Privacy Policy

Thank you for your interest in us and the services we offer. We know, respect and defend your right to the protection of your personal data, which we process with particular care to ensure its integrity and confidentiality.

We recommend that you read this Privacy Policy carefully and with interest, as very important information is provided regarding your personal data.

 

  1. What is the Privacy Policy?

The Privacy Policy, hereinafter referred to as the Policy or document, is the document that contains information on how we process personal data and the reasons for which we process it.

For us, this Policy has the value of a commitment to the users of the site and to our customers.

For you, the purpose of this Policy is to inform you about the processing of personal data concerning you, respectively to explain to the user what personal data we collect, the purpose for which we collect it and the way in which it is processed.

Privacy is the cornerstone of our business and we understand how important each user’s personal data is. That is why we pay particular attention to the processing process and strive to store personal data securely.

Your personal data belongs to you and we assure you that your data will not be passed on to third parties without informing you accordingly.

This Privacy Policy may be modified at any time. All updates and changes to this Policy are effective immediately upon publication on the Site.

Any concerns or questions related to your personal data can be addressed to the e-mail address privacy@pm-boutique.com. At the same email address, you can also exercise your legal rights.

 

  1. Who are we?

The pm-boutique.com domain belongs to and is administered by STYLO PROJECT CONCEPT S.R.L., headquartered in Romania, 2 Franceză Street, Izbășești, Stolnici Village, Argeș county, registered under Trade Register no. J3/1300/2015, VAT no. RO 35068335.

According to the legislation on the protection of personal data, we are the data controller, having responsibility for the way in which the personal data processing activity concerning you is carried out and we are directly responsible for any non-conformities in the data processing process.

 

  1. Who are you?

From the perspective of the legislation on the protection of personal data, you are the “data subject”, that is the natural person, identified or identifiable, beneficiary of our services or the person in a relationship of any kind with us.

In order to ensure transparency regarding data processing and to facilitate the possibility to exercise your rights at any time, we have implemented appropriate measures so that the relationship and communication between us, the data controller, and you, the data subject, is effective and efficient.

 

  1. What is personal data?

Personal data is any information that can be linked to an identified or identifiable natural person, called a data subject.

Personal data includes all types of direct or indirect information relating to the data subject, such as name, date of birth, address, e-mail address, telephone numbers, etc.

 

  1. What personal data do we process?

The categories of personal data we process differ depending on the relationship between you and us.

  • Site user

In the event that you are a simple user of the site, without benefiting from the services we offer, the personal data we process is limited to how you interact with our site, for example, information about how and when you access our site or what device you use to access the site, your IP address and the like. For more information in this regard, we invite you to read our Cookie Policy.

  • Our client

In the event that a contractual relationship exists or is concluded and you are or become our customer, the categories of personal data that we process may be the following:

  • Identification data: name, surname, address (required by the fiscal legislation)
  • Contact details: telephone number, e-mail address
  • Financial and banking data: IBAN account (required for invoicing)
  • Any other data that is necessary to provide you with our services.

 

5.3.      The legal/conventional representative of our client

If you are the representative of our client in a B2B relationship, we will process your identification data such as name, surname, quality and signature, necessary to conclude and perform the contract.

Please note that we do not request data that is part of special categories of data (sensitive data), such as data on racial or ethnic origin, political opinions, religion, health data, sexual orientation, biometric data for unique identification.

The data we process are those strictly necessary in relation to the purposes and grounds of the processing and we aim to minimize the volume of data we request, taking into account the specifics of our activity and your rights, freedoms and interests.

 

  1. Why do we process your data? – purposes and grounds of processing

The processing of personal data is an indispensable subsidiary activity to our main activity – the provision of legal services.

It is your right to refuse to provide personal data. We inform you that, in the absence of personal data, we cannot carry out our activity. Consequently, if you refuse to provide personal data, you will not be able to benefit from the services we offer.

Below you will find a table through which we try to give you the most accurate picture of the purposes and legal grounds of the processing:

             Personal data

 

Purposes Legal grounds

Identification data: name, surname, signature

 

Provision of our services

 

Conclusion and performance of contract

 

Providing the information you request from us

 

Compliance with our legal obligations: financial-accounting documents, accounting records, obligations specific to various procedures, etc.

