LEGAL_DOCUMENT_V1.0 · GDPR_COMPLIANT

Privacy
Policy

Last Updated: April 2025 · Technik Solutions S.R.L. · Reg. J40/XXXX/2020 · CUI ROXXXXXXXX

DATA CONTROLLER

Technik Solutions S.R.L., headquartered in Bucharest, Romania, is the data controller for all personal data collected through this platform. We are committed to protecting your privacy in accordance with Regulation (EU) 2016/679 (GDPR) and Romanian national data-protection law. This policy explains what data we collect, why we collect it, and what rights you have over it.

/ 01

Data We Collect

AUTH_CODE: PP-COLLECTED SYS_VER_2.4.0

We collect the following categories of personal data when you use our platform:

CategoryData PointsCollection Method
IdentityFirst name, last nameRegistration form / Google OAuth
ContactEmail address, phone numberRegistration form, checkout
AccountPassword hash, authentication tokensCreated automatically on registration
CommercialOrders, returns, invoices, favouritesYour activity on the platform
BillingInvoice details, VAT number, company nameBilling profile form
DeliveryDelivery address, recipient nameDelivery address form
TechnicalIP address, browser type, session data, cookiesAutomatically on each visit
BehaviouralPages visited, search queries, click eventsAnalytics cookies (with consent)
/ 02

Why We Process Your Data

AUTH_CODE: PP-PURPOSES SYS_VER_2.4.0

We process personal data only for specified, explicit, and legitimate purposes. The table below maps each purpose to its legal basis under GDPR Article 6:

PurposeLegal Basis
Creating and managing your accountPerformance of a contract (Art. 6(1)(b))
Processing and fulfilling ordersPerformance of a contract (Art. 6(1)(b))
Issuing invoices and managing billingLegal obligation (Art. 6(1)(c)) · Romanian fiscal law
Processing return and refund requestsPerformance of a contract (Art. 6(1)(b))
Sending order confirmation and status emailsPerformance of a contract (Art. 6(1)(b))
Sending marketing communicationsConsent (Art. 6(1)(a)) · Opt-in only
Improving platform performance via analyticsConsent (Art. 6(1)(a)) · Cookie consent
Fraud detection and securityLegitimate interests (Art. 6(1)(f))
Complying with tax and accounting obligationsLegal obligation (Art. 6(1)(c))
/ 03

Data Retention

AUTH_CODE: PP-RETENTION SYS_VER_2.4.0

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:

  • Account data: retained for the duration of your account. Deleted within 30 days of account closure request, subject to legal hold requirements.
  • Order and invoice data: retained for 10 years in accordance with Romanian fiscal and accounting legislation (Legea contabilității nr. 82/1991).
  • Technical and log data: retained for up to 12 months for security and debugging purposes.
  • Marketing consent records: retained until consent is withdrawn plus an additional 3 years for compliance evidence.
  • Cookie data: session cookies expire at browser close; persistent analytics cookies expire after 12 months.
/ 04

Data Sharing & Third Parties

AUTH_CODE: PP-SHARING SYS_VER_2.4.0

We do not sell your personal data. We share data only with the processors listed below, under written data-processing agreements, and solely to the extent necessary:

  • Courier and logistics partners — for delivery address and recipient name only.
  • Payment processors — for transaction authentication. We do not store card numbers.
  • Cloud infrastructure providers (EU-based) — for hosting the platform and its database.
  • Email delivery services — for transactional and, with consent, marketing emails.
  • Analytics platforms — aggregated, anonymised data only, subject to your cookie consent.
  • Accounting and auditing firms — only invoice and fiscal data, under strict confidentiality requirements.

⚠ Any transfer of data outside the EU/EEA is governed by Standard Contractual Clauses (SCCs) approved by the European Commission.

/ 05

Security Measures

AUTH_CODE: PP-SECURITY SYS_VER_2.4.0

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction:

  • All data in transit is encrypted using TLS 1.3.
  • Passwords are never stored in plain text — only salted hashes using bcrypt.
  • Access to production systems is restricted to authorised personnel via role-based access control.
  • Authentication tokens use cryptographically secure random generation with short expiry windows.
  • The platform undergoes regular security audits and dependency vulnerability scans.
  • Databases are backed up daily and stored in encrypted form in a geographically separate location.
/ 06

Cookies & Tracking

AUTH_CODE: PP-COOKIES SYS_VER_2.4.0

Strictly Necessary Cookies

These cookies are required for the platform to function (session management, authentication, CSRF protection). They cannot be disabled and do not require consent.

Analytics Cookies

With your consent, we use analytics cookies to understand how visitors interact with the platform. This data is aggregated and anonymised. You can withdraw consent at any time via the cookie settings panel.

Marketing Cookies

We do not currently use marketing or tracking cookies for advertising purposes. If this changes, we will request your explicit consent before activating them.

⚠ Cookie consent is managed via our in-platform cookie banner. You may update your preferences at any time.

/ 07

Minors

AUTH_CODE: PP-MINORS SYS_VER_2.4.0

Our platform is intended for use by individuals aged 18 and over, or by businesses acting through authorised representatives. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected such data, we will delete it promptly. If you believe a minor has registered on our platform, please contact us immediately at privacy@technik-solutions.ro.

/ 08

Your GDPR Rights at a Glance

Right of Access

Request a copy of all personal data we hold about you (Art. 15 GDPR).

Right to Rectification

Ask us to correct inaccurate or incomplete personal data (Art. 16 GDPR).

Right to Erasure

Request deletion of your data where there is no overriding legal basis to retain it (Art. 17 GDPR).

Right to Restriction

Ask us to pause processing your data in certain circumstances (Art. 18 GDPR).

Right to Portability

Receive your data in a structured, machine-readable format or have it transferred to another controller (Art. 20 GDPR).

Right to Object

Object to processing based on legitimate interests or for direct marketing at any time (Art. 21 GDPR).

PRIVACY_CONTACT

Exercise Your Rights

To make a data request or file a complaint, contact our privacy team. We respond within 30 days as required by GDPR.

privacy@technik-solutions.ro

Mon–Fri · 09:00–17:00 EET

Supervisory Authority: ANSPDCP · anspdcp.ro

This Privacy Policy is governed by Romanian law and Regulation (EU) 2016/679 (GDPR). Technik Solutions S.R.L. reserves the right to update this policy at any time. Continued use of the platform constitutes acceptance of any revised policy.

STATUS: PENDING_APPROVAL

Cookie Settings

This system utilizes cryptographic identifiers (cookies) for operational performance and deployment metrics.