Privacy Policy

Last updated: 20 July 2026


1. General information

The protection of your personal data is important to us. This Privacy Policy explains how we collect, use, store and protect personal data when you use the website proflex-tech.ro, contact us or request information, products or services.

The personal data controller is:

PROFLEX AUTOMOTIVE SRL
Tax ID: 34492005
Trade Registry No.: J2015000475266
EUID: ROONRC.J2015000475266
Registered office: Str. Ierbușului no. 38/B, Reghin, Mureș County, postal code 545300, Romania
E-mail: oddice@proflex-tech.ro

For the purposes of this policy, PROFLEX AUTOMOTIVE SRL may be referred to as “PROFLEX”, the “Company”, the “Controller”, “we”, “us” or “our”.


2. Applicable legal framework

The processing of personal data is carried out in accordance with applicable legislation, including:

  • Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, hereinafter referred to as the “GDPR”;
  • Law no. 190/2018 on measures for implementing the GDPR;
  • Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector;
  • any other legal acts applicable to the Company’s activity.


3. Who this policy applies to

This Privacy Policy applies to natural persons whose data is processed by the Company, including:

  • visitors to the Website;
  • persons who complete contact or quotation request forms;
  • customers and potential customers;
  • representatives, employees and contact persons of corporate customers;
  • representatives of suppliers, distributors, manufacturers and contractual partners;
  • persons who communicate with us by e-mail, telephone or other channels;
  • persons who submit a CV or an enquiry regarding a possible professional collaboration;
  • participants in meetings, presentations, events or technical demonstrations;
  • subscribers to commercial communications, where such an option is available.


4. What personal data means

Personal data means any information relating to an identified or identifiable natural person.

A person may be identified directly or indirectly through elements such as name, contact details, professional position, online identifiers, location data or other information specific to that person’s identity.

Information that relates exclusively to a legal entity does not, in principle, constitute personal data. However, information regarding the representatives, directors, employees or contact persons of a company constitutes personal data.


5. Personal data we may collect


5.1. Identification and contact data

  • first name and last name;
  • professional role or position;
  • name of the represented company;
  • e-mail address;
  • telephone number;
  • postal address or delivery address;
  • signature, when required in contractual documents.


5.2. Data relating to requests and communications

  • the content of messages sent through the contact form;
  • requests for quotation;
  • correspondence history;
  • information communicated by telephone;
  • preferences regarding the requested products or services;
  • notifications, complaints and support requests.


5.3. Technical data and project information

Depending on the nature of the request, we may receive documents and information relating to a technical project, such as:

  • technical specifications;
  • drawings, sketches and plans;
  • photographs and video materials;
  • information about equipment and installations;
  • data regarding the project location;
  • contact details of the persons responsible for the project;
  • information regarding site access and work organisation.

Please do not include personal data in the submitted documentation unless such data is necessary for analysing your request.


5.4. Contractual and financial-accounting data

  • data of the legal representative or contact person;
  • data included in offers, orders and contracts;
  • data required for invoicing and making payments;
  • information regarding deliveries, installations and acceptances;
  • commercial and contractual history;
  • data regarding warranties and maintenance services.

We do not usually collect or store full bank card details. If payment services provided by third parties are used, payment data is processed according to the rules of the respective provider.


5.5. Technical data collected when using the Website

When you access the Website, certain information may be collected automatically, such as:

  • IP address;
  • device type;
  • browser type and version;
  • operating system;
  • date and time of access;
  • pages visited;
  • the page from which you reached the Website;
  • information regarding Website errors and security;
  • online identifiers and information collected through cookies.


5.6. Data for commercial communications

If you subscribe or request to receive commercial communications, we may process:

  • first name and last name;
  • e-mail address;
  • telephone number, if applicable;
  • company and professional role;
  • communication preferences;
  • the date and manner in which consent was expressed.


5.7. Recruitment-related data

If you send us a CV or request a professional collaboration, we may process information such as:

  • first name and last name;
  • contact details;
  • education and qualifications;
  • professional experience;
  • skills and certifications;
  • other information voluntarily included in the CV or message.


6. Data we ask you not to send us

We do not usually request the submission through the Website of special categories of personal data, such as information regarding:

  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic or biometric data;
  • health status;
  • sex life or sexual orientation;
  • criminal convictions and offences.

