Privacy policy

This Privacy Policy defines how we, www.olin.ro, a website owned by OLIN SRL, collect, store and use your personal data when you access or interact with our website, and where we obtain or collect your data.
This Privacy Policy is applicable from May 22, 2018, updated with the requirements of EU Regulation 2016/679
• Data operator: OLIN S.R.L.
• How we collect or obtain information about you:

  • when you provide the respective data (eg: by contacting us, by accessing, ordering or purchasing different products, by registering in the database to receive marketing information about our products;
  • when we validate, ship and invoice an order to you;
  • to solve cancellations or problems of any kind related to an order or a contract, to the services or products purchased by you;
  • to ensure your access to the requested service;
  • sending periodic newsletters and/or alerts, exclusively in electronic format;
  • contacting you, at your voluntary request;
  • contacting you, in matters of Customer Relations;
  • statistical purposes when you access our website, some data is collected through cookies

What information do we collect: name, surname, telephone number, product delivery address, e-mail address, company name and identification data required for issuing the invoice (if applicable).
• How we use your data: in particular to contact you and to process the orders you place on our website, to fulfill our contractual obligations, to promote our goods and services and in connection with the rights and our legal obligations.
• Disclosure of data to third parties: we provide the minimum data necessary to fulfill our contractual obligations to you, namely to transport service providers.
• Your data is not sold to third parties.
• How long your information is stored: no longer than necessary - depending on our legal obligations (e.g. to maintain accounting records), or depending on any other basis on which we use the information (e.g.: consent, obligations contractual, legitimate interests). Information about specific storage periods of user data can be found in the section Duration of storing your data.
• How your data is secured: by using technical and organizational solutions such as: storing information on secure servers, encrypting data transfers to and from our servers using SSL technology, encrypting payment operations on the site using SSL technology, allowing access to your personal data only when necessary.
• Use of cookies and similar technologies: we use cookies and similar information collection technologies, such as web beacons, on our website including essential, functional, analytical and targeting cookies. For more information, please access our cookie policy here: http://www.olin.ro/politica-utilizare-cookies.html. Transfer of your personal data outside the European Economic Area: we will only transfer your personal data outside the European Economic Area if we are required to do so by law or in order to fulfill our contractual obligations to you - when we do this, we ensure that there are adequate protection measures, for example: the protection of personal data to partners outside the European Union is regulated by standard contractual clauses for the transfer of personal data from the Community to third countries.• Use of automatic decision-making processes: we use automatic decision-making processes in relation to our website, e.g.: the use of Google Analytics tools, cookies, web beacons or the use of cookies targeting to display advertisements to people who visit our site on other websites (for example, by using the Google AdWords network).

Your rights in relation to your personal data:

  • the right to information - art. 13 and 14 GDPR - you can request information regarding the processing activities of your personal data;
  • the right to rectification - art 16 GDPR - you can rectify inaccurate personal data or complete them;
  • the right to delete data ("the right to be forgotten") - art 17 GDPR - you can obtain the deletion of data, if their processing was not legal or in other cases provided by law;
  • the right to restriction of processing - art 18 GDRP - you can request the restriction of processing if you dispute the accuracy of the data, as well as in other cases provided by law;
  • the right of opposition - art 21 GDPR - you can object, in particular, to data processing based on our legitimate interest;
  • the right to data portability - art 20 GDPR - you can receive, under certain conditions, the personal data you have provided us, in a format that can be read automatically or you can request that the respective data be transmitted to another operator;
  • the right to file a complaint - you can file a complaint against the manner of personal data processing at the National Authority for the Supervision of Personal Data Processing;
  • the right to withdraw consent - in cases where the processing is based on your consent, you can withdraw it at any time. The withdrawal of consent will only have effects for the future, the processing carried out prior to the withdrawal still remaining valid;
  • additional rights related to automatic decisions: you can request and obtain human intervention regarding the respective processing, you can express your own point of view regarding this and you can contest the decision.
    You can exercise these rights, either individually or cumulatively, very easily, by simply sending a request to our headquarters in Brasov, Brazilor str., no. 55 or by email at: dpo@olin.ro

