Privacy policy

This privacy policy determines how Pensiunea Negoiu (“we”) collects, stores and uses information about you when you use or interact with the Pensiuneanegoiu.ro website, applications and/or services offered.

By accessing or using this site and / or any information, tools and documents contained or described in it, you declare that you understand and confirm at all times the privacy policy in the current version. If you do not agree to this, it is not possible to access and use our website.

  1. About us

You can contact us by sending an e-mail to info@pensiuneanegoiu.ro . If you have any questions about this privacy policy, please contact us via the email address provided.

  1. The information we collect when you visit our website

We collect and use information from website visitors in accordance with this section as well as section 9 below.

2.1 Information regarding server logins.We use a third-party server to host our site pensioneanegoiu.ro. The server automatically records the IP address you use to access our website, as well as other information about your visit, such as the pages accessed, the information requested, the date and time of the request, the source of your access to our website ( eg the website or URL (link) through which you arrived at our site), and your browser version and operating system. Our server is located in Romania.

2.2 Use of information stored on the server for IT security purposes. We and our third-party hosting providers collect and store logs on the server to ensure network and information security so that the server and site are not compromised. This includes analyzing log files to help identify and prevent unauthorized access to our network, the distribution of malware, preventing server attacks and other cyber attacks by detecting unusual or suspicious activity.

(i) Legal basis for processing:compliance with a legal obligation to which we are subject (Article 6 paragraph (1) letter (c) of the General Data Protection Regulation).

Legal obligation:we have a legal obligation to implement technical and organizational measures necessary to ensure a level of security appropriate to the risk of processing personal information. Logging access to our website using server log files is one such measure.

 

(ii) Legal basis for processing:our legitimate interests and those of third parties [Article 6(1)(f) of the General Data Protection Regulation].

Legitimate interests:we and our third-party hosting provider have a legitimate interest in using your information to ensure network and information security.

2.3 Use of website server login information to analyze website usage and improve the website.We use information collected through logins to our site to analyze how users interact with the site and its features. For example, we analyze the number of visits and unique visitors we receive, the time and date of the visit, the location of the visit, the operating system and the browser used. We use the information collected from analyzing this information to improve our website. For example, we use the information collected to modify the information, content and structure of the site and individual pages based on how users interact and how long they spend on certain pages on our site.

Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:improving our website for users and learning about their preferences so that our website can better meet their needs and wants.

2.4 Use of cookies and similar technologies.Cookies are data files that are sent from a website to a browser to record user information for various purposes. We use cookies and similar technologies on our website, including essential, functional, analytical and targeting cookies and web beacons. For more information on how we use cookies, see our cookie policy.

You can reject some or all of the cookies we use on or through our site by changing your browser settings, but this may affect your ability to use our site or some or all its functionalities. For more information about cookies, including changing your browser settings, visitwww.allaboutcookies.orgor see our cookie policy.

  1. The information we collect when you interact with our site

We collect and use information from individuals who interact with certain features of our website in accordance with this section, as well as section 9 below.

3.1 Registering on our website. When you register and create an account on our site, we collect the following information: your username, email address, IP address, avatar image and any other information you provide us when you complete the registration form. If you do not provide the mandatory information required by the registration form, then you will not be able to register or create an account on our site.

 

Legal basis for processing:it is necessary to perform a contract or to take steps at your request before a contract is concluded (Article 6(1)(b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:creating an account on our website is necessary to purchase the products from our offer.

Transfer and storage of your information The information you provide to us through the registration form on our website will also be stored outside the European Economic Area. For further information on the safeguards used when your information is transferred outside the European Economic Area, see section 9 below.

  1. Information we collect when you contact us

We collect and use information from people who contact us in accordance with this section and section 9 below.

4.1 Contact by e-mail.When you send an e-mail to the e-mail address displayed on our website, we collect your e-mail address and any other information you provide in that e-mail (such as your name, your . of phone number and the information contained in the email signature).

(i) Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:we respond to questions and messages we receive and keep track of electronic correspondence.

(ii) Legal basis for processing:necessary to conclude a contract or to take steps at your request before concluding a contract (Article 6(1)(b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:where your message is about the provision of goods or services or taking steps at your request before we provide you with our goods and services (for example, providing information about such goods and services); we will process your information to do this.

Transferring and storing your informationWe use a third-party email provider to store the emails you send. For more information, see the section of this privacy policy entitled Transfer of your information outside the European Economic Area.

