Privacy Policy
Introduction
MARIA FOODNOVA HOLDING S.R.L. (hereinafter referred to as “we”, “the company”, or “the data controller”), the owner of the website www.blacksealamb.com, aligns with the Regulation (EU) 2016/679 – the General Data Protection Regulation (GDPR) and places utmost importance and interest in protecting the privacy and private nature of the information entrusted to us through the use of this site.
One of the fundamental principles of this Regulation is transparency, and through this General Privacy Policy, we wish to inform you about how we collect, use, and protect your personal data.
We reserve the right to update, revise, and periodically modify this General Privacy Policy.
Should there be any changes, we will display the updated and revised version on our website.
Terms of the Regulation:
Data Controller – the entity – in this case – the operator or any other legal entity, public authority, agency, or non-governmental organization, which processes or establishes the purposes and means of processing personal data;
Personal data – means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, particularly by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person;
Data Subject – any natural person whose personal data can be or are processed by the controller;
Purpose of the General Privacy Policy:
When the data subject enters into any kind of relationship with us, they entrust us with their information.
The purpose of this General Privacy Policy is to explain to the data subjects what data we process, why we process it, and how we use it further – in our capacity as a data controller. We take privacy seriously and never transfer or sell personal data of any kind of our customers, lists, or email addresses. Fully aware that personal information belongs to each individual, we do our utmost to store it securely and process it with care. We do not provide information to third parties without first informing the data subjects, except in cases where, according to the law, it is forbidden to notify the data subject. This information is important. We hope it is read carefully.
This General Privacy Policy does not cover applications and websites of third parties that people may access by clicking on links on our website. This is beyond our control. We thus encourage the review of the Privacy Policy on any site and/or application before providing any personal data.
This General Privacy Policy also covers the recruitment and selection process for candidates for the positions offered.
MARIA FOODNOVA HOLDING S.R.L. informs applicants about the personal data that will be collected, the purpose of its collection, and how it will be used, in close connection with the existence of a specific Privacy Policy for recruitment.
According to legislation, the natural person beneficiary of our services or the person in any kind of relationship with us is a “data subject”, i.e., an identified or identifiable natural person.
To be completely transparent about data processing and to allow the data subject to easily exercise their rights at any time, we have implemented measures to facilitate communication between us, the data controller, and the data subject.
If you have not yet reached the age of 16, you will need the consent of your parents or guardian before providing any personal information for the purpose of registration or other online activities. If you are unsure about the information you see on this site, ask your parents or guardian for help.
Any processing of personal data of minors will only be carried out in accordance with the law.
Commitment of MARIA FOODNOVA HOLDING S.R.L.:
Protecting the personal information of the data subjects is very important to us.
Therefore, we have committed to respecting the new Regulation (EU) 2016/679, applicable national legislation in the field, as well as the following principles:
Legality, fairness, and transparency:
We process personal data legally and correctly. We are always transparent about the information we use, and the data subject is appropriately informed.
Control belongs to the data subject
Within the limits of the law, we offer the possibility to review, modify, delete the personal data shared with us, and to exercise the other rights.
Data integrity and purpose limitation:
We use the data only for the purposes described at the time of collection or for purposes compatible with those initial ones. In all cases, our purposes are compatible with the legislation. We take reasonable measures to ensure that personal data are accurate, complete, and up-to-date.
Security:
We have implemented reasonable security and encryption measures to protect the information as best as possible. However, it should be noted that no website, no application, and no internet connection is completely secure.
About MARIA FOODNOVA HOLDING S.R.L.
MARIA FOODNOVA HOLDING S.R.L., a Romanian legal entity with its registered office in Sat Chirnogi, Comuna Chirnogi, Strada Principală, Nr. 19L, Camera 3, Județ CĂLĂRAȘI, registered at the Trade Register under number J51/618/06.08.2021, having the unique registration code 44704407.
In terms of data protection legislation, we are considered a DATA CONTROLLER when processing your personal data. To ensure the secure processing of the personal data of the data subjects, we have made every effort to implement reasonable measures to protect their personal information.
Because we are always interested in hearing your opinions, as well as providing any additional information you may need regarding the processing of your data, we inform you that you can contact us at the email address: [email protected], or directly through a request registered at our registry or sent by mail or courier to our address below.
Rights of the data subject under the new Regulation
- The right to withdraw consent where processing is based on consent;
- The right to be informed about data processing;
- The right of access to data;
- The right to rectify inaccurate or incomplete data;
- The right to erasure (“the right to be forgotten”);
- The right to restrict processing;
- The right to have the data we hold about the data subject transferred to another controller;
- The right to object to data processing;
- The right not to be subject to a decision based solely on automated processing, including profiling;
- The right to seek legal redress;
- The right to lodge a complaint with the Supervisory Authority.
