Skip to content
RONPAY

Privacy Policy

Home / Privacy Policy

This is a translation for information purposes. The Romanian version of this document is the official one and prevails in case of any discrepancy.

1. The data controller

Nedermann Financial Services SRL

Registered office: Bulevardul Eroilor, No. 42, Floor 1, Apt. 9, Cluj-Napoca, Romania

Tax identification code: RO54642492

Email: info@ronpay.ro

2. Data Protection Officer (DPO)

Nedermann Financial Services SRL has not currently appointed a DPO, as the conditions that would require such an appointment under Article 37 GDPR are not met.

For any matter concerning the processing of personal data, you can contact the data controller using the contact details above.

3. Categories of personal data processed

Ordinary data: identification, contact, company, contractual and payment-related data (through certified external processors), as well as browsing data.

Special categories of data: processed only to the extent strictly necessary and with explicit consent (Article 9 GDPR).

4. Purposes and legal basis of processing

Contractual purposes: performance of a contract / provision of services (Article 6(1)(b) GDPR) — providing the data is mandatory.

Legal purposes: compliance with legal obligations (Article 6(1)(c) GDPR) — providing the data is mandatory.

Direct marketing: commercial communications/newsletters (legitimate interest for existing customers; consent for new contacts) — you may object at any time.

Profiling and analysis: personalisation of services/market research (consent — Article 6(1)(a) GDPR) — optional.

Security: protecting systems/preventing fraud (legitimate interest — Article 6(1)(f) GDPR).

5. Methods of processing

Processing is carried out by electronic means and, where necessary, on paper, with appropriate security measures under Article 32 GDPR (pseudonymisation/encryption, integrity, availability, resilience, restoration, periodic testing).

6. Data retention period

Contractual and accounting/tax data: 10 years from the end of the relationship (tax/accounting obligations).

Marketing data: 24 months from the last contact for active customers; until consent is withdrawn.

Browsing data: 12 months.

Special categories of data: for the period strictly necessary and, in any case, no longer than until the end of the relationship.

7. Recipients of personal data

Internal recipients: employees/collaborators; directors and shareholders (within the limits of the purposes pursued).

Processors: IT/hosting; banks and intermediaries; consultants; audit/control; couriers; electronic communications service providers.

Recipients provided for by law: judicial authorities/law enforcement bodies; the National Agency for Fiscal Administration (ANAF); supervisory/control bodies; other recipients provided for by law.

The complete list of processors is available at the data controller's registered office.

8. Transfers to third countries

Data is stored on servers located in the European Union. Some processors may be located in third countries.

Transfers take place only on the basis of an adequacy decision or where appropriate safeguards exist (Article 46 GDPR: standard contractual clauses, binding corporate rules, certifications). Information about the safeguards adopted is available on request.

9. Data subject rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), withdrawal of consent and the right to lodge a complaint with the data protection supervisory authority.

10. How to exercise your rights

Email: info@ronpay.ro

Registered office address: Bulevardul Eroilor, No. 42, Floor 1, Apt. 9, Cluj-Napoca, Romania

The request must include your full identification details, an identity document, the right you wish to exercise and, where applicable, an address to which the reply should be sent.

We will respond within 30 days (a period that may be extended by 60 days in complex cases, with appropriate justification).

11. Automated decision-making and profiling

Profiling may be carried out for the purposes of personalising services, targeted marketing communications and analysing preferences and behaviour.

You have the right not to be subject to a decision based solely on automated processing, to obtain meaningful information about the logic involved, to request human intervention, to express your point of view and to contest the decision.

12. Data security

Appropriate technical and organisational measures are in place, including encryption, access/authentication controls, backups and disaster recovery, staff training, periodic audits and incident management.

13. Personal data breach

Where applicable, notification to the data protection supervisory authority will be submitted within 72 hours of becoming aware of the breach; affected data subjects will be informed without undue delay where the risk is high; breaches and remedial measures will be documented.

14. Changes to this privacy notice

This privacy notice may be updated as a result of new legal provisions, changes to processing activities or security improvements.

Significant changes will be communicated at least 30 days in advance, through the website, by email or through the dedicated customer area.

15. Contact and information

Nedermann Financial Services SRL — Bulevardul Eroilor, No. 42, Floor 1, Apt. 9, Cluj-Napoca, Romania

Email: info@ronpay.ro