Terms
Terms of Service
Effective date: October 2, 2026 · Version: 1.0
These terms cover your use of selfoia.com and our free check. Paid work is covered by our Service Terms. How we handle personal data is explained in our Privacy Policy.
1. Who we are
1.1. The website selfoia.com is run by SELFOIA S.R.L., a limited liability company registered in Romania:
- Registered office: Strada Gladiolelor 2, 040144 Bucharest, Romania
- Trade Register number: J2025075767005
- Tax / VAT code (CUI): RO52628580
- Email:
1.2. In these terms, "SELFOIA", "we" and "us" mean SELFOIA S.R.L. "You" means the person using the website. If you use it on behalf of a company, "you" also means that company, and you confirm you are allowed to act for it.
2. What these terms cover
2.1. These terms apply to:
- the website selfoia.com and its content: pages, guides, the checklist, the glossary, the sample report and any free tools;
- the free check described in section 4.
2.2. If you buy a paid service (an audit, a sprint or a subscription), the Service Terms apply to that service. If these terms and the Service Terms say different things about a paid service, the Service Terms win.
2.3. By using the website or sending a free-check request, you agree to these terms. If you don't agree, please don't use the website.
3. Using the website
3.1. General information, not advice. Our content explains common problems in apps built with AI tools. It is general. It is not a review of your app and it is not legal, tax or compliance advice.
3.2. Things change fast. AI tools, platforms and their defaults change often. We date our content and try to keep it current, but we can't promise it is complete or up to date on the day you read it.
3.3. Sources. Where we quote a number, we link to its source. We are not responsible for the accuracy of third-party sources.
3.4. Self-checks are for your own app. The self-checks in our checklist and guides are meant for apps you own or are authorised to test. Make a backup before you change anything.
3.5. Free tools. If we offer a free tool on the website, it runs as described on its page. Don't paste passwords, secret keys or other people's personal data into it.
3.6. Availability. We may change, pause or remove any part of the website at any time. We don't promise the website will always be available or error-free.
4. The free check
4.1. What it is. A free, written reply within 2 business days (Monday to Friday, excluding Romanian public holidays) that covers:
- up to 3 main risks we can see from your app's public signals; and
- a plain-English read of the scanner results you paste (for example a Lovable security scan or Supabase Security Advisor), including which items look real.
There is no call and no obligation to buy anything. The 2-business-day time is our target, not a contractual deadline.
4.2. We only look, we don't touch. For a free check we load your app's public pages the way any visitor's browser does. We look at what any visitor receives: HTTP headers, HTML, public JavaScript files, the TLS certificate and public files such as robots.txt. We do not:
- log in, create accounts or use any credentials;
- send requests to your database, API or login endpoints beyond what a normal page load does by itself;
- guess passwords, run automated attack tools, fuzz inputs or run load tests;
- try to get around any protection.
4.3. Only for your own app. You may request a free check only for an app you own, or one whose owner has authorised you to request it. The form asks you to confirm this. A false confirmation breaches these terms, and you are responsible for what follows from it.
4.4. Sensitive details only after you prove ownership. If we see something that looks like a secret key or exposed personal data, we share the details only after you show that the app is yours. You can do that by:
- writing to us from an email address on the app's domain;
- placing a short token file we give you on the app's website; or
- sending a screenshot from your own account on the platform or scanner.
Until then, we send general guidance only.
4.5. What we do with a secret we find. We never use a key or credential we find, not even to check whether it works, and we don't store it. If we can't verify ownership and the exposure looks serious for the app's users, we may alert the app owner or the platform's published security contact. That message contains only what the recipient needs to fix the problem, and no sales offer. We are not obliged to send it.
4.6. Don't send us secrets. Before pasting scanner results, remove passwords, secret keys, tokens and your customers' personal data. If you send us a secret anyway, we delete our copy and ask you to rotate it (replace it with a new one).
4.7. We may decline. We may decline a request, for example when we're at capacity, when the app isn't one we can help with, or when a request looks like spam or misuse. We'll try to tell you.
4.8. No reliance. A free check is a quick look at public signals. It is not an audit, a penetration test or a certificate, and it will miss things. If we find nothing, that does not mean your app is safe. The free check is provided "as is". What you do with it is your decision.
4.9. Confidentiality. We treat what you send us as confidential. We don't publish it and we don't name your app. The only exception is the alert described in section 4.5.
4.10. Research use only with your permission. The form has a separate, optional box that lets us use anonymised findings from your app in aggregate research. It is unticked by default and saying no changes nothing about your free check. See our Privacy Policy.
5. Acceptable use
You must not:
- use the website in breach of any law;
- attack, overload or probe our website or systems, except for good-faith security research under section 6;
- send spam or automated requests, or try to get around our anti-spam checks or rate limits;
- request a free check for an app you are not authorised to request it for, or use the free check to gather information about someone else's app;
- upload malware or harmful code;
- scrape the website in a way that puts load on it (normal crawling that respects
robots.txtis fine); - impersonate anyone, or suggest that we have reviewed, certified or endorsed your app when we haven't.
6. Found a security issue on our website?
6.1. Please report it to . Tell us what you found and how to reproduce it.
6.2. We treat good-faith research as authorised if you:
- only test selfoia.com, not our providers' systems (for example Vercel or Cloudflare);
- don't access, change or keep anyone else's data;
- don't degrade the website for others;
- give us reasonable time to fix the issue before you tell anyone else.
6.3. If you follow section 6.2, we won't take legal action against you for that research. We can only speak for ourselves, not for third parties.
7. Intellectual property
7.1. The website, its text, design, code, checklist, sample report and our name and logo belong to us or our licensors.
7.2. You may read, print and share links to our pages, and quote short parts with a link back to the source. Anything more needs our written permission, unless a page says otherwise.
The checklist is the exception. The checklist at selfoia.com/checklist, selfoia.com/checklist.md and in its public GitHub repository is licensed under Creative Commons Attribution 4.0 International (CC BY 4.0). You may copy, adapt and share it, including commercially, as long as you credit SELFOIA, link to the source and say if you changed it. The licence doesn't cover our name or logo, and it doesn't mean we endorse your version.
7.3. Names such as Lovable, Bolt, Cursor, Replit, v0, Base44, Claude Code, Supabase, Firebase, Stripe, OpenAI and Vercel belong to their owners. We use them only to describe what we work with. We are not affiliated with those companies unless we say so.
7.4. If you send us feedback or ideas, we may use them without owing you anything.
8. Links to other websites
The website links to other services, such as Calendly for booking a call, Stripe for payment and the sources we quote. Their own terms and privacy policies apply there. We are not responsible for their content or how they work.
9. Our liability for the website and the free check
9.1. The website and the free check are free and provided "as is" and "as available". To the extent the law allows, we give no promises about them beyond what these terms say.