- The right to information:
This allows data subjects to know, right from the moment of data collection (or within a maximum of one month from the acquisition of the data, in the case of data collected indirectly from the data subject) how those data will be used, to whom they will be disclosed or transferred, what rights the individuals have concerning the processed data, etc.
- The right of access to data:
Article 15 GDPR allows data subjects to obtain from the controller confirmation as to whether or not personal data concerning them are being processed and, if so, access to the data and other useful information (art. 15 of GDPR contains a list of this useful information, including the purposes of processing, the categories of processed data, recipients, etc.).
As a result of the right of access, the data subject will receive personalized information (see the content of the information as presented in a later chapter), which will explain what data is processed, for what purpose, on what basis, the retention period of that data, to whom they can be transferred and for what purpose, mentioning the rights that the data subject has concerning those rights, including the right to lodge a complaint with the Supervisory Authority if the person is not satisfied with how this response is drafted, etc.
In addition to this information regarding processed data, the data subject has the right to obtain a copy of the data in question. If the above information talks about categories of data (e.g., Email address, name, etc.), in the case of the data copy, the data itself will be provided.
- The right to erasure of data
Article 17 GDPR allows data subjects to obtain from the controller the erasure of personal data concerning them without undue delay.
The first thing a controller should do when receiving such a request for access would be to check whether it falls under one of the exceptions provided by Art. 17(3) of GDPR, which allows or obliges him to retain the data, even in the case of a request for erasure, namely:
- The right to erasure does not apply if processing is necessary:
(a) for exercising the right to freedom of expression and information;
(b) for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(c) for reasons of public interest in the area of public health in accordance with Article 9(2)(h) and (i) – occupational medicine, public health, and Article 9(3) – processed under the obligation of professional secrecy;
(d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), to the extent that the right referred to in paragraph (1) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
(e) for the establishment, exercise, or defense of legal claims.
The right to rectification of data
According to Art. 16 GDPR: the data subject has the right to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
- The right to restrict data
Article 18 GDPR: the right to restrict data is a temporary right. In some situations, between the time, for example, the controller decides to erase certain data (no longer needs the personal data for the purposes of processing) and the actual erasure of the data, the data subject makes a request opposing the deletion, arguing that he or she requests them for the establishment, exercise, or defense of legal claims. As a result of such a request, the controller stops processing the data for a certain period.
At the time of lifting the processing restriction, the Controller must inform the data subject that the restriction has been lifted.
- The right to data portability
Article 20 GDPR. The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used, and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided. In other words, personal data must be provided to the data subject in a structured format, so that he or she can decide to download them or, conversely, can send them to another controller.
This right applies only to the extent that the data are processed based on a contract or the consent of the data subject, as well as (cumulatively) when processing is carried out by automated means.
The right to data portability applies to data provided directly by the data subject. Excluded from portability are derived or inferred data, as they are usually called, i.e., the conclusions that operators draw (based on profiling operations, usually) about data subjects.
- The right to object:
Article 21 GDPR. The data subject has the right to object, for example, to the processing of his or her personal data when they are processed for direct marketing purposes. It is very important that, when there are processing operations that could give rise to this right for the data subject, the information mentions the existence of this right.
- The right not to be subject to a decision based solely on automated processing:
Profiling occurs when evaluating certain personal aspects to make predictions about you, even if no decision is made.
The exclusively automated decision-making process occurs when decisions are made about you using technological means and without any human involvement: these decisions can be made even without profiling.
Data protection law establishes that you have the right not to be subject to a decision based solely on automated means if the decision produces legal effects concerning you or similarly significantly affects you in a significant measure. A decision produces legal effects when it has an impact on your legal rights (such as the right to vote). In addition, processing can significantly affect you if it influences your circumstances, behavior, or choices.
Decisions based on algorithms cannot use special categories of data unless you have given your consent or if processing is permitted by EU law or national law.
The right of access means that you have the right to obtain confirmation from us whether we process your data or not, and if so, to provide you access to these data as well as information about how they are processed;
- The right to portability refers to the fact that you can receive personal data in a structured format, which can be read automatically and that these can be transmitted directly to another operator;
- The right to object concerns the right to oppose the processing of personal data when it serves a public interest or our legitimate interest;
- The right to rectification refers to correcting without undue delay, inaccurate personal data;
- The right to erasure/right to be forgotten means that you have the right to have your collected data erased without undue delay, in any of the following situations: they are no longer necessary for the purposes for which they were collected, you have withdrawn your consent and there is no other legal ground for processing, you object to processing, the data were unlawfully collected, the data must be erased for compliance with a legal obligation, the collection was in connection with the offer of information society services;
- The right to restrict processing can be exercised if the accuracy of the data is contested for a period enabling the verification of the data, if processing is unlawful and you do not want the data erased but only their use restricted, in case the controller no longer needs the personal data for the purposes of processing but you request them for the establishment, exercise, or defense of legal claims, if you have objected to processing pending the verification whether the legitimate grounds of the controller override your rights.
