PRYWATNOŚĆ
Polityka przetwarzania danych osobowych
S.C. Great Food Labs S.R.L., siedziba w gminie Chiajna, powiat Ilfov, ul. Nuferilor nr 13, lok. 29, wieś Roșu, zarejestrowana w Rejestrze Handlowym pod nr J23/2238/07.04.2021, NIP 44072467.
1. Compliance
The company ensures compliance with EU Regulation 2016/679 (GDPR), Law 677/2001 and Law 506/2004 on the protection of personal data. This policy establishes key data protection principles and describes how the controller manages personal information collected through www.greatfood.ro.
2. Key definitions (Art. 4 GDPR)
- Personal data — information that identifies or can identify a natural person.
- Processing — operations performed on personal data (collection, recording, storage, modification, disclosure).
- Data controller — the entity that determines the purposes and means of processing.
- Data subject — the identified or identifiable person.
- Consent — a free, specific and informed expression of will accepting data processing.
- Data breach — accidental or unlawful destruction, loss, alteration or unauthorized disclosure.
- Supervisory authority — an independent public authority established by member states.
3. Processing principles
Data processing complies with the following principles:
- Lawful, fair and transparent processing.
- Collection limited to specific, explicit and legitimate purposes.
- Data accuracy, correctness and completeness are maintained.
- Storage duration is limited to what is necessary.
- Respect for data subjects' rights regarding integrity, security and confidentiality.
4. Consent requirements
Processing is lawful only when the data subject's informed and unambiguous consent is obtained. The company uses only the minimum data necessary, relevant to the stated purposes.
Personal data collected: first name, last name, address, phone, email.
5. Data subjects and their obligations
Data subjects include customers/users (natural persons) and authorized representatives of business partners, suppliers and service providers.
Data subjects must provide complete, current and accurate information. Refusal may prevent contract execution or service provision.
Providing personal data implies express consent for processing in accordance with applicable data protection legislation.
6. Withdrawal of consent
Data subjects may refuse processing or withdraw prior consent when data is no longer necessary for service provision, legal obligations or legitimate interests. Withdrawal applies only prospectively.
Data subjects may withdraw marketing consent at any time, without justification. Withdrawal does not affect the lawfulness of prior processing based on given consent.
Withdrawal is as simple as giving consent.
7. Purposes of data collection
By providing personal data, data subjects expressly consent to its use for:
- Commercial/contractual activity and order fulfilment.
- Billing and payment collection.
- Complaint/suggestion management.
- Marketing, promotional and advertising communications (general and personalized).
- Service development and improvement.
- Operational management (other entities may process data on the controller's behalf).
- Commercial communication with customers/suppliers.
- Fulfilment of legal obligations.
- Communication with authorities/public institutions.
- Audit, control and supervisory activities.
- Dispute and litigation resolution.
Additional processing purposes require prior notification and/or consent under applicable law.
8. Data sharing
The controller considers all information confidential and does not share it with third parties without express, prior consent — except for trusted business partners and service providers who maintain IT systems or provide services on the controller's behalf.
Service providers must:
- Use data exclusively according to the company's instructions and specified purposes.
- Adequately protect and maintain data confidentiality.
Exceptions to non-sharing:
- Transmission to competent authorities with legal authority to request data.
- Transmission to lawyers, bailiffs or courts if obligations are breached and legal rights are exercised.
- Only necessary data is transmitted to fulfil stated purposes.
9. Data processing for promotional/marketing purposes
Personal data (name, surname, address, email, phone) may be processed for:
- Marketing and direct marketing communications regarding the company's services.
- Commercial communications potentially with business partners through any communication method, including electronic services.
Data subjects are notified before data is used for direct marketing and may request cessation of processing at any time through unsubscribe options.
Request process: written, dated and signed request to contact@greatfood.ro, processed within 48 hours of registration.
After withdrawal, data subjects no longer receive commercial communications.
10. Data subject rights (under GDPR and Law 677/2001)
- Right to information — how and why personal data is used.
- Right of access — requesting access to personal data.
- Right to rectification/intervention — requesting correction of inaccurate/incomplete data.
- Right to erasure ("right to be forgotten") — requesting deletion when there are no compelling grounds for continued processing.
- Right to restriction of processing — requesting restriction when accuracy or legality is contested.
- Right to data portability — obtaining and reusing personal data for own purposes across different services.
- Right to object — objecting to specific types of processing.
- Right against automated decisions — not being subject to fully automated decisions with legal or similarly significant effects.
- Right to withdraw consent — withdrawing consent given for processing.
- Right to lodge a complaint — with the National Supervisory Authority for Personal Data Processing.
- Right to judicial remedy — access to courts of law.
11. Duration of data processing
The controller processes personal data throughout organizational activities, until the data subject or legal representative exercises the right to object/delete (except where processing is legally mandated or justified by legitimate interest).
After processing for collection purposes is completed, data is:
- Archived according to internal procedures, if objection/deletion rights are not exercised, or
- Destroyed according to legal requirements.
Data is kept only as long as necessary for stated purposes or as required by law, then irreversibly deleted or anonymized. For marketing purposes, data is stored until consent withdrawal, maximum 5 years.
12. Data security
The company uses security methods, technologies, policies and procedures to protect personal data.
Complete internet transmission security cannot be guaranteed. Data transmission involves a risk assumed by data subjects. Upon receipt, strict procedures and measures are applied to prevent unauthorized use, illegal activity, destruction, accidental loss or disclosure.
International transfers: transfers outside the EU and European Economic Area take place only in accordance with EU legislation and specific national protections for personal data processing.
13. Data breach protocol
In the event of data loss, damage, theft, compromise or complaints regarding data management:
- Report the breach to the National Supervisory Authority for Personal Data Processing within 72 hours of discovery.
- Notify affected persons without undue delay.
- Make reasonable efforts to limit the damage.
14. Response time for requests
Requests to exercise the above-mentioned rights receive a response within 30 days, with the possibility of extension after notifying the data subject with justified reasoning.
15. Remedies for manifestly unfounded requests
When data subjects, directly or through representatives, exercise rights in a manifestly unfounded, unjustified or excessive manner (especially repeatedly), the controller may:
- Charge reasonable fees reflecting administrative costs for providing information or requested measures, or
- Refuse the request.
For exercising objection rights in a manifestly unfounded manner, especially repeatedly, the controller may consider the contract terminated by operation of law, without any formality or judicial intervention, except for prior notification.
16. Data protection contact
To exercise your rights: written, dated and signed request to contact@greatfood.ro.
17. Confirmation
By reading and signing this document, data subjects confirm:
- Receipt of an informed, complete and accurate notification.
- Full understanding of and agreement with the provisions.
- Acknowledgment that personal data constitutes essential elements for access to services and commercial/contractual activity.
