Privacy policy

1. Who We Are and Who This Policy Applies To

This Privacy Policy explains how the operator of the Bonyta.ro online store (“Bonyta”, “we”, “us”) collects, uses, discloses, transfers, and protects the personal data of website visitors, customers, potential customers, and subscribers to marketing communications.

The data controller is:

PINOVA S.R.L.
Registered office: Ilfov County, Voluntari, Strada Erou Iancu Nicolae, No. 12–26, Villa 43
Tax Identification Number (CUI): 52723744
Trade Register No.: J2025079873007
Data protection email: ninutza94@gmail.com
Phone: 0790 662 939

This Policy applies to the Bonyta.ro website, online orders, customer accounts, forms, email/SMS/telephone communications, customer service interactions, and related marketing activities.


2. Our Principles

We:

  • process personal data lawfully, fairly, and transparently;
  • collect only data that is adequate, relevant, and necessary for the stated purposes;
  • retain data only for as long as necessary or required by law;
  • implement reasonable technical and organisational measures to protect personal data;
  • do not sell our customers’ personal data.

3. What Personal Data We Collect

We may collect the following categories of personal data:

Identification Data

  • first name;
  • last name;
  • account name;
  • customer identifiers.

Contact Data

  • email address;
  • telephone number.

Delivery and Billing Data

  • postal address;
  • city;
  • county/district;
  • postal code;
  • country;
  • invoicing details.

Order Data

  • products purchased;
  • order value;
  • discounts;
  • returns;
  • refunds;
  • order history.

Payment Data

  • payment status;
  • payment method;
  • transaction identifiers.

Full payment card details are generally processed by the payment service provider and not directly by Bonyta.

Marketing Data

  • consent status;
  • communication preferences;
  • interactions with newsletters and SMS messages;
  • subscription source.

Technical and Usage Data

  • IP address;
  • device and browser type;
  • pages visited;
  • cookies;
  • online identifiers;
  • conversion events.

Communications

  • messages sent to customer service;
  • requests;
  • complaints;
  • responses and correspondence.

Fraud Prevention and Security Data

  • risk indicators;
  • authentication information;
  • logs;
  • suspicious activity or attempted fraud.

4. How We Obtain Personal Data

We obtain personal data:

  • directly from you when you place an order, create an account, complete a form, subscribe to marketing communications, or contact us;
  • automatically through cookies and similar technologies, depending on your consent preferences;
  • from service providers involved in order fulfilment and payment, such as Shopify, payment processors, courier companies, and fraud prevention tools;
  • from advertising or social media platforms when you interact with our advertisements and the applicable law allows such data transfers.

5. Purposes and Legal Bases for Processing

Purpose Data Used Legal Basis
Processing, confirming, paying for and delivering orders identification, contact, address, order and payment data performance of a contract and pre-contractual steps
Order-related communication and customer support email, phone number, order data and communications performance of a contract and legitimate interest in handling customer requests
Invoicing, accounting and tax obligations identification, billing, order and payment data legal obligation
Returns, refunds, warranties and complaints identification, contact, order and communication data performance of a contract and legal obligation
Fraud prevention and website security technical, payment, order and log data legitimate interest and, where applicable, legal obligations
Newsletters, offers and product launches by email email address, preferences and interactions consent; where permitted by law, the existing-customer exception for similar products, with a clear opt-out option
Promotional SMS messages or calls telephone number, preferences and interactions explicit consent, except where expressly permitted by law
Content personalisation and advertising measurement technical data, cookies and interactions consent for non-essential cookies and technologies; legitimate interest only where legally permitted
Internal analytics and store improvement aggregated, technical, usage and order data legitimate interest and/or consent, depending on the technology used
Protection of legal rights and dispute resolution relevant categories of personal data listed above legitimate interest and legal obligation

6. Data Required for Placing an Order

Your name, contact information, and delivery address are necessary for entering into and performing the sales contract.

If you do not provide this information, we may be unable to process or deliver your order.

Providing data for marketing purposes is optional and is not a condition for making a purchase.


7. Email and Telephone Marketing

We use your email address and/or telephone number for commercial communications only where there is a valid legal basis for doing so.

When consent is used as the legal basis, it must be:

  • freely given;
  • specific;
  • informed;
  • unambiguous;
  • separate from acceptance of the Terms and Conditions.

Consent boxes must not be pre-ticked.

You may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

Each promotional email must include an easy way to unsubscribe.

For SMS marketing, you may follow the unsubscribe instructions included in the message or contact us directly.

We may retain a minimal record of your opt-out request in order to respect your preference and prevent further marketing messages from being sent.

Strictly transactional communications relating to your order, payment, delivery, return, refund, or account security are not considered marketing communications.


