PRIVACY POLICY

PRIVACY POLICY

www.katerinimou.com

1. WHO ARE WE?

KATERINIMOU SRL (hereinafter referred to as the " Operator " or " Katerinimou " ), attaches great importance to your personal data, constantly taking the necessary diligence to ensure that the data processing carried out complies with the legal requirements in this field. For this purpose, we have developed this commitment through which we undertake to respect the confidentiality of your personal data and through which we explain to you which categories of personal data Katerinimou processes , how the said data are used, as well as the purpose for which they are subject to processing operations.

This Policy relates only to the personal data that we process through our website www.katerinimou.com (hereinafter referred to as the " Site " or " Platform ") in the context in which you interact with it by completing the available forms, by placing an order, subscribing to the newsletter or in the case where you just browse it, or in the case where you contact our staff through inbound or outbound telephone calls. We would like to assure you that we have taken all necessary measures to ensure the confidentiality of your data, these being processed only by the Operator's staff who have been previously trained on the processing of personal data and authorized in this regard and who comply with firm confidentiality commitments.

Your data is processed by Katerinimou and securely, meaning that the Operator has implemented a series of technical and organizational measures , adequate to protect personal data against incidents such as: destruction, loss, accidental or unlawful modification, unauthorized use , disclosure or access , especially when the processing involves the transmission of data over a network , as well as against any other form of unlawful processing .

To "get to know" us virtually, we provide you with our identification data.

The operator who processes your personal data when you browse or interact with the online platform www.katerinimou.com it is KATERINIMOU SRL ., with registered office in Aleea Hortensiei , no. 20, Constanta, registered in the Register Trade under registration number J13/2369/2016, having tax code 36584091 .

For any questions/concerns regarding the protection of personal data, you are invited to send a request to the postal address indicated above or to the electronic correspondence address of contact@katerinimou.com . Persons sending such requests to Katerinimou are asked to mention in the subject of the email/on the envelope information such as " data protection ", " GDPR " or " personal data ", in this way there is a guarantee that the requests will be treated with priority.

In this capacity, you will receive a response within 30 days of the communication of the document to Katerinimou , an extension of this deadline may only operate in exceptional situations. In these cases, we assure you that you will be duly informed of this deadline.

2. DEFINITIONS

  • " Personal data " means any information relating to an identified or identifiable natural person. An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity.

For the purposes of this policy, the personal data that will be processed may refer to: name, surname, telephone number, e-mail address, order delivery and billing address, etc., as described below.

  • " Processing of personal data " means any operation or set of operations which is performed on personal data, whether or not by automatic means, such as : collection, recording, organization, storage, adaptation or modification, retrieval, consultation, use, disclosure to third parties by transmission, dissemination or otherwise, alignment or combination, blocking, erasure or destruction.

! For the purposes of this policy, data processing refers to those processings carried out at the time of your browsing on the website www.katerinimou.com or interacting with it by completing the forms available on the Platform or in the context of placing orders for products from the Operator's portfolio .

  • " Operator " means the person who, alone or jointly with others, determines the purposes and means of the processing of personal data.

! For clarity, for the purposes of this Privacy Policy, the Personal Data Controller is KATERINIMOU SRL

  • " The person concerned " represents the person whose personal data are the subject of processing.

! For the purposes of this Policy, the person concerned by data processing is the Internet user browsing the website www.katerinimou.com or place an order through it . 

  • " Consent " of the data subject means any free, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear statement, signifies agreement to the processing of personal data concerning him or her.

! The data processing carried out through the Platform and based on the legal basis of consent has the exclusive purpose of subscribing to the newsletter, respectively accepting cookies, other than the necessary (essential) ones, as highlighted in the cookie pop-up, respectively detailed in the Cookie Policy.

  • " Third party " means a natural or legal person, public authority, agency or body, other than the data subject, the controller, the processor and the persons who, under the direct authority of the controller or the processor, are authorised to process personal data.

  • " Processor " means the person who processes personal data on behalf of the operator. This may be represented by the operator's partner companies, such as companies providing courier , IT, legal, marketing services, etc.

