Skip to content
WebIDWebID
  • WebIDWebID
  • Who it's for
    • Plumbers
    • Towing companies
    • Roofing companies
    • Auto repair shops
    • Tradespeople
    • Dental clinics
    • Psychotherapy
    • Beauty salons
    • Tattoo studios
    • Yoga and pilates studios
    • Guesthouses
    • Event venues
    • Event planners
    • Pastry shops
    • Restaurants and pizzerias
    • Law firms
    • Driving schools
    • Funeral homes
  • Services
    • Essentials
      • Website + admin panel
      • Blog & Resources
    • Your clients
      • Bookings
      • SMS messaging
      • Website assistant
    • Getting found
      • SEO
      • Google Business Profile
      • Collect reviews
      • Blogging Plus
    • Payments
      • Online payments
    • More languages
      • Multilingual website
      • Website translation
  • Pricing
  • How it works
  • About
  • Make My Website
  • 0
  • EN
    RO-Română
EN
RO-Română
Cookies
  1. Home
  2. Legal
  3. Data processing agreement
FAQ

Data Processing Agreement (DPA)

This document was drafted in Romanian. This English version is a translation provided for convenience; in case of any discrepancy, the Romanian version prevails.

⚠ Work in progress. This text is a draft under legal review. Until it is validated by a lawyer, it is for information only. (This note will be removed when the validated version is published.)

Version 1.22 - draft of September 27, 2026 · Annex to the WebID Terms and Conditions

Why this document exists, in short. If your website takes bookings, sends text messages to your clients or talks to your visitors, your clients' personal data passes through it. For that data, the law says clearly who is who: you are the controller (you decide why it is collected), and we are the processor (we operate the infrastructure, on your behalf). Article 28 of the GDPR requires this relationship to be put in writing - which is exactly what this agreement does. And it protects you first of all: in any inspection, you can show that the processing through your website provider is regulated, with safeguards and known providers.

The agreement is accepted once, through a separate checkbox when you order, and applies automatically to all the modules involving data processing that you activate, now or later.


1. The parties and their roles

  • The controller: you - the client identified in the order, the owner of the website.
  • The processor: us - FAMILIA TASE SRL (the WebID brand), Str. Erou Chivu Dumitru nr. 27, VILA 2, Voluntari, Ilfov County, 077190, Romania, CUI (tax ID) RO41641665, Trade Register No. J40/12194/2019, email contact@webid.ro.

The terms "personal data", "processing", "data subject" and "personal data breach" have the meaning given in the GDPR (Regulation (EU) 2016/679).

What this agreement does NOT cover: your data as our client (your name, invoicing, access to the admin panel) - for that data we are ourselves the controller, and the information is in the Privacy Notice. Nor your clients' payment data through the Payments module: the payment account is yours, opened directly with the payment processor, and the card details go from your client directly to the processor - they don't pass through us and we don't see them.


2. Subject matter, duration, nature and purpose of the processing

  • Subject matter: the technical operation of your website and of the activated modules, insofar as it involves personal data of your clients, patients, guests or visitors ("data subjects").
  • Duration: for as long as you have active services involving processing, plus the handover and deletion period in §10.
  • Nature: hosting and storage, collection through forms, sending messages, content generation, display, backups, deletion.
  • Purpose: solely to provide the services you ordered. We do not use your clients' data for our own purposes - we don't sell it, we don't use it for our marketing, we don't train our products on it.

