1. Introduction
At vinyllaz.com, we are committed to protecting and respecting your personal data privacy and security. This policy explains what types of information we collect, why we need them, and how we use them, in accordance with Regulation (EU) 2016/679 on data protection (GDPR). In accordance with the requirements of Regulation (EU) 2016/679 on the protection of personal data (GDPR) and applicable legislation in the European Union and European Economic Area, vinyllaz.com (administered by HODIȘ IONEL LAVINIU – PFA) has the obligation to collect, store and process the personal data you provide us only for the purposes mentioned in this Privacy Policy, under conditions of security, confidentiality and respect for your rights. The website is administered by: HODIȘ IONEL LAVINIU – Sole Proprietor CIF: 44311254 Registration No. RC: F2021001086055 E-mail: info@vinyllaz.com Phone: +40 743 589 991 As data administrator and operator, we assume responsibility for managing your personal information in a transparent, secure and legal manner. This policy aims to clearly inform you about how we process your personal data when you use our online store, www.vinyllaz.com.
2. What data we collect
When you use our website or place an order, we may collect the following categories of personal data: • Identification data: first name, last name, e-mail, phone number; • Delivery and billing data: complete address; • Payment information: transmitted and processed securely through authorized platforms; • Order data: purchased products, order history; • Technical data: IP address, browser type, operating system, device type used (desktop, tablet, mobile phone) and other details regarding site access and usage.
3. Purpose of data processing
We use the personal data you provide to offer you the best and safest experience when ordering from our website. More specifically, we process your data for the following purposes: • Processing and delivering your orders in the best conditions; • Issuing invoices and complying with legal and tax obligations that fall upon us; • Communication related to orders, returns or other requests sent; • Sending special offers, promotions, news related to vinyllaz.com activity, as well as invitations to contests, promotional campaigns or other initiatives — only if you have clearly expressed your consent in this regard; • Administrative or non-commercial messages (for example, related to changes to the website, your account or our policies); • Analysis of how the site is used — from desktop, laptop, tablet or smartphone — to constantly improve functionality and browsing experience.
4. Duration of personal data retention
Your personal data is kept only as long as necessary to fulfill the purposes for which they were collected, while respecting applicable legal obligations. Thus: • Data related to your orders and transactions will be kept for the period required by tax and accounting legislation, which is generally 5 years; • Data collected for commercial communications, promotions, newsletters or other marketing activities will be kept only as long as you have given consent and have not withdrawn it; • Technical data collected automatically through the site (eg: IP address, device type) are kept in accordance with internal policies and data security and protection legislation, for a reasonable period that allows service improvement; • In case it is necessary to retain data for other legal purposes (eg: resolving disputes), they will be retained for the strictly necessary period. After the retention period expires or after consent is withdrawn (where applicable), your data will be permanently deleted or anonymized, under maximum security conditions, so that they can no longer be associated with you.
5. Place of processing and disclosure of personal data
Your personal data is processed and stored in Romania, in secure environments, ensuring that we respect all legal requirements regarding data protection. We may transmit your personal data to our partners or other third parties only to the extent necessary to fulfill the requested services or to comply with legal obligations. These may include: • Authorized payment processors, such as Stripe, which is the payment operator currently used on the www.vinyllaz.com website and which securely manages online transactions. We do not store and do not have access to your banking data; • Courier companies, for the delivery of ordered products; • Technical service providers, such as hosting platforms, maintenance and traffic analysis, that contribute to the operation and optimization of the website; • Contractual partners, only to the extent necessary for order processing and ensuring the necessary support; • Competent public authorities, when the law requires us to provide certain information (eg: for investigations or tax reports). In all these cases, we ensure that these third parties respect strict confidentiality requirements and use your data exclusively for the purposes provided in this policy. We do not sell, rent or disclose your personal data to other entities for marketing purposes, without your express consent.
