Document sablon. Acest document este un sablon initial conform GDPR (Regulament UE 2016/679) si trebuie revizuit de un consultant juridic / DPO inainte de publicare oficiala.
01Operatorul de dateData controller
Operatorul datelor cu caracter personal colectate prin intermediul site-ului eccogroup.ro este:The controller of personal data collected through the eccogroup.ro website is:
- Ecco Group
- Sediul social: Strada Magura Vulturului 58, etaj 1, sector 2, Bucuresti, RomaniaRegistered office: Magura Vulturului 58, 1st floor, district 2, Bucharest, Romania
- Email contact GDPR: office@epin.roGDPR contact email: office@epin.ro
02Date colectateData collected
Site-ul nostru poate colecta urmatoarele categorii de date cu caracter personal:Our site may collect the following categories of personal data:
Date furnizate voluntarVoluntarily provided data
- Nume, prenume, denumire companieFirst name, last name, company name
- Adresa de email, numar de telefonEmail address, phone number
- Continutul mesajelor trimise catre noiContent of messages sent to us
Date colectate automatAutomatically collected data
- Adresa IP, tipul si versiunea browser-uluiIP address, browser type and version
- Sistemul de operare si dispozitivul utilizatOperating system and device used
- Paginile vizitate, durata vizitei, click-uriPages visited, visit duration, clicks
- Cookies (vezi Politica de Cookiessee Cookie Policy)
03Scopul prelucrariiPurpose of processing
Datele sunt prelucrate in urmatoarele scopuri:Data is processed for the following purposes:
- Raspuns la intrebari si solicitari de integrareResponding to integration inquiries and requests
- Comunicari comerciale (cu acord prealabil)Commercial communications (with prior consent)
- Analiza statistica anonimizata a traficuluiAnonymized statistical traffic analysis
- Imbunatatirea continua a site-ului si serviciilorContinuous improvement of site and services
- Indeplinirea obligatiilor legale (fiscalitate, contabilitate)Fulfilling legal obligations (taxation, accounting)
04Temeiul legalLegal basis
Prelucrarea datelor se bazeaza pe:Data processing is based on:
- Consimtamantul dvs. (Art. 6 alin. 1 lit. a GDPR) — pentru newsletter, marketing directConsent (GDPR Art. 6(1)(a)) — for newsletter, direct marketing
- Executarea unui contract (Art. 6 alin. 1 lit. b) — pentru integrari B2BContract performance (Art. 6(1)(b)) — for B2B integrations
- Obligatie legala (Art. 6 alin. 1 lit. c) — facturare, raportari fiscaleLegal obligation (Art. 6(1)(c)) — invoicing, tax reporting
- Interes legitim (Art. 6 alin. 1 lit. f) — securitate site, prevenirea fraudeiLegitimate interest (Art. 6(1)(f)) — site security, fraud prevention
05Perioada de stocareStorage period
Datele sunt pastrate doar atat cat este necesar pentru scopurile declarate sau conform obligatiilor legale:Data is retained only as long as necessary for stated purposes or legal obligations:
- Date contractuale: 10 ani de la incheierea relatiei contractualeContract data: 10 years after contract termination
- Date de marketing: pana la retragerea consimtamantuluiMarketing data: until consent withdrawal
- Date de trafic: maxim 24 luniTraffic data: maximum 24 months
06Drepturile dvs.Your rights
Conform GDPR, beneficiati de urmatoarele drepturi:Under GDPR, you benefit from the following rights:
- Dreptul de acces — sa fiti informat ce date prelucram despre dvs.Right of access — to be informed what data we process about you
- Dreptul de rectificare — sa cereti corectarea datelor incorecteRight to rectification — to request correction of incorrect data
- Dreptul de stergere ("dreptul de a fi uitat")Right to erasure ("right to be forgotten")
- Dreptul la restrictionarea prelucrariiRight to restrict processing
- Dreptul la portabilitatea datelorRight to data portability
- Dreptul de opozitieRight to object
- Dreptul de a nu fi supus unor decizii automateRight not to be subject to automated decisions
07Cum exercitati drepturileHow to exercise your rights
Puteti exercita oricand drepturile prin email la office@epin.ro cu mentiunea "GDPR — solicitare drepturi". Vom raspunde in maxim 30 de zile.You can exercise your rights at any time by email to office@epin.ro with the subject "GDPR — rights request". We will respond within 30 days.
08PlangeriComplaints
Aveti dreptul sa depuneti o plangere la ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal): dataprotection.roYou have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP): dataprotection.ro
09Securitatea datelorData security
Implementam masuri tehnice si organizationale adecvate pentru protectia datelor (criptare TLS, acces restrictionat, audit-uri periodice). Suntem certificati ISO 27001 (securitatea informatiei).We implement appropriate technical and organizational measures to protect data (TLS encryption, restricted access, periodic audits). We are ISO 27001 certified (information security).
10ModificariChanges
Politica poate fi actualizata periodic. Modificarile substantiale vor fi notificate prin banner pe site cu cel putin 30 zile inainte de aplicare.This policy may be updated periodically. Substantial changes will be notified via site banner at least 30 days before application.