4.2 Contact via the contact form on the website.When you contact us using the contact form on our website, we collect your name, email address and IP address. We also collect any other information you provide us when you complete the contact form. If you do not provide the mandatory information requested by the contact form, you will not be able to submit the contact form and we will not receive your request. If you do not provide the optional information requested by our contact form, we may not be able to respond to or process your message.

(i) Legal basis for processing: our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:we respond to requests and messages we receive and keep track of correspondence.

(ii) Legal basis for processing:necessary to conclude a contract or to take steps at your request before concluding a contract (Article 6(1)(b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:where your message is about the provision of goods or services or taking steps at your request before we provide you with our goods and services (for example, providing information about such goods and services); we will process your information to do this.

Transferring and storing your informationThe messages you send us through our contact form will be stored in the European Economic Area.

4.3 Contact by Mail.If you contact us by post, we will collect all the information you give us in any written communications you send us.

(i) Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:we respond to questions and messages we receive and keep track of correspondence.

(ii) Legal basis for processing:necessary to conclude a contract or to take steps at your request before concluding a contract (Article 6(1)(b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:where your message is about the provision of goods or services or taking steps at your request before we provide you with our goods and services (for example, providing information about such goods and services); we will process your information to do this.

  1. Information collected or obtained from third parties

5.1 Information received from third parties. We generally do not receive information about you from third parties. The third parties from whom we receive information about you will generally include group companies or partners. Third parties with whom we have had no prior contact may also provide us with information about you. The information we obtain from third parties will generally be your name and contact details, but will include any additional information about you that you provide to us.

(i) Legal basis for processing:it is necessary to perform a contract or to take steps at your request before a contract is concluded (Article 6(1)(b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:where a third party has submitted information about you (such as your name and email address) to provide you with services, we will process your information to take action on your request to enter into a contract with you and to terminate a contract with you (as applicable).

(ii) Legal basis for processing:your consent (Article 6(1)(a) of the General Data Protection Regulation).

Your consent:where you have asked a third party to share information about you with us and the purpose of sharing that information is not related to the performance of a contract or services by us to you, we will process your information based on your consent ., which you grant by requesting that third party to provide your information.

(iii) Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:where a third party has shared information about you with us and you have not consented to the sharing of information, we will have a legitimate interest in processing that information in certain circumstances. For example, we would have a legitimate interest in processing your information to fulfill our obligations under the subcontract with the third party, where the third party has the main contract with you. Our legitimate interest is to fulfill our obligations under our subcontract. Similarly, third parties may pass on information about us if you have violated or may violate any of our legal rights. In this case, we will have a legitimate interest in processing this information to investigate and prosecute any such possible breach.

5.2 Information received in error.If we receive information about you in error from a third party and/or we do not have a legal basis for processing that information, we will delete your information.

  1. How we use your information

Creating a profile. Please note that we use visitor profiling on our site. We do not consider this to have any legal effect on you or similarly affect you. You have the right to object to the use of the automatic profiling information described in this section. You can do this by opting out of cookies and similar technologies in accordance with the method described in the relevant section below. Your IP address is not associated with any other information about you as it is only used for traffic / connection statistics – therefore we cannot identify you based on your IP. You can learn more about the use of cookies and similar technologies (including the legal basis we use) and how to opt out of them in our cookie policy.

Profiling is any form of automatic processing of your information to assess personal aspects about you, in particular to analyze or estimate things such as your job performance, economic situation, health, personal preferences, interests, reliability , behavior, location or movements performed.

6.1 Use of profile for web analytics.Our web analysis service, Google Analytics uses and collects information such as your location (based on your IP address) and your behavior (based on cookies) when you visit the site (such as the pages you visit and where you click). We will only process information from cookies if you have consented to the installation of cookies on your device in accordance with the cookie policy.

The logical approach:by automatically analyzing and classifying information such as location (based on IP address), as well as the behavior and devices of visitors to our site (using cookies), we can better understand what site visitors want (in terms of the content of our website and our products), how to improve the website and how to promote it and market our products and services.

Meaning and Intended Consequences: cookies will be used to track and store information about your behavior and device on our site (unless you have opted out of receiving such cookies through the pop-up window or emailing your IP address and your location will be analyzed based on your IP address.

Legal basis for processing:legitimate interests [Article 6(1)(f) of the General Data Protection Regulation].

