PRIVACY POLICY


Version applicable from June 10, 2021

WHY IS IT IMPORTANT TO READ THIS PRIVACY POLICY?

This Privacy Policy (“policy”) describes how UAB Convenity (hereinafter referred to as “Company”, “we”, “us”) collects, uses, discloses, and stores your personal data and your legal rights. We protect your personal data in compliance with the General Data Protection Regulation (2016/679) (“GDPR”) and other applicable laws. We may unilaterally modify this policy occasionally.

WHO IS RESPONSIBLE FOR PROTECTING MY INFORMATION?


Our registration number is: RO32088257
Our address: Expres Colet SRL, Iași, 78 Aureliu Vlaicu St
Our email address: office.exprescolet@gmail.com

WHY AND HOW DO YOU COLLECT MY INFORMATION?

1. TO PROCESS ORDERS IN OUR ONLINE STORE, RECEIVE PAYMENTS, AND SHIP PRODUCTS YOU HAVE PURCHASED

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
When you purchase our products First name, last name, shipping address, phone number, price information, and currency of the product, credit card brand and type, BIN number and issuing country of the credit card, IP address, language, device type, and payment history. Contract (Art. 6 (1) (b) of GDPR) From you It is a necessary requirement to conclude a contract. If you do not provide this information, you will not be able to purchase and receive our products. 10 years

2. TO ENSURE SECURITY AND IMPROVE OUR WEBSITE

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
When you use our website or violate the Terms of Service IP address, device ID and data, web browser information, your activity on our website, country, information about the violation of the Terms of Service, and blacklist status. Legitimate interest (security and improvement of our website) (Art. 6 (1) (f) of GDPR) From you No One month from the last time you use our website; 10 years for information regarding violations of the Terms of Service and blacklist status.

3. TO PROVIDE CUSTOMER SUPPORT SERVICE

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
When you send a question or complaint to our customer support service First name, last name, shipping address, country, phone number, subject of the inquiry, date of the inquiry, content of the inquiry, attached files, response to the inquiry, customer contact history, order ID. Consent (Art. 6 (1) (a) of GDPR) From you

Customer support service providers
No 10 years from the time your last inquiry was received

4. TO INFORM YOU ABOUT OUR PRODUCTS OR TO SHOW YOU ADS ON THE INTERNET

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
When we want to inform you or seek your opinion about our products or show you ads on the internet Full name, email, phone number, IP address, order data, country, postback data, website that directed to the company's website, your interaction with online ads. Consent (Art. 6 (1) (a) of GDPR)

Customer relationship

Legitimate interest (direct marketing and online ads) (Art. 6 (1) (f) of GDPR)
From you

Social media service providers

Marketing service providers

E-commerce service providers
No 5 years unless you opt out

5. TO INTERACT WITH YOU THROUGH SOCIAL MEDIA

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
If you interact with our social media profiles (e.g., send us a message, follow our profiles, share a post, react to a post) Full name, email address, gender, country, photo, message, date and time message received, message content, attached files, response to message, time of response to message, company rating information, comments on a post, shares of a post, information about reactions to a post. Consent (Art. 6 (1) (a) of GDPR) From you and social media service providers No 10 years from your last interaction with our social media profiles

6. TO CONDUCT POTENTIAL EMPLOYEE SELECTION

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
When we receive your job application, when you consent to store your resume, or when we contact you based on information you publicly disclose on professional social media platforms. Full name, email, phone number, resume, professional experience, other data you provide to us Consent (Art. 6 (1) (f) of GDPR)

Contract (Art. 6 (1) (b) of GDPR)

Legitimate interest (contacting you if you make your information public) (Art. 6 (1) (f) of GDPR)
From you

Professional social media service providers

Recruitment agencies
It is necessary to conclude a contract only when we intend to enter into an employment contract with you. If you do not provide this information, we cannot enter into an employment contract with you. 6 months after the conclusion of the relevant recruitment process

5 years after you have given consent or made your information public on professional social media platforms

7. TO COMPLY WITH LEGAL ACCOUNTING REQUIREMENTS

When does this affect me? What information do you collect about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
When you purchase our products Full name, email address, phone number, bank account number, address, signature, invoice, reports, accounting documents, payments, amounts paid, other data we are legally obliged to collect. Legal obligation (Art. 6 (1) (c) of GDPR) From you

Audit service providers
It is a legal requirement. If you do not provide this information, you will not be able to purchase our goods or services. 10 years after the transaction

8. TO DEFEND OUR RIGHTS AND INTERESTS

When does this affect me? What information is collected about me? What is the legal basis for collecting my information? Where do you collect my information from? Am I required to provide this information? How long do you keep my information?
If we are involved in legal proceedings that affect you or are legally required to collect information about you All data mentioned above, accounting and legal files, legal documents, other data provided by you, other data we are legally required to collect and/or provide. Legal obligation (Art. 6 (1) (c) of GDPR)

Legitimate interest (to protect our rights and interests) (Art. 6 (1) (f) of GDPR)
From the mentioned sources, police authorities, parties involved in legal proceedings, courts Yes, when we are legally required to collect personal data 10 years from the end of the contractual relationship with us or, if longer, the duration of the legal proceedings and the 3 years after the final decision of the authority comes into effect.
If applicable: information about crimes and criminal convictions Establishing, exercising, or defending legal claims (Art. 9 (2) (f) of GDPR)

WHO DO YOU SHARE MY DATA WITH?

