SEISHINDO · LEGAL INFORMATION
Privacy notice
How Seishin Do SRL processes personal data in connection with the seishindo.ro online store.
1. Controller
Seishin Do SRL, Str. Garoafei nr. 30, 520067 Sfântu Gheorghe, Covasna County, Romania; CUI 33986019; J14/10/2015; info@seishindo.ro; +40 742 880 888.
2. Data and purposes
Depending on the features used, we may process name, email, phone, billing/delivery addresses, tax details, ordered items, amounts and status, payment technical identifiers (not full card data), support correspondence, withdrawal/return/warranty/complaint data, account details, IP/security logs, cookie choices and, when ordering a personalised gift, the text, name, photograph, artwork or other personalisation content supplied for producing the item, as well as other information supplied voluntarily.
Purposes include contract preparation/performance, ordering, payment, delivery, invoicing, support, returns/warranty/complaints, fraud prevention, legal duties, IT security, and only with consent, marketing and non-essential measurement technologies.
3. Legal bases
GDPR Art. 6(1)(b) for contracts and pre-contract steps; Art. 6(1)(c) for legal duties; Art. 6(1)(f) for legitimate interests such as security, fraud prevention, legal claims and minimal operational logging subject to balancing; Art. 6(1)(a) for consent-based activities.
4. Recipients and processors
Where necessary, data may be shared with hosting/IT providers, payment processors, couriers/logistics, accounting/invoicing providers, email/SMS providers, legal advisers/auditors and competent authorities. Only necessary data is shared. Specific payment and delivery providers are shown in the ordering flow.
5. International transfers
We prefer EU/EEA providers. Transfers outside the EEA occur only with a lawful GDPR Chapter V safeguard, such as an adequacy decision or Standard Contractual Clauses and supplementary measures where required.
6. Retention
Order/invoice data is retained for accounting/tax obligations; contract and legal-claim data until relevant limitation periods expire; support/complaint data as needed for resolution and evidence; account data while the account exists plus mandatory retention; security logs for a limited period; consent-based marketing until consent is withdrawn or the purpose ends. A specific statutory period prevails where applicable.
7. Data-subject rights
Subject to the GDPR, you may request access, rectification, erasure, restriction, portability and object to legitimate-interest processing. Consent may be withdrawn at any time without affecting prior lawfulness. Direct marketing can be opposed at any time. Requests: info@seishindo.ro.
8. Supervisory complaint
You may complain to Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP), Bd. G-ral Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, www.dataprotection.ro, anspdcp@dataprotection.ro.
9. Automated decisions
The current core store does not use solely automated decisions producing legal or similarly significant effects within GDPR Art. 22. Relevant future use will be separately disclosed.
10. Security
We use access control, HTTPS, logging, security updates, permission management and data minimisation. Absolute security cannot be guaranteed, but risk-appropriate technical and organisational measures are maintained.
11. Children
The store is not designed as a child-directed data-collection service. Where a future feature requires parental consent or other special conditions, those will be implemented before activation.