Privacy policy

The protection of the information obtained during the processing of personal data is a major concern for us, which is why all personal data is processed in accordance with the legal provisions in force in the European Union and in national law. We pay the utmost attention to personal data and their protection, but we also place great importance on informing data subjects in detail. Therefore, by means of the principles below, we wish to inform in extenso about the personal data we collect and process.

WHO WE ARE

This privacy policy is assumed by

Safe & Quality Textiles Srl, personal data controller, based in Constanța, str. Dinu Lipatti, nr. 14, et. 3, ap. 14, jud. Constanta, registered in the Trade Register under no. J13/3672/2023, CIF: 49068785, e-mail: contact@ateliersisa.ro; telephone: 0790738873; which operates the website www.ateliersisa.ro

The Company, hereinafter referred to as the Operator, processes personal data lawfully and responsibly, by complying with Regulation (EU) No 679/2016 (hereinafter referred to as GDPR) and the provisions of national law and by implementing and periodically reviewing organizational and technical security measures.

DEFINITIONS

personal data of the data subject – any information relating to an identified or identifiable natural person (data subject); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity;
processing of personal data – any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure to third parties by transmission, dissemination or otherwise, alignment or combination, blocking, erasure or destruction;
storage – keeping personal data collected on any kind of support;
personal data filing system – any organized personal data structure, accessible according to specific criteria, regardless of whether this structure is organized in a centralized or decentralized manner or is distributed according to functional or geographical criteria;
controller – any natural or legal person, whether governed by private or public law, including public authorities, institutions and their territorial structures, who determines the purpose and means of processing personal data;
third party – any natural or legal person, whether governed by private or public law, including public authorities, institutions and their territorial structures, other than the data subject, the controller or the processor or persons who, under the direct authority of the controller or the processor, are authorized to process data;
addressee – any natural or legal person, whether governed by private or public law, including public authorities, institutions and their territorial structures, to whom data are disclosed, regardless of whether or not they are third parties; public authorities to whom data are disclosed under a special investigation power shall not be considered as addressees;
anonymized data – data which, due to their origin or the specific way in which they are processed, cannot be associated with an identified or identifiable person;
statistical data – data that have been obtained as a result of the processing of personal data by the controller but which cannot be used to identify a person and are used exclusively for statistical and/or informational, promotional purposes.

PRINCIPLES OF PERSONAL DATA PROCESSING

Personal data must be processed lawfully, fairly and transparently
Personal data may only be collected for specific, explicit and legitimate purposes
Personal data must be adequate, relevant and limited to what is necessary
Personal data that is inaccurate, having regard to the purposes for which it is processed, shall be erased or rectified without delay (“accuracy”)
Personal data must be kept in a form which permits identification of the data subject only for as long as necessary for the processing
Personal data must be processed in a manner which ensures appropriate security
Demonstration of compliance with the other principles of the GDPR (accountability)

CATEGORIES OF PERSONAL DATA PROCESSED

Most of the time, the personal data detailed below is processed directly from data subjects when they create an account on the website, when they place an order, when they send us e-mails.

Through the www.ateliersisa.ro website, the following types of personal data are processed: name and surname; date of birth; e-mail address; telephone (landline and mobile); home/mailing address; IP, browser used and records of the behavior of the visitor of the www.ateliersisa.ro website.

We do not process special personal data as defined by the GDPR. We also do not wish to collect or process data from minors under the age of 16.

PURPOSES AND GROUNDS FOR PROCESSING

The personal data mentioned above are processed for the following purposes:

1. invoicing the products purchased by the data subjects;
2. solving problems related to the products ordered and shipped to the data subjects (return, refund of the amounts paid for returned items);
3. creating and managing the user account on the website;
4. delivery, by express courier service, of the ordered products;
5. communication of information between the parties relating to the purchased products;
6. providing support, including providing answers to questions that data subjects send us via chat.
7. notifying the availability of items previously signaled by data subjects through the management of the “wish list” tool made available to customers who have created an account on the site;
8. evaluating the products and services offered.

Data processing for these purposes (1 – 10) takes place pursuant to Art. 6, para. 1, lit. a, b, c of the GDPR and is in most cases justified by our legitimate interest and the conclusion and performance of a contract (distance contract) between the Controller and the data subject. Also, some processing determined by these purposes is required by applicable tax and accounting legislation.

