CONTENTS
- 1. Who is responsible
- 2. Two different situations
- 3. The data we process, and why
- 4. Your data stays private
- 5. Our service providers
- 6. What the plugin sends to sdravobiz.com
- 7. Transfers outside the European Union
- 8. Your rights
- 9. Security
- 10. Your members’ data stays with you
- 11. Cookies
- 12. Minors
- 13. Complaints
- 14. Changes
- 15. Contact
This policy explains what personal data we process, why, for how long, and what your rights are. It applies to the fcextensions.com website, to the store and customer account operated on sdravobiz.com, and to the FC Extensions WordPress plugin.
It is written in accordance with Regulation (EU) 2016/679 (“GDPR”), Legea nr. 190/2018 and Legea nr. 506/2004.
1. Who is responsible
Sdravobiz S.R.L.
Strada Trandafirilor 51, 307220 Giroc, Romania
CUI: RO51472367, EU VAT number: RO51472369
Registrul Comerțului: J2025016522009
Email: contact@sdravobiz.com
Sdravobiz is not required to appoint a data protection officer under Article 37 of the GDPR: its activity does not involve large-scale processing of sensitive data or large-scale systematic monitoring of individuals.
Any request may be sent to contact@sdravobiz.com, with “GDPR” in the subject line.
2. Two different situations
This is the most important point of this policy, and it is also the main difference between FC Extensions and an online service.
Your own data, as a customer or visitor to our site. We are the controller of this data: account, order, invoice, license, support, newsletter. This is covered in articles 3 to 9.
The data of your community members. It is stored in the database of your WordPress site, on your hosting. It does not pass through any of our servers, is never sent to us and is not accessible to us. You are the sole controller of this data, and we are neither a controller nor a processor. This is covered in article 10.
3. The data we process, and why
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Orders, licenses and invoicing: account creation, performance of the contract, invoices, accounting obligations | Last name, first name, company, address, email, VAT number, order and invoice history, license key | Performance of a contract (Art. 6.1.b) and legal obligation (Art. 6.1.c) | Term of the contract, then 10 years under Legea nr. 82/1991 |
| Activation management: checking license validity, counting sites, delivering updates | License key, address of activated sites, product identifier, installed version, activation and check dates | Performance of a contract (Art. 6.1.b); legitimate interest in protection against unauthorized use (Art. 6.1.f) | Term of the license, then 3 years |
| Payments: collection, fraud prevention and disputes | Billing details, transaction history and identifiers | Performance of a contract (Art. 6.1.b); legitimate interest in fraud prevention (Art. 6.1.f) | 10 years (accounting obligations) |
| Service emails: confirmation, invoice, license key, update availability, renewal date, security incident | Name, email, account identifier | Performance of a contract (Art. 6.1.b) | Term of the contract, then legal archiving |
| Support and customer relations | Name, email, content of exchanges, screenshots and environment reports you send us | Performance of a contract (Art. 6.1.b); legitimate interest for prospects (Art. 6.1.f) | 3 years after the last exchange (customers); 13 months (prospects) |
| FC Extensions community: access to the help space, posts and replies | Display name, email, content of published messages | Performance of a contract (Art. 6.1.b); consent for publication (Art. 6.1.a) | Duration of participation, then 12 months |
| Newsletter and product information | Name, email, language, opens and clicks | Consent (Art. 6.1.a); legitimate interest for customers regarding a similar product | Until consent is withdrawn, and no later than 3 years after the last interaction |
| Site analytics | Anonymized IP address, pages viewed, duration, traffic source, device and browser | Consent (Art. 6.1.a) for non-essential cookies; legitimate interest for anonymized measurement | 14 months |
| Legal obligations and litigation | Invoices, supporting documents, connection data | Legal obligation (Art. 6.1.c); legitimate interest in defending legal claims | Applicable legal period |
We make no fully automated decisions that produce legal effects concerning you, and we do not carry out advertising profiling.
4. Your data stays private
Sdravobiz does not sell, rent or transfer your personal data to third parties for commercial purposes. It is used only for the purposes described in article 3.
