Processing of Personal Data

Our Privacy Policy is based on the provisions of Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR")

This Document informs you about how we collect, use, transfer and protect your personal data when you interact with us in relation to our products and services, including through our website.

We reserve the right to periodically update and amend this Privacy Policy to reflect any changes in the way we process your personal data or any changes in legal requirements. In the event of any such change, we will post the amended version of the Privacy Policy on our website, so please check the contents of the Privacy Policy periodically.

WHO WE ARE AND HOW YOU CAN CONTACT US: see "TERMS AND CONDITIONS" document

For the purposes of data protection legislation, we are a controller when processing your personal data.

As we are always open to your views, as well as to provide you with any further information you may need regarding the processing of your data, we encourage you to contact the SC Nova Pan SRL Data Protection Officer at data.protection@novapan.ro or by post or courier to Brasov, Str. Poienelor, 2A, Postal Code 500419- with the mention: for the attention of the Data Protection Officer.

PERSONAL INFORMATION WE COLLECT

When you visit the website, we automatically collect certain information about your device including information about your web browser, IP address, time zone and some cookies installed on your device. In addition, as you browse pages on the Site, we collect information about the individual web pages or products you view, which websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically collected information as Device Information.

We also collect personal information directly from you, so you have control over the type of information you provide to us. By way of example, we receive information from you like this: When you create an account on www.cofetarulistet.ro, you provide us with: your e-mail address, first and last name;

When you launch your first order, from My Account on www.cofetarulistet.ro we ask you for additional information, such as: mobile phone number, landline number, billing address, delivery addresses, alternative e-mail address, bank card details, etc.

We do not collect or otherwise process sensitive data, included by the General Data Protection Regulation in special categories of personal data. We also do not wish to collect or process data from minors under the age of 16.

HOW DO WE USE PERSONAL INFORMATION?

We use the Order Information that we collect generally to fulfil orders placed through the Website (including processing your payment information, organising shipping and providing invoices and/or order confirmations). In addition, we use this Order Information for:

- Communicating with you;

- Resolving cancellations or problems of any nature relating to an order, goods or services purchased;

- Returning products as required by law;

- Marketing

- Reimbursement of the value of the products as provided by law;

The processing of your data for these purposes is in most cases necessary for the conclusion and execution of a contract between SC Nova Pan SRL and you. Also, certain processing subsumed to these purposes is required by applicable legislation, including tax and accounting legislation.

In accordance with the preferences you have shared with us, we will provide you with information or advertising about our products or services.

We use the device information we collect to help us monitor potential risks (in particular your IP address) and generally to improve and optimise our Site (for example, by generating analytics about how our customers browse and interact with the Site and to evaluate the success of our marketing and advertising campaigns).

We want to keep you informed about the best offers on products/services that interest you. To this end, we may send you any type of message (such as: e-mail/SMS/phone/etc.) containing general and thematic information, information on products similar or complementary to the ones you have purchased, information on offers or promotions, information on products added in the "Account/My Account" or "Account/Favourites" section or you have shown interest in purchasing, as well as other commercial communications such as market research and opinion polls. In order to provide you with information of interest to you, we may use certain data about your shopping behaviour (e.g. products viewed/added to "Favourites"/purchased) to create a profile of you. We always ensure that these processing operations are carried out with respect for your rights and freedoms and that the decisions taken on the basis of these operations do not have legal effects on you and do not affect you in a similar way to a significant extent.

In most cases, we base our marketing communications on your prior consent. You can change your mind and withdraw your consent at any time by:

- Accessing the unsubscribe link displayed within the messages you receive from us;

- Contacting SC Nova Pan SRL using the contact details described above.

In certain situations, we may base our marketing activities on our legitimate interest in promoting and developing our business. In any situation where we use information about you for our legitimate interest, we take care and take all necessary steps to ensure that your fundamental rights and freedoms are not affected. However, you can ask us at any time, by the means described above, to stop the processing of your personal data for marketing purposes and we will comply with your request.

