Privacy Policy
Table of Contents
- 1. How to contact us
- 2. Categories of personal data we process
- 3. Legal bases for processing your data
- 4. Purposes for which we process your personal data
- 5. To whom we will disclose your data
- 6. How long we will store your data
- 7. Security of your data
- 8. What are your rights and how you can exercise them
- 9. What can happen if you do not provide us with your data
- 10. Changes to the information notice
- 11. Meaning of some terms used
1. How to contact us
The content of this information notice is purely informative and does not affect the rights granted to you by law. We will do our best to facilitate their exercise. If you have any comments, suggestions, questions regarding any information in this notice or regarding any other aspects related to the processing of your data that we carry out, please do not hesitate to contact our data protection officer at any time. Depending on your preferences, you can contact us through any of the communication channels below:Full name: EASYPAY SYSTEM SRL
Workplace: Bd. Theodor Pallady no. 287, 4th floor, sector 3, postal code 032258, Bucharest
Phone number: (+4) 0753 999 918
Email address: office@easypaysystem.ro
2. Categories of personal data we process
The data we will process are ordinary personal data obtained directly from you or from third parties who had permission to share information with us and may include the following categories of data:- name; surname; gender; date of birth / age; nationality; home address / residence, mobile / landline phone number, fax number; email address;
- video recordings (in our premises where we have CCTV video surveillance cameras installed – where present, these are indicated by visible signs); personal identification number (CNP); the rest of the information from your identity document (including issue date, expiry date of the document, place of birth);
- your contact with us such as requesting an offer, an email, or other records of contact with us;
- payment data: billing address, bank account number or bank card number / IBAN code, name and surname of the bank account holder or bank card holder (may be different from yours if someone else made a payment for an invoice on your behalf and for you); validity date of the bank card; expiry date of the bank card;
- professional data: employer; position;
- opinions and views (may include sensitive data), such as: any opinions and views you transmit to us or any opinions and views you publicly post about us on social media or make known through other public channels;
- data related to purchases and interaction with us, such as: records of your interactions with us; details related to your purchase history from us.
- You purchase or use any of our products and services (maintenance and upkeep);
- You subscribe to newsletters, alerts, or other services offered by us;
- You contact us through various channels, or request information about a product;
- You visit or browse our website;
- You have granted permission to other companies, such as our business partners or associates, as well as when we transmit such data to third-party providers or our contractors, to the extent that we have legal grounds, for example: banking financial institutions, accounting service providers, public authorities or institutions, notaries, lawyers, etc.;
- When your personal data is public;
- We use cookies (small text files stored in your browser) and other techniques such as web beacons (small, transparent image files used to track your movements on our site).
3. Legal bases for processing your data
EASYPAY SYSTEM SRL will process your ordinary personal data based on the following legal grounds:Performance or conclusion of the contract with you.
For example, for initiating, conducting, and finalizing negotiations to conclude a contract with you, at your request, or to perform a contract concluded with you.
The consent you provide
For example, regarding our marketing communications, we process your data based on your consent for processing for this specific purpose.
Compliance with a mandatory legal requirement
For example, accounting and tax requirements that are subject to strict internal policies such as the retention period for fiscal / accounting documents. We may process your data to fulfill our archiving obligations, obligations to communicate certain information to public authorities upon request, or other legal obligations.
Our legitimate interest
There are also cases where we process your data to maintain network security and improve our services.
4. Purposes for which we process your personal data
The purposes for which we process personal data relating to you are the following:For the provision of our service
For providing the products and services you have purchased from us, as well as to keep you updated on the purchase process.
Billing and customer relations
To bill you for the purchase of our products and services, to contact you if the billing data you provided is incorrect, about to expire, or we cannot collect payment, to answer any questions or concerns you may have regarding our products and services.
Marketing communications
To the extent you have given your consent, we may keep you informed through various means (e.g., email, mobile or landline phone, text messages (SMS), mail, messages sent on social media platforms, or in person) regarding news about available products, services, offers related to them, newsletter subscriptions, or providing other information that might interest you. You can control your marketing permissions and the data we use to personalize these communications at any time on our website www.easypaysystem.ro or by using the contact details in the “How to contact us” section above.
Management of our communication and IT systems
Management of our communication systems; management of our IT security; conducting security audits on our IT networks, issuing reports to authorized institutions, or repairing system errors.
Fulfillment of our legal obligations
Fulfillment of our legal obligations regarding archiving, security, record-keeping, and other obligations imposed by law.
Improvement of products and services
Identifying potential problems with our existing products and services to improve them, resolving your complaints.
Surveillance of premises according to legal provisions
CCTV systems installed for the surveillance of access routes, areas with valuables, for monitoring and streamlining activities, and for the protection of goods and personnel in those office spaces, etc.
