Version 2.0. This policy explains how Euro Intermed Solutions S.R.L. processes personal data in connection with the Euro Intermed B2B platform, its websites, forms, communication channels and associated services. This notice is provided in accordance with Articles 13–14 of Regulation (EU) 2016/679 (GDPR).
1. Who we are
The data controller is EURO INTERMED SOLUTIONS S.R.L., with its registered office in Brașov, Romania, tax ID (CUI) 39132147, registered with the Trade Register under no. J8/735/2018, e-mail: contact@euro-intermed.com, telephone: 0765934455, hereinafter the “Controller” or “we”.
For any data-protection requests you can contact us at contact@euro-intermed.com.
2. Who this policy applies to
This policy applies to natural persons whose data is processed in a B2B context, including: persons who request quotes or submit enquiries through the platform, website, chat or other channels; representatives, administrators, employees or contact persons of client, supplier or partner companies; contact persons associated with commercial leads; platform users; and persons whose data is obtained indirectly from public sources, from partners, from counterparties or from company-verification providers.
Although the platform is B2B in purpose, certain professional data — such as a name, job title, professional e-mail address or work phone number — constitutes personal data when it identifies or makes a natural person identifiable.
3. What data we process
Depending on how you interact with us, we may process the following categories of data:
- identification and contact data, such as first name, last name, job title, company, professional e-mail address, professional phone number;
- company and commercial-relationship data, such as company name, tax ID (CUI), fiscal-status data, field of activity, information about representatives or administrators, where relevant to verifying a business relationship;
- data relating to the enquiry, offer or lead, such as the commercial interest expressed, product or service category, quantities, locations, deadlines, and the content of documents, images or messages sent;
- the content of conversations and interactions, including messages sent through the form, web chat, e-mail, WhatsApp or other channels used in your dealings with us;
- internally generated commercial-qualification data, such as lead status, commercial priority, or internal interest or compatibility scores;
- technical and usage data, such as IP address, session identifiers, access logs, security and consent logs, browser type, device data and interaction with the platform;
- data required for legal compliance, such as billing information, supporting documents and records necessary for tax, accounting or the defence of our rights.
We do not seek to process special categories of data, except where these are provided incidentally or there is a distinct and necessary legal basis for the processing. If a particular flow were to involve special-category data or national identification numbers, it would be subject to additional safeguards and, where appropriate, a specific notice.
4. Sources of the data
We may obtain data either directly from you or indirectly, from other sources.
When data is obtained directly, it generally comes from forms, user accounts, requests for quotes, conversations, sign-ups, e-mails, chat, WhatsApp, calls or other direct interactions with us.
When data is obtained indirectly, it may come from: the company you represent or act for; clients, partners, suppliers or counterparties who send us contact data in the context of a commercial opportunity; public or publicly accessible sources, including trade registers, fiscal sources or company databases; third-party providers of company verification and commercial-data enrichment; professional platforms or communication channels used in the business environment, to the extent permitted by law.
Where data is not obtained directly from the data subject, we provide the information required by Article 14 GDPR within a reasonable period, at the latest within one month of obtaining the data, or at the first contact with the data subject if this occurs earlier, or at the latest at the first disclosure to another recipient, if such a disclosure takes place earlier.
Where individually informing each data subject would prove impossible or would involve a disproportionate effort in relation to the legitimate purposes pursued, or would seriously impair the achievement of those purposes (for example, in certain fraud-prevention activities), we may rely on the exceptions permitted by applicable law, provided that appropriate safeguards for the rights and freedoms of data subjects are put in place.
5. Purposes and legal bases for processing
We process data for one or more of the following purposes.
- To handle enquiries, qualify requests and offers, contact the relevant person, manage the pre-contractual relationship and, where applicable, perform the contract, the basis is taking steps at the request of the data subject prior to entering into a contract, or performance of the contract, as the case may be.
- To create and administer user accounts, provide platform access, authentication, technical support, maintenance and the operation of the service, the basis is performance of the contract or our legitimate interest in administering and securing the service.
- To verify companies, validate the existence of a commercial partner, prevent fraud, carry out commercial-compliance and creditworthiness checks, avoid duplications and protect our economic interests, the basis is legitimate interest, and where the law requires certain checks or retention, the basis may also be a legal obligation.
- For operational communications, such as confirmations, replies to enquiries, account, security, contractual-relationship or request-status notifications, the basis is performance of the contract or the legitimate interest in administering the professional relationship.
- To improve services, perform internal analytics, measure commercial performance, organise leads and carry out internal, non-solely-automated scoring, the basis is the legitimate interest in making our commercial services and processes more efficient, while respecting the rights and freedoms of data subjects.
- To comply with legal obligations, including in tax, accounting, archiving, defence of rights in court, cooperation with authorities and security, the basis is a legal obligation or legitimate interest, as the case may be.
