Skip to content
EVOrange
Stations Charging Pricing App Partners
Sign in
  • Română RO
  • English EN
Open the map Map

Primary navigation

01 Stations 02 Charging 03 Pricing 04 App 05 Partners Have suitable land or a location? We can build it together.
Open the map Sign in Create account
Română English

Last updated: 17 August 2026

Protection of personal data

This explains what we collect, why, who receives it, how long we keep it and what you can ask of us. It is written to be read, not to be ticked.

Contents
  • 01 1. Who processes the data
  • 02 2. What we collect
  • 03 3. Purposes and legal bases
  • 04 4. Who we share it with
  • 05 5. Transfers outside the European Economic Area
  • 06 6. Security
  • 07 7. Your rights
  • 08 8. How to exercise your rights
  • 09 9. Complaining to the supervisory authority
  • 10 10. Automated decisions and profiling
  • 11 11. Children
  • 12 12. Changes to this document
  • 13 13. Where data comes from
  • 14 14. Station data and OCPP
  • 15 15. Payments and Stripe
  • 16 16. Invoices, accounting and RO e-Factura
  • 17 17. First-party measurement and consent
  • 18 18. Support, internal access and temporary links
  • 19 19. How retention periods are applied

Contents

  • 01 1. Who processes the data
  • 02 2. What we collect
  • 03 3. Purposes and legal bases
  • 04 4. Who we share it with
  • 05 5. Transfers outside the European Economic Area
  • 06 6. Security
  • 07 7. Your rights
  • 08 8. How to exercise your rights
  • 09 9. Complaining to the supervisory authority
  • 10 10. Automated decisions and profiling
  • 11 11. Children
  • 12 12. Changes to this document
  • 13 13. Where data comes from
  • 14 14. Station data and OCPP
  • 15 15. Payments and Stripe
  • 16 16. Invoices, accounting and RO e-Factura
  • 17 17. First-party measurement and consent
  • 18 18. Support, internal access and temporary links
  • 19 19. How retention periods are applied

1. Who processes the data

The data controller must be the legal entity identified on the Legal details page. A field marked incomplete means the controller disclosure is not complete and must not be read as an operator identity. Use the address below for a privacy request; the missing legal details remain a launch requirement, not information supplied by this text.

Company name to be completed
Registered office RO
Requests about personal data [email protected]

2. What we collect

We collect only what the function you use needs. Not every category below applies before launch: charging, payment and billing data arise only if the corresponding service is enabled and used.

  • Identification and contact details — name, email address, phone number, town, and for business customers the company name and tax details.
  • Account data — the password stored as a hash, preferred language, communication preferences and sign-in history.
  • Session data — the station and location used, start and end time, energy delivered and cost.
  • Payment data — card type, the last four digits and the transaction identifier from the payment processor. The full card number never reaches us.
  • Billing data — billing address, invoice series and number, amounts and payment method.
  • Correspondence with us — messages sent through the form, tickets and notes from phone conversations.
  • Partnership enquiries — contact and organisation details, information about a site, fleet or network, stated goals and the commercial qualification history.
  • Applications — the CV and the details from the careers form, plus notes from the recruitment process.
  • Technical data — IP address, browser type, pages visited and cookie identifiers.
  • Station protocol data — station and connector identifiers, statuses, timestamps, meter values, session events and the pseudonymous technical identifier needed for OCPP authorisation.
  • Security and audit data — logins, IP addresses, administrative actions, webhook statuses, errors and technical identifiers redacted under the applicable retention rules.
  • Fiscal data — the buyer identity, address and supplied tax identifiers, invoice lines, corrections and transmission references for applicable fiscal systems.

3. Purposes and legal bases

Every processing operation has a purpose and a legal basis from art. 6(1) of Regulation (EU) 2016/679 (GDPR). We do not use the data for anything not written below.