8. Who We Share Your Personal Data With

We may disclose personal data only to the extent necessary to the following categories of recipients:

  • Shopify and e-commerce hosting or infrastructure providers;
  • payment processors and financial institutions;
  • courier and logistics providers;
  • email marketing, SMS and consent-management providers;
  • analytics, advertising, security and fraud-prevention providers;
  • accountants, auditors, legal advisers and IT service providers;
  • public authorities, courts or other entities where disclosure is required by law.

The specific list of providers used at the date of publication should be completed as follows:

  • Shopify;
  • [payment processor];
  • [courier(s)];
  • [email/SMS provider];
  • [analytics/advertising provider];
  • [invoicing provider];
  • [other providers].

9. Shopify and International Data Transfers

Our store is hosted on the Shopify platform.

Shopify and its service providers may process personal data within the European Economic Area and in other jurisdictions.

Where personal data is transferred outside the EEA, we will use transfer mechanisms recognised under the GDPR, such as:

  • adequacy decisions;
  • Standard Contractual Clauses;
  • supplementary safeguards, where appropriate.

The specific transfer arrangements must be verified against the agreements and subprocessor lists applicable to the Bonyta Shopify account.


10. How Long We Retain Personal Data

Orders, invoices and accounting documents

Retained in accordance with applicable legal requirements, generally for up to 10 years for relevant financial and accounting documents, unless the law requires a different period.

Customer Account

Retained for as long as the account remains active and for a reasonable period afterwards.

Requests and Complaints

Retained for the duration of the request or complaint and afterwards for as long as necessary to protect our legal rights.

Retention period: [●]

Marketing Consent and Records

Retained until consent is withdrawn or the user unsubscribes, after which a minimal compliance record may be retained to demonstrate compliance.

Retention period: [●]

Cookies and Analytics Data

Retained according to the periods stated in our Cookie Policy and the applicable platform settings.

Fraud Prevention and Security Data

Retained for:

[● retention period]

depending on the relevant risks and service provider requirements.

Once the applicable retention period expires, personal data will be deleted, anonymised, or archived with restricted access, as appropriate.


11. Cookies and Similar Technologies

The website may use:

  • strictly necessary cookies;
  • functional cookies;
  • analytics cookies;
  • marketing cookies.

Non-essential cookies will only be activated after you have expressed your preferences where consent is required by law.

Detailed information regarding cookies should be published in the Cookie Policy and reflected in Shopify’s consent management platform.


12. Your Rights

Under applicable data protection law, you may have the following rights:

  • the right to access your personal data and obtain a copy;
  • the right to rectify inaccurate or incomplete personal data;
  • the right to erasure, where the legal requirements are met;
  • the right to restrict processing;
  • the right to data portability, where applicable;
  • the right to object to processing based on legitimate interest;
  • the right to object at any time to direct marketing;
  • the right to withdraw consent at any time;
  • the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, under the conditions provided by the GDPR;
  • the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP);
  • the right to seek judicial remedies before the competent courts.

To exercise your rights, please send a request to:

ninutza94@gmail.com

We may request reasonable information to verify your identity.

We will generally respond within one month, although this period may be extended in the circumstances permitted by the GDPR.


13. Automated Decision-Making and Profiling

We may use automated tools for:

  • fraud detection;
  • audience segmentation;
  • marketing personalisation.

Where such processing takes place, we will provide any additional information required by law and, where applicable, the possibility to request human intervention.


14. Children’s Personal Data

Bonyta products and services are not intended for the intentional collection of personal data from children.

We do not ask minors to subscribe to marketing communications unless the applicable legal requirements are met.

If we become aware that we have improperly collected personal data relating to a minor, we will take reasonable measures to delete that information.


15. Data Security

We implement measures appropriate to the nature and risk of the processing, including, where applicable:

  • access controls;
  • authentication measures;
  • encryption in transit;
  • backups;
  • security updates;
  • service provider management;
  • incident-response procedures.

However, no method of transmission or storage can guarantee absolute security.


16. Third-Party Links and Services

The website may contain links to or integrations with third-party services.

Where these third parties process personal data as independent data controllers, their own privacy policies apply.

We recommend reviewing the privacy policies of any third-party services you use.


17. Changes to This Privacy Policy

We may update this Privacy Policy to reflect:

  • legislative changes;
  • operational changes;
  • technological developments;
  • changes to the services or tools we use.

The updated version will be published on the website and will indicate the date of the most recent revision.

Where significant changes are made, we may provide additional notice.


18. Contact and Complaints

For questions or requests concerning personal data, please contact:

PINOVA S.R.L.
Ilfov County, Voluntari
Strada Erou Iancu Nicolae, No. 12–26, Villa 43
Email: ninutza94@gmail.com
Phone: 0790 662 939

You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).

The authority’s current official contact details and complaint procedure are available on its official website.