- For commercial communications and direct marketing through electronic channels, the basis and conditions differ depending on the channel and the context in which the data was collected. Commercial communications sent by e-mail or other means governed by the special law applicable to electronic communications will only be carried out under the conditions permitted by that law. Where necessary, we will request prior express consent. Where the legal conditions are met for promoting our own similar products or services to a customer whose e-mail address was obtained directly in the context of a commercial relationship, we may rely on this legal exception, offering a clear and free means to object both at the point of collection and in every subsequent message.
Where instant-messaging channels (for example, WhatsApp Business or similar services) are used for commercial communications, we will act only under the conditions permitted by the applicable data-protection and electronic-communications legislation, and in compliance with the contractual terms and usage policies of the providers of those services (including requirements on consent, permitted content type, message frequency, template approval and unsubscribe mechanisms). We will not use such channels to send unsolicited bulk commercial messages (spam).
6. Legitimate interests pursued
Where processing is based on legitimate interest, our interests may include: efficiently administering the platform and commercial relationships; preventing fraud and verifying the commercial trustworthiness of partners; organising and prioritising commercial enquiries; securing our systems, ensuring service continuity and defending our rights; and improving our products, services and commercial flows.
In every case where we rely on legitimate interest, we assess the impact on the data subject and apply measures of limitation, proportionality and data minimisation.
In all cases where we rely on legitimate interest, you have the right to object, on grounds relating to your particular situation, to such processing. In that case, we will no longer process the data for that purpose, unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or that the processing is necessary for the establishment, exercise or defence of a legal claim.
7. When providing data is necessary, and what happens if you don’t
Some data is necessary to respond to your enquiry, create your account, send an offer, connect the relevant parties or perform the contract. If this data is not provided, we may be unable to process the request, open or maintain the account, provide the service, or continue the commercial relationship.
Other data is optional. Its absence does not necessarily prevent your relationship with us, but it may limit the functionality of the service, the accuracy of commercial qualification, or the ability to personalise the interaction.
If a particular set of data is required under a legal obligation, we will indicate this at the point of collection.
8. Who we disclose data to
We may disclose data, strictly to the extent necessary, to the following categories of recipients: providers of hosting, infrastructure, storage, support and IT maintenance; providers of transactional e-mail, ticketing, security, analytics and technical-administration services; providers of AI or assisted-processing services, where used in our flows, within contractually and technically defined limits; company-verification and commercial-validation providers; legal, tax, accounting or audit advisers, under confidentiality; commercial partners or counterparties, where this is necessary to process a requested opportunity or transaction; and public authorities and institutions, where there is a legal obligation or a valid request.
Some recipients process data on our behalf, as processors, under agreements compliant with Article 28 GDPR. Other recipients may act as independent controllers for their own purposes, as may be the case for certain platforms or communication channels. In those situations, their processing is also governed by their own policies.
9. International transfers
In principle, we aim to store and process data within the European Union or the European Economic Area.
If, for certain features or providers (for example, cloud infrastructure, artificial-intelligence services or messaging services), data is transferred to or accessed from outside the EEA, the transfer is carried out only under the conditions of Chapter V of the GDPR, on the basis of an appropriate legal mechanism — such as an adequacy decision, standard contractual clauses or other appropriate safeguards — and, where applicable, with the implementation of supplementary technical and organisational measures to ensure a level of protection substantially equivalent to that in the EU.
If we use providers that may involve international access to data, we will indicate in this policy the relevant categories of providers, the countries involved or the transfer mechanism used, to the extent applicable.
In particular, for AI, cloud-infrastructure or messaging providers, we will assess whether their use involves transfers of data outside the EEA and, if so, we will implement the transfer mechanisms provided for in Chapter V of the GDPR (such as standard contractual clauses) and supplementary technical and organisational measures, where necessary to ensure a substantially equivalent level of protection.
10. How long we keep data
We keep data only for as long as necessary for the purposes for which it was collected, to fulfil legal obligations, or to defend our rights.
- Leads with no conversion and no subsequent interaction are generally kept for a period of 24 months from the last relevant contact, after which they are deleted or anonymised.
- Data relating to active contractual relationships is kept for the duration of the commercial relationship and thereafter for the period necessary to fulfil legal obligations or defend our rights.
- Tax and accounting documents are kept for the periods required by applicable law.
- Conversation transcripts, support tickets and technical logs are kept for differentiated periods, proportionate to the purpose, security and the need for traceability.
- Records of consent, objection, unsubscribe and marketing preferences may be kept for as long as necessary to demonstrate compliance and to respect the data subject’s choice not to be contacted.
Upon expiry of the applicable period, data is deleted, anonymised or restricted, as appropriate.
We periodically review the data we hold and delete or anonymise it when it is no longer necessary for the purposes described above, taking into account the applicable limitation periods and the legitimate need to retain certain information for the establishment, exercise or defence of legal claims.
11. Profiling, scoring and automated decisions
We may use internal mechanisms for organising and commercially scoring leads, for example to prioritise, route internally or make the commercial relationship more efficient.
