Privacy Policy

Respecting the right to personal data protection, as well as the right to privacy, is one of the fundamental missions of our company. SC Razadi SRL.

SC Razadi SRL, as the author, owner, administrator of www.cupiocosmetics.com, respects the privacy and security of personal data processing of each person who visits this site for making online purchases, being registered under No. 26337 at the National Authority for the Supervision of Personal Data Processing.

SC Razadi S.R.L. commits not to transmit any personal data of the site's users to third-parties, except for direct collaborators, where access to certain data is necessary to provide services (email marketing/newsletter services, payment processors, courier companies, etc.).

Accessing/visiting this website by you is subject to theTerms and Conditions of use, implies your explicit acceptance regarding these and represents the entire agreement (contract) between parties.

SC Razadi SRL reserves the right to change and update the content of the www.cupiocosmetics.com website at any time, as well as the Terms and Conditions of use, without any prior notification. Therefore, please visit this section periodically to check the terms and conditions you have agreed to respect.

We undertake all necessary steps to process your personal data in accordance with the principles established by the data protection legislation applicable in Romania, including Regulation (EU) 2016/679 of the European Parliament and of the European Council of 27 April 2016 on the protection of individuals with regard to personal data processing and on the free movement of such data, nullifying Directive 95/46/EC ("GDPR").

Definitions

personal data - any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or one or more specific factors of his/her physical, physiological, psychological, economic, cultural or social identity;

processing of personal data - any operation or set of operations performed on personal data, by automatic or non-automatic means, such as collection, recording, organisation, storage, adaptation or alteration, extraction, consultation, use, disclosure to third parties by transmission, dissemination or in any other way, joining or combining, blocking, deletion or destruction;

storage - keeping on any type of support of the collected personal data;

personal data filing system - any organised structure of personal data, accessible according to certain criteria, regardless of whether this structure is organised centrally or decentralised or is distributed according to functional or geographical criteria;

data operator - any natural person or company, private or public, including public authorities, institutions and their territorial structures, who establishes the purpose and means of processing personal data;

third-party - any natural person or company, private or public, including public authorities, institutions and their territorial structures, other than the data subject, the data operator or the person empowered or the persons who, under the direct authority of the data operator or the person empowered, are authorised to process data;

recipient - any natural person or company, private or public, including public authorities, institutions and their territorial structures, to whom data are disclosed, whether or not it is a third party; public authorities to which data are communicated under a special investigation competence will not be considered recipients;

anonymous data - data that, due to their origin or specific processing mode, cannot be associated with an identifiable person;

"business contact" type data - data that includes the name, function, business address, telephone number or e-mail address of an employee of an organisation, in this capacity. "Business contact" type data do not fall into the category of personal data;

statistical data - data that have been obtained as a result of processing by the data operator of personal data but cannot be used to identify a person and are used exclusively for statistical purposes and/or information, promotion, etc.

Collecting Information

Data collection by www.cupiocosmetics.com is done in three ways:

  • directly from the user:when subscribing to the services offered by SC Razadi SRL. To keep track of the site usage you may be required to provide personal information (email address, name, surname, address, etc.)
  • from the server traffic report: when visiting www.cupiocosmetics.com, you provide certain information about yourself, such as the IP address, visit time, location from where you visited, duration of the visit
  • through cookies: when you visit www.cupiocosmetics.com you may be sent a cookie to facilitate the storage and tracking of your preferences.

No bank card or account data are collected.

The data collected are IP addresses and cookies.

Cookies

The cookie is a ".txt" type file, offered to your browser by a web server, which can be placed on your hard disk. Most browsers are set to accept these cookies. If you don't want this, you can reset your browser to notify you each time you receive a cookie or to refuse to accept these cookies. It is important to know that if you have set your browser to refuse cookies, you may not be able to view some sections of the site normally. If you don't want information collected through the use of Cookies, there is a simple procedure in many browsers that allows you to reject or accept Cookie features/functions. However, please note that Cookies might be necessary to provide you with some of our online services.

www.cupiocosmetics.com cannot control and does not have access to the cookies on your computer, installed by a third party. These cookies cannot be used to identify you.

SC Razadi SRL may collect personal data from you, but only with your consent and if you voluntarily provide us with it. The registration form presented on the www.cupiocosmetics.com website asks for information by which you can be identified, or by which we can contact you, this being from the category of "business contact" type data.

The cookies we use belong to the following companies: Remarketing.biz, Doubleclick, Facebook, Google, Zoopim.