Please do not include such information in forms, messages, CVs or documents sent to us, unless it is strictly necessary and there is an appropriate legal basis.


7. Sources from which we may obtain data

We may collect personal data:

  • directly from you, through forms, e-mail, telephone, meetings or documents;
  • from the company or organisation you represent;
  • from colleagues, representatives or partners involved in a project;
  • from distributors, manufacturers, suppliers or contractual partners;
  • from public registers and databases;
  • from professional websites, company websites or other public sources;
  • through cookies and similar technologies;
  • from the technical systems used for the security and operation of the Website.

When you provide us with the personal data of another person, you are responsible for ensuring that you have the right to disclose it to us and that the respective person has been properly informed.


8. Purposes and legal bases of processing

Purpose of processingData usedLegal basis
Receiving and handling contact requestsIdentification data, contact data and message contentSteps taken at the request of the person before entering into a contract and the legitimate interest of responding to requests
Preparing and sending commercial offersContact data, professional information and project dataPre-contractual steps and legitimate interest
Concluding and performing contractsIdentification data, contact data, contractual data and project informationPerformance of the contract or pre-contractual steps
Managing relationships with representatives of corporate customers and partnersName, position, company, contact data and correspondenceThe legitimate interest of carrying out and managing B2B commercial relationships
Delivery, installation, commissioning and maintenance of productsContact data, information regarding location and projectPerformance of the contract and legitimate interest
Invoicing, accounting and fulfilment of tax obligationsContractual and financial-accounting dataFulfilment of legal obligations
Managing complaints, warranties and service requestsIdentification data, contact data, product information and communication historyPerformance of the contract, legal obligation and legitimate interest
Protecting rights and resolving disputesContractual data, correspondence and other relevant informationThe legitimate interest of establishing, exercising or defending a right
Security and operation of the WebsiteIP address, technical logs, device and browser dataThe legitimate interest of protecting the Website, IT systems and processed information
Analysing usage and improving the WebsiteTechnical data and information collected through cookiesConsent, where required, or legitimate interest for strictly necessary information
Sending commercial communicationsName, e-mail address, telephone number, company and preferencesConsent or legitimate interest, in situations permitted by law
Recruitment and assessment of applicationsData included in the CV and in submitted communicationsSteps taken at the request of the candidate and legitimate interest
Complying with requests from authoritiesData lawfully requestedFulfilment of a legal obligation


9. Legitimate interests pursued

When processing is based on legitimate interest, we may pursue interests such as:

  • communicating with potential customers, customers and partners;
  • developing and managing commercial relationships;
  • preparing offers and managing projects;
  • improving products and services;
  • ensuring system security and preventing fraud;
  • protecting the Company’s assets, personnel and information;
  • establishing, exercising or defending the Company’s rights;
  • retaining evidence regarding communications and transactions;
  • promoting services to professional contacts, under the conditions permitted by law.

Before using legitimate interest as a legal basis, we assess whether the interests, rights and freedoms of the data subject override the interest pursued by the Company.


10. Mandatory or optional nature of providing data

Providing the data marked as mandatory in a form is necessary in order to process the respective request.

If you refuse to provide the necessary data, we may not be able to:

  • respond to the request;
  • prepare an offer;
  • conclude or perform a contract;
  • deliver or install a product;
  • provide maintenance or warranty services;
  • comply with certain legal obligations.

Providing data used exclusively for marketing or optional data in forms is not mandatory.


11. To whom we may disclose personal data

Data may be accessed or transmitted, to the extent necessary, to the following categories of recipients:

  • the Company’s authorised employees and collaborators;
  • providers of web hosting, IT maintenance and IT security services;
  • providers of e-mail, storage, communication and document management services;
  • providers of CRM, ERP, invoicing or project management applications;
  • providers of accounting, audit and tax consultancy services;
  • lawyers, consultants and other specialists involved in protecting the Company’s rights;
  • manufacturers, distributors, subcontractors and technical partners involved in a project;
  • providers of transport, courier, installation and service services;
  • banking institutions and payment service providers;
  • public authorities, courts and control bodies, when disclosure is required by law;
  • a potential buyer, investor or successor, in the context of a reorganisation, merger, acquisition or sale of assets, in compliance with legal requirements.

Providers that process data on our behalf have a contractual obligation to use the data only according to the instructions received, to maintain confidentiality and to implement appropriate security measures.