9.2. To the extent the law allows, we are not liable for loss that comes from using or relying on the website's content or a free check. That includes lost profit, lost data, business interruption, and indirect or consequential loss. A free check that finds nothing doesn't mean your app is safe (section 4.8).
9.3. If we are liable anyway, our total liability for the website and the free check, for all claims together, is limited to USD 100.
9.4. Nothing in these terms limits or excludes liability:
- for damage caused intentionally or through gross negligence (art. 1355 of the Romanian Civil Code);
- for death or personal injury;
- that cannot be limited or excluded by law; or
- your mandatory rights as a consumer.
9.5. Liability for paid services is covered by the Service Terms.
10. Changes to these terms
10.1. We may update these terms. The date and version at the top show which version applies.
10.2. If a change matters, we will say so on the website. Changes don't apply to a free-check request you sent before the change.
11. Law and disputes
11.1. These terms are governed by Romanian law.
11.2. The courts of Bucharest, Romania, have jurisdiction.
11.3. If you are a consumer, you keep the protection of the mandatory laws of the country where you live, and you can also bring a claim in the courts of that country.
11.4. If you have a complaint, please write to us first at . Consumers can also use the out-of-court dispute resolution options listed in section 19.8 of our Service Terms.
12. General
12.1. If a court finds part of these terms invalid, the rest still applies.
12.2. If we don't enforce a right straight away, we don't give it up.
12.3. These terms are written in English, and the English version governs. Any translation is for convenience only. If you are a consumer and the law gives you the right to these terms in your own language, ask us and we will provide that version.
12.4. Questions: .
Service Terms
Effective date: October 2, 2026 · Version: 1.0
These terms apply when you buy a paid service from SELFOIA S.R.L.: a Vibe Code Audit, a Fix Sprint, a Speed & AI-Cost Sprint, On-call CTO or Guard. They sit alongside our Terms of Service (website and free check), our Privacy Policy and the Data Processing Addendum (Annex B).
The short version
This summary is here to help you read the terms. The numbered clauses below are what count.
- We review, fix and speed up apps built with AI tools. We close the holes we find and improve your app. We don't promise it will never have another bug, leak, vulnerability or outage. We promise fixes and improvements, not perfection.
- If our own work has a mistake, we fix it at no charge. Tell us within 30 days of delivery (sections 5.9, 7.5 and 23.2). That is a promise about our work, not a guarantee about your whole app.
- An audit is a technical review. It is not a penetration test, a certificate or a guarantee.
- We only test what you authorise in writing, and by default we don't touch your customers' data.
- You stay in control of, and responsible for, your app's access control, credentials, backups and deployments, and any changes you or your AI tools make after us.
- The audit fee counts toward a Fix or Speed & AI-Cost Sprint ordered within 30 days of the report. If the audit finds nothing Critical or High, we refund half the fee.
- Subscriptions run month to month and you can cancel at any time.
- We are not liable for indirect loss, lost profit, lost data or business interruption. Our total liability is capped at what you paid for the service in question (for a subscription, the last 3 months' fees). The law doesn't allow these limits for intent, gross negligence, death or personal injury, or against a consumer's mandatory rights, so they don't apply there.
- If you are a consumer, you keep all your legal rights, including the 14-day right to withdraw (section 19).
Part A · General
1. Who we are and who these terms are for
1.1. Us: SELFOIA S.R.L., registered office Strada Gladiolelor 2, 040144 Bucharest, Romania; Trade Register J2025075767005; CUI / VAT code RO52628580; email . Our founder and lead engineer is Denys Kharkovskyy.
1.2. You: the person or company that orders a service. If you order for a company, you confirm you may bind it.
1.3. Business or consumer. Most clients buy for a business, including founders buying for a business they are building. Some rules apply only to consumers: individuals buying mainly for purposes outside their trade, business or profession. Where a clause says "if you are a consumer", it applies only to consumers. Nothing in these terms takes away a consumer's mandatory legal rights.
1.4. Age. You must be at least 18 to buy a service.
2. How a contract is made
2.1. Steps. Depending on the service, you:
- (a) choose a service on selfoia.com and read these terms;
- (b) if you are a consumer, tell us whether you want us to start within the 14-day withdrawal period (section 19);
- (c) accept these terms, including the clauses listed in section 30.4, by ticking the box at checkout or by replying "accepted" to our written estimate;
- (d) pay through Stripe or by bank transfer against our invoice.
2.2. When the contract starts.
- For audits and subscriptions: when we email you the order confirmation after payment.
- For Fix and Speed & AI-Cost Sprints: when you accept our written estimate.
2.3. Checking your order. You can review and correct your details at each step before you pay.
2.4. Your copy. We email you an order confirmation within 1 business day of your payment (for a sprint, of your acceptance of the Estimate). It lists what you ordered, the version of these terms, the clauses you accepted expressly (section 30.4) and when you accepted them, and, if you are a consumer, your choice under section 19. A PDF of that exact version of these terms is attached. We keep a record of the version you accepted.
2.5. Language. The contract is made in English.
2.6. Estimates. A written estimate is valid for 14 days unless it says otherwise.
3. Words we use
- App: the application you ask us to work on, with the environments and code named in your authorisation.
- Authorisation: your written authorisation and scope for our work (Annex A).
- Business day: Monday to Friday, excluding Romanian public holidays.
- Deliverables: what we hand over: reports, recordings, fix prompts, code changes and before/after results.
- Estimate: our written, fixed-price proposal for a sprint: scope, price, timeline, assumptions and payment schedule.
- Finding: an issue we record in a report, with a severity level.
- Materials: everything you give us: code access, exports, test accounts, documents and information.
- Severity Definitions: the definitions of Critical, High, Medium and Low published at https://selfoia.com/vibe-code-audit#severity as they stood on the day you paid. Annex D reproduces them.
Part B · What we do
4. Services at a glance
| Service | What you get | Price | Timing | How you pay |
|---|---|---|---|---|
| Vibe Code Audit | Review of your app and code in 5 zones, plain-English report, fix prompts | USD 500 launch price (first 10 audits), then USD 950 | Report in 3 business days | Upfront, Stripe |
| Fix Sprint | Fixes from the audit, re-check, before/after report | From USD 3,000, fixed estimate | 1–2 weeks | Invoice |
| Speed & AI-Cost Sprint | Faster pages and queries, AI spend controls, before/after metrics | From USD 3,000, fixed estimate | 1–2 weeks | Invoice |
| On-call CTO | Change reviews, answers, small fixes, watching errors and bills | USD 1,500/month (up to 10 h) or USD 2,500/month (up to 20 h) | Ongoing, month to month | Monthly subscription, Stripe |
| Guard (after an audit) | Monthly passive re-check, alerts, quarterly mini-review | USD 390/month | Ongoing, month to month | Monthly subscription, Stripe |
Taxes are covered in section 16.