6. Your rights regarding data protection
In accordance with applicable legislation on the protection of personal data (Regulation (EU) 2016/679 - GDPR), you have the following rights over your data: • The right of access to personal data we hold about you; • The right to rectification of incorrect or incomplete data; • The right to erasure of data under certain conditions ("the right to be forgotten"); • The right to restriction of data processing in certain situations; • The right to object to the processing of personal data; • The right to data portability, that is, to receive your data in a structured, widely used format; • The right to withdraw consent at any time, without affecting the legality of previous processing; • The right to file a complaint with the National Authority for the Supervision of Personal Data Processing (ANSPDCP), if you believe that data processing does not comply with the law. To exercise these rights or for any questions related to your personal data, you can contact us at any time at the email address: info@vinyllaz.com. We undertake to respond to your requests within the legal deadline provided.
7. Security of personal data
We are committed to protecting your personal data through adequate technical and organizational measures, designed to prevent unauthorized access, loss, disclosure or destruction thereof. Access to data is allowed only to authorized personnel or partners who need this information to provide you with the requested services or products. All these entities are contractually obligated to respect confidentiality and protect data in accordance with applicable legislation. We also use technical solutions such as communication encryption (SSL), traffic monitoring and periodic infrastructure updates, to ensure adequate protection of data stored and transmitted through www.vinyllaz.com.
8. Comments and user-generated content
By "user" in this section we mean any person who accesses or interacts with the site, regardless of whether they have an account or not. Posting comments is optional and is not a condition for using the services or placing an order. Comments are allowed only if they respect our usage rules and best practices. When a user leaves a comment, we collect the information provided in the comment form, the IP address and the user agent (browser used), to prevent spam and abusive activities. For displaying the profile photo associated with the comment, an anonymized hash of the email address may be transmitted to the Gravatar service, in accordance with their privacy policy: https://automattic.com/privacy/. After comment approval, the profile photo will be visible to the public along with the comment. If you upload images to the site, we recommend removing embedded location data (EXIF GPS), as this information may be accessed by other users. The site administrator, who also has the capacity of personal data operator, moderates comments to prevent offensive, illegal or inappropriate content and reserves the right to delete comments that violate the rules. Site registration Users have the possibility to create an account on the vinyllaz.com website to facilitate the ordering process and to benefit from certain additional functionalities. For account creation, users provide personal data such as name, email address and other necessary information. This data is managed in accordance with the provisions of this Privacy Policy. All registered users can access, edit or delete personal information from their profile, except for the username, which cannot be modified. Site administrators can access and manage this information to ensure the correct functioning of services. Users are responsible for keeping authentication data confidential and to immediately inform the site administrator in case of suspicions of unauthorized access. Duration of storage of comments and profile data Comments and their metadata are kept indefinitely to allow recognition and automatic approval of future comments, thus avoiding placing them in the moderation queue. Personal data provided during site registration is kept for the duration of account activity and in accordance with applicable legal requirements. User rights over data Users can request at any time an exported file with the personal data we hold about them, including data provided through comments or profile. They can also request the deletion of personal data, except for those we are required to keep for administrative, legal or security purposes. Comment verification User comments may be subject to verification through automated spam detection services to ensure the security and quality of content published on the site.
9. Cookies
Information about cookies and how they are used on the www.vinyllaz.com website is available in the Cookie Policy. We encourage you to consult this document for details and to manage your cookie preferences.
10. Changes to the Privacy Policy
The site administrator, as personal data operator, reserves the right to update or modify this Privacy Policy at any time or whenever necessary, to reflect legislative, regulatory or internal practice changes. Any changes will be published on the www.vinyllaz.com website, and the update date will be revised accordingly. We encourage you to check this page periodically to stay up to date with any changes. Continued use of the site after publishing changes constitutes acceptance thereof.
11. Contact and support
For any questions, clarifications or requests related to the processing of your personal data, our privacy policy or the exercise of your rights, please contact us through: • E-mail: info@vinyllaz.com • Phone: +40 743 589 991 We undertake to respond to all requests within a reasonable period and in accordance with applicable legal requirements.