9. electronic transmission of general and thematic newsletters, as well as other communications of the same invoice. The newsletter is sent via the MailChimp service. The name and e-mail address are securely stored in the MailChimp application. Specifically, data subjects’ data cannot be accessed by third parties or other MailChimp customers. Only the Operator has access to and uses the data subjects’ data for sending newsletters. The consent given to receive the newsletter (obtained by clicking the “Subscribe” button on our website) can be withdrawn at any time by writing to us at contact@ateliersisa.ro or by unsubscribing directly from the newsletter received at
10. sending special discount codes for future orders of customers with accounts

These processings (12, 13) are subsumed under the general purpose of promotion/marketing and are provided for in art. 6, para. 1, lit. a and/or f of the GDPR. We base our marketing activities on our legitimate interest to develop/promote our business. We ensure that they are carried out with due respect for the rights and freedoms of the data subjects and that the decisions taken on the basis of them do not affect them to a significant extent.

12. improving the services we provide to data subjects.

For this purpose, we may process some information in relation to the behavior of the buyer/visitor of the website www.ateliersisa.ro. We base this type of processing, which takes place pursuant to art. 6, para. 1, lit. f of the GDPR, on our legitimate interest to carry out commercial activities, always taking care that the fundamental rights and freedoms of data subjects are not affected.

The processing of personal data is done by automated and manual means.

DATA RETENTION AND DELETION PERIOD

The Controller shall not keep personal data in a form which allows the identification of data subjects for longer than necessary in relation to the purpose(s) for which the data were originally collected. We process and store personal data for a period of time absolutely necessary to secure all rights and obligations arising, for example, from the sales contract, specifically for the duration of the order and the warranty period. Personal data must be disposed of securely, thus protecting the rights and freedoms of the data subjects.

DISCLOSURE OF DATA TO THIRD PARTIES AND AUTHORIZED PERSONS; INTERNATIONAL TRANSFER

The operator shall ensure that personal data is not disclosed without the data subject’s consent to unauthorized third parties, which include family members, friends, governmental bodies acting without explicit legal basis in relation to the purpose of their requests. All employees must be careful when asked to disclose personal data held by another person to a third party. The GDPR permits certain disclosures without consent as long as the information is required for one or more of the following purposes: to protect national security; to prevent or detect criminal offenses; to prevent serious harm to a third party; and to protect the vital interests of the individual.

Personal data processed by the Operator are/may be shared with the following categories of recipients:

a) the data subject;
b) the Operator’s partners with the same management structure as the Operator;
c) courier service providers;
d) banking service providers;
e) payment service providers;
f) companies providing services related to the functioning of information systems;
g) companies providing hosting services.
h) public authorities (courts of law or arbitration, notaries public, lawyers, bailiffs, bailiffs, other authorized services), if we have a legal obligation to do so or if it is necessary to protect a legitimate interest.

When we use a natural or legal person as a processor of a part of the personal data, we will ensure that he or she assumes the obligations to process the personal data according to our instructions and to implement measures to protect the confidentiality of personal data.

We do not transfer the personal data of data subjects to other companies, organizations or persons in third countries.

DATA PROTECTION AND SECURITY

The Operator, together with all of its employees, are responsible for ensuring that all personal data held by the Operator is kept secure and is not disclosed in any way to a third party unless that third party has been specifically authorized to receive such information.

All personal data must be accessible only to those who need to use it.

All personal data must be processed securely and must be kept in a locked/access-controlled room; and/or in a locked drawer or cabinet; and/or if stored on computers, password protected.

PC screens and terminals must not be visible to anyone other than authorized employees/staff.

Physical records may not be left where they can be accessed by unauthorized personnel and may not be removed from the premises without explicit authorization. As soon as records in physical format are no longer required for day-to-day customer use, they must be securely destroyed.

For the processing of personal data, the Operator applies the necessary technical and organizational measures in order to ensure their security, protection against accidental or unlawful destruction or accidental or unlawful alteration, unauthorized disclosure or access, according to industry standards. Permanent improvement of information security measures is one of the Operator’s priorities.

The www.ateliersisa.ro page is hosted on a secure server in Romania. The data of data subjects is transmitted in encrypted form. We use the SSL (secure socket layer) encryption system. Access to the customer account is possible only after entering the personal password. It is very important that the login data is not disclosed to third parties and that the browser window is closed after the visit to the client account.

RIGHTS OF DATA SUBJECTS

Under the GDPR, data subjects have the following rights:

– information
– access to data
– rectification
– erasure of data
– restriction of processing
– data portability
– objection to data processing
– right not to be subject to automated individual processing

Data subjects may apply to the courts or to the National Supervisory Authority for Personal Data Processing (info: www.dataprotection.ro, tel. 0318059 211) to protect the rights mentioned. These rights are set out in detail in Articles 12 to 23 of the GDPR. These rights can be exercised at any time, by e-mail to contact@ateliersisa.ro; or, by post/mail to Safe & Quality Textiles Srl , str. Dinu Lipatti, nr. 14, et. 3, ap. 14, loc. Constanța, jud. Constanța.

We reserve the right to make any additions or changes to this document whenever we deem it necessary.