5. Vibe Code Audit
5.1. Scope: five zones. We review your App for the problems AI-built apps most often have:
- Leaks: secrets in the browser, database rules that expose data.
- Break-ins: authorisation and login weaknesses, users reaching other users' data, unprotected admin areas.
- Money and AI cost: missing limits on AI and paid features, abuse that runs up bills, unverified payment webhooks.
- Speed: slow pages and queries, missing indexes, heavy front ends.
- Safety net: backups, monitoring, alerts and risky dependencies.
5.2. How we review.
- We read your code with read-only access (a read-only repository invite or an archive).
- We read exports of your database schema, access policies, functions and storage/auth settings. We give you ready-made queries to produce these.
- We run tests on your live App only from our own test accounts, preferably on a staging copy with fake data.
- We look at your App's public signals and any scanner results you share.
Section 14 explains how we handle data.
5.3. What you receive.
- A written report in plain English. Each Finding has:
- a severity under the Severity Definitions;
- what it means for you;
- evidence, with any personal data removed;
- the steps to fix it and a time estimate;
- a copy-paste fix prompt for your AI tool, and how to check the result.
- A recorded walkthrough of the report (video with subtitles).
- An optional 30-minute call to go through the report, if booked within 30 days of delivery.
Every report is read and signed by Denys Kharkovskyy.
5.4. Timing. We deliver the report within 3 business days. The clock starts on the later of the dates below (for a consumer who didn't ask us to start early, not before the withdrawal period in section 19.2 has ended):
- the day we receive your payment; and
- the day we have everything the Authorisation lists (access, exports, test accounts).
5.5. If we can't start in time. If we can't start within 10 business days of having everything we need, for reasons on our side, you may cancel for a full refund.
5.6. Size. The audit price covers one web app with one database or backend project, up to about 30 screens or routes and 25 database tables. If your App turns out to be larger, we tell you before we start. You then choose one of three options:
- a narrower scope at the same price;
- an estimate for the extra work; or
- cancel for a full refund.
5.7. When work starts. We email you when we start the review. Before that email, you can cancel for a full refund.
5.8. Launch price. The USD 500 launch price applies to the first 10 audits we sell. After that the price is USD 950. The price you paid is the price you pay; it never changes afterwards.
5.9. Mistakes in the report. If the report has a mistake in it, for example a Finding that is described wrongly or a fix prompt with an error in it, tell us within 30 days of delivery and we correct it at no charge. This covers the report as it applied to your App when we reviewed it, not later changes to your App.
6. Audit fee credit and half refund
6.1. Credit toward a sprint. The audit fee you paid counts toward a Fix Sprint or a Speed & AI-Cost Sprint for the same App, if you accept the sprint's Estimate within 30 days of our delivering the audit report.
- If we refunded half the fee under section 6.2, the credit is the half you kept.
- We apply the credit to the first invoice of that sprint.
- The credit is used once, can't be transferred and has no cash value.
6.2. Half refund if nothing Critical or High. If the final report contains no Finding rated Critical or High under the Severity Definitions, we refund 50% of the audit fee.
- You don't need to ask.
- We send the refund within 14 days of delivering the report, to the payment method you used.
6.3. No other refunds after work starts. Once we have started (section 5.7), the audit fee is not refundable, because the work and the AI-tool costs are already spent. There are three exceptions:
- the half refund in section 6.2;
- sections 5.5 and 5.6; and
- your consumer rights in section 19.
7. Fix Sprint
7.1. Scope. We fix Findings from our audit, or from another review we agree to work from. Each sprint has an Estimate covering:
- the Findings in scope;
- the fixed price (from USD 3,000);
- the timeline (usually 1–2 weeks);
- the assumptions, what we need from you, and the payment schedule.
7.2. How we work.
- We make changes in a separate branch or pull request, staging first where one exists.
- You review, merge and deploy, unless we agree in writing that we deploy.
- Before any deployment, you make sure a current backup exists (section 13.3).
7.3. Re-check and report. When the fixes are in place, we re-check the fixed Findings and give you a before/after report.
7.4. Acceptance. Please review the delivered work within 5 business days and tell us if a fix doesn't do what the Estimate describes. If we hear nothing in that time, the work is accepted.
7.5. Our fix-it promise: we fix our own mistakes. If a fix we made doesn't work as the Estimate describes, tell us within 30 days of delivery and we correct it at no charge, even if the work was already accepted under section 7.4. This applies in the environment we delivered to, as long as the fix hasn't been changed since by you, your AI tools, your developers or anyone else. It is a promise about our own work, not a guarantee that your App has no other problems (section 11).
7.6. Changes of scope. Anything outside the Estimate needs a new or updated Estimate that you accept first.
8. Speed & AI-Cost Sprint
8.1. Scope. Depending on the Estimate, we work on:
- slow pages and database queries;
- limits on AI features, and per-user limits;
- caching;
- controls and alerts on AI and cloud spend.
Sections 7.1 to 7.6 apply in the same way.
8.2. Metrics. We measure the agreed metrics before and after, under the conditions we describe in the report.
8.3. No promised numbers. Speed and cost depend on things outside our control: your traffic, your providers' performance and pricing, and later changes to your App. We don't promise a specific figure unless the Estimate says so explicitly.
9. On-call CTO
9.1. Plans.
- USD 1,500 per month for up to 10 hours.
- USD 2,500 per month for up to 20 hours.
9.2. What's included:
- reviewing changes before you deploy them;
- answering technical questions;
- small fixes;
- watching errors and bills through access you give us.
Larger pieces of work go through a sprint Estimate.
9.3. Contact and response. You reach us by email, or in a shared chat channel if we agree one. We reply within 1 business day. On-call CTO is not a 24/7 emergency or incident-response service.
9.4. Hours. We track time in 15-minute increments and can send you the log each month.
- Unused hours don't roll over to the next month.
- We only work extra hours if you approve them in writing first, at a rate we agree in writing before that work starts.
9.5. Billing and cancellation. See section 18.
10. Guard
10.1. Who it's for. Guard is available only for an App that had a Vibe Code Audit with us in the 6 months before Guard starts.
10.2. Price. USD 390 per month, month to month.
10.3. What's included:
- a monthly passive re-check: secrets in public JavaScript, security headers, TLS certificate, endpoints listed in your Authorisation, and availability;
- alerts on AI spend and errors, where you give us read-only access or forward notifications to us;
- a quarterly mini-review of new changes (up to 2 hours).
10.4. What's not included.
- Guard includes no fixes. Fixes go through On-call CTO or a sprint.
- Guard is not 24/7 monitoring and not incident response.
- Alerts depend on third-party services and on the access you give us staying valid, so an alert can be late or missed.
11. What we don't do
11.1. Not a penetration test, not a certificate, not a guarantee.
- Our services are technical reviews and engineering work.
