Privacy Policy
PRIVACY POLICY
HYDRAULIC SEALS STORE SRL
• https://hydsealstore.ro
Last updated:
13 July 2026 | Version 1.0
This
Policy explains how HYDRAULIC SEALS STORE SRL collects, uses, discloses and
protects personal data when you visit https://hydsealstore.ro, create an
account, request a quotation, place an order, request support, or interact with
us by telephone, email, contact form or social media. It applies to
individuals, including representatives, employees and contact persons of
corporate customers or partners. Information relating exclusively to a legal
entity is not personal data, but the personal data of its contacts is protected
under this Policy.
This
English version is intended to convey the same information as the Romanian
version. If an inconsistency arises, the Romanian version prevails to the
extent permitted by applicable law, without limiting any mandatory statutory
rights.
1. Data controller and contact details
The
data controller is HYDRAULIC SEALS STORE SRL, tax identification number (CUI)
RO50330595, Trade Registry no. J2024004875231, with its registered office at
30B Trifoiului Street, Dobroești Village, Dobroești Commune, Ilfov County,
postal code 077085, Romania.
For
data protection questions or to exercise your rights, contact us at:
•
Email: [email protected]
•
Telephone: +40 773 366 558
•
Post: HYDRAULIC SEALS STORE SRL,
30B Trifoiului Street, Dobroești, Ilfov, 077085, Romania, marked “Data
Protection”.
2. Personal data we process and its sources
Depending
on how you interact with us, we may process the following categories of
personal data:
•
Identification and contact
data: first
and last name, email address, telephone number, postal address and, where
relevant, job title and the organisation you represent.
•
Account data: customer type, account identifier,
email address, authentication data and account preferences.
•
Billing and commercial data:
company
name, tax/VAT number, registration number, registered office, billing address,
order data, products, quantities, prices, currency, discounts, invoices and
transaction history.
•
Delivery data: recipient name and telephone
number, delivery address, delivery instructions, tracking number and delivery
status.
•
Payment and refund data: payment method, amount,
currency, status and transaction identifier, and bank account details where
needed for a refund. Full card data is processed by the payment provider, not
by us.
•
Communications and support
data: messages,
enquiries, quotations, complaints, returns, warranties and any information you
choose to provide.
•
Technical and usage data: IP address, cookie or device
identifiers, device and browser type, operating system, pages viewed, date and
time, referral source and security log information.
•
Marketing preferences: consents, objections,
unsubscribe records and, where applicable, interactions with our messages.
•
Social media data: profile name, public content
and messages you send when interacting with our pages.
The
data is mainly obtained directly from you, generated automatically when you use
the Site, or received from providers involved in an order (for example, payment
confirmation or delivery status), from the legal entity you represent, or from
the social platform through which you contact us. Please do not send sensitive
data (for example, health or biometric data, or information about beliefs or
orientation) unless it is strictly necessary and expressly requested.
3. Purposes and lawful bases
We
process only the data necessary for the purposes below. Where the same data is
used for more than one purpose, more than one lawful basis may apply.