We use the personal data collected for the following purposes:

  • To ensure that the web pages are relevant to your needs
  • To deliver services such as newsletters, events or products you have requested or purchased;
  • For sending offers, advertising and marketing messages;
  • To ensure access to sections with limited access to the website;
  • To provide the delivery services that you purchased;
  • To be able to bill for the services ordered by you;
  • To make online payments;
  • To ensure the security of the transaction/online payment/credit card by applying anti-fraud filters;
  • To register you as a member in the www.cupiocosmetics.com loyalty program;

SC Razadi SRL collects information about what pages you access within the cupiocosmetics.com site, including the IP address from which the site is visited.

SC Razadi SRL may use cookies on the cupiocosmetics.com site, temporarily storing personal data for the following purposes:

  • To improve access security.
  • To improve usability and provide you with the best possible service.

In addition to personal information, our systems automatically collect a series of anonymous information that helps us better understand how the site is used and how we can improve our services. This data includes, but is not limited to, the IP address of the computer used to access the website, the operating system used, the navigation software used, and the time spent on the website.

When you visit the website, data about you may also be collected by third parties such as traffic counting systems and online advertising systems.

Protection of Confidential Information

The information collected from you is very important and therefore it is confidential. SC Razadi SRL uses security methods and technologies, along with policies applied to employees and work procedures, to protect the personal data collected in accordance with the applicable legal requirements. The server on which the cupiocosmetics.com site is hosted is protected, with limited physical and remote access, being placed in technically appropriate and secure premises. We make all reasonable, commercially justified efforts to protect your personal data collected, analyse new technologies in the field and, if and when necessary, apply them to upgrade our security systems.

No data regarding your bank card or account are collected.

Use of statistical data and anonymous data

SC Razadi SRL may use statistical data or anonymous data resulting from processing for the following purposes:

  • creating / analysing reports;
  • informations for our own purposes;
  • publishing and promoting the services offered by SC Razadi SRL

Legislation

The privacy policy is subject to Romanian and European legislation. In case of litigation, an amicable resolve will first be attempted, within 30 working days from the registration of the complaint at the headquarters of SC Razadi SRL. If an agreement cannot be reached within the aforementioned term, the court from the same administrative region as the headquarters of SC Razadi SRL will be considered competent.

External links

The www.cupiocosmetics.com online store contains links to other websites, beyond the control of SC Razadi SRL, websites that we believe you will find useful. If you access these links, you will access/visit websites that may have a different privacy policy than SC Razadi SRL. Before making your personal information known on any other websites, we advise you to go through the usage terms and conditions of those websites as well as their security specifications.

Contact - issues or questions

For any other questions related to our data security policy, or if you have problems or complaints, please send us an email at hello@cupiocosmetics.com.

By navigating and shopping in your beauty store, CUPIO, you have given us your trust, and we thank you for your visits. CUPIO assures you that it will process your data only in a necessary, limited, justified, and transparent manner, according to your will, in accordance with the stipulations and changes brought by the General Regulation (EU) on the protection of personal data of individuals No. 2016/679 ("GDPR").

This is the reason why we have decided to inform you through this guide on processing personal data about:

We will have the same approach every time you visit us or shop at CUPIO.

We reserve the right to adapt and modify this data processing guide in the interest of consumers whenever necessary, legally, justified, when legislative changes impose this step in the activities through which we process your data. We will post any such changes on our website, www.cupiocosmetics.com, and inform you accordingly.

Who are we?

CUPIO was founded in 2011 and is a Romanian privately-owned company. It started its activity at a time when the market for professional cosmetic products in Romania was poorly developed and dominated by foreign brands.

From the beginning, CUPIO sold professional cosmetic products, intended for both beauty salons and end consumers. Currently, we have over 8000 products in the portfolio and 9 own brands: CupioGels, Cupio To Go, Cupio One Step, Cupio Acryl DELUXE, CupioLash, Cupio Make-up Pro, Cupio ProDepil, Cupio in the City, Cupio Spa.

Thus, our Cupio stores feature essential professional products for any specialist in the fields of manicure, makeup, body care, and beauty.

You can contact us at any time at:

For enhanced personal data protection, CUPIO has chosen to appoint a data protection officer. For any questions or misunderstandings related to this Policy, how CUPIO processes your data, or your rights, you can contact us at the dedicated email address: date.personale@cupio.ro. We guarantee that any question will benefit from the personal data protection that we will collect as a result of your message.

