English
Choose language
Choose currency
Centrul de apeluri funcționează între orele 09.00-18.00
Alegeți moneda
HYDSEALSTORE.RO © 2025-2026

Privacy Policy

PRIVACY POLICY

HYDRAULIC SEALS STORE SRL  •  https://hydsealstore.ro

Last updated: 13 July 2026  |  Version 1.0

This Policy explains how HYDRAULIC SEALS STORE SRL collects, uses, discloses and protects personal data when you visit https://hydsealstore.ro, create an account, request a quotation, place an order, request support, or interact with us by telephone, email, contact form or social media. It applies to individuals, including representatives, employees and contact persons of corporate customers or partners. Information relating exclusively to a legal entity is not personal data, but the personal data of its contacts is protected under this Policy.

This English version is intended to convey the same information as the Romanian version. If an inconsistency arises, the Romanian version prevails to the extent permitted by applicable law, without limiting any mandatory statutory rights.

1. Data controller and contact details

The data controller is HYDRAULIC SEALS STORE SRL, tax identification number (CUI) RO50330595, Trade Registry no. J2024004875231, with its registered office at 30B Trifoiului Street, Dobroești Village, Dobroești Commune, Ilfov County, postal code 077085, Romania.

For data protection questions or to exercise your rights, contact us at:

      Email: [email protected]

      Telephone: +40 773 366 558

      Post: HYDRAULIC SEALS STORE SRL, 30B Trifoiului Street, Dobroești, Ilfov, 077085, Romania, marked “Data Protection”.

2. Personal data we process and its sources

Depending on how you interact with us, we may process the following categories of personal data:

      Identification and contact data: first and last name, email address, telephone number, postal address and, where relevant, job title and the organisation you represent.

      Account data: customer type, account identifier, email address, authentication data and account preferences.

      Billing and commercial data: company name, tax/VAT number, registration number, registered office, billing address, order data, products, quantities, prices, currency, discounts, invoices and transaction history.

      Delivery data: recipient name and telephone number, delivery address, delivery instructions, tracking number and delivery status.

      Payment and refund data: payment method, amount, currency, status and transaction identifier, and bank account details where needed for a refund. Full card data is processed by the payment provider, not by us.

      Communications and support data: messages, enquiries, quotations, complaints, returns, warranties and any information you choose to provide.

      Technical and usage data: IP address, cookie or device identifiers, device and browser type, operating system, pages viewed, date and time, referral source and security log information.

      Marketing preferences: consents, objections, unsubscribe records and, where applicable, interactions with our messages.

      Social media data: profile name, public content and messages you send when interacting with our pages.

The data is mainly obtained directly from you, generated automatically when you use the Site, or received from providers involved in an order (for example, payment confirmation or delivery status), from the legal entity you represent, or from the social platform through which you contact us. Please do not send sensitive data (for example, health or biometric data, or information about beliefs or orientation) unless it is strictly necessary and expressly requested.

3. Purposes and lawful bases

We process only the data necessary for the purposes below. Where the same data is used for more than one purpose, more than one lawful basis may apply.

Purpose

Data categories

Lawful basis

Site, cart and account operation

Technical data, strictly necessary cookies, account and authentication data.

Article 6(1)(b) GDPR – contract/pre-contractual steps; Article 6(1)(f) – legitimate interests in operating and securing the Site.

Quotations, orders, contract, delivery and collection

Identification, contact, billing, order, delivery and communication data.

Article 6(1)(b) GDPR; Article 6(1)(c) where a legal obligation applies.

Payments, refunds and fraud prevention

Method, amount, status and transaction ID; refund bank account; relevant technical data.

Article 6(1)(b), (c) and (f) GDPR – contract performance, legal obligations, fraud prevention and transaction security.

Invoicing, accounting, tax and reporting

Identification/billing data, invoices, payments and supporting records.

Article 6(1)(c) GDPR – accounting, tax and record-retention obligations.