Contact information:
[email protected]
telephone blacksealamb
Categories of personal data. Purposes and grounds for processing:
MARIA FOODNOVA HOLDING S.R.L. will process your personal data, depending on the context of your interactions and relationships with us by phone or with the website blacksealamb.com.
Special categories of personal data are those revealing (according to Art. 9 GDPR):
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade union membership;
- genetic data;
- biometric data for the purpose of uniquely identifying a natural person;
- data concerning health;
- data concerning a natural person’s sex life or sexual orientation.
These special categories are excluded from processing. ROMANIAN PERSONAL DEVELOPMENT & AWARENESS STUDIES CENTER DOES NOT PROCESS SUCH DATA.
According to GDPR (Art. 6(1)), processing is lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is subject;
(d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, which require protection of personal data, especially when the data subject is a child.
A controller must have one of the above points as the basis of its processing activity.
For most controllers (excluding public entities and other very specific types of entities), the four conditions to remember (also called processing grounds) are:
The consent of the data subject
Execution of a contract / steps prior to entering into a contract
The existence of a legal obligation for the controller;
The existence of a legitimate interest of the controller or of a third party;
We process your name, surname, date of birth, billing details, email address, address, and telephone number, included in the contract concluded with us, for:
- executing the training contract concluded with you, including carrying out activities performed by us in your interest under the contract between us;
- drafting documents in your name or on your behalf, according to the mandate entrusted;
- fulfilling the legal obligations imposed on adult training service providers;
Unless otherwise stipulated, data are stored for up to 10 years, except in the case of adult training service provider registers, which may be kept for longer, according to the law. These data are processed because the data subject (you) has given consent to the processing of his or her personal data for one or more specific purposes; processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; processing is necessary for compliance with a legal obligation to which the controller is subject;
We process your telephone number and your email address and Facebook account as well as the other data provided in point 2 (exceptionally and if you have provided them), for:
-Improving our services or to communicate new offers or information about us, our website, our policies, our data, or our decisions.
-Unless otherwise stipulated, data are stored for up to 10 years, except in the case of adult training service provider registers, which may be kept for longer, according to the law. These data are processed because the data subject (you) has given consent to the processing of his or her personal data for one or more specific purposes; processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; processing is necessary for compliance with a legal obligation to which the controller is subject;
Unless otherwise stipulated, data are stored for up to 10 years, except in the case of adult training service provider registers, which may be kept for longer, according to the law.
We do not use personal data for automated processing or for profiling. We never make automated decisions about you. We use technical means for storing data securely. We do not process data for secondary purposes incompatible with the purposes for which we collected them.
This General Privacy Policy refers to the personal data of customers, suppliers, other people who contact us and visit us and their representatives, potential collaborators, and applies to data collected through our website blacksealamb.com, as well as all other personal data we collect through email and contact forms.
Thus, visitors and users of the site may have the following categories of data processed:
-In the case of requesting additional information, contact and/or complaints: name, surname, email address, telephone number;
-In the case of placing an order: name, surname, date of birth, billing address, address, email, Facebook account, email address, telephone number.
Note that any sensitive and/or demographic information you voluntarily communicate to us during the booking process (gender, nationality, citizenship information, patient medical or health information – conditions, previous treatments) and/or data on racial, ethnic, or religious origin are considered sensitive personal data and will not be processed, but if found in the documents communicated or in emails from you, they cannot be deleted except by deleting the email, which is impossible, being preserved to prove the existence of communication.
For the purpose of providing services, delivering goods, and making payments under relevant contracts, we may process your personal data, such as identification data, contact data, business contact data, banking data, and tax identification number, for VAT-registered individuals.
Also, visiting the website blacksealamb.com involves the automatic collection of the following data:
- technical data, for example, this may include the Internet Protocol (IP) address used to connect your computer to the internet, login information, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, device type, and mobile device brand; these data are collected and processed on our behalf, through third-party cookies, and you can find more information about this at the Cookie Policy address
- data about your visit, for example, this may include data about the URL, clickstream to, through, and from the website www.blacksealamb.com (including date and time), the information or products you viewed or searched for on the site.