12. Transfer of data to manufacturers and technical partners

In order to prepare a solution, verify product compatibility, obtain a quotation or carry out a project, it may be necessary to transmit certain information to manufacturers, distributors, suppliers or technical partners.

We will transmit only the information necessary for the respective purpose. Where possible, technical documents will be transmitted without personal data that is not relevant.


13. International data transfers

Some of our suppliers or partners may be established outside the European Economic Area or may use technical infrastructure located in other countries.

In the event of an international data transfer, we will use a mechanism permitted by the GDPR, such as:

  • an adequacy decision adopted by the European Commission;
  • standard contractual clauses approved by the European Commission;
  • binding corporate rules;
  • other safeguards or derogations provided by applicable legislation.

You may request additional information about the applicable safeguards by contacting us at oddice@proflex-tech.ro.


14. Data retention period

We retain data only for as long as necessary to fulfil the purposes for which it was collected, in compliance with legal obligations.

As a guideline, we apply the following periods or criteria:

  • General requests and quotation requests: up to 3 years from the last communication, if the request does not lead to the conclusion of a contract;
  • Contractual data: for the duration of the contract and subsequently for the duration of the applicable legal limitation periods;
  • Financial-accounting documents: in principle, 5 years calculated from 1 July of the year following the end of the financial year in which they were prepared, or for a longer period if another legal obligation requires this;
  • Data regarding warranties, equipment and technical interventions: for the relevant lifetime of the product, the warranty, the service contract or for the period necessary to defend a right;
  • Complaints and disputes: until final resolution and expiry of the applicable legal periods;
  • Marketing data: until withdrawal of consent, exercise of the right to object or termination of the purpose for which it was collected;
  • CVs and applications that did not lead to employment: usually no more than 6 months from the completion of the process, unless the person agrees to retention for future opportunities;
  • Technical logs and security data: usually up to 12 months, except where they are required to investigate an incident;
  • Cookies: according to the duration of each cookie, mentioned in the Cookie Policy or in the consent management module.

When determining the retention period, we may take into account the nature of the data, the purpose of processing, legal obligations, existing risks and the need to keep evidence of contractual relationships or communications.


15. Data security

We apply reasonable technical and organisational measures to protect data against:

  • unauthorised access;
  • accidental loss, destruction or damage;
  • unauthorised alteration;
  • unauthorised disclosure;
  • misuse;
  • other forms of unlawful processing.

Measures may include, as appropriate:

  • access control to systems and documents;
  • use of individual accounts and passwords;
  • creation of backups;
  • updating and monitoring systems;
  • use of secure connections;
  • limiting access to data according to responsibilities;
  • confidentiality obligations;
  • procedures for managing security incidents;
  • selecting providers that offer appropriate safeguards.

No method of electronic transmission or storage can guarantee absolute security. If you have reason to believe that your data has been compromised, please contact us immediately.


16. Cookies and similar technologies

The Website may use cookies and similar technologies for:

  • the proper functioning of pages and forms;
  • remembering user preferences;
  • protecting the Website against abuse;
  • analysing traffic and performance;
  • measuring the effectiveness of communications or campaigns;
  • displaying content provided by external platforms.

Strictly necessary cookies may be used without consent when they are indispensable for the functioning of the Website.

Analytics, advertising or personalisation cookies will be used only under the conditions permitted by law and, where required, after obtaining consent.

Details regarding the cookies used and how to change preferences are available in the Cookie Policy and in the consent management module displayed on the Website.


17. Services and content provided by third parties

The Website may integrate services provided by third parties, such as:

  • interactive maps;
  • video materials;
  • traffic analysis tools;
  • security and automated message prevention tools;
  • communication platforms or social networks;
  • external forms or functionalities.

When you access or activate such a service, the third-party provider may collect data about your device and your interaction.

Processing carried out independently by these providers is governed by their own privacy policies.


18. Commercial communications

We may send information regarding PROFLEX products, services, projects or news:

  • based on expressed consent;
  • within an existing commercial relationship, where the law permits;
  • to professional contacts, based on legitimate interest, respecting the right to object.

You may withdraw your consent or object to commercial communications at any time by:

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.


19. Automated decisions and profiling

The Company does not usually use decision-making processes based solely on automated processing that produce legal effects concerning individuals or significantly affect them in a similar way.