3. What data, and whose - by module

ModuleData processedData subjects
Website + hosting (if we host it)All the website content, including the personal data you choose to publish (your team, contact details); your team members' accounts in the admin panel (name, email, role) and the log of their actions, kept for 12 months; the server's technical logsYour employees, the people in the content, visitors
The contact form / booking requestThe requests sent by your website's visitors: name, phone and, if they fill them in, email, message, the services chosen and the preferred time slot. We do not store the visitor's IP address - for protection against abuse, we keep only a derived technical identifier, which expires daily and cannot be turned back into an address. Requests are deleted automatically 1 year after receipt or once 2,000 requests are stored, whichever comes first - beyond that number, the oldest are deleted even if they haven't reached the deadline. You can delete them at any time, individually, from the admin panelYour website's visitors
BookingsName, phone, email, date and time, the service requested, the history in the client records, your notes. You set the retention period, as controller, counted from each client's last interaction - we don't impose it on you. If you choose a period, once it is reached we automatically anonymize the records that have exceeded it, with 30 days' notice: first you see them, with names, in the monthly report and in the admin panel; only at the next run are the name, phone, email, address and notes cleared, while the booking stays in the history, without identifying data. If the client returns in the meantime or you change the period, the record is not touched. We carry out the anonymization as your instruction (Art. 28), on the period you set; if you don't set any period, we don't anonymize anything. Complete deletion of records remains yours: it is irreversible, so we don't do it automatically - every month we show you which records have exceeded the period, with names, contact details and the services used, together with the legal basis, and you confirm from the admin panel; beforehand, you can download an archive. Only one rule of the service is automatic: bookings and requests older than 5 years are deleted monthly, with the same 30 days' notice (you see them in the report and in the admin panel and can export them beforehand); client records are not affected by it - they follow only your period. Deletion at the data subject's request remains separate and immediate, regardless of the period chosenYour clients / patients / guests; your employees (calendars)
SMS confirmationsThe phone number, the message content, the reply (confirmation/cancellation)Your clients with bookings
Review GeneratorName and phone from your records, the date of the visit, the messages sent and the repliesYour clients
The Google moduleYour business profile data, the public reviews (the reviewer's name, the text), the replies composed on your behalfReviewers, your clients
SEO Management / the Google module - the connection to GoogleThe data brought in from your Google properties, through the access you give us: traffic figures (Google Analytics), searches and impressions (Search Console), the business profile's statistics and reviews. The connection to Google goes through our server (webid.ro): the access is stored there, encrypted; the reports are generated there and deleted once they reach your website's admin panel (at most 90 days, if delivery fails). For the text of the report, only aggregated figures go to the AI provider. What we send to Google on your behalf is recorded (content, time, who clicked) and kept for 12 months. On disconnection or when the service ends, we revoke the access at Google the same dayYour website's visitors (aggregated only), reviewers, your clients
Voice AssistantThe real-time voice conversation and its temporary transcription (see the special rules in §8)Your website's visitors
Blogging Plus / generated contentThe information about your business sent for generating the articles - it may include personal data (for example, the names of people on your team)Your employees, the people mentioned

The data is adequate and limited to what each module needs to work. We do not collect additional categories on our own initiative.


4. Sensitive data - the case of clinics (Art. 9 GDPR)

A booking at a medical practice may reveal, by its mere existence, information about health ("orthodontic consultation, Tuesday") - that is, a special category of data, with a stricter regime.

  • Your part: as controller, the legal basis for health data is yours - typically Art. 9(2)(h) GDPR (the provision of health care), for which you qualify as a professional subject to professional secrecy. Informing your patients is also up to you (your privacy notice, displayed on your website).
  • Our part: we treat booking data from clinics as sensitive data, with the measures in §6, access restricted to what is strictly necessary, and no secondary use whatsoever.
  • The messaging modules (Confirmations, Reviews) send neutral texts, with no diagnostic or treatment details beyond what you configure.

5. Your instructions

  1. We process the data only on your documented instructions. The instructions = this agreement + the contract + the configuration you make in the admin panel (which modules you activate, which fields you ask for, which messages are sent) + your subsequent written requests, if they are technically reasonable.
  2. The same applies to transfers outside the EU/EEA - they take place only under the conditions in §7.
  3. If an instruction of yours, in our opinion, infringes the GDPR or another data protection rule, we inform you immediately before carrying it out.

6. Confidentiality and security (Art. 32 GDPR)

  1. People: access to your clients' data is limited to the persons who need it in order to provide you with the services, all of them under a confidentiality obligation.
  2. The technical and organizational measures we maintain include:
  • an architecture with a small attack surface: the public part of the website is static (files, no exposed database); the modules' data sits behind the admin panel, protected by authentication;
  • encryption of communications (HTTPS/TLS) on the admin panel and on the websites hosted on the infrastructure we operate; if your website runs on your own hosting, the certificate and its configuration are up to your provider - we help you with the installation;
  • individual accounts in the admin panel for your team members, with roles (administrator, editor, article editor), which you create and control - the same in the Bookings module - and a log of the actions in the admin panel (who changed what, and when), kept for 12 months on the website's server;
  • daily backups, kept in age tiers (details in §10, "At the end"), and restore points at every content save, with the possibility of going back to earlier versions;
  • technical logging for diagnostics and incident investigation;
  • updating software components and fixing the vulnerabilities discovered.
  1. The measures evolve with technology; we will not reduce them below the level described here.

