HidrostyleHidrostyle

Privacy Policy

The Romanian version of this document, available at Privacy Policy (RO), is the legally binding one. The English text below is a complete translation provided for convenience.

 Last updated: 25.03.2026.

 1. GENERAL INFORMATION

 1.1. Purpose of the policy

This Privacy Policy aims to inform data subjects on how personal data are collected, used, stored and protected within the activities carried out by HIDROSTYLE S.R.L., acting as a data controller. Through this policy, the controller seeks to ensure an adequate level of transparency regarding the processing of personal data, in accordance with the principles laid down by the applicable data protection legislation.

 1.2. Scope

This policy applies to all personal data processing operations carried out by the controller in connection with:

  • a) the use of the website: hidrostyle.ro;
  • b) the creation and management of user accounts;
  • c) the placement and execution of online or contractual orders;
  • d) communication with customers and potential customers;
  • e) marketing activities and the sending of commercial communications;
  • f) contractual relationships with individual customers and representatives of legal entities.

This policy applies to the following categories of data subjects:

  • website visitors;
  • individual customers;
  • representatives of legal entities;
  • persons subscribed to the newsletter or other commercial communications.

1.3. Legal framework

The processing of personal data is carried out in accordance with the applicable legal provisions, in particular Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) and Law no. 190/2018 on measures for the implementation of the GDPR, with subsequent amendments and additions.

1.4. Principles of personal data processing:

The controller processes personal data in compliance with the following principles:

  • a) lawfulness, fairness and transparency;
  • b) purpose limitation – data are collected for specified, explicit and legitimate purposes;
  • c) data minimisation – only necessary data are processed;
  • d) accuracy – data are kept up to date;
  • e) storage limitation – data are kept only for as long as necessary;
  • f) integrity and confidentiality – adequate data security is ensured.

2. IDENTITY OF THE CONTROLLER

2.1. Identification details

The data controller of personal data is HIDROSTYLE S.R.L., a Romanian legal entity, organised and operating in accordance with the applicable legislation, having the following identification details:

  • registered office: Bucureşti, Sos. Gheorghe Ionescu-Siseşti, nr. 146-156, bloc A, parter, ap. 1, camera 1, sector 1;
  • trade register registration number: J2014007062400;
  • unique registration code (CUI): RO33276925;

The Company acts as a data controller of personal data, within the meaning of Art. 4 point 7 of Regulamentul (UE) 2016/679.

 2.2. Contact details

For any questions, requests or the exercise of the rights provided by the data protection legislation, data subjects may contact the controller at:

  • e-mail address: office@hidrostyle.ro;
  • phone number: 0747 060 060;
  • postal address: Bucuresti, Sos. Gheorghe Ionescu-Sisesti, nr. 146-156, bloc A, parter, ap. 1, camera 1, sector 1;

The controller shall make all reasonable efforts to respond to requests within a reasonable timeframe, in accordance with the applicable legal provisions.

 2.3. Data protection officer

At present, the controller has not appointed a data protection officer (DPO), as it is not mandatory, since the conditions provided by Art. 37 of Regulamentul (UE) 2016/679 are not met.

For any matters regarding the processing of personal data, data subjects may contact the Controller directly, using the contact details mentioned in section 2.2.

3. CATEGORIES OF DATA SUBJECTS

In the course of its activities, the controller processes personal data belonging to the following categories of data subjects, depending on the nature of the legal relationships established and the method of communication with them:

  • a) Website visitors: Website visitors are the natural persons who access and use the website www.hidrostyle.ro without creating a user account or initiating a contractual relationship, but who may provide personal data through contact forms, newsletter subscription or through the use of automated technologies (such as cookies).
  • b) Individual customers: Individual customers are the natural persons who purchase products or services offered by the controller, either through the website or under direct contractual relationships, in which case personal data are processed for the purpose of concluding and executing the contracts.
  • c) Representatives or contact persons of legal entities: Representatives or contact persons of legal entities are natural persons acting on behalf of or in the interest of legal entities (for example, directors, legal representatives or contact persons), whose data are processed in the context of the commercial relations between the controller and the respective entities.
  • d) Newsletter subscribers: Newsletter subscribers are natural persons who have expressed their consent to receive commercial communications, including newsletters, offers or other promotional materials, through the communication channels made available by the controller.