Support, returns, warranties and complaints

Contact and order data, communications, documents and relevant evidence.

Article 6(1)(b), (c) and (f) GDPR – contract, legal obligations and efficient customer relationship management.

Direct marketing and offers

Contact data, preferences, purchase history and message interactions.

Article 6(1)(a) GDPR – consent; for similar products to existing customers, Article 6(1)(f) GDPR together with Article 12(2) of Romanian Law 506/2004, with a simple and free opt-out.

Analytics, audience measurement and advertising

IP address, cookies/identifiers, device, pages and interactions.

For non-essential technologies: Article 6(1)(a) GDPR and Article 4(5) of Romanian Law 506/2004 – consent.

Security, abuse prevention and legal claims

Technical logs, account, orders, payments and relevant communications.

Article 6(1)(c) and (f) GDPR – system security, fraud prevention and establishment, exercise or defence of legal claims.

Social media interactions

Public profile, comments, reactions and messages.

Article 6(1)(b) or (f) GDPR – responding to enquiries and managing our online presence; consent where required.

 

4. Whether providing data is mandatory

Mandatory fields and data needed for a quotation, order, payment, invoice or delivery are required to enter into or perform the contract and/or comply with legal obligations. If you do not provide them, we may be unable to create the account, process the order, issue an invoice, deliver products or resolve the request. Marketing data and consent to non-essential cookies are optional, and refusing them does not affect your ability to purchase products.

5. Online payments

Card payments are processed through NETOPIA Payments. The payment provider collects and processes the data needed to authorise and secure the payment under its own privacy policy. We generally receive only information such as the amount, currency, payment status and transaction identifier, and do not receive the full card number or CVV/CVC. NETOPIA Payments may act as an independent controller for processing determined by its legal obligations and payment-system rules.

6. Cookies, Google Analytics and social media

The Site uses strictly necessary cookies for operation, security, authentication and the shopping cart. With your consent, it may use preference, analytics and marketing cookies, including Google Analytics. Non-essential cookies and similar technologies must not be activated before consent. You can accept, reject or change your choices through the cookie management tool available on the Site; withdrawing consent does not affect the lawfulness of prior processing.

Details about cookies, providers, purposes and durations are available in the Cookie Policy on the Site. Links to Facebook, Instagram and TikTok take you to services operated by independent controllers. When you access or interact with those services, their operators may collect data under their own policies.

7. Recipients of personal data

We may disclose data only as necessary to the following categories of recipients:

      IT providers: hosting, e-commerce platform, maintenance, security, backup, email and cloud services.

      Payment and financial providers: NETOPIA Payments, banks and institutions involved in payments and refunds.

      Logistics providers: couriers, carriers, postal operators, warehouses, customs brokers and customs authorities, depending on the order destination.

      Professional advisers: accountants, auditors, consultants, lawyers and insurers, to the extent necessary.

      Analytics, advertising and social providers: only as described in the Cookie Policy and, for non-essential technologies, on the basis of consent.

      Authorities and courts: ANAF, supervisory authorities, judicial bodies and other institutions where disclosure is required or permitted by law.

Providers acting on our behalf receive only the data they need and are contractually required to protect it. We do not sell personal data.

8. Transfers outside the European Economic Area

Some technology, analytics, cloud, payment or social media providers may process data outside the European Economic Area (EEA). In such cases, transfers are made only under a mechanism permitted by Chapter V GDPR, such as an adequacy decision, European Commission-approved Standard Contractual Clauses together with supplementary measures where necessary, or an applicable statutory derogation.

For orders delivered outside the EEA, recipient and delivery data may be disclosed to carriers, logistics partners and authorities in the destination country to the extent necessary to perform the contract and complete customs formalities. You may request information about the applicable safeguards using the contact details in section 1.