3. WHAT TYPES OF PERSONAL DATA DO WE PROCESS?

Your browsing on the Site and interaction with it involves the processing of two categories of personal data, namely:

  1. personal data that you disclose to the Operator voluntarily (e.g. via the order form, respectively in the case of subscribing to the newsletter or by making telephone calls to the Operator ), these being collected individually;

  2. data that you provide involuntarily, simply by browsing our website.

Katerinimou collects, based on the voluntary provision of the data subject, the following personal data:

A. In case of placing an order:

  • first and last name;

  • company (optional);

  • phone number;

  • email address;

  • residence/domicile address , for delivery of the ordered product;

  • billing address, when it is different from the delivery address .

Note: For payments made by bank card, the Operator uses the services of the online payment processor STRIPE . In this situation, your data will not be processed by the Operator, the payment activity falling under the requirements set out in the Privacy Policy of the partner payment processor. When choosing to make a payment by bank card, you will be redirected to the payment platform of the online payment processor STRIPE , where the card transaction is carried out in full security . For more information on the particularities of data processing carried out by STRIPE, we invite you to access the privacy policy of this Operator .

B. In the context of returning ordered products:

  • first and last name;

  • phone number;

  • email address;

  • residence/domicile address for picking up the package;

  • bank account (for the return of the amount paid [the value of the returned product]);

  • information about the order placed and which is to be returned (product ordered/product ID, order date, order amount, etc.), if applicable;

  • any other information you make available to the Operator in the context of the return .

C. To contact the Operator via e-mail :

  • first and last name;

  • email address;

  • any other information you make available to the Operator in the body of the e-mail thus transmitted.

D. For newsletter subscription

Subscribing to the newsletter is conditional on your consent for the purpose of receiving commercial and marketing messages. In this context, your e-mail address, namely your first name and last name (indirectly, if it results from the e-mail address of the type nume.prenume@x.ro) will be processed as personal data .

This data contributes to the provision of the services offered by Katerinimou , but also to the communication with the Operator or the transmission of marketing communications from it, but with the prior consent of the user, as detailed in the Newsletter Policy .

The user is duly informed about the processing of personal data when he provides his data to the Operator through the forms on the site, thus Katerinimou fulfills its legal obligation to inform the user.

E. In the context of inbound/outbound telephone calls

  • the voice ;

  • phone number ;

  • other categories of personal data that the data subject makes available in the context of telephone conversations and which may refer to:

  • first and last name ;

  • email address ;

  • product delivery address ;

  • bank account (for reimbursement of amounts related to returned products );

  • And so on

F. In the context of registration for the Operator's workshops

  • first and last name ;

  • email address ;

  • phone number ;

  • bank account – in case of payment of participation through online banking services;

  • signature, if applicable ;

  • image – but only if you provide your consent to be photographed during the Operator's workshops and only if applicable.

The Operator also processes marketing and communication data only based on the prior consent of users, as well as technical data and browsing actions through cookie files and similar technologies , in accordance with the Cookie Policy.

In the event that you provide us with personal data that is not necessary for the purposes described below, namely for fulfilling the orders placed, for resolving your complaints or for providing additional information, we reserve the right to immediately remove them from our database.

The operator may involuntarily collect other personal data belonging to you, namely: IP address, browser version, time zone and location setting, operating system, platforms on the devices used to access the site , etc. This information will not be used to identify individuals and will not be made public other than under the conditions inserted in this Privacy Policy, supplemented by the Cookie Policy.

The Operator reserves the right to request additional information, accompanied by supporting documents, via email, printed or in any other manner deemed appropriate by the Operator, if applicable.

The payment processing service provider will process the following categories of personal data: bank card details (card number, CVC, etc.), the name and surname of the cardholder. This payment processing service provider processes your data as an independent personal data controller , which is why the data processing carried out by them is subject to its Privacy Policy.

Note: Katerinimou has concluded data processing agreements with its service providers (for example: IT/online system administration, legal services, payment processing services, marketing services, etc.), but is not responsible for the processing carried out by these providers on its own behalf, in the event that they process the data as independent operators, the data subject being duly informed regarding the processing that involves a transfer of data between Katerinimou and any company that provides services to the Operator.

Your personal data may be communicated by Katerinimou , for processing, to persons empowered to process them, including contractual partners, financial authorities and institutions, courts or competent bodies, at their request and for the purpose of making available the products offered by the Operator.