- They are not a penetration test or a certification. They are not an attestation for SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR or any other standard.
- We don't guarantee that your App is or will stay secure, or that it is or will stay free of bugs, leaks, vulnerabilities or outages. We don't guarantee that it will reach a particular speed or cost either.
11.2. A point in time. An audit is a risk-based review of your App as it was when we looked at it. It covers the most likely and most harmful problems in the five zones; it can't find everything. Your App, your AI tools and your dependencies keep changing after we finish.
11.3. Not included:
- testing of third-party platforms' own infrastructure, such as Supabase, Firebase, Stripe, Vercel or Lovable (we review your configuration and code on them);
- denial-of-service or load tests, social engineering, phishing, physical tests, or brute force against production;
- legal, tax or compliance advice (we may point out issues that could matter legally, so you can ask an adviser);
- access to your customers' data, unless we agree an exception under section 14.4.
Part C · Your side
12. Your authorisation to test
12.1. Written authorisation first. Before we do anything beyond looking at your public pages, you give us written authorisation using the form in Annex A. You can sign it, or confirm it by email from the address you ordered with. It sets out:
- the App and its environments (URLs, repositories, projects);
- what we may do;
- the test accounts;
- the time window;
- your contacts;
- anything that is off-limits.
12.2. What you confirm. By giving the Authorisation, you confirm that:
- you own the App, or the owner has authorised you, and you may grant this authorisation;
- the terms of the platforms and hosts your App uses allow the checks listed (it's your job to check their policies);
- you have told anyone in your organisation who needs to know;
- you may share the Materials with us without breaking anyone else's rights or confidentiality.
12.3. We stay in scope. We do only what the Authorisation allows. If we need to do more, we ask first, in writing.
12.4. We stop when it's unsafe. We act in good faith. We stop and tell you straight away if a check seems to affect your App's stability. If a check reveals real third-party data, we stop at the first proof and tell you straight away (section 14.3).
12.5. If your authorisation is wrong. If the Authorisation turns out to be wrong or incomplete, you are responsible for the claims that follow. You will compensate us for our resulting losses, including reasonable legal costs. If you are a consumer, this applies only as far as the law allows.
13. Your responsibilities
13.1. Access and information. Give us the access and Materials listed in the Authorisation, on time, and keep the information you give us accurate. Name a contact who replies within 2 business days. Delays on your side move our deadlines by the same amount.
13.2. Credentials and access control. You create and control all access we get. Use the least access that does the job. Remove our access when the work ends. Rotate any secret you shared with us, even by mistake. You remain responsible for who can reach your App, its accounts, keys and data, and for its access rules, during and after our work.
13.3. Backups. Keep current, tested backups of your code and data, especially before deploying any change or running any fix prompt. We are not responsible for data loss that a backup would have prevented.
13.4. Your decisions. You decide what to fix, when, and whether to deploy. Unless we agree otherwise, you deploy and you keep the fixes in place.
13.5. Changes after our work. We are not responsible for changes made after our work by:
- you or your team;
- your AI tools (for example when Lovable, Bolt or Cursor regenerates code);
- other developers;
- platform updates or dependency updates.
That includes changes that bring back an issue we fixed.
13.6. Fix prompts. AI tools don't always do what a prompt asks and can change other parts of your App. Before running a fix prompt:
- back up;
- run it on staging if you can;
- review the changes;
- test the result as the report explains.
We are responsible for the content of our prompts. We are not responsible for what an AI tool does with them.
13.7. Your legal duties. As the App owner, you remain responsible for your App's legal duties. These include your privacy policy, your terms with your users, and any breach notices to authorities or users.
14. Access to data
14.1. By default, no access to your customers' data. We work from:
- your code (read-only);
- exports of schema, policies and settings;
- tests from our own test accounts, preferably on a staging copy with fake data.
14.2. We never ask for database passwords, service-role or admin keys, or data exports. If you send us one anyway, we don't use it. We delete our copy and ask you to rotate it.
14.3. First-proof rule. If a check shows that real data belonging to someone else is reachable, we stop at the first proof. We record only row counts and field names. We don't copy or keep any values. We tell you straight away, whatever the severity, without waiting for the report. Separately, we notify you without undue delay of any personal data breach we become aware of (DPA section 11).
14.4. Exception: read-only database access. We accept read-only database access only when it's needed and we agree it in writing. You create a restricted, time-limited role for us, and remove it at the end. The DPA applies. Before any read-only database access, we both sign (or e-sign) the DPA.
14.5. Data Processing Addendum. Whenever we process personal data on your behalf, including by accident under section 14.3, the Data Processing Addendum (Annex B) applies and forms part of these terms.
14.6. Storage and deletion. We keep Materials only on encrypted devices and accounts that we control. We delete our code copies, database structure exports and working notes within 30 days of final delivery (for On-call CTO and Guard: of the end of the engagement), unless you ask us in writing to keep them longer. We keep the report, the contract and our correspondence as section 20.4 describes.
14.7. AI tools we use. We may use AI coding assistants to help us review and fix code. We use them only under terms or settings that don't allow the provider to train on your content (for example business or API terms, or model training switched off). We never put secrets or personal data into them. They are listed in DPA Annex 2, and we name the ones we use on your App if you ask. If you'd rather we didn't use them on your App, tell us before we start. That may affect timing and price.
Part D · Money
15. Prices and payment
15.1. Currency. Prices are in US dollars (USD).
15.2. When you pay.
- Audit: in full, upfront, through Stripe.
- On-call CTO and Guard: monthly in advance, through Stripe, renewing automatically each month until cancelled (section 18).
- Fix and Speed & AI-Cost Sprints: as the Estimate says. Unless it says otherwise, you pay 50% when you accept the Estimate and 50% on delivery, each within 14 days of the invoice, through Stripe Invoicing or bank transfer. We start once the first payment arrives, unless we agree otherwise in writing.
15.3. Card details. Card payments are handled by Stripe. We never see or store your full card details.
15.4. Late payment. If a payment is late, we may pause the work after telling you. Late amounts carry interest: for businesses, the late-payment interest and recovery costs set by Romanian Law 72/2013; for consumers, the legal interest set by Romanian law.
15.5. Fees. Each side pays its own bank and currency-conversion fees.
15.6. Price changes.
- A price never changes for an order you've already paid for or an Estimate you've accepted.
- For subscriptions, we give 30 days' notice of any price change, and you can cancel before it applies.
16. Taxes and invoices
16.1. Invoices. SELFOIA S.R.L. issues an invoice for every payment, through Stripe Invoicing or our invoicing software, and also through the Romanian e-Factura system where the law requires it.
16.2. VAT. Stripe Tax works out VAT at checkout from your country and VAT status:
- Businesses outside the EU: no Romanian VAT. Any tax your own country charges on services bought from abroad is yours to account for.
