Politica de confidențialitate
  1. Applicability 
  2. The privacy policy applies to the personal data of those who wish to become, are, or have been customers of SC COSROM COSMETICS S.R.L., including data collected, used, or disclosed while using our company's website, available at www.casiani.ro. When we refer to the "Company," we refer to SC Cosrom Cosmetics SRL. You can manage your consent regarding the purposes for which personal data will be used by sending an email to office@casiani.ro or by writing to Strada Londra 22, Sector 1, Bucharest. This policy is valid starting from November 15, 2023.

  3. Purpose
  4. The privacy policy helps you understand what personal data we collect about you, how we use your personal data, and what options you have regarding their use. We are committed to maintaining the accuracy, confidentiality, and security of your personal data. To be in compliance with legislative changes and/or practical realities, we reserve the right to adjust this policy at any time, with the changes becoming mandatory upon publication on the website.

  5. Personal Data
  6. Personal data are pieces of information about an identified or identifiable person. Examples of such data include: name, surname, address, telephone number, email, ID card details, personal identification number (CNP), banking information, cookies, computer's IP address, mobile device IDs, information from your web browser (such as browser type and language), actions you take on our website, etc.

  7. Purpose of Collecting
  8. Personal Data Personal data is collected for the effective conduct of commercial relationships, to provide you with the best services (fast deliveries, electronic payments, etc.), to continuously improve the functionalities of our website, or to bring relevant advertisements and promotions to your attention.
We limit the personal data we collect to what is relevant for the particular processing purposes. We do not process your personal data in ways that are incompatible with the purposes for which the information was collected or subsequently authorized by you.

CONTRACTUAL Data (mandatory) - for initiating the process of entering into a contract and for the effective conduct of the commercial relationship Data (name, surname, telephone number, email, etc.) may be collected to respond to your inquiries regarding our products and services (including using a dedicated CRM sales solution), to organize the processing and actual delivery of your orders. This data is collected through dedicated forms on the website such as: contact, online order, request for consultation, my account, etc. This data is generically referred to as "contractual data." Without them, your order cannot be processed (e.g., no tax documents can be issued for collecting the value of the products, etc.) and cannot be delivered (by courier or other accepted methods).

You will not be able to benefit from our services or products using our website without providing this data. We may disclose your personal data without giving you the option to opt out when we use third-party processors (courier companies, online payment processors, etc.) to perform services on our behalf and in accordance with our instructions. Customers cannot opt out of receiving emails related to the processing, conduct, and delivery of the order (or other processes associated with this purpose).

FUNCTIONAL Data Direct data (name, surname, telephone number, email, etc.) may be collected to ensure a better experience using the website. Data is collected through forms on the website such as: stock alert (to be notified when a product is back in stock), abandoned carts (to remind you of unfinished purchases), etc. This data is generically referred to as "data for functional purposes." Indirect data that can be used to create a better-structured website (e.g., reports from Google Analytics, etc.) may be collected. This data helps us see the navigation flow of visitors to the website, the volume of browsing, as well as other useful information relevant to improving the website, to provide you with the best browsing experience. All these functionalities are designed to provide you with the best options for information and purchase. If you do not agree to the use of data for this purpose, you cannot benefit from the advantages of these functionalities.

MARKETING Data Personal data, such as direct data (name, surname, telephone number, email, etc.) or indirect data (cookies, computer's IP address, location, mobile device IDs, etc.), may be collected. Direct data is collected for newsletter subscriptions (sending informative newsletters, etc.). If you no longer wish to receive such materials, you can access the "unsubscribe" link at the bottom of the Company's marketing emails. Cookies are data files sent from a website to a browser to record user information for various purposes. We use cookies and similar technologies. For additional information, refer to the page on our website containing the cookie policy. Data may be used to display ads tailored to your desires (e.g., Google Remarketing, Facebook Pixel, etc.). You may be presented with ads for products you have been interested in or viewed. Our website allows you to connect with social media networks, such as social media networks. By connecting, your IP address and the page you visit on our website may be collected. A cookie may also be set to allow social media applications to function correctly. You may be offered an option by social media accounts to post information about your activities on your personal profile page in the social media network, allowing other users access to that information from your network. These data are generically referred to as "data for marketing purposes."

 

  1. Collection and Management of Consent
  2. When you interact with our website, we offer you the opportunity to grant and withdraw your consent for the use of your data at any time. We provide visitors to the website and Users/Buyers who provide personal data with the means to choose how we use this data.
Consent regarding the processing of personal data may be requested when creating an account, placing an order (with or without an account), launching a form, as well as for any other purpose involving the granting of consent, by accessing a general control panel (cumulative or individual, for each category of data or individual purpose) or by other technical means created for this purpose.

You will have the opportunity to explicitly give your consent regarding the purposes for which personal data will be used and to manage it subsequently, in accordance with applicable regulations.

