Information notice regarding personal data

BILKA STEEL SRL (hereinafter “BILKA”), having its registered office in 17 Henri Coanda St., Brasov, Brasov county, registered with the Trade Register under no. J08/989/2007, URC: 21520278, as owner and operator of the website www.bilka.ro, shall respect the privacy and security of the processing of personal data of each person using the services provided by BILKA and/or accessing the website. In this regard, we used our best efforts to make sure that the information entered in our databases is only used for specified, explicit and legitimate purposes.

Definitions:

  • ANSPDCP = Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal /National Supervisory Authority for Personal Data Processing/;
  • “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  • “processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  • “restriction of processing” means the marking of stored personal data with the aim of limiting their processing in the future;
  • “controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
  • “processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller
  • “recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
  • “consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

All our personal data processing activities comply with the following principles:

  • all data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”)
  • all data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (“purpose limitation”)
  • all data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”)
  • all data shall be accurate and, where necessary, kept up to date (“accuracy”)
  • all data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”)
  • all data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).

Types of personal data processed

When delivering the products and services to its customers, BILKA processes the following types of personal data: last name, first name, phone number, e-mail address, product delivery address, IBAN.

Furthermore, the surveillance cameras and other security means placed within our properties may capture or record images of our guests in public places (such as entrances to our manufacturing areas, storage areas and office areas), as well as your location data (through the images captured by the surveillance cameras).

You may choose at any time which personal data you wish to provide us. However, if you choose not to provide certain personal data, and the grounds for our request is represented by the need to comply with a legal obligation, contractual obligations or obligations required to conclude an agreement, we will be unable to provide you with certain services, such as:

(i) if you do not wish to provide us the last name, first name, e-mail address or phone number when you wish to receive a quotation, we will not be able to process your request, or

(ii) considering that in the order form or in the agreement you will have to enter certain personal data required by law, if you do not wish to fill out these required fields, we will not be able to fulfill your order.

If you are a representative or contact person of our suppliers or business partners, we collect the last name, first name and function, as well as any other data provided by you or the company you represent.

If you are under 16 years of age, you have to get the consent or authorization of your parents or guardian in order to provide any personal data.

If you have applied for or intend to apply for any of the vacant positions published by BILKA through various channels, usually we collect the following types of personal data:

  • Job history and formal education history;
  • Professional competencies and skills;
  • Date of birth, age;
  • Nationality and capability to perform paid work on the territory of Romania;
  • Information provided during interviews, which may include experience, own performance, data about your personal records, etc.
  • Information provided through references;
  • information included in your Résumé and the Résumé itself, respectively;
  • information you provide regarding the career interests and other information on your qualification for employment.

You provide us these data voluntarily, as part of a recruiting process you participate in by your own accord. Furthermore, you, as applicant for a job published by BILKA, shall determine the complexity of the information provided. Furthermore, if no information is provided or if the information provided is inaccurate, this might affect our capability to consider a natural person in a recruiting / employment process or to offer relevant employment opportunities. In addition, accurate personal data and proof of such data must be provided, otherwise the employment agreements shall be deemed void.

If you are a visitor in our location, we collect the last name, first name, as well as the serial number of the identity document. Furthermore, the surveillance cameras and other security means may capture or record images of the visitors in public places (such as access routes to our areas).

Purpose of data processing

BILKA processes your personal data for the following purposes:

  • to accept requests for quotations from data subjects interested in the products and services provided by BILKA and the submission of the requested quotations
  • to make the necessary arrangements to conclude an agreement;
  • to be able to respond to questions and requests;
  • to ensure the warranty of products and services
  • to protect us against cyber-attacks or unauthorised access in our locations;
  • marketing activities
  • to provide and improve the services we provide;

Personal data collection methods

We collect personal data in various ways and through multiple channels, such as:

  • in digital format through e-mail, through the www.bilka.ro website
  • through the communication channels associated with social media applications such as Facebook, Youtube, LinkedIn, Twitter, etc.;
  • through recruitment platforms: bestjobs, ejobs, linkedin, etc.;
  • during our interactions with our customers and suppliers

Legal grounds for data processing

According to GDPR (applicable as of May 25, 2018), the consent of the person is not requested if the data processing is required to make arrangements for the conclusion of an agreement, fulfill a legal obligation or for a legitimate interest.

