PRIVACY POLICY

Lastupdate:April1,2021

I. INTRODUCTION

This policy of confidentiality has role to state the purpose of processing data of character personnel in the The web site www.cassa.ro ( ” Website “) and the application information for billing , management and administration of documents the accounting or administrative CASSA (“ Application ”), in accordance with Regulation (EU) 2016/679 the protection of those individuals in which that the processing of data of character personnel and on the free movement of such data and the repeal of Directive 95/46 / EC ( referred to hereinafter ” GDPR”), of Law no. 190/2018 on measures for implementing the application of Regulation (EU) 2016/679 on the protection of individuals individuals in terms that the processing of data of character personnel and on the free movement of such data and the repeal of Directive 95/46 / EC and the Law no. 506/2004 on the processing of data of character personnel and protection of life private in the communications electronics .

This policy of confidentiality is supplemented with terms and conditions available on the Website and in the application , and the terms defined in the content Terms and conditions have the same meaning and in the policy of confidentiality.

This policy of confidentiality the data of character personnel of visitors Website- ‘s , the representatives of the users ( people legal ) of users ( people physical ), the representatives of suppliers ( people legal ) of suppliers ( people physical ) of employees authorities public and of participants in events , conferences , fairs .

By means of this Policy of Privacy we will inform with respect to:

✅ What personal data we process;

✅ For what purpose we pro cess personal data and what is the legal basis of the processing;

✅ For how long we store personal data;

✅ If there are recipients to whom personal data are transmitted;

✅ If we intend to transfer personal data to a third country or international organization (outside the European Union or the European Economic Area);

✅ If we make automatic decisions or make profiles;

✅ Your rights as a data subject

II. OPERATOR DATA

The company CASSA DIGITAL SOFTWARE S.R.L, (hereinafter referred to as “CASSA”), with its registered office in Bucharest, Sector 2, Cal. Moșilor, no. 158, ground floor, module P193, registered at the Trade Register under no. J40 / 10442/2019, fiscal code 41497978, legally represented by Mr. Fugaru Dumitru Cornel and Mr. Teodoroiu Daniel, as administrators, e-mail roxana@cassa.ro, as a personal data controller, processes your personal data in accordance with this Privacy Policy.

III. . WE PROCESS PERSONAL DATA

A. OF THE VISITORS OF THE WEBSITE AND OF THE USER (PERSON INDIVIDUAL) OR OF THE USER’S REPRESENTATIVE (LEGAL ENTITY)

1. Data processed automatically during the visit of the Website

Your browser automatically transmits, each time you access the Website, data that is stored in the server’s log files. This includes the following data (hereinafter referred to as “log file data“):

⚫ information about the type of browser and its version;

⚫ information about the operating system of the device from which you access the Website;

⚫ information about the Internet service provider and IP address; and

⚫ date and time of access.

The data in the log files are evaluated anonymously for the purpose of continuous improvement of the Website, its adaptation and the prompt correction of errors, if they occur during the use of the Website. For these purposes, we process this data in accordance with our legitimate interest in improving the Website and maintaining it in a free form. fall.

In an anonymized format, Data from log files are used exclusively to detect malfunctions and ensure system security, including for detecting and tracking attempts at improper access and fraud or attempts at abuse. The data are stored for a period of 30 days and then deleted, unless storage for a longer period of time is required for evidentiary purposes. In individual cases, the data in the log files can be transmitted to the research authorities.

At the same time, in order to be able to take into account the preferences you expressed in previous browsing sessions, to adapt the Website to the device you are using and to solve the problems you may encounter when accessing, we process the following date:

⚫ IP address;

⚫ cookie identifiers;

⚫ other online identifiers;

⚫ unique device identifier (unique universal ID – UUID);

⚫ date and time of access website;

⚫ history of visits;

⚫ web request;

⚫ date and time of request / date and time of accessing the Website;

⚫ the type of device from which you access the Website;

⚫ the type of Internet browser and the language of the browser;

⚫ information about events on your device (for example, errors);

⚫ information about the hardware settings of your device;

⚫ information about where you are when you access the Website.

The data processed in order to adapt the Website to the device you use and to your preferences are processed in our legitimate interest to make available to the Website adapted to your preferences and needs.

2. Data processed during the use of the Application

By requesting an offer for Access to the Application or for contracting another Service available within the Application made by telephone, on the Website or in the Application, taking into account the fact that you act as User (natural person) or representative of the User (legal person), in order to transmit the requested offer, we will process the following personal data filled in by you:

⚫ name and surname;

⚫ name and surname;

⚫ telephone number.