What data do we process about you?

What is personal data?

Personal data means any data or information that helps us to identify you directly (for example your name, surname) or indirectly (based on the profile that we create to transmit personalised offers). Certain information is less obvious (such as your shopping preferences and habits, your computer's IP), but, associated with your person, they help us to identify you and thus fall within the concept of "personal data".

CUPIO's intention is to collect and process only the data that is necessary for your registration, creating, placing, and finalising your orders and delivering the goods to the person and address you will indicate. For this purpose only, our store needs the following types of personal data:

  • Name and surname
  • E-mail address
  • Phone number
  • Sex
  • Age
  • Date of birth
  • Information about purchased products and services
  • Degree of use and your activities on our online store
  • Interests and preferences for products on the website

More precisely, we have presented the personal data ("Data" sau "Personal Data") which we collect directly from you, which result from interacting with you, and which we or our partners track in order to provide the ordered products, or to provide you with various personalised offers when browsing/shopping on our web site or when using various devices (computer, tablet, or mobile phone).

Personal Data of Minors

In principle, CUPIO is addressed to consumers over 18 years old, but also to persons who the law recognizes as rightful to represent or act on behalf of a minor. Minors aged between 14 and 18 can create accounts on the CUPIO website only with the legal approval of parents/guardians/other legal representatives, approval transmitted in writing by parents/guardians/other legal representatives. Minors under 14 cannot create accounts on the CUPIO website.

The products sold on the CUPIO website are not intended for minors under 14 years of age. Our company does not process personal data of minors, regardless of age, for creating customer profiles, in order to transmit personalised offers by text message, email, or other communication channels. Our company will not conduct marketing activities, raffles, or contests, nor will use tracking techniques or cookies to determine minors to consent and/or register or transmit their personal data on the CUPIO website.

Our purpose is to limit the possibility of minors to conclude illegal purchases or purchase operations unauthorised by parents/the parent exercising parental authority or the person in whose care the minor was entrusted (guardian/legal representative). Any purchase operations carried out by minors must meet legal requirements, be authorised by parents/the parent exercising parental authority, or the person in whose care the minor has been entrusted (guardian/legal representative). We therefore guarantee the collection, processing, and retention of personal data only for the declared purpose, for a limited term, with the consent of the minor, the parent and/or its representative, in order to respect their absolute right to protection.

How do we collect and process your data?

CUPIO collects and processes your data for fulfilling the orders you make and delivering the products you want, improving your experiences on the CUPIO website, providing assistance and support when you use the CUPIO website/client account, or to create a customer profile for sending personalised offers (direct marketing).

In the table below we detailed how we process your data, the purposes, and the legal basis of the activities through which we process your data.

The purpose of collecting and storing your personal data What data do we collect and how do we process it? What is the legal basis for processing the data?

Data provided directly to us

Creating your client account

We can only create a user account on the CUPIO website if you provide us with the following personal data:

  • first name, last name;
  • e-mail;
  • phone number;
  • date of birth.

Alternatively, you can create a customer account by logging in to your Facebook or Google account, using the email or phone number and password from that social network.

Art. 6, para. 1, letter b) of Regulation 679/2016 with relation to concluding a contract.

Logging into your client account

You have the option to log into your customer account by connecting to your existing Facebook or Google account (connection through social networks). For connection, you are redirected to the page of your social network (Facebook or Google), where you can log in with your user data. Thus, your Facebook or Google profile is linked to the customer account. Following the connection, Facebook Inc. or Google Inc., may automatically send us certain information such as:

  • Social network numeric ID;
  • E-mail;
  • First and last name;
  • Gender;
  • Your Facebook or Google username;
  • If your user account has been verified (e.g., "confirmed");

By associating an account managed by a social networking website with your account and authorising us to access this information, you agree that we may collect, use, and store the information provided in accordance with this privacy agreement.

In addition, the social network service operator receives information about the connection of the respective account to our page. We store and use certain public data transmitted by Facebook or Google to be able to identify you as an authorised customer and to provide our services to you.

Art. 6, para. 1, letter b) Regulation 679/2016 for the execution of a contract, respectively for the ability to use the website for placing orders.

Making online purchases on our website

You can make online purchases on our website both when you have created a customer account, and when, although you do not have a customer account, you place some products in the shopping cart, and then place an order.

Each time you place an order, we will collect and process the following data:

  • name and surname;
  • delivery address;
  • phone number.

