Privacy

Data privacy.

How we collect, use and protect your personal data, in line with GDPR. Short and clear.

Updated: July 2026

1. Data controller

Forms collecting order and newsletter data are disabled until the controller's complete, verified legal identity is published. For questions, use the public contact details.

2. What data we collect

We collect only the data necessary for the purposes described below. The categories of data we process are:

  • Identification data: first name, last name.
  • Contact data: email address, phone number.
  • Delivery and billing data: full address, postal code, city, county.
  • Order data: products, quantities, value and order status. The current checkout records the request as unpaid and does not collect card details.
  • Order history and communication history with our team.
  • Technical request data (such as IP address and browser type), processed by the hosting and security infrastructure, plus aggregate traffic and performance measurements collected without analytics cookies.

3. Purposes and legal basis (art. 6 GDPR)

We process your data on the following legal bases:

  • Steps requested by you before entering into a contract and performance of that contract (GDPR art. 6(1)(b)): recording and checking the order, delivering products, issuing invoices, handling warranties and returns.
  • Legal obligation (art. 6(1)(c) GDPR): retaining accounting and fiscal documents for the legally required period, sharing data with fiscal or judicial authorities where required.
  • Legitimate interest (art. 6(1)(f) GDPR): fraud prevention, securing the website, improving services based on anonymised aggregate data.
  • Consent (art. 6(1)(a) GDPR): sending marketing communications (newsletter, promotional offers) — only if you have given explicit consent, withdrawable at any time.

4. Recipients and processors

Your data may be transmitted, for the purposes described above, to the following categories of recipients:

  • The courier selected for the order — to arrange and carry out delivery.
  • Hosting and cloud infrastructure providers (including Vercel, Inc.) — for operating and securing the platform.
  • Email and communication service providers — for order notifications and support communications.
  • Public authorities (ANAF, ANPC, courts) — upon explicit request or legal obligation.

We do not sell, transfer or rent your data to third parties for marketing purposes.

5. International transfers

Some of our infrastructure and service providers are located or process data outside the European Economic Area (EEA), including in the United States of America. These transfers are carried out with adequate safeguards: standard contractual clauses adopted by the European Commission or recognised adequacy decisions. We ensure that every transfer complies with GDPR requirements.

6. Storage duration

We retain your data for as long as necessary for each purpose:

  • Mandatory accounting records and supporting documents: five years calculated from 1 July of the year following the end of the financial year in which they were prepared, under Romanian Accounting Law no. 82/1991, unless a specific rule requires a different period.
  • Order and delivery data: for as long as needed to perform the contract, handle warranties, meet accounting duties and establish or defend legal claims; data included in accounting documents follows the statutory period applicable to those documents.
  • Marketing and newsletter data: until consent is withdrawn or erasure is requested, while retaining evidence and a minimal suppression record where needed to respect your choice.
  • Technical and security logs: only for as long as needed for operation, incident investigation and security, according to the infrastructure configuration and applicable duties.

7. Your rights

Under GDPR, you have the following rights, which you can exercise at any time by contacting us:

  • Right of access (art. 15): you can request a copy of the data we hold about you.
  • Right to rectification (art. 16): you can request correction of inaccurate or incomplete data.
  • Right to erasure (art. 17): you can request deletion of data, subject to legal retention obligations.
  • Right to restriction of processing (art. 18): you can request limiting processing under certain conditions.
  • Right to portability (art. 20): you can request your data in a structured, machine-readable format.
  • Right to object (art. 21): you can object to processing based on legitimate interest or for direct marketing.
  • Right to withdraw consent: at any time, without affecting the lawfulness of prior processing.

You may lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP), headquartered in Bucharest, 32 Olari Street, sector 2 — www.dataprotection.ro.

8. Security

We take appropriate technical and organisational measures to protect your data against unauthorised access, modification, disclosure or destruction. Public connections use HTTPS/TLS, and administrative access to data is limited according to role.

If a personal-data breach is likely to result in a risk to people's rights and freedoms, we notify the ANSPDCP without undue delay and, where feasible, within 72 hours of becoming aware of it, under GDPR Article 33. We inform affected people without undue delay when the breach is likely to result in a high risk, under GDPR Article 34.

10. Contact and supervisory authority

For any request regarding your personal data, write to us at nautic.profi@gmail.com or call +40 730 374 009. We answer any request within the legal term of one month (with possibility of justified extension).

If you believe your rights are not respected, you may lodge a complaint with the ANSPDCP or appeal to competent courts.

Still have questions?
Send us your question and product details.
Contact us