Legitimate interest: providing the best experience to our visitors based on region, language and interests.

  1. How long we keep your information

This section sets out how long we will keep your information. If possible, we provide specific retention periods. Where this is not possible, we have set out the criteria we use to determine the retention period.

7.1 Retention Periods

  • Server History Information: We retain log information on our server in accordance with legal requirements in our country. For logins that do not fall under a special status, we keep the information for a maximum period of three years.
  • Correspondence and enquiries: If you make an inquiry or correspond with us for any reason, whether by email, post or telephone, we will retain your information for as long as we need to respond to and resolve your enquiry, and for a further 12 months, after which we will delete your information.

7.2 Criteria for determining retention periods.In any other circumstances, we will not retain your information for longer than is necessary, taking into account the following:

  • the purpose(s) and use of your information both now and in the future (such as whether it is necessary for us to continue to store this information to continue to fulfill our obligations under a contract with you or to contact you future);
  • if we have a legal obligation to continue processing your information (such as any information retention obligations imposed by law or relevant regulations);
  • if we have any legal basis to continue processing the information (such as your consent);
  • how important your information is (both now and in the future);
  • any practices agreed in the field regarding the duration of information retention;
  • the levels of risk, cost and liability involved in continuing to hold the information;
  • how difficult it is to ensure that the information can be updated and accurate; and
  • any relevant circumstances (such as the nature and state of our relationship with you).
  1. How we secure your information

We take appropriate technical and organizational measures to secure your information and protect it against unauthorized or unlawful use and accidental loss or destruction, including:

  • information is stored encrypted and access to it is limited to internal personnel with specific interest, using login credentials and in accordance with the rules defined by the internal policies on the use of personal data as defined in the company register.
  • use of secure servers to store information;
  • verifying the identity of any person requesting access to information before granting access to information;
  • using Secure Sockets Layer (SSL) and Transport Layer Security (TLS) software to encrypt any information you submit to us through any forms on our website;

Improper ways of sending information via the Internet (encryption is non-existent or weak) by the user releases us from any responsibility that falls to him.

  1. Transfer of Your Information

Your information will be transferred and stored outside the European Economic Area (EEA) under the conditions set out below. We will also transfer your information outside the EEA or to an international organization to comply with legal obligations to which we are subject (for example, complying with a court order). If we are required to do so, we will provide appropriate safeguards and protections.

9.1 Contact form.The information you submit to us via our contact form may be transferred outside the EEA and stored on third party and email providers’ host servers.

9.2 Email.The information you send us by email is transferred outside the EEA and stored on the servers of our third party email service provider.

9.3 Google Analytics. The information collected by Google Analytics (IP address and the actions you take on our website) is transferred outside the EEA and stored on Google servers. You can access Google’s privacy policy here:https://www.google.com/policies/privacy/

Country where we store data:United States of America. This country is not subject to an adequacy decision by the European Commission.

Safety measures used:Google has automatically certified compliance with the EU-US Privacy Shield, available here:https://www.privacyshield.gov/welcome. The EU-US Privacy Shield is a certification mechanism approved under Article 42 of the General Data Protection Regulation, which is permitted under Article 46(2)(f) of the General Data Protection Regulation. You can access the European Commission’s decision on the adequacy of the EU-US Data Protection Shield here:http://ec.europa.eu/justice/data-protection/international-transfers/adequacy/index_en.htm

  1. Disclosure of Your Information

10.1 Disclosure to Service Providers.We use third parties to provide us with services that are necessary to manage our business or to help us run our business and that process your information on our behalf. These include:

  • Hosting provider(s), located in Romania.

Your information will be shared with these service providers as necessary to provide you with the services you have requested, whether you access our website or order goods and services from us. We do not publicly display the identity of all our service providers for security and competition reasons. If you would like more information about the identity of service providers, please contact us directly via our contact form or by email and we will provide you with such information, where you have a legitimate reason to request it ( if we have shared your information with such service providers, for example).

(i) Legal basis for processing:legitimate interests [Article 6(1)(f) of the General Data Protection Regulation].

The legitimate interest invoked:if we share your information with these third parties in a context other than as necessary to perform a contract (or take action at your request to do so), we will share your information with such third parties to be able to run and manage our business effectively.