If we implement such a process in the future, we will provide the information required by law regarding the logic used, its significance and the envisaged consequences.


20. Your rights

Under the conditions provided by the GDPR, you benefit from the following rights:


20.1. Right to be informed

You have the right to receive clear information regarding how your data is processed.


20.2. Right of access

You may request confirmation that we process your data and you may obtain access to such data, as well as information regarding the processing.


20.3. Right to rectification

You may request the correction of inaccurate data and the completion of incomplete data.


20.4. Right to erasure

You may request the deletion of data when the legal conditions are met, including if the data is no longer necessary or has been processed unlawfully.

The right to erasure is not absolute. We may retain certain data when processing is necessary for compliance with a legal obligation, exercising a right or defending ourselves in a dispute.


20.5. Right to restriction of processing

You may request the limitation of data use in the situations provided by law, for example during the period of verifying its accuracy.


20.6. Right to data portability

In the cases provided by law, you may receive the data provided in a structured, commonly used and machine-readable format or you may request its transmission to another controller.


20.7. Right to object

You may object to processing carried out based on legitimate interest, for reasons relating to your particular situation.

When data is processed for direct marketing purposes, you may object at any time, without needing to provide a reason.


20.8. Right to withdraw consent

When processing is based on consent, it may be withdrawn at any time.


20.9. Right not to be subject to a decision based solely on automated processing

You have the right not to be subject to a decision based solely on automated processing, including profiling, if it produces legal effects or similarly significantly affects you, subject to the exceptions provided by law.


20.10. Right to lodge a complaint

You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing or another competent supervisory authority.


20.11. Right to apply to the courts

Exercising administrative rights does not limit the right to apply to the competent courts.


21. How you can exercise your rights

To exercise your rights, you may send us a request at:

PROFLEX AUTOMOTIVE SRL
Str. Ierbușului no. 38/B
Reghin, Mureș County
Postal code 545300
E-mail: oddice@proflex-tech.ro

The request must contain sufficient information to identify the person and the processing to which it refers.

To protect data, we may request additional information necessary to verify identity. We will not request more information than is necessary for this purpose.

We will respond without undue delay and, in principle, no later than one month from receiving the request.

In the case of a complex request or a large number of requests, the deadline may be extended by no more than two months. We will inform you of the extension and the reasons for it within one month of receiving the request.

Exercising your rights is, in principle, free of charge. In the case of manifestly unfounded or excessive requests, especially due to their repetitive nature, we may charge a reasonable fee or refuse to handle the request, in accordance with the law.


22. Filing a complaint with the ANSPDCP

If you believe that the processing of your data violates data protection legislation, you may lodge a complaint with:

The National Supervisory Authority for Personal Data Processing
B-dul General Gheorghe Magheru no. 28-30
Sector 1, postal code 010336
Bucharest, Romania
E-mail: anspdcp@dataprotection.ro
Telephone: +40 31 805 92 11
Website: www.dataprotection.ro

Before filing a complaint, we encourage you to contact us so that we can try to resolve the reported issue directly.


23. Children’s data

The Website and the Company’s services are primarily intended for adults and representatives of companies or organisations.

We do not intend to knowingly collect personal data from children. If you become aware that a minor has sent us data without the appropriate authorisation, please contact us so that we can analyse the situation and, if necessary, delete the data.


24. Links to other websites

The Website may contain links to websites managed by third parties.

The Company does not control how these websites collect and process personal data. We recommend that you review the privacy policy of each external website before submitting personal data.


25. Change of processing purpose

We will use data for the purposes for which it was collected.

If we intend to use data for a new purpose that is incompatible with the original purpose, we will provide you with the necessary information before starting the new processing and will request consent where required.


26. Updating the Privacy Policy

We may periodically update this Privacy Policy to reflect legislative, technical or operational changes.

The updated version will be published on the Website and will include the date of the latest change.

In the case of significant changes, we may display a visible notice on the Website or inform the data subjects directly, if this is necessary and we have their contact details.


27. Contact

For questions, requests or information regarding the processing of personal data, you may contact us using the following details:

PROFLEX AUTOMOTIVE SRL
Tax ID: 34492005
Trade Registry No.: J2015000475266
EUID: ROONRC.J2015000475266
Registered office: Str. Ierbușului no. 38/B, Reghin, Mureș County, postal code 545300, Romania
E-mail: office@proflex-tech.ro