When we confirm your order, or notify you that the products have arrived at the pickup points, we will process:

  • your phone number and your email address to inform you about the status of your order/delivery.

Contract Execution

In order to be able to fulfil your orders, deliver products to the indicated address / hand over the products at the pickup points, fulfil our warranty obligations associated with the products, or, where appropriate, return a product.

Payment for purchases / refund in case of product return / order cancellation

The details of the card used for the 3D Secure payment of your purchases will not be accessible or stored by CUPIO, but only by the entity authorising the transaction or another entity authorised to provide card identification data storage services, whose identity you will be informed of before effectively introducing the details of the card used for online payment.

[3D Secure represents a security measure that involves redirecting the customer at the time of payment to a secure page (romania.payu.com/en/), where each cardholder's registration is made by assigning an authorization code for each online transaction. The cards accepted for payment are those issued under the VISA (Classic and Electron) and MASTERCARD (including Maestro, if they have a CVV/CV2 code) logos.]

CUPIO only processes the following data that it sends to the partner for authorising payments / online transactions:

  • first and last name;
  • order ID;
  • date of initiation of the transaction, date of completion;
  • transaction ID;
  • payment status (payment made / not made);
  • transaction amount (as applicable).

In case of returns / order cancellations we collect and process:

  • Your bank account IBAN and the bank where you opened your account, to refund the money paid for the returned products / cancelled orders

Contract Execution

To provide the necessary support for processing the payment of products ordered by you, by our authorised partners.

Product delivery to you

We deliver the products to the indicated address, through our couriers, with whom we strictly share the data necessary for product delivery:

  • first and last name;
  • delivery address;
  • phone;
  • the value of the amount payable on delivery (as applicable).

If you pick up the product from our collection points, to identify you we will compare the data from your ID with the ones from the order (without keeping a copy of the ID), respectively:

  • first and last name;
  • date of birth.

Contract Execution

Fulfilling our obligations related to handling and delivering products to the customer under the agreed conditions and times.

Customer Assistance and Support

In order to provide you with support related to your customer account / orders that you place on the website, we will identify you by confirming:

  • your first and last name;
  • your e-mail address;
  • your phone number;

With your prior agreement, we can process your voice from the recordings of phone calls with you to respond to your requests for assistance.

We will process the same personal data in order to resolve your complaints.

Contract Execution

Fulfilment of our responsibilities / activities during the contract execution period.

Actions for Increasing Loyalty / Awarding Benefits

CUPIO offers various discounts and benefits related to our loyalty actions (in the form of vouchers, discounts, etc.). In your customer account, you can view all the vouchers you have benefited from at a certain point.

Contract Execution / Legitimate Interest

For the purpose of carrying out actions to increase loyalty, in our relationship with you.

Promotional Campaigns, Contests, Promotions or Raffles

We collect email addresses for online contests carried out on the CUPIOCOSMETICS.COM website. We also organise contests on the official Facebook page, where we collect, depending on the campaign, the following data necessary for your participation in the contest, respectively, for validating the winners through random.org:

  • name and surname;
  • e-mail address, or
  • phone number.

The above data is collected only if you give us your consent that you want to participate in these campaigns. You can withdraw your consent at any time through a message sent to the email address: date.personale@cupio.ro.

If you are a winner, we will mention your name and surname on the official Facebook page of CUPIOCOSMETICS.COM or on our website..

Consent

For the purpose of your participation in the contests organised by CUPIO and being awarded the respective prizes, if won.

Personal data that we collect automatically

Creating customer profiles for direct marketing purposes

Based on your interactions and behaviour on our website, we collect and process your data through our partners only for the purpose of creating your customer profile, in order to subsequently transmit personalised offers through the communication channels chosen by you.

For profiling, we process the following data:

  • your name, surname, email address and/or correspondence address and mobile phone number;
  • the history of your interactions with us, respectively:
    • what products you viewed, searched for, or ordered;
    • what products you added to your shopping cart and later removed, ordered/bought;
    • what orders you started and then completed or cancelled;
    • what products were delivered to you, what products were paid for;
  • your preferences when shopping from the Online Store (what products you bought, at what date/time, how you made the payment);
  • online identifiers obtained from the device you used when browsing the Online Store's website or mobile application.