9. Data retention

We retain data only for as long as necessary for the relevant purpose and legal obligations. The indicative periods applied are:

Category

Period / criterion

Customer account

While the account is in use; following inactivity, for up to 3 years after the last activity, after which it may be deleted or anonymised. Order data is retained separately under the rules below.

Quotations, orders, delivery, support, returns and warranties

For the relationship and generally for 3 years after completion of the order or closure of the request; longer where a complaint, warranty or dispute remains pending.

Invoices and accounting records

Five years calculated from 1 July of the year following the end of the financial year in which the records were created, under Article 25 of Romanian Accounting Law no. 82/1991, unless another rule requires a different period.

Enquiries not followed by an order

Up to 3 years after the enquiry is resolved, unless a shorter period is appropriate.

Direct marketing

Until consent is withdrawn or an objection is made and, in any event, no more than 2 years after the last relevant interaction; proof of consent/objection may be kept for up to 3 years for compliance purposes.

Technical and security logs

Generally up to 12 months; longer where needed to investigate an incident, prevent fraud or defend a legal claim.

Cookies and identifiers

For the periods stated in the Cookie Policy and consent management tool.

Disputes and investigations

Until final closure and, where applicable, expiry of relevant enforcement or archival periods.

 

10. Automated decision-making and profiling

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. If you consent to analytics or marketing cookies, the relevant providers may create segments or inferred interests for audience measurement and ad personalisation; this does not determine whether an order is accepted or refused and can be stopped by withdrawing cookie consent.

11. Your rights

Subject to the conditions in the GDPR, you have the following rights:

      Access: to learn whether we process your data and receive a copy and the information required by law.

      Rectification: to correct inaccurate data and complete incomplete data.

      Erasure: to request deletion in the cases under Article 17 GDPR; this right is not absolute, for example where retention is required by law or necessary to defend a legal claim.

      Restriction: to request restricted use of data in the cases under Article 18 GDPR.

      Portability: to receive data you provided in a structured, commonly used and machine-readable format and, where feasible, transmit it to another controller, where processing is automated and based on consent or contract.

      Objection: to object, on grounds relating to your particular situation, to processing based on legitimate interests. You may object to direct marketing at any time without giving a reason; we will stop that processing.

      Withdrawal of consent: to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.

      Automated decisions: not to be subject to a solely automated decision with legal or similarly significant effects and, where such a decision is permitted by law, to request human intervention, express your point of view and contest the decision, under Article 22 GDPR.

      Complaint and judicial remedy: to lodge a complaint with a supervisory authority and seek a remedy before the competent courts.

12. How to exercise your rights

Send your request to [email protected] and clearly identify the right you wish to exercise and the information needed to locate your request. To protect personal data, we may request reasonable information to verify your identity and, where a representative acts for you, proof of authority.

We will respond without undue delay and generally within one month of receipt. This period may be extended by a further two months where the request is complex or numerous; we will inform you of the extension and reasons within the first month. Exercising rights is free of charge, except for manifestly unfounded or excessive requests, for which the law permits a reasonable fee or refusal.

You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): 28-30 General Gheorghe Magheru Boulevard, Sector 1, 010336 Bucharest, Romania; email: [email protected]; website: https://www.dataprotection.ro. You may also contact the supervisory authority in the EU/EEA Member State where you live, work or believe the infringement occurred.

13. Data security

We apply technical and organisational measures appropriate to the risks, including, as appropriate, access controls, least-privilege access, HTTPS-protected communications, backups, monitoring, and confidentiality obligations for staff and providers. No system can guarantee absolute security; if you suspect a problem affecting your account or personal data, contact us without delay.

14. Changes to this Policy

We may update this Policy to reflect legal, technical or service changes. The current version will be posted on the Site with the last-updated date. If a change is material, we will use a prominent Site notice or another appropriate channel where necessary. We recommend reviewing this page periodically.

This site uses cookies.
Our site uses cookies to improve your experience, personalize content, provide social networking features and analyze traffic.