. When you have Access to the Application, we will process your personal data for the following purposes:

⚫ creation and administration of the User Account;

⚫ managing the relationship between Users and facilitating communication between them;

⚫ managing the documents uploaded in the Application;

⚫ keeping records of the documents uploaded in the Application;

⚫ management of placed orders;

⚫ issuing the invoice and recording the payment;

⚫ generating invoices and proforms in the Application;

⚫ providing the ordered services;

⚫ maintenance of the Account;

⚫ improving the services offered;

⚫ diagnosis and remediation of technical problems;

⚫ fulfillment of legal obligations (for example, tax obligations);

⚫ finding or claiming a right in court;

⚫ fraud prevention.

In order to fulfill the purposes mentioned above in connection with access to the Application, we will process the following personal data:

⚫ name and surname;

⚫ the position within the company you represent (the User);

⚫ opinions;

⚫ invoice and payment data;

⚫ address;

⚫ IBAN account;

⚫ card related data (Cardholder name, card number, CVV code, expiration date).

In the event that you act as a representative of the User (legal entity), we base the processing of your personal data on the fulfillment of our legitimate interest in managing the business relations of the User you represent and on the fulfillment of legal obligations.

In the event that you act as User (natural person), we base the processing of your personal data on the execution of the contract under which you are a party or to take the necessary steps at your request before concluding the contract and on fulfilling the legal obligations.

3. Data processed in order to operate in optimal parameters of the Website and the Application

In order to ensure the operation of the Website and the Application and to notify you of the information concerning you as a User (individual) or a representative of the User, we process your personal data for the purpose of sending messages / alerts. We also process your personal data in order to produce internal statistics on the functionality of the Website and the Application.

We will process the following data:

⚫ name and surname;

⚫ name and surname;

⚫ telephone number;

⚫ IP address;

⚫ data from access and use logs.

The basis of these processing will be, our legitimate interest in maintaining the application and the Website in the optimal parameters of operation.

4. Data processed in order to provide a response to a request / notification / complaint

You can contact us both by filling in the contact form available on the Website, by phone or by e-mail at roxana@cassa.ro.

In order to respond to your request / notification / complaint, we will process the following personal data:

⚫ name and surname;

⚫ name and surname;

⚫ telephone number;

⚫ any other data and information contained in the request / notification / complaint you send us.

In this case, we base the processing of your personal data on the fulfillment of our legitimate interest in responding to requests / notifications / complaints received.

Following the resolution of your request, personal data will be deleted to the extent that and if we have no obligation to store them for reasons provided by commercial and tax law.

5. Communication for marketing purposes

In order to send you communications and offers about the products, our services and promotions (on our own initiative), it is necessary to process your personal data. In this case, the data processing will be based on your consent.

We will process the following personal data:

⚫ name and surname;

⚫ name and surname;

⚫ telephone number.

If and to the extent that you have consented to receive information for advertising purposes (for example, you have subscribed to receive newsletters by e-mail), but subsequently no longer wish to receive such advertising information, you may revoke your consent. you have given it at any time, which will have effects for the future (for example, you can withdraw your consent using the unsubscribe link included in the newsletter).

B. SUPPLIERS ‘REPRESENTATIVES

1. To be able to conduct business relations with

In order to be able to start and maintain the collaboration with the supplier you represent, it is necessary to process certain personal data of yours as a representative of the supplier. In this case, we base the processing of your personal data on our legitimate interest in managing business relationships with suppliers.

To fulfill this purpose, we will process the following personal data:

⚫ name and surname;

⚫ name and surname;

⚫ telephone number.

2. Solving requests / requests / complaints

In order to be able to answer any requests, requirements, complaints or any other questions you send us in the contractual relationship with the supplier you represent, we will process the following personal data:

⚫ name and surname;

⚫ name and surname;

⚫ telephone number;

⚫ any other data and information contained in the application you send us.

In this case, we base the processing of your personal data on fulfilling our legitimate interest in responding to requests / requests / complaints received.

C. OF EMPLOYEES PUBLIC AUTHORITIES

In order to be able to manage the relationship with the public authorities, as well as to be able to fulfill our legal obligations (such as submitting or picking up documents, responding to requests from authorities, paying contributions, fees and the like), we will process your data staff as a representative of a public institution.