Content

• Details about our company
• What information do we collect when you visit our website
• What information do we collect when you contact us
• What information do we collect when you interact with our website
• Use of automated decision-making systems
• How we collect information about you from third parties
• Disclosure and additional uses of your data.
• Duration of storage of your data.
• Securing your information.
• Your rights to personal data
• Your right to object to data processing for certain purposes
• Sensitive personal data
• Changes to our privacy policy

Details about our company
The data operator regarding our website is: OLIN S.R.L., with headquarters in Brasov, str. Brazilor, no. 55, Romania. You can contact us by writing to the previously mentioned address or by e-mail at dpo@olin.ro.
If you have any questions about this privacy policy, please contact the data operator.
What information do we collect when you visit our website
We collect and use information from website visitors in accordance with this section and the section entitled Disclosure and additional uses of your data.
Information about the Web server log
We use a third-party server to host our website, called ROSPOT S.R.L, whose privacy policy is available here: https://rohost.com/confidentialitate/. Our website server automatically records the IP address you use to access our website, as well as other information about your visit, such as the pages accessed, the information requested, the date and time of the request, the source of access to the website our website (for example, the website or URL (link) that referred you to our website) and your browser and operating system version.
Use of information from the website's server logs for IT security purposes
Our provider collects and stores the server logs to ensure the security of the IT network. This includes analyzing log files to help identify and prevent unauthorized access to our network, the distribution of malicious code, predicting DDOS attacks and other cyber attacks by detecting unusual or suspicious activity.
If we are not investigating suspected or potential criminal activity, we do not and do not allow our provider to make any attempt to identify you based on information collected through server logs.
The legal basis for processing: compliance with the legal obligations to which we are subject (Article 6 paragraph (1) letter (c) of the General Data Protection Regulation).
Legal obligation: recording access to our website using server log files is a technical measure to ensure an adequate level of security to protect the information collected from our website in accordance with Article 32 paragraph (1) of General regulation on data protection.

Cookies and similar technologies
Cookies are data files that are sent from a website to a browser to record information about users for different purposes.
We use cookies on our website, including essential, functional, analytical and targeting cookies and web beacons. For additional information about the use of cookies, consult our cookie policy, which is available here: https://www.olin.ro/en/cookies-policy/.
You can reject some or all of the cookies we use on our website by changing your browser settings or you can disable non-essential cookies using our cookie control tool, but by rejecting them you may affect the functioning of the website or some features of the website. For additional information about cookies, including changing your browser settings, visit www.allaboutcookies.org or consult our cookie policy.

What information do we collect when you contact us?
We collect and use information from people who contact us in accordance with this section and the section entitled Disclosure and Additional Uses of Your Information.
• Email
When you send a message to the email address displayed on our website, we collect your email address and any other information you provide in that email (such as your name, your phone number and the information contained in any signature block in the e-mail).
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: To answer the questions and messages we receive and to keep records of the correspondence.
The legal basis for processing: it is necessary for the execution of a contract or to start the process of engaging in a contract at your request (Article 6 paragraph (1) letter (b) of the General Data Protection Regulation).
The reason why it is necessary for the performance of a contract: if your message concerns the provision of goods or taking measures at your request before providing you with the goods marketed by us (for example, providing information about such goods) ; we will process your information to do this.

Transfer and storage of your information.
We use a third-party email provider to store the emails you send us. Our email provider is Microsoft - Office 365. Its privacy policy is available here: https://privacy.microsoft.com/en-us/privacystatement.
The e-mails you send us will be stored inside the European Economic Area on Microsoft Office 365 servers in Austria.

Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: to answer the questions and messages we receive and to keep records of the correspondence.
The legal basis for processing: it is necessary for the execution of a contract or to start the process of engaging in a contract at your request (Article 6 paragraph (1) letter (b) of the General Data Protection Regulation).
The reason why it is necessary for the execution of a contract: if your message concerns the provision of goods or services or taking measures at your request before providing you with our goods and services (for example, providing information about such goods and services); we will process your information to do this.

• Telephone
When you contact us by phone, we collect your phone number and any information you provide during the conversation with us.

Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation)
Legitimate interest: to answer the questions and messages we receive and to keep records of the correspondence.
The legal basis for processing: it is necessary for the execution of a contract or to start the employment process in a contract at your request (Article 6 paragraph (1) letter (b) of the General Data Protection Regulation).
The reason why it is necessary for the execution of a contract: if your message concerns the provision of goods or taking measures at your request before providing you with the goods marketed by us (for example, providing information about such goods) ; we will process your information to do this).
The transfer and storage of your information.
Information about your call, such as your phone number and the date and time of your call, is processed by our telephone service providers:
- Vodafone Romania, with the confidentiality policy from the address: https://www.vodafone.ro/personal/servicii-si-tarife/termeni-si-proceduri-legale/confidentialitate/index.htm.
- Telekom Romania, with the privacy policy from the link: https://www.telekom.ro/images/docs/Legal_docs/utilizare_site/PROTECTIA_DATELOR_CU_CHARACTER_PERSONAL_telekom.ro.pdf

• Post office
If you contact us by post, we will collect all the information you provide us in any postal communications you send us.

Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation)
Legitimate interest: to answer the questions and messages we receive and to keep records of the correspondence.
The legal basis for processing: it is necessary for the execution of a contract or to start the employment process in a contract at your request (Article 6 paragraph (1) letter (b) of the General Data Protection Regulation).
The reason why it is necessary for the execution of a contract: if your message concerns the provision of goods or taking measures at your request before providing you with the traded goods (for example, providing information about such goods and services) ; we will process your information to do this).

What information do we collect when you interact with our website
We collect and use data from people who interact with certain features of our website, in accordance with this section and the section entitled Disclosure and additional uses of your information.
• Newsletter
When you sign up for our newsletter to receive information about new collections, promotions, events or contests, through the subscription forms or from any other form on the basis of which you can express your consent to register in the database, we collect names, first name, email.

Legal basis for processing: your consent (Article 6 paragraph (1) letter (a) of the General Data Protection Regulation).
Consent: you give your consent to receive our newsletter by registering to receive it, using the steps described above.
Transfer and storage of your data.
We use a service provided by a third party to send our newsletter and to manage our email list, namely Mailchimp. Information about its privacy policy can be found here: https://mailchimp.com/contact/
Mailchimp uses technologies to measure the performance of newsletter campaigns, such as delivery rates, open rates and click-through rates and unsubscribe rates, links with which the customer has interacted.
• Registration on our website
When you register and create an account on our website, we collect the following information: name, surname and e-mail address. If you do not provide all the information required by the registration form, you will not be able to register or create an account on our website.

Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: registration and administration of accounts on our website to allow you to access the history of purchased services and invoices.
Transfer and storage of your data.
The information you provide us through the registration form on our website will be stored in the European Economic Area on the servers of the web hosting service provider SC ROSPOT SRL from Romania. Its privacy policy is available here: https://rohost.com/confidentialitate/

