Last update: 24th of September 2024
Please read this Privacy Policy (hereinafter referred to as the "Policy") carefully as it contains important information regarding how, when, and why ECOLOR SRL collects, uses, and stores your personal data, with whom it may share it, as well as to inform you about your rights as a data subject and the measures taken to protect your personal data, in connection with ECOLOR SRL's processing over its website, products and services.
The website www.ecolor.ro (hereinafter referred to as the "Website") is owned and managed by ECOLOR SRL, a company incorporated by Romanian laws, headquartered at 12, Duvana Street, Juc-Herghelie, Cluj, Romania.
1. APPLICABILITY
This Policy regarding the processing of personal data only applies to the processing activities performed by ECOLOR SRL.
The Website may contain information about or links to other websites that are outside ECOLOR SRL custody and/or control. Carefully read and review the privacy policies of each of those websites when you browse on them to get an understanding of how your personal data is being used and shared by those third-party websites.
2. DEFINITIONS
• "ECOLOR", "we", "us" or "our" means ECOLOR SRL and any of it's affiliates that are providing the Website, products and services.
• "Users" means any natural person or any customer's employees, representatives, consultants, contractors, or agents who are using the Services for customer's benefit.
• "You" or "your" means current or potential customer of ECOLOR, as a User of the Website, products and Services provided by ECOLOR.
• "Services" means all of our web-based websites (including this website), applications, tools and platforms that you have subscribed to or that we otherwise make available to you, and are developed, operated, and maintained by us, accessible via the Website, or another designated URL, and any ancillary products and services, including any consulting services, that we provide to you either for a fee or free of charge; Services or other products or features made available by us to you on an unpaid trial or free basis are considered free Services.
• "Personal data" means any information relating to an identified or identifiable natural person.
• "Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
• "Processing activity(ies)" means one or more operations that relate to one of the different stages that the processing of personal data may involve.
• "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Policy, ECOLOR acts as Controller.
• "Data subject" means an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
• "Consent" of the data subject means any freely given, specific, informed and unambiguous indication of the user's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
3. COLLECTING PERSONAL DATA
In general, the personal data we process is collected directly from you, as a data subject. However, there may be situations where your personal data is collected indirectly from social media, from the website of the company you represent, from your employer as a contact person, from a third party who recommended you or from various public platforms (for example ad platforms).
When we, as the Controller, do not receive the personal data directly from you, we will inform you within the legal term about our processing of your personal data.
If you provide us with personal data belonging to other individuals (for example, colleagues), you have the responsibility to inform them about how we process their personal data for the purposes mentioned below, as well as regarding their rights related to the processed personal data. You are also responsible to ensure that you rely on the appropriate legitimate ground for collecting and sharing the personal data, such as obtaining the consent of the individuals concerned, when this consent is required by the law for processing of their personal data, such as collection, use, storage and transfer.
4. CHILDREN AND SPECIAL DATA
Our Website and Services are not directed at children. We do not knowingly or intentionally collect personal data from children who have not reached the level of maturity in their country and who are not able to assume obligations in accordance with the applicable legislation.
If you are the holder of parental responsibility of a child who has not reached the level of maturity in the country of residence and you believe your child has provided us with personal data, please contact us to request the erasure of their personal data and we will act upon your request in accordance with the legal requirements.
We do not collect nor is our intention to collect personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation, or personal data relating to criminal convictions and offences or related security measures, excepting the situations expressively regulated by the law.
5. PROCESSED PERSONAL DATA, PURPOSES, LEGAL GROUNDS AND RETENTION PERIODS
Below you will find information about the purposes for which we process your personal data, the categories of personal data we collect for those purposes, the legal grounds on which we carry out the processing activities and the periods of time we store the personal data in relation to the purposes of the processing.
Where the lawful basis for the processing is the data subject's consent, you may withdraw your consent at any time without constraint and without affecting the lawfulness of the processing prior to its withdrawal.
Depending on the nature of our relationship or interaction, we will process your personal data for the following purposes:
5.1. Purpose: Solving your requests and/or complaints.
Personal data categories: first name, last name, e-mail address, telephone number, address, and any other data you voluntarily provide in your request and/or complaint.
Legal basis: our legitimate interest to communicate with you and to provide our support in resolving your request and/or complaint.
Retention period: personal data is stored for a period of 1 (one) year from the date of submission of the response to your request and/or complaint. At the end of the storage period, personal data will be deleted.
5.2. Purpose: Ensuring participation in the contracting procedure in order to prepare the offer, the tender, the negotiation.
Personal data categories: first name, last name, e-mail address, telephone number, company, position, powers of representation, signature.
Legal basis: our legitimate interest in concluding a contract with the company you represent.
Retention period: personal data processed in the pre-contractual phase is stored for a period of 3 (three) years from the termination of the contracting procedure. At the end of the storage period, personal data will be deleted.
5.3. Purpose: Conclusion and execution of the contract with the company you represent.
Personal data categories: first name, last name, e-mail address, telephone number, company, position, powers of representation, signature.