 3.1. Protection of minors

The website and the services provided by HIDROSTYLE S.R.L. are not intended for persons who have not reached the age of 18. We do not knowingly collect or process personal data of minors. If we discover that we have accidentally collected data from a person under 18, we shall proceed to the immediate deletion of this information from our databases.

4. CATEGORIES OF PROCESSED DATA

Depending on the processing purposes and the nature of the relationships established with the data subjects, the controller may process the following categories of personal data:

4.1. Identification data

The controller processes identification data consisting of first and last name, necessary for the identification of the data subjects within the commercial relations and for their individualisation in the internal systems.

4.2. Contact data

Contact data such as email address, telephone number, home or delivery address are processed in order to communicate with the data subjects, transmit relevant information and fulfil contractual obligations, including the delivery of products.

4.3. Extended identification data

The controller may process, as the case may be, the personal identification number, the series and number of the identity document or other similar data, in the context of concluding an individual contract or when required by law.

4.4. Transaction data

The controller processes information regarding placed orders, their history and payment status. Bank card data are not collected or stored by the controller.

4.5. Technical data

The controller processes the IP address and other information resulting from the use of the website, necessary for its operation and security.

4.6. Marketing data

The data controller processes information regarding users' preferences and interaction with the services, used for marketing purposes, in accordance with the law.

5. PURPOSES AND LEGAL BASES OF PROCESSING

 The data controller processes personal data for determined, explicit and legitimate purposes, in accordance with the provisions of art. 6 of Regulamentul (UE) 2016/679, as follows:

5.1. Creation and management of the user account

Personal data are processed for the purpose of creating and managing the user account on the site, facilitating access to its functionalities and managing the relationship with users. For this purpose, identification and contact data may be processed. The legal basis for processing is the performance of a contract or steps taken at the request of the data subject prior to entering into a contract, in accordance with art. 6 para. (1) lit. b) of the GDPR.

5.2. Order processing

Personal data are processed for the purpose of receiving, validating and processing orders placed by customers. In this context, identification data, contact data and transaction data are processed.

The legal basis for processing is the performance of the contract concluded between the data controller and the data subject, in accordance with art. 6 para. (1) lit. b) of the GDPR.

5.3. Delivery of products

Personal data are used for the delivery of the ordered products, including for transmitting them to the partners involved in the delivery process. For this purpose, identification data and contact data are processed. The legal basis for processing is the performance of a contract, in accordance with art. 6 para. (1) lit. b) of the GDPR.

 5.4. Invoicing and tax obligations

Personal data are processed for the purpose of issuing tax documents, accounting records and fulfilling the legal obligations incumbent upon the data controller. In this context, identification data, contact data and, where applicable, extended identification data may be processed. The legal basis for processing is the fulfilment of a legal obligation incumbent upon the data controller, in accordance with art. 6 para. (1) lit. c) of the GDPR.

5.5. Direct marketing

Personal data are processed for the purpose of sending newsletters, offers or other commercial communications, by electronic means. For this purpose, contact data and information regarding the preferences of the data subjects are mainly processed. The legal basis for the processing is the data subject's consent, freely given, specific, informed and unambiguous, in accordance with art. 6 para. (1) lit. a) of the GDPR.  You may unsubscribe at any time by accessing the unsubscribe link included in each commercial communication or by sending a request to office@hidrostyle.ro.

5.6. Operation of the website and system security

Personal data may be processed for the purpose of ensuring the proper operation of the website, administering the IT systems and protecting them against unauthorised use. In this context, technical data and information resulting from the use of the website may be mainly processed. The legal basis for the processing is the legitimate interest of the data controller, in accordance with art. 6 para. (1) lit. f) of the GDPR.

The use of cookie-type technologies and other similar technologies is separately regulated by the Cookie Policy available on the website.

5.7. Activity analysis and internal reporting

Personal data may be processed for the purpose of conducting internal analyses, reports and statistics regarding the data controller's activity, including through the use of cloud storage and processing solutions (for example: Google Drive).

In this context, identification data, contact data and information regarding transactions may be processed, to the extent necessary to achieve the aforementioned purpose. The legal basis for the processing is the legitimate interest of the data controller, in accordance with art. 6 para. (1) lit. f) of the GDPR, consisting in the optimisation of the activity and the improvement of the services provided.

