Privacy policy

Overview

Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, in this document - GDPR, Regulation or RGPD) was adopted by the European Parliament and the Council of the European Union on April 27, 2016, its provisions being directly applicable starting from May 25, 2018. This Regulation expressly repeals Directive 95/46/CE, thus replacing the provisions of Law no. 677/2001 (currently repealed).

The regulation is directly applicable in all member states, protecting the rights of all natural persons on the territory of the European Union. From a material point of view, the Regulation applies to all operators who process personal data. The Regulation does not apply to the processing of personal data concerning legal entities and, in particular, enterprises with legal personality, including the name and type of legal entity and the contact details of the legal entity.

Personal data is defined as any information regarding an identified or identifiable natural person ("data subject"); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more specific elements, specific to his physical, physiological, genetic, psychological, economic, cultural or social identity.

The processing of personal data involves any operation or set of operations performed on data or sets of personal data, with or without the use of automated means, such as collection, registration, organization, structuring, storage, adaptation or modification, extraction , consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction.

Operator identity

Considering article 4 point 7 of the Regulation, which defines the notion of "operator" as the natural or legal person, public authority, agency or other body that, alone or together with others, establishes the purposes and means of personal data processing , the operator that processes personal data through this website is XUX INVESTMENT SRL, based in Sibiu, Strada Tractorului 12, registered at the Commercial Registry Office J32/712/2013, having CUI 32102114, legally represented by Tarnaru Raul-Nicusor, with contact details [email protected], 0371306055.

Collection of personal data

What personal data is collected

The operator of this website collects, stores and processes the following personal data of / about you:

Obtaining Consent

Overview

In order for the processing of personal data to be legal, the GDPR requires that it be carried out on the basis of a legitimate reason, such as the execution or conclusion of a contract, the fulfillment of a legal obligation, or on the basis of the valid consent previously expressed by the data subject. In the latter case, the operator is required to be able to prove that the person in question has given his consent for the respective processing. The consent expressed under the rule of Directive 95/46/EC remains valid if it meets the conditions provided by the GDPR.

Consent must be given through a statement or through an unequivocal action that constitutes a freely expressed, specific, informed and clear manifestation of the data subject's consent to the processing of his personal data. If the data subject's consent is given in the context of a statement, in electronic form or in writing, which also relates to other matters, the request for consent must be presented in a form that clearly differentiates it from the other matters, can be achieved even by ticking a box. In order for the processing of personal data to be legal, the GDPR requires that it be carried out on the basis of a legitimate reason, such as the execution or conclusion of a contract, the fulfillment of a legal obligation, or based on the valid consent previously expressed by the data subject. In the latter case, the operator is required to be able to prove that the person in question has given his consent for the respective processing. The consent expressed under the rule of Directive 95/46/EC remains valid if it meets the conditions provided by the GDPR.

Cookies

Cookies are used on this site. They do not harm your computer and do not contain viruses, but have the role of contributing to an easier, more efficient and safer use of the site. They are small text files that are saved on your computer and are saved by the browser you use.

Many of the cookies used are called "session cookies", which are automatically deleted after visiting this site. Others remain in your computer's memory until you delete them, making it possible for your browser to recognize them on a subsequent visit.

You can configure your browser to inform you about the use of cookies so that you can decide on a case-by-case basis whether to accept or reject a cookie. Alternatively, your browser can be configured to automatically accept cookies under certain conditions or to always reject them, or to automatically delete cookies when you close your browser. Disabling cookies may limit the functionality of this website.

Cookies that are necessary to enable electronic communications or to provide certain functions that you want to use (such as the shopping cart) are stored in accordance with the provisions of art. 6 paragraph 1 lit. f) of the GDPR, according to which the processing is legal only if and to the extent it is necessary for the purposes of the legitimate interests pursued by the operator or a third party. Therefore, the operator of this website has a legitimate interest in storing certain cookies, to ensure an optimization without technical errors. Other cookies (such as, for example, those used to analyze your browsing behavior) are also stored and will be treated separately in this document.

Server log files

The provider of this website automatically collects and stores the information that your browser automatically transmits to us through log files. These are:

The legal basis for the processing of such data is represented by art. 6 para. 1 lit. b) GDPR, which allows data processing when it is necessary for the execution of a contract to which the data subject is a party or to take steps, at the request of the data subject, before concluding a contract.

