Privacy Policy — Drelo.ai
EDI & SAP Solutions SRL | Last updated: April 2026
1. Introduction
EDI & SAP Solutions SRL ("ESS", "we", "us", "our") operates Drelo.ai, an AI-powered AP and invoice automation platform. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with Drelo.ai.
As a company established in Romania, we process personal data under:
- EU General Data Protection Regulation (GDPR)
- Romanian data protection law
Where other data protection laws apply to a specific relationship — for example the California Consumer Privacy Act (CCPA) or data protection laws in Asia-Pacific jurisdictions — we address the applicable requirements for that relationship rather than stating a general compliance position here.
2. Data Controller
EDI & SAP Solutions SRL
Nicolae Titulescu 4, 500010 Brașov, Romania
European Union
Email: contact@edisapsolutions.com
For GDPR purposes, ESS acts as:
- Data Controller for personal data of website visitors and demo requesters
- Data Processor for personal data contained within Client Data (invoices, vendor records, etc.)
3. Data We Collect
3.1 Website and Demo Request Data
When you visit drelo.ai or submit a demo request, we collect:
- Name and surname
- Business email address
- Phone number (optional)
- Company name
- ERP system type
- Invoice volume range
- Deployment region preference
- Message content
- IP address and browser information
3.2 Client Account Data
When an organization subscribes to Drelo.ai:
- Account administrator contact details
- Billing information (processed by payment provider)
- Support ticket contents
- Usage logs and access records
3.3 Client Data (as Data Processor)
As part of providing the Service, we process financial documents uploaded by Clients, which may contain:
- Invoice numbers, dates, and amounts
- Vendor names and addresses
- Purchase order references
- General ledger codes
- Employee names (on expense-related documents)
- Bank account details (on payment documents)
We process Client Data strictly as a Data Processor, acting on instructions from the Client (Data Controller).
3.4 Technical Data
- Server access logs
- API usage data
- Performance metrics
- Essential cookie data (see Section 9)
4. Legal Basis for Processing (GDPR)
| Data Type | Legal Basis |
|---|---|
| Demo request data | Legitimate interest / Pre-contractual measures |
| Account data | Contract performance |
| Client Data (invoices, etc.) | Contract performance / Data Processing Agreement |
| Marketing communications | Consent |
5. How We Use Your Data
5.1 To Provide the Service
- Process and extract invoice data
- Facilitate ERP integrations
- Manage approval workflows
- Provide support via Essix.ai
5.2 To Communicate With You
- Respond to demo requests
- Send service updates and notifications
- Provide support and onboarding assistance
5.3 To Improve the Service
- Analyze usage patterns (anonymized data only)
- Fix bugs and improve performance
- Improve AI models (using anonymized data only — never Client Data without explicit consent)
5.4 To Comply With Legal Obligations
- Maintain records as required by Romanian and EU law
- Respond to lawful requests from authorities
6. Data Sharing and Third Parties
We do not sell your personal data. We share data only with:
6.1 Service Providers (Sub-processors)
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication for the drelo.ai website | Confirmed on request |
| Lovable | Website hosting and content delivery | Confirmed on request |
| Resend | Transactional email for demo requests | Confirmed on request |
These are the providers used for the drelo.ai website and demo request handling. Providers involved in a specific Client deployment, and the processing locations that apply to it, are set out for that deployment rather than listed here. Sub-processors are engaged under data processing terms; we do not make a general statement about the protections a third party provides beyond those terms.
6.2 ERP Systems
Client Data is transmitted to the Client's ERP or target systems as directed by the Client. The Client is responsible for the lawfulness of this transmission.
6.3 Legal Requirements
We may disclose data if required by law, court order, or governmental authority, subject to applicable legal protections.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Demo request data | 24 months from submission |
| Account data | Duration of contract + 5 years |
| Client Data (invoices, etc.) | Duration of contract + 30 days post-termination |
| Support tickets | 3 years |
| Server logs | 12 months |
Retention of any backup copies, and the arrangements for them, are agreed as part of the contract for a specific deployment. Clients may request earlier deletion of Client Data subject to legal retention requirements.
