance with Regulation (EU) 2016/679 (“GDPR”), Romanian Law no. 190/2018, and Romanian Law no. 506/2004.
1. Who is responsible
Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367 — Intra-EU VAT: RO51472369
Trade Register: J2025016522009
Email: contact@sdravobiz.com
Sdravobiz is not required to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR: its activity relies neither on large-scale processing of sensitive data nor on large-scale systematic monitoring of individuals.
Any request may be sent to contact@sdravobiz.com, indicating “GDPR” in the subject line.
2. Two distinct situations
This is the most important point of this policy, and it is also the main difference between FunnelCart and an online service.
Your own data, as a customer or visitor to our site. We are the data controller for it: account, order, invoice, license, support, newsletter. This is the subject of Articles 3 to 9.
The data of the people who browse your sales funnels. It is stored in the database of your WordPress site, on your hosting. It does not pass through any of our servers, is never transmitted to us, and is not accessible to us. You are the sole data controller for it, and we are neither a controller nor a processor. This is the subject of Article 10.
3. What we process, and why
| Purpose | Data | Legal Basis | Retention |
|---|---|---|---|
| Orders, Licensing, and Invoicing — account creation, contract performance, invoices, accounting obligations | Last name, first name, company, address, email, VAT number, order and invoice history, license key | Performance of a contract (Art. 6(1)(b)) and legal obligation (Art. 6(1)(c)) | Duration of the contract, then 10 years under Law no. 82/1991 |
| Activation Management — license validity check, site count tracking, update distribution | License key, address of activated sites, product identifier, installed version, activation and verification dates | Performance of a contract (Art. 6(1)(b)); legitimate interest for protection against unauthorized use (Art. 6(1)(f)) | Duration of the license, then 3 years |
| Payments — collection, fraud prevention, disputes, and refunds | Billing details, transaction history, and transaction identifiers | Performance of a contract (Art. 6(1)(b)); legitimate interest in fraud prevention (Art. 6(1)(f)) | 10 years (accounting obligations) |
| Service Emails — confirmation, invoice, license key, update availability, expiration, security incident | Name, email, account identifier | Performance of a contract (Art. 6(1)(b)) | Duration of the contract, then statutory archiving |
| Support and Customer Relations | Name, email, message content, screenshots, and environment reports you send to us | Performance of a contract (Art. 6(1)(b)); legitimate interest for prospective customers (Art. 6(1)(f)) | 3 years after the last contact (customers); 13 months (prospective customers) |
| FunnelCart Community — access to the help community, posts, and replies | Display name, email, content of published messages | Performance of a contract (Art. 6(1)(b)); consent for publication (Art. 6(1)(a)) | Duration of participation, then 12 months |
| Newsletter and Product Information | Name, email, language, opens, and clicks | Legitimate interest (Art. 6(1)(f)) for customers, regarding a similar product, and for professionals who write to us through the contact form, about their business; consent (Art. 6(1)(a)) in other cases | Until you unsubscribe, in one click from any email, and at most 3 years after the last interaction |
| Website Analytics | Anonymized IP address, page views, duration, traffic source, device, and browser | Consent (Art. 6(1)(a)) for non-essential cookies; legitimate interest for anonymized analytics | 14 months |
| Legal Obligations and Litigation | Invoices, supporting documents, connection logs | Legal obligation (Art. 6(1)(c)); legitimate interest for legal defense | Applicable statutory period |
We do not make any fully automated decisions that have legal effects concerning you, and we do not practice advertising profiling.
4. We do not sell your data
Sdravobiz does not sell, rent, or transfer your personal data to third parties for commercial purposes.
Your data is only disclosed to the service providers listed in Article 5, to competent administrative or judicial authorities upon legal request, and to our advisers in the event of legal proceedings.
5. Our service providers
We use processors within the meaning of Article 28 of the GDPR, selected for their guarantees. This list is subject to change.
| Service Provider | Role | Location | Transfer Safeguards |
|---|---|---|---|
| Stripe Payments Europe, Ltd | Online payment, anti-fraud | Ireland (EU), group servers in the United States | Standard Contractual Clauses + EU-US Data Privacy Framework |
| o2switch | Hosting of the website, shop, customer portal, and license server | France (EU) | No transfers outside the EU |
| Shop, licenses, and customer portal (self-hosted) | Orders, subscriptions, license keys, activations, invoices | France (EU) | Not applicable — self-hosted |
| Contact and email management (self-hosted) | Service emails, newsletter | France (EU) | Not applicable — self-hosted |
| Support and community (self-hosted) | Support tickets, user peer-support forum | France (EU) | Not applicable — self-hosted |
| Google Ireland Ltd (Analytics, Search Console) | Audience measurement and SEO tracking | Ireland (EU), servers in the United States | Standard Contractual Clauses + EU-US Data Privacy Framework |
| Chartered accountant and legal counsel | Accounting and legal obligations | Romania | Service agreement, confidentiality clause |
None of these service providers has access to the data that you collect with the extension on your own site.
