Privacy Policy with respect to the processing of personal data

We consider ensuring the right to the protection of personal data as a fundamental commitment of L’ORTEC MEDICAL, so we will devote all the resources and efforts to process your data in full compliance with Regulation (EU) 2016/679 (the “General Data Protection Regulation” “Or” GDPR “), as well as any other applicable legislation in Romania. Since one of the key principles of this legal framework is transparency, we have prepared this document to let you know how we collect, use, transfer and protect your personal data when interacting with us about products and services including our web site or applications available on your mobile phone.

We reserve the right to periodically update and modify this Privacy Policy to reflect any changes in the way we process your personal data or any changes to your legal requirements. In the event of any such change, we will display on our website the modified version of the Privacy Policy, so please periodically review the contents of this Privacy Policy.
Who we are and how to contact us

L’ORTEC MEDICAL is the trade name of S.C. ERFTAL SRL, Romanian legal entity, having its registered office in Bucharest, aNDRONACHE NR.55 Road, sector 2, with serial number in the Trade Register J40 / 7974/2015, unique tax registration number 34715107 (hereinafter “L’ORTEC MEDICAL “or” new “). For the purposes of data protection law, we are an operator when we process your personal data.

Since we are always open to your views and provide you with any additional information you may need regarding the processing of your data, we encourage you to contact the L’ORTEC MEDICAL Responsible with data protection at your email address. protection@lortec-romania.ro
Which categories of personal data we process

In general, we collect your personal data directly from you so you have control over the type of information you provide us. For example, we receive information from you as follows:

When you create an L’ORTEC MEDICAL account, you submit: your email address, your first and last name;

Within your personal page (My Account) on L’ORTEC MEDICAL you can add additional information such as: mobile phone number, fixed phone number, date of birth, delivery addresses, alternative email address, bank card details etc .;

When placing an order, you provide us with information such as: the product you want, your first and last name, delivery address, billing details, payment method, phone number, bank card details, etc.

We also offer you the opportunity to register with L’ORTEC MEDICAL through your Facebook, Google, or Twitter account. If you opt for one of these variants, you will be directed to a Facebook Admin / Google LLC page where they will inform you about your transfer of data to L’ORTEC MEDICAL. You can view the Facebook privacy policies, respectively Google, using the following links:

    https://www.facebook.com/about/privacy
    https://policies.google.com/privacy
    https://twitter.com/en/privacy

We can also collect and then process certain information about your behavior while browsing our website or using the smartphone, personalizing your online experience, and making offers tailored to your profile. we invite you to find out more details in this regard by consulting the section on the purposes of processing below.

On our website and smartphone we can store and collect information in cookies and similar technologies, according to the Cookie Policy.

We do not collect or otherwise process sensitive data included in the General Data Protection Regulation in special categories of personal data. We also do not want to collect or process data of minors under the age of 16.
What are the purposes and basics of the processing

We will use your personal data for the following purposes:

1. 1. To provide L’ORTEC MEDICAL services for your benefit.

This general purpose may include, as appropriate, the following:

    a) Create and manage your account at L’ORTEC MEDICAL;
    b) Processing of orders, including taking over, validating, dispatching and invoicing;
    c) Solving cancellations or problems of any kind related to an order, to the goods or services purchased;
    d) return of the products according to the legal provisions;
    e) Reimbursement of the value of the products according to the legal provisions;
    f) Provide support services, including providing answers to your questions about your orders or the L’ORTEC MEDICAL goods and services

The processing of your data for these purposes is in most cases necessary for the conclusion and performance of a contract between L’ORTEC MEDICAL and you. Certain processes underlying these purposes are also required by applicable law, including tax and accounting legislation.

2. 2. To improve our services

We always want to offer you the best online shopping experience. To do this, we may collect and use certain information about your Purchaser behavior, we may invite you to fill in satisfaction queries subsequent to the completion of an order, or we can conduct market research and market research directly or through partners.

We base our activities on our legitimate interest in doing business, always taking care that your fundamental rights and freedoms are not affected.

3. For marketing

We want to keep you informed about the best offers for the products / services you are interested in. In this regard, we may send you any type of message (such as e-mail / SMS / phone / mobile push / webpush / etc.) Containing general and thematic information, information on similar or complementary products you have purchased information about offers or promotions, product information added in the “Account / My Basket” section or the “Account / Favorites” section or you have shown interest in purchasing them, as well as other commercial communications such as research market and opinion polls, and we can show personalized recommendations on your website and smartphone. In order to provide you with information of interest to you, we may use certain data about your buyer behavior (e.g., products viewed / added to wishlist / purchased) to create a profile. We always ensure that such processing is done with due respect for your rights and freedoms and that the decisions taken thereon do not have any legal effect on you and do not affect you to a similar extent to a significant extent.

