PRIVACY POLICY

Processing of personal data - GDPR ver.1.0 / CRD | Last modified: May 24, 2018
Consent to the processing of personal data EU General Data Protection Regulation - G.D.P.R. (General Data Protection Regulation)

The preamble

We consider ensuring the right to the protection of personal data as a fundamental commitment, therefore we will dedicate all necessary resources and efforts to process your data in full compliance with Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR ”), As well as with any other legislation applicable on the territory of Romania. As one of the key principles of this legal framework is transparency, we have prepared this document to inform you about how we collect, use, transfer and protect your personal data when you interact with us about products and services. including our website or mobile applications.

We reserve the right to periodically update and modify this Privacy Policy to reflect any changes to the way we process your personal data or any changes to legal requirements. In the event of any such changes, we will display the modified version of the Privacy Policy on our website, for which reason please check the contents of this Privacy Policy periodically.

Who we are and how you can contact us

The trade name of the company / institution is S.C. Cris Lum Sib S.R.L. with the headquartered in Str. Carpați, Nr. 5, Sibiu, county Sibiu, Unique Registration Code 41434473, registered in the Trade Register under number J32 / 1483/2019 For the purposes of data protection legislation, we are the operator when we process your personal data.

As we are always open to find out your opinions, as well as to provide you with any additional information you may need regarding the processing of your data, we encourage you to contact the head of our company / institution with data protection at the e-mail address: contact @ cristealumanari .ro with the mention: in the attention of the Data Protection Officer (DPO).

What categories of personal data do we process

We generally collect your personal data directly from you so that you have control over the type of information you provide to us. By way of example, we receive information from you as follows:

If you subscribe to our newsletter, send us: your e-mail address, your first and last name; If you create an account in our platform, send us: your e-mail address, your first and last name; alternate email address, etc .; If you purchase products from our platform, provide us with information such as: the desired product, name and surname, delivery address, billing details, payment method, phone number, bank card details, etc.

We may also collect and further process certain information about your behavior while visiting our website or using your smartphone to personalize your online experience and provide you with tailored offers for your profile. We invite you to find out more details in this regard by consulting the section on the purposes of processing below.

We have Google analytics scripts which in turn distribute cookies to analyze all traffic to this site. This is the purpose for which information is sent to Google about how you use our site (from which websites you came to us, which pages you visited, the duration of your visit, etc.), so that we can analyze this information with the purpose of improving our services.

On our website and in the smartphone application we can store and collect information in the form of cookies and similar technologies, according to the Cookies Policy. We do not collect or otherwise process sensitive data, included in the General Data Protection Regulation in special categories of personal data.

What are the purposes and grounds of processing

We will use your personal data for the following purposes:

For the provision of services for your benefit

This general purpose may include, as appropriate, the following:
1) Creating and managing the account within our online platform;
2) Order processing, including taking over, validating, shipping and invoicing;
3) Solving cancellations or problems of any kind related to an order, the goods or services purchased;
4) Returning the products according to the legal provisions;
5) Reimbursement of the value of the products according to the legal provisions;
6) Providing support services, including providing answers to your questions about your orders or our goods and services.
The processing of your data for these purposes is in most cases necessary for the conclusion and performance of a contract between us and you. Also, certain processing subsumed for these purposes is required by applicable law, including tax and accounting law.

To improve our services

We always want to offer you the best online shopping / communication experience. To do this, we may collect and use certain information about your Buyer's behavior, we may invite you to complete satisfaction questionnaires subsequent to the completion of an order or we may conduct, directly or with the help of partners, market research and research. We base these activities on our legitimate interest in doing business, always making sure that your fundamental rights and freedoms are not affected.

For marketing

We want to keep you informed about the best offers for the products / services that interest you. In this regard, we can send you any type of message (such as: e-mail / SMS / telephone / mobile push / webpush / etc.) Containing general and thematic information, information on similar or complementary products to those that you have purchased, information about offers or promotions, information about products added to the "My Account / Cart" section or the "Account / Favorites" section, or have shown interest in purchasing them, as well as other business communications such as research market and opinion polls, and we can display personalized recommendations on the website and in the smartphone app. In order to provide you with information of interest to you, we may use certain data about your buyer behavior (eg products viewed / added to your wishlist / purchased) to create a profile for you. We always make sure that these processing is carried out in compliance with your rights and freedoms and that the decisions taken on the basis of them do not have legal effects on you and do not affect you in a similar way to a significant extent. In most cases, we base our marketing communications on your prior consent. You can change your mind and withdraw your consent at any time by:
- Change the settings in the client account in the "My subscriptions" section;
- Accessing the unsubscribe link displayed in the messages you receive from us; or through
- Contacting our address using our contact details. In certain situations, we may base our marketing activities on our legitimate interest in promoting and developing our business. In any case where we use information about you for our legitimate interest, we take care and take all necessary measures to ensure that your fundamental rights and freedoms are not affected. However, you can ask us at any time, by the means described above, to stop the processing of your personal data for marketing purposes, and we will process your request.