(ii) Legal basis for processing:necessary to conclude a contract and / or to take steps at your request before concluding a contract (Article 6 (1) letter (b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:we may share information with our service providers to enable us to fulfill our obligations under that contract or to take steps you have requested before entering into a contract with you.

10.2 Disclosure to Other Third Parties. We also disclose your information to third parties in certain circumstances as described below.

10.2.1 Provision of information to third parties such as Google Inc. Google collects information through our use of Google Analytics on our website. Google uses this information, including IP addresses and cookie information, for several purposes, such as improving the Google Analytics service. The information is shared with Google on an aggregated and anonymous basis. To learn more about what information Google collects, how it uses this information, and how you can control the information sent to Google, see the following page:https://www.google.com/policies/privacy/partners/.

Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:compliance with the contractual obligations towards Google according to the Google Analytics Terms and Conditions (https://www.google.com/analytics/terms/us.html). You can opt out of Google Analytics by installing the browser plugin here:https://tools.google.com/dlpage/gaoptout.

Transferring and storing your informationThe information collected by Google Analytics is stored on Google servers in the United States of America. For further information on the safeguards in place when your information is transferred outside the European Economic Area, see section 9 above.

10.2.2 Sharing your information with third parties that are either related to or associated with our business operations, where it is necessary for us to do so.Information is stored encrypted and can only be decrypted using login credentials assigned to certain users with specific interests in accordance with our GDPR policies.

Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interest:the effective operation and management of the site.

  • We occasionally obtain advice from consultants such as accountants, financial advisors, lawyers, public relations professionals and security specialists. We will only share your information with these third parties when necessary to provide relevant advice.
  • Business partners. Business partners are the companies we work with that provide goods and services complementary to our own business or that enable us to provide goods or services that we cannot provide ourselves. We share information with our business partners where you have requested services that they provide either independently of us or in connection with our services, or their own services.
  • Independent contractors. We use independent contractors in some cases. Your information will only be shared with independent contractors as necessary for them to perform certain tasks.
  • We will share your information with our insurers where this is necessary, for example in relation to a complaint or potential complaint we receive or make, or in accordance with our general disclosure obligations under the contract our insurance with them.

10.2.3 Sharing information within the institution for internal administrative purposes, including customer and employee information.

(i) Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interest: the efficient operation and management of the website.

(ii) Legal basis for processing:necessary to conclude a contract or to take steps at your request before concluding a contract (Article 6(1)(b) of the General Data Protection Regulation).

The reason why it is necessary to make a contract:we need to share information about you with other companies in order to fulfill our contractual obligations to you or to take action at your request before entering into a contract, for example because of the services or information you have requested .

10.3 Disclosure of Information for Legal Reasons.

10.3.1 Reporting crimes or threats to public safety.If we suspect that criminal or potentially criminal behavior has occurred, we must in certain circumstances contact an appropriate authority, such as the police. This could be the case, for example, if we suspect that fraud or cybercrime has been committed, or if we receive threats or malicious communications. We will generally only need to process your information for this purpose if you have been involved in or affected by such an incident in any way.

Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:preventing crime or suspected criminal activity (such as fraud).

10.3.2 Enforcement or possible enforcement of legal rights.We will use your information in connection with the enforcement or possible enforcement of our legal rights. Our legal rights may be contractual (where we have entered into a contract with you) or non-contractual (such as the legal rights we have under copyright or tort law).

Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interest:to enforce our legal rights and to take steps to enforce our legal rights.

10.3.3 In connection with litigation, potential litigation or legal proceedings.We may need to use your information if we are involved in a dispute with you or a third party, for example, either to resolve the dispute or as part of any mediation, arbitration or court resolution or a similar process.

Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interests:resolution of disputes and potential disputes.

10.3.4 Compliance with laws, regulations and other legal requirements.We will use and process your information to comply with legal obligations to which we are subject. For example, we may need to disclose your information pursuant to a court order or subpoena, if we receive one.

(i) Legal basis for processing:compliance with a legal obligation (Article 6(1)(c) of the General Data Protection Regulation).

Legal obligation:the legal obligations to disclose information that are part of Romanian legislation or that are mandatory for Romanian legal entities, for example based on an international agreement signed by Romania.

(ii) Legal basis for processing:our legitimate interests (Article 6(1)(f) of the General Data Protection Regulation).

Legitimate interest:if the legal obligations are part of the laws of another country and have not been integrated into the legal framework of Romania, we have a legitimate interest in respecting these obligations.

