This policy describes how TODY & MADY S.R.L. processes personal data in accordance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (the “GDPR”) and applicable Romanian law, including Law no. 190/2018.
In short: our website has no forms, sets no cookies and uses no analytics or advertising tools. We only process personal data when you contact us by phone or email, and when we work together on a shipment.
1. Who we are
The controller of your personal data is:
- TODY & MADY S.R.L.
- Registered office: Calea Făgărașului nr. 219, 507061 Vlădeni, Brașov County, Romania
- Tax ID (CUI): RO28491510; Trade Register no.: J08/846/2011
- Email: todymady@gmail.com
- Phone: +40 746 313 176 (in english)
- Phone: +40 756 481 302 (in romanian)
We have not appointed a Data Protection Officer (DPO), as our activities do not require one under Article 37 GDPR. For any question about your data, please write to the email address above.
2. What personal data we process
2.1. When you contact us
If you call or email us, we process the data you give us: your name, company and position, phone number, email address, the content of your message and the details of the requested transport (for example, loading and unloading addresses).
2.2. When we work together
To conclude and perform transport contracts, we process the contact details of the people designated by our customers and partners, as well as data that appears in transport and accounting documents (for example names, signatures, phone numbers and vehicle registration numbers).
2.3. When you visit the website
The website does not use cookies, forms, analytics tools, tracking pixels or embedded third-party content (maps, videos, social media). Fonts and images are hosted on the same server as the website.
The website is hosted on Google’s Firebase Hosting service. Like any web server, the hosting provider’s server may automatically record technical logs containing data such as your IP address, the date and time of access, the requested page and your browser type. This data is needed to deliver the pages and keep the website secure. It is not used to identify you or to build a profile.
3. Why we process data and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Replying to your enquiries and sending quotes | Art. 6(1)(b) – steps taken at your request before entering into a contract; Art. 6(1)(f) – our legitimate interest in replying to messages we receive |
| Concluding and performing transport contracts | Art. 6(1)(b) – performance of a contract; Art. 6(1)(f) – for contact persons of customers and partners |
| Complying with legal obligations (accounting, tax, transport documents) | Art. 6(1)(c) – legal obligation |
| Operating and securing the website (server logs) | Art. 6(1)(f) – our legitimate interest in running the website securely |
| Establishing, exercising or defending legal claims | Art. 6(1)(f) – legitimate interest |
We do not use your data for direct marketing, we do not make decisions based solely on automated processing and we do not create profiles.
4. How long we keep data
- Correspondence and quotes not followed by a contract: up to 1 year after the last contact.
- Contract, transport and accounting documents: for the duration of the contract and afterwards for the periods required by accounting and tax law (currently, as a rule, 5 years for supporting documents and 10 years for accounting registers).
- Server logs: for the short period set by the hosting provider, strictly as needed to run and secure the website.
When these periods expire, the data is deleted or anonymised.
5. Who we share data with
We do not sell or rent your data. We may share it, only as far as necessary, with:
- our IT service providers, mainly Google (Firebase Hosting for the website and Gmail for email);
- our accountant or accounting firm;
- partners involved in performing a shipment (shippers, consignees, loading and unloading points, any subcontracted carriers);
- insurers, in the event of an insured incident;
- legal advisers, courts and public authorities, where required by law or to defend our rights.
Providers that process data on our behalf do so under a contract, only on our instructions and with appropriate security measures.
6. Transfers outside the European Economic Area
We use Google services (Firebase Hosting and Gmail), which may process data outside the European Economic Area, including in the United States. In that case, the transfer relies on the European Commission’s adequacy decision on the EU-US Data Privacy Framework and/or the Standard Contractual Clauses approved by the Commission (Articles 45 – 46 GDPR). Any other transfer outside the EEA only takes place with similar safeguards.
7. Your rights
Regarding your personal data, you have the right to:
- access – find out whether we process data about you and receive a copy (Art. 15);
- rectification – have inaccurate data corrected or incomplete data completed (Art. 16);
- erasure – have your data deleted, under the conditions set by law (Art. 17);
- restriction of processing (Art. 18);
- data portability – receive your data in a structured format or have it sent to another controller (Art. 20);
- object – to processing based on our legitimate interest (Art. 21);
- not be subject to a decision based solely on automated processing (Art. 22).
To exercise your rights, write to us at todymady@gmail.com. We will reply without undue delay and within one month of receiving your request. This period may be extended by two further months for complex or numerous requests, in which case we will let you know. Exercising your rights is free of charge. We may ask for additional information to confirm your identity.
8. Right to lodge a complaint
If you believe we process your data unlawfully, please contact us first so we can try to resolve the issue. You always have the right to lodge a complaint with the supervisory authority:
National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru nr. 28 – 30, Sector 1, postal code 010336, Bucharest, Romania
Email: anspdcp@dataprotection.ro
Web: www.dataprotection.ro
You may also complain to the supervisory authority in the EU Member State where you live or work, or where the alleged infringement took place.
9. How we protect data
We use appropriate technical and organisational measures to protect data against unauthorised access, loss or destruction: an encrypted connection (HTTPS) for the website, access to data limited to people who need it, and protected accounts and passwords.
10. Changes to this policy
We may update this policy when the way we process data or the law changes. The version in force is always the one published on this page, with the last-updated date shown above.
See also our Cookie Policy and Terms & Conditions.