Privacy Policy

1 Introduction

Thank you for your interest in our company for our products and/or services.
The protection and confidentiality of personal data is a very important topic for us. When you enter into a relationship of any kind with us, you entrust us with your information. This information presented in this document (hereinafter referred to as "Privacy policy" or "Document") they are important.
We recommend that you read them carefully. The purpose of this Privacy Policy is to explain to you what data we process (collect, use, share), why we process it, how we process it, your rights. under the GDPR and how you can exercise these rights. In collecting this information, we are acting as an Operator and are required by law to provide this information to you.

Being fully aware that your personal information belongs to you, we do our best to store it securely and process it carefully. We do not provide information to third parties without informing you as required by law. We do not make exclusively automated decisions with a significant impact on you.  

By visiting our website www.tehmin.ro , purchase of products, services   nyours or by interacting with us by any means and/or through any communication channel (email, phone, social media, etc.), you agree to this Privacy Policy. If you do not agree with what is described in this Privacy Policy, please do not use the Services TEHMIN BRASOV SRL, being a data operator within the meaning of the General Regulation Regarding the Protection of Personal Data (GDPR).

2 Definitions

1.1. "GDPR", "GDPR" or "Regulation" means REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (Regulation general data protection).

1.2. "The operatoror "we" means Society TEHMIN BRASOV SRL,with registered office located at Str. Tudor Vladimirescu no. 47, Bod Locality, Brasov County, registered at the Trade Register Office  under no. J08/1639/2022 With Unique Identification Code – 15051207.

1.3. "Targeted person” means any identified or identifiable natural person whose data is processed by us as an operator, such as customers, potential customers or site visitors. 

1.4."Processing"means any operation or set of operations performed on personal data or sets of personal data, with or without the use of automated means, such as collecting, recording, organizing, structuring, storing, adapting or modifying, extracting, consulting , use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction;

1.5. "Consent"means any free, specific, informed and unambiguous manifestation of the data subject's will by which he accepts, through a statement or an unequivocal action, that the personal data concerning him be processed by the Operator;

1.6."Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more many specific elements, specific to its physical, physiological, genetic, psychological, economic, cultural or social identity.

The other terms used in this document have the meaning conferred by the GDPR and the other applicable legal provisions. 

3 Other Services

This Privacy Policy does not cover the applications and websites of other third parties that you may reach by accessing links on our website. This is beyond our control. We encourage you to review the Privacy Policy on any site and/or application before providing personal data.

4 Who are we?

Society TEHMIN BRASOV SRL, with its registered office located in Str. Tudor Vladimirescu no. 47 Bod Locality Brasov County, registered at the Trade Register Office under no. J08/1639/2002 With Unique Identification Code – 15051207 is responsible for the processing of your personal data that we collect directly from you or from other sources.  

According to the legislation, our company is a personal data operator. Because your data to be processed securely, we have made every effort to implement reasonable and appropriate technical and organizational measures to protect your data. personal. 

5 Who are you? 

According to the legislation, you, the natural person beneficiary of our services/products, the representative or contact person of a company that is our client or potential client, the website visitor or the person in a relationship of any kind with us, are a "data subject" means an identified or identifiable natural person. In order to be completely transparent about data processing and to allow you to easily exercise your rights at any time, we have implemented measures to facilitate the exercise of rights. 

6 Our commitment

Protection of your information personal is very important to us. That is why we are committed to complying with European and national legislation on the protection of personal data, in particular Regulation (EU) 679/2016, also known as GDPR, and the following principles: 

  • Legality, fairness and transparency

We process your data legal and fair. We are always transparent about the information we use, and you you are properly informed.

  • Control belongs to you

To the extent permitted by law, we provide you with the opportunity to review, modify, delete the personal data you have shared with us, and exercise your other rights.

  • Data Integrity and Purpose Limitation 

We use the data only for the purposes described at the time of collection or for new purposes compatible with the original ones. In all cases, our purposes are compatible with the law. We take reasonable steps to ensure that personal data is accurate, complete and up-to-date. 

  • Security

We have implemented reasonable personal data security measures in order to protect your personal information as best as possible. However, keep in mind that no website, app, or internet connection is completely secure.

7 change

We may change this Privacy Policy at any time. All updates and changes to this Policy are effective immediately, so please always read this Privacy Policy.

8 Your Information, Purposes, Legal Basis 

When you browse our website, when you send us a request by e-mail or contact us for any other purpose and through any other communication channel, you may provide us with the following personal data, which we collect directly from you. or from other sources, as we explain in the table below. 

 Personal data processed* Purpose/Purposes* Grounds/Legal Basis

Name

Address

  •  For the purpose of creating an account on the site.
  • For billing.
  • To comply with the law.
  • To prevent fraud and other crimes.
  • For direct marketing (only if we have your prior consent).