Katerinimou may store your personal data even after registering a request to delete this data, if the storage is for one of the following purposes, provided for by art. 1 7 of the GDPR, namely:

  1. execution of a contract;

  2. fulfillment of a legal obligation that requires processing under European Union law or national law applicable to the operator;

  3. exercising the right to freedom of expression and information;

  4. protecting the vital interests of the data subjects;

  5. performing a task that serves the public interest;

  6. archiving in the public interest, scientific or historical research or for statistical purposes;

  7. the protection of the legitimate interests of the Operator or a third party, except where the interests or fundamental rights and freedoms of the data subject prevail, which require the protection of personal data, in particular where the data subject is a child;

  8. for the establishment, exercise or defense of a right in court.

4. FOR WHAT PURPOSE AND ON WHAT LEGAL BASIS DO WE PROCESS PERSONAL DATA?

Katerinimou processes your personal data for the following purposes and on the following legal grounds:

  1. the processing is necessary for the performance of a contract to which the data subject is subject is a party or to take steps at the request of the data subject prior to the conclusion of a contract (art. 6 para. (1) letter b) of Regulation (EU) no. 679/2016 , hereinafter referred to as " GDPR " ), specifically, for the purpose of ensuring the data subject's access to the products marketed on the Platform www.katerinimou.com and the conclusion of the distance sale;

  2. the processing is carried out on the basis of the consent of the data subjects (art. 6, para. (1), letter a) of the GDPR ), in the case of the transmission of commercial and marketing communications , respectively the acceptance of cookies other than the necessary (essential) ones ;

  3. the processing is necessary for the purposes of the legitimate interests pursued by the Operator (art. 6 para. (1) letter f) of the GDPR ), to resolve problems of any nature relating to the content of the website www.katerinimou.com or products offered by the Operator, as well as for actions involving interaction with the online platform ;

  4. processing is necessary to and in order to fulfill a legal obligation (for example , fiscal obligations ) to which the Operator is subject art. 6 para. (1) letter c) of the GDPR.

Your personal data will be processed so that Katerinimou can:

  1. improve the site and the services provided through it;

  2. determine the usefulness/popularity of the web content presented on the site;

  3. send technical, assistance or administrative notifications;

  4. honor requests and resolve complaints received from users;

  5. facilitate the user's access to the services offered by the Operator;

  6. communicate information of interest to site users;

  7. protect the rights belonging to the Operator.

5. DURATION OF PERSONAL DATA PROCESSING

Personal data processed at the Katerinimou level through the website www.katerinimou.com are retained for a reasonable period of time in relation to the purpose of data processing, in accordance with the legal provisions on data archiving.

For example, if you are a client of the Operator, the latter will process your data for the entire duration of the contractual relationship and after its conclusion, in accordance with the legal obligations incumbent on Katerinimou . For example, in the case of financial and accounting supporting documents, these are archived at the Operator level in accordance with the law, for a period of 10 years from their issuance.

Regarding the e-mail address provided for the purpose of subscribing to the newsletter, the Operator will process this personal data only for the period in which the consent thus granted is valid, and will remove it from its databases at the time of withdrawal of the consent provided for direct marketing.

Telephone calls from or to the Operator are not recorded, so the data thus provided (voice, telephone number) to Katerinimou staff will not be stored in the Operator's records.

Last but not least, any other categories of personal data that are not included in the above-mentioned ones will be kept for the period necessary to fulfill the purpose for which they were processed, in compliance with the general 3-year limitation period for their deletion.

6. TRANSFER OF PERSONAL DATA . DATA RECIPIENTS

Your data is processed within the European Union, via secure internal servers. However, through social media plugins (e.g. Instagram), which are third-party recipients of the data, it is possible that your data processed in this context may be transferred outside the European Union/European Economic Area and stored on servers in third countries. In this regard, the Operator has implemented a series of necessary and appropriate measures to ensure compliant data processing.

Katerinimou undertakes that the collected data shall be processed only in accordance with the declared purposes and not to make public, sell, rent, license, transfer, etc. unauthorized the database containing information regarding the data of the data subjects to a third party not involved in fulfilling the declared purposes, except in the situation where the transfer/access/viewing, etc. is requested by the authorized bodies, in the cases provided for by the regulations in force on the date of the event.