In the defence of our legitimate interests there may be situations where we will use or disclose information to protect our rights and business. These may include:

- Measures to protect the www.cofetarulistet.ro website and ContentSpeed platform users from cyber-attacks;

- Measures to prevent and detect fraud attempts, including the transmission of information to relevant public authorities;

- Measures to manage various other risks.

The general basis for these types of processing is our legitimate interest in the defence of our business, it being understood that we ensure that any measures we take strike a balance between our interests and your fundamental rights and freedoms. Also, in certain cases we base our processing on legal provisions such as the obligation to ensure the safekeeping of goods and valuables provided for by the applicable legislation in this matter.

TRANSMISSION OF PERSONAL INFORMATION & DATA RETENTION

When we talk about Personal Information in this Privacy Policy, we are talking about both Device Information and Order Information. In addition, when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, email address, and telephone number. We refer to this information as Order Information.

When you place an order through the Site, we will retain your order information, deemed Necessary, for our records unless and until you ask us to delete this information.

We transmit personal information deemed Necessary to third parties to help us process and deliver your orders as described above. The third parties to whom we provide your personal information include Fan Courier, Cargus, Google Analytics, Facebook Pixel, banking service providers.

For example, we use ecommerce platform provider ContentSpeed to provide our online store - you can read more about how ContentSpeed uses your personal information here: https: //www.contentspeed.com/legal/privacy.

We also use Google Analytics to help us understand how our customers use the Site - you can read more about how Google uses your personal information here: https: //www.google.com/intl/ro/policies/privacy/ You can also opt out of Google Analytics here: https: //tools.google.com/dlpage/gaoptout .

Finally, we may also transmit your personal information to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or other lawful request for the information we receive, or to otherwise protect our rights.

We ensure that access to your data by third parties who are private legal entities is done in accordance with the legal provisions on data protection and confidentiality of information, based on contracts with them.

YOUR RIGHTS

If you are a European resident, you have the following rights:

- to access the personal information we hold about you.

- to request the correction, updating or deletion of your personal information.

- the right to portability of collected data

- the right to lodge a complaint with a supervisory authority

If you wish to exercise these rights, please contact us at: /index.php?page=gdpr

In addition, if you are a European resident, please note that we process your information in order to fulfil any contracts we may have with you (for example, if you place an order through the Site) or to pursue your legitimate business interests listed above.

We take the confidentiality of all records containing personal data seriously. For this reason, please send us your requests regarding such records using the e-mail address data.protection@novapan.ro. We reserve the right to verify your identity by requesting additional information aimed at confirming your identity.

Please be advised that we will not charge you a fee for exercising any of your rights in relation to your personal data, unless your request for access to information is unfounded, i.e. repetitive or excessive, in which case we will charge a reasonable fee in such circumstances. We will inform you of any fees charged before we deal with your request.

We need not honour a request if it would adversely affect the rights and freedoms of other data subjects.

In Romania, the contact details of the data protection supervisory authority are as follows:

National Supervisory Authority for Personal Data Processing

B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, Bucharest, Romania

Telephone: +40.318.059.211 or +40.318.059.212; E-mail:anspdcp@dataprotection.ro

Without prejudice to your right to contact the Supervisory Authority at any time, please contact us in advance, and we promise that we will endeavour to resolve any problem amicably.

HOW LONG WE KEEP YOUR DATA PERSONAL DATA

As a general rule, we will store your personal data for as long as you have an account on the www.cofetarulistet.ro website. You may at any time request us to delete certain information or to close your account and we will comply with such requests, subject to retaining certain information even after your account is closed, where required by applicable law or in our legitimate interests.

HOW WE PROTECT THE SECURITY OF YOUR DATA. PERSONAL DATA

We are committed to ensuring the security of your personal data by implementing appropriate technical and organisational measures in accordance with industry standards. Your personal data is transmitted using state-of-the-art encryption algorithms and stored on secure servers, while ensuring data redundancy. The platform benefits from HTTPS encryption technology.

Notwithstanding the measures taken to protect your personal data, please note that the transmission of information over the Internet in general, or over other public networks, is not completely secure, with the risk that the data may be seen and used by unauthorised third parties. We cannot be responsible for such vulnerabilities in systems outside our control.