6. What the extension sends to our servers
The extension installed on your site communicates with our license server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update searches.
On each of these occasions, and on these occasions only, your site transmits exactly the following items:
- the product identifier;
- your license key;
- your site address;
- the version number of the installed extension;
- a single-use nonce, intended to prevent response replay.
And nothing else. In particular, the following are never transmitted: data from your visitors, leads, and customers, their email addresses, their orders, their IP addresses, your statistics, your funnels, your settings, your site content, your administrator email address, your PHP or WordPress version, the list of your extensions.
The extension contains no telemetry, no usage statistics tracking, and no installation reporting. The diagnostic screen displays a description of your technical environment: this description remains on your site and is only transmitted if you copy it yourself into a support message.
Communications with FluentCRM, your webhooks, your advertising platforms, and your other tools go directly from your server to the destinations you have specified yourself. They do not pass through any of the publisher’s servers.
7. Transfers outside the European Union
Our customer data is hosted within the European Union. The only transfers likely to occur outside the European Economic Area concern our payment provider and our audience measurement tools, whose groups maintain infrastructure in the United States.
These transfers are governed by the safeguards of Chapter V of the GDPR: adequacy decisions where available (in particular the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained upon request at contact@sdravobiz.com.
The data you collect with the extension is not subject to any transfer on our part, as it is never sent to us.
8. Your rights
You have the following rights (Articles 15 to 22 of the GDPR):
- access: know whether we process data concerning you and obtain a copy of it;
- rectification: have inaccurate or incomplete data corrected;
- erasure: obtain its deletion, within the limits of our legal retention obligations;
- restriction: temporarily restrict processing;
- portability: receive your data in a structured, machine-readable format;
- objection: object to processing based on legitimate interest, and unconditionally to commercial prospecting;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing;
- post-mortem directives on the fate of your data;
- complaint with a supervisory authority (Article 13).
How to exercise them. By email to contact@sdravobiz.com (subject line “GDPR”) or by mail to our registered office. To prevent any fraudulent communications, we may request proof of identity. We respond within a period of one (1) month, extendable by two months in case of complexity or volume of requests (Article 12.3 of the GDPR).
If you have gone through a sales funnel on the website of a company using FunnelCart and wish to exercise your rights regarding this information, please contact that company directly: they alone are the data controller, and they alone hold this data. We have no access to it and therefore cannot provide it to you or delete it.
9. Security
We implement the appropriate technical and organizational measures provided for in Article 32 of the GDPR, including: connection encryption (HTTPS/TLS), payments processed by a PCI-DSS Level 1 certified provider, strict access control and strong authentication for administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our subcontractors.
The update archives served by our server are sealed and cryptographically signed, and their signature is verified by your site prior to installation.
No system can guarantee absolute security. In the event of a data breach likely to result in a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 of the GDPR).
10. Your visitors’ data remains with you
This article is addressed to you, the client, regarding the individuals who browse the sales funnels installed on your site.
10.1 You are the sole data controller
This data is stored in tables of your own WordPress database, on your hosting. We do not receive it, host it, consult it, and cannot restore it.
You alone determine the purposes and means of the processing. It is your responsibility to inform your visitors, define your legal bases and retention periods, publish your own privacy policy, collect the necessary consents, and respond to requests to exercise individual rights. Regarding this data, we are neither a data controller nor a data processor: we provide you with software, not a data processing service.
10.2 What the extension records on your end
So that you can include it verbatim in your own policy, here is what is recorded when a visitor goes through a funnel:
- their journey: the funnel pages they view, the offers presented, accepted, or declined, and the date and time of each event;
- the information they enter on a capture page: first name, email address, responses to the fields you have placed;
- their orders, as recorded by FluentCart: items, amounts, payment method retained by your payment provider for a potential one-click offer;
- proof of their consent to the one-click offer: the text displayed at checkout and the date;
- their acquisition source: campaign parameters, ad click IDs, landing page, and referring site;
- their device and, depending on your settings, their IP address — retained by default, can be disabled in the settings;
- the notes and tags you subsequently add to their record.
