Privacy Policy
Privacy Policy regarding the processing of personal data
BOGAS ensures the right to personal data protection as a fundamental commitment, therefore we will dedicate all resources to process your data in full compliance with Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR"), as well as with any other applicable legislation in Romania. Since one of the essential principles of this legal framework is transparency, we have prepared this document to inform you about how we collect, use, transfer, and protect your personal data when you interact with us regarding our products and services, including through our website or the applications available on your mobile phone.
We reserve the right to periodically update and modify this Privacy Policy to reflect any changes in how we process your personal data or any changes in legal requirements. In the event of any such changes, we will display the modified version of the Privacy Policy on our website, which is why we kindly ask you to check the content of this Privacy Policy regularly.
Who we are and how you can contact us
BOGAS is the trade name of BOGAS SHOP SA., a legal entity of Romanian nationality, having its registered office at Ilfov, Voluntari, Bd-ul Pipera nr. 1/VI, Hyperion, Tower 1, office 3, office 2, floor 3, with registration number in the Trade Register J2015002145408, unique tax registration code RO34142212 (hereinafter referred to as “BOGAS” or “we”). In terms of data protection legislation, we are the operator when we process your personal data.
Since we are always open to hearing your opinions, as well as providing you with any additional information you may need regarding the processing of your data, we encourage you to contact our Data Protection Officer at the email address data.protection@bogas.ro.
What categories of personal data do we process?
In general, we collect your personal data directly from you, so you have control over the type of information you provide us. For example, we receive information from you like this:
When you create a BOGAS account, you provide us with: your email address, first name, and last name;
When you place an order/exchange products, you provide us with information such as: the desired product, your first and last name, delivery address, billing details, payment method, phone number, credit card information, etc.
When you make a return request, please provide us with information such as: your first and last name, the address for picking up the package, refund details, phone number, and bank account.
We can also collect and process certain information about your behavior while visiting our website or using the smartphone app, in order to personalize your online experience and provide you with offers tailored to your profile. We invite you to learn more about this by checking the section below regarding the purposes of processing.
On our website and in the smartphone app, we can store and collect information in cookies and similar technologies, in accordance with the Cookie Policy.
We do not collect or process sensitive data in any other way, as defined by the General Data Protection Regulation, which includes special categories of personal data. Additionally, we do not wish to collect or process data from minors who are under the age of 16.
What are the purposes and grounds for processing
We will use your personal data for the following purposes:
1. For the provision of BOGAS services for your benefit.
This general goal may include, as appropriate, the following:
a) Creating and managing the account within the BOGAS platform;
b) Processing orders, including taking, validating, shipping, and invoicing them;
c) The solution area for cancellations or any issues related to an order, the goods or services purchased;
d) Returning products in accordance with legal provisions;
e) Reimbursement of the value of the products according to legal provisions;
f) Providing support services, including answering your questions regarding your orders or the goods and services of BOGAS or BOGAS Marketplace partners.
Processing your data for these purposes is, in most cases, necessary for the conclusion and execution of a contract between BOGAS and you. Additionally, certain processing related to these purposes is required by applicable legislation, including tax and accounting laws.
2. For improving our services
We always want to provide you with the best online shopping experience. To achieve this, we may collect and use certain information related to your behavior as a Shopper, invite you to complete satisfaction surveys after you finish an order, or conduct market studies and research, either directly or with the help of partners.
We base these activities on our legitimate interest in conducting business, always ensuring that your fundamental rights and freedoms are not affected.
3. For marketing
We want to keep you updated on the best offers for the products/services that interest you. In this regard, we can send you any type of message (such as: email/SMS/phone/mobile push/web push/etc.) containing general and thematic information, information about similar or complementary products to those you have purchased, information about offers or promotions, information regarding products added to the "Account/My Cart" or "Account/Favorites" sections, or that you have shown interest in purchasing, as well as other commercial communications such as market research and opinion surveys, and we can display personalized recommendations on the website and in the smartphone app. To provide you with information that is relevant to you, we may use certain data regarding your shopping behavior (e.g., products viewed/added to wishlist/purchased) to create a profile for you. We always ensure that these processes are carried out with respect for your rights and freedoms and that decisions made based on them do not have legal effects on you and do not significantly affect you in a similar manner.