Purpose Legal basis Retention period
Creating and running your account Performance of the contract — art. 6(1)(b) GDPR For as long as the account exists, plus 3 years after it closes, the general limitation period
Providing the charging service and managing sessions Performance of the contract — art. 6(1)(b) GDPR For the duration of the contract, plus 3 years
Issuing invoices and keeping accounting records Legal obligation — art. 6(1)(c) GDPR, Accounting Law no. 82/1991 and the Fiscal Code The statutory accounting period, generally 5 years calculated from 1 July of the year following the relevant financial year, or longer where another rule requires it
Taking payment, refunds and fraud prevention Performance of the contract and legitimate interest — art. 6(1)(b) and (f) GDPR For the duration of the contract, plus 3 years
Answering messages, tickets and complaints Performance of the contract, or our legitimate interest in answering people who write to us — art. 6(1)(b) and (f) GDPR 3 years from closing the ticket
Assessing and managing a partnership enquiry or proposed charging site Pre-contractual steps at your request — art. 6(1)(b) GDPR; legitimate interest in organising and defending commercial correspondence — art. 6(1)(f), where applicable While the enquiry is active and throughout the contractual relationship; after rejection, withdrawal or contract end, a default of 2 years, configurable only within the approved policy. An explicit legal hold suspends redaction until it is released
Recording your marketing choice and, only if the communication channel is activated, sending the messages you agreed to receive Consent — art. 6(1)(a) GDPR Until consent is withdrawn
Assessing applications received through the careers page Pre-contractual steps at your request — art. 6(1)(b) GDPR; for keeping a CV on file for future roles, consent — art. 6(1)(a) 6 months after the process ends, or 2 years if you agreed to be considered for future roles
Platform security, technical logs, filtering automated messages Legitimate interest — art. 6(1)(f) GDPR 12 months
Recording cookie choices, first-party performance measurement when accepted, and any later functional or marketing integration only after the relevant consent Consent — art. 6(1)(a) GDPR and art. 4(5) of Law no. 506/2004 See the duration of each category in the cookie policy
Station communication, technical authorisation and reconciliation of charging events Performance of the contract and legitimate interest in network integrity — art. 6(1)(b) and (f) GDPR Raw protocol logs currently default to 30 days, or 7 days for rejected connections; the commercial session record follows its applicable contractual period
Accounting records, fiscal documents and transmission through RO e-Factura where applicable Legal obligation — art. 6(1)(c) GDPR and applicable tax and accounting law The statutory period for the fiscal document, including any extension required by an audit or dispute
Fraud prevention, incident review and protection of payments and infrastructure Legitimate interest — art. 6(1)(f) GDPR; legal obligation where a specific rule requires it According to log type and risk; technical security identifiers are currently redacted after no more than 365 days unless there is an incident or legal hold
Carrying out a closure request, separating erasable data from records that must be kept and preventing unauthorised reactivation Performance of contract, legal obligation and legitimate interest — art. 6(1)(b), (c) and (f) GDPR, depending on the record Eligible data is erased or anonymised; the rest follows the applicable fiscal, limitation, security or legal-hold period

4. Who we share it with

We do not sell personal data. Depending on the function you use and the suppliers configured for this network, data may be disclosed only where needed for the purposes described below and under the applicable data-protection terms.

  • The payment processor, for charges, pre-authorisations and refunds.
  • The transactional email provider, so that confirmations and invoices reach you.
  • The hosting and infrastructure provider, on whose servers the platform runs.
  • Our accountant and, where applicable, our auditor, for invoices and reporting.
  • The external map-tile provider receives ordinary request data, such as IP address and browser headers, when your browser opens the station map.
  • Public authorities, only where the law obliges us and only within the limits of their request.
  • Stripe, when it is the configured payment processor; for some activities Stripe may act as a separate controller under its own notice and the service used.
  • ANAF and the RO e-Factura infrastructure where issuing or transmitting the document falls within the applicable legal duty.
  • Authorised technical-maintenance or support suppliers, only with the access required for the intervention and appropriate confidentiality and data-protection duties.
  • The configured AI provider, only when an operator explicitly requests a summary and reply suggestion. Before disclosure we remove identity fields, evident contact details and internal notes, and limit the conversation to the necessary public messages.

5. Transfers outside the European Economic Area

The configured hosting location is identified on the legal-details page once completed. A configured supplier may process data outside the European Economic Area; where Chapter V GDPR requires a transfer mechanism, we use an applicable adequacy decision or contractual safeguards and provide information about them on request.

6. Security

Measures used by the platform include TLS for production traffic, one-way password hashing, restricted internal access and encryption for fields configured as sensitive. No measure removes every risk. We assess any personal-data breach and notify the supervisory authority within the applicable period, including the 72-hour GDPR period where required; affected people are informed when the legal threshold is met.

  • Traffic protected by TLS in production and session cookies configured as secure and HTTP-only, with application-level encryption enabled by default.
  • Passwords retained only as hashes and sensitive fields encrypted where the data model marks them as such.
  • Role-based internal access, authorisation for administrative actions and audit trails for sensitive operations.
  • Temporary access tokens expire, and values that can be checked through a hash are not retained in plain text.
  • Logs have bounded periods, with technical identifiers redacted and separate preservation only for incidents, duties or disputes.
  • Backups, incident response and restoration are managed through operational measures whose security must be reviewed periodically.

7. Your rights

The GDPR gives you the rights below, subject to the conditions and exceptions in the Regulation. Requests are generally free of charge.