Consent

For the creation of profiles and the transmission of personalised offers through the communication channels to which you consent (text message, e-mail, push-up notifications). You can withdraw your consent at any time by sending an email to the address date.personale@cupio.ro

More details about how we do profiling for direct marketing actions can be found below in the "Profile Creation" section. You have the right at any time to object to profile creation by sending us an email to the address date.personale@cupio.ro

Online browsing

When you visit our Online Store, log into your customer account, or use our mobile app, we also collect information with the help of cookies and data obtained from your computer, phone, tablet, or other device you use ("device"). These are online identifiers that we can use to identify you ("online identifiers"), and we use them for profiling for direct marketing purposes:

  • IP Address;
  • The internet browser you are using and the version of the device's operating system;
  • HTTP/HTTPS protocol data.
 
Advertising Based on your Online Behaviour

PBased on your navigation and behaviour on the CUPIO website, through Google Analytics, monitored via cookies, we will provide you with online advertisements for some of our products that may interest you. Based on the information about your navigation on the CUPIO website or from our mobile application, we will classify you in a group of interest with other similar customers, in terms of browsing behavior, and thus we will deliver advertisements (banners) based on those interests.

For example, a "manicure" interest profile can be assumed from your data by evaluating the products you visited on the CUPIO website through Google Analytics and in this way a cookie is placed on your device to classify you as someone interested in the "manicure", category, and later you will receive some specially personalised advertising messages from the "manicure" category.

Cookie Consent

For cookies that monitor your behaviour on the CUPIO website.

If you do not want to participate in cookie tracking for the purpose of delivering online advertisements (banners) based on your interests, you can refuse to set a cookie module for this purpose by setting your browser to generally disable the automatic setting of cookie modules. You can also deactivate cookie modules for browser service providers' advertising services (e.g., Google) by setting your browser in such a way that cookie modules from the respective domain are blocked. You can do this very easily from the following page.

Opting out of online behavioural advertising will not stop the display of general advertisements that are not personalised based on your interests.

Offers Based on Custom Audiences (customer lists)

With your agreement, we will use your email address and mobile phone number to create encoded customer lists ("hash data"), and then we will use the encoded data from this list to correlate your data (and that of other customers in an interest group) with the data of people on Facebook, to send, through this channel, personalised offers to your Facebook account via targeted ads.

Facebook encodes the hash data, uploads it to the social platform, and thus creates an audience for us, using these hash data exclusively for correlation with the data from your Facebook account, without distributing this data to third parties (or other commercial advertising agencies) and will be automatically deleted by Facebook immediately after correlation.

In addition, on the CUPIO website, we also use Facebook's custom audience services created with the help of your pixel data and data from your mobile application. With this service offered by Facebook, we and Google can identify the fact that you clicked on our ads on Facebook and were redirected to the CUPIO website. The data collected with Facebook serve exclusively for compiling statistics on the success and use of our advertising campaigns on Facebook.

Consent

For transmitting personalised offers on Facebook (by using the custom audience service based on customer lists).

For more details regarding the purposes, the way of collecting and processing personal data by Facebook, and for privacy settings on Facebook, you can consult the Facebook Privacy Policy help centre for promoters.

You can always withdraw your consent by sending an email to the address date.personale@cupio.ro

Maintenance and Security of the CUPIO Website

We use the following online identifiers for the maintenance and security of the CUPIO website:

  • IP address;
  • The internet browser you use and the version of the operating system of the device you connect with;
  • HHTP/HTTPS protocol data;
  • Location of the device (if geo-location is activated) from which you connect to the CUPIO website.

More precisely, we process your data for:

Ensuring the proper functioning of the website, specifically:

  • Correct display of the CUPIO website content;
  • Retaining your login data (when you request it);
  • Improving the CUPIO website;
  • Setting up the device from which you connect/login to meet the requirements of the CUPIO website.

Ensuring the security of the website and ensuring that we protect you against fraud or any IT security breach concerning the CUPIO website.

Identifying and remedying faults that prevent the use of our website or your customer account.

Legitimate interest

Implementing, setting up, and maintaining the security measures of the CUPIO website.

Audit and reporting

We process your data for annual financial audits, as well as for submitting tax and accounting declarations to the fiscal authorities.

Requirements for Legal provisions

For compliance with legal obligations imposed by fiscal and accounting matters.

Defending our rights in court

When we defend our rights in court to recover owed amounts, or when we protect our interests against unjustified claims/complaints, we will process your necessary data for formulating responses, written conclusions, requests, and specific documents.

Legitimate interest

Exercising the right of defence before the courts, public authorities or control institutions.

Procedures and investigations by authorities and/or judicial bodies

In exceptional cases and according to the law, we will provide your data: name, address, email, phone, to competent authorities and institutions during formal procedures/investigations or any other actions imposed by law, according to the procedure provided by law.