In most cases, we base our marketing communications on your prior consent. You can change your mind and withdraw your consent at any time by:

    Changing your client account settings in the “My Subscriptions” section;
    Access the unsubscribe link displayed in the messages you receive from us; or through
    Contacting L’ORTEC MEDICAL using the contact details described above.

In some situations, we can base our marketing activities on our legitimate interest in promoting and developing our commercial activity. In any situation where we use information about you for our legitimate interest, we take care and take all necessary measures to ensure that your fundamental rights and freedoms are not affected. However, you may, at any time, request us, by the means described above, to stop processing your personal data for marketing purposes, following your request.

4. 4. To defend our legitimate interests

There may be situations in which we use or transmit information to protect our rights and commercial activity. These may include:

    Measures to protect the website and users of L’ORTEC MEDICAL against cyber attacks:
    Measures to prevent and detect fraud attempts, including the transmission of information to competent public authorities;
    Measures to manage various other risks.

The general focus of these types of processing is our legitimate interest in defending our commercial activity, being understood that we ensure that all the measures we take guarantee a balance between our interests and your fundamental rights and freedoms.

We also, in some cases, base our processing on legal provisions such as the obligation to safeguard the goods and values ​​provided for by the applicable legislation in this field.
How long do we keep your personal data

As a general rule, we will store your personal data as long as you have an account on the L’ORTEC MEDICAL platform. You may request us to delete certain information or account closure at any time, and we will respond to these requests, subject to the storage of certain information, including after the account has been closed, in cases where applicable law or legitimate interests impose it.
Who we send your personal data to

As the case may be, we may transmit or give you access to certain personal data of the following categories of recipients:

    companies within the same group of companies as L’ORTEC MEDICAL;
    courier service providers;
    payment / banking service providers;
    marketing / telemarketing service providers;
    market research service providers;
    insurance companies;
    IT service providers;
    other companies with which we can develop joint marketing programs for our goods and services.

If we have a legal obligation or if it is necessary to protect our legitimate interest, we can also disclose certain personal data to public authorities.

We ensure that access to your data by third-party private law entities is done in accordance with the legal provisions on data protection and confidentiality of information, based on contracts concluded with them.
In which countries transfer your personal data

We currently store and process your personal data on the territory of Romania.

However, we may transfer certain of your personal data to entities located within or outside the European Union, including countries where the European Commission has not recognized an adequate level of protection of personal data.

We will always take action to ensure that any international transfer of personal data is carefully managed in order to protect your rights and interests. Transfers to service providers and other third parties will always be protected by contractual commitments and, where appropriate, by other safeguards, such as the standard European Commission’s contractual clauses or certification schemes, such as Privacy Shield for Personal Data Protection transferred from within the EU to the United States of America.

You can contact us anytime, using the contact details listed above, to find out more about the countries where we transfer your data, the pairs and the safeguards we have applied to these transfers.
How we protect the security of your personal data

We are committed to ensuring the security of personal data by implementing appropriate technical and organizational measures, according to industry standards.

The transmission of your personal data is done using state-of-the-art encryption algorithms and stored on secure servers while ensuring data redundancy.

We use PayU processor services to make payments. Any payment information is encrypted using HTTPS technology with TSL 1.2 encryption.

Despite the steps taken to protect your personal data, we would point out that the transmission of information via the Internet in general or through other public networks is not completely secure, with the risk that data may be seen and used by third parties unauthorized parties. We can not be responsible for such vulnerabilities of systems that are not under our control.
What rights do you have

The General Data Protection Regulation recognizes a series of rights with respect to your personal data. You can request access to your data, correct any mistakes in our files, and / or you can oppose the processing of your personal data. You can also exercise your right to complain to your competent supervisory authority or to appeal to the courts. As the case may be, you may also have the right to request the deletion of your personal data, the right to restrict your data processing and the right to data portability.

More information about each of these rights can be obtained by consulting the table below.

In order to exercise your rights, you can contact us using the contact details listed above. Please note the following if you want to exercise these rights:

Identity. We take seriously the confidentiality of all records that contain personal data. For this reason, please send us your requests regarding such records using the L’ORTEC MEDICAL e-mail address. Otherwise, we reserve the right to verify your identity by requesting additional information to confirm your identity.

Fees. We will not charge a fee to exercise any right with respect to your personal data, unless your request for access to information is ungrounded, repetitive or excessive, in which case we will charge a reasonable amount in such circumstances. We will inform you of any fees applied before you resolve your request.

Response time. We plan to respond to any valid requests within a maximum of one month, unless this is particularly complicated or if you have made several requests, in which case we will respond within a maximum of two months. We’ll let you know if we’ll need more than a month. We may ask if you can tell us exactly what you want to receive or what you are worried about. This will help us to act faster and shorten the response time to your request.

Rights of third parties. We do not have to respect an application if it adversely affects the rights and freedoms of other people concerned.