Your data is shared only with the service providers listed in article 5, with the competent administrative or judicial authorities upon lawful request, and with our advisers in the event of legal proceedings.
5. Our service providers
We use processors within the meaning of Article 28 of the GDPR, selected for the guarantees they provide. This list may change.
| Provider | Role | Location | Transfer safeguards |
|---|---|---|---|
| Stripe Payments Europe, Ltd | Online payment, fraud prevention | Ireland (EU), group servers in the United States | Standard contractual clauses + EU-US Data Privacy Framework |
| o2switch | Hosting of the site, store, customer account and license server | France (EU) | No transfer outside the EU |
| Store, licenses and customer account (self-hosted) | Orders, license keys, activations, invoices | France (EU) | Not applicable, self-hosted |
| Contact management and emails (self-hosted) | Service emails, newsletter | France (EU) | Not applicable, self-hosted |
| Support and community (self-hosted) | Support tickets, user help space | France (EU) | Not applicable, self-hosted |
| Google Ireland Ltd (Analytics, Search Console) | Analytics and search performance tracking | Ireland (EU), servers in the United States | Standard contractual clauses + EU-US Data Privacy Framework |
| Chartered accountant and legal advisers | Accounting and legal obligations | Romania | Service agreement, confidentiality clause |
None of these providers has access to the data you collect with the plugin on your own site.
6. What the plugin sends to sdravobiz.com
The plugin installed on your site communicates with our license server in three situations: when you activate a key, when you deactivate it, and during periodic checks or update checks.
On each of these occasions, and only on these occasions, your site sends exactly the following:
- the product identifier;
- your license key;
- your site address;
- the version number of the installed plugin;
- a single-use random value (nonce), used to prevent the response from being replayed.
And nothing else. In particular, the following are never sent: your members’ data, their email addresses, their posts, their messages, their IP addresses, your statistics, your settings, your site content, your administrator email address, your PHP or WordPress version, or your list of plugins.
The plugin includes no telemetry, no usage statistics reporting and no notification on installation.
Emails sent by the extensions, such as the Account Deletion verification code, are sent from your server. They do not pass through any of the publisher’s servers.
7. Transfers outside the European Union
Our customer data is hosted in the European Union. The only transfers that may occur outside the European Economic Area involve our payment provider and our analytics tools, whose groups have infrastructure in the United States.
These transfers are covered by the safeguards of Chapter V of the GDPR: an adequacy decision where one exists (in particular the EU-US Data Privacy Framework) and standard contractual clauses adopted by the European Commission. A copy of these safeguards can be obtained on request at contact@sdravobiz.com.
The data you collect with the plugin is never transferred by us, since it never reaches us.
8. Your rights
You have the following rights (Articles 15 to 22 of the GDPR):
- access: to know whether we process data about you and to obtain a copy;
- rectification: to have inaccurate or incomplete data corrected;
- erasure: to have your data deleted, within the limits of our legal retention obligations;
- restriction: to temporarily restrict processing;
- portability: to receive your data in a structured, machine-readable format;
- objection: to object to processing based on legitimate interest, and unconditionally to direct marketing;
- withdrawal of consent at any time, without affecting the lawfulness of prior processing;
- post-mortem instructions on what happens to your data;
- complaint to a supervisory authority (article 13).
How to exercise them. By email to contact@sdravobiz.com (subject “GDPR”) or by post to our registered office. To prevent fraudulent disclosure, we may ask for proof of identity. We respond within one (1) month, which may be extended by two months depending on the complexity or number of requests (Article 12.3 of the GDPR).
If you are a member of a community that uses FC Extensions and wish to exercise your rights over that information, contact the operator of that community directly: they alone are the controller, and they alone hold this data. We have no access to it and therefore cannot provide it to you or erase it.
9. Security
We implement the appropriate technical and organizational measures required by Article 32 of the GDPR, including: encrypted connections (HTTPS/TLS), payments handled by a PCI-DSS Level 1 certified provider, strict access control and strong authentication for administrator accounts, access logging, regular backups, continuous security updates, and contractual confidentiality commitments with our processors.
Update packages served by our server are sealed and cryptographically signed, and your site verifies their signature before installation.