7. Sub-processors and transfers outside the EU/EEA

  1. General authorization. You authorize us to use sub-processors (providers that process data on our behalf, for you) from the list in §12.
  2. Notification of changes. If we add or replace a sub-processor, we notify you in writing at least 14 days in advance (at the contact email). You may object within this period, on reasonable grounds related to data protection. If you object and we don't find a solution (another provider, another configuration), you may terminate the affected module, without us charging you anything for the remaining period; amounts already paid follow the rule in the Terms. The rule exists precisely because some providers (especially AI ones) may change along the way.

⚠ What is NOT a change of sub-processor: switching to another model or another version from the SAME provider - for example, a newer artificial intelligence model from the same company. The sub-processor is the entity that processes the data, not the product we use from it. We make such changes without notification, as long as the level of service does not decrease and neither the country nor the processing conditions change.

  1. The same obligations. We impose on each sub-processor, by contract, data protection obligations equivalent to those here. We remain fully liable to you for the performance of our sub-processors' obligations (Art. 28(4) GDPR).
  2. Transfers outside the EU/EEA: they take place only to countries with an adequacy decision of the European Commission (for the USA: providers certified under the EU-U.S. Data Privacy Framework) or on the basis of the standard contractual clauses (SCCs), with supplementary measures where appropriate. The specific mechanism for each provider is in the table in §12.
  3. Explicit commitment: we do not use sub-processors that process personal data in China - for any service, including voice assistants.

8. Special rules for the Voice Assistant

The voice assistant is the service with the most direct exposure - a free-flowing voice conversation with your visitors. The rules below apply from the moment you activate the module, and we design and operate it on the principle of data minimization (Art. 5 GDPR):

  1. The assistant does not collect personal data by voice. It is instructed, when a visitor wants to leave contact details or make a booking, to invite them to enter the details in the form, not to say them out loud. The form has explicit consent and written, verifiable text; voice has neither.
  2. Transcripts are not kept. The conversation is transcribed only for as long as it lasts, to guide the answers, and is then discarded. We do not build a history of identifiable conversations for your website.
  3. Informing the visitor: when the assistant starts, the visitor is shown a short information notice (provided by the platform) about the voice processing and the provider involved. This is a requirement toward the visitor, distinct from this DPA, and it is shown every time, before the conversation starts.
  4. The voice AI provider is a sub-processor (§12), with the retention terms recorded there. We have no physical control over the provider's servers; that is why it is chosen on strict retention and location criteria, and changing it follows the procedure in §7, "Notification of changes".
  5. Your part: do not configure the assistant in a way that contradicts the principles above (for example, do not ask it to collect medical data verbally).

9. The assistance we give you

  1. Data subjects' rights. If a client of yours exercises a GDPR right (access, erasure, rectification...) and the request reaches us, we forward it to you without delay - you are the controller who answers it. We help you with what relates to the system: finding, exporting, correcting or deleting their data in the modules.
  2. Security incidents. If we become aware of a personal data breach concerning your clients' data, we notify you without undue delay, and no later than 48 hours after discovering it, with the information you need for your own obligations (Art. 33-34 GDPR): what happened, what data and how many people appear to be affected, what measures we have taken. Notifying the authority, if necessary, is your decision and your obligation as controller - but we don't leave you alone with it.
  3. Impact assessments (DPIA) and consultations with the authority: we provide you with the information about the processing that you need, insofar as we hold it.

10. At the end: handover and deletion of data

  1. When the services involving processing end, you choose: we hand the data over to you (export in a common, usable format), we delete it, or both - first the handover, then the deletion.
  2. Unless you ask otherwise, 30 days after termination we delete your clients' data from the active systems. We make the backups ourselves, on the same server where the data is stored: archives of the data (not of the published pages), made daily only when something has changed, kept in age tiers - the oldest copy is at most 182 days old; the Bookings module's data has daily copies kept for 14 days. What has been deleted from the active systems disappears from the copies through this rotation, so no later than 182 days after deletion. The copies are not separately encrypted - they are protected by the same measures as the live data (§6) and are not accessible on the web. In addition, the hosting provider keeps a weekly backup of the account, under its own retention policy (§12).
  3. Exception: data that the law requires us to keep (for example, invoicing records - but those are in any case data of our direct relationship, not of your clients).

11. Verification and liability

  1. Information and audit. On request, we provide you with the information needed to verify compliance with this agreement (a description of the measures, the list of sub-processors with the relevant framework contracts, certifications where they exist). You may request an audit - once a year, with reasonable notice, during business hours, without access to other clients' data; the costs of the audit are yours.
  2. Liability follows the rules in the Terms §14 and Art. 82 GDPR: each party is liable for its own share of the obligations - we for the processor's obligations, you for the controller's (legal basis, information, instructions).
  3. In the event of a conflict between this DPA and the Terms, the DPA prevails as regards data protection.

