Skip to document
SMSifyBusiness SMS policies

Effective August 22, 2026

Privacy Notice

How SMSify collects, uses, discloses, protects, retains, and deletes business-account and messaging data.

1. Roles and scope

CLP SOFTWARE STUDIO S.R.L. (registered office Sat Negrilești nr. 206, jud. Bistrița-Năsăud, 427068, Romania, CUI 38691736), operating the service as SMSify, is the controller for account administration, business verification, billing, fraud prevention, security, support, and legal compliance. For message content, recipient data, and customer-imported contact data processed on a customer’s instructions, SMSify generally acts as a processor or service provider under the Data Processing Addendum.

Privacy questions and rights requests may be sent to support@smsify.app.

2. Information handled

  • Company identity, registry and tax identifiers, service address, authorized representatives, and verification evidence.
  • Account credentials, authentication events, device and security signals, support requests, and audit events.
  • Billing records, invoices, payment references, usage quantities, purchased and promotional balances, and refund records. SMSify does not store full card details.
  • Telephone numbers, consent and suppression records, routing metadata, delivery status, and message or media content only to the extent necessary to provide and secure the requested service.

3. Purposes and legal bases

Information is used to contract with and serve the business customer, verify eligibility, route communications, calculate charges and taxes, prevent abuse, meet carrier and legal duties, provide support, defend claims, and improve reliability using appropriately minimized data. It is not sold or used to build advertising profiles.

4. Sharing and international transfers

Data may be disclosed to approved communications carriers, cloud and database providers, payment processors, business-verification providers, tax and compliance vendors, email or support providers, professional advisers, and authorities when legally required. Each production provider must appear in the Subprocessor Notice before launch.

Transfers from the EEA require an approved GDPR transfer mechanism and assessment. A Quebec customer’s disclosure of personal information outside Quebec requires its privacy impact assessment and a written agreement reflecting that assessment before the service is enabled.

5. Retention and deletion

SMSify applies storage limitation: each data class must have an approved purpose, retention period, deletion method, legal-hold rule, and responsible owner before production use. Message bodies should be transient by default and retained only when a documented service or legal need justifies a defined period.

The same controls apply to subprocessors; local deletion alone is insufficient. Account, invoice, tax, fraud, consent, and security records may be kept for distinct periods required by law or necessary to establish or defend claims. Automated production deletion and anonymization are currently disabled under the published no-mutation retention policy; valid rights requests, legal obligations, and legal holds are handled through the applicable process.

6. Individual rights

Subject to applicable law and role allocation, individuals may request access, correction, deletion, restriction, portability, or objection and may complain to the competent privacy authority. Customer administrators must route recipient requests involving customer-controlled message data under the Data Processing Addendum.

7. Notifications and message privacy

Browser or installed-app push notifications are generic. They do not display or derive content from message bodies, telephone numbers, recipient names, order details, account identifiers, or push payload text. Opening a notification requires the user to authenticate before protected activity is shown.

8. Security and incidents

SMSify uses access controls, encryption appropriate to the data and transfer, audit logging, abuse controls, vulnerability management, backups, and incident response proportionate to risk. No security measure is absolute. Incident notification timing and cooperation are governed by applicable law and the approved Data Processing Addendum.

Fail-closed launch gate

Production retention mutation remains disabled by default. Quebec accounts follow the same Canadian checkout path; SMSify must still provide the applicable French-language flow, privacy assessment, transfer terms, and rights-request process.