PRIVACY POLICY AND PROCESSING OF PERSONAL DATA

Effective date: 17.02.2026

1. PREAMBLE AND COMMITMENT

The confidentiality of your personal data is one of the main concerns of GEKO COMERT SRL. As a data controller, we undertake to respect the private nature of your information and to ensure a high level of data protection, in accordance with:

  • Regulation (EU) 2016/679 (“GDPR”) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
  • Law no. 190/2018 regarding measures for the implementation of the GDPR Regulation in Romania;
  • Law no. 506/2004 regarding the processing of personal data and the protection of privacy in the electronic communications sector.

This document is intended to transparently inform you about how we collect, use, transfer, and protect your data when you interact with the website https://www.geko.ro/.

2. IDENTITY OF THE DATA CONTROLLER

Your data is processed by:

  • Commercial Name: GEKO COMERT SRL
  • Legal Form: Limited Liability Company (LLC)
  • Unique Registration Code (CUI): 14832668
  • Trade Register Number: J40/7903/2002
  • Registered Office: BUCHAREST, Sector 2, Str. VIDIN, No. 3A, Bl. SUPRAFATA 160MP BUCURESTI SECT 2, Ground Floor.
  • Website: https://www.geko.ro/
  • Dedicated data protection e-mail: office@geko.ro

3. DEFINITIONS

For a better understanding of this policy, the terms below have the following meanings:

  • Personal data: Any information relating to an identified or identifiable natural person (name, personal identification number, email, location data, online identifiers, etc.).
  • Processing: Any operation performed on data (collection, recording, organization, storage, adaptation, consultation, use, disclosure, deletion).
  • Data subject: You, as a visitor or customer of the website.
  • Controller: GEKO COMERT SRL, the entity that determines the purposes and means of personal data processing.

4. CATEGORIES OF DATA PROCESSED

We collect the data that you provide to us directly, as well as data collected automatically through your interaction with the website.

4.1. Data provided directly by you

  • When creating an account: First name, last name, e-mail address, password (encrypted).
  • When placing an order: Billing address, delivery address, phone number, company details (if applicable – CUI, Trade Register No., Bank).
  • When contacting customer service: Name, e-mail, phone number, content of the message or call recordings (if applicable and if you are notified).
  • When subscribing to the Newsletter: E-mail address.

4.2. Automatically collected data (Technical Information)

When you access the website, our servers automatically collect:

  • The IP address of the device.
  • The type of browser and its version.
  • The operating system.
  • Information about the visit (pages accessed, time spent on pages, browsing history on the website, download errors).
  • Traffic source (where you came from to reach our website).

This data is collected through cookies and similar technologies (see the Cookies Section).

5. PURPOSES AND LEGAL GROUNDS OF PROCESSING

We do not process your data except for legitimate and well-defined purposes, as follows:

Purpose of Processing Details Legal Basis (GDPR)
1. Order Processing Receiving the order, validation, shipping, invoicing, providing status updates, returns. Performance of the contract (Art. 6 para. 1 lit. b). Without this data we cannot fulfill the order.
2. Compliance with legal obligations Accounting, archiving tax documents, reporting to ANAF, fraud prevention. Legal Obligation (Art. 6 para. 1 lit. c).
3. Support Services (Customer Care) Resolving issues related to orders, products, warranties. Legitimate interest (Art. 6 para. 1 lit. f) to ensure customer satisfaction.
4. Direct Marketing (Newsletter) Sending offers, promotions, product news. Consent (Art. 6 para. 1 lit. a). You may unsubscribe at any time.
5. Service improvement and traffic analysis Statistics, analysis of user behavior for website optimization. Legitimate interest (Art. 6 para. 1 lit. f).
6. Defense of rights in court Establishing, exercising, or defending a legal claim in the event of disputes. Legitimate interest (Art. 6 para. 1 lit. f).

6. DATA RETENTION PERIOD

GEKO COMERT SRL will store your personal data only for the period necessary to achieve the processing purposes set out above, in compliance with the legislation in force:

  1. Data related to orders and invoices: Stored for 10 years from the end of the financial year, in accordance with Accounting Law no. 82/1991.
  2. User account data: Stored until you decide to delete the account or after a period of inactivity of 3 years from the last login.
  3. Marketing data (Newsletter): Stored until consent is withdrawn (unsubscribe). After unsubscription, the data is deleted or anonymized within 30 days.
  4. Cookies: The lifespan of cookies varies from one session up to 2 years, depending on their type.