Legal requirements

To comply with specific legal obligations imposed by applicable laws in relation to protection against fraud, money laundering, and terrorism.

Data which we collect from other sources

Browsing on social media platforms

If you like the CUPIO page on Facebook or if you log in to your customer account with your Facebook, e-mail and password, we will receive this data. We won't use it for anything other than communicating with you and, potentially, sending you some personalised offers through your Facebook account, based on custom audiences.

Consent

We use your consent to send you personalised offers on Facebook (by using the custom audience service based on customer lists).

You can withdraw your consent at any time by sending an email to date.personale@cupio.ro

Creating Profiles for Direct Marketing Purposes

When we send you personalised offers through direct marketing channels (sms, e-mail, push-up notifications), we may use certain "profiling techniques". This involves an automated processing of your data, particularly for analysing and interpreting your personal data. This is necessary to evaluate or predict aspects related to your shopping preferences and interests on the CUPIO website. CUPIO does not process sensitive data regarding sexual orientation, religious beliefs, or political affiliations for profiling.

Your shopping behaviour and personal preferences emerge from your browsing history and/or purchases on the CUPIO website, your use of the mobile application, your financial situation resulting from your purchases, and other personal interests that you have provided to us, interests that are common with other customers.

You can change your direct marketing preferences in your customer account on CUPIOCOSMETICS.COM at any time after registering as a CUPIO customer, directly in the customer account.

You can oppose the creation of profiles for direct marketing purposes on any of the communication channels that you have previously consented to, by refusing the setting of a cookie module, through the browser setting that generally deactivates the automatic setting of cookie modules. You can also deactivate cookie modules for the advertising services of a browser service provider (e.g., Google) by setting your browser in such a way that the cookie modules of the respective domain are blocked. You can do this very easily from the following page...

Opting out of online behavioural advertising will not stop the display of general ads. It will only mean that they will not be personalised based on your interests.

How Long Do We Keep Your Data?

CUPIO processes your data and keeps it for the period necessary to fulfil the purposes for which they were collected and in accordance with our personal data retention policies. In some cases, some legal provisions may require or allow us to keep data for a longer period.

We keep personal information as long as necessary to safely provide the Services you requested or for other purposes, such as to comply with legal obligations, to resolve disputes, and to enforce our policies.

After we no longer need to keep your personal information, we will arrange for safe deletion in accordance with our data retention and deletion policies. We will respect your legal right to request the deletion of personal information from our system.

Legal or contractual obligations require us to keep your data for a certain period (for example, the periods prescribed by law for defending our rights in court).

We will only keep your data as long as you have a customer account and/or continue to shop on the CUPIO website. If you deactivate your customer account from the Online Store, the data associated with your customer account will be deleted or anonymized so that you can no longer be identified in our data records systems, except when we are required to keep your data for a longer period, based on the law or our legitimate interest.

In this way, we will ensure your full control over your personal data. We will collect and process your data again if you provide it to us on the CUPIO website.

For the purposes for which you gave us your consent to process data, highlighted in the table above, we will process your data related to the respective purpose until you withdraw your consent, except when we are obliged to keep these data for a longer period according to the law, for reporting to public authorities, or for defending our rights in court.

We inform you that we rely on your consent when we process your data to send you:

  • personalised offers based on online behavioural advertising;
  • personalised offers based on profiling we do for direct marketing purposes, through text messages, email communication channels;
  • offers based on personalised audiences (on customer lists) on Facebook;

* Consent  – means your free, specific, and informed agreement by which you undoubtedly accept that your data is processed by us for the purpose for which you give your agreement. On the CUPIO website, you can express your consent by checking the relevant box associated with the purpose and means specified in this Information Note.

Who Do We Share Your Data With?

Your personal data can be transferred to and processed by our trusted partners to deliver your products.

To deliver the products ordered on the CUPIO website, we will share your data with our trusted partners. We carefully select the partners and suppliers who carry out operations to support our activities on our behalf. We share with them only the personal data necessary for the specific activities that we entrust to them.

When we outsource certain activities to our trusted partners, we make all reasonable efforts to verify beforehand whether they provide protection for your data through strict data security measures and we will sign data processing contracts with each of them.