Legal basis: our legitimate interest to conclude and execute the contract with the company you represent.
Retention period: personal data is stored for a period of 3 (three) years from the termination of the contractual relationship with the company that you represent. At the end of the storage period, personal data will be deleted.
5.4. Purpose: Establishing, exercising, or defending a right in proceedings before a court, administrative procedure or other formal proceedings in which we are involved.
Personal data categories: first name, last name, e-mail address, telephone number, company, position, powers of representation, signature, as well as any other personal data necessary to fulfill the purpose.
Legal basis: our legitimate interest to defend or exercise our rights and interests, in conjunction with the fulfillment of a legal obligation incumbent upon us as the controller.
Retention period: personal data are stored according to the legislation in force, or until the final settlement of the case. At the end of the storage period, personal data will be deleted.
5.5. Purpose: Comply with legal obligations such as accounting records, archiving, etc.
Personal data categories: first name, last name, e-mail address, telephone number, company, position, powers of representation, signature, as well as any other personal data necessary to fulfill the purpose.
Legal basis: for the purposes listed above, personal data may be retained for a longer period of time for the fulfillment of a legal obligation incumbent on us as the controller.
Retention period: personal data is stored in accordance with the regulations on the protection of personal data, as long as they are required by law or are necessary to fulfill the purpose. At the end of the storage period, personal data will be deleted.
5.6. Purpose: Selection of candidates for vacancies within the company for employment.
Personal data categories: first name, last name, e-mail address, phone number, address, country of residence, information on the professional/work experience of the candidate (former employers, current employer, seniority in the current position), information on studies, diplomas, certifications, profile on a professional social media platform (e.g LinkedIn), as well as any other data included in the CV.
Legal basis: steps at your request in order to conclude an employment contract.
Retention period: personal data is stored during the recruitment process and subsequently for a period of 6 (six) months to manage possible complaints. At the end of the storage period, the data will be deleted.
Additional information regarding the processing of your personal data for purposes compatible with this purpose can be found in the Privacy Notice regarding the processing of personal data in the recruitment and selection process, available on our website in the Careers Section.
5.7. Purpose: Contacting the candidate for future positions within the company.
Personal data categories: first name, last name, e-mail address, phone number, address, country of residence, information on the professional/work experience of the candidate (former employers, current employer, seniority in the current position), information on studies, diplomas, certifications, profile on a professional social media platform (e.g LinkedIn), as well as any other data included in the CV.
Legal basis: your freely expressed consent. You can withdraw your consent at any time without restrictions and without the withdrawal of consent affecting the lawfulness of the processing based on consent prior to its withdrawal.
Retention period: personal data is stored for a period of 6 (six) months from the date of completion of the recruitment process during which personal data was collected, or until the withdrawal of the consent of the candidate. At the end of the storage period, personal data will be deleted.
5.8. Purpose: Ensuring the safety and security of company property and persons, when you visit our premises.
Personal data categories: your image filmed by the video cameras when accessing our premises.
Legal basis: fulfillment of our legal obligations under the legislation on the protection of objectives, goods, values and the protection of persons, in conjunction with our legitimate interest to protect our goods and data and those of our employees/our clients against a case of theft, destruction, unauthorized disclosure etc.
Retention period: the images filmed by the video cameras are stored for 30 (thirty) days. At the end of the storage period, personal data will be deleted.
5.9. Purpose: Announcing visits and identifying visitors who are located in our premises.
Personal data categories: first name, last name, destination, arrival time, departure time, the company you represent.
Legal basis: our legitimate interest in identifying you and being informed when you visit our premises.
Retention period: personal data is stored only on the day you visit us. At the end of each day, personal data is deleted.
5.10. Purpose: Providing and maintaining an internal channel for reporting information on violations of the law, as well as for investigating and dealing with misconduct, including alleged fraud, and maintaining records of reports.
Personal data categories: first name, last name, e-mail address, telephone number, date of reporting, object of reporting, signature (if applicable), voice (recorded) (if applicable), manner of resolution, as well as any other personal data subject to reporting.
Legal basis: fulfilling our legal obligations under the legislation on the protection of whistleblowers in the public interest to ensure and maintain internal reporting channels on breaches of law, in conjunction with our legitimate interest to ensure that violations of applicable laws or regulations are dealt with properly and in a timely manner in order to protect the company, employees, customers etc. from the effect of illicit acts, in conjunction with the consent of the data subject for recording the conversation (if the report is made using a telephone line or another voice messaging system) and disclosing the identity of the data subject and any other information that would allow his direct or indirect identification.
Retention period: personal data is stored for a period of 5 (five) years from the reporting date, according to the legislation on the protection of whistleblowers in the public interest. At the end of the storage period, personal data will be deleted.
5.11. Purpose: Promote the company's image by carrying out social responsibility campaigns.
Personal data categories: your image.
Legal basis: your freely expressed consent. You can withdraw your consent at any time without restrictions and without the withdrawal of consent affecting the lawfulness of the processing based on consent prior to its withdrawal.