|
Purpose |
Data categories |
Lawful basis |
|
Site, cart and account operation |
Technical data, strictly necessary cookies,
account and authentication data. |
Article 6(1)(b) GDPR –
contract/pre-contractual steps; Article 6(1)(f) – legitimate interests in
operating and securing the Site. |
|
Quotations,
orders, contract, delivery and collection |
Identification,
contact, billing, order, delivery and communication data. |
Article
6(1)(b) GDPR; Article 6(1)(c) where a legal obligation applies. |
|
Payments, refunds and fraud prevention |
Method, amount, status and transaction ID;
refund bank account; relevant technical data. |
Article 6(1)(b), (c) and (f) GDPR – contract
performance, legal obligations, fraud prevention and transaction security. |
|
Invoicing,
accounting, tax and reporting |
Identification/billing
data, invoices, payments and supporting records. |
Article
6(1)(c) GDPR – accounting, tax and record-retention obligations. |
|
Support, returns, warranties and complaints |
Contact and order data, communications,
documents and relevant evidence. |
Article 6(1)(b), (c) and (f) GDPR –
contract, legal obligations and efficient customer relationship management. |
|
Direct
marketing and offers |
Contact
data, preferences, purchase history and message interactions. |
Article
6(1)(a) GDPR – consent; for similar products to existing customers, Article
6(1)(f) GDPR together with Article 12(2) of Romanian Law 506/2004, with a
simple and free opt-out. |
|
Analytics, audience measurement and
advertising |
IP address, cookies/identifiers, device,
pages and interactions. |
For non-essential technologies: Article
6(1)(a) GDPR and Article 4(5) of Romanian Law 506/2004 – consent. |
|
Security,
abuse prevention and legal claims |
Technical
logs, account, orders, payments and relevant communications. |
Article
6(1)(c) and (f) GDPR – system security, fraud prevention and establishment,
exercise or defence of legal claims. |
|
Social media interactions |
Public profile, comments, reactions and
messages. |
Article 6(1)(b) or (f) GDPR – responding to
enquiries and managing our online presence; consent where required. |
4. Whether providing data is mandatory
Mandatory
fields and data needed for a quotation, order, payment, invoice or delivery are
required to enter into or perform the contract and/or comply with legal
obligations. If you do not provide them, we may be unable to create the
account, process the order, issue an invoice, deliver products or resolve the
request. Marketing data and consent to non-essential cookies are optional, and
refusing them does not affect your ability to purchase products.
5. Online payments
Card
payments are processed through NETOPIA Payments. The payment provider collects
and processes the data needed to authorise and secure the payment under its own
privacy policy. We generally receive only information such as the amount,
currency, payment status and transaction identifier, and do not receive the
full card number or CVV/CVC. NETOPIA Payments may act as an independent controller
for processing determined by its legal obligations and payment-system rules.
6. Cookies, Google Analytics and social media
The
Site uses strictly necessary cookies for operation, security, authentication
and the shopping cart. With your consent, it may use preference, analytics and
marketing cookies, including Google Analytics. Non-essential cookies and
similar technologies must not be activated before consent. You can accept,
reject or change your choices through the cookie management tool available on
the Site; withdrawing consent does not affect the lawfulness of prior
processing.
Details
about cookies, providers, purposes and durations are available in the Cookie
Policy on the Site. Links to Facebook, Instagram and TikTok take you to
services operated by independent controllers. When you access or interact with
those services, their operators may collect data under their own policies.
7. Recipients of personal data
We
may disclose data only as necessary to the following categories of recipients:
•
IT providers: hosting, e-commerce
platform, maintenance, security, backup, email and cloud services.
•
Payment and financial
providers: NETOPIA
Payments, banks and institutions involved in payments and refunds.
•
Logistics providers: couriers, carriers, postal
operators, warehouses, customs brokers and customs authorities, depending on
the order destination.
•
Professional advisers: accountants, auditors,
consultants, lawyers and insurers, to the extent necessary.
•
Analytics, advertising and
social providers: only as described in the Cookie Policy and, for non-essential
technologies, on the basis of consent.
•
Authorities and courts: ANAF, supervisory
authorities, judicial bodies and other institutions where disclosure is
required or permitted by law.
Providers
acting on our behalf receive only the data they need and are contractually
required to protect it. We do not sell personal data.
8. Transfers outside the European Economic Area
Some
technology, analytics, cloud, payment or social media providers may process
data outside the European Economic Area (EEA). In such cases, transfers are
made only under a mechanism permitted by Chapter V GDPR, such as an adequacy
decision, European Commission-approved Standard Contractual Clauses together
with supplementary measures where necessary, or an applicable statutory
derogation.
For
orders delivered outside the EEA, recipient and delivery data may be disclosed
to carriers, logistics partners and authorities in the destination country to
the extent necessary to perform the contract and complete customs formalities.
You may request information about the applicable safeguards using the contact
details in section 1.
