Informații complete despre modul în care colectăm, utilizăm și protejăm datele dvs. personale, conform GDPR.Complete information on how we collect, use and protect your personal data, in accordance with GDPR.
Prelucrăm datele dvs. în baza următoarelor temeiuri juridice, conform art. 6 GDPR:
Executarea unui contract (art. 6(1)(b)) — pentru comenzi, livrări și servicii contractate.
Obligație legală (art. 6(1)(c)) — pentru facturare și arhivare contabilă.
Interes legitim (art. 6(1)(f)) — pentru securizarea website-ului și prevenirea fraudelor.
Consimțământ (art. 6(1)(a)) — pentru newsletter și marketing direct (retractabil oricând).
4. Durata Stocării Datelor
Date din solicitări necontractate: maxim 12 luni de la ultima interacțiune.
Date contractuale: 10 ani de la încheierea contractului (obligație legală contabilă).
Date pentru marketing: până la retragerea consimțământului sau cererea de ștergere.
Date din loguri website: maxim 12 luni.
La expirarea perioadei de stocare, datele sunt șterse sau anonimizate ireversibil.
5. Destinatarii Datelor
Datele dvs. pot fi transmise către:
Furnizori de servicii IT — hosting, email, CRM (procesatori autorizați GDPR).
Contabil/firmă de contabilitate — pentru îndeplinirea obligațiilor fiscale.
Autorități publice — când este obligatoriu prin lege (ANAF, instanțe judecătorești etc.).
Parteneri de transport/logistică — doar datele necesare livrării (nume, adresă, telefon).
Nu vindem, nu închirim și nu facem schimb de date personale cu terțe părți în scopuri comerciale proprii.
Nu transmitem datele dvs. în afara Spațiului Economic European fără garanții adecvate conform GDPR.
6. Drepturile Dvs. (GDPR)
Conform GDPR, aveți următoarele drepturi în legătură cu datele dvs. personale:
Dreptul de accesPuteți solicita o copie a datelor pe care le deținem despre dvs.
Dreptul de rectificarePuteți solicita corectarea datelor inexacte sau incomplete.
Dreptul la ștergerePuteți solicita ștergerea datelor (cu excepțiile legale).
Dreptul la portabilitatePuteți primi datele dvs. într-un format structurat, lizibil.
Dreptul de opozițieVă puteți opune prelucrării datelor în scopuri de marketing.
Dreptul de restricțiePuteți solicita limitarea prelucrării în anumite situații.
Pentru exercitarea oricărui drept, trimiteți o solicitare scrisă la maxcomserv@yahoo.com. Vom răspunde în termen de maxim 30 de zile. Dacă nu sunteți mulțumit de răspunsul nostru, aveți dreptul să depuneți o plângere la ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal) — www.dataprotection.ro.
7. Securitatea Datelor
Implementăm măsuri tehnice și organizatorice adecvate pentru protejarea datelor dvs. personale împotriva accesului neautorizat, divulgării, alterării sau distrugerii. Printre măsurile aplicate:
Conexiune HTTPS/SSL pentru toate comunicațiile cu website-ul
Acces restricționat la date pe baza principiului "need-to-know"
Parole securizate și autentificare în doi pași pentru sistemele interne
Backup periodic al datelor pe servere securizate
Instruirea periodică a angajaților privind protecția datelor
În cazul unui incident de securitate care afectează datele dvs., vă vom notifica în conformitate cu obligațiile GDPR (în termen de 72 de ore de la identificarea incidentului, dacă este cazul).
8. Transfer Internațional de Date
În general, datele dvs. sunt prelucrate în România și în Spațiul Economic European (SEE). În situații excepționale, dacă utilizăm servicii ale unor furnizori din afara SEE (ex. servicii cloud), ne asigurăm că sunt în vigoare garanții adecvate: Clauze Contractuale Standard aprobate de Comisia Europeană sau alte mecanisme conforme GDPR.