- Businesses in another EU country with a valid VAT number: no VAT from us. Under the reverse-charge rule, you account for the VAT yourself. Please give us your VAT number before you pay.
- Businesses in Romania: Romanian VAT (currently 21%) is added.
- Consumers in the EU: VAT is added where the law requires it. You see the total, including VAT, before you pay.
- Everyone else: tax is added only where the law requires it, and you see the total before you pay.
16.3. Other taxes. Our prices don't include any tax your country requires you to withhold from a payment to us. If you must withhold tax, tell us before you pay, and add it on top so that we receive the full price, unless we agree otherwise in writing before you pay.
17. Cancellations and refunds (one-off services)
17.1. Audit.
- Before work starts (section 5.7), you can cancel for a full refund.
- After work starts, sections 6.2 and 6.3 apply.
17.2. Sprints. You can cancel a sprint at any time by writing to us. You then pay for the work done up to that point, in proportion to the Estimate, plus any third-party costs we have already committed to with your approval. Once that's paid, we hand over the work done so far.
17.3. How refunds are paid. Refunds go to the payment method you used, within 14 days.
17.4. Consumers. Section 19 also applies.
18. Subscriptions (On-call CTO and Guard)
18.1. Renewal. A subscription renews automatically each month, and we charge the monthly price at the start of each period, until you cancel.
18.2. Cancelling. You can cancel at any time, online through the Stripe customer portal (the link is in your order confirmation), or by emailing .
- Cancellation takes effect at the end of the month you have paid for.
- We confirm it by email.
- There are no refunds for part of a month, except under section 19.
18.3. Reminders. We send a reminder of the renewal terms at least once a year.
18.4. When we can end a subscription.
- With 30 days' notice, for any reason.
- Immediately, if a payment is more than 14 days late after a reminder, or if section 26.2 applies.
19. If you are a consumer
19.1. Right to withdraw. You can withdraw from a service contract within 14 days of the day it was made, without giving a reason.
19.2. Starting early. We start within those 14 days only if you expressly ask us to. At checkout you tick a box that says, in substance:
"Please start the work now. I understand that if I withdraw before it's finished, I pay for the work done until then, and that I lose my right to withdraw once the service has been fully performed."
If you don't tick the box, we start after the 14 days have passed.
19.3. What you pay if you withdraw after asking us to start. You pay an amount in proportion to what we did before you told us you were withdrawing. We refund the rest.
19.4. Once the service is complete, you can't withdraw. For example, once we have delivered the audit report. The half refund in section 6.2 still applies.
19.5. Subscriptions. You can withdraw within 14 days of signing up. Sections 19.2 and 19.3 apply to the days already used.
19.6. How to withdraw. Send us a clear statement by email to or by post to our registered office. You can use the model form in Annex C, but you don't have to. We refund you within 14 days of receiving it, using the payment method you used, at no cost to you.
19.7. Your other rights. Your statutory rights stay in full, including your rights when digital content or a digital service doesn't conform to the contract and your protection against unfair terms. Where these terms limit our liability, they do so only as far as consumer law allows.
19.8. Complaints. Please contact us first at . We reply within 15 days. If we can't resolve it:
- you can use the alternative dispute resolution (SAL) platform of ANPC, Romania's consumer protection authority, at https://reclamatiisal.anpc.ro;
- consumers elsewhere in the EU can also contact their national consumer authority or the European Consumer Centres Network.
Part E · Legal protections
20. Confidentiality
20.1. What counts. Each of us keeps the other's confidential information confidential, and uses it only for the services. That includes code, security findings, business information and anything marked or obviously confidential.
20.2. What doesn't count. Confidentiality doesn't cover information that:
- is or becomes public without anyone breaking this clause;
- the other side already had lawfully;
- the other side gets lawfully from someone else; or
- the other side develops independently.
20.3. When we may disclose. Either of us may disclose confidential information when the law, a court or an authority requires it. Where allowed, we tell the other side first. Either of us may also share it, as far as needed, with our own lawyers, accountants and insurers, and we may share it with contractors working on your services (section 27). All of them must be bound by confidentiality.
20.4. How long.
- Confidentiality lasts for the contract and 5 years after it ends.
- For security findings, secrets and personal data, it lasts for as long as the information stays confidential.
- We keep reports, contracts and our correspondence for 3 years after the work ends, to deal with any questions or claims. We keep invoices, and any contract or record that supports them, for as long as Romanian accounting and tax law requires.
20.5. NDA. We're happy to sign your NDA as well. If it conflicts with this section, the stricter confidentiality rule applies. An NDA doesn't change the limits in section 24 unless it says so expressly.
21. Intellectual property
21.1. Your Materials stay yours. You give us a licence to use them only to deliver the services.
21.2. Code we write for you belongs to you.
- Once you have paid in full, we assign to you all economic rights in the code we write specifically for your App. The assignment is exclusive and worldwide, lasts for the full term of protection, and covers every form of use, including reproduction, modification, adaptation, distribution and publication, and the right to license others.
- The price of the service is the full payment for this assignment.
- Until you have paid in full, you may use the code for testing only.
- As far as the law allows, we won't object to changes you make to it.
21.3. Reports and recordings. You own the copy of the report and recordings you receive. You may use them, and share them in confidence with your team, developers, advisers, investors, insurers and customers. You may not:
- present them as a certificate, a guarantee or our endorsement of your App;
- edit them in a way that misleads; or
- use our name to say your App is "secure", "certified" or similar.
A factual, dated statement such as "reviewed by SELFOIA on [date]" needs our written consent.
21.4. Our know-how stays ours. We keep all rights in our existing and general materials: methods, checklists, templates, prompt libraries, scripts, tools and general know-how, including improvements we make while working for you. Where any of these are built into your Deliverables, you get a perpetual, worldwide, non-exclusive, royalty-free licence to use them as part of those Deliverables for your App.
21.5. Fix prompts. You may use our fix prompts freely for your App.
21.6. Third-party code. Open-source and third-party components stay under their own licences.
22. Anonymised learnings and publicity
22.1. We may use the general know-how and experience we gain from our work.
22.2. We keep an internal quality log of Findings without your name, App name, URLs or any personal data: platform, finding type, severity, time to fix and before/after metrics. The log holds nothing that identifies you or your App, and we don't publish it.
22.3. We use anything from your engagement in published material (statistics, research or examples) only if you have opted in, and only in anonymised, aggregated form. You can withdraw your opt-in for future publications at any time.
22.4. We name you, your App or your company, or publish a case study, only with your separate written consent.
23. Our promise about the quality of our work
23.1. We do the work with reasonable skill and care, in line with good industry practice for work of this kind, using qualified people.
