INFOCOM

Privacy policy

PIATRAONLINE PRIVACY POLICY

This Privacy Policy explains how S.C. ROCK STAR CONSTRUCT S.R.L. (“PIATRAONLINE,” “the Company”) manages and handles personal data when you register or visit the website piatraonline.com, engage with us to use the Company’s services, apply for a position, supply goods/services, or act as a representative/employee/agent of a supplier company.

Contents: 1. Purpose of the policy; 2. Who we are and what we do; 3. How to contact us; 4. What personal data we collect; 5. How we use personal data; 6. Legal basis; 7. Who we share data with; 8. Use of cookies; 9. Processors, independent controllers, and associates; 10. Where we transfer data; 11. How long we keep data; 12. Confidentiality and security; 13. The right of access and other rights; 14. Changes.

1. Purpose: Explains our approach to the personal data we collect from you or obtain from a third party, the purposes of processing, and your rights.

2. Who we are: S.C. ROCK STAR CONSTRUCT S.R.L. (“PIATRAONLINE”), headquartered in Bucharest, Aleea Teișani no. 137a, Sector 1, tax ID 22680005, J40/20648/2007, legally represented by managing director Mariana Constantinescu Bradescu. PIATRAONLINE is Romania’s first, and largest, online natural stone store, with over 15 years in business.

3. Contact: [email protected].

4. What personal data we collect: The website and services are aimed at people over 18. Data is processed for: identity verification, providing products/services, improving/developing/marketing our services, performing contracts, resolving requests, investigating disputes, complying with the law, protecting rights, recruitment, business administration, and marketing. Categories, depending on the situation:

  1. Website visitors: information from cookies (display preferences, consent to cookie processing and the Terms and Conditions).

  2. Visitors using the contact form/chat/WhatsApp: first and last name, contact details (email, phone), the content of the “Message” field.

  3. User account: first/last name, contact details, password, Facebook data (name, email, profile picture) / Google data (name, email, language preferences, profile picture), order history, billing address.

  4. Placing an order on the website: user account data, order summary, price, payment method, delivery address, additional details (delivery window), showroom visit details.

  5. Paying for an order via the website: first/last name, amount, transaction ID.

  6. Orders through other channels (showroom, email): first/last name, contact details, order summary, price, payment method, billing address, delivery address, additional details.

  7. Product returns: first/last name, contact details, the product returned, the refund amount, bank account details.

  8. Comments on product pages/blog: first/last name, email, subject, comment.

  9. Customers and prospective customers: the content of requests, complaint data, marketing preferences, data for contests/giveaways/events, audio/video recordings or photos (phone calls, CCTV, online conferences), photos/recordings from events.

  10. Representative/employee/agent of a client/supplier company: first/last name, contact details, the company’s identification details, role/relationship, power-of-attorney data, activity details, complaint data, audio/video recordings, special categories (e.g. dietary preferences).

  11. Individual collaborators helping with promotion/events (architects, designers, contractors, speakers, influencers): first/last name, pseudonym, contact details, role/capacity, company represented, biography/awards, activity details, areas of expertise, promotional material content, testimonials/reviews/interviews, recordings, special categories.

  12. Interaction via social media: first/last name, profile data (username, photo, bio), message/review/rating content, location data.

  13. Prospective candidates: data from CVs, ID documents, photos, academic records, courses/certifications, work history, references; special categories (e.g. disabilities). Sources: directly from the candidate, recruitment agencies, public online sources (LinkedIn), referrals.

  14. Data processed on the instructions of, or as a result of actions by, third parties: in the context of events (name, contact details, company identification, photos/recordings) and via social media (being tagged by a friend, etc.).

  15. Data processed by third parties: 1. social media plug-ins (Like/Share buttons – collected automatically, outside the Company’s control); 2. payments through the website (third-party processors, e.g. mobilpay.ro – card data is collected by the processor, not by PIATRAONLINE); 3. external links (the Company is not responsible for the practices of third-party websites).

5. How we use the data:

I. To perform our services, deliver products, and resolve requests (processing orders, handling complaints/returns, support). Legal basis: contract/legal obligation.

  1. Business administration and legal compliance (managing registration, account administration, quality improvement, sales analysis, promotional and loyalty campaigns, business transactions, fraud prevention, protecting rights, exercising legal rights, regulatory compliance). Legal basis: legitimate interest/legal obligation/legal defense.

  2. Marketing and remarketing (email/SMS/phone/mobile push/webpush) – information about services, loyalty programs, offers, events; a profile based on purchasing behavior. Generally based on consent. Withdrawal: unsubscribe link, email to [email protected], or Google/Facebook opt-out links, the cookie module.

  3. Analytics (cookies for a personalized experience and measuring effectiveness). Legal basis: consent.

V. Recruitment (assessing suitability for positions). Legal basis: legitimate interest/pre-contractual steps.

  1. Profiling and automated decision-making (for remarketing, respecting your rights; with no significant legal effect). Legal basis: consent.

6. Legal basis: performance of contractual obligations; legitimate interest of the Company or a third party; legal obligation; consent. Special categories of data – under the conditions set out in the GDPR.

7. Who we share data with: third parties involved in our services (payment processors, banks, event partners/suppliers, marketing/PR/advertising agencies); IT, cloud, hosting, document storage, audit, and training providers; professional advisors (lawyers, assessors, tax advisors, accountants); HR and payroll companies, security firms, couriers; online promotion/newsletter service providers; prospective buyers of the business; public/regulatory/tax authorities.

8. Use of cookies: For traffic analysis and remarketing (Google AdWords, Facebook, TikTok, Instagram). Cookies are text files with a set lifespan, containing no malware. Information accessed (anonymized): IP address, country and server, operating system/browser/device, Java/cookie configuration, shopping preferences and on-site behavior, demographic information, apps/plug-ins, the address of the site that referred you to ours. Details in the Cookie Policy.

9. Processors, independent controllers, and associates: Data is only shared under a confidentiality commitment. A “Data Processing Agreement between independent/associated controllers” is signed; each controller is responsible for the lawfulness of processing data under its control and for responding to data subject requests.

10. Where we transfer data: Potentially outside the European Economic Area, subject to an adequacy decision or appropriate safeguards, or based on exceptions (explicit consent, contract performance, public interest, legal defense, vital interests, public register).

11. How long we keep data: For as long as necessary for the purpose and for legal/accounting/reporting requirements. Order/return data – until the legal obligation or legitimate interest ends; invoice data; user account data; marketing data – until unsubscription/objection. CVs of candidates who aren’t selected are not retained.

12. Confidentiality and security: Appropriate technical, physical, and organizational measures; access limited to authorized recipients; an information security program; enhanced measures for special categories of data.

13. The right of access and other rights: right of access; rectification; erasure; restriction of processing; data portability; objection (including to direct marketing and to photo/video content from events); withdrawal of consent; filing a complaint with the supervisory authority (www.dataprotection.ro). PIATRAONLINE does not make individual automated decisions with legal effect. To exercise these rights: email [email protected].

14. Changes: The policy is updated from time to time; significant changes are notified by email.

Withdrawing consent: Free of charge, at any time (e.g. opting out of marketing messages).

Contact us: Email [email protected]; PIATRAONLINE’s Data Protection Officer, Aleea Teișani 137A, 014034, Bucharest.