Privacy policy (DRAFT)
Controller: [Company], [Address], [Email].
This policy covers our website and our own customer data. For the data in your shop, we are processor; see the DPA.
Data we process
- Customer accounts and contracts: name, company, VAT ID, address, email, phone. Basis: contract (GDPR Art. 6(1)(b)).
- Invoices and payments: billing data; payments run through Stripe. Basis: legal duty (Art. 6(1)(c)), kept as long as tax law requires.
- Support emails: content of your messages. Basis: contract.
- Server logs of our website: IP address, time, page. Basis: legitimate interest in security (Art. 6(1)(f)). Kept at most 30 days.
Recipients
Our subprocessors (see subprocessors.md), our accountant, and authorities when the law requires it.
Your rights
Access, correction, deletion, restriction, portability, objection, and a complaint to the Romanian authority (ANSPDCP, www.dataprotection.ro). Write to [Email].