Contact form

If you send us questions via the contact form, we will collect the data entered in the form, including the contact data you provide, in order to answer your and others' subsequent questions. We do not transmit this information without your permission. Therefore, we will process all the data you enter in the contact form only with your consent [in accordance with the provisions of art. 6 para. 1 lit. a) GDPR1]. You can revoke your consent at any time, an informal email to this effect is sufficient. Data processed before receiving your request may be processed lawfully. We will keep the data you provide on the contact form until:

Any mandatory legal provisions, in particular those relating to mandatory data retention periods, are not affected by the above.

Contact by e-mail, phone or fax

If you contact us by e-mail, telephone or fax, your request, including all the personal data you will provide, will be stored and processed by us for the purpose of solving your request, based on your consent.

Therefore, we will process all the data you provide based on the following legal provisions contained in the GDPR, respectively:

We will keep the data you provide in this way until:

Registration on the website

You can register on this website to access additional functions and services offered by our company. In this sense, the data entered by you will be used and processed for the purpose of using the respective service or functions for which you have registered. The mandatory data requested during registration must be provided by you in full, otherwise the registration operation will be rejected.

To inform you about important changes, such as those in the scope of our site or about technical changes, we will use the email address you specified at the time of registration.

The processing of personal data, provided in the registration procedure, is done only with your consent and in compliance with the provisions of art. 6 para. 1 lit. a) GDPR. You can revoke your consent at any time, an informal email to this effect is sufficient. We will continue to store the data collected during registration for as long as you remain registered on this website, but the mandatory storage periods remain valid and will be respected.

Login via Facebook

If you do not want to register directly on this site, you can connect via Facebook (Connect). This service is provided by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland.

To log in using Facebook, press "Login with facebook" or "Connect with Facebook" and you will be automatically redirected to this platform, where you will be asked for your username and password details and thus you will connect to this website with your profile by Facebook. In this way, we will have access to all the data stored on Facebook, for example (and not limited to):

This data will be used to create and customize your account on this website.

For more information, you can access the Facebook Terms and Conditions, as well as the Privacy Policy, available at https://www.facebook.com/privacy and https://www.facebook.com/legal/terms.

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the Privacy Shield EU – US does not have an appropriate character.


Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of standard contractual clauses for data transfers from EU data controllers to data controllers established outside the EU or the European Economic Area (EEA). It also issued a set of contractual clauses for data transfers from EU operators to processors established outside the EU or EEA. For more information on these Clauses, we recommend accessinghttps://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.

Facebook uses Standard Contractual Clauses as an adequate data protection guarantee, in accordance with the level of protection guaranteed by the GDPR.

For more details, go to: https://www.facebook.com/legal/EU_data_transfer_addendum

Comments section

By accessing the Comments section, certain personal data (such as, but not limited to, email address, username, IP address) will be processed and stored, some of them being necessary from the perspective of preventing illegal actions or defamatory content.

EThere is also the possibility to sign up/subscribe to this site in order to receive the comments via the provided email, so that:

The purpose of processing the collected data

Part of the data collected on this site is used to:



The processing of personal data is carried out in accordance with the provisions of the General Regulation on Data Protection, based on both the consent of the data subject and reasons for the compliant execution of contracts or the realization of the legitimate interests of the operator (unless the interests prevail or the fundamental rights and freedoms of the data subject, which require the protection of personal data, especially when the data subject is a child).

User rights

Your rights regarding personal data and the means of exercising them are: The right to information, The right to access, The right to rectification, The right to delete data, The right to restrict processing, The right to data portability, The right to opposition, The right not to is the subject of a decision based exclusively on automatic data processing, Right to lodge a complaint and address to the courts, Right to withdraw consent.

Obligations of the data controller

Hosting

Personal data registered on this website are stored on GLOBEHOSTING servers. The processing of the data provided and stored complies with the following legal provisions:

Regardless of the purpose for which personal data is processed, the principles of legality, fairness and transparency are respected, but also that the personal data processed are adequate, relevant and limited to what is necessary in relation to the purposes for which are processed.