9. Data retention
We
retain data only for as long as necessary for the relevant purpose and legal
obligations. The indicative periods applied are:
|
Category |
Period / criterion |
|
Customer account |
While the account is in use; following
inactivity, for up to 3 years after the last activity, after which it may be
deleted or anonymised. Order data is retained separately under the rules
below. |
|
Quotations,
orders, delivery, support, returns and warranties |
For the
relationship and generally for 3 years after completion of the order or
closure of the request; longer where a complaint, warranty or dispute remains
pending. |
|
Invoices and accounting records |
Five years calculated from 1 July of the
year following the end of the financial year in which the records were
created, under Article 25 of Romanian Accounting Law no. 82/1991, unless
another rule requires a different period. |
|
Enquiries
not followed by an order |
Up to 3
years after the enquiry is resolved, unless a shorter period is appropriate. |
|
Direct marketing |
Until consent is withdrawn or an objection
is made and, in any event, no more than 2 years after the last relevant
interaction; proof of consent/objection may be kept for up to 3 years for
compliance purposes. |
|
Technical
and security logs |
Generally
up to 12 months; longer where needed to investigate an incident, prevent
fraud or defend a legal claim. |
|
Cookies and identifiers |
For the periods stated in the Cookie Policy
and consent management tool. |
|
Disputes
and investigations |
Until
final closure and, where applicable, expiry of relevant enforcement or
archival periods. |
10. Automated decision-making and profiling
We
do not make decisions based solely on automated processing that produce legal
effects concerning you or similarly significantly affect you. If you consent to
analytics or marketing cookies, the relevant providers may create segments or
inferred interests for audience measurement and ad personalisation; this does
not determine whether an order is accepted or refused and can be stopped by
withdrawing cookie consent.
11. Your rights
Subject
to the conditions in the GDPR, you have the following rights:
•
Access: to learn whether we process
your data and receive a copy and the information required by law.
•
Rectification: to correct inaccurate data
and complete incomplete data.
•
Erasure: to request deletion in the
cases under Article 17 GDPR; this right is not absolute, for example where
retention is required by law or necessary to defend a legal claim.
•
Restriction: to request restricted use of
data in the cases under Article 18 GDPR.
•
Portability: to receive data you provided
in a structured, commonly used and machine-readable format and, where feasible,
transmit it to another controller, where processing is automated and based on
consent or contract.
•
Objection: to object, on grounds
relating to your particular situation, to processing based on legitimate
interests. You may object to direct marketing at any time without giving a
reason; we will stop that processing.
•
Withdrawal of consent: to withdraw consent at any
time, without affecting the lawfulness of processing before withdrawal.
•
Automated decisions: not to be subject to a
solely automated decision with legal or similarly significant effects and,
where such a decision is permitted by law, to request human intervention,
express your point of view and contest the decision, under Article 22 GDPR.
•
Complaint and judicial
remedy: to
lodge a complaint with a supervisory authority and seek a remedy before the
competent courts.
12. How to exercise your rights
Send
your request to [email protected] and clearly identify the right you wish
to exercise and the information needed to locate your request. To protect
personal data, we may request reasonable information to verify your identity
and, where a representative acts for you, proof of authority.
We
will respond without undue delay and generally within one month of receipt.
This period may be extended by a further two months where the request is
complex or numerous; we will inform you of the extension and reasons within the
first month. Exercising rights is free of charge, except for manifestly
unfounded or excessive requests, for which the law permits a reasonable fee or
refusal.
You
may lodge a complaint with the Romanian National Supervisory Authority for
Personal Data Processing (ANSPDCP): 28-30 General Gheorghe Magheru Boulevard,
Sector 1, 010336 Bucharest, Romania; email: [email protected]; website:
https://www.dataprotection.ro. You may also contact the supervisory authority
in the EU/EEA Member State where you live, work or believe the infringement
occurred.
13. Data security
We
apply technical and organisational measures appropriate to the risks,
including, as appropriate, access controls, least-privilege access,
HTTPS-protected communications, backups, monitoring, and confidentiality
obligations for staff and providers. No system can guarantee absolute security;
if you suspect a problem affecting your account or personal data, contact us
without delay.
14. Changes to this Policy
We
may update this Policy to reflect legal, technical or service changes. The
current version will be posted on the Site with the last-updated date. If a
change is material, we will use a prominent Site notice or another appropriate
channel where necessary. We recommend reviewing this page periodically.