To fulfill this purpose, we will process the following personal data:

⚫ name and surname;

⚫ the quality held in the public authority of which you are part;

⚫ your signature (for example, the signature in the control registers that the law requires us to keep).

In this case, we base the processing of your personal data on the fulfillment of our legal obligations, respectively on our legitimate interest to respond to requests received from public authorities.

D. D. OF PARTICIPANTS IN EVENTS, CONFERENCES, FAIRS

If you visit our booths at events, conferences or trade fairs we attend, we process your personal data that you voluntarily provide to us in response to your requests (for example, for future discussions and offers) or to keep in touch with you. .

We process personal data that you may provide to us at events, conferences or fairs in our legitimate interest to respond to your requests or to keep in touch with you.

At our stands and at the events we organize, we occasionally take photos and videos for documentary, marketing and media purposes, which are published, among other things, on our social media pages (eg Facebook or Instagram) or on the Website. In this case, we will explicitly tell you this by posting a announcement at the stand and we will ask your consent for the taking of photos and videos and for their use.

IV. WHAT ARE YOUR RIGHTS

According to the law on data protection, you have the following rights in connection with the personal data processing activities that we carry out:

  1. The right of access

You have the right to obtain a confirmation of the processing or non-processing of your personal data, access to them by providing a copy of the personal data (if the data is processed).

  1. The right to rectification

You have the right to request the rectification of your personal data that you consider to be inaccurate. You also have the right to ask us to fill in your personal data that you consider to be incomplete.

In order to comply with your request, you must: with the request for rectification:

✅ clearly specify the character data staff you believe are inaccurate or incomplete;

✅ explain how yor personal data should be rectified or supplemented; and

✅ provide evidence of inaccuracies, where applicable

  1. The right to the deletion of personal data

You can request the deletion of your personal data, and CASSA will only process your request if one of the following circumstances applies:

✅ personal data are no longer required by CASSA to fulfill the purposes for which they were collected or processed;

✅ you initially consented to the processing of your personal data by CASSA, but you withdrew your consent and there is no other legal basis for the processing;

✅ CASSA has collected or processed your personal data illegally;

✅ CASSA has the legal obligation to delete your data;

✅ personal data has been collected in connection with the use of the Website or the Application by a child under the age of 16 and for whom consent to the processing of data has not been given or authorized by the holder of parental responsibility over it.

CASSA may refuse in whole or in part the deletion of your personal data in the following circumstances:

✅ processing is necessary for the exercise of the right to free expression and information;

✅ the processing is necessary in order to comply with a legal obligation of CASSA (for example, according to Law no. 16/1996 on National Archives) or to fulfill a task performed in the public interest;

✅ processing is necessary for the establishment, exercise or defense of a right in court;

✅ processing is necessary for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes.

  1. The right to restrict processing

You can request a restriction on the processing of personal data if one of the following circumstances applies:

✅ challenge the accuracy of the data, for a period that allows CASSA to verify the accuracy of the data;

✅ the processing is illegal and you object to the deletion of personal data and instead request the restriction of their use;

✅ CASSA no longer needs personal data for the purpose of processing, but you request them for the finding, exercise or defense of a right in court;

✅ you object to the processing for reasons related to your particular situation, for the period of time in which it is verified if the legitimate rights of CASSA prevail over those of your rights.

  1. 5. The right to object to the processing

You have the right to object at any time, for reasons related to your particular situation, to the processing of your personal data if the basis underlying the processing is the legitimate interest of CASSA. In this case, CASSA will no longer process your personal data, unless CASSA demonstrates that it has legitimate and compelling reasons justifying the processing and prevailing over your interests, rights and freedoms or that the purpose is to establish, exercise or defend a right in court.

You have the right to object at any time to the processing of your personal data for the purpose of direct marketing, including the creation of profiles in connection with direct marketing.

You have the right to object, for reasons related to your particular situation, to the processing of your personal data for the purposes of scientific or historical research or for statistical purposes, unless the processing is necessary to perform a task for reasons of public interest.

  1. The right to data portability

You have the right to receive personal data concerning you and which you have provided to CASSA in a format structured, commonly used and automatically readable and you have the right to transmit this data to another operator, without encountering obstacles from CASSA, if:

✅ the processing is based on your consent or on a contract concluded with CASSA to which you are a party, and

✅ the processing is performed by automatic means.

