Privacy Policy — Drelo.ai

    EDI & SAP Solutions SRL | Last updated: April 2026


    1. Introduction

    EDI & SAP Solutions SRL ("ESS", "we", "us", "our") operates Drelo.ai, an AI-powered AP and invoice automation platform. This Privacy Policy explains how we collect, use, store, and protect personal data in connection with Drelo.ai.

    As a company established in Romania, we process personal data under:

    Where other data protection laws apply to a specific relationship — for example the California Consumer Privacy Act (CCPA) or data protection laws in Asia-Pacific jurisdictions — we address the applicable requirements for that relationship rather than stating a general compliance position here.


    2. Data Controller

    EDI & SAP Solutions SRL
    Nicolae Titulescu 4, 500010 Brașov, Romania
    European Union
    Email: contact@edisapsolutions.com

    For GDPR purposes, ESS acts as:


    3. Data We Collect

    3.1 Website and Demo Request Data

    When you visit drelo.ai or submit a demo request, we collect:

    3.2 Client Account Data

    When an organization subscribes to Drelo.ai:

    3.3 Client Data (as Data Processor)

    As part of providing the Service, we process financial documents uploaded by Clients, which may contain:

    We process Client Data strictly as a Data Processor, acting on instructions from the Client (Data Controller).

    3.4 Technical Data


    4. Legal Basis for Processing (GDPR)

    Data TypeLegal Basis
    Demo request dataLegitimate interest / Pre-contractual measures
    Account dataContract performance
    Client Data (invoices, etc.)Contract performance / Data Processing Agreement
    Marketing communicationsConsent

    5. How We Use Your Data

    5.1 To Provide the Service

    5.2 To Communicate With You

    5.3 To Improve the Service

    5.4 To Comply With Legal Obligations


    6. Data Sharing and Third Parties

    We do not sell your personal data. We share data only with:

    6.1 Service Providers (Sub-processors)

    Sub-processorPurposeLocation
    SupabaseDatabase and authentication for the drelo.ai websiteConfirmed on request
    LovableWebsite hosting and content deliveryConfirmed on request
    ResendTransactional email for demo requestsConfirmed on request

    These are the providers used for the drelo.ai website and demo request handling. Providers involved in a specific Client deployment, and the processing locations that apply to it, are set out for that deployment rather than listed here. Sub-processors are engaged under data processing terms; we do not make a general statement about the protections a third party provides beyond those terms.

    6.2 ERP Systems

    Client Data is transmitted to the Client's ERP or target systems as directed by the Client. The Client is responsible for the lawfulness of this transmission.

    6.3 Legal Requirements

    We may disclose data if required by law, court order, or governmental authority, subject to applicable legal protections.


    7. Data Retention

    Data TypeRetention Period
    Demo request data24 months from submission
    Account dataDuration of contract + 5 years
    Client Data (invoices, etc.)Duration of contract + 30 days post-termination
    Support tickets3 years
    Server logs12 months

    Retention of any backup copies, and the arrangements for them, are agreed as part of the contract for a specific deployment. Clients may request earlier deletion of Client Data subject to legal retention requirements.


    8. International Data Transfers

    The Deployment Region field in our demo request form records a preference you tell us about. It is not a statement that a deployment exists in that region: where data is processed for a specific Client deployment is agreed in the contract for that deployment, together with the safeguards that apply.

    For the drelo.ai website and demo request handling, personal data is processed by the providers listed in Section 6.1. Where such processing involves a transfer outside the European Economic Area, it takes place on the basis of the transfer mechanism agreed with that provider, such as EU Standard Contractual Clauses.

    We do not state a hosting location, region or data residency guarantee on this page. If you need the processing locations documented — for a vendor assessment or a data processing agreement — request them and they will be confirmed in writing for your case.


    9. Cookies

    CookieTypePurposeDuration
    session_idEssentialAuthenticationSession
    csrf_tokenEssentialSecuritySession

    This website does not use advertising or analytics cookies and does not run third-party tracking scripts. You can control cookie preferences via your browser settings; disabling essential cookies may affect Service functionality.


    10. Your Rights

    10.1 GDPR Rights (EU/EEA Residents)

    You have the right to:

    10.2 CCPA Rights (California Residents)

    You have the right to:

    10.3 APAC Rights

    Residents of Singapore, Japan, and other APAC jurisdictions have rights under applicable local laws. We honor equivalent rights to access, correction, and deletion as required.

    10.4 How to Exercise Your Rights

    Submit requests to: contact@edisapsolutions.com
    Subject line: "Data Subject Request"

    We will respond within:

    We may require identity verification before processing requests.


    11. Data Security

    Our approach to security is described on the security and data handling page. In summary:

    We do not state encryption standards, certifications, penetration-test results or recovery objectives on this page. Those are answered in writing for a specific deployment as part of a security assessment, so that the answer is one your organisation can rely on. No system is completely secure, and we cannot guarantee absolute security of your data.


    12. Data Processing Agreement (DPA)

    For Clients subject to GDPR, ESS enters into a Data Processing Agreement as required by Article 28 GDPR. The DPA governs ESS's role as Data Processor for Client Data.

    To request a DPA: contact@edisapsolutions.com


    13. Children's Privacy

    Drelo.ai is a B2B enterprise platform intended for business use only. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected such data, we will delete it promptly.


    14. Changes to This Policy

    We may update this Privacy Policy periodically. Material changes will be communicated via:

    Changes take effect 30 days after notification. Continued use of the Service constitutes acceptance.


    15. Supervisory Authority

    If you are located in the EU and believe we have not addressed your concerns adequately, you have the right to lodge a complaint with your local data protection authority.

    Romanian supervisory authority:
    Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
    Website: www.dataprotection.ro
    Email: anspdcp@dataprotection.ro


    16. Contact

    EDI & SAP Solutions SRL
    Nicolae Titulescu 4, 500010 Brașov, Romania
    Email: contact@edisapsolutions.com
    Website: https://drelo.ai

    We aim to respond to all privacy inquiries within 5 business days.


    © 2026 EDI & SAP Solutions SRL — Drelo.ai is a product of ESS — Brașov, Romania 🇷🇴

    These documents are provided for informational purposes. For legally binding terms specific to your organization, please request a signed Order Form and Data Processing Agreement. This does not constitute legal advice.