Retention period: personal data is stored for the duration of the social responsibility promotion campaign during which the content of the promotional material was produced or until you withdraw your consent, whichever occurs first. At the end of the storage period, the data will be deleted.
6. TRACKING TECHNOLOGIES
Our website does not use cookies, plug-ins and other online identifiers (collectively referred to as "cookies") in order to ensure functional browsing or to provide a better browsing experience, to perform statistical analysis regarding accessed information, or to provide you with custom content and advertising appropriate to your preferences and interests.
7. AUTOMATED DECISION MAKING, INCLUDING PROFILING
We do not make decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
8. DISCLOSURE AND TRANSFER OF PERSONAL DATA
We may transfer your personal data, to the extent that this is necessary, to the following categories of recipients: companies from the same group, service partners, subcontractors, payment providers, archiving companies, IT service providers, software or hardware vendors, market research companies, marketing companies, public authorities, court or arbitral tribunals, as well as competent authorities to investigate criminal offenses.
Personal data may be disclosed or transferred to the categories of recipients mentioned above in order to provide our Services at the highest quality level, ensure the intervention of specialists by outsourcing parts of our business or to provide access to services and benefits according to our business partnerships, or to ensure compliance with the specific legal obligations to which we are subject according to the activity carried out.
In the event that personal data is transferred to third countries we will apply the technical and organizational measures required by law and we will inform you about the transfer in accordance with the legal requirements.
9. SECURITY OF PERSONAL DATA
The security of your personal data is important to us. Therefore, we maintain a variety of appropriate technical and organizational measures to protect your personal data from loss, misuse, and unauthorized access or disclosure. We limit access to personal data to employees or contractors who we believe reasonably need to retrieve that information to provide our Services. Considering the current state of technology, we have implemented reasonable physical, technical and procedural safeguards designed to protect your personal data, such as limiting access, encrypting, anonymizing, or storing it on secure media.
It is very important that you, as a data subject, know the risks and take the measures to protect your personal data, for example by checking the sources of information, avoiding access to suspicious or unknown links, regularly changing passwords and using appropriate antivirus and antimalware solutions.
10. YOUR RIGHTS AND HOW TO EXERCISE THEM
The law grants data subjects enforceable and effective rights concerning their personal data which can be exercised under particular conditions.
You have the following rights regarding your personal data:
• Right to be informed: You have the right to be informed regarding the processing of your personal data, as we are doing through this Policy.
• Right of access: You have the right to obtain confirmation whether or not we process your personal data, as well as information on the specifics of the processing activities, and get access to that personal data.
• Right to rectification: You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
• Right to erasure: You have the right to obtain from us without undue delay the erasure of your personal data, to the extent that the legal requirements are met. Personal data will be erased when the legal requirements are met.
• Right to restriction of processing: If the applicable legal provisions are met, you have the right to obtain the restriction of processing of your personal data.
• Right to data portability: If the applicable legal provisions are met, you have the right to receive your personal data which you have provided to us, in a structured, commonly used and machine-readable format, and the right to transmit those data to another Controller.
• Right to object In certain situations, such as when we process personal data based on legitimate interest, you have the right to object to the processing of your personal data. In the event of unjustified opposition, as Controller we are entitled to further process your personal data.
• Right to object commercial communication: You may also object to the processing of your personal data for the purpose of sending commercial messages.
• Right not to be subject to decisions based solely on automated processing, including profiling: If the applicable legal provisions are met, you have the right not to be subject to a decision based solely on automatic processing, including profiling, which has legal effects on you or affects you similar to a significant extent.
• Right to address to the Supervisory Authority: You have the right to file a complaint with the competent Supervisory Authority on any violation of your rights regarding the processing of your personal data.
If you want to contact the Supervisory Authority from your place of residence in EU, you may find the contact details at https://edpb.europa.eu/about-edpb/aboutedpb/members_en.
• Consent withdrawal: To the extent that we process your personal data based on your given consent, you can withdraw your consent at any time, without affecting the lawfulness of the processing based on the consent prior to its withdrawal.
Except for the right to contact the Supervisory Authority, which you can exercise using the contact details indicated above, you can exercise your legal rights by contacting our Data Protection Officer by e-mail at dpo@ecolor.ro.
We will respond to your requests without undue delay and in any case within one month of receiving the request. This period may be extended by two months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receiving your request, stating the reasons for the delay.
In the event that we do not take action on your request, we will inform you, without undue delay and no later than one month after the receipt of your request, of the reasons for not taking action. In such a case, you have the possibility to lodge a complaint with the competent Supervisory Authority or to take a legal action.
11. UPDATES
This Policy is subject to periodic reviews and updates to ensure that it always corresponds to reality, and it is in line with the applicable legal requirements. For this reason, please regularly consult this Policy to keep up to date with any changes. Any major changes to this Policy will be notified accordingly.
12. CONTACT
If you have any questions or concerns regarding the processing of your personal data, this Policy or how it applies, or you wish to exercise any of your rights, you can contact our Data Protection Officer as follows:
• E-mail: dpo@ecolor.ro
Thank you for your interest,
ECOLOR team