23.2. If our work has a mistake, we put it right. If something we delivered doesn't match what we agreed, tell us within 30 days of delivery and we correct it at no charge (sections 5.9 and 7.5 give the details for reports and fixes). If we can't correct it, we refund the part of the fee that relates to the work that doesn't match.
23.3. Beyond sections 23.1 and 23.2, and to the extent the law allows, we make no other promises, express or implied, about results. Section 11 lists what we don't do.
24. Liability
24.1. What we never limit. Nothing in these terms limits or excludes liability:
- for damage caused intentionally or through gross negligence (art. 1355 of the Romanian Civil Code);
- for death or personal injury;
- that the law doesn't allow to be limited; or
- a consumer's mandatory rights.
24.2. Losses we don't cover. To the extent the law allows, we are not liable for indirect or consequential loss, or for any of the following, whether direct or indirect:
- lost profit, revenue, business, opportunity or goodwill;
- business interruption or downtime;
- loss or corruption of data (you keep backups under section 13.3);
- AI, cloud or other usage charges;
- fines or penalties imposed on you;
- claims by your users or customers.
24.3. What we are not responsible for. We are not responsible for loss caused by:
- issues we didn't find, or couldn't reasonably find, within the agreed scope and time;
- code or configuration we didn't write;
- changes made after our work (section 13.5);
- your decision not to act on a recommendation, or to delay it;
- gaps in your App's access control, credentials, backups or deployments, which stay your responsibility (section 13), including not deploying our fixes or not rotating secrets (mistakes in our own fixes are covered by section 23.2);
- what AI tools do with fix prompts (section 13.6);
- acts, failures or outages of third-party platforms and providers, including alerts that arrive late or not at all (section 10.4);
- wrong or incomplete information or Authorisation from you.
24.4. Cap. Our total liability arising from or in connection with a service, for all claims together and including under the DPA, is limited to:
- for a one-off service (audit or sprint): the fees you paid for that service;
- for a subscription: the fees you paid for that subscription in the 3 months before the event that caused the claim.
24.5. Tell us early. Tell us promptly about any problem, and take reasonable steps to limit the loss.
24.6. Consumers. If you are a consumer, sections 24.2 to 24.4 apply only as far as consumer law allows.
24.7. Mistakes in our work. If you are a business, and to the extent the law allows, correcting our work under section 23.2, or refunding the part of the fee it relates to, is the remedy for work that doesn't match what we agreed. Section 24.1 still applies.
25. Events outside our control
25.1. Force majeure. Neither of us is liable for a delay or failure caused by events outside reasonable control (force majeure, art. 1351 of the Romanian Civil Code). Examples include major outages or attacks at platforms and providers, internet failures, and acts of authorities. The affected side tells the other promptly, and deadlines move accordingly.
25.2. Key person. We are a small company. If the engineer assigned to your work is seriously ill or otherwise unable to work, and we can't reasonably replace them, we tell you straight away. You may then:
- wait; or
- cancel and get back what you paid for work not yet done.
26. Ending the contract
26.1. Breach. Either of us may end the contract by written notice if the other seriously breaches it and doesn't put it right within 10 days of being asked. Either of us may also end it straight away if the other becomes insolvent.
26.2. When we may stop straight away. We may refuse or stop work immediately if:
- the Authorisation is false;
- you ask us to test systems you don't control;
- you ask us to do anything unlawful; or
- we reasonably believe the App is being used for unlawful purposes.
26.3. What happens when the contract ends.
- You pay for the work done up to the end.
- We deliver the work you have paid for.
- We return or delete Materials under section 14.6 and the DPA.
26.4. What survives. Sections 6, 12.5, 16, 20, 21, 22, 24 and 28 continue after the contract ends.
27. Contractors
27.1. We may use qualified contractors to help deliver the services. They are bound by confidentiality and, where they touch personal data, by the DPA's rules on subprocessors.
27.2. We remain responsible for their work.
27.3. Denys Kharkovskyy reviews and signs every audit report.
28. Law and disputes
28.1. Governing law. These terms and every contract under them are governed by Romanian law, without its conflict-of-law rules.
28.2. Try to resolve it first. Before going to court, we both try in good faith to settle a dispute within 30 days of one of us raising it in writing. This doesn't limit a consumer's options in section 19.8.
28.3. Courts. The courts of Bucharest, Romania, have jurisdiction. Either of us may still ask any competent court for urgent interim measures.
28.4. Consumers. If you are a consumer, you keep the protection of the mandatory laws of the country where you live, and you may also bring a claim in the courts of that country.
29. Changes to these terms
29.1. Scope. Changes apply only to orders placed after the change. The version you accepted governs your order.
29.2. Subscriptions. For subscriptions, we email you any change at least 30 days before it applies. If you don't agree, you can cancel before then.
30. General
30.1. Entire agreement. The contract consists of:
- these terms;
- the order confirmation or accepted Estimate;
- the Authorisation (Annex A);
- the DPA (Annex B).
It replaces anything said before about the same subject.
30.2. Which document wins. If the documents conflict, this order applies:
- the accepted Estimate or a signed order form, for the specific commercial points it covers;
- the DPA, for personal data;
- these Service Terms;
- the Terms of Service.
30.3. Notices. We send notices to the email address you gave us, and you send them to or by post to our registered office (section 1.1).
30.4. Clauses we ask you to accept expressly. Under art. 1203 of the Romanian Civil Code, certain standard clauses need your express acceptance. When you order, we ask you to accept these separately:
- 6.3 (no refunds after work starts);
- 12.5 (responsibility for the Authorisation);
- 18.1 and 18.4 (automatic renewal and our right to end a subscription);
- 24 (limits on liability);
- 26 (ending the contract and suspension);
- 28 (governing law and courts).
We show them in bold at checkout, next to a separate box you tick to accept them. For a sprint, the Estimate lists them and you accept them when you accept the Estimate. Our order confirmation (section 2.4) records the clauses you accepted, the version of these terms and when you accepted them.
30.5. Assignment. You may not transfer the contract without our consent. We may transfer it to a company that takes over our business, and we will tell you.
30.6. Severability and waiver. If a court finds part of these terms invalid, the rest still applies. If we don't enforce a right straight away, we don't give it up.
30.7. Language. These terms are in English, and the English version governs. Any translation is for convenience only. If you are a consumer and the law gives you the right to these terms in your own language, ask us and we will provide that version.
Annex A · Authorisation and scope form (template)
Send it back signed, or confirm by email from the address you ordered with.
- Client: legal name, address, contact person, email, phone.
- App owner (if different from the client): name, and how the client is authorised to act for them.
- App and environments in scope: production URL(s), staging URL(s), repository, database project(s), hosting project(s).
- What we may do:
- read code (read-only);
- read the exports you provide;
- create and use our own test accounts;
- run the non-destructive checks described in section 5 of the Service Terms;
- for Guard, run passive checks of the endpoints listed here: [list].