To defend our legitimate interests

There may be situations in which we use or transmit information to protect our rights and business. These may include:
- Measures to protect the website and users of our platform from cyber attacks;
- Measures to prevent and detect fraudulent attempts, including the transmission of information to the competent public authorities;
- Measures to manage various other risks.
The general basis of these types of processing is our legitimate interest in defending our commercial activity, it being understood that we ensure that all the measures we take guarantee a balance between our interests and your fundamental rights and freedoms.

As long as we keep your personal data

As a general rule, we will store your personal data as long as you have an account on our platform. You can always ask us to delete certain information or close your account permanently, stating that such data cannot be recovered.

To whom we transmit your personal data

Where applicable, we may transmit or provide access to certain personal data of yours to the following categories of recipients:

- companies within the same group of companies as ours;
- courier service providers; - if we sell products online;
- payment / banking service providers; - if we sell products online.

If we have a legal obligation or if it is necessary to defend a legitimate interest, we may also disclose certain personal data to public authorities.

We will establish technical and procedural measures to protect and ensure the confidentiality, integrity and accessibility of your personal data processed; We will prevent unauthorized use or access and we will prevent the breach of the security of personal data, in accordance with the legislation in force.

In which countries we transfer your personal data

We currently store and process your personal data in Romania.

Transfers to service providers and other third parties will always be protected by contractual commitments and, where appropriate, other guarantees, such as standard contractual clauses issued by the European Commission or certification schemes, such as the Privacy Shield for the protection of personal data. transferred from within the EU to the United States.

How we protect the security of your personal data

We are committed to ensuring the security of personal data by implementing appropriate technical and organizational measures, in accordance with the standards regarding the security of data on our servers.

The transmission of your personal data is done using state-of-the-art encryption algorithms and we store them on secure servers, while ensuring data redundancy.

Despite the measures taken to protect your personal data, we warn you that the transmission of information via the Internet, in general, or through other public networks, is not completely secure, there is a risk that the data may be seen and used by third parties. unauthorized parties. We cannot be held responsible for such vulnerabilities in systems that are beyond our control.

What rights do you have?

The General Data Protection Regulation gives you a number of rights in relation to your personal data. You may request access to your data, correct any errors in our files and / or object to the processing of your personal data. You may also exercise your right to complain to the competent supervisory authority or to go to court. Where applicable, you may also have the right to request the deletion of your personal data, the right to restrict the processing of your data and the right to data portability.

Target rights / Description

Access - You can ask us:

- to confirm if we process your personal data;
- provide you with a copy of this data;
- to provide you with other information about your personal data, such as the data we have, what we use it for, to whom we disclose it, if we transfer it abroad and how we protect it, how long we keep it, what rights you have , how you can make a complaint, where we obtained your data, to the extent that the information has not already been provided to you by this information.

Rectification - You may ask us to rectify or complete your inaccurate or incomplete personal data. We may try to verify the accuracy of the data before rectifying it.

Data deletion - You can ask us to delete your personal data / account from our platform permanently without any explanation in advance. Warning: Data cannot be recovered later.

Data portability - You can ask us to provide you with personal data in a structured, commonly used and automatically readable format, or you can request that it be "ported" directly to another data controller.

Opposition - You may object at any time, for reasons related to your particular situation, to the processing of your personal data under our legitimate interest, if you consider that your fundamental rights and freedoms prevail over this interest. You may also object at any time to the processing of your data for direct marketing purposes (including profiling), without giving any reason, in which case we will cease processing as soon as possible.

Claims - You have the right to lodge a complaint with the supervisory authority regarding the processing of your personal data. In Romania, the contact details of the data protection supervisory authority are the following:
National Authority for the Supervision of Character Data Processing

Personal
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, Bucharest, Romania
Phone: +40.318.059.211 or +40.318.059.212;
E-mail: anspdcp@dataprotection.ro

Without prejudice to your right to contact the supervisory authority at any time, please contact us in advance, and we promise that we will make every effort to resolve any issues amicably..

Subscribe to our Newsletter

Find out the latest news. Exclusive offers valid only for subscribers.