  1. The right not to be subject to an automated individual decision-making process, including for the creation of profiles

You have the right not to be subject to a decision based solely on automatic processing, including profiling, which produces legal effects that affect you or similarly affect you to a significant extent.

CASSA may make decisions based solely on automated processing, including profiling, in one of the following situations:

✅ the decision is necessary for concluding or executing a contract between you and CASSA;

✅ the decision is authorized by law which CASSA applies and which provides appropriate measures to protect your rights, freedoms and legitimate interests;

✅ the decision is based on your explicit consent.

However, we currently provide the necessary human attention to your personal data through our staff. Under the current conditions, you will not be subject to a decision of ours based solely on the automatic processing of your data (including the creation of profiles) which will produce legal effects on you or which will affect you in a similar way to a significant extent.

  1. The right to lodge a complaint

You have the right to address the National Authority for the Supervision of Personal Data Processing or the competent courts, to the extent you deem necessary.

To make a request in connection with one of the rights mentioned above (points 1-6), please contact us at e-mail address roxana@cassa.ro. CASSA will not charge any fees for the exercise of your rights as long as your claim is not excessive or unfounded. We will respond to your request within one month, with the possibility of extending this period by another two months if necessary, taking into account the complexity and number of requests, with your prior notice, including the reasons for the delay.

V. TO WHOM WE TRANSMIT PERSONAL DATA

  1. The payment service provider

Payment data will be transmitted to the payment service provider for payment processing. If you make the payment through the __________________ platform, you will be redirected to the _______________________ website via a link. Please see the General Terms and Conditions, Terms of Use and Privacy Policy used on the ____________________ _ website. Please note that payment details are not available stored at no time on CASSA servers, but are processed and stored only by the transaction authorization institution or by another entity authorized to provide card identification data storage services, whose identity you will be informed, previously data entry.

In the case of the 3D Secure system for payment with Visa or MasterCard cards, the data related to the card used are entered directly into the Visa or MasterCard systems. This security measure involves redirecting you when making the payment to a secure page where each cardholder is registered by assigning an authorization code for each online transaction. Cards accepted for payment are those issued under the logos VISA (Classic and Electron) and MASTERCARD (including Maestro, if they have CVV / CV2 code).

  1. Facebook

Facebook may receive information that you have accessed the Website and may have interacted with the insert. By activating the insert, your personal data will be saved and sent to Facebook in the USA.

We do not exercise any influence over the data collected and the data processing operations, nor are we aware of the exact extent of the data collection, the purpose of the processing or the data retention periods set by Facebook. We also do not have information on how the data collected by Facebook can be deleted.

You can completely prevent the loading of inserts by using add-ons for your browser, the so-called “script blockers”.

For more information on Facebook’s data processing policy, see https://www.facebook.com/about/privacy.

On the Website, we use various services provided by Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA (hereinafter referred to as “Google”).

For more information about Google and Google’s personal data protection policy, please visit http://www.google.com/privacy/ads/.

If we provide links to the websites of other organizations, this Privacy Policy does not cover how that organization processes personal data. We encourage you to read the privacy policies of the other websites you visit.

  1. Public authorities

Where necessary, for purposes limited to cooperation with public authorities and in accordance with applicable laws, CASSA may disclose your personal data to certain public authorities (eg tax authorities, law enforcement authorities, including law criminal).

We mention that we will fully cooperate with public authorities in any investigation related to any illegal content or activity on the Website or Application.

VI. HOW LONG WILL WE STORE YOUR DATA?

Data storage with personal character is made on servers in Romania and Germany.

Your personal data is stored in accordance with our personal data storage policy, which assigns a storage period according to the purpose of the processing and the category of data processed.

The established periods are based on legal provisions (especially in the field of personal data protection), also taking into account the obligations to store certain data, the applicable limitation periods, best practices in practice and the purposes of our activity.

VII. ARE YOU COMING. REFUSAL TO PROVIDE PERSONAL DATA

Depending on the purpose of the processing, you are not obliged to provide us with your personal data, but in certain situations, if you do not provide us with the necessary personal data, it will not be possible for us to provide access and use.

VIII. UPDATES

If in the future it will be we need to review this Privacy Policy, we will post the revised privacy policy on the Website and in the Application, and we will report the updated version by changing the “Last Updated” date at the top of the policy.

IX. CONTACT

If you have any questions, complaints or need additional information about this Privacy Policy, please contact us at roxana@cassa.ro and we will do our best to respond as soon as possible.