Skip to content

Legal Agreement

Data Processing Agreement

Version 1 · Last updated: 11 September 2026

Translation for convenience

This English text is provided to help you understand the document. The Romanian version is the legally binding one; in the event of any discrepancy between the two, the Romanian text prevails.

This Data Processing Agreement (“DPA”) supplements the ToolFlux Terms and Conditions and applies where, by using the ToolFlux application and console, you entrust us with personal data about your employees or contractors (e.g. names, signatures, equipment assignments). You accept it by ticking the corresponding box when activating your company account — this constitutes a contract within the meaning of art. 28 of Regulation (EU) 2016/679 (“GDPR”).

1. Parties and roles

For the purposes of the GDPR: you (the customer company) are the Controller of your employees'/contractors' data entered into ToolFlux. ToolFlux (MORNINGSTAR SOFTWARE S.R.L., tax code (CUI) 55437739) acts as Processor and processes this data exclusively on your behalf, in order to provide the service.

2. Subject matter, duration and nature of processing

  • Subject matter: hosting and operating the ToolFlux platform (mobile app + web console) for equipment management.
  • Duration: for the whole term of the active subscription, plus the post-termination retention period described in §7.
  • Nature: storage, structuring, consultation, modification and deletion, performed automatically through the platform.

3. Categories of data and data subjects

  • Data subjects: employees, contractors and users of your company with access to ToolFlux.
  • Data processed: name, e-mail, role, digital signature (handover reports), assignment/activity history, photographs of equipment associated with their actions.
  • We do not intentionally process special categories of data (art. 9 GDPR).

4. ToolFlux's obligations as processor

We undertake to:

  • process the data only on your documented instructions (the configuration and normal use of the platform);
  • ensure confidentiality — persons authorised to access the data are bound by confidentiality obligations;
  • implement appropriate technical and organisational measures (art. 32): encryption in transit and at rest, role-based access control, per-company data isolation;
  • notify you without undue delay of any personal data breach we become aware of, providing the information you need for your own notification obligations;
  • assist you, to a reasonable extent, in responding to data subject requests (access, rectification, erasure) and with impact assessments, where required;
  • on termination of the contract, delete or return the data, in accordance with §7;
  • make available the information needed to demonstrate compliance and allow reasonable audits, on prior notice.

5. Sub-processors

We use the following sub-processors to provide the service, each under contractual obligations equivalent to those in this DPA:

Sub-processorServiceData location
Google Ireland Ltd. (Firebase / Google Cloud)Database, authentication, file storage, hosting, server functionseurope-west4 (Netherlands)

The website's digital assistant and our contact-form notifications use further suppliers (Google Gemini, Zoho). Those do not process your employees' data and are therefore outside this DPA; they are described in our Privacy Policy, which covers visitors to the website.

You grant us general authorisation to use additional sub-processors, provided we inform you in advance of any change and give you the opportunity to object.

6. International transfers

Your employees' data is stored and processed in the European Union. The database and every server function that acts on it are in europe-west4 (Netherlands). The functions moved into that region on 10 September 2026; before that date they ran in the United States, under the safeguards named below.

Any transfer outside the EEA, should it become necessary, will be made only on the basis of the safeguards provided by the GDPR (e.g. standard contractual clauses approved by the European Commission).

7. Deletion and return of data

On termination of the subscription, the company's data remains available for export for «e.g. 30 days», after which it is permanently deleted from active systems, unless the law requires us to retain it for longer.

8. Liability

Each party is liable under the GDPR for its own breaches of the obligations undertaken through this Agreement and through the ToolFlux Terms and Conditions.

9. Acceptance

This DPA is deemed accepted when the company administrator ticks the agreement box during initial account setup. The date and version of acceptance are recorded in the system. Continued use of the platform after a notified update to this document constitutes acceptance of the new version.

10. Contact

For any request relating to this Agreement: support@toolfluxapp.com. See also our Privacy Policy and Terms and Conditions.