Legal basis for processing: necessary for the execution of a contract (Article 6 paragraph (1) letter (b) of the General Data Protection Regulation).
The reason why it is necessary for the execution of a contract: we need the information collected through the order placement form in order to fulfill our obligations arising from the contract, i.e. sending the ordered goods.
Legal basis for processing: compliance with a legal obligation (Article 6 paragraph (1) letter (c) of the General Data Protection Regulation).
Legal obligation: we have the legal obligation to issue you an invoice for the goods and services you have purchased from us, in which you are registered for VAT purposes and we request the mandatory information collected for this purpose by our payment form.
Optional information
Also, please express your consent if you wish to receive marketing communications from us. For additional information, see the "Marketing Communications" section below.
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (a) of the General Data Protection Regulation).
Legitimate interests: you agree to process any optional information you provide by sending this information to us, so that you can be permanently informed about our offers and services.
Marketing communications
When completing the order, you will have the option to receive marketing communications from us, by ticking the option indicating that you wish to receive marketing communications from us.
The transfer and storage of your information.
We use a service provided by a third party to send newsletters and to manage our email list, namely Mailchimp. Information about its privacy policy can be found here: https://mailchimp.com/contact/
Mailchimp uses technologies to measure the performance of newsletter campaigns, such as delivery rates, open rates and click-through rates and unsubscribe rates, links with which the customer interacted
Legal basis for processing: consent (Article 6 paragraph (1) letter (a) of the General Data Protection Regulation).
Consent: You consent to us sending you information about our goods and services by signing up to receive such information in accordance with the steps described above.

Information collected or obtained from third parties
If we mistakenly receive information about you from a third party and/or we do not have a legal basis for processing this information, we will delete your information.

Use of automated decision-making mechanisms
We use automatic decision-making mechanisms on our website. We do not consider this to have a legal effect on you or affect you in a similar way.
You have the right to object to our use of automated decision-making and profiling mechanisms described in this section. You can do this by opting out of cookies and similar technologies, in accordance with the method described in the relevant section of this privacy policy. If you do not want us to process your real IP address (usually the IP address assigned by your Internet Service Provider) when you visit our site, you can use a virtual private network (VPN) or a free service such as Tor .
You can find out more about the use of cookies and similar technologies (including the legal basis for their use) and how to opt out of them in the cookie policy, available here: http://www.olin.ro/politica-utilizare -cookies.html
Use of automated decision-making mechanisms for advertising
Automatic decision-making mechanisms are those decision-making mechanisms by technological means (by means of a machine) without human involvement.
We automate the display of advertisements containing our products on other websites you visit by using cookies. For additional information about the types of cookies we use, see our cookie policy, available here: http://www.olin.ro

Legitimate interest: If we share your information with these third parties in a context other than where it is necessary to perform a contract (or at your request to do so), we will share your information with such third parties to enable us to run and manage our business effectively.
Legal basis for processing: it is necessary to perform a contract or to take measures at your request to conclude a contract (Article 6 paragraph (1) letter (b) of the General Data Protection Regulation).
The reason why it is necessary to perform a contract: we may share information with our service providers to enable us to fulfill our obligations arising from that contract or to take the measures you have requested before entering into a contract with you.

Disclosure of your information to other third parties
We disclose your information to third parties in certain circumstances, as set out below.
Provision of information to third parties, such as Google Inc., Facebook. Google collects information through the use of Google Analytics on our website. Google, Facebook, use this information, including IP addresses and information from cookies, for several purposes, such as improving the quality of our services and your browsing experience. The information is collected by Google and Facebook anonymously.
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interests: improving the quality of our services.

Disclosure and use of your information for legal reasons
The indication of possible criminal acts or threats to public safety to a competent authority
If we suspect that criminal or potential behavior has occurred, we will need, in certain circumstances, to contact a competent authority, such as the police. This could be the case, for example, if we suspect that a fraud or cybercrime has been committed or if we receive threats or malicious communications towards us or towards third parties.
In general, we will only need to process your information for this purpose, if you have been involved or affected by such an incident in one way or another.
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: preventing crime or suspected criminal activity (such as fraud).
In connection with the enforcement or potential enforcement of our legal rights
We will use your information in connection with the enforcement or potential enforcement of our legal rights, including, for example, sharing information with debt collection agencies, if you do not pay amounts owed when you are contractually obligated to do so . Our legal rights may be contractual (where we have entered into a contract with you) or non-contractual (such as the legal rights we have under copyright or tort).
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: to enforce our legal rights and to take measures to ensure our legal rights.
In relation to a legal or potentially legal dispute or procedure
We may need to use your information if we are involved in a dispute with you or a third party, for example, either to resolve the dispute or as part of mediation, arbitration or a court order or a similar process.
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: resolution of disputes or possible disputes.
For continuous compliance with laws, regulations and other legal requirements
We will use and process your information to comply with the legal obligations to which we are subject. For example, we may be required to disclose your information based on a court order or subpoena, if we receive one.
Legal basis for processing: compliance with a legal obligation (Article 6 paragraph (1) letter (c) of the General Data Protection Regulation).
Legal obligation: the legal obligations to disclose information, established in our charge by internal or international normative acts (for example in the form of an international agreement that Romania signed).
Legal basis for processing: our legitimate interests (Article 6 paragraph (1) letter (f) of the General Data Protection Regulation).
Legitimate interest: if the legal obligations are part of the law.

