

POLICY
REGARDING THE PROCESSING OF PERSONAL DATA
Respecting your privacy is one of our fundamental commitments, and therefore, we pay the utmost attention to processing your personal data in accordance with applicable laws.
ZADA WEB SYSTEMS S.R.L., headquartered at STR. ȘCOALA FLOREASCA, NR.34, CAMERA 1, BL.LOT A, ET.1, AP.LOT 3, Bucharest, Sector 1, fiscal identification code 46368745, registered with the Trade Registry under no. J40/12110/2022 ("ZADA WEB SYSTEMS S.R.L.", "we") processes, as a controller, your personal data ("Personal Data"). The purpose of this notice ("Policy") is to detail how ZADA WEB SYSTEMS S.R.L. processes your Personal Data.
Personal data processed: name, surname, email address, phone number.
Purpose of Processing |
Legal Basis |
|---|---|
Online customer contact regarding requested offers or addressing reported issues |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: name, surname, payment amount, bank card details.
Purpose of Processing |
Legal Basis |
|---|---|
Processing payment for purchased products |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: name, surname, purchased products, delivery address, phone number, any additional information provided by the customer.
Purpose of Processing |
Legal Basis |
|---|---|
Delivering the placed order |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: name, surname, product added.
Purpose of Processing |
Legal Basis |
|---|---|
Adding the product to the shopping cart |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: name, surname, purchased products, delivery address, phone number, email address, any additional information provided by the client.
Purpose of Processing |
Legal Basis |
|---|---|
Finalizing and placing the order |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: name, surname, home address, purchased products, payment amount.
Purpose of Processing |
Legal Basis |
|---|---|
Issuance of invoices for purchased products |
Compliance with a legal obligation of the Company (Art. 6, para. 1, letter c of GDPR) |
Personal data processed: name, surname, email address.
Purpose of Processing |
Legal Basis |
|---|---|
Creating the client's user account |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: image.
Purpose of Processing |
Legal Basis |
|---|---|
Completing the user's profile |
Consent of the data subject (Art. 6, para. 1, letter a of GDPR) |
Personal data processed: name, surname, order date, ordered products, payment amount.
Purpose of Processing |
Legal Basis |
|---|---|
Displaying the order history |
Execution of a contract to which the data subject is a party or to take steps at the request of the data subject before entering into a contract (Art. 6, para. 1, letter b of GDPR) |
Personal data processed: name, surname, phone number, email address.
Purpose of Processing |
Legal Basis |
|---|---|
Sending commercial messages to promote the company’s services |
Consent of the data subject (Art. 6, para. 1, letter a of GDPR) |
Personal data processed: name, surname, email address, other information provided by the client.
Purpose of Processing |
Legal Basis |
|---|---|
Requesting and analyzing customer feedback to improve services |
Consent of the data subject (Art. 6, para. 1, letter a of GDPR) |
Personal data processed: name, surname, home address.
Purpose of Processing |
Legal Basis |
|---|---|
Defending rights and legitimate interests and supporting claims before judicial bodies or other public authorities |
Legitimate interest of the Company (Art. 6, para. 1, letter f of GDPR) |
You may refuse to provide certain Personal Data, but in such a case, you may not be able to benefit from specific services related to this Policy.
The legal basis for processing varies depending on the specific situation and the Personal Data processed.
In situations where we process your Personal Data based on consent, we will request your free, informed, specific, and unequivocal consent for that processing. By expressing your consent, you agree that we may collect, use, disclose, process, and transfer Personal Data in accordance with this Policy.
The source of Personal Data is: the online client.
Your Personal Data will not be processed for generating decisions based solely on automated processing that would produce legal effects on you or significantly affect you, as provided by Art. 22 (1) of GDPR.
The duration of processing Personal Data varies depending on the specific processing operation:
Operation |
Duration |
Contacting the online client |
The time required to resolve the request |
Making a payment |
Until payment completion |
Order delivery |
The time required to deliver the products |
Adding to the shopping cart |
Until the order is finalized or until the products are removed from the cart |
Placing an order |
3 years |
Issuing an invoice |
10 years |
Creating a user account |
The duration of the account's existence |
Completing the user profile |
The duration of the account's existence |
Order history |
The duration of the account's existence |
Commercial messages |
Until consent is withdrawn |
Customer feedback |
The time required to analyze the feedback |
Litigation issues |
The time required to resolve the dispute |
In certain circumstances, we may retain Personal Data for longer periods to maintain an accurate record of your relationship with us in the event of complaints or if we reasonably believe there is a prospect of litigation.