 

Prevention of possible fraud and crimes

 

The conclusion or performance of a contract – Art. 6 (1) b GDPR – applicable to natural persons

 

Legitimate interest – Art. 6 (1) f GDPR – applicable to companies

 

Legal obligation – Art. 6 (1) c GDPR

Contact details: telephone number, e-mail address, home address/residence*

 

* for invoicing natural persons

 

Providing our services and the information you request from us

 

Invoicing and sending invoices

 

Compliance with our legal obligations: financial-accounting documents, accounting records, obligations specific to various procedures, etc.

 

Facilitating communication and correspondence with customers

 

The conclusion or execution of a contract – Art. 6 (1) b GDPR – applicable to natural persons

 

Legitimate interest – Art. 6 (1) f GDPR – applicable to companies

 

Legal obligation – Art. 6 (1) c GDPR

Financial and banking data: IBAN account

 

Billing

 

Compliance with our legal obligations: financial-accounting documents, accounting records, obligations specific to various procedures, etc.

 

Prevention of possible fraud and crimes

 

The conclusion or execution of a contract – Art. 6 (1) b GDPR – applicable to natural persons

 

Legitimate interest – Art. 6 (1) f GDPR – applicable to companies

 

Legal obligation – Art. 6 (1) c GDPR

Data on how you use our website (through cookies) – more details in the Cookies Policy

Site Operation

 

Improving user experience

 

Prevention and response to potential cyber attacks

 

Analise traffic and activities on the website

 

Statistics

 

More details in our Cookies Policy

 

Legitimate interest – Art. 6 (1) f GDPR

 

Consent – Art. 6 (1) a GDPR – only for certain cookie modules

Other categories of data

 

Provision of our services – depending on the service provided, additional personal data may be processed. When required, a Data Processing Agreement shall be conducted.

 

The conclusion or execution of a contract – Art. 6 (1) b GDPR – applicable to natural persons

 

Legitimate interest – Art. 6 (1) f GDPR – applicable to companies

 

In addition to the purposes listed, we process your data, based on the legitimate interest, to exercise a possible right or interest or to be able to defend ourselves before public authorities and courts of law, in the event of a dispute.

For the processing carried out on the basis of the legitimate interest, before processing your data, we carry out a legitimate interest analysis, whereby we balance our interest and your interest and process the respective data only if and to the extent that the legitimate interest prevails over your interests.

Your consent to data processing is only required in certain situations and not for all processing activities. At the moment, your consent to processing is only required for the use of certain cookies. Please note that you have the right to withdraw your given consent at any time, without this having any negative effect on you and without affecting the legality of the processing carried out prior to the withdrawal of consent. For more information on cookies and the withdrawal of consent for their use, please read the 3

If the situation arises, where we perform a task that serves the public interest, your data could be processed pursuant to Article 6 para. (1) letter e from the GDPR.

In the event of a medical emergency or other exceptional event, processing may be necessary to protect the vital interests of you or another natural person. In this situation, your data may be processed pursuant to Article 6 para. (1) letter d of the GDPR.

 

  1. How do we process your data?

The legislation on the protection of personal data establishes clear and strict rules regarding the processing of your data. Our commitment is to process your data in full compliance with legislative rigors.

Personal data concerning you will be used only for the purpose for which it was collected and will be stored only as long as necessary in relation to the purpose for which it was collected, ensuring its confidentiality and integrity.

If you are our customer, our client representative or user of the site, personal data is collected directly from you. The purpose of this Policy is to ensure your information regarding the personal data processing activity.

The principles governing the processing activity are imperative for all data controllers. In our activity, we strive to respect them exactly, being transposed in the measures adopted in the process of collecting and processing personal data.

The principle of legality, fairness and transparency requires that the processing activity is carried out in accordance with the legal requirements, in a fair and transparent manner, ensuring your information about it.

The principle of purpose limitation requires that your data is processed exclusively in accordance with the purposes for which it was collected and about which you have been informed. If there is any change regarding the purpose(s) of the processing, you will be informed accordingly. In this regard, please check this Privacy Policy.

The principle of data minimization involves the processing of only those data that are absolutely necessary, without processing unnecessary data in relation to the purposes of the processing and the legal grounds.

The principle of accuracy requires that your data, which we process, is correct and complete and maintained throughout the processing. In order to ensure the accuracy of the data, it is our duty to verify the veracity of the data you provide us.

The principle of limitation related to storage requires that your data be kept exclusively for the period of time necessary to achieve the purposes pursued, following that at the end of the respective period it will be deleted from our database.

The principle of integrity and confidentiality requires that your data be kept in safe conditions that ensure adequate security, including protection against any unauthorized or illegal access and against accidental loss, destruction or alteration.

