Skip to content

Privacy policy

What data we process, why, and for how long

Updated on August 5, 2026

This policy explains what personal data we process through the Dexter platform, and in what capacity we do so.

Two different roles

The distinction matters, because it decides who is responsible for what:

  • For your account data (name, email, phone, billing details) we are the controller. We decide why we keep it and for how long.
  • For the contacts you upload and send messages to, we are a processor. You are the controller: you decide who goes on the list and why, and we only carry out the sending on your instruction.

What data we process

  • Account data: name, email address, password stored as a cryptographic hash, phone number.
  • Billing data: company name, address, tax code, order and invoice history.
  • Usage data: messages sent, sending time, delivery status, IP address at sign-in.
  • Your contacts: the phone numbers and fields you upload for message personalisation.

Why we process it

To perform the contract (providing the service and invoicing), to meet legal obligations (accounting records, invoice retention), and on the basis of our legitimate interest in preventing abuse and keeping the platform secure.

How long we keep it

  • Account data: for the life of the account and 30 days after it is closed.
  • Invoices and accounting documents: 10 years, as required by law.
  • Message history: 12 months, then anonymised.
  • Your contacts: until you delete them or the account is closed.

Who we share it with

Data reaches only the providers needed to run the service: the mobile operator that delivers the message, the payment processor, the electronic invoicing provider and the hosting provider. We do not sell data and we do not use it for advertising.

Your rights

You have the right of access, rectification, erasure, restriction, portability and objection. Exercise them by writing to contact@bdcdesign.ro. We respond within 30 days at most. You may also contact ANSPDCP, the Romanian data protection authority.

Security

Traffic is encrypted in transit, passwords are stored as cryptographic hashes, and provider keys and credentials are encrypted in the database. Internal access is limited to what is strictly necessary.