The data controller ensures that the processing is limited to the strictly necessary data and that adequate measures are implemented to protect them.

6. DATA RETENTION PERIOD

The data controller retains personal data only for the period necessary to fulfil the purposes for which they were collected, as well as subsequently, to the extent that there are legal obligations or legitimate interests justifying such retention.

The data retention period is determined according to the type of data processed and the purpose of the processing, as follows:

6.1. Data related to the user account

The data associated with the user account are retained for the entire duration of the account's existence.

If the account is no longer used, the data may be retained for a period of up to 3 years from the date of the last activity or from the date of account deletion, for the purpose of managing any requests or defending the data controller's rights.

6.2. Data related to contractual relations

Data processed for the purpose of concluding and executing contracts are retained for the duration of the contractual relationship, as well as subsequently, for the period necessary to establish, exercise or defend rights in court.

6.3. Accounting and tax data

Personal data included in financial-accounting documents are retained in accordance with applicable legal obligations, namely for a period of 5 years from the closing of the financial year in which they were drawn up.

6.4. Data processed for marketing purposes

Data processed for the purpose of sending commercial communications are retained for the duration of the consent expressed by the data subject. In the event of withdrawal of consent, the data will no longer be used for this purpose.

7. RECIPIENTS OF THE DATA

In order to fulfil the aforementioned purposes, the data controller may disclose personal data to third parties, under confidentiality conditions and only to the extent necessary for the conduct of its activity.

7.1. Service providers

Personal data may be transmitted to service providers acting on behalf of or in the interest of the data controller, including, but not limited to:

  • courier service providers, for the purpose of product delivery;
  • IT service providers, website administration and data storage providers (for example: web hosting providers, the MiniCRM platform, traffic analysis tools and cloud storage solutions such as Google Drive)
  • accounting service providers;
  • marketing and communication service providers;
  • other contractual partners involved in the conduct of the activity (for example, carriers or subcontractors).

These providers process the data exclusively based on the data controller's instructions and in accordance with applicable legal obligations regarding data protection.

7.2. Payment service providers

In the case of online payments, the data necessary for processing payments are transmitted to authorised payment service providers.

The data controller uses the services of an external payment processor (such as Netopia Payments), without having access to or storing the full card details used by customers.

7.3. Public authorities and other entities

Personal data may be disclosed to public authorities, competent institutions or other entities, to the extent that such disclosure is required by legal obligations or is necessary to protect the legitimate rights and interests of the data controller.

8. TRANSFERS OUTSIDE THE EUROPEAN UNION

In the course of its activities, the data controller does not intentionally transfer personal data to countries located outside the European Union or the European Economic Area.

To the extent that data storage or processing services provided by entities such as Google are used, certain personal data may be transferred to countries outside the European Union or the European Economic Area, including to the United States of America.

In these situations, the data controller ensures the implementation of appropriate safeguards, in accordance with the provisions of Regulamentul (UE) 2016/679, such as the use of standard contractual clauses approved by the European Commission and, where applicable, the application of other additional measures necessary to ensure an adequate level of data protection.

These safeguards may include, where applicable, the use of standard contractual clauses approved by the European Commission or other mechanisms recognised by the applicable legislation, intended to ensure an adequate level of data protection.

9. DATA SECURITY

The data controller attaches particular importance to the protection of personal data and implements appropriate measures to prevent unauthorised access, loss, destruction or disclosure thereof.

9.1. Technical measures

In order to ensure data security, the data controller uses appropriate technical measures, such as:

  • protecting access to IT systems by means of passwords;
  • using backup systems to prevent data loss;
  • using technical solutions designed to ensure the safe operation of IT systems.
  • using the HTTPS (Secure Socket Layer) protocol to encrypt information transmitted via the website, preventing the unauthorised interception of data entered by users in forms.

9.2. Organisational measures

The data controller applies organisational measures designed to limit access to personal data and to ensure its confidentiality, including:

  • granting access to data only to persons who need it to fulfil their job duties;
  • staff assuming confidentiality obligations;
  • managing access to IT systems at an internal level.

The data controller exercises all reasonable diligence to ensure an adequate level of data security, in relation to the risks presented by the processing.