9. Contact și Plângeri
Pentru orice întrebare sau solicitare legată de prelucrarea datelor dvs. personale, ne puteți contacta:
MaxSIP SRL — Responsabil protecția datelor
Email: maxcomserv@yahoo.com
Telefon: 0722 328 446
Adresă: Str. Ortansiei, Clinceni, Ilfov, România
ANSPDCP (autoritatea de supraveghere): www.dataprotection.ro | anspdcp@dataprotection.ro
1. What Data We Collect
MaxSIP SRL collects personal data directly (provided by you) and indirectly (through website usage). The data categories are:
1.1 Directly provided data
Identification data: first name, last name, company name (where applicable)
Contact data: email address, phone number, postal address
Commercial data: information about your project or interest, approximate budgets, location
Correspondence data: messages sent through the contact form or email
1.2 Automatically collected data
IP address and browser type
Pages visited and session duration
Traffic source (search engine, direct link, etc.)
Device used (desktop / mobile / tablet)
We do not collect special categories of data (race, religion, health, political opinions) and do not process data of minors under 16 without parental consent.
2. Purpose of Processing
Your personal data is processed exclusively for the following purposes:
Responding to inquiries — to answer questions and requests sent via form or email.
Quoting and contracting — to prepare personalized quotes and manage the contractual relationship.
Contract performance — for delivery of ordered products/services and communication throughout the project.
Legal obligations — issuing invoices, archiving accounting documents as required by law.
Direct marketing — sending information about products and offers, only with your explicit consent and with the right to withdraw at any time.
Website improvement — traffic analysis to optimize user experience (anonymized data).
3. Legal Basis for Processing
We process your data based on the following legal grounds, in accordance with Art. 6 GDPR:
Performance of a contract (Art. 6(1)(b)) — for orders, deliveries and contracted services.
Legal obligation (Art. 6(1)(c)) — for invoicing and accounting archiving.
Legitimate interest (Art. 6(1)(f)) — for website security and fraud prevention.
Consent (Art. 6(1)(a)) — for newsletter and direct marketing (withdrawable at any time).
4. Data Storage Duration
Data from non-contracted requests: maximum 12 months from the last interaction.
Contractual data: 10 years from contract completion (legal accounting obligation).
Marketing data: until consent is withdrawn or deletion is requested.
Website log data: maximum 12 months.
Upon expiry of the storage period, data is deleted or irreversibly anonymized.
5. Data Recipients
Your data may be shared with:
IT service providers — hosting, email, CRM (GDPR-authorized processors).
Accountant/accounting firm — to fulfill tax obligations.
Public authorities — when required by law (tax authorities, courts, etc.).
Transport/logistics partners — only the data necessary for delivery (name, address, phone).
We do not sell, rent or exchange personal data with third parties for their own commercial purposes.
We do not transfer your data outside the European Economic Area without adequate GDPR safeguards.
6. Your Rights (GDPR)
Under GDPR, you have the following rights regarding your personal data:
Right of accessYou can request a copy of the data we hold about you.
Right to rectificationYou can request correction of inaccurate or incomplete data.
Right to erasureYou can request deletion of your data (with legal exceptions).
Right to portabilityYou can receive your data in a structured, readable format.
Right to objectYou can object to processing for marketing purposes.
Right to restrictionYou can request limitation of processing in certain situations.
To exercise any right, send a written request to maxcomserv@yahoo.com. We will respond within a maximum of 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the competent supervisory authority in your country.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration or destruction. Among the measures applied:
HTTPS/SSL connection for all website communications
Restricted data access based on the "need-to-know" principle
Secure passwords and two-factor authentication for internal systems
Regular data backups on secure servers
Periodic employee training on data protection
In the event of a security incident affecting your data, we will notify you in accordance with GDPR obligations (within 72 hours of identifying the incident, where applicable).
8. International Data Transfer
In general, your data is processed in Romania and within the European Economic Area (EEA). In exceptional situations, if we use services from providers outside the EEA (e.g. cloud services), we ensure that adequate safeguards are in place: Standard Contractual Clauses approved by the European Commission or other GDPR-compliant mechanisms.
9. GDPR Contact and Complaints
MaxSIP SRL — Data Protection Officer
Email: maxcomserv@yahoo.com
Phone: 0722 328 446
Address: Str. Ortansiei, Clinceni, Ilfov, Romania