In most cases, we base our marketing communications on your prior consent. You can change your mind and withdraw your consent at any time by:
– Accessing the unsubscribe link provided in the messages you receive from us; or through
– Contact BOGAS using the contact details described above.
In certain situations, we can base our marketing activities on our legitimate interest in promoting and developing our business. In any situation where we use information about you for our legitimate interest, we take care and implement all necessary measures to ensure that your fundamental rights and freedoms are not affected. However, you can request at any time, through the means described above, that we stop processing your personal data for marketing purposes, and we will comply with your request.
4. For the defense of our legitimate interests
There may be situations where we use or share information to protect our rights and business activities. These may include:
– Measures to protect the BOGAS website and its platform users from cyber attacks:
– Measures for preventing and detecting attempts at fraud, including the transmission of information to the competent public authorities;
- Measures for managing various other risks.
The general basis for these types of processing is our legitimate interest in protecting our business activities, with the understanding that we ensure all measures we take guarantee a balance between our interests and your fundamental rights and freedoms.
Also, in certain cases we base our processing on legal provisions such as the obligation to ensure the security of goods and values as provided by the applicable legislation in this matter.
How long do we keep your personal data
As a general rule, we will store your personal data for as long as you have an account on the BOGAS platform. You can request the deletion of certain information or the closure of your account at any time, and we will comply with these requests, subject to retaining certain information even after the account is closed, in situations where applicable law or our legitimate interests require it.
Who do we share your personal data with?
Depending on the case, we may share or provide access to certain personal data of yours to the following categories of recipients:
– companies within the same group of companies as BOGAS;
– to the partners of BOGAS Marketplace;
- courier service providers;
- payment/banking service providers;
- marketing / telemarketing service providers;
– other companies with which we can develop joint programs to market our goods and services.
In the event that we have a legal obligation or if it's necessary to defend a legitimate interest, we may also disclose certain personal data to public authorities.
We ensure that access to your data by third-party private legal entities is carried out in accordance with legal provisions regarding data protection and information confidentiality, based on contracts concluded with them.
In which countries do we transfer your personal data
Currently, we store and process your personal data on the territory of Romania.
However, it is possible for us to transfer certain personal data of yours to entities located in the European Union or outside the Union, including to countries that the European Commission has not recognized as having an adequate level of personal data protection.
We will always take measures to ensure that any international transfer of personal data is handled carefully to protect your rights and interests. Transfers to service providers and other third parties will always be safeguarded through contractual commitments and, where applicable, through other guarantees, such as the standard contractual clauses issued by the European Commission or certification schemes like the Privacy Shield for the protection of personal data transferred from within the EU to the United States.
You can contact us anytime using the contact details provided above to learn more about the countries where we transfer your data, as well as the safeguards we have put in place regarding these transfers.
How we protect your personal data security
We are committed to ensuring the security of personal data by implementing appropriate technical and organizational measures, in accordance with industry standards.
Your personal data is transmitted using state-of-the-art encryption algorithms, and we store it on secure servers while ensuring data redundancy.
To make payments, we use the services of the payment processor MOBILPAY. Any information regarding payments is encrypted using HTTPS technology with TSL 1.2 encryption.
Despite the measures taken to protect your personal data, we want to draw your attention to the fact that transmitting information over the Internet, in general, or through other public networks, is not completely secure, and there is a risk that your data may be seen and used by unauthorized third parties. We cannot be held responsible for such vulnerabilities in systems that are not under our control.
What rights do you have
The General Data Protection Regulation recognizes a number of rights regarding your personal data. You can request access to your data, correct any mistakes in our files, and/or object to the processing of your personal data. You also have the right to complain to the competent supervisory authority or to seek justice. Depending on the situation, you may also have the right to request the deletion of your personal data, the right to restrict the processing of your data, and the right to data portability.
More information about each of these rights can be obtained by consulting the table presented below.
To exercise your rights, you can contact us using the contact details provided above. Please keep the following points in mind if you wish to exercise these rights:
Identity. We take the confidentiality of all records containing personal data very seriously. For this reason, please send us your requests regarding such records using the email address associated with your BOGAS account. Otherwise, we reserve the right to verify your identity by requesting additional information aimed at confirming your identity.
Fees. We will not charge a fee for exercising any rights regarding your personal data, unless your request for access to information is unfounded, repetitive, or excessive, in which case we will charge a reasonable amount under such circumstances. We will inform you of any applicable fees before we process your request.