10. RIGHTS OF DATA SUBJECTS

In accordance with the provisions of Regulamentul (UE) 2016/679, data subjects benefit from the following rights regarding the processing of personal data:

  1. Right to information (art. 13 si 14 GDPR) – the right to receive clear, transparent and easily accessible information regarding the manner in which personal data are processed;
  2. Right of access (art. 15 GDPR) – the right to obtain confirmation as to whether or not personal data are being processed by the Data Controller and, if so, access to such data, as well as information regarding the purposes of the processing, the categories of data concerned and their recipients.
  3. Right to rectification (art. 16 GDPR) – the right to obtain from the data controller the rectification of inaccurate data concerning you or, where applicable, the completion of personal data that are incompletely/incorrectly recorded in our internal records.
  4. Right to erasure of data (“right to be forgotten”) (art. 17 GDPR) – You have the right to request that we erase the personal data that we process about you.
  5. Right to restriction of processing (art. 18 GDPR) – You have the possibility to request us to restrict the processing of your personal data when:
  • you contest the accuracy of the personal data we process, for the period during which we verify the accuracy of the data;
  • the processing of data is unlawful, but instead of requesting the erasure of personal data you wish to restrict their processing;
  • the personal data are no longer necessary for the purpose for which they were processed, but you request those data for the establishment, exercise or defence of a right in court;
  • you have objected to the processing pursuant to art. 21 of GDPR and request restriction for the duration in which we verify whether our legitimate interest for the processing prevails.
  1. Right to data portability (Art. 20 GDPR) – Where we process your data either based on your consent or for the performance of a contract to which you are a party or in order to take steps prior to entering into a contract at your request, you have the right to receive from us your personal data in a structured, commonly used and machine-readable format.
  2. Right to object (Art. 21 GDPR) –  You have the right to object, at any time, to the processing of your personal data based on the legitimate interests of the controller or of a third party, for reasons relating to your particular situation. In this case, the controller shall cease the processing, unless it demonstrates the existence of compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
  3. Right not to be subject to a decision based solely on automated processing, including profiling (Art. 22 GDPR) – This right applies where the automated decision-making process produces legal effects concerning you or similarly significantly affects you.
  4. Right to lodge a complaint (Art. 77 GDPR)

To the extent that you have a complaint regarding the way we process your personal data, please contact us so that we can resolve the issue. You may also contact the Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal (the Romanian data protection authority) using the contact details mentioned in Chapter 15 of this Policy.

11. MEANS OF EXERCISING RIGHTS

Data subjects may exercise their rights provided by the applicable data protection legislation by sending a request to the controller, using the contact details indicated below.

11.1. Contact details

Requests regarding the exercise of rights may be sent:

  • by email, at the address: office@hidrostyle.ro;
  • by post, to the address of the controller's registered office: Bucuresti, Sos. Gheorghe Ionescu-Sisesti, nr. 146-156, bloc A, parter, ap. 1, camera 1, sector 1.

The controller may request additional information to confirm the identity of the data subject, in order to prevent unauthorised access to personal data.

11.2. Response time

The controller shall respond to requests submitted by data subjects without undue delay and, in any case, within a period of at most one month from the receipt of the request.

In justified situations, given the complexity or number of requests, this period may be extended by up to two months, the data subject being informed of this extension.

12. COOKIES

The website uses cookie-type technologies and other similar technologies to ensure its proper functioning, as well as to improve the user experience.

Detailed information regarding the types of cookies used, their purposes and the method of managing preferences is available in the Cookies Policy, accessible on the website.

13. PROFILING

The data controller does not carry out automated decision-making processes that produce legal effects on data subjects and does not perform profiling within the meaning of Art. 22 of Regulamentul (UE) 2016/679.

However, limited information regarding user preferences may be used for the purpose of sending tailored commercial communications, to the extent that the data subject's consent exists.

14. AMENDMENTS TO THE PERSONAL DATA PROTECTION POLICY

The data controller reserves the right to amend or update this privacy policy whenever necessary. The updated version will be published on the website, and to the extent that the changes are significant, data subjects will be informed through appropriate means. The date of the last update will be indicated in the introductory part of the document.

15. SUPERVISORY AUTHORITY

Data subjects have the right to lodge a complaint with the Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) (the Romanian data protection authority), if they consider that the processing of personal data infringes their rights.

The authority's contact details are as follows:

  • name: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal;
  • registered office: B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, București;
  • website: www.dataprotection.ro;
  • e-mail: anspdcp@dataprotection.ro.