ssm.ro Docs
Compliance & Data Protection

Record of Processing Activities

Record of processing activities in accordance with Art. 30 GDPR

The Record of Processing Activities (ROPA) documents the processing of personal data carried out through the SSM.ro platform, in accordance with Art. 30 GDPR.

Processing activities

ActivityData categoriesPurpose / legal basisRecipientsRetention
Platform account and accessName, email, phone, employer, badge numberContract performance (Art. 6(1)(b))Employer, IT providersFor the duration of the account + legal deadlines
Advanced electronic signature (standard flow)Document hash (no national identification data)Contract performance (Art. 6(1)(b))Electronic Signature Provider (QTSP)5-year audit trail
Qualified signature certificate (exceptional)CNP, ID document series/number, ID card copyLegal obligation (Art. 6(1)(c))Electronic Signature Provider (QTSP)5-year audit trail
Communication (notifications, OTP)Email, phoneContract performance (Art. 6(1)(b))Postmark (Shared) / AWS SES (Dedicated)For the duration of the relationship
Training and coursesEmployee data, training resultsContract performanceEmployerFor the duration of the account
MarketingEmailConsent (Art. 6(1)(a))Until consent is withdrawn
InvoicingBilling data (company name, tax ID, address, contact person)Legal obligation (accounting) (Art. 6(1)(c))Legal accounting deadlines
Activity logsOnline identifiers, eventsLegitimate interest / security3 months

Categories of data subjects

  • Platform administrators and users (on behalf of tenants)
  • Employees invited for training and signing
  • Billing contact persons

Data source

Data is collected directly from the data subject, through intermediaries (partner applications), or from the employer, in accordance with the Privacy Policy.

Security measures

Details of the technical and organizational measures are in the Security section: encryption in transit/at rest, tenant isolation, RBAC, minimization (hashing at signing).