Need Help?
+40371.546.681Privacy Policy
We consider ensuring the right to personal data protection as a fundamental Todome commitment, therefore we will dedicate all necessary resources and efforts to process your data in full compliance with Regulation (EU) 2016/679 ("General Data Protection Regulation" or "GDPR"), as well as any other applicable legislation. As one of the essential principles of this legal framework is transparency, we have prepared this document to inform you about how we collect, use, transfer and protect your personal data when you interact with us in relation to our products and services, including through our website or mobile apps.
We reserve the right to periodically update and amend this Privacy Policy to reflect any changes in the way we process your personal data or any changes in legal requirements. In the event of any such changes, we will post the amended version of the Privacy Policy on our website, so please check the content of this Privacy Policy periodically.
Who we are and how to contact us
Todome is the trade name of Todome Fero SRL, a legal entity of Romanian nationality, with registered office in Aleea 2 Henry Ford nr 2A, Craiova, Dolj, with number in the Trade Register J16/1467/2009, unique tax registration code RO26228399 (hereinafter "Todome" or "we"). For the purposes of data protection legislation, we are an operator when processing your personal data.
As we are always open to hearing your views, as well as providing you with any additional information you may need regarding the processing of your data, we encourage you to contact Todome's Data Protection Officer at contact@todome.ro or by post or courier at Aleea 2 Henry Ford nr 2A, Craiova, Dolj - with the mention: for the attention of Todome's Data Protection Officer.
What categories of personal data we process
In general, we collect your personal data directly from you, so you have control over the type of information you give us. By way of example, we receive information from you as follows:
- When you create an account on Todome, send us your e-mail address, phone number, first and last name;
- On your personal page (My Account) on the Todome platform you can add additional information such as: nickname, landline number, date of birth, education level, delivery address, alternative e-mail address, bank card details, etc.
- When you place an order, you provide us with information such as the desired product, delivery address, billing details, payment method, phone number, etc.
We may also collect and further process certain information about your behavior while visiting our website or using our smartphone app in order to personalize your online experience and provide you with offers tailored to your profile. We invite you to learn more about this by consulting the section on processing purposes below.
On our website and smartphone app we may store and collect information in cookies and similar technologies in accordance with the Cookie Policy.
We do not collect or otherwise process sensitive data, included by the General Data Protection Regulation in special categories of personal data. We also do not want to collect or process data from minors under the age of 16.
What are the purposes and grounds for processing
We will use your personal data for the following purposes:
1. For the provision of Todome services for your benefit
This general purpose may include, as appropriate, the following:
- Account creation and administration within the Todome platform;
- Order processing, including order picking, validation, shipping and invoicing;
- Solving cancellations or problems of any kind related to an order, goods or services purchased;
- Returning products in accordance with legal provisions;
- Reimbursement of the value of the products according to legal provisions;
The processing of your data for these purposes is in most cases necessary for the conclusion and performance of a contract between Todome and you. In addition, certain processing for these purposes is required by applicable law, including tax and accounting law.
2. To improve our services
We always strive to provide you with the best online shopping experience. To do this, we may collect and use certain information about your shopping behaviour, invite you to complete satisfaction surveys following the completion of an order, or conduct market research directly or with partners.
We base these activities on our legitimate interest in doing business, always taking care that your fundamental rights and freedoms are not affected.
3. For Marketing
We want to keep you up to date with the best offers for the products you are interested in. To this end, we may send you, via electronic communication channels (e-mail/SMS/mobile push/webpush/etc.) general and thematic newsletters, information on products similar or complementary to those you have purchased or have shown interest in purchasing, as well as other similar commercial communications, and we may display personalized recommendations on the website and in the smartphone application. In order to provide you with information of interest to you, we may use certain data about your shopping behaviour (e.g. products viewed/added to wishlist/purchased) to create a profile for you. We always ensure that these processing operations are carried out with respect for your rights and freedoms, and that decisions taken on the basis of these operations do not have legal effects on you and do not affect you in a similar way to a significant extent.
In most cases, we base our marketing communications on your prior consent, expressed by ticking the box "I would like to receive the weekly newsletter with Todome exclusive news and campaigns". You can change and withdraw your consent at any time by:
- Change the settings in your customer account in the "Personal Data" section;
- Accessing the unsubscribe link displayed within the messages you receive from us;
- Contacting Todome using the contact details described above.
In certain situations, we may base our marketing activities on our legitimate interest in promoting and developing our business. In any situation where we use information about you for a legitimate interest of ours, we take care and all necessary measures to ensure that your fundamental rights and freedoms are not affected. However, you can always ask us, by the means described above, to stop the processing of your personal data for marketing purposes, and we will comply with your request as soon as possible.
4. In defence of our legitimate interests
There may be situations where we use or transmit information to protect our rights and business. These may include:
- Measures to protect the Todome website and platform users from cyber attacks;
- Measures to prevent and detect fraud attempts, including the transmission of information to the competent public authorities;
- Measures to manage various other risks.
The general basis for these types of processing is our legitimate interest in protecting our business, and it is understood that we ensure that any measures we take guarantee a balance between our interests and your fundamental rights and freedoms. Also, in certain cases we base our processing on legal provisions such as the obligation to ensure the security of goods and values provided for by the applicable legislation in this matter.