Specifically, we transmit some data to third parties (our suppliers and partners) to perform functions and services necessary for the operation of the Online Store's activities, such as:

  • the server data storage service provider, located in Romania;
  • the Warehouse Management System application provider that ensures the management of operations in the warehouse and product collection points, or who helps us print and deliver your product invoices in localities throughout Romania;
  • the telephony services provider who helps us keep in touch with you, located in Romania;
  • third-party couriers authorised by us to deliver the products you purchased (DPD, GLS, Urgent Cargus, DPD);
  • payment processors who are authorised by us to mediate payments via the 3D Secure system (PayU).

We share your data with our partners and for marketing purposes

To offer you personalised products according to your interests and preferences, we share certain data with some partners who help us send you personalised offers, such as: (i) processing data through the Facebook platform to send you personalised offers through targeted ads using the function of custom audiences on customer lists, or (ii) processing data to send you personalised offers based on behavioural online advertising run with Google AdWords. The way Facebook or Google processes your data is presented in the above table in this Data Processing Policy.

Sharing data with authorities and public institutions or judicial bodies

We may share some of your personal data with competent authorities or public institutions when the law imposes it (e.g. fraud investigation; money laundering prevention; submission of statements, financial statements to tax authorities etc.), or we may send this data to the courts when we defend ourselves in court, or in front of other public authorities.

Access for auditors and consultants

If we decide in the future to sell the shares or the CUPIO business, we will provide access to data to potential auditors and consultants employed by the buyers for conducting the necessary audit for the acquisition of the shares/ business. For this purpose, we will ensure that any potential buyer will follow and implement the necessary security measures for the protection of your data, and the parties will sign in advance a data processing contract for the purpose of the transaction.

When do we transfer your data outside the European Union or EEA space?

As a rule, your data is not stored in a country located outside the European Union or the European Economic Area ("EEA").

However, some data may be transferred to our partners who help us operate the activities of the CUPIO website and are located outside the European Union. With each of these partners, we have made reasonable efforts to ensure that there are adequate data protection measures.

If we transfer your data to other CUPIO partners/suppliers located in countries that do not provide an adequate level of protection of the transmitted data, we commit to take all necessary measures to ensure that these partners/suppliers comply with the terms and conditions established in this Policy. These measures may additionally include the implementation of data protection standards (e.g. ISO 27001), standard contractual clauses adopted by the European Commission, as well as direct control systems of these mechanisms.

What security measures do we take for the protection of your data?

CUPIO ensures the technical and organisational measures necessary for the collection, processing and storage of data safely, including gaining unauthorised access, unauthorised use of data, or destruction, loss or alteration of data. We commit to keeping your personal data safe and take all reasonable protection measures to do this.

We implement systematic processes to train the people responsible for IT security and to monitor and audit the security of our systems and IT infrastructure according to CUPIO's internal policies.

In addition, we make all reasonable efforts to ensure (including through contracts signed with them) that our trusted partners follow the same adequate technical and organisational measures for processing the data we share with them.

What are your rights and options regarding the data we process?

We want to make sure that at any time you have full control over your data and that you can effectively exercise your rights and options under GDPR.

To ensure that you have effective control of your data, we inform you that you have the following options based on the technologies you have available:

  • from your customer account you can manage the access, rectification or direct deletion of some data available in your customer account on the CUPIO website;
  • you will be able to delete cookies or your browsing history from the settings of the CUPIO website; in addition, you can choose to modify the settings of the browser you are using so that you can restrict the tracking of your behaviour on the CUPIO website (however, these restrictions may affect your browsing experience on the CUPIO website);
  • social media platforms and search engines (e.g. Google or Facebook) offer you the possibility to manage various options regarding the way you choose to process your data.

In addition to these options, GDPR offers you, as a data subject, the rights described below. Before we respond to any request regarding your rights, we will make sure that you are the data holder regarding which you choose to exercise these rights, and for this purpose we may request some information/data to verify your identity, or we may request more details about your request. The correspondence we will have with you may be held to ensure that we keep track of your requests and answers regarding your rights.

  • The right to be informed. You have the right to receive clear, transparent, easy-to-understand and easily accessible information about how we process your data, including details about your rights, as a data subject. This information about the data, purpose and how we process your data is also included in this policy.
  • The right to access your data. You have the right to access the data we process about you, without charging any kind of fee for the first-time data supplies. If you need copies of the already supplied data, we may charge a reasonable fee considering the administrative costs of providing the data. We have the right to refuse excessive or repeated and unjustified requests.
  • To exercise your right of access, you can send your request to: date.personale@cupio.ro;
  • The right to rectify data, in case you identify that your processed data is incorrect, incomplete or inaccurate. You can send us a request for rectification/deletion of data at the e-mail address: date.personale@cupio.ro;
  • The right to object to direct marketing (including profiling for direct marketing purposes).