  • The right of access — to know whether we process data about you and to receive a copy of it, together with the purposes and the recipients (art. 15).
  • The right to rectification — to have inaccurate or incomplete data corrected or completed (art. 16).
  • The right to erasure — to have data deleted once we no longer have a lawful reason to keep it (art. 17).
  • The right to restriction of processing — to have it paused while we verify a challenge (art. 18).
  • The right to data portability — to receive your data in a structured, commonly used, machine-readable format, or to have it sent to another controller (art. 20).
  • The right to object — to processing based on our legitimate interest, and at any time and without reason to direct marketing (art. 21).
  • The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significant ones (art. 22).
  • The right to lodge a complaint with the supervisory authority and to go to court (art. 77-79).

Where processing is based on consent, you can withdraw it at any time, as easily as you gave it. Withdrawal does not affect the lawfulness of processing carried out before it, per art. 7(3) GDPR.

8. How to exercise your rights

Write to [email protected] or use the contact form. We answer within one month of receiving the request; if it is complex we may extend by two months and will tell you why. There is no charge, except for manifestly unfounded or excessive requests. So that we do not hand your data to somebody else, we may ask for further information to identify you.

9. Complaining to the supervisory authority

If our answer does not satisfy you, you have the right to lodge a complaint with the Romanian supervisory authority.

Company name National Supervisory Authority for Personal Data Processing
Address B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest
Email [email protected]
Website dataprotection.ro

10. Automated decisions and profiling

Form-security filters may quarantine a submission for review, and a configured payment processor may run automated fraud checks that accept or refuse a transaction. These operational checks are not intended to make solely automated decisions with legal or similarly significant effects about you. Contact us if you believe a legitimate message or transaction was incorrectly blocked so the case can be reviewed.

Depending on the service used, Stripe may separately determine its own anti-fraud rules as an independent controller. You can consult the Stripe notice and ask us to review elements under our control. Quarantined messages and disputed requests can be reviewed by an authorised person; the platform does not present an automated classification as a human decision. An AI assistant may prepare a summary, classification and reply draft for an operator, but it does not send it, change the ticket status or make decisions about the request.

11. Children

Accounts and future paid charging services are intended for people over 18. If you believe a minor has submitted personal data, write to us so we can assess and erase it where there is no lawful reason to retain it.

12. Changes to this document

When we change this document we publish a new effective date. A material change is highlighted on the site and communicated directly where the law requires direct notice or renewed consent.

13. Where data comes from

Most data comes directly from you. Other data arises only when you use a function, equipment sends an event or a supplier returns the status of an operation.

  • From you: account, profile, billing, consents, forms, tickets and documents you choose to send.
  • From your device and browser: web requests, IP address, browser type and, only after the relevant choice, the first-party performance identifier.
  • From the station through OCPP: statuses, events, measurements and technical identifiers linked to the session.
  • From Stripe and communication suppliers: payment status, identifiers, delivery confirmations and operational errors, not extra content without a declared purpose.
  • From authorities, location partners or legitimate public sources only where needed for a duty, an investigation or verification of a specific request.

14. Station data and OCPP

OCPP allows the platform and station to coordinate authorisation, status and metering. We do not turn the technical identifier into a separate customer product.

  • We record the station, connector, transaction, statuses, timestamps, meter values and technical reasons needed for diagnosis.
  • Internal authorisation may use a temporary, pseudonymous idTag. It is not presented as a physical customer credential and must not be used as a public identifier.
  • The platform does not receive continuous vehicle GPS location through this flow; the location is that of the selected station.
  • Raw protocol logs default to 30 days and rejected connections to 7 days. An incident, duty or legal hold may justify isolating a copy for longer.
  • The commercial session summary is kept separately for as long as needed for the contract, payment, fiscal document and applicable claims.

15. Payments and Stripe

When Stripe is configured, its secure payment form sends card data directly to Stripe. The application does not receive or store the full card number or CVC.

  • We retain Stripe identifiers, authorisation and collection status, amount, currency, brand and last four digits, as well as relevant refunds and disputes.
  • Stripe may act as a processor for processing requested by the operator and may be a separate controller for its own duties, security and fraud prevention; the role depends on the particular service and activity.
  • Webhook messages are authenticated and used for reconciliation. The current operational setting redacts a resolved webhook body after 14 days and removes its envelope after 45 days.
  • An unresolved webhook, incident, dispute or legal hold may require controlled retention for longer.
  • Never send a complete card number, CVC or bank-authentication password through support.

16. Invoices, accounting and RO e-Factura

Fiscal data is handled separately from marketing preferences and account closure. The particular duty depends on customer type, document and the rules in force when it is issued.

  • The invoice includes buyer details supplied and validated for the transaction, lines, tax, payment and the link to any correction.
  • Documents enter the accounting record and are transmitted through RO e-Factura where the law requires this of the operator.
  • An individual consumer is not required for this reason alone to hold a Romanian Private Virtual Space account; delivery of the invoice to the customer follows the applicable channel.
  • An erasure request or account closure does not remove documents that tax or accounting law requires us to keep.
  • A correction uses the appropriate fiscal document and retains its link to the original document.