We share your data with information recipients both within and outside the European Economic Area (EEA) where necessary for the purposes described above and permitted by applicable laws.

Information recipient or category of information recipient Purpose of information transfer Recipient's country European Commission decision on whether a non-EEA country provides an adequate level of data protection Adequate safeguards protecting my information when transferred to non-EEA countries
Accounting and audit service providers To comply with legal accounting requirements EU N/A N/A
Archiving service providers To maintain our archive EU N/A N/A
Electronic communication service providers To operate our electronic communications EU N/A N/A
Lawyers, notaries, judicial agents, auditors, data protection officers, consultants To ensure compliance and defend our rights and interests EU N/A N/A
Email and cloud hosting service providers To operate our IT resources Worldwide No EU Standard Contractual Clauses
Banks, payment processors, and other financial service providers To process payments Worldwide No EU Standard Contractual Clauses
Marketing and telemarketing service providers To promote our products Worldwide No EU Standard Contractual Clauses
Shipping service providers and distribution centers To ship our products Worldwide No EU Standard Contractual Clauses
Customer support service providers To provide customer support Worldwide No EU Standard Contractual Clauses
Social media service providers To manage our social media profiles Worldwide No EU Standard Contractual Clauses

WHAT LEGAL RIGHTS DO I HAVE REGARDING MY INFORMATION?

Subject to the conditions and limitations provided by applicable laws, you have the right (i) to receive confirmation if we collect data related to you and to request access to this information; (ii) to correct inaccurate or incorrect data or complete them when they are incomplete; (iii) to delete the data we have about you; (iv) to restrict the use of your data when you dispute their accuracy, object to their processing, or need them for legal purposes; (v) to request your information in a structured, commonly used, and machine-readable format; (vi) to object to the processing of information; (vii) to withdraw any consent you have given us in relation to the processing of your information; (viii) to file a complaint with supervisory authorities; and (ix) to not be discriminated against in exercising your rights. Below you will find more information about your rights and the cases in which they apply.

WHAT DOES MY RIGHT TO REQUEST ACCESS TO INFORMATION ENTAIL?

You have the right to request that we disclose certain data about the collection and use of your information. After we receive and verify your request, we will disclose the categories of personal data and sources of personal information we have collected about you, our commercial or business purposes for collecting this personal information, the categories of third parties with whom we share this personal information, the specific pieces of personal information we have collected about you, and other data we are required to provide in accordance with applicable laws. We disclose data to third parties for commercial or business purposes, as described in Section 4 of this policy.

WHAT DOES MY RIGHT TO RECTIFICATION ENTAIL?

You have the right to obtain the rectification of inaccurate personal data concerning you. Considering the purposes of the processing of the information, you have the right to request the completion of incomplete data, including by submitting a supplementary declaration.

WHAT DOES MY RIGHT TO REQUEST THE DELETION OF INFORMATION ENTAIL?

You have the right to request the deletion of data collected and stored by us in cases where (i) the information is no longer necessary for the purposes for which it was collected or otherwise processed, (ii) you have withdrawn the consent on which the data processing is based and there is no other legal basis for processing the data; (iii) when you object to the processing of your data and there are no overriding legitimate grounds for processing them or you object to processing for direct marketing purposes; (iv) the data have been processed contrary to the law; (v) the information must be deleted to comply with a legal obligation; (vi) the information has been collected in connection with the provision of information society services directly to a child and is subject to consent. After we receive and verify your request, we will delete (and ask our service providers to delete) your data from our records, unless applicable laws require data retention in a specific case (e.g., data retention is necessary for us or our service provider(s) to complete the transaction for which we collected the personal information, provide the requested good or service, take actions reasonably anticipated in the context of the ongoing business relationship with you, or otherwise fulfill the contract with you, detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activities or prosecute those responsible for such activities, comply with a legal obligation, make other lawful internal uses of this information that are compatible with the context in which you provided it).

WHAT DOES MY RIGHT TO RESTRICT PROCESSING OF INFORMATION ENTAIL?

You have the right to restrict the processing of your information in cases where (i) you have disputed the accuracy of the personal information; (ii) the processing is illegal, and you object to the deletion of personal information and request that it be restricted instead; (iii) we no longer need personal information for processing purposes, but you need it for establishing, exercising, or defending legal claims; (iv) you have objected to processing.

WHAT DOES MY RIGHT TO DATA PORTABILITY ENTAIL?

You have the right to data portability when you want to receive the data you have provided in a structured, commonly used, and machine-readable format or to transfer this data to another operator when the processing is based on consent or a contract and is carried out by automated means.

