Legal
Privacy policy
How we process the data you send us, under Regulation (EU) 2016/679 — GDPR.
Last updated: 15 August 2026
1. Data controller
The controller determining the purposes and means of processing is the company identified in the box above. For any request concerning your data, write to us at the email address shown there.
2. What we collect
We collect only what we need in order to assess and fulfil an order:
- Entity details: name, tax identification number, registration number, registered office, delivery address.
- Professional contact details: name of the person writing to us, role, email address, telephone number.
- The content of correspondence exchanged by email or WhatsApp.
- Billing and payment details, including the bank transaction reference.
We do not collect health data or any other special category of personal data. We neither ask for nor wish to receive such information.
3. Where the data comes from
All data comes directly from you, through the messages you send us. We additionally verify entity details against official public registers, information that is publicly accessible in any case.
4. Purposes and legal bases
- Preparing and performing the contract — Article 6(1)(b) GDPR: handling the enquiry, issuing the proforma, delivery and related correspondence.
- Compliance with legal obligations — Article 6(1)(c) GDPR: invoicing, accounting records, archiving.
- Legitimate interests — Article 6(1)(f) GDPR: verifying registered status and retaining evidence of the use declaration, both necessary in order to supply on compliant terms.
5. How long we keep it
Financial and accounting records are kept for the period required by applicable tax and accounting law. Correspondence that does not result in an order is deleted within 12 months. Use declarations are kept for the duration of the commercial relationship and for three years thereafter.
6. Who we share it with
We do not sell or rent data. We share it only where necessary to fulfil an order:
- The courier company, for delivery details.
- Our accounting provider, for financial documents.
- Cloudflare, Inc. — website hosting and content delivery.
- Sanity.io — the system in which we manage the product catalogue.
- WhatsApp Ireland Ltd., where you choose to message us there; in that case the messages are also subject to that service's own policy.
- Public authorities, upon lawful request.
7. Transfers outside the European Union
Some of the providers listed above may process data outside the European Economic Area. Such transfers take place on the basis of the standard contractual clauses adopted by the European Commission or other safeguards provided for in Chapter V of the GDPR.
8. Cookies
This site sets no tracking cookies, runs no traffic analytics, and embeds no social network buttons or scripts. Fonts are served from our own server, not loaded from third parties. That is why you are not shown a cookie consent banner: there is nothing to ask you about.
9. Your rights
As a data subject you have the right of access, rectification, erasure, restriction of processing, portability and objection. You may exercise any of these by writing to the email address in the box above; we respond within 30 days at the latest.
If you consider that the processing infringes your rights, you may lodge a complaint with the Romanian supervisory authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, or with the supervisory authority in your own country, or bring the matter before the courts.
10. Automated decisions
We take no automated decisions and carry out no profiling. Every order is assessed by a person.