You can object and unsubscribe at any time from our direct marketing communications. You can do this easily by clicking on the "unsubscribe" link in any email we will send you.

In addition, you can opt to withdraw your consent previously expressed for the transmission of personalised offers based on profiling through communication channels email, text message or push-up notifications directly from the customer account. The withdrawal of consent (through the ‘unsubscribe' button or written request) does not affect the legality of the processing based on consent expressed before the withdrawal.

  • The right to object to processing based on a legitimate interest

You can object at any time to any data processing when we base such processing on our legitimate interest. See the section "What is the legal basis for data processing?" in the table above to identify situations where our processing is based on our legitimate interest.

You can exercise this right in writing by sending a written request to the e-mail address: date.personale@cupio.ro;

  • The right to erase data (the right to be forgotten).

You have the right to ask us to erase your data in any of the following situations:

    1. personal data is no longer necessary to fulfil the purposes for which we have previously processed them;
    2. you withdraw your consent based on which we processed your data and there is no other legal basis on which we can rely on a future processing;
    3. you oppose the processing of data when we process data for direct marketing purposes (including, profiling for direct marketing purposes);
    4. you oppose the processing of data based on our legitimate interest and we cannot demonstrate that we have legitimate reasons justifying the processing which prevail over your interests, rights and freedoms;
    5. personal data is processed contrary to the law;
    6. personal data must be erased to comply with our legal obligations.

This is not an absolute right. We may reject your request to delete data if: (i) we are obliged to comply with legal obligations to keep data; or (ii) if the data is necessary for exercising the defence of our rights in court.

You can exercise this right in writing by sending a written request to date.personale@cupio.ro.

  • The right to restrict processing

You have the right to obtain from us the restriction of data processing in one of the situations described below:

    1. the accuracy of the data is contested by you (the data subject), for a period that allows us to verify the accuracy of the data;
    2. the processing of data is illegal and you (the data subject) oppose the erasure of data and request the restriction of the processing of these data;
    3. we no longer need your data, but they are requested by you (the data subject) for compiling the right to defense or other legal claims;
    4. you (the data subject) raise some objections regarding the processing of data based on our legitimate interests, under the verification if the legitimate reasons of the operator exceed those of the data subject (i.e. yours).

You can exercise this right in writing by sending a written request to the email address: date.personale@cupio.ro.

  • The right to data portability

When we process your data based on consent or execution of the contract, automatically, you will have the right to ask us to transfer your data: (a) to you or (ii) to another operator indicated by you. The second situation implies that you have the option to ask us to transmit the data associated with the customer account to another data operator (e.g. to an operator who administers another online store website). Specifically, you will only be able to request the transfer of personal data which you have directly and actively provided to us (excluding any derived or created/ developed data by CUPIO, such as for example a customer profile).

You can exercise this right in writing by sending a written request to the email address: date.personale@cupio.ro. We will transmit your requested data according to what is specified here in a structured format that allows data reuse (e.g. in XML, JSON, CSV format).

  • The right to file complaints with the supervisory authority

You have the right to file any complaints with A.N.S.P.D.C.P. about how we process your personal data. However, we hope you will decide to discuss with us first, before filing any complaints with A.N.S.P.D.C.P. The protection of your data is very important to us and we will take all necessary measures to solve any problem regarding the control and security of your data.

You can also address various questions to A.N.S.P.D.C.P., the supervisory authority for data protection in Romania. You can find some guides and guidelines regarding your rights on the authority's web page https://www.dataprotection.ro/

Questions and requests regarding data protection

CUPIO is at your disposal for any uncertainties, clarifications or any details you need regarding this data processing guide. You can also contact us for any suggestions or comments related to this guide or how we collect and use your data.

When is this guide updated?

This data processing guide is subject to changes and is completed by other specific policies of CUPIO, respectively: (a) The data processing policy through CCTV systems [if any], and (b) Cookie usage policy, available on the Online Store website.

Correspondence address: Calea Lugojului, no. 148, CTPark, Tim4 Building, Ghiroda, Timis

Headquarters address: Timisoara, Str. Felix, Nr.25, Sc.B, Ap.2, Jud. Timis.

Momentan suntem offline. Intre orele 9:00-17:30, L-V, suntem aici pentru tine. 🤗