Quorify

Data Processing Agreement (DPA) - Quorify 230

Version 1.0 · Last updated: August 31, 2026

In case of conflict between the two versions, the Romanian version prevails.

This Data Processing Agreement ("DPA") is entered into between the Organization, as controller, and Quorify [LEGAL ENTITY], as processor, under Art. 28 of Regulation (EU) 2016/679 (GDPR), and governs the processing of taxpayer data collected through the Quorify 230 Service. This DPA forms part of the Quorify 230 Terms.

1. Subject and duration

1.1. This DPA governs Quorify's processing, on behalf of and on the instructions of the Controller, of the personal data of taxpayers who complete Formular 230. It is effective for the duration of use of the Service and ends upon deletion of the data under section 9.

2. Roles of the parties

2.1. The Organization is the controller: it determines the purpose (collecting Formular 230 and filing with ANAF) and the means. Quorify is the processor and processes the data solely on the Controller's documented instructions, including through this DPA.

3. Nature, purpose and data categories

3.1. Nature of processing: collection, encryption, storage, PDF generation, making available for export, and deletion.

3.2. Purpose: solely to generate Formular 230 and make it available to the Controller for filing with ANAF.

3.3. Data subjects: individual taxpayers with salary and assimilated income.

3.4. Data categories: last name, first name, father's initial (optional), national ID number (CNP), address, phone and email (optional), signature, redirection options; the hashed form (SHA-256) of the IP address and browser agent, plus the consent timestamp.

3.5. CNP is special-regime data under Art. 4 of Law 190/2018 and benefits from the enhanced measures in section 6.

4. Processor obligations (Quorify)

  • processes data only on the Controller's documented instructions and solely for the stated purpose;
  • ensures confidentiality and binds authorized persons to confidentiality;
  • implements the technical and organizational measures in section 6;
  • assists the Controller, by appropriate technical measures, in fulfilling data-subject requests (section 7) and its security, breach-notification and impact-assessment obligations (Art. 32-36 GDPR);
  • notifies the Controller under section 8 in case of a personal-data breach;
  • does not engage another sub-processor without complying with section 5;
  • makes available the information needed to demonstrate compliance and allows audits under section 10.

5. Sub-processors

5.1. The Controller generally authorizes the following sub-processors for the 230 Service:

  • Supabase - database and storage of encrypted data (including encrypted CNP), in the European Union;
  • Vercel - compute at form-generation and export time.

5.2. Express exclusion: Formular 230 PDF documents are never sent to the Microsoft Office preview service and are not processed by any third-party document-viewing service.

5.3. Quorify will notify the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds; failing a solution, the Controller may stop using the 230 Service. Quorify remains liable for its sub-processors' compliance. Current list: Sub-processor List.

6. Security measures (Art. 32 GDPR)

  • Field-level encryption: CNP and all taxpayer personal data are encrypted with AES-256-GCM before storage, using a dedicated, separate encryption key; data is never stored in clear text.
  • Controlled decryption: decryption occurs only server-side, at the time of export authorized by the Controller.
  • Secure documents: generated PDFs are stored in a private space, accessible only via temporarily signed links.
  • Telemetry pseudonymization: IP address and browser agent are stored only as hashes (SHA-256).
  • Access control: Row Level Security and restriction to Organization administrators holding the specific Formular 230 management permission; service-key access is strictly server-side.
  • Traceability: access to and exports of 230 data are logged.
  • Strong authentication: two-factor authentication (2FA/TOTP) available for administrator accounts.

7. Assistance with data-subject rights

7.1. When a taxpayer exercises a right (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) directly with the Controller, Quorify provides, at the Controller's request, the technical assistance needed to locate, correct, export or delete the relevant data within a reasonable time, generally within 10 business days.

8. Personal-data breach notification

8.1. Quorify notifies the Controller without undue delay and within 72 hours of becoming aware of a breach affecting 230 data, by email and via the Platform, providing: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

8.2. Because the data includes CNP (special-regime data), a breach may trigger the Controller's obligation to notify ANSPDCP (Art. 33 GDPR) and to notify affected individuals (Art. 34 GDPR) where the breach is likely to result in a high risk to their rights and freedoms - generally presumed for CNP. However, under Art. 34(3)(a) GDPR, individual notification may not be required if the affected data was encrypted (AES-256-GCM) and the encryption key was not compromised, so the data remains unintelligible to unauthorized persons. Quorify supports the Controller in assessing the risk and meeting these obligations.

9. Deletion and return of data

9.1. On end of the Service, the Controller has a 30-day window to export the data. After that window, Quorify deletes the data, except where retention is legally required.

9.2. Independently of termination, data from expired campaigns is automatically deleted after the legal archiving period of 5 fiscal years + 1 year. This period is aligned with the general 5-year limitation term for the tax authority's right to establish tax claims under the Fiscal Procedure Code (Law 207/2015), Art. 110, plus one additional buffer year. Deletion is performed by a recurring automated process that permanently removes the records and associated PDF documents.

10. Audit rights

10.1. The Controller may verify Quorify's compliance. Quorify provides the reasonable documentation needed. On justified request, an audit may be carried out with reasonable prior notice (at least 30 days), at most once per year, during business hours, without affecting other customers' security, at the Controller's cost, keeping the findings confidential.

11. International transfers

11.1. 230 data is hosted in the European Union. To the extent a sub-processor involves a transfer to a third country, it is carried out under the Standard Contractual Clauses (Implementing Decision (EU) 2021/914), incorporated by reference, supplemented by additional technical measures (encryption, pseudonymization, access control).

12. Governing law and jurisdiction

12.1. GDPR, Law 190/2018 and Romanian law. Jurisdiction: the competent Romanian courts.