7. DATA RECIPIENTS (TO WHOM WE DISCLOSE DATA)

In order to carry out our activity, we transmit data to contractual partners (“Processors”), who process data on our behalf and strictly in accordance with our instructions:

  • Courier service providers: (e.g. Fan Courier, Cargus, Sameday, DPD etc.) – for the delivery of goods.
  • Online payment processors: (e.g. Netopia, EuPlatesc, Stripe, the bank’s processor) – for card payment processing. GEKO COMERT SRL does not have access to your full card details.
  • IT service providers and Web Maintenance: The companies that host the website and ensure its functionality.
  • Marketing service providers: (e.g. Google Analytics, Facebook Ads, Mailchimp/Sendinblue) – for analytics and personalized advertising.
  • Accounting services: For mandatory accounting records.
  • Public Authorities: We may disclose data if we are required by law (ANAF, Police, courts) or to protect our vital interests.

8. TRANSFER OF DATA OUTSIDE THE EUROPEAN ECONOMIC AREA (EEA)

As a rule, your data is processed within the EU/EEA. However, some providers (e.g. Google, Facebook, Microsoft) may have servers outside the EU (for example, in the USA). In such cases, we ensure that the transfer is lawful, based on:

  • Adequacy decisions issued by the European Commission (e.g. the EU-U.S. Data Privacy Framework).
  • Standard Contractual Clauses (SCC) approved by the European Commission, requiring the provider to protect data according to European standards.

9. DATA SECURITY

We have implemented robust technical and organizational measures to protect data against destruction, loss, alteration, or unauthorized access:

  • Encryption: We use the SSL (Secure Socket Layer) protocol to encrypt the data transmitted between your device and our website.
  • Access control: Access to the database is strictly restricted to employees who need this data to perform their job duties.
  • Backup: We perform periodic backups to ensure data availability.
  • Passwords: Account passwords are stored in hashed form (irreversibly encrypted).

10. YOUR RIGHTS

Under GDPR, you benefit from extensive rights regarding your data:

  1. Right of access (Art. 15): You may request confirmation of data processing and a copy of the data.
  2. Right to rectification (Art. 16): You may request correction of inaccurate data or completion of incomplete data.
  3. Right to erasure (“Right to be forgotten”) (Art. 17): You may request deletion of data if: it is no longer necessary, you have withdrawn consent, the data was processed unlawfully, etc. (Note: We cannot delete data that we are legally obliged to retain, e.g. invoices).
  4. Right to restriction of processing (Art. 18): You may request the “freezing” of data for a limited period (e.g. while we verify its accuracy).
  5. Right to data portability (Art. 20): You may receive the data in a structured format (XML, CSV) in order to transfer it to another provider.
  6. Right to object (Art. 21): You may object at any time to processing for direct marketing purposes.
  7. Right not to be subject to an automated decision (Art. 22): You may request that important decisions (e.g. granting credit) be made by a human, not by an algorithm.

How do you exercise your rights?
You may send a written, dated, and signed request to the e-mail address: office@geko.ro or by post to our headquarters in Bucharest, Sector 2, Str. VIDIN, No. 3A. We will respond within 30 days.

11. COOKIE POLICY

The website www.geko.ro uses cookies (small text files stored on your device).

  • Necessary: Ensure the functioning of the website (login, shopping cart). They do not require consent.
  • Statistics (Google Analytics): Help us understand traffic.
  • Marketing (Facebook Pixel/Google Ads): To show you relevant ads on other websites.

You may change cookie settings at any time from your browser or from the cookie preferences module on the website.

12. PROCESSING OF MINORS’ DATA

GEKO COMERT SRL services are not intended for minors under the age of 16. We do not knowingly collect data from persons under this age. If we discover that we have collected data from a minor without parental consent, we will delete it immediately.

13. POLICY UPDATES

We reserve the right to periodically update this Privacy Policy to reflect any changes in the way we process data or legislative changes. The new version will be published on the website, and for major changes, we will notify you by e-mail.

14. SUPERVISORY AUTHORITY

If you are dissatisfied with how we have responded to your request, you have the right to lodge a complaint with:

National Supervisory Authority for Personal Data Processing (ANSPDCP)
Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania.
Phone: +40.318.059.211
Website: www.dataprotection.ro


Document generated for GEKO COMERT SRL.