For more information on the processing of personal data by GLOBEHOSTING, go to https://www.globehosting.ro/politica-de-confidentialitate.html

We have a contract/a convention/legal act (including the possibility of including and agreeing to the clauses of the Website Terms and Conditions) concluded with GLOBEHOSTING to ensure the processing of personal data in accordance with the legal regulations in the field. We comply with our obligations according to Article 28 of the GDPR, by choosing an external service provider that offers sufficient guarantees for the implementation of appropriate technical and organizational measures, so that the processing complies with the requirements set out in the regulation and ensures the protection of your rights.

Data encryption

This site uses SSL encryption for security reasons and to protect the transmission of confidential information. This encryption can be recognized by you by the lock window ("lock icon") that appears in the browser bar and by changing the address of the respective browser from http:// to https://. Once encryption of this type is activated, the transmitted or transferred data will not be able to be seen by third parties.

According to the GDPR, if the breach of the security of personal data is likely to generate a high risk for your rights and freedoms, the operator of this website will inform you, without undue delay, about this breach, unless the supplementary provisions become incident from the same Regulation (art. 34 paragraph 3).

The data protection officer

As the provisions of the GDPR are not applicable (art. 37 paragraph 1 - according to which the Operator and the person authorized by the operator appoint a data protection officer whenever:

  1. the processing is carried out by a public authority or body, with the exception of courts acting in the exercise of their jurisdictional function;
  2. the main activities of the operator or the person authorized by the operator consist of processing operations which, by their nature, scope and/or purposes, require a periodic and systematic monitoring of the persons concerned on a large scale; or
  3. the main activities of the operator or the person authorized by the operator consist in the large-scale processing of special categories of data pursuant to Article 9 or of personal data relating to criminal convictions and offences, referred to in Article 10)

Regarding the obligation to appoint a Data Protection Officer, for any information or clarifications regarding the operation of this website, please contact us on the following dates:

Records of processing activities

According to the GDPR Regulation, the operator or the person authorized by the operator should keep, for a reasonable period, records of the processing activities under his responsibility. Thus, these records will include all the following information:

The obligation detailed above does not apply to an enterprise or organization with less than 250 employees, unless the processing it carries out is likely to generate a risk for the rights and freedoms of the data subjects, the processing is not occasional or the processing includes special categories of data or personal data relating to criminal convictions and offences.

Adequate technical and organizational measures

Taking into account the current state of technology, the context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, the operator implements appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for each specific purpose of the processing.

Notification of the supervisory authority in case of personal data security breach

According to art. 33 para. 1 of the GDPR, if there is a breach of personal data security, we will notify the National Authority for the Supervision of the Processing of Personal Data without undue delay and, if possible, within 72 hours at most from the date we became aware of it, unless it is unlikely to generate a risk for the rights and freedoms of natural persons.

Informing the data subject about the data security breach of personal data

Related to the provisions of art. 34 of the GDPR, if the breach of the security of personal data is likely to generate a high risk for the rights and freedoms of natural persons, we will inform the data subject without undue delay about this breach, except in situations where:

Social Media

Facebook plugins (Like & Share Button)

This service uses social plugins ("plugins") managed by the social network facebook.com. Plugins can be identified by a Facebook logo (a white "f" on a blue board or a "thumbs up" sign) or are labeled by adding the phrase "Facebook Social Plugin". The list and layout of Facebook plugins can be seen here:  https://developers.facebook.com/docs/plugins/.  As long as you use the Like extension, you will like our website's Facebook page without having to leave it. To the extent that you use the Share extension, you will share our site or certain content from it on your personal Facebook page without having to leave the site.  

Through the plugin, Facebook receives the information that you access on our website. If you are also logged in to Facebook at the same time, Facebook can attribute the actions taken on the page to your account and, implicitly, to you personally. When you interact with the plugins, for example by clicking the Like button or sharing certain content from the website, the corresponding information is transferred directly from your browser to Facebook and stored there. Even if you are not a Facebook member, it is still possible for the social network to obtain and store your IP address.  

By clicking on one of these buttons, you agree to the use of this plugin and therefore to the transfer of personal data to Facebook. We have no control over the nature and purpose of this transmitted data, as well as over its subsequent processing. Regarding the purpose and extent of data collection, processing and further use of data by Facebook, as well as permissions and settings to protect privacy.