Compliance with the listed principles is ensured by adopting various appropriate technical and organizational measures.

 

  1. How long do we keep personal data?

In accordance with the principle of storage limitation, your data is kept exclusively for the period of time necessary to achieve the purposes for which it was processed. The data retention period differs depending on the category of data and the purposes of the processing.

In certain situations, i.e. when the processing takes place on the basis of a legal obligation, the retention period for the personal data is established by law and we respect it as such in order to comply with our obligations. When the period is not established by law, your data will be kept for the period of time in which there is a contract between you and us or for a reasonable period of 5 years from the termination of the contract or from our last interaction or until at the time you withdraw your consent, for those processing for which your consent is required. The exception is the processing activities through the cookie modules we use, regarding which we invite you to consult our Cookie Policy.

Next, we have prepared a table for you that we hope will help you have a more accurate picture of the period of time for which we keep your data:

 

Data categories

 

Retention period

 

Contact details: phone number, email address

 

5 years from last interaction with us/termination of contract

 

Data required for invoicing: name, surname, address, bank details

 

10 years – legal term

 

Data on how to use the website

 

According to the Cookie Policy
Other categories of data

 

5 years from last interaction with us/termination of contract

 

 

At the end of the retention period related to each category of data, your data will be deleted or destroyed or transformed into anonymous data to be used for scientific, historical or statistical research purposes.

 

  1. How and to whom do we disclose your data?

Certain categories of personal data about you may be disclosed to our contractual partners, such as other companies in our group, cloud and hosting service providers, accounting service providers, partners with whom we collaborate to provide you with our services.

All these partners have been carefully selected. Between us and our partners there are contractual clauses that ensure the processing of personal data in full compliance with the legislative rigors on data protection.

We will also disclose your data to institutions and public authorities to which and to the extent we have a legal obligation to disclose them, within the limits of the law.

We are entitled to disclose your personal data if it is necessary to exercise a right of ours or to defend ourselves against any possible accusation concerning us, respecting the legal limits.

Any disclosure of your data is carried out in full compliance with the legislative rigors, ensuring their appropriate protection, with strict respect for the purposes for which they are processed, the legal grounds and only to the extent that the disclosure is necessary and proportionate. Your rights and best interests are the main criterion according to which we assess the appropriateness of the disclosure of your personal data.

 

  1. Information on transfers to non-EU countries

All personal data that we process are kept on the territory of the European Union and European Economic Area and we do not make transfers to third countries.

If there is any change regarding data transfers to third countries, we will inform you accordingly, including by updating this Policy.

Any data transfer to third countries can only be carried out to the extent that an adequate level of protection is ensured, with strict compliance with the legislative rigors in this matter.

 

  1. How do we ensure the security of your data?

In order to ensure the security of your personal data, we have adopted specific technical and organizational measures, depending on the nature, context, scope, purpose and risks of the processing.

In this sense, for example, we use secure computer systems, antivirus and antimalware programs, trying to maintain the highest standards of computer security, apply dedicated policies and procedures for the processing of personal data, restrict access to data and ensure adequate training of our collaborators who have access to your personal data, we ensure that there are strict contractual clauses between us and our partners, so that your data is as well protected as possible, and we only disclose to the extent that the disclosure of data is absolutely necessary in relation to the purpose of the processing, otherwise we anonymize the data contained in the documents that we have to transmit. In addition, we ensure the back- up of the data we process, so that we can recover them in the event of a security incident.

We assure you that we make continuous efforts to maintain the security of the data we process. However, in the unfortunate and undesirable situation where a security incident occurs, you will be notified of this, to the extent that the breach is likely to generate a major risk to your rights and freedoms, within a reasonable time after the discovery of such breach. The exception is the situation where an authorized public body determines that the notification would prevent a criminal investigation or harm national security. In such event, notification shall be deferred as directed by such body. We will promptly respond to your questions regarding such a data breach.

 

  1. What are your rights?

Based on the legislation in the field of data protection, you, as a data subject, benefit from a series of rights, and we, the data controller, have the obligation to provide you with the means by which you can exercise them optimally. Thus, for each of your rights, we have certain correlative obligations to respect them.

