Privacy Policy
Last updated: January 2025
1. Introduction
Holmara srl ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and protect your information when you visit our website holmara.shop or make purchases from us.
GDPR Compliance: This policy complies with the EU General Data Protection Regulation (GDPR) and Romanian data protection laws.
2. Information We Collect
2.1 Personal Information
We collect the following types of personal information:
Data Type |
Examples |
Purpose |
Legal Basis |
Contact Information |
Name, email, phone, address |
Order processing, delivery |
Contract performance |
Payment Information |
Billing address, payment method |
Transaction processing |
Contract performance |
Technical Data |
IP address, browser type |
Website functionality |
Legitimate interests |
Usage Data |
Pages visited, time spent |
Service improvement |
Legitimate interests |
2.2 Automatically Collected Information
- Device information and browser type
- IP address and location data
- Website usage patterns and preferences
- Cookies and similar tracking technologies
3. How We Use Your Information
3.1 Primary Uses
- Order Processing: Fulfill orders, process payments, arrange delivery
- Customer Service: Respond to inquiries, handle returns and warranties
- Legal Compliance: Meet tax, accounting, and regulatory requirements
- Security: Prevent fraud and ensure website security
3.2 Marketing Communications
With your explicit consent, we may send you:
- Product updates and promotional offers
- Order status and shipping notifications
- Important account or service updates
Opt-out: You can unsubscribe from marketing emails at any time using the unsubscribe link or by contacting us.
4. Information Sharing and Disclosure
4.1 Third-Party Service Providers
We share information only with trusted partners for:
- Payment Processing: Secure payment gateways (PayPal, banks)
- Shipping Partners: Delivery companies for order fulfillment
- Technical Services: Website hosting and security providers
- Analytics: Website performance and user experience analysis
4.2 Legal Requirements
We may disclose information when required by:
- Romanian or EU legal obligations
- Court orders or government requests
- Protection of our rights or others' safety
- Prevention of fraud or illegal activities
No Sale of Data: We never sell your personal information to third parties for marketing purposes.
5. Data Security
5.1 Security Measures
- SSL Encryption: All data transmission is encrypted
- Secure Storage: Personal data stored on protected servers
- Access Controls: Limited employee access on need-to-know basis
- Regular Audits: Periodic security assessments and updates
5.2 Data Breach Protocol
In case of a data breach, we will:
- Notify affected users within 72 hours
- Report to Romanian data protection authorities
- Take immediate steps to secure data
- Provide guidance on protective measures
6. Your GDPR Rights
Right to Access
Request a copy of personal data we hold about you
Article 15 GDPR
Right to Rectification
Correct inaccurate or incomplete personal data
Article 16 GDPR
Right to Erasure
Request deletion of your personal data ("right to be forgotten")
Article 17 GDPR
Right to Restrict Processing
Limit how we use your personal data
Article 18 GDPR
Right to Data Portability
Receive your data in a structured, machine-readable format
Article 20 GDPR
Right to Object
Object to processing for direct marketing or legitimate interests
Article 21 GDPR
Right to Withdraw Consent
Withdraw consent at any time (where applicable)
Article 7(3) GDPR
7. Cookies and Tracking
7.1 Types of Cookies
- Essential Cookies: Required for website functionality
- Performance Cookies: Help us improve website performance
- Functional Cookies: Remember your preferences
- Marketing Cookies: Used for targeted advertising (with consent)
7.2 Cookie Management
You can control cookies through:
- Browser settings (block or delete cookies)
- Our cookie consent banner
- Third-party opt-out tools
8. Data Retention
Data Type |
Retention Period |
Reason |
Order Information |
7 years |
Tax and accounting requirements |
Customer Accounts |
Until account deletion |
Service provision |
Marketing Data |
Until consent withdrawn |
Marketing communications |
Website Analytics |
26 months |
Website improvement |
9. International Data Transfers
Your data is primarily processed within the EU. When we use services outside the EU, we ensure:
- Adequate protection through EU adequacy decisions
- Standard contractual clauses (SCCs)
- Certified data processing agreements
- Your explicit consent where required
10. Children's Privacy
Our services are not intended for children under 16. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. When we make changes:
- We'll update the "Last updated" date
- Notify you of significant changes via email
- Post prominent notices on our website
- Obtain consent for material changes affecting your rights
12. Contact Us
Complaints: If you're not satisfied with our response, you have the right to lodge a complaint with the Romanian National Authority for Personal Data Protection (ANSPDCP).