Regarding the data we collect automatically through cookies or other similar technologies, the grounds for data processing is the consent. By accessing the website, the user validly gives his/her consent to data processing.

The consent-based processing of personal data creates various communications for marketing purposes, such as the promotion of the BILKA services, and does not represent a condition for the delivery/performance of the contractual services.

Duration of the storage of personal data

Your personal data shall be stored by BILKA for a duration that never exceeds the period required to fulfill the goals described above and/or for any other period required by virtue of the applicable legal obligations, such as the data included on fiscal invoices (stored for a period of 10 years, according to the legislation in force).

International data transfers

While performing its activities, BILKA does not intend to disclose or transfer the personal data of natural persons to third parties outside the EEA (European Economic Area).

We are bound to disclose such information to the following entities:

  • International partners in import-export operations
  • Service providers. We may disclose information to our service providers acting as processors, e.g. the company that provides support services for the IT infrastructure of BILKA. These entities are selected with utmost care in order to make sure that they meet the specific requirements related to the protection of personal data. These entities have a limited capability to use the information provided by us for other purposes than to provide us with the services;
  • Courts of law, public prosecutor’s offices, police or other national and local public authorities, in order to comply with the legal provisions or as a response to a mandatory legal procedure (court orders, etc.);
  • Other parties, upon the consent or the instructions collected otherwise than the situations described in this Information Notice, we may transfer the information to third parties where the user consents or requests such an action to be undertaken.

Your rights

BILKA undertakes to meet the requirements of the Regulation (EU) 2016/679 (“GDPR”) and to respect the rights of natural persons, namely:

  • Right of access – the right of the data subject to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and to the information related to the way such data are processed.
  • Right to data portability – the right to receive the personal data in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller, if this is technically feasible.
  • Right to object – the right to object to the processing of personal data where the processing is necessary for the performance of a task carried out for reasons of public interest or where it concerns a legitimate interest of the controller. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data.
  • Right to rectification – the right to obtain without undue delay the rectification of inaccurate personal data stored. The rectification shall be communicated to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
  • Right to erasure (“right to be forgotten”) – the right of the data subject to obtain from the controller the erasure of personal data concerning him or her without undue delay, where one of the following grounds applies: the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; the data subject withdraws consent on which the processing is based and where there is no other legal ground for the processing; the data subject objects to the processing and there are no overriding legitimate grounds for the processing; the personal data have been unlawfully processed; the personal data have to be erased for compliance with a legal obligation; the personal data have been collected in relation to the offer of information society services.
  • Right to restriction of processing – a right exercised when the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data; the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.
  • Right not to be subject to an automated decisional process – in this regard BILKA shall not use software applications, algorithms, artificial intelligence or automations to make decisions that have an effect on natural persons.

In order to exercise your rights, please send your request to office@bilka.ro

BILKA has implemented organizational and technical security procedures to ensure the privacy, transparency, integrity and availability of the personal data and to comply with the requirements of European Regulation (EU) 2016/679.

If you consider that your rights set out in Regulation (EU) 679/2016 have been violated by BILKA, you may turn to ANSPDCP by submitting a complaint.

The contact details of ANSPDCP are:

Address: B-dul G-ral. Gheorghe Magheru 28-30

Sector 1, cod postal 010336

Bucharest, Romania

Phone: +40.318.059.211

+40.318.059.212

Fax:       +40.318.059.602

E-mail:    anspdcp@dataprotection.ro

Website: www.dataprotection.ro

This Information Notice is subject to change without prior notice. Please visit this section periodically for up-to-date information on the types of personal data processed by BILKA, as well as the way they are used.