Your rights and our correlative obligations are as follows:

  • The right to withdraw the consent given for some/all processing activities carried out on the basis of the consent – our correlative obligation to stop the processing for which the consent has been withdrawn;
  • The right to be informed – our correlative obligation to inform you adequately, according to legal requirements;
  • The right of access – our correlative obligation to provide you with the requested information, in accordance with the law;
  • Right to rectification – our correlative obligation to rectify inaccurate data and complete incomplete data;
  • The right to delete data or the right to be forgotten – our correlative obligation to delete personal data, without undue delay, under the conditions provided by law;
  • The right to restrict processing – our correlative obligation to comply with the processing restriction, under the conditions provided by law, with the exception of storage;
  • The right to data portability – our correlative obligation to disclose, provide or transmit personal data, as the case may be, without obstacles, under the conditions provided by law;
  • The right to object – our correlative obligation to stop the processing of personal data, with certain exceptions, under the conditions provided by law;
  • The right not to be subject to a decision based solely on automated processing, including profiling – our correlative obligation to take appropriate measures to protect your rights and interests and to ensure human intervention in decision-making, under the conditions provided by law;
  • The right to lodge a complaint with the Supervisory Authority.

 

Your rights are not absolute, and can be exercised within the limits and under the conditions expressly provided by law.

 

  1. How can you exercise your rights?

Regarding the relationship with us, you can exercise your rights recognized by law as a data subject through a written request sent to the e-mail address privacy@pm-boutique.com.

We will respond to your requests without undue delay and no later than one month after receiving the request. This period may be extended by two months when necessary, taking into account the complexity and number of applications. In this case, we will inform you of any such extension within one month of receiving the request, including the reasons for the delay. If you submit a request to us electronically, the information is provided electronically where possible, unless you ask us to use a different format for your response.

Any communication or action you request in exercising your rights is provided free of charge. By way of exception, where your requests are manifestly unfounded or excessive, in particular due to their repetitive nature, we have the right to refuse to comply with the request or to charge a reasonable fee, taking into account the administrative costs of providing the information or of communication or for taking the requested measures.

 

  1. Automated decision-making and profiling

We do not use automated individual decision-making processes, including profiling , in our business.

In the event that there will be changes regarding the use of automated decision-making processes, you will be informed accordingly, including through the modification of this Policy.

 

  1. How can you withdraw your consent?

For those personal data processing activities carried out on the basis of your consent, you have the right to withdraw your given consent at any time, without the withdrawal of consent having any negative consequences for you and without it affecting the legality of the processing activities carried out prior to the consent withdrawal.

In the personal data processing activity that we carry out, your consent is only required for the use of certain cookie modules used on our website. The withdrawal of consent regarding these cookies consists in deleting the cookies placed through your browser. For more details and information on deleting cookies, please access the Cookie Policy.

 

  1. When and how can you object to processing?

Article 21 GDPR

Right to object

(1.) The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6(1), including profiling based on those provisions. The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

(2.) Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

(3.) Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

(4.) At the latest at the time of the first communication with the data subject, the right referred to in paragraphs 1 and 2 shall be explicitly brought to the attention of the data subject and shall be presented clearly and separately from any other information.

(5.) In the context of the use of information society services, and notwithstanding Directive 2002/58/EC, the data subject may exercise his or her right to object by automated means using technical specifications.

(6.) Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1), the data subject, on grounds relating to his or her particular situation, shall have the right to object to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

One of the rights recognized by law for the data subject is that of objecting at any time, for reasons related to the particular situation in which they are, to the processing carried out on the basis of the legitimate interest or the public interest, as well as the processing aimed at direct marketing.

Thus, we conclude that the right to opposition operates exclusively with regard to those processing activities carried out on the basis of the legitimate interest or public interest, as well as the processing aimed at direct marketing.

In order to exercise the right to opposition, in accordance with the law, please send us a notification to this effect by e-mail at privacy@pm-boutique.com.

 

  1. How can you notify the Supervisory Authority?

The contact details of the National Authority for the Supervision of Personal Data Processing are as follows:

Website: www.dataprotection.ro

Mail address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania

Email: anspdcp@dataprotection.ro

Telephone: +40.318.059.211; +40.318.059.212

Fax: +40.318.059.602

 

  1. Modification of the Privacy Policy

This Policy will be updated whenever there are changes regarding the processing of personal data, so that you are constantly informed about how we process your data.

For questions or clarifications regarding this Privacy Policy, you can write to us at the e-mail address privacy@pm-boutique.com.

 

COPYRIGHT

Thank you for your interest in us and the services we offer.

We inform you that the entire content of this Privacy Policy belongs to our specialists and for its reproduction in any way our prior consent is required. In this regard, you can write to us at the e-mail address privacy@pm-boutique.com.

This Privacy Policy entered into force on 15th of May 2023.