Research and analysis
We use analytical methods for:
- market research and for conducting research and statistical analyses;
- providing reports to third parties (these reports do not contain information that could identify you as an individual). These may be provided to third parties, such as content providers and entities advertising our products and services.
We have strict rules that ensure the anonymization or removal of identifying elements from personal data.
5. To whom we will disclose your data
As a general rule, we do not disclose your data to other companies, organizations, or individuals from any country (including Romania). However, there are certain situations where, according to the law, we must communicate your data to other natural or legal persons. However, we try to be as transparent and specific as possible, and below we will present the categories of such recipients:- If you request us or give us your consent to do so;
- To persons who can demonstrate that they have the legal authority to act on your behalf;
- Other companies within the group – for legitimate reasons related to our activity according to applicable law;
- Public authorities: at their request or on our initiative, in accordance with applicable law;
- Accountants, auditors, lawyers, and other external professional consultants, contractual partners, our service providers acting as processors or joint controllers – these will be obliged by law or by the contract concluded with us to maintain the confidentiality of your data, e.g.: archiving, accounting, storage, destruction, premises surveillance services;
- An agency, bailiff, or court in Romania – to the extent necessary for the establishment, exercise, or defense of a legal right;
- If it is in our legitimate interest to do so to manage, expand, or develop commercial activity, for example, if we sell or transfer all or part of our shares, our assets, or our business (including in the event of our reorganization, dissolution, or liquidation), in which case the personal data held by us will constitute one of the transferred assets – in this situation, potential acquirers will be bound by a confidentiality obligation.
6. How long we will store your data
We will store your data for as long as required by law. If there is no legal requirement, we will store it only for as long as necessary for processing the data for the purposes mentioned above. Unless otherwise provided by law, as a rule, we will process your data for the duration of a contract or agreement between you and EASYPAY SYSTEM SRL plus a period of 3 years from its termination, for example, for granting a lifetime warranty on equipment purchased by you. For storing your data in electronic format, we use our own servers or those of other companies specialized in electronic archiving.7. Security of your data
We have implemented the following technical and organizational measures to ensure the security of personal data:Dedicated Policies
We adopt and review our data processing practices and policies for our customers and other individuals, including physical and electronic security measures, to protect our systems from unauthorized access and other possible security threats. We constantly verify how we apply our own personal data protection policies and how we comply with data protection legislation.
Data Minimization
We have ensured that the personal data we process is limited to what is necessary, adequate, and relevant for the purposes stated in this notice.
Restriction of data access
We strictly restrict access to the personal data we process to employees, collaborators, and other persons who need to access it to process it for us. All these companies and individuals are subject to strict confidentiality obligations, and we will not hesitate to hold them accountable and terminate our collaboration with them if they do not comply with the policies regarding the protection of your data and that of other individuals.
Specific technical measures
We use technologies that ensure our customers and other individuals that their data security is protected. To protect your data security, we recommend that you do not use public (unsecured) workstations or workstations with multiple access, and also do not hand over to other people the paper document on which your data or passwords are written.
Backups and security audits
We perform daily archives (backups), which we keep securely for a minimum of six (6) months. All technical equipment we use for processing your data is secured and updated to protect the data. We also conduct regular security audits of the IT systems we use for processing the personal data of our customers and other individuals.
Ensuring the accuracy of your data
From time to time, we may ask you to confirm the accuracy and/or timeliness of the personal data about you that we process.
Staff training
We constantly train and test our employees and collaborators on legislation and best practices in the field of personal data processing.
Data anonymization
In compliance with the law, we anonymize / pseudonymize the personal data we process, so that the individuals to whom it refers cannot be identified.
Control of our service providers
We include clauses in contracts with those who process data for us (processors) or with us (other controllers – joint controllers) to ensure the protection of the data we process, in accordance with legal requirements.
8. What are your rights and how you can exercise them
We treat with seriousness and full commitment the rights you have in connection with the processing we carry out on your data. Your rights are as follows:- Right of access to data. You have the right to request information about the personal data we hold about you, including information about the categories of data we hold or control, what they are used for, the source from which we collected them if we obtained them indirectly, and to whom these data are disclosed, if applicable. We will provide you with a copy of your personal data upon request.
- Right to rectification of data. You have the right to obtain the rectification of your data that we process if it is inaccurate.
- Right to erasure of data (“right to be forgotten”). You have the right to obtain from us the erasure of your data that we process or control. EASYPAY SYSTEM SRL aims to process and retain your data only for as long as necessary. We must comply with this request if we process your personal data and if:
- personal data is no longer necessary for the purposes for which it was collected;
- you object to the processing for reasons related to your particular situation;
- your data has been unlawfully processed;
- personal data must be erased for compliance with a legal obligation incumbent on us;
- for exercising the right to freedom of expression and information;
- for compliance with a legal obligation we have;
- for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes; or
- for the establishment, exercise, or defense of a legal claim in court.
- Right to restriction of data processing. You can obtain from us the restriction of the processing of your personal data, if:
- you contest the accuracy of your personal data, for the period we need to verify the accuracy;
- the processing is unlawful, but you oppose the erasure of personal data and request the restriction of their use instead;
- your personal data is no longer needed but you require it for the establishment, exercise, or defense of a legal claim in court;
- you object to the processing, for the period during which it is verified whether, from a legal point of view, the data processing is necessary.
- Right to object to the use of personal data. You have the right to object to the processing of your data by us or on our behalf. Where processing is not based on your consent but on our legitimate interests or those of a third party, you can object at any time to the processing of your personal data for reasons related to your particular situation. In this case, we will no longer process your personal data, unless: (a) we can demonstrate compelling legitimate grounds for the processing or (b) the purpose is the establishment, exercise, or defense of a legal claim in court. If you object to the processing, please specify if you also wish for your personal data to be erased; otherwise, we will only restrict it. You can always object to the processing of your personal data for marketing purposes, whatever your reason. If marketing was based on your consent, you can withdraw your consent.
- Right to data portability. You have the right to receive the personal data you have provided to us, and if technically feasible, to request that we transmit your personal data (which you have provided to us) to another organization. These two rights are rights you have if, cumulatively: (a) we process your personal data by automated means, (b) we rely, in the processing of your personal data, on your consent or our processing of your personal data is necessary for the conclusion or performance of a contract to which you are a party; (c) your personal data is provided to us by you; and (d) the transmission of your personal data does not have a negative effect on the rights and freedoms of other individuals. You have the right to receive your personal data in a structured, commonly used, and machine-readable format. Your right to receive personal data must not adversely affect the rights and freedoms of other individuals. This could happen if a transmission of your personal data to another organization also involves the transmission of personal data of other individuals (who do not consent to this transfer). Your right for your personal data to be transmitted by us to another organization is a right you have if this transmission is technically feasible.
- Right to withdraw consent. In situations where we process your data based on your consent, you have the right to withdraw your consent; you can do this at any time, at least as easily as you initially gave your consent. The withdrawal of consent will not affect the lawfulness of the processing of your data that we carried out before the withdrawal.
- Right to lodge a complaint with the supervisory authority. If you have a complaint about how we process your data, please contact us directly so we can resolve your issue. If you still have complaints, you can contact the National Supervisory Authority for Personal Data Processing (www.dataprotection.ro):
Address: B-dul G-ral. Gheorghe Magheru no. 28-30, sector 1, Bucharest, Romania
Phone: +40 318 059 211 / +40 318 059 212
Fax: +40 318 059 602
Email: anspdcp@dataprotection.ro
Please note
To exercise one or more of these rights or to address any question about any of these rights or other aspects of our processing of your data, please use the contact details in the “How to contact us” section above, as well as the support form available on our website www.easypaysystem.ro, whenever you wish. Also, printed forms are available at our headquarters that you can fill out to request the exercise of one or more of the above rights. We will try to respond to your request within one month, a period that may be extended by two months due to specific reasons related to the specific right invoked or the complexity of your request. In any case, if this period is extended, we will inform you about the extension period and the reasons that led to this extension. In certain situations, we may not be able to grant you access to all or part of your personal data due to legal restrictions. If we deny your access request, we will communicate the reason for this refusal. In certain cases, we may not be able to identify your personal data due to the identification elements you provide in the request. In such cases, if we cannot identify you as a data subject, we cannot process your request in accordance with this section, unless you provide us with additional information that allows us to identify you. We will inform you and give you the opportunity to provide such additional details.9. What can happen if you do not provide us with your data
You are not obliged to provide us with the personal data mentioned in this document. In this case, we may not be able to provide you with the services you request.10. Changes to the information notice
We reserve the right to modify, improve when necessary, our data protection practices and to update and amend this information notice at any time, to ensure that your data is secure. For this reason, we encourage you to periodically check this information notice.11. Meaning of some terms used in this notice
| What does personal data processing mean? | Personal data processing means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
|---|---|
| What does personal data mean? | Personal data means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. |
| What does personal data controller mean? | Personal data controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. |
| What does Processor mean? | The natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller. According to the law, responsibility for compliance with personal data legislation primarily rests with the controller. In relation to you, we are the controller, and you are the data subject. |
| What does Data Subject mean? | The data subject is the natural person to whom certain personal data refers (to whom it “belongs”). In relation to us (the controller), you are the data subject. |
| What is the Supervisory Authority? | An independent public authority which, according to the law, has responsibilities regarding the supervision of compliance with personal data protection legislation. In Romania, this supervisory authority for personal data processing is the National Supervisory Authority for Personal Data Processing (ANSPDCP). |