It is possible that your data may be disclosed to other companies that provide services to us and act as authorized persons, such as providers of website maintenance, IT, legal, courier services, etc.

Your data may also be processed by our partner who provides payment processing services for Katerinimou . This data is processed in order to make the payment for your order placed online.

These entities are selected with particular care to ensure that they meet specific requirements regarding the protection of personal data. They have a limited ability to use your information for purposes other than providing services to us.

In addition to the disclosures described in this Privacy Policy, we may share information with third parties to whom you consent or request that we make such disclosure.

We will process the data securely, we will apply and maintain appropriate technical measures to protect personal data against accidental or unlawful destruction or loss, alteration, disclosure or unauthorized access, in particular when the processing involves the transmission of data over a network, as well as against any other form of unlawful processing. Questions related to the confidentiality of personal data can be sent to the email address contact@katerinimou.com.

7. LINKS, HYPERLINKS, THIRD PARTY SITES

Website www.katerinimou.com may contain links to third-party sites that may collect, in turn, your personal data, including through cookies or other similar technologies.

In the event of connecting to a third-party website, Katerinimou 's privacy policy will not be applicable to your browsing on that site.

8. WHAT ARE YOUR RIGHTS AS A DATA SUBJECT?

Any natural person browsing our website, as a data subject, has the following rights in relation to Katerinimou , as the Personal Data Controller:

  • The right to access means the right of the data subject to obtain confirmation from the Operator as to whether or not the latter is processing personal data concerning him or her and, if so, access to the said data and to information on the manner in which the data are processed;

  •  The right to rectification refers to the correction, without undue delay, of inaccurate personal data processed or to their completion, if incomplete. These can be modified by sending an e-mail to the following address: contact@katerinimou.com ;

  • The right to erasure/right to erasure ("right to be forgotten") of personal data from the database means the right of the data subject to request the erasure of personal data without undue delay where one of the following grounds applies: they are no longer necessary for the purposes for which they were collected or processed, they withdraw their consent and there is no other legal basis for the processing, they object to the processing and there are no overriding legitimate grounds , the personal data have been processed unlawfully, the personal data must be erased for compliance with a legal obligation, the personal data have been collected in connection with the provision of information society services;

  • The right to restrict processing may be exercised if the data subject requests the limitation of the processing of his or her personal data, in which case they will be used strictly for the exercise of the data subject's other legal rights, including to respond to any requests/complaints from him or her;

  • The right to portability refers to the right to receive personal data in a structured, commonly used and machine-readable format and to the right to have these data transmitted directly to another controller, when the processing is based on consent or the performance of a contract and is carried out by automated means, if this is technically feasible;

  • The right to object refers to the right of the data subject to object to the processing of personal data when the processing is necessary for the performance of a task carried out in the public interest or when it is based on a legitimate interest of;

  •  The right to object to processing based on automated individual decisions refers to the fact that the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects him or her. However, it will not be possible to exercise this right if the decision is necessary for the conclusion or performance of a contract between the data subject and Katerinimou , is authorized by the law applicable to the Operator, provided that it ensures adequate protection of the rights, freedoms and interests of the data subjects or is based on the consent of the data subject obtained in compliance with the legislation in force;

  • The right to address the National Supervisory Authority for Personal Data Processing. In the event that the data subject considers that the rights provided above have been violated, he or she has the possibility to address the ANSPDCP by filing a complaint.

The contact details of ANSPDCP are as follows:

Address : Bucharest Municipality, Sector 1, B-dul G-ral. Gheorghe Magheru no. 28-30;

Telephone : 0.318.059.211/0.318.059.212;

Fax : 0.318.059.602;

Email : anspdcp@dataprotection.ro ;

Web page : www.dataprotection.ro .

To exercise the rights provided above, the data subject will contact Katerinimou by sending a request to the postal or electronic correspondence address indicated in the first section of this Policy.

9. FINAL PROVISIONS

The provisions of the Privacy Policy are complemented by the provisions of the Cookie Policy , respectively the Newsletter Subscription Policy, present on the website www.katerinimou.com .