If you do not want Facebook to associate your visit to this website with your Facebook account information, you can log out.

Instagram Plugin

This service uses social plugins ("plugins") managed by the Instagram social network, functions provided by Instagram Inc., with headquarters at 1601 Willow Road, Menlo Park, CA 94025, USA. Plugins can be identified by an Instagram logo or are labeled by adding the phrase "Instagram Social Plugin".  

Via the plugin, Instagram is informed about the actions you take on our page. If you are also connected to your personal account on the social network at the same time, it can attribute the actions taken on your Instagram account page and, implicitly, to you personally. When you access the plugins, the corresponding information is transferred from your browser to the social network and stored there. Even if you are not a member of Instagram, it is still possible for it to obtain and store your IP address.  

By clicking on one of these buttons, you agree to the use of this plugin and therefore to the transfer of personal data to Instagram. We have no control over the nature and purpose of this transmitted data, as well as over its subsequent processing. Regarding the purpose and scope of data collection, processing and further use of data by Instagram, as well as permissions and settings to protect user privacy, you can consult Instagram's privacy policies at: https://help.instagram.com/155833707900388

If you are a member of Instagram and do not want it to collect your data through the plugin and link it to the data already stored on Instagram, you must log out of the social network before visiting this site.

Google+ plugin

This service uses social plugins ("plugins") managed by the social network Google+. Plugins can be identified by a Google+ logo.  

Through the plugin, Google receives the information that you access on our page. If you are also connected to the social network at the same time, Google can assign the actions performed on the page to your Google+ account and, implicitly, to you personally. When you interact with the plugins, the corresponding information is transferred directly from your browser to Google+ and stored there. Even if you are not a member of Google+, it is still possible for it to obtain and store your IP address.  

By clicking on one of the plugin buttons, you can express your consent to their use and therefore to the transfer of personal data to Google+. We have no control over the nature and purpose of this transmitted data, as well as over their subsequent processing. Regarding the purpose and extent of data collection, processing and further use of data by Google+, as well as permissions and settings to protect user privacy, you can consult the Google+ privacy policies at: https://policies.google.com/privacy?hl=en

If you are a member of Google+ and do not want it to collect your data through the plugin and link it to the data already stored on Google+, you must log out of the social network before visiting the site.

Newsletter

To receive a newsletter, it is necessary to indicate a valid e-mail address, along with specific information that can identify the owner of this address. Also, your consent is required for sending the newsletter and, therefore, we inform you that any other personal data will be collected and stored only based on your consent. The data thus collected are processed only for the purpose of sending the newsletter and will not be transmitted to third parties.

Therefore, we will process any data you enter in the contact form only with your consent, in accordance with the provisions of art. 6 para. 1 lit. of the GDPR.  

Plugins and Tools

Youtube

Our website uses plugins of the YouTube platform, which is operated by Google. The operator of the website is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA.

If you visit a page on our website where a YouTube plug-in has been integrated, a connection to the YouTube servers will be established. Consequently, the YouTube server will be notified, which of the pages have been visited by you.

In addition, YouTube will be able to insert different cookies, with the help of which it will be possible to obtain information about the visitors of our website. Among other things, this information will be used to generate video statistics with the aim of improving the ease of use of the site and preventing fraud attempts.  

If you are signed in to your YouTube account while visiting our website, you allow YouTube to directly assign your browsing patterns to your personal profile. You have the option to prevent this by signing out of your YouTube account.

The use of YouTube is based on our interest in presenting online content to you in an attractive manner. According to art. 6 para. 1 lit. f) GDPR, this is a legitimate interest.

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the EU – US Privacy Shield (Privacy Shield) does not have an appropriate character. Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) should be based on the Standard Contractual Clauses (SCC) of the European Commission.

For more information on how YouTube handles user data, see YouTube's Data Privacy Policy at:  https://policies.google.com/privacy?hl=en.

Vimeo

Our website uses plugins of the video portal Vimeo. The provider is Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

If you visit one of the pages on our website where a Vimeo plug-in has been integrated, a connection to the Vimeo servers will be established. Consequently, the Vimeo server will receive information about the pages you have visited. In addition, Vimeo will receive the IP address. This will also happen if you are not signed in to Vimeo or do not have a Vimeo account. The information recorded by Vimeo will be transmitted to the Vimeo server in the United States.