The extension also maintains aggregated daily counters — page views, offers displayed, sales — which contain no data that can identify an individual.
10.3 What the extension makes available to you
- An exporter and an eraser registered with native WordPress tools: export and erasure requests that you process from your site’s “Tools” screen automatically include data recorded by the extension.
- A configurable retention period for visitor journeys — thirty days by default, after which they are automatically purged daily — and a separate period for buyers, kept indefinitely by default because they constitute a sales history.
- A suggested privacy policy text, added to the WordPress privacy policy screen, which you can use and adapt.
- A complete erasure upon uninstallation, if you choose this option.
Warning: buyers are kept indefinitely by default, and visitors’ IP addresses are stored by default. Configure these two settings upon installation.
10.4 What you are responsible for
- Describe in your privacy policy the data listed in section 10.2, their purposes, their legal bases, and their retention periods.
- Display a clear consent text before submission, and keep it as is: it is archived as proof.
- Declare in your cookie policy the attribution cookie described in section 11.3, and subject it to consent if it is used for advertising purposes.
- Do not ask questions that elicit sensitive data within the meaning of Article 9 of the GDPR, banking data, or government identifiers.
- Verify that the messages you send from your funnels comply with the rules applicable to electronic marketing.
- Check what the contact management system to which you copy this data does with it: this copying constitutes a processing operation for which you are responsible.
10.5 The only case where we see your data
If you provide us, as part of support, with a screenshot, an export, or access to your site, we may be exposed to your visitors’ data. We then act as a processor, on your specific and documented instruction, solely for the duration necessary to process your request. These items are deleted upon closing the ticket, and at the latest within the three (3) years of retention for support exchanges.
We recommend that you anonymize your screenshots before sending them to us.
11. Cookies
11.1 On our site
| Category | Tool | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Strictly necessary | WordPress Session (wordpress_*) | Authentication to the customer area, security | Session / 30 days | Legitimate interest — without consent |
| Strictly necessary | Cart and order | Keep the current order | Session | Legitimate interest — without consent |
| Strictly necessary | Language preference (pll_language) | Display language | 12 months | Legitimate interest — without consent |
| Audience measurement | Google Analytics (_ga, _ga_*) | Anonymized statistics | 13 months | Consent |
| Functional / marketing | Email tracking (fcrm_*) | Opens and clicks on our emails | 12 months | Consent |
During your first visit, a banner allows you to accept, decline, or configure non-strictly necessary cookies. You can modify your preferences at any time via the “Manage my cookies” link at the bottom of each page. Refusing non-essential cookies does not prevent access to the site or viewing its content.
11.2 What the extension stores on your visitors’ devices
On our customers’ websites, the extension places the following item in visitors’ browsers. It is set by your website, under your domain name, and it is your responsibility to declare it.
| Name | Type | Purpose | Duration |
|---|---|---|---|
fcf_sid | Signed cookie, inaccessible to JavaScript | Recognize the visitor from one funnel page to the next, link their order to their journey, and present them with the intended offers | Configurable, 30 days by default |
11.3 The case of advertising platforms
The extension always measures your funnels on your end: statistics, user journeys, and step rankings do not depend on any cookie banner. What depends on it is solely what is sent to an advertising platform (Meta, Google, TikTok): these transmissions are only made if the visitor has given their consent through your website’s consent tool. In the absence of any signal, nothing is sent.
As the publisher of your website, it is up to you to qualify this use and connect your consent tool.
12. Minors
Our website and our product are not intended for minors under sixteen (16) years of age. We do not knowingly collect their data without the consent of the holder of parental authority (Article 8 of the GDPR). If we discover such data, we delete it without delay.
If your funnels are aimed at a minor audience, it is your responsibility, as the data controller, to implement the required verification and parental consent collection measures.
13. Complaints
If you believe that the processing of your data is not compliant, you may contact the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro — anspdcp@dataprotection.ro — +40 318 059 211
If you reside in another Member State, you can also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).
14. Changes
We may modify this policy to reflect legal, regulatory, technical, or contractual developments. The applicable version is the one published on the date of your visit. In the event of a substantial change, we will inform you via a banner on the site or by email if you are a customer.
15. Contact
Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR) — contact@sdravobiz.com (service and support)
https://funnelcart.pro/en/accueil/
Last updated: September 28, 2026
