Privacy policy

Last reviewed on 28 November 2019

Who we are?

SC DESIGN DECO MAISON SRL is a Romanian legal entity, duly formed and existing under the laws of Romania, with its registered office and billing address located in Calea Vacaresti nr 207, Bl85B, sc A, ap 15, sector 4, Bucharest, Romania (hereinafter referred to as the “Company” or “we“), and for the purposes of the data protection legislation, we are the “data controller” with respect to your personal data collected and processed via our website https://www.cristianagrasu.de which can be accesed also via the following addresses: https://www.cristianagrasu.ro, https://www.cristianagrasu.com (the “Website“).

Scope of the Privacy Policy

This Privacy Policy contains information about what happens to the personal data that we may collect and process during your interaction with the Website. This Privacy Policy and our Cookies Policy apply to all users navigating on the Website.

How we obtain your personal data?

We obtain your personal data directly from you when you navigate our Website or when you send your e-mail address in the section Stay in touch. We may obtain your personal data indirectly if you access our Comments section via your Facebook account, Google account, Yahoo account, Github sccoun, Disqus account or Twitter account. Additionally, we may also obtain data from third parties tools such as Google Analytics however the data received in this manner are not associated with a particular user therefore they may be considered anonymized data.

Types of personal data collected, proposes and legal basis

The Company collects the following personal data from and about you:

  • e-mail address if you choose to provide us with such information in order for us to be able to keep in touch and send you newsletters, commercial communications or other information which relates directly or indirectly to the contents of our Website. In order for us to be able to process such personal data we will, we shall rely on your freely given, specific, informed and unambiguous agreement for such processing.
  • records of the correspondence with the Company, including information provided by you when sending us a question or comment via the Website. Such information is necessary in order for us to be able to keep, for a limited period of time, a record of our interactions with our users. In order to process such personal data we shall rely on the legitimate interests of our Company in ensuring that we provide clear and consistent responses and information to our Website users.
  • IP address via the security plug-in. In this way, we can detect possible attacks and block bad “IPs”. In order to process such personal data we shall rely on the legitimate interests of our Company in ensuring that you have a safe navigation on our Website.
  • name, e-mail and user name from the third parties mentioned in section 3 above. We process such personal data because we wish to keep track of the opinions expressed on our website and also to be able to identify and respond to you on your freely given, specific, informed and unambiguous agreement for such processing.

You are not obliged to provide us with your personal data. Nevertheless, should you choose not to provide us with your personal data some of the Website’s functionalities may be unavailable for your use (for example, you will not be able to send any questions or comments to us).

We do not process any special categories of personal data relating to you such as any personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation, as well as personal data relating to criminal convictions and offences. We insist that you do not to include such information in any correspondence with us and not to circulate such personal data on or through the Website or otherwise.

You have the right to withdraw your consent at any time, without affecting the lawfulness of processing performed by the Company based on consent before its withdrawal.

Who has access to your personal data?

For purposes in line with those indicated in Section 4 of this Privacy Policy, the Company may share your personal data with third parties service providers that we entrusted with processing activities and appointed as processors, located within the European Union: cloud service providers, companies that provide IT services, experts and consultants, and/or Company’s lawyers. The list of the data processors appointed by the Company may be requested the by contacting us at contact@cristianagrasu.de.

Transfers of personal data outside the EEA

We may use certain service providers based in the US which may have access to your personal data collected via the cookies place on the Website.  We will only use US services providers which are part of the Privacy Shield which requires them to provide similar protection to personal data shared between Europe and the US. For more details, see the European Commission: EU-US Privacy Shield (https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/eu-us-privacy-shield_en).

Retention period

Your data will be retained only for the duration necessary to achieve the purposes for which the personal data was collected. In any case, the personal data collected for the purposes mentioned at Section 4 of this Privacy Policy is retained for the time necessary to provide you access to the Website to which we have added the length of any applicable statute of limitation following the termination of your visit on the Website. In any event, we shall not keep your personal data for more than two (2) years. At the end of the retention period your personal data will be cancelled, anonymized or aggregated.

What are your rights regarding your personal data?

You can lodge a complaint with the The National Supervisory Authority For Personal Data Processing  (Romanian ANSPDCP) which may be contacted at: 28-30 G-ral Gheorghe Magheru Bld. District 1, post code 010336 Bucharest, Romania, telephone number: +40.318.059.211,  +40.318.059.602

Access Right: You may ask the Company to: (i) confirm whether we collect or process your personal data; (ii) provide you with a copy of that personal data; (iii) give you with other information about your personal data such to the extent that information has not already been provided to you in this Privacy Policy.

Rectification Right: You may ask the Company to rectify your incorrect personal data. We may ask you to provide us with verification information to check the accuracy of the data before rectifying it. Considering the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

Erasure Right: You may ask the Company to delete your personal data. This will happened however only when: (i) it is no longer necessary for the purposes for which it was collected; or (ii) you have withdrawn your consent (if the data processing was relied on your consent); or (iii) following a successful right to object (see ‘Objection Right’ below); or (iv) it has been processed unlawfully; or (v) too comply with a legal obligation to which the Company is subject. However, please bear in mind that the Company is not required to comply with your request to delete your data if the processing of your personal data is required: (i) for compliance with a legal obligation; or (ii) for the establishment, exercise or defense of legal claims. There are certain other circumstances in which we are not required to comply with your erasure request, although these two are the most likely circumstances in which we would deny that request.

Right to restriction of processing: You may ask the Company to restrict (in other words to keep but not to use) your personal data, but only if: (i) the accuracy of the personal data is contested (see Rectification Right), to give us the opportunity us to check its accuracy; or (ii) the processing is illegal, but you do not want it deleted; or (iii) it is no longer needed for the purposes for which it was collected, however we still require such personal data to establish, exercise or defend legal claims; or (iv) you have exercised the objection right, and checking mandatory grounds is ongoing. The Company may continue to process your personal data even if a request for restriction was submitted, if: (i) we have your consent; or (ii) to establish, exercise or defend legal claims; or (iii) to protect the rights of another natural or legal person.

Portability Right: You may ask the Company to provide your personal data to you in a structured, commonly used, machine-readable format, or you may ask to have it ‘ported’ directly to another data controller, however in each case only if: (i) the processing is based on your consent or on the performance of a contract with you; and (ii) the processing is carried out by automated means.

Objection Right: You may object to any processing of your personal data which has our ‘legitimate interests’ as its legal basis, if you believe your fundamental rights and freedoms outweigh the Company’s legitimate interests.

Exercising your rights

To exercise your rights you may contact us as set out in Section 11 however please note the following if you do wish to exercise these rights:

  1. We need proof of your identity. We take the confidentiality of all records containing personal data seriously and reserve the right to ask you for proof of your identity if you make a request in respect of such records.
  2. We will charge no costs: We will not ask for a fee to exercise any of your rights in relation to your personal data, unless your request for access to information is unfounded, respective repetitive or excessive, in which case we will charge a reasonable amount in the circumstances. We will let you know of any charges before completing your request.
  3. We will respond within specific timeframes. We aim to respond to any valid requests within two (2) weeks unless your request is particularly complex, or you have made several requests, in which case we aim to respond within three (3) weeks.

Updates to this Privacy Policy

The Company may amend or/and update this Privacy Policy taking into account the manner in which the General Data Protection Regulation shall be construed or any decisions, opinions and guidance relating to the General Data Protection Regulation issued by specialize authorities.

Contact us

If you have a complaint or concerns about how we use your personal data, please contact us at contact@cristianagrasu.de and we will attempt to resolve the issue as soon as possible.

Would you like to start a project with us?