  1. Your rights in relation to your information.

11.1 Subject to certain restrictions on certain rights, you have the rights listed below in relation to your information.You can also exercise these rights by sending an email to info@pensiuneanegoiu.ro

  • The right to request access to your information and information related to the use and processing of your information;
  • The right to request the correction or deletion of your information;
  • The right to request restriction of the use of your information;
  • The right to receive the information you have provided to us in a structured, commonly used format that can be read on any device (for example a CSV file) and the right to transfer it to another data controller (including a third party data controller);
  • The right to object to the processing of your information for certain purposes (for more information, see section 12 below); and
  • The right to withdraw your consent to the use of your information at any time where we rely on your consent to use or process that information. Please note that if you withdraw your consent, this will not affect the lawfulness of the use and processing of your information based on your consent before the time you withdraw your consent.

In accordance with Article 77 of the General Data Protection Regulation, you also have the right to lodge a complaint with a supervisory authority, in particular in the state where you are habitually present, at work or for an alleged infringement of the General Data Protection Regulation.

11.2 The above rights are provided in summary form only and certain limitations apply to many of these rights.You can find more information about your rights, as well as information about any limitations that apply to those rights, by reading the underlying legislation contained in Articles 12-22 and 34 of the General Data Protection Regulation, available here:

https://ec.europa.eu/info/law/law-topic/data-protection/reform_ro/

11.3 If you request access to your information, we are required by law to use all reasonable steps to verify your identity before doing so.These measures are designed to protect your information and prevent the risk of identity fraud, identity theft, or general unauthorized access to your information.

How we verify your identity. If we have relevant information about you, we will try to verify your identity using that information. If it is not possible for us to identify you with such information, or if we do not have sufficient information about you, we may request original documents or certified copies of certain documents so that we can verify your identity before we can provide you with access to your information. We will be able to confirm the exact information we need to confirm your identity in your particular circumstances if and when you make such a request.

  1. The right to object to the processing of your information for certain purposes.

In relation to the use or processing of your information, you have the right to the objections listed below. You can also exercise these rights by sending an email to info@pensiuneanegoiu.ro

  • The right to object to the use or processing of your information, where we use or process it to carry out a public interest task or for our legitimate interests, including “profiling” (analyzing or estimating your behavior in your information base) based on any of these purposes; and

For more information on how you can object to the use of information collected from cookies and similar technologies, see our cookie policy.

  1. sensitive personal information; children’s privacy.

13.1 “Sensitive personal information” is information about an individual that reveals racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic information, biometric information for the purpose of uniquely identifying an individual, health or life information sexual orientation or sexual orientation of a natural person.

We do not knowingly or intentionally collect sensitive personal information from individuals, and you should not send us sensitive personal information. If, however, you accidentally or intentionally submit sensitive personal information to us, we will consider that you have explicitly given us your consent to process the sensitive personal information in accordance with Article 9(2)(a) of the General Data Protection Regulation. We will use and process your sensitive personal information for the purpose of erasure.

13.2 We do not knowingly contact or collect information from persons under the age of 18. Our site is not intended to solicit information of any kind from persons under the age of 18. We may receive information about persons under the age of 18 through the fraud or deception of a third party. If we are notified of this, as soon as we verify the information, when required by law, we will immediately obtain appropriate parental consent to use that information or, if we cannot obtain parental consent, we will delete the information from our servers. If you would like to notify us about receiving information about persons under the age of 18, please do so by sending an email to info@pensiuneanegoiu.ro

  1. Changes to our privacy policy

We may update and change our privacy policy from time to time.

14.1 Minor Changes.If we make minor changes to our privacy policy, we will update the privacy policy with a new date stated at the beginning of it. The processing of your information will be governed by the practices set forth in the new version of the privacy policy as of its effective date.

14.2 Major Changes.If we make major changes to our privacy policy or intend to use your information for a new purpose or for a purpose different from the purposes for which we originally collected it, then we will notify you by email (if possible ) or by publishing a notice on our website. We will provide you with information about the change in question and its purpose and any other relevant information before we use your information for the new purpose. Whenever necessary, we will obtain your prior consent before using your information for a purpose other than the purposes for which we originally collected it.

  1. Additional information

Our website may contain links to third party websites. The privacy policies or practices of such third parties are beyond our control. Therefore, please read the privacy policies of these sites before using them.