GDPR

Processing of Personal Data

 

Privacy Policy regarding the processing of personal data

We consider ensuring the right to the protection of personal data as a fundamental commitment of Industry Transilvan, therefore we will dedicate all necessary resources and efforts to process your data in full compliance with Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR"), as well as with any other applicable legislation in Romania. Since one of the essential principles of this legal framework is transparency, we have prepared this document to inform you about how we collect, use, transfer, and protect your personal data when you interact with us regarding our products and services, including through our website.

We reserve the right to update and modify this Privacy Policy periodically to reflect any changes in how we process your personal data or any changes in legal requirements. In case of any such changes, we will display the modified version of the Privacy Policy on our website, so please periodically check the content of this Privacy Policy.

Who we are and how to contact us

We are INDUSTRY TRANSILVAN SRL, a Romanian legal entity, with registered office in Harghita County, Gheorgheni City, Tatarului Street No. 156-158, registered in the Trade Register under No. J19/651/1991, unique fiscal registration code RO529690 (hereinafter "Transilvan" or "we"). Within the meaning of data protection legislation, we are the data controller when we process your personal data.

Since we are always open to hearing your opinions and providing you with any additional information you may need regarding the processing of your data, we encourage you to contact us at the email address comenzi@transilvan.ro or by mail or courier at the address Tatarului Street No. 156-158, Gheorgheni City, Harghita County, with the mention: attention to the Data Protection Officer.

What categories of personal data we process

In general, we collect your personal data directly from you, so you have control over the type of information you provide to us. For example, we receive information from you when you create an account on the Industry Transilvan page: email address, first and last name. Within your personal page (My Account), you have the possibility to add additional information, such as: mobile phone number, landline number, date of birth, delivery addresses.

When you place an order, you provide us with information such as: the desired product, first and last name, delivery address, billing details, payment method, phone number, bank card details, etc.

On our website, we may store and collect information in cookies and similar technologies, in accordance with the Cookie Policy.

We do not collect or otherwise process sensitive data, included by the General Data Protection Regulation in special categories of personal data. Also, we do not intend to collect or process data of minors who have not reached the age of 16.

What are the purposes and legal bases of the processing

We will use your personal data for the following purposes:

For the provision of Industry Transilvan services for your benefit.

This general purpose may include, where applicable, the following:

a) Creating and managing the account within the Industry Transilvan platform;

b) Processing orders, including their acquisition, validation, dispatch, and billing;

c) Resolving cancellations or any issues related to an order, the goods, or services purchased;

d) Returning products in accordance with legal provisions;

e) Refunding the value of products in accordance with legal provisions;

f) Providing support services, including answering your questions regarding Industry Transilvan orders or goods.

The processing of your data for these purposes is in most cases necessary for the conclusion and execution of a contract between Industry Transilvan and you. Also, certain processing activities related to these purposes are required by applicable law, including tax and accounting legislation.

For the defense of our legitimate interests, there may be situations where we will use or transmit information to protect our rights and business activity. These may include:

- Measures to protect the website and users of the Industry Transilvan platform against cyber attacks;

- Measures to prevent and detect fraud attempts, including the transmission of information to competent public authorities;

- Management of various other risks.

The general basis for these types of processing is our legitimate interest in defending our business activity, ensuring that we take all measures to guarantee a balance between our interests and your fundamental rights and freedoms.

Also, in certain cases, we base the processing on legal provisions such as the obligation to ensure the protection of goods and values provided by applicable legislation in this matter.

How long we keep your personal data

As a general rule, we will store your personal data as long as you have an account on our platform. You can request at any time the deletion of certain information or the closure of the account, and we will comply with these requests, subject to the retention of certain information even after the closure of the account, in situations where applicable law or our legitimate interests require it.

To whom we transmit your personal data

Where appropriate, we may transmit or provide access to certain personal data of yours to the following categories of recipients:

- Courier service providers;

- Payment/banking service providers;

In cases where we have a legal obligation or it is necessary to defend a legitimate interest, we may also disclose certain personal data to public authorities.

We ensure that access to your data by third-party legal entities is carried out in accordance with legal provisions regarding data protection and confidentiality of information, based on contracts concluded with them.

In which countries we transfer your personal data

Currently, we store and process your personal data in Romania.

How we protect the security of your personal data

We are committed to ensuring the security of personal data by implementing appropriate technical and organizational measures, in accordance with industry standards.

The transmission of your personal data is done using state-of-the-art encryption algorithms, and we store them on secure servers, ensuring data redundancy at the same time.

For making payments, we use the services of the payment processor Netopia. Any payment-related information is encrypted using HTTPS technology with TSL 1.2 encryption.

Despite the measures taken to protect your personal data, we draw your attention to the fact that transmitting information over the Internet, in general, or through other public networks, is not completely secure, and there is a risk that data may be seen and used by unauthorised third parties. We cannot be responsible for such vulnerabilities of systems that are not under our control.