  1. Rights
  2. We make every effort to guarantee your rights in accordance with current legislation. You have the right to access your personal data. Accordingly, if applicable, we provide you with access to the personal data we hold about you and offer you the opportunity to choose whether you want to receive offers and promotions from us, as well as to correct, modify, or delete your information.
We may limit or refuse access to personal data if the effort or expense of providing access would be disproportionate to the risks to your privacy, or if the rights of other individuals, other than yourself, would be violated. Other reasons for refusing or limiting access may include restrictions imposed by applicable law or other similar justifications.

You have the right to modify and delete your personal data, especially incomplete or inaccurate data; for example, if some of the personal data you provided (phone number, email address, authorized person, etc.) are no longer current.

We take reasonable measures to ensure that the personal data we process are viable for the intended use and accurate, complete, and up-to-date. In this regard, we rely on you to update and correct personal data as necessary for the purposes for which they were collected or subsequently authorized by you.

Requests for access, modification, or deletion of information will be processed within 30 days.

You have the right to restrict processing, object to the processing of personal data concerning you, and request rectification, updating, or deletion of data under the law. This right can be exercised at any time, free of charge and without justification, except for those data for which processing is a legal obligation.

You have the right to request the portability (export) of personal data. We may limit or refuse the portability of personal data if the effort or expense of providing access would be disproportionate to the benefits in that specific case.

You have the right not to be subject to an individual decision with automatic character.

You have the right to lodge a complaint with the National Authority for the Supervision of Personal Data Processing (A.N.S.P.D.C.P.), as well as to seek justice, in accordance with the applicable legal provisions.

  1. To whom do we disclose your data and where do we transfer them?
  2. We collaborate with courier companies, authorized electronic payment processors, and internet companies: Google, Facebook, etc. - all for the best possible experience with our website.
We may share your personal data with contracted service providers for order processing and delivery (such as payment processors, courier service providers, etc.), to improve the user experience of the online store (e.g., Google Analytics, etc.), or to provide marketing, advertising, and advertising services (Google, Facebook, Mailchimp, etc.), as well as for other purposes: accounting services, legal services, consulting, affiliates, business partners, etc. Disclosure of data is based on the fact that the necessary services for the conduct of our business cannot be provided by us.

We make every effort to have a confidentiality commitment from them, guaranteeing that this data is kept safe and that the provision of this personal information is made in accordance with applicable law.

In the event that our hosting service providers, newsletter delivery, or other similar services are transferred outside the European Economic Area (EEA), efforts are made to ensure adequate protection measures.

We may disclose your personal data by legal prescription, legal proceedings, litigation, and/or requests from public and governmental authorities in your country of residence or abroad. We may also disclose personal information about you if we determine that disclosure is reasonably necessary to ensure compliance with our terms and conditions or to protect our operations or users. Relevant information can also be found in announcements regarding specific data processing activities.

Additionally, we may transfer personal data in the event of an audit or in the event of a sale or transfer, total or partial, of our business or assets (including in the event of a merger, acquisition, joint venture, reorganization, dissolution, or liquidation).

  1. Ensuring Data Security
  2. We take reasonable and appropriate measures to protect personal data from loss, misuse, and unauthorized access, disclosure, alteration, and destruction, taking into account their nature. We take all internal measures to identify and ensure the security of information, with measures being regularly verified and adapted to the state of the art.
The Company uses reputable service providers in the market (e.g., hosting services, software development services, marketing solutions, etc.) to achieve this goal.

  1. Data Retention Period
  2. The storage of personal data is done for periods specified by applicable law, for the purpose of maintaining records related to activities, for protecting rights in court and exercising other rights under the law and contracts concluded, meeting any archiving requirements, in accordance with legal provisions.
Personal data necessary for benefiting from the functionalities of our website and promotional activities are stored for an indefinite period of time, until the deletion of your account.

  1. Requests from Minors
  2. We do not provide services and do not deliver goods to minors.
Our company does not process personal data of minors under 16 years of age in its data processing activities. We do not carry out promotional marketing activities directly to minors.

Any person who provides us with personal data guarantees that they are of legal age, namely have full legal capacity. In case personal data processing takes place for a person who is not of legal age, we will stop processing this data once we become aware of this fact.

  1. Security Incidents
  2. Rectifying the situation is our priority; informing you and the authorities is the first step.
In the event of a breach of personal data, we will notify the competent data protection authorities within 72 hours, depending on the level of risk to the User or the visitor of the website.

Affected Users or website visitors will also be notified of the breach.

We will take all necessary measures to remedy the situations that have arisen, in order to protect your rights.

  1. Records
  2. We keep records to demonstrate compliance with the requirements of this policy. We will keep relevant records about: a. the purpose of processing personal data; b. the categories of data subjects and personal data processed; c. when possible, the envisaged retention periods for different categories of personal data; d. a general description of the security measures used to protect personal data; e. the exercise of the rights you have.