In principle, these mechanisms are not used to make decisions based solely on automated processing that produce legal effects or similarly significantly affect the data subject, without human intervention.
Scoring is indicative and may take into account information such as the type of request, the completeness of the data, the company’s commercial profile, the history of interactions and relevance to the services offered. Any relevant commercial decision is subject to human validation.
If a particular flow were to involve a decision based solely on automated processing within the meaning of Article 22 GDPR, we would provide a separate, additional notice, including the relevant logic, significance and consequences of the processing.
To the extent that profiling is based on our legitimate interest or is used for direct-marketing purposes, you have the right to object at any time to such profiling, under the conditions described in Section 12.
12. Your rights
Under the GDPR, you have the right of access to the data concerning you, the right to rectification, the right to erasure, the right to restriction of processing, the right to object, the right to data portability, and — where processing is based on consent — the right to withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
If we process data for direct-marketing purposes, you may object at any time to such processing, including profiling related to direct marketing. In that case, we will stop processing for that purpose.
To exercise your rights, you can contact us at contact@euro-intermed.com or at our registered office in Brașov, Romania. We will respond without undue delay and, in any event, within one month of receiving the request, with the possibility of extension under the conditions provided by law.
You also have the right to object, on grounds relating to your particular situation, to processing based on our legitimate interest, as described in Section 6.
You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), whose current contact details are available on its website.
13. Commercial communications and contact preferences
Strictly operational communications — necessary to respond to a request, administer the account, perform the contract or secure the service — are distinct from commercial communications.
As regards direct marketing by e-mail or other electronic channels governed by special law, we will act only under the conditions permitted by law. Where consent is required, it will be requested separately, specifically, in an informed manner and easy to withdraw. Where we rely on the legal exception for similar products or services, we will provide a clear, simple and free means to object, both at the point the address is collected and in every subsequent message.
Every commercial message we send will include a valid and functional means to unsubscribe or object, as appropriate.
Where instant-messaging channels, such as WhatsApp Business, are used for commercial communications, we will contact you only if we have a valid legal basis and in compliance with the terms and policies of the relevant provider. We will not create groups or broadcast lists on such channels for promotional purposes without your prior agreement and an appropriate legal basis, and you may at any time object to or request that communications cease through a simple and effective mechanism (for example, an unsubscribe link or by sending a clear “STOP” message).
14. Cookies and similar technologies
The website or platform widget may use cookies and similar technologies.
In accordance with the applicable electronic-communications legislation, any storage of information, or gaining of access to information already stored, in the user’s terminal equipment (for example, through cookies or similar technologies) is permitted only if it is strictly necessary for transmitting a communication over an electronic-communications network or for providing an information-society service expressly requested by the user, or if the user has given prior consent through the consent mechanism displayed on the website.
Cookies for analytics, measurement, personalisation or marketing, as well as any storage of or access to information on the user’s device that is not strictly necessary, are used only on the basis of a valid choice expressed through the applicable consent mechanism.
Detailed information about the categories of cookies, their purposes, duration and management options can be found in the Cookie Policy and in the consent mechanism displayed on the website.
15. Data security
We apply appropriate technical and organisational measures to protect data, including measures relating to access control, separation of roles, logging, communications security, back-up, operational continuity and infrastructure protection.
Although we make reasonable efforts to protect data, no system can guarantee absolute security. In the event of an incident affecting you in a way that requires notification, we will act in accordance with the applicable legal obligations.
16. Changes to this policy
We may update this policy from time to time to reflect legislative, technical or operational changes. The updated version and the date of the last revision will be published on the platform or website.
If the changes are substantial, we will use an appropriate means of notification, proportionate to the nature of the change and to our relationship with the data subjects.
Annex A — Short notice at the point of collection (data obtained directly)
We process the data you provide in order to analyse your request or offer, to contact you and, where applicable, to manage the contractual or pre-contractual relationship. The controller is Euro Intermed Solutions S.R.L. The main legal bases are pre-contractual steps, performance of the contract and, where applicable, legitimate interest. We may use technical and company-verification providers. You have rights of access, rectification, erasure, objection and to lodge a complaint with the ANSPDCP. The full information is available in this policy.
Annex B — Short notice for indirectly obtained contacts (Art. 14 GDPR)
We obtained your professional data from a source such as a public register, a partner, a counterparty, a company-verification provider, or the company you represent, in order to assess a commercial opportunity, validate the relevant professional relationship or manage a possible B2B contractual relationship. The data may include name, job title, company and professional contact details. The controller is Euro Intermed Solutions S.R.L. The main basis is the legitimate interest in managing B2B commercial relationships and preventing fraud or identification errors. If you no longer wish us to use your data for commercial-contact purposes, you may object at any time at contact@euro-intermed.com.
To the extent that individually informing all data subjects would be impossible or would involve a disproportionate effort, we may use reasonable alternative means of information or rely on the exceptions permitted by applicable law, provided that appropriate safeguards for the rights and freedoms of data subjects are put in place.