- Test accounts: who creates them, which roles, staging or production.
- Off-limits: systems, data, times or actions we must not touch.
- Time window: from [date] to [date], and any quiet hours.
- Personal data: does the App hold special categories of data (for example health data) or children's data? Is read-only database access needed (section 14.4)?
- Emergency contact: who we call if a check shows signs of instability or real third-party data.
- Platforms: the client confirms that the terms of the platforms listed in point 3 allow these checks.
- Confirmation: "I confirm that I own the App or am authorised by its owner, and I authorise SELFOIA S.R.L. to carry out the activities above within this scope and time window, under the SELFOIA Service Terms version [x]."
Name, role, date, signature or confirming email.
Annex B · Data Processing Addendum
See the Data Processing Addendum below.
Annex C · Model withdrawal form (consumers only)
Complete and return this form only if you wish to withdraw from the contract.
To SELFOIA S.R.L., Strada Gladiolelor 2, 040144 Bucharest, Romania, :
I/We (*) hereby give notice that I/We (*) withdraw from my/our (*) contract for the provision of the following service (*):
Ordered on (*) / received on (*):
Name of consumer(s):
Address of consumer(s):
Signature of consumer(s) (only if this form is notified on paper):
Date:
(*) Delete as appropriate.
Annex D · Severity definitions
These are the Severity Definitions published at https://selfoia.com/vibe-code-audit#severity (section 3), version 2026-09-28. The half refund in section 6.2 depends on them, so if we change them, we date the new version here and on the website at the same time. Your order uses the version in force on the day you paid.
| Level | What it means for you | When to fix |
|---|---|---|
| Critical | A stranger could reach your users' data or your money, take over accounts, or get your secret keys, right now and without special skills or access. | Before your next user or payment. |
| High | A real way to lose data, money or access, but it needs some effort, a login, or a specific situation. It also covers a realistic path to a serious outage, data loss without a backup, or runaway costs. | Within days, before you grow or launch. |
| Medium | Makes your app weaker, slower or more expensive, but isn't an open door today. | In the next few weeks. |
| Low | Good practice that makes future problems less likely. | When it's convenient. |
Data Processing Addendum
Annex B to the SELFOIA Service Terms · Effective date: October 2, 2026 · Version: 1.0
This addendum ("DPA") covers the personal data we may process when we work on your app. Our method is designed to avoid your customers' data altogether. This DPA covers the cases where we come across it anyway, and the rare cases where we agree to read-only database access.
1. Roles and when this DPA applies
1.1. Parties. This DPA is between you (the client under the Service Terms) and SELFOIA S.R.L. ("we"). It forms part of the Service Terms and applies automatically to every engagement. You don't need to sign it separately, except before read-only database access (section 1.3(b)), but we'll sign a copy whenever you ask.
1.2. Roles.
- For the personal data held in your app, you are the controller and we are your processor.
- If you are yourself a processor for someone else, we are your sub-processor. You confirm that your own controller has authorised you to use us.
1.3. When it applies. This DPA applies whenever we process personal data on your behalf:
- (a) incidentally, during work under our default method (Service Terms section 14.1). For example, when a test shows that real data is reachable (the "first-proof rule"), or when your code or exports happen to contain personal data;
- (b) exceptionally, when we agree in writing to read-only database access through a restricted, time-limited role (Service Terms section 14.4). Before any read-only database access, we both sign (or e-sign) this DPA.
1.4. Words. Terms such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meaning given in the GDPR (Regulation (EU) 2016/679).
2. Details of the processing
| Item | Details |
|---|---|
| Subject matter | Review, fixing and improvement of your app under the Service Terms |
| Duration | For the engagement, until the data is deleted under section 12 |
| Nature | Viewing and, only in case (b), querying data in read-only mode. We don't copy, export or keep any values (section 5). |
| Purpose | Only to deliver the services you ordered, such as an audit, a sprint, On-call CTO or Guard |
| Data subjects | Your app's users, customers and staff, and other people whose data your app holds |
| Categories of data | Whatever your app holds. Typically: account identifiers, names, email addresses, profile data, user-generated content, usage logs and payment metadata (not full card numbers). |
| Special categories | Not expected. If your app holds health data, other special-category data, criminal records data or children's data, tell us in the Authorisation form before we start, so we can agree extra measures. |
| Frequency | Incidental, or occasional under case (b) |
3. Your instructions
3.1. What counts as instructions. We process personal data only on your documented instructions. These are:
- the Service Terms;
- the Authorisation form (Annex A);
- the accepted Estimate;
- any written instruction you give us later.
3.2. If an instruction breaks the law. We tell you straight away if we think an instruction breaks data protection law.
3.3. If the law requires otherwise. If EU or Romanian law requires us to process data in another way, we tell you first, unless that law forbids it.
3.4. Your responsibility as controller. You are responsible for having a lawful basis for the processing, and for giving your users the information the law requires. That includes information about using service providers like us.
4. Confidentiality of our people
Everyone who may access the personal data is bound by confidentiality, either by contract or by law. That covers our staff, contractors and Denys Kharkovskyy. They process the data only as this DPA allows.
5. How we keep data exposure to a minimum
5.1. Default method. We work from code, exports of schema and policies, and our own test accounts, preferably on staging with fake data. We never ask for database passwords, service-role or admin keys, or data exports.
5.2. First-proof rule.
- If a check shows that real personal data is reachable, we stop at the first proof.
- We record only row counts and field names.
- We don't copy, screenshot, download or keep any values.
- We tell you straight away, whatever the severity, without waiting for the report.
Separately, section 11 applies to any personal data breach we become aware of: we notify you without undue delay.
5.3. Secrets. If you send us a secret, we don't use it. We delete our copy and ask you to rotate it.
5.4. Reports. Reports, recordings and fix prompts contain no personal data from your app. Any evidence is redacted.
5.5. Read-only access (case (b)).
- You create the restricted role and set when it expires.
- We use it only for the agreed queries, from our own devices.
- We tell you when we have finished, so you can remove the role.
6. Security
We apply the technical and organisational measures in Annex 1, which meet Art. 32 GDPR. We may improve them over time, but never below the level described.
7. Subprocessors
7.1. General authorisation. You give us a general written authorisation to use the subprocessors described in Annex 2. When your engagement starts, and whenever you ask, we give you the current list with each subprocessor's name, location and transfer safeguard.
7.2. New subprocessors. We tell you by email at least 14 days before we add or replace one. If you have a reasonable data protection objection, tell us within that time. We'll then try to find a solution. If we can't, either of us may end the affected service, and you get back any prepaid fees for services not yet delivered.
7.3. Obligations passed down. We bind each subprocessor to data protection obligations that are at least as protective as this DPA.