WHAT DOES MY RIGHT TO OBJECT TO PROCESSING OF INFORMATION ENTAIL?

You have the right to object to the processing of your information when its collection and use were based on public interest or the exercise of official authority or legitimate interest, including profiling, as explained in section 3 of this policy or when you object to the collection of your personal information for direct marketing purposes.

WHAT DOES MY RIGHT TO WITHDRAW CONSENT ENTAIL?

You have the right to withdraw any consent given regarding the processing of your information when its processing is based on consent, as explained in Section 3 of this policy, and you wish to withdraw it at any time.

WHAT DOES MY RIGHT TO FILE A COMPLAINT WITH SUPERVISORY AUTHORITIES ENTAIL?

You have the right to file a complaint with supervisory authorities when you want to file a complaint with the supervisory authority, especially in the member state of your habitual residence, place of work, or in the event of an alleged GDPR infringement.

WHAT DOES MY RIGHT TO NOT BE TREATED DISCRIMINATORILY IN EXERCISING MY RIGHTS ENTAIL?

In exercising your rights provided by applicable laws, you have the right not to be discriminated against. For example, because you exercised your rights under applicable law, you will not be denied any goods or services, charged a different price, offered goods or services of different quality, etc.

HOW DO I SUBMIT A REQUEST?

If you want to exercise the above-mentioned rights, please send us a request by email to office.exprescolet@gmail.com

CAN I USE AN AUTHORIZED AGENT?

Yes, of course. You can use an authorized agent to submit an opt-out request on your behalf if you provide us with written permission to do so. In this case, please provide us with a copy of the permission, as indicated in section 18 of this policy. We may deny a request from an authorized agent who does not provide proof that they have been authorized by you to act on your behalf. You can also submit a request on behalf of your minor child.

DO YOU PARTICIPATE IN AUTOMATED INDIVIDUAL DECISION-MAKING, INCLUDING PROFILING?

No, we do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you.

DOES YOUR SITE SAVE ANY COOKIES ON MY DEVICE?

Yes, our site saves the following cookies on your device.

Cookie name Cookie description Cookie expiration
Strictly necessary and statistical cookies
_fbp Used to distinguish and track each user 3 months
_ga This cookie is used to distinguish between users, assigning them a randomly generated number as a client identifier. It is included in each page request on a website and used to calculate visitor, session, and campaign data for website analysis reports. 2 years
_gat This cookie is used by Google Analytics to throttle request rate. 1 day
_gid This cookie stores and updates a unique value for each page visited and is used to count and track visits to the website. 1 day
__cfruid Cookie associated with sites like CloudFare, used to identify trusted web traffic. Only during the session
_fw_crm_v Used to track visitor/user identity and chat sessions performed by the user 1 year
_hjid Hotjar cookie that is set when the customer first lands on a page with the Hotjar script. It is used to persist the Hotjar user ID, unique to that site in the browser. This ensures that behavior at subsequent visits to the same site is attributed to the same user ID. 1 year
_uetvid This is a cookie used by Microsoft Bing Ads. It allows us to connect with a user who has previously visited our website. 1 year
XSRF-TOKEN This cookie is intended to help with website security by preventing Cross-site request forgery attacks. 1 day
enence_session Used to store information about your current visit to the site. This cookie is essential for website functionality. Only during the website visit
c This cookie is used to detect spam and improve website security. It does not store specific visitor data. 2 years
soundestID This cookie is used to determine whether the visitor has visited the website before or if it is a new visitor. Only during the website visit
soundtest-views Assigns a specific ID to the visitor. This allows the website to determine the number of visits of specific users for analytics and statistics. Only during the website visit
Marketing cookies
ads/ga-audiences This cookie is used by Google AdWords to re-engage visitors who are likely to convert to customers based on their online behavior on websites. Only during the website visit
REST/webTracking/v1/event This cookie measures the effectiveness of website marketing. It is used to measure the conversion rate between website marketing and phone response. Only during the website visit
Preference cookies
_gat_gtag_UA_136786017_1 This cookie is part of Google Analytics and is used to limit requests (throttle request rate). 1 minute

HOW ARE COOKIES MANAGED?

You can configure your browser to reject some or all cookies or to request permission before accepting them. Please note that deleting or disabling future cookies may prevent access to some parts or features of our website. You can control the use of technical, preference, or advertising cookies by adjusting your computer settings. To learn how to manage cookies in your browser, visit one of the following links:

Mozilla Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
Google Chrome: https://support.google.com/chrome/answer/95647
Opera: https://www.opera.com/help/tutorials/security/privacy
Microsoft Edge: https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy
Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-information-sfri11471/mac

HOW CAN I CONTACT THE DATA PROTECTION OFFICERS?

If you have questions, comments, or complaints about how we collect, use, and store your personal information, our data protection officers can help. If you need assistance, you can contact them anytime via email at office.exprescolet@gmail.com.