8. International Data Transfers
The Deployment Region field in our demo request form records a preference you tell us about. It is not a statement that a deployment exists in that region: where data is processed for a specific Client deployment is agreed in the contract for that deployment, together with the safeguards that apply.
For the drelo.ai website and demo request handling, personal data is processed by the providers listed in Section 6.1. Where such processing involves a transfer outside the European Economic Area, it takes place on the basis of the transfer mechanism agreed with that provider, such as EU Standard Contractual Clauses.
We do not state a hosting location, region or data residency guarantee on this page. If you need the processing locations documented — for a vendor assessment or a data processing agreement — request them and they will be confirmed in writing for your case.
9. Cookies
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| session_id | Essential | Authentication | Session |
| csrf_token | Essential | Security | Session |
This website does not use advertising or analytics cookies and does not run third-party tracking scripts. You can control cookie preferences via your browser settings; disabling essential cookies may affect Service functionality.
10. Your Rights
10.1 GDPR Rights (EU/EEA Residents)
You have the right to:
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion ("right to be forgotten")
- Restriction — limit how we process your data
- Portability — receive your data in a portable format
- Object — object to processing based on legitimate interest
- Withdraw Consent — at any time, where processing is based on consent
10.2 CCPA Rights (California Residents)
You have the right to:
- Know what personal information is collected
- Know whether personal information is sold or disclosed
- Opt out of the sale of personal information (we do not sell data)
- Request deletion of personal information
- Non-discrimination for exercising your rights
10.3 APAC Rights
Residents of Singapore, Japan, and other APAC jurisdictions have rights under applicable local laws. We honor equivalent rights to access, correction, and deletion as required.
10.4 How to Exercise Your Rights
Submit requests to: contact@edisapsolutions.com
Subject line: "Data Subject Request"
We will respond within:
- 30 days for GDPR requests (extendable to 90 days for complex requests)
- 45 days for CCPA requests
- As required by applicable APAC law
We may require identity verification before processing requests.
11. Data Security
Our approach to security is described on the security and data handling page. In summary:
- Access control: access is granted by role and scoped to what the process requires
- Traceability: processing steps, decisions and exception resolutions are recorded
- Separated environments: development, test and production are kept apart
- Transport protection: the drelo.ai website and its forms are served over HTTPS
- Data minimisation: we process the data the invoice process and our communication with you require
- Incident handling: notification obligations are set out in the contract and data processing agreement for a deployment
We do not state encryption standards, certifications, penetration-test results or recovery objectives on this page. Those are answered in writing for a specific deployment as part of a security assessment, so that the answer is one your organisation can rely on. No system is completely secure, and we cannot guarantee absolute security of your data.
12. Data Processing Agreement (DPA)
For Clients subject to GDPR, ESS enters into a Data Processing Agreement as required by Article 28 GDPR. The DPA governs ESS's role as Data Processor for Client Data.
To request a DPA: contact@edisapsolutions.com
13. Children's Privacy
Drelo.ai is a B2B enterprise platform intended for business use only. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected such data, we will delete it promptly.
14. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via:
- Email notification to registered account holders
- Prominent notice on the Drelo.ai website
Changes take effect 30 days after notification. Continued use of the Service constitutes acceptance.
15. Supervisory Authority
If you are located in the EU and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority.
Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Website: www.dataprotection.ro
Email: anspdcp@dataprotection.ro
16. Contact
EDI & SAP Solutions SRL
Nicolae Titulescu 4, 500010 Brașov, Romania
Email: contact@edisapsolutions.com
Website: https://drelo.ai
We aim to respond to all privacy inquiries within 5 business days.
© 2026 EDI & SAP Solutions SRL — Drelo.ai is a product of ESS — Brașov, Romania 🇷🇴
These documents are provided for informational purposes. For legally binding terms specific to your organization, please request a signed Order Form and Data Processing Agreement. This does not constitute legal advice.