Response time. We aim to respond to any valid requests within a maximum of one month, unless it is particularly complicated or if you have made multiple requests, in which case we will respond within a maximum of two months. We will let you know if we need more than a month. We might ask you if you can tell us exactly what you would like to receive or what specifically concerns you. This will help us act faster and shorten the response time to your request.
Third party rights. We do not have to comply with a request if it would negatively affect the rights and freedoms of other individuals involved.
Targeted rights |
Description |
Access |
You can ask us: · to confirm whether we are processing your personal data; · to provide you with a copy of this data; • to provide you with more information about your personal data, such as what data we have, how we use it, to whom we disclose it, whether we transfer it abroad and how we protect it, how long we keep it, what rights you have, how you can make a complaint, where we obtained your data, to the extent that this information has not already been provided to you through this notice. |
Correction |
You can ask us to correct or complete your inaccurate or incomplete personal data. It might be a good idea to try to verify the accuracy of the data before correcting it. |
Data deletion |
You can ask us to delete your personal data, but only if: · these are no longer needed for the purposes for which they were collected; or · you have withdrawn your consent (if the data processing was based on consent); or · exercise a legal right to object; or · these have been processed illegally; or · it is a legal obligation in this regard. We are not obligated to comply with your request to delete your personal data if the processing of your personal data is necessary: · for compliance with a legal obligation; or · for the establishment, exercise, or defense of a right in court. There are certain other circumstances in which we are not obligated to comply with your request for data deletion, although these two are the most likely circumstances under which we could deny this request. Please keep in mind that, before exercising this right, you should download from your BOGAS account and save all documents related to the orders made from BOGAS, regardless of whether the billing was done to you or to another individual or legal entity (such as: invoices, warranty certificates). If you do not take this step before exercising your right to deletion, you will lose all these documents and BOGAS will be unable to provide them to you afterwards, as the data deletion process, including the BOGAS account along with all its related data and documents, is irreversible. |
Data processing restriction |
You can ask us to restrict the processing of personal data, but only in cases where: · their accuracy is disputed (see the correction section), to allow us to verify their accuracy; or · processing is illegal, but you don't want the data to be deleted; or · these are no longer necessary for the purposes for which they were collected, but you need them to establish, exercise, or defend a right in court; or · you have exercised your right to object, and the verification of whether our rights prevail is ongoing. We can continue to use your personal data following a request for restriction if: · we have your consent; or · to establish, exercise, or ensure the defense of a right in court; or · to protect the rights of BOGAS or another individual or legal entity. |
Data portability |
You can ask us to provide your personal data in a structured, commonly used, and machine-readable format, or you can request that it be "ported" directly to another data controller, but in each case only if: · processing is based on your consent or on the conclusion or execution of a contract with you; and · processing is done using automated means. |
The Opposition |
You can object at any time, for reasons related to your particular situation, to the processing of your personal data based on our legitimate interest, if you believe that your fundamental rights and freedoms outweigh this interest. You can also object at any time to the processing of your data for direct marketing purposes (including profiling), without having to provide any reason, in which case we will stop this processing as soon as possible. |
Automated decision making |
You can request not to be subject to a decision based solely on automated processing, but only when that decision: produces legal effects concerning you; or affects you in a similar way and to a significant extent. This right does not apply in cases where the decision reached as a result of automated decision-making: is necessary for us to enter into or execute a contract with you; is authorized by law and there are adequate safeguards for your rights and freedoms; or is based on your explicit consent. |
Complaints |
You have the right to file a complaint with the supervisory authority regarding the processing of your personal data. In Romania, the contact details of the data protection supervisory authority are as follows: National Authority for the Supervision of Personal Data Processing G-ral. Gheorghe Magheru Blvd. no. 28-30, Sector 1, postal code 010336, Bucharest, Romania Phone: +40.318.059.211 or +40.318.059.212; E-mail:anspdcp@dataprotection.ro Without affecting your right to contact the supervisory authority at any time, please reach out to us in advance, and we promise that we will make every effort necessary to resolve any issue amicably. |
- We remind you that you can contact the BOGAS Data Protection Officer at any time by sending your request through any of the following methods:
– by email at the address: data.protection@bogas.ro BOGAS