Duration of storage of your data
This section establishes how long we keep the collected data. We have set specific retention periods where possible. If this was not possible, we have established the criteria we use to determine the retention period.
Retention periods
Server logs: we keep server log information for a period of 6 months.
Information regarding orders placed: when you place an order for goods, we keep this information for ten years from the end of the financial year in which you placed the order, in accordance with our legal obligation to keep records for tax purposes.
Correspondence: when you make a request or contact us for any reason, either by e-mail or by phone, we will keep your information as long as necessary or until your express request to delete your data, which will be applied in conjunction with the legal obligations established in our charge.
Newsletter: we keep the information you used to sign up for our newsletter as long as you remain subscribed (as long as you do not unsubscribe) or if we decide to cancel our newsletter service.
Criteria for establishing retention periods
In any other circumstances, we will keep your information only as long as it is necessary, taking into account the following:
• the purpose and use of your information both now and in the future (for example, if it is necessary to continue storing that information to continue fulfilling our obligations under a contract with you or to contact you in the future;
• if we have a legal obligation to continue processing your information (such as any record keeping obligations imposed by law or relevant regulations);
• if we have any grounds to continue processing the information (such as your consent);
• if we have a legitimate interest to continue processing your data;
• the levels of risk, cost and responsibility involved in continuing to hold the information
Securing your information
We take appropriate technical and organizational measures to secure your information and to protect it against unauthorized or illegal use and accidental loss or destruction, including:
• sharing and providing access to your data to the minimum extent necessary, subject to confidentiality restrictions, where appropriate and anonymously, whenever possible;
• the use of secure servers for storing information;
• verifying the identity of any person requesting access to information before granting them access to information;
• using the Secure Sockets Layer (SSL) standard to encrypt any information you send us through any forms on our website;
• we transfer your data only through a closed system or through encrypted data transfers.

Sending information to us by e-mail
The transmission of information over the Internet is not entirely secure and if you send us information over the Internet (by e-mail or any other means), you do so entirely at your own risk.
We cannot be liable for any expense, loss of profit, damage to reputation, damages, liabilities or any other form of loss or damage suffered by you as a result of your decision to submit information to us by such means.

Your rights to personal data
Subject to certain restrictions, you have the following rights in relation to your data, which you can exercise by submitting a written request sent to OLIN SRL – www.olin.ro, at the address:
Municipality of Brasov, Str. Brazilian, no. 55 or by sending an e-mail to dpo@olin.ro:
• you have the right to access your data and receive information about its use
• you have the right to request the correction and/or completion of information (the right to rectification)
• you have the right to request the deletion of data (the right to be forgotten)
• you have the right to restrict the use of data
• you have the right to receive the data in a portable format
• you have the right to object to the processing of your data.
• you have the right to withdraw your consent for the processing of your data.
• you have the right to appeal to a supervisory authority - in accordance with Article 77 of the General Data Protection Regulation. For this purpose, in Romania, the supervisory authority is: www.dataprotection.ro
Verification of your identity if you request access to your information.
If you request access to your information, we are required by law to use all reasonable measures to verify your identity before doing so.
These measures are designed to protect your information and to reduce the risk of identity fraud and theft.