17. First-party measurement and consent

Detailed journey analytics is optional. The cookie-panel choice controls whether the platform may link visits through a random first-party identifier.

  • Without performance consent we do not set evo_vid or build an individual journey; we keep only an aggregated daily total without a visitor identifier.
  • With consent we may record the random identifier, page, referrer, campaign and coarse technical information needed for our own statistics.
  • evo_vid may last up to 2 years with renewal on use, while detailed first-party records are currently removed after 14 months.
  • Withdrawal stops linking new visits and requests expiry of the identifier on the next response. It does not retrospectively make earlier processing unlawful.
  • You may request access or erasure for earlier identifiable data; you need to provide the information reasonably needed to find the correct identifier.

18. Support, internal access and temporary links

Tickets may bring together account, session and payment context so the problem can be understood. Access must be limited to the people and data needed for resolution.

  • We retain the message, necessary attachments, status, assignee, history and links to the relevant session or payment.
  • The current operational period for a closed ticket is 3 years; a complaint, dispute or legal hold may require a different period.
  • Temporary access links use expiring tokens, and the checkable value is held as a hash rather than a reusable plain-text secret.
  • Roles limit staff access, and sensitive administrative actions can be audited.
  • If the operator requests AI assistance, we send the configured provider only the necessary public messages after redacting evident identity and contact details; internal notes are excluded. The resulting draft is encrypted in the internal record, becomes stale when the conversation changes and can enter the editor only after a separate human action.
  • Do not use a ticket for passwords, CVC, complete card numbers or information about other people that is unnecessary for the case.

19. How retention periods are applied

The periods in the table and special sections apply by category, not as one deletion date for the whole account.

  • We apply the shortest period compatible with the purpose, except for a legal duty, limitation period, incident or documented legal hold.
  • At expiry, data is erased, anonymised or redacted so personal identifiers are no longer operationally available.
  • Account closure starts separating eligible data from fiscal documents, payments, incidents and tickets that have their own period.
  • Backups follow their controlled lifecycle and are not used as an active archive; deleted data reappears only where restoration requires the operation to be reapplied.
  • Aggregated statistics that no longer allow a person to be identified may be retained outside GDPR rules for personal data.
  • You may ask for the period and criterion applying to a specific record; the answer takes account of the transaction, document and any active duty.

Related documents

  • Terms and Conditions
  • Cookie policy
  • Legal details

If anything is unclear, write to us through the contact form. We will acknowledge the request and reply as soon as we can, subject to any statutory deadline that applies.

Charge simply, wherever the road takes you. The map shows the station, power and price before you start.
EVOrange

Încărcare care pur și simplu merge.

Charge
Stations Charging Pricing App Partners
Company
About Contact Careers
Information
Terms and conditions Privacy Cookie policy Legal information
Submit a complaint to A.N.P.C. ANPC — Alternative Dispute Resolution

You can request alternative dispute resolution directly through the official ANPC platform.

© 2026 EVOrange
Sign in Create account Sitemap
Language and region Română English

You choose which cookies we use

We use strictly necessary storage to run the site and remember this choice. We ask before setting any non-essential analytics, functional or marketing identifier.

Legal basis: art. 6 of Regulation (EU) 2016/679 (GDPR) and art. 4(5) of Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.

Cookie preferences

You can turn each category on separately. A saved choice applies immediately and remains until you change it, it expires or the policy version changes.

  • Strictly necessary Always on

    These make the site work: your session, form protection and the record of this choice. Without them sign-in and protected forms cannot work reliably.

    These cannot be switched off, because without them the service you asked for cannot be delivered.

  • These show us which pages get read, where visitors come from, and where people get stuck. The statistics are ours, hosted by us, and sold to nobody.

    If you refuse, we still count visits in aggregate, but with no identifier on your device and without linking two pages to the same person.

  • This category is reserved for optional interface preferences, such as a saved map view or filters, if those features are introduced.

    No optional functional identifier is currently activated by this choice.

  • This category is reserved for advertising measurement if a campaign integration is introduced later.

    No advertising code is currently loaded, regardless of this preference. The notice will be updated before that changes.

How long we keep data. The analytics identifier cookie lasts 2 years. Detailed statistics are deleted automatically after 14 months.

How to withdraw consent. Open “Cookie settings” from any page and switch the category off. The server expires the analytics identifier on your next request.

You have the right of access, rectification, erasure, restriction and objection. Write to us at [email protected], or lodge a complaint with ANSPDCP.

Legal basis: art. 6 of Regulation (EU) 2016/679 (GDPR) and art. 4(5) of Romanian Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector.