Processing of personal data
We consider ensuring the right to the protection of personal data as a fundamental commitment of Ameco, therefore we will dedicate all necessary resources and efforts to process your data in full compliance with Regulation (EU) 2016/679 ("General Data Protection Regulation" or " GDPR "), as well as with any other applicable legislation on the Romanian territory. As one of the key principles of this legal framework is transparency, we have prepared this document to inform you about how we collect, use, transfer and protect your personal data when you interact with us about products and services. including our website or mobile applications.
Who we are and how you can contact us
Ameco is the trade name of AMECO RENEWABLE ENERGY SRL., A legal entity of Romanian nationality, having its registered office in Joseni commune, Str Principala no. 1, Harghita county, Romania, with order number in the Trade Register Office J19 / 372/2006, unique fiscal registration code RO18630351 (hereinafter "Ameco" or "new"). For the purposes of data protection legislation, we are the operator when we process your personal data.
As we are always open to hearing your opinions, as well as to provide you with any additional information you may need regarding the processing of your data, we encourage you to contact the Ameco Data Protection Officer at email@example.com or by post or courier at Str Principala no. 1, 537130, Joseni, Jud Harghita- with the mention: in the attention of the Data Protection Officer Ameco.
What categories of personal data do we process
In general, we collect your personal data directly from you, so you have control over the type of information you provide to us. By way of example, we receive information from you as follows:
When you create an Ameco account, send us: your email address, first and last name; Within your personal page (My Account) in the Ameco platform you can add additional information, such as: photo, gender, nickname, mobile phone number, landline number, date of birth, level of education, delivery addresses, alternative e-mail address -mail, bank card details, etc .;
When you place an order, you provide us with information such as: desired product, name and surname, delivery address, billing details, payment method, phone number, bank card details, etc.
We also offer you the opportunity to register on the Ameco platform through your Facebook or Google account. If you opt for one of these options, you will be directed to a page managed by Facebook Inc / Google LLC, where they will inform you about the transfer of your data to Ameco. You can consult the privacy policies of Facebook and Google, respectively, using the following links:
We may also collect and further process certain information regarding your behavior while visiting our website or using your smartphone application, in order to personalize your online experience and provide you with offers tailored to your profile.
We invite you to find out more details in this regard by consulting the section on the purposes of processing below.
On our website and in the smartphone application we can store and collect information in cookies and similar technologies, according to the Cookies Policy.
Creating an account / registration on the Ameco platform, respectively placing an order on our site constitutes YOUR AGREEMENT. regarding the collection and processing of your personal data.
With the creation of an account on our site, you must expressly accept both the Terms and Conditions and the Personal Data Processing Policy by checking the appropriate box.
We do not collect or otherwise process sensitive data, included by the General Regulation on data protection in special categories of personal data. We also do not want to collect or process data from minors under the age of 16.
What are the purposes and grounds of processing
We will use your personal data for the following purposes:
1. To provide Ameco services for your benefit. This general purpose may include, as appropriate, the following:
a) Creating and managing the account within the Ameco platform;
b) Order processing, including taking over, validating, shipping and invoicing;
c) Solving cancellations or problems of any kind related to an order, the goods or services purchased;
d) Returning the products according to the legal provisions;
e) Reimbursement of the value of the products according to the legal provisions;
g) Providing support services, including providing answers to your questions about your orders or Ameco goods or services or those of Ameco Shop partners
The processing of your data for these purposes is in most cases necessary for the conclusion and execution of a contract between Ameco and you. Also, certain processing subject to these purposes is required by applicable law, including tax and accounting law.
2. To improve our services
We always want to offer you the best online shopping experience. For this, we may collect and use certain information regarding your Buyer's behavior, we may invite you to complete satisfaction questionnaires subsequent to the completion of an order or we may conduct, directly or with the help of partners, studies and market research. We base these activities on our legitimate interest in conducting business, always taking care that your fundamental rights and freedoms are not affected.
3. For marketing We want to keep you informed about the best offers for the products / services that interest you. In this regard, we can send you any type of message (such as: e-mail / SMS / telephone / mobile push / webpush / etc.) Containing general and thematic information, information on products similar or complementary to those that you have purchased them, information about offers or promotions, information about products added to the "My Account / Cart" section or the "Account / Favorites" section, or you have shown interest in purchasing them, as well as other commercial communications such as research market and opinion polls, and we can display personalized recommendations on the website and in the smartphone application. In order to provide you with information of interest to you, we may use certain data regarding your buyer behavior (eg products viewed / added to wishlist / purchased) to create a profile for you. We always ensure that such processing is carried out in compliance with your rights and freedoms and that the decisions made thereunder have no legal effect on you and do not affect you in a similar manner to a significant extent. In most cases, we base our marketing communications on your prior consent. You can change your mind and withdraw your consent at any time by:
- Changing client account settings in the "My Subscriptions" section;
- Accessing the unsubscribe link displayed in the messages you receive from us; or through
- Contact Ameco using the contact details described above. In certain situations, we may base our marketing activities on our legitimate interest in promoting and developing our business. In any case where we use information about you for our legitimate interest, we take care and take all necessary measures to ensure that your fundamental rights and freedoms are not affected. However, you can ask us at any time, by the means described above, to stop the processing of your personal data for marketing purposes, and we will process your request.
4. To defend our legitimate interests There may be situations in which we use or transmit information to protect our rights and business. These may include:
- Measures to protect the website and users of the Ameco platform from cyber attacks:
- Measures to prevent and detect fraudulent attempts, including the transmission of information to the competent public authorities;
- Measures to manage various other risks. The general basis of these types of processing is our legitimate interest in defending our commercial activity, it being understood that we ensure that all the measures we take guarantee a balance between our interests and your fundamental rights and freedoms.
Also, in certain cases we base the processing on legal provisions such as the obligation to ensure the protection of goods and values provided by the applicable legislation in this matter. From the point of view of EU Regulation 679/2016, each processing of personal data meets one of the following conditions: the data subject has given his or her consent; it is necessary for the execution of a contract or to take steps at the request of the data subject before concluding a contract; it is necessary in order to fulfill the legal obligation incumbent on Ameco, in accordance with its object of activity; it is necessary for the fulfillment of a task of / in the public interest; it is necessary for the purpose of the legitimate interests pursued by Ameco. Your refusal makes it impossible to carry out the activities described above.
As long as we keep your personal data safe
As a general rule, we will store your personal data as long as you have an account on the Ameco platform. You may ask us to delete certain information or close your account at any time, and we will respond to such requests, subject to the retention of certain information, including after closing the account, in cases where applicable law or our legitimate interests so require.
To whom we transmit your personal data
Where applicable, we may transmit or provide access to certain personal data of yours to the following categories of recipients:
- companies within the same group of companies as Ameco;
- Ameco Shop partners;
- courier service providers;
- payment / banking service providers;
- marketing / telemarketing service providers;
- market research service providers; (tb. SCOASE)
- insurance companies;
- IT service providers;
- other companies with which we can develop joint programs for offering our goods and services on the market. If we have a legal obligation or if it is necessary to defend a legitimate interest, we may also disclose certain personal data to public authorities.
We ensure that access to your data by third parties under private law is made in accordance with the legal provisions on data protection and confidentiality of information, based on contracts concluded with them.
In which countries we transfer your personal data
We currently store and process your personal data in Romania. However, we may transfer certain of your personal data to entities located in the European Union or outside the Union, including in countries for which the European Commission has not recognized an adequate level of protection of personal data. We will always take steps to ensure that any international transfer of personal data is carefully managed in order to protect your rights and interests. Transfers to service providers and other third parties will always be protected by contractual commitments and, where applicable, by other guarantees, such as standard contractual clauses issued by the European Commission or certification schemes, such as the Privacy Shield for the protection of personal data. transferred from within the EU to the United States. You can contact us at any time, using the contact details listed above, to find out more about the countries in which we transfer your data, as well as the guarantees we have put in place regarding these transfers.
How we protect the security of your personal data
We are committed to ensuring the security of personal data by implementing appropriate technical and organizational measures in accordance with industry standards. The transmission of your personal data is done using state-of-the-art encryption algorithms and stored on secure servers, while ensuring data redundancy. We use PayU payment processor services to make payments. Any payment information is encrypted using HTTPS technology with TSL 1.2 encryption. Despite the measures taken to protect your personal data, we warn you that the transmission of information via the Internet, in general, or through other public networks, is not completely secure, there is a risk that the data may be viewed and used by third parties. unauthorized parties. We cannot be held responsible for such vulnerabilities in systems that are beyond our control. In particular, we have implemented the following technical and organizational measures to ensure the security of personal data:
(i) Data minimization. We have made sure that your personal data that we process is limited to what is necessary, appropriate and relevant for the purposes stated in this note.
(ii) Restricting access to data. We strictly restrict access to personal data that we process to employees, collaborators and others who need to access it in order to process it for us. All these companies and individuals are subject to strict confidentiality obligations and we will not hesitate to hold them accountable and stop working with them if they do not comply with your data protection policies and those of others.
(iii) Specific technical measures. We have purchased and use technologies to ensure that the security of their data is protected. We take the necessary measures to protect personal data against loss, misuse and unauthorized access, disclosure, modification or destruction. (iv) Staff training. We constantly train and test our employees and collaborators on the legislation and best practices in the field of personal data processing. (v) Data anonymization. Where possible and appropriate to our business, we anonymize / pseudo-anonymize the personal data we process so that we can no longer identify the persons to whom it relates.
What rights do you have?
The general data protection regulations will recognize a number of rights in relation to your personal data. You may request access to your data, the correction of any errors in our files and / or you may object to the processing of your personal data. You may also exercise your right to complain to the competent supervisory authority or to go to court. Where applicable, you may also have the right to request the deletion of your personal data, the right to restrict the processing of your data and the right to data portability.
More information about each of these rights can be obtained by consulting the table below. In order to exercise your rights, you may contact us using the contact details listed above. Please note the following if you wish to exercise these rights: Identity. We take seriously the confidentiality of all records that contain personal data. For this reason, please send us your requests regarding such registrations using the e-mail address of the Ameco account. Otherwise, we reserve the right to verify your identity by requesting additional information to confirm your identity.
Fees. We will not charge you a fee to exercise any rights with respect to your personal data, unless your request for access to information is unfounded, repetitive or excessive, in which case we will charge a reasonable amount. in such circumstances. We will inform you of any fees applied before resolving your request.
Response time. We intend to respond to any valid requests within a maximum of one month, unless this is particularly complicated or if you have made several requests, in which case we will respond within a maximum of two months. We will let you know if we need more than a month. We may ask you if you can tell us exactly what you want to receive or what worries you. This will help us to act faster and shorten the response time to your request.
Third party rights. We must not comply with a request if it would adversely affect the rights and freedoms of other data subjects. Target rights Description Access You can ask us:
to confirm if we process your personal data; provide you with a copy of this information;
to provide you with other information about your personal data, such as the data we have, what we use it for, to whom we disclose it, if we transfer it abroad and how we protect it, how long we keep it, what rights you have , how can you make a complaint, from where we obtained your data, to the extent that the information has not already been provided to you by this information.
You may ask us to rectify or complete your inaccurate or incomplete personal data. We may try to verify the accuracy of the data before rectifying it.
You may ask us to delete your personal data, but only if: it is no longer necessary for the purposes for which it was collected; or you have withdrawn your consent (if the data processing is based on consent); or exercise a legal right to object; or they have been processed illegally; or we have a legal obligation in this regard. We have no obligation to comply with your request to delete your personal data if the processing of your personal data is necessary: to comply with a legal obligation; or for finding, exercising or defending a right in court. There are certain other circumstances in which we are not required to comply with your request to delete data, although these are the two most likely circumstances in which we may deny this request. Please note that before exercising this right, you must download from your Ameco account and save all documents related to orders made from Ameco, regardless of whether the invoicing was made to you or to another natural or legal person (such as: invoices, warranty certificates). If you do not do this before exercising your right to delete, you will lose all these documents and Ameco will be unable to provide them to you, as the case may be, because the process of deleting the data, respectively the Ameco account , with all its data and documents, is an irreversible process.
Restricting data processing
You can ask us to restrict the processing of personal data, but only if: their accuracy is contested (see rectification section), to allow us to verify their accuracy; or the processing is illegal, but you do not want the data to be deleted; or they are no longer necessary for the purposes for which they were collected, but you need them to establish, exercise or defend a right in court; or you have exercised your right to object, and check whether our rights
prevails is ongoing. We may continue to use your personal data following a restriction request, if: we have your consent; or to establish, exercise or ensure the defense of a right in court; or to protect the rights of Ameco or any other natural or legal person.
You can ask us to provide you with personal data in a structured, commonly used and automatically readable format, or you may request that it be "ported" directly to another data controller, but in each case. only if: the processing is based on your consent or the conclusion or execution of a contract with you, and the processing is done by automatic means.
You may object at any time, for reasons related to your particular situation, to the processing of your personal data under our legitimate interest, if you consider that your fundamental rights and freedoms prevail over this interest. You may also object at any time to the processing of your data for direct marketing purposes (including profiling), without giving any reason, in which case we will cease processing as soon as possible.
Automatic decision making
You can ask not to be subject to a decision based solely on automatic processing, but only when that decision: produces legal effects on you; or affects you in a similar way and to a significant extent. This right does not apply if the decision is reached following the automatic decision- making: we are required to conclude or enter into a contract with you; is authorized by law and there are adequate guarantees for your rights and freedoms; or is based on your explicit consen.
You have the right to file a complaint with the supervisory authority regarding the processing of your personal data. In Romania, the contact details of the data protection supervisory authority are the following: National Authority for the Supervision of Personal Data Processing G-ral Blvd. Gheorghe Magheru no. 28-30, Sector 1, postal code 010336, Bucharest, Romania Phone: +40.318.059.211 or +40.318.059.212; E-mail: firstname.lastname@example.org Without affecting your right to contact the supervisory authority at any time, please contact us in advance, and we promise that we will make every effort to resolve any issues amicably.