We process your personal data for various technical, administrative, and operational reasons, such as: - to ensure that content is presented in the most effective manner for you;
- to improve the website blacksealamb.com, including its functionality;
- for the administration of the website blacksealamb.com;
- for internal operations, including troubleshooting, data
- analysis, testing, research, statistics, and survey;
- to keep the website blacksealamb.com safe;
- for advertising and marketing, including for specific marketing purposes, so that we can offer content, including personalized content, that might be of greater interest to you.
Data storage of personal data
Unless otherwise stipulated, data are stored for up to 10 years, except in the case of adult training service provider registers, which may be kept for longer, according to the law. These data are processed because the data subject (you) has given consent to the processing of his or her personal data for one or more specific purposes; processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; processing is necessary for compliance with a legal obligation to which the controller is subject;
Also, in the event that data are not collected in the context of an agreement, such data will be kept as long as necessary to achieve the anticipated data collection purpose or any other longer period imposed by law, a record retention regulation.
Immediately after the applicable retention period ends, the data must be:
Deleted or securely destroyed
or
Transferred to an archive (unless this is prohibited by law or by the record retention regulation).
After the period ends, the personal data of the data subjects will be destroyed or deleted from the information systems or transformed into anonymous data to be used for scientific, historical, or statistical research purposes.
Under the law, these may also be disclosed to Romanian authorities, in criminal cases.
MARIA FOODNOVA HOLDING S.R.L. confirms that the personal data obtained are stored securely or are destroyed, in which sense we inform the data subjects that there are data processing agreements with the software provider/providers through which they have ensured, in turn, the company, that they are compliant with GDPR.
MARIA FOODNOVA HOLDING S.R.L. may disclose data of data subjects, in compliance with applicable law, to business partners or other third parties, such as its own processors. In these situations, we will previously request the commitment of these individuals to comply with this policy.
We make continuous reasonable efforts to ensure that these third parties have implemented adequate protection and security measures. With these third parties, we have contractual clauses so that your data are protected. We will inform data subjects each time about the identity of these companies before transmission or within a reasonable term, and we will ensure that any transfer is legitimate based on their consent or another legal basis.
Also, the company could share the data of data subjects to business partners as a result of a joint effort to offer a product or service.
Data could also be transmitted to other parties with the consent or according to the instructions of the data subject.
Personal information may also be provided to the prosecutor’s office, police, courts, and other competent state bodies, on the basis and within the limits of the legal provisions and as a result of expressly formulated requests.
Within reasonable limits, MARIA FOODNOVA HOLDING S.R.L. will ensure that the data of the data subjects do not leave the European Economic Area however, to the extent that it will transfer to countries outside the EEA, it will always seek in all cases that the transfers are legitimate, based on the explicit consent of the data subject or another legal basis.
Requests and exercising rights
MARIA FOODNOVA HOLDING S.R.L. informs any data subject that:
If he or she wishes to exercise their rights, they can do so by registering a written request, which is submitted at the address indicated above or through a written request sent to the email address [email protected].
The rights listed above are not absolute. There are exceptions, therefore each request received will be examined so that it can be decided if it is founded or not. To the extent that the request is founded, the company will facilitate the exercise of the rights. If the request is unfounded, it will be rejected, however, data subjects will be informed of the reasons for the refusal and of their rights to lodge a complaint with the Supervisory Authority and to seek judicial redress.
The company will try to respond to this request within 30 days. However, the term may be extended depending on various aspects, such as the complexity of the request, the number of requests received, or the inability to identify you in a timely manner.
If, despite all efforts, the company fails to identify the data subject, and he or she does not provide additional information to manage to identify him or her, the company will not be obliged to comply with the request.
In the event that you wish to exercise any of the rights listed above in this General Privacy Policy, to make observations or to obtain information or additional clarifications regarding the processing of your personal data, if you have questions or concerns regarding the processing of your information or wish to exercise your legal rights or have any other concern regarding data privacy, please contact MARIA FOODNOVA HOLDING S.R.L. through the email address [email protected].
The response to all requests will be sent in the shortest possible time, which will not exceed one month from the receipt of the request, with the possibility of extending the duration by a maximum of two months if we are talking about complex processing or a large volume of such requests.
All requests will be submitted personally or sent by mail/courier to our Bucharest office, or by electronic mail to the email address: [email protected]. The resolution term of the request is 30 days.
Also, it is good to know that in Romania operates the National Supervisory Authority for Personal Data Processing (“A.N.S.P.D.C.P.”) and that you have the right to lodge a complaint when you consider that your rights have been violated, by accessing the website www.dataprotection.ro.