Privacy policy
Last updated: 5 October 2026
This is an English translation; in case of any difference, the Romanian version prevails.
This policy explains what personal data we process when you visit the site and send us an order request, why we process it, how long we keep it and what rights you have. We process data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the applicable Romanian legislation.
Contents
Who is responsible for your data
The controller of your data is SC CRISTAL L SRL (Cristal L), registered with the Trade Register under no. J29/989/1991, fiscal code RO 1360911.
Shops: 15 Cuza Vodă Street, block 5D, ground floor, Ploiești; 2 Mihai Viteazu Square, block 37G, ground floor, Ploiești.
You can contact us by e-mail at cristall.ploiesti@gmail.com or by phone at 0244 593 377.
What data we process
From the order form:
- your name, phone number and e-mail address;
- your company name, if you fill it in;
- the products and quantities you choose, as well as your notes on the order and on each product – for example, the text to be put on a stamp, which may include names, company identification details or a description of a logo;
- the language in which you sent the request (Romanian or English).
If we exchange e-mails about the order, we also process those messages.
From visits to the site: the server keeps, for a limited time, technical logs with the IP address, the page accessed, the date and time and information about the browser (for example, its type and version). Refused or suspicious order requests are logged together with the IP address they were sent from.
Why we process the data and on what legal basis
- To respond to your request: we contact you to confirm the details and the price, make the order and hand it over to you; where applicable, we automatically send you an e-mail confirming that we have received your request. Legal basis: steps taken at your request before entering into a contract, and the performance of the contract (Art. 6(1)(b) GDPR).
- To comply with our legal obligations, for example keeping accounting records when we issue an invoice. Legal basis: legal obligation (Art. 6(1)(c) GDPR).
- For the security of the site, preventing abuse and detecting faults, using the technical logs. Legal basis: our legitimate interest in having a secure and working site (Art. 6(1)(f) GDPR).
Do you have to give us your data?
There is no legal obligation, but without your name, phone number and e-mail address we cannot process your request: we would have no way of contacting you for confirmation. The company name and the notes are optional; any missing details can be agreed together at confirmation.
Where the data is kept and who receives it
Order requests are kept in the site’s database, on the shop’s own server in Romania, and are sent to us by e-mail, to the shop’s addresses. They are used only by our employees who handle orders.
Our e-mail address is a Google (Gmail) account. Order e-mails – including, where applicable, the automatic confirmation sent to you, and any further correspondence – therefore pass through Google’s services, as our e-mail provider. Google may also process data outside the European Economic Area (EEA), under the safeguards it applies to such transfers. You can ask us for details about these safeguards.
Data may be disclosed to public authorities only when the law requires us to do so.
How long we keep the data
- Order requests and the correspondence about them: as long as needed to fulfil your order and to deal with any claims. We review old orders periodically and delete the data we no longer need.
- Financial and accounting documents, such as invoices: as long as required by the Accounting Law no. 82/1991.
- Technical logs: in files of limited size, which the server overwrites automatically, oldest entries first, as new ones are added. How long they last therefore depends on the traffic: typically a few weeks, longer for rare entries such as those about refused order requests. When the server's monitoring is switched on, a copy of the logs is kept for at most 30 days.
What we do not do with your data
- We do not send you marketing messages and we have no newsletter.
- We do not create profiles or make automated decisions about you.
- We do not sell or rent your data.
- We use no traffic analytics, advertising or social media plugins.
- The site does not load scripts, fonts or maps from other sites.
- There are no customer accounts.
The shopping cart is kept only in your browser and reaches us only as part of the request you send. Details are in the Cookie policy.
Your rights
Under the GDPR (Art. 15–22), you have the right:
- to find out whether we process your data and to receive a copy of it (right of access);
- to have inaccurate data corrected and incomplete data completed (right to rectification);
- to have your data erased, under the conditions set by law; for example, we cannot erase accounting documents that the law requires us to keep (right to erasure);
- to have the processing restricted (right to restriction of processing);
- to receive the data you provided to us in a commonly used electronic format, or to have us transmit it to another controller (right to data portability);
- to withdraw your consent, if any processing is based on consent; the processing described here is not based on consent.
Separately, you have the right to object: you may object at any time, on grounds relating to your particular situation, to processing based on our legitimate interest (the technical logs and security measures).
To exercise your rights, write to us at cristall.ploiesti@gmail.com, call us at 0244 593 377 or send us a letter to one of our shops.
Exercising your rights is, as a rule, free of charge. We reply within one month of receiving your request; if the request is complex, this period may be extended by two further months, and we will let you know. We may ask you for additional information to confirm your identity.
If you believe that we process your data in breach of the law, you may lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, sector 1, Bucharest.
Changes to this policy
We may update this policy when the way we process data changes. The version in force is the one published on this page, with the date of the last update.
If you have questions, you can find us on the Contact page.