If you are signed in to your Vimeo account, you allow Vimeo to directly assign your browsing patterns to your personal profile. You can prevent this by signing out of your Vimeo account.

The use of Vimeo is based on our interest in presenting your online content in an attractive manner. According to art. 6 para. 1 lit. f) GDPR, this is a legitimate interest

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the EU – US Privacy Shield (Privacy Shield) does not have an appropriate character.

Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from EU data controllers to data controllers established outside the EU or the European Economic Area (EEA). It also issued a set of contractual clauses for data transfers from EU operators to processors established outside the EU or EEA. For more information on these Clauses, we recommend accessing https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro

Vimeo uses Standard Contractual Clauses as an adequate data protection guarantee, in accordance with the level of protection guaranteed by the GDPR. For more information, go to https://www.activecampaign.com/legal/scc and the full privacy policy available here: https://vimeo.com/privacy.

Google Web Fonts

This site uses Web Fonts provided by Google to ensure consistent use of fonts on this site. 

When you access a page on this website, your browser will load, as a result of establishing a connection with Google's servers, the web fonts necessary for the correct display of text and fonts. So,  

The use of Google Web Fonts is based on Art. 6 para. 1 lit. f) GDPR, there is a legitimate interest in the uniform presentation of the font on this website. If there is a consent expressed in this regard (for example, consent to the archiving of cookies), the data will be processed exclusively on the basis of art. 6 para. 1 lit. a) GDPR.

For more information on how Google Web Fonts handles user data, see the Privacy Policy available at: https://policies.google.com/privacy?hl=en.

Google Maps

This site uses Google Maps, a mapping and location service, through an API. The provider is Google Inc., 1600 Amphitheater Parkway Mountain View, CA 94043, United States of America.

To guarantee data protection on our website, you will find that Google Maps has been disabled when you visit our website for the first time. A direct connection to the Google servers will not be established before the autonomous activation of Google Maps, i.e. with your consent in accordance with Article 6 para. 1 lit. a) GDPR. This will prevent the transfer of data to Google during the first visit to our website. After you have activated the service, Google Maps will store your IP address. As a rule, it is then transferred to a Google server in the United States, where it is stored. The provider of this website has no control over this data transfer once Google Maps has been activated.

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the EU – US Privacy Shield (Privacy Shield) does not have an appropriate character.

Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from EU data controllers to data controllers established outside the EU or the European Economic Area (EEA). It also issued a set of contractual clauses for data transfers from EU operators to processors established outside the EU or EEA. For more information on these Clauses, we recommend accessing https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro

Google Maps uses Standard Contractual Clauses as an adequate data protection guarantee, in accordance with the level of protection guaranteed by the GDPR. For more information, see Google's Data Privacy Statement at the following address: https://policies.google.com/privacy

Google reCaptcha

We use "Google reCAPTCHA" (hereinafter referred to as "reCAPTCHA") on our website. The provider is Google Inc., located at 1600 Amphitheater Parkway, Mountain View, CA 94043, USA ("Google"). The purpose of reCAPTCHA is to determine whether data entered on our site (for example, information entered in a contact form) is provided by a human user or an automated program. To determine this, reCAPTCHA analyzes the behavior of website visitors based on a variety of parameters. This analysis is automatically triggered as soon as the website visitor enters the website. For this analysis, reCAPTCHA evaluates a variety of data (eg IP address, time the website visitor spent on the website or user-initiated cursor movements). The data tracked during these analyzes is sent to Google. reCAPTCHA analyzes run entirely in the background. Site visitors are not alerted that an analysis is in progress. The data are processed based on art. 6 para. 1 lit. f) GDPR. Website operators have a legitimate interest in protecting the operator's web content against misuse by automated industrial espionage systems and against SPAM.  

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the EU – US Privacy Shield (Privacy Shield) does not have an appropriate character.

Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from EU data controllers to data controllers established outside the EU or the European Economic Area (EEA). It also issued a set of contractual clauses for data transfers from EU operators to processors established outside the EU or EEA. For more information on these Clauses, we recommend accessing https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro

Google reCatpcha uses Standard Contractual Clauses as an adequate data protection guarantee, in accordance with the level of protection guaranteed by the GDPR. For more information, see Google's Data Privacy Statement available here: https://policies.google.com/privacy  and here: https://policies.google.com/terms?hl=en

Chat Online

Online Chat Platform

Facebook Messenger

On this website we use Facebook Messenger, a free instant messaging application, thus ensuring the instant exchange of text messages with one or even more people or computers at once. It is an American messaging app and platform developed by Facebook, Inc. Originally developed as Facebook Chat in 2008, the company revamped its messaging service in 2010.

Through Facebook Messenger, we can provide you with fast support by allowing you to interact with us, including by tracking purchases, receiving notifications and initiating personal conversations with the company's customer service representatives.

The legal basis for the processing of personal data through Facebook Messenger is represented by art. 6 para. 1 lit. f) of the Regulation, based on our legitimate interest in the legality of the processing. In relation to the processing of personal data, Facebook Ireland can be contacted online or by post at the following address Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland.

The data collected through Facebook Messenger is used, among other things, to provide, personalize and improve the chat, to enable the provision of analysis services, but also to communicate with you.  

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the EU – US Privacy Shield (Privacy Shield) does not have an appropriate character.

Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from EU data controllers to data controllers established outside the EU or the European Economic Area (EEA). It also issued a set of contractual clauses for data transfers from EU operators to processors established outside the EU or EEA. For more information on these Clauses, we recommend accessing https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro

Facebook Messenger complies with the provisions of the GDPR and the Standard Contractual Clauses (SSC) approved by the European Commission, constantly taking into account its decisions regarding data transfers to the United States and other countries. The European Commission has recognized countries such as Andorra, Argentina, Canada (trade organisations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland and Uruguay as providing adequate protection.  

More information is available here https://www.facebook.com/privacy/explanation and here  https://www.facebook.com/legal/EU_data_transfer_addendum

WhatsApp

Through WhatsApp, we ensure effective communication with our customers. For those who live in a country in the European Economic Area (which includes the European Union) and any other country or territory included (collectively the "European Region"), Whatsapp is operated by WhatsApp Ireland Limited, based at 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.

According to the WhatsApp policy, which can be consulted and analyzed here: https://www.whatsapp.com/legal/#privacy-policy, Whatsapp Ltd. being part of the Facebook Companies, through this service personal data is collected and processed personally in compliance with the security and privacy principles applicable at European level (in particular, RGPD) or at international level (if we are talking about services provided by Whatsapp Inc. – EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework).

Through Whastapp, the following are processed:

The legal basis for the processing of personal data through Whatsapp is represented by art. 6 lit. f) of the Regulation, based on our legitimate interest in the legality of the processing.

Considering the Judgment of July 16, 2020 (pronounced in case C-311/18 – Data Protection Commissioner/Facebook Ireland Limited, Maximillian Schrems) , the European Court of Justice ruled that the protection offered by the EU – US Privacy Shield (Privacy Shield) does not have an appropriate character.

Therefore, the transmission of personal data to the USA and other countries outside the European Economic Area (EEA) is based on the Standard Contractual Clauses (SCC) of the European Commission. The Commission has issued two sets of Standard Contractual Clauses for data transfers from EU data controllers to data controllers established outside the EU or the European Economic Area (EEA). It also issued a set of contractual clauses for data transfers from EU operators to processors established outside the EU or EEA. For more information on these Clauses, we recommend accessing https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_ro.

WhatsApp uses Standard Contractual Clauses as an adequate data protection guarantee, in accordance with the level of protection guaranteed by the GDPR, according to the information available here https://www.whatsapp.com/legal/#privacy-policy-our-global-operations

Conclusion

This policy regarding the processing of personal data is generated in accordance with the provisions of Regulation no. 679/2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, but also with the other applicable national legal provisions.

We reserve the right to make any additions or changes to this policy. We recommend consulting the Policy regularly for correct and up-to-date information regarding the processing of personal data.

For more details regarding this GDPR Policy, as well as to exercise any of the aforementioned rights, a written notification can be sent to the contact details indicated above.