As of 25 May 2018, Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC applies, hereinafter referred to as the “GDPR”.
1. Definitions
- Controller — The controller responsible for processing the data within the meaning of the GDPR is UNIQUE LIGHT THERAPY S.R.L., with its registered office at București Sectorul 6, Splaiul INDEPENDENȚEI, Nr. 313B, CORP C6, Etaj 7, Ap. 72, registered with the Trade Register under no. J2025005704009, VAT ID: 51195829, email: Wellness@alexandraneamtu.net.
- Data subject — the identified or identifiable natural person (who can be identified, directly or indirectly, in particular by reference to an identifier: name, identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity). The data subject may be a person requesting a service offered by the Controller, as well as any other natural person whose personal data is transmitted to the Controller (by way of example, a customer or potential customer, a candidate for a particular available position, a user of the Controller’s site, etc.).
- Categories of data processed — personal data (first name, surname, date of birth, address, telephone number and email address, etc.) is processed by us only where you enter that data into a field on the site or send it to us by email.
- Processing of personal data — means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2. Purpose of processing personal data
a. Accessing the site
Each time a user accesses a page in our offering and each time a file is opened, the access data is saved by us and partly by third parties in the form of protocol files. Each data set comprises: the web page from which you access our page, the IP address, the date and time of access, the client’s request, the http response code, the amount of data transferred, and information about the browser program and operating system you use.
b. Geographical location
Through geographical location, using the IP address, it is technically possible to estimate the location of the internet user. Certain traffic data (such as IP addresses or other identifiers of the devices you use to access our site) may in certain circumstances be personal data, and we will treat it as such.
c. Users’ interaction with the site through the available functionality
By using the functionality available on the site, visitors can:
- submit requests;
- place orders for products/services;
- make online payments through a payment processor;
- create a customer account;
- opt in to the newsletter.
In these contexts, personal data may be processed such as: surname, first name, email address, telephone number, delivery address, the data needed for invoicing, contact preferences, and other information provided voluntarily. This data is collected and processed exclusively for the purpose of:
- managing requests and communicating with the data subject;
- processing orders and delivering products/services;
- enabling online payments securely;
- administering the customer account;
- sending commercial communications, where the data subject has given their consent to this.
All processing is carried out in accordance with the principles laid down by Regulation (EU) 2016/679 and on an appropriate legal basis (e.g. performance of a contract, consent, legitimate interest).
3. Legal basis
The processing of personal data in the context of the Controller’s use of the personal data mentioned above is based on the Controller’s legitimate interest, in accordance with the provisions of Article 6(1)(f) of Regulation (EU) 2016/679 (GDPR).
That legitimate interest consists in:
- ensuring effective communication with site visitors and customers who place an order;
- preventing possible fraud or abusive use of the public contact channels available on the site;
- ensuring the general functionality and security of the website, including as regards protecting the integrity of the IT systems and the content transmitted;
- documenting interactions initiated by data subjects, for the purpose of fulfilling legal obligations or defending the Controller’s legitimate interests in the event of a dispute.
The Controller has carried out a balancing assessment of its legitimate interest, finding that processing data in this context is proportionate, necessary for the purposes pursued, and does not prejudice the fundamental rights and freedoms of data subjects. Data subjects have the right to object to this processing, under the conditions of Article 21 GDPR.
4. Rights of the data subject regarding the processing of personal data
- Right to information and access to personal data: the right to obtain confirmation as to whether or not personal data concerning you is being processed and, if so, access to that data.
- Right to rectification: the right to request the Controller and to obtain, without undue delay, the rectification of inaccurate personal data concerning you and/or to obtain the completion of personal data that is incomplete, noting that in the case of an online account you can make these changes yourself from the account data editing section.
- Right to erasure (“right to be forgotten”): the right to obtain the erasure of personal data concerning you, without undue delay, where certain grounds set out in the GDPR apply.
- Right to restriction of processing: the right to obtain restriction of processing in certain cases.
- Right to data portability: the right to receive the personal data concerning you and to transmit it to another controller.
- Right to object: the right to object at any time to the processing of personal data concerning you, under the conditions of the GDPR.
- Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) where you consider that your data has not been processed in accordance with the legal provisions.
5. Exercising your rights
To exercise the rights mentioned above, please contact us by written, dated and signed request to the email address: Wellness@alexandraneamtu.net.
Within one month at the most, calculated from receipt of your request, you will be provided with information about the actions taken or, where applicable, about the reasons why the requested measures cannot be taken.
In order to act on a request for access to personal data, we will take all reasonable measures to verify the identity of the data subject.
In accordance with the GDPR, the response period mentioned above may be extended by no more than two months where necessary, taking into account the complexity and number of requests; we will inform you of this if applicable.
6. Transmission of data to public institutions and competent authorities
In special cases, where this is required by law, the Controller may provide competent institutions with information concerning personal data.
7. Web analytics services
Our site may use web analytics tools for statistical purposes, in order to better understand how visitors interact with our pages and to improve the user experience. These tools are configured so as to comply with the requirements imposed by Regulation (EU) 2016/679 (GDPR) as regards the protection of personal data. The use of this tool complies with the principles of data minimisation and storage limitation, in accordance with the provisions of Article 5(1)(c) and (e) GDPR.
8. Legal basis
Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (available at dataprotection.ro).
Top-level management is committed to this privacy policy being observed by all employees, through the implementation of specific internal procedures and rules on the protection of personal data, in accordance with the legal basis for processing it.