 The conclusion or execution of a contract - Art. 6 (1) b GDPR.

legal obligation – Art. 6 (1) c GDPR.

consent - Art. 6 (1) a) – (only for direct marketing).

 E-mail
  •  For the purpose of creating an account on the site.
  • For billing.
  • To comply with the law.
  • To prevent fraud and other crimes.
  • For direct marketing (only if we have your prior consent).

 The conclusion or execution of a contract - Art. 6 (1) b GDPR.

consent - Art. 6 (1) a) – (only for direct marketing).

legitimate interest - Art. 6 (1) f) GDPR.

 IP address

 

  •  to defend against cyber attacks.
  • to prevent fraud.
  • for network operation.
 legitimate interest - Art. 6 (1) f) GDPR

We collect most information directly from you. (for example, by filling in a form on the website). Most of the information is as described above, but there may be situations where we collect data from third parties (ie partners, platforms). 

In addition to the information indicated above, we may also collect the following information, depending on the circumstances:  

  • How you interact with our website(s) (for example, information about how and when you access our website or what device you use to access the website). For more information in this regard, we invite you to also read our Policy on the use of cookie modules.
  • Content of messages sent via messaging systems and e-mail.

In addition to the purposes listed in the table in the previous section, we also process personal data for the following purposes: 

  • To respond to your questions and requests and provide you with customer support service;
  • For marketing purposes, but only where we have your consent. PRE or where there is a legal exception to obtaining consent;
  • To provide and improve the services we offer;
  • To diagnose or fix technical problems;
  • To defend against cyber attacks;
  • To comply with legislation, such as compliance with tax legislation which requires us to keep accounting records for a period of 10 years;
  • In the unlikely event of litigation, to establish or claim a right in court.

8.1 Other information about legal grounds

(a) Legitimate Interest.  In the situation where we use legitimate interest, we perform a legitimate interest analysis (balancing test) through which we can balance our interest and your interests. In the situation where our interests prevail, we will use the legitimate interest. In the situation where your interests prevail, we will not use the legitimate interest, and to the extent that we fail to identify another correct legal basis, we will not carry out that processing activity.

(b) Consent. Please note that consent is not mandatory and we will proceed to obtain your consent. only in situations where we failed to use another legal basis. We currently only use consent for email marketing. 

(c) Vital Interest. In the unlikely event of a medical emergency or other exceptional event processing may be necessary to protect your vital interests. or of another natural person. 

9 Storage period

We store your data personal only for the period necessary to fulfill the purposes, but not more than 5 years after the termination of the contract or the last interaction with us.  

After the end of the period, personal data will be destroyed or deleted from computer systems or transformed into anonymous data to be used for scientific, historical or statistical research purposes.

Note that in certain expressly regulated situations, we store data for the period required by law.

10 Data Transfers

We may disclose your data, subject to applicable law, to business partners or other third parties. We always make reasonable efforts to ensure that these third parties have adequate protection and security measures in place. We have contractual clauses with these third parties so that your data to be protected. In these situations, we will ensure that any transfer is legitimate under the law.   

We may also pass on the data to other parties with your consent or according to your instructions, such as if you exercise a portability request.

We may also provide your information. personally and to the prosecutor's office, the police, the courts and other competent state bodies, based on and within the limits of the legal provisions and as a result of expressly formulated requests.

The transfer of personal data to a third country can only take place if the country to which the transfer is intended ensures an adequate level of protection.

The transfer of data to a state whose legislation does not provide a level of protection at least equal to that provided by the General Data Protection Regulation is possible only if there are sufficient guarantees regarding the protection of the fundamental rights of the data subjects. These guarantees will be established by us through contracts concluded with the suppliers/service providers to which your personal data will be transferred.

Whenever we transfer your personal data outside the EEA, we will ensure that there is a similar level of protection through one of the following safeguards:

  • we will transfer your personal data to countries where it has been demonstrated by the European Commission to provide an adequate level of security for personal data. 
  • when we use certain service providers, we may use certain model contracts provided and approved by the European Commission that give personal data the same protection as it has in Europe.

11 Data security

We understand how important the security of personal data is and take the necessary measures to protect our customers and other persons whose data we process from unauthorized access to personal data, as well as from the unauthorized modification, disclosure or destruction of data that we process in the current business .

We have implemented the following technical and organizational security measures for personal data:

Dedicated policies. We adopt and constantly review internal personal data processing practices and policies (including physical and electronic security measures) to protect our systems from possible unauthorized access or other possible threats to their security. These policies are subject to constant review to ensure that we comply with legal requirements and that the systems are working properly.

Last update: 27.07.2023