We may transfer Personal Data, to the extent necessary, to the following categories of recipients: IT service providers, payment service providers, courier service providers, accounting service providers, marketing service providers, state authorities.
These recipients may be located within the European Union and/or the European Economic Area, as well as outside these areas, including in countries not recognized as providing an adequate level of protection. In such cases, the transfer of Personal Data is carried out only if adequate safeguards exist, in accordance with applicable law (such as standard contractual clauses issued by the European Commission). You may request a list of recipients in third countries, as well as a copy of the agreed provisions ensuring an adequate level of protection for Personal Data.
The security of your Personal Data is important to us. Therefore, your Personal Data will be processed by applying reasonable technical and organizational measures to protect them, such as limiting access to Personal Data, encrypting or anonymizing Personal Data, and storing them on secure media. However, despite our efforts, we cannot always guarantee the effectiveness of the implemented security measures and, therefore, cannot guarantee the security of Personal Data at all times.
Right of Access: You have the right to obtain confirmation from us that your Personal Data is being processed, as well as information about the specifics of the processing, such as: the purpose, categories of processed Personal Data, their recipients, the period for which they are retained, their source, whether we transfer them abroad and how we protect them, your rights, and your right to file a complaint with the supervisory authority.
Right to Rectification: You have the possibility to request the correction of your Personal Data, provided the applicable legal requirements are met. In the event of errors, we will promptly correct your Personal Data after notification.
Right to Erasure: In certain cases, you may request the deletion of Personal Data, such as when: (i) they are no longer necessary for the purposes for which we collected and processed them; (ii) you have withdrawn your consent for the processing, and we can no longer process the Personal Data on other legal grounds; (iii) the Personal Data is processed unlawfully; (iv) you exercise a legal right to object. We are not obligated to comply with your deletion request if the processing of Personal Data is necessary to comply with a legal obligation or for the establishment, exercise, or defense of a legal claim. Additionally, there are other circumstances where we are not required to honor such a request.
Right to Restrict Processing: You may request that we restrict the processing of your Personal Data in the following situations: (i) when you contest the accuracy of the Personal Data, for a period that allows us to verify their accuracy; (ii) when the processing is unlawful, and you oppose the deletion of Personal Data, requesting instead the restriction of their use; (iii) when we no longer need the Personal Data for processing purposes, but you require them for legal action; (iv) when you have objected to processing, for the time required to determine whether our legitimate rights as a data controller prevail over those of the data subject. We may continue to use Personal Data following a restriction request if: (i) we have your consent; (ii) to establish, exercise, or defend a legal claim; or (iii) to protect the rights of another natural or legal person.
Right to Data Portability: If Personal Data is processed based on your consent or for the execution of a contract, and processing is carried out by automated means, you have the right to have your Personal Data provided to you in a structured, commonly used, and machine-readable format and the right to transmit this data to another controller. This right does not negatively affect the rights and freedoms of others.
Right to Object: In certain situations, such as when we process your Personal Data based on a legitimate interest, you have the right to object to our processing of your Personal Data. In cases of unjustified opposition, ZADA WEB SYSTEMS S.R.L. is entitled to continue processing the Personal Data. Additionally, you may object to the processing of your Personal Data for commercial message purposes.
Withdrawal of Consent: Where we process your Personal Data based on your consent, you may withdraw your consent at any time without affecting the legality of processing based on consent before its withdrawal.
Automated Individual Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you in a similar way. This right is not applicable when the decision: (i) is necessary for entering into or performing a contract between you and us; (ii) is authorized by law, which also provides adequate safeguards for your rights and freedoms; (iii) is based on your explicit consent.
Right to Lodge a Complaint: You have the right to file a complaint with the National Authority for the Supervision of Personal Data Processing ("ANSPDCP") regarding any violation of your rights concerning the processing of your Personal Data. The contact details of ANSPDCP are: G-ral. Gheorghe Magheru Blvd 28-30, Sector 1, postal code 010336, Bucharest, Romania; e-mail: anspdcp@dataprotection.ro.
To exercise the rights mentioned above, please contact us at: office@zadawebsystems.com.
If you have any questions or concerns about this Policy or its implementation, please contact us at: office@zadawebsystems.com.