No system can guarantee absolute security. In the event of a data breach likely to pose a risk to your rights and freedoms, we notify the ANSPDCP within seventy-two (72) hours and inform you directly when the risk is high (Articles 33 and 34 of the GDPR).
10. Your members’ data stays with you
This article is addressed to you, the customer, regarding the members of your community.
10.1 You are the sole controller
Your community’s data is stored in your own WordPress database, on your hosting, by Fluent Community and by the plugin. We do not receive it, host it or view it, and we cannot restore it.
You alone determine the purposes and means of processing. It is your responsibility to inform your members, define your legal bases and retention periods, publish your own privacy policy and respond to their requests.
10.2 What the plugin stores on your site
The extensions rely on the data Fluent Community already manages: profiles, spaces, posts, comments and messages. FC Extensions adds the following to your WordPress database:
- the settings of FC Extensions and of each extension turned on;
- the count of deleted accounts;
- the temporary verification code emailed to a member who deletes their account, valid for fifteen (15) minutes;
- the anonymous profile that holds the content of deleted members, under the name you choose.
When a member deletes their account with the Account Deletion extension, their profile, photo, cover image, subscriptions, notifications and progress are erased, along with their FluentCRM contact and their WordPress account. Their posts, comments, reactions and messages remain in the community, under the anonymous profile. Their FluentCart orders are kept, detached from the account.
10.3 What you need to do
- Describe in your privacy policy your community’s data, its purposes, legal bases and retention periods.
- Inform your members of what happens to their account when they delete it: content kept under an anonymous profile, profile and account erased.
- Check what the other services you use on your site do with your members’ data.
10.4 The only case where the publisher sees your data
If, for support purposes, you send us a screenshot, an export or access to your site, we may be exposed to your members’ data. In that case we act as a processor, on your instructions and solely for the purposes of support.
We recommend that you anonymize your screenshots before sending them to us.
11. Cookies
11.1 On our site
| Category | Tool | Purpose | Duration | Legal basis |
|---|---|---|---|---|
| Strictly necessary | WordPress session (wordpress_*) | Customer account login, security | Session / 30 days | Legitimate interest, no consent required |
| Strictly necessary | Cart and checkout | Keep the current order | Session | Legitimate interest, no consent required |
| Strictly necessary | Language preference (pll_language) | Display language | 12 months | Legitimate interest, no consent required |
| Analytics | Google Analytics (_ga, _ga_*) | Anonymized statistics | 13 months | Consent |
| Functional / marketing | Email tracking (fcrm_*) | Opens and clicks on our emails | 12 months | Consent |
On your first visit, a banner managed by the CookieAdmin tool lets you accept, refuse or customize cookies that are not strictly necessary. You can change your preferences at any time. The site and its content remain accessible whatever you choose.
11.2 On our customers’ sites
FC Extensions sets no cookies in the browsers of your site’s visitors and members. Their login relies on the usual WordPress and Fluent Community cookies, set by your site, under your domain name.
12. Minors
Our site and our product are not intended for minors under sixteen (16) years of age. We do not knowingly collect their data without the consent of the holder of parental responsibility (Article 8 of the GDPR). If we discover such data, we delete it without delay.
If your community is aimed at minors, it is your responsibility, as controller, to implement the required age verification and parental consent measures.
13. Complaints
If you believe that the processing of your data does not comply with the rules, you can lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București, 010336, Romania
https://www.dataprotection.ro
anspdcp@dataprotection.ro, +40 318 059 211
If you live in another Member State, you can also contact your national authority (CNIL in France, AEPD in Spain, Garante in Italy, CNPD in Portugal, BfDI in Germany, etc.).
14. Changes
We may update this policy to reflect legal, regulatory, technical or contractual changes. The applicable version is the one published on the date you consult it. In the event of a substantial change, we will inform you through a banner on the site, or by email if you are a customer.
15. Contact
Sdravobiz S.R.L.
Strada Trandafirilor 51
307220 Giroc, Romania
contact@sdravobiz.com (legal and GDPR)
contact@sdravobiz.com (service and support)
https://fcextensions.com
Last updated: October 10, 2026