7.4. Responsibility. We remain responsible to you for our subprocessors' performance.
8. Transfers outside the EEA
8.1. Our subprocessors. We transfer personal data outside the European Economic Area only through the subprocessors in Annex 2, and only with a valid safeguard: an adequacy decision (including the EU-US Data Privacy Framework for certified US companies) or the European Commission's Standard Contractual Clauses.
8.2. Clients outside the EEA. If you are outside the EEA and we send you any personal data, the Commission's Standard Contractual Clauses, Module Four (processor to controller), apply where the law requires them. They are incorporated by reference. In practice our method means we return no personal data to you, only row counts and field names.
9. Helping you with data subject requests
9.1. If a data subject contacts us about your app, we pass the request on to you without undue delay and don't answer it ourselves.
9.2. We help you, as far as reasonably possible, to respond to requests to exercise GDPR rights.
10. Helping you meet your other obligations
10.1. We reasonably help you with:
- security;
- breach notifications;
- data protection impact assessments;
- prior consultations with a supervisory authority (Art. 32 to 36 GDPR).
10.2. We don't charge for this help when it is small. We may charge for substantial help at our usual rates, if we agree that first.
11. Personal data breaches
11.1. Breaches on our side. If we become aware of a personal data breach affecting data we process for you, we notify you without undue delay and in any case within 48 hours. Our notice includes, as far as we know at the time:
- what happened;
- the categories and approximate number of people and records affected;
- the likely consequences;
- what we have done or propose to do;
- a contact person.
We send updates as we learn more.
11.2. Exposures we find in your app. During our work we may find signs that your app's data is already exposed or has been accessed by someone else. That is not a breach on our side, but it may be one for you. We tell you as soon as we see it, without waiting for the report. That matters because under Art. 33 GDPR your 72-hour notification clock may start when you become aware.
11.3. Who notifies. Deciding whether to notify a supervisory authority or your users is your responsibility as controller. We don't notify them on your behalf unless you instruct us to in writing, or the law requires it.
12. Deletion and return at the end
12.1. Deletion. We delete any personal data we hold for you, with our code copies, database structure exports and working notes, within 30 days of final delivery (for On-call CTO and Guard: of the end of the engagement), unless you ask us in writing to keep them longer. We delete earlier if you ask. Given our method, there is usually nothing to return. If you ask before deletion and it's technically possible, we return the data to you.
12.2. Written confirmation. We confirm deletion in writing if you ask.
12.3. Exception. We keep data only where EU or Romanian law requires it, and then only for as long as required, keeping it protected.
13. Information and audits
13.1. Documents first. On request, we give you the information you need to show that we meet Art. 28 GDPR. Usually this means a completed security questionnaire and a description of our measures.
13.2. Audits. If that isn't enough, or if a supervisory authority requires it, you or an independent auditor bound by confidentiality may audit us. The conditions are:
- at most once a year;
- 30 days' written notice;
- during business hours;
- remotely where possible;
- at your cost.
This limit doesn't apply to audits a supervisory authority orders, or audits after a breach on our side.
14. Liability
14.1. Between us. The limits of liability in the Service Terms (section 24) apply to this DPA.
14.2. Data subjects. Nothing in this DPA limits either party's liability towards data subjects under Art. 82 GDPR. Nor does it limit anything that can't be limited by law, including liability for intent or gross negligence (art. 1355 of the Romanian Civil Code).
15. Duration, conflicts and law
15.1. Duration. This DPA lasts as long as we process personal data for you.
15.2. Conflicts. On personal data, this DPA prevails over the Service Terms. The Standard Contractual Clauses, where they apply, prevail over both.
15.3. Law. Romanian law governs this DPA, as the Service Terms say. If you are not subject to the GDPR, we still handle your data as this DPA describes.
Annex 1 · Security measures
Access
- Least privilege. We ask only for read-only access and our own test accounts. We never ask for admin or service-role keys.
- Multi-factor authentication on every account we use: email, code hosting, password manager, cloud.
- Temporary credentials and invitations are kept only in our password manager (Annex 2). We delete them at the end of the engagement and ask you to revoke them.
Devices and storage
- Full-disk encryption on every work device, with automatic screen lock and up-to-date operating systems.
- Client Materials are stored only in encrypted storage we control. Never on shared or personal cloud folders without encryption, and never in public repositories.
Data minimisation
- No copies of production personal data. First-proof rule (section 5.2).
- Staging with fake data preferred. Our own test accounts use fake details.
- Reports, screenshots and recordings are checked and redacted before delivery.
- Secrets or personal data are never put into AI tools or ticket systems.
People
- Everyone with access is under confidentiality.
- Contractors have access only to the engagements they work on, and it is removed when they finish.
- Denys Kharkovskyy reviews every report before it goes out.
Deletion
- Code copies, database structure exports, working notes and any incidental data are deleted within 30 days of final delivery (for On-call CTO and Guard: of the end of the engagement), unless you ask us in writing to keep them longer, and sooner if you ask (section 12).
Incidents
- A written incident procedure, with notice to you within 48 hours (section 11).
- Lost or stolen devices are wiped remotely where possible.
Annex 2 · Subprocessors
These are the kinds of subprocessors we may use, and only where your engagement needs them. When your engagement starts, and whenever you ask, we give you the current list with each one's name, location and transfer safeguard (section 7.1). Before any read-only database access, that list is attached to the DPA we both sign (section 1.3(b)). We tell you about changes as section 7.2 says.
| Subprocessor | Purpose | Data it might see | Location | Transfer safeguard |
|---|---|---|---|---|
| Our email and file storage provider | Email, encrypted file storage | Correspondence; code and exports, which rarely contain personal data | EU or USA | EU data region, adequacy decision (including the EU-US Data Privacy Framework) or Standard Contractual Clauses |
| AI coding assistants, used only under terms or settings that don't allow the provider to train on your content (for example business or API terms, or model training switched off) | Help with code review and fixes | Code; no secrets or production personal data (Annex 1) | USA | EU-US Data Privacy Framework or Standard Contractual Clauses |
| Our password manager | Storing temporary credentials | Access credentials only | EU or USA | EU data region, EU-US Data Privacy Framework or Standard Contractual Clauses |
| Our screen-recording tool | Recorded report walkthroughs | Screens of code and test accounts, redacted | EU or USA | EU data region, EU-US Data Privacy Framework or Standard Contractual Clauses |
| The video tool used for our calls (Google Meet or Zoom) | Calls about your App | Only what you show us on screen | USA and a global network | EU-US Data Privacy Framework or Standard Contractual Clauses |
| Individual contractors (named to you before they start) | Delivery support | As the engagement needs | EU or elsewhere | Contract with confidentiality and Art. 28 terms; Standard Contractual Clauses if outside the EEA |
Annex 3 · Contacts
- Our contact for data protection and breaches: Denys Kharkovskyy, .
- Your contact: as given in the Authorisation form (Annex A to the Service Terms).
SELFOIA