12. List of sub-processors

Current version of the list. Any change follows the notification procedure in §7, "Notification of changes". Last updated: September 27, 2026 (draft).

Sub-processorWhat it doesWhat data it touchesCountry of processingTransfer mechanism
Gazduire.net - a brand of TES EURO MEDIA SRL, Calea Hărmanului nr. 47, comuna Sânpetru, Brașov County, Romania, CUI (tax ID) RO14612719, Trade Register J2002000536080Hosting of the websites and the admin panel (only if the hosting is with us); hosting of the modules we operate (for example, Bookings), including sending their emails through the hosting's email server; domain registration; the webid.ro server, which the clients' Google connections go through (the tokens, encrypted) and where the reports are generatedAll the website content, the modules' data, the emails sent to your clients (the copies in the email server's queues and logs follow the provider's retention), technical logs; the domain registration data; the access to the connected Google accounts (encrypted) and the data brought in from themRomania (EU)Not required - the processing stays in the EU. The provider declares itself a processor and has its own processing agreement, published in its terms
SMSLink [legal entity to be completed] - SMS providerSending the text messages (Confirmations, Reviews)Phone numbers, message contentRomania (EU) [to be confirmed at contracting]Not required (processing in the EU)
Anthropic [contracting entity to be verified] - AI provider for textsWriting and checking the articles (Blogging Plus), translating the website's texts (Multilingual) and drafting your website's textsThe brief and the texts sent: the company, the services, the website text, the voice, the names of the specialists - they may contain personal dataUSA [EU entity to be confirmed at contracting]EU-U.S. Data Privacy Framework + standard contractual clauses [to be verified in the provider's DPA, with link]
OpenAI [contracting entity and plan to be verified] - AI providerThe second check of the articles (Blogging Plus, Premium tier) and generating images for articlesThe article brief: the company, the services, the website text, the voice, the names of the specialists - they may contain personal dataUSA [EU entity to be confirmed at contracting]EU-U.S. Data Privacy Framework + standard contractual clauses [to be verified in the provider's DPA, with link]
Google (Gemini) [the exact service and contracting entity to be confirmed at build time] - voice AI providerThe Voice Assistant's conversations (speech recognition, response, synthesis) - only from the moment you activate the moduleThe audio stream and the temporary transcription of the conversation[to be confirmed at build time - with a preference for an EU region]EU-U.S. Data Privacy Framework + standard contractual clauses [to be verified in the service's terms, with link]
GoogleThe Google module: managing the business profile through the APIThe GBP profile data, the reviews and the repliesUSAEU-U.S. Data Privacy Framework

On data retention at the AI providers: the retention entry for each AI provider (whether and for how long it keeps the data sent through the API, whether it uses it for training) is recorded here based on the provider's written terms, with a link to them - not based on reputation. [To be completed when the real account is verified, before publication.]

On backups: our copies are described in §10, "At the end". The hosting provider separately keeps a weekly backup of the account, kept under its own retention policy.

A note on reselling: if we provide hosting under our own brand ("white-label" reselling), the real provider remains on this list. The list answers the question who actually processes the data, not what name appears on the invoice.


13. Acceptance and versions

The agreement is accepted through a separate checkbox when you order ("I accept the Data Processing Agreement"), with a link to this page. The checkbox is never pre-checked. We keep the proof: who accepted, when, which version. Changes to the agreement follow the rules in the Terms §17, and for the list of sub-processors - the procedure in §7, "Notification of changes".

Language of this agreement. This document was drafted in Romanian. This English version is a translation provided for convenience; in case of any discrepancy, the Romanian version prevails.

FAMILIA TASE SRL · Str. Erou Chivu Dumitru nr. 27, VILA 2, Voluntari, Ilfov County, 077190, Romania · CUI (tax ID) RO41641665 · contact@webid.ro

Version 1.22 - draft of September 27, 2026.

WebIDWebID

WebID builds websites for small businesses in Romania: copy included, you see it before you pay, and the admin panel is in English or Romanian.

We reply within 24 hours

contact@webid.ro

Navigation

  • Who it's for
  • Services
  • Pricing
  • How it works
  • About

Services

  • Essentials
  • Your clients
  • Getting found
  • Payments
  • More languages

Legal information

  • Terms and conditions
  • Privacy
  • Cookies
  • DPA

Contact

FAQ

ANPC - Alternative Dispute Resolution (SAL)
© 2026 WebID |

We use cookies to understand which pages help and which don't. You choose what you accept.