How long we keep your personal data
As a general rule, we will store your personal data as long as you have an account on the Todome platform. You may at any time request us to delete certain information or to close your account, and we will comply with such requests, subject to retaining certain information even after account closure, in situations where applicable law or our legitimate interests so require.
If you do not have an account on the Todome platform, the general rule is to keep information related to orders placed for a period of [3] years from the time the order is completed. Similar to the previous situation, it is possible to keep certain data even after the expiry of this period, in accordance with applicable law or our legitimate interests.
To whom we transmit your personal data
Where appropriate, we may transmit or provide access to certain of your personal data to the following categories of recipients:
- companies within the same group of companies as Todome;
- courier service providers;
- payment/banking service providers
- marketing/telemarketing service providers;
- market research service providers;
- insurance companies;
- IT service providers;
- other companies with whom we can develop joint programmes to market our goods and services.
If we have a legal obligation to do so, or if necessary to protect a legitimate interest, we may also disclose certain personal data to public authorities.
We ensure that access to your data by third parties who are private legal entities is carried out in accordance with the legal provisions on data protection and confidentiality of information, based on contracts concluded with them.
To which countries we transfer your personal data
Currently, we store and process your personal data in Romania.
However, from time to time, we may transfer some of your personal data to entities located outside of Romania. These entities may be located in the European Union or outside the European Union, including in countries where the European Commission has not recognised an adequate level of personal data protection.
We will always take steps to ensure that any international transfer of personal data is carefully managed in order to protect your rights and interests. Transfers to service providers and other third parties will always be protected by contractual commitments and, where appropriate, other safeguards, such as standard contractual clauses issued by the European Commission or certification schemes, such as the Privacy Shield for the protection of personal data transferred from within the EU to the United States.
You can contact us at any time, using the contact details set out above, to find out more information about the countries to which we transfer your data, as well as the safeguards we have put in place in relation to these transfers.
How we protect the security of your personal data
We are committed to ensuring the security of personal data by implementing appropriate technical and organisational measures in accordance with industry standards.
We store your personal data on secure servers, using state-of-the-art encryption algorithms and ensuring storage redundancy.
We use the services of the payment processor PayU/Mobilpay to make payments. All payment information is encrypted using SSL technology.
In ciuda masurilor luate pentru a proteja datele dvs cu caracter personal, va atragem atenţia ca transmiterea informaţiilor prin Internet, in general, sau prin intermendiul altor reţele publice, nu este complet sigura, existand riscul ca datele sa fie vazute şi utilizate de catre terţe parţi neautorizate. Nu putem fi responsabili pentru astfel de vulnerabilitati ale unor sisteme care nu sunt sub controlul nostru.
What rights do you have
The General Data Protection Regulation gives you a number of rights in relation to your personal data. You can request access to your data, correct any errors in our files and/or object to the processing of your personal data. You may also exercise your right to complain to the competent supervisory authority or to take legal action. Where applicable, you may also have the right to request the deletion of your personal data, the right to restrict the processing of your data and the right to data portability.
More information on each of these rights can be found in the table below.
To exercise your rights, you can contact us using the contact details above. Please note the following if you wish to exercise these rights:
Identity. We take the confidentiality of all records containing personal data seriously. For this reason, please send us your requests for such records using the e-mail address of your Todome account. Otherwise, we reserve the right to verify your identity by requesting additional information to confirm your identity.
Fees. We will not charge you a fee to exercise any right in relation to your personal data, unless your request for access to information is unfounded, i.e. repetitive or excessive, in which case we will charge a reasonable fee in such circumstances. We will inform you of any fees charged before we deal with your request.
Response time. We aim to respond to any valid requests within a maximum of one month, unless this is particularly complicated or if you have made several requests, in which case we will respond within a maximum of two months. We will let you know if we need more than one month. We may ask you to tell us exactly what you would like to receive or what you are concerned about. This will help us to act faster and shorten the response time to your request.
Third party rights. We do not have to comply with a request if it would adversely affect the rights and freedoms of other data subjects.
Rights concerned and their description
Access
You can ask us:
- to confirm whether we process your personal data;
- provide you with a copy of this data;
- provide you with other information about your personal data, such as what data we hold, what we use it for, who we disclose it to, whether we transfer it abroad and how we protect it, how long we keep it, what rights you have, how you can make a complaint, where we obtained your data, to the extent that the information has not already been provided to you through this notice.
Correction
You can ask us to rectify or complete your inaccurate or incomplete personal data. We may attempt to verify the accuracy of the data before rectifying it.
Deleting data
You can ask us to delete your personal data, but only if:
- they are no longer needed for the purposes for which they were collected;
- you have withdrawn your consent (if the processing is based on consent);
- you exercise a legal right to object;
- it has been unlawfully processed;
- we have a legal obligation to do so.
We are under no obligation to comply with your request to delete your personal data if the processing of your personal data is necessary:
- for compliance with a legal obligation;
- for the establishment, exercise or defence of a legal claim
There are certain other circumstances in which we are not obliged to comply with your request for deletion of data, although these two are the most likely circumstances in which we may refuse your request.
Before exercising this right, you should download from your Todome account and save all the documents related to the orders you have placed with Todome, regardless of whether the invoicing was made to you or to another natural or legal person (such as: invoices, warranty certificates). If you do not take this step before exercising your right of deletion, you will lose all these documents and Todome will be unable to make them available to you because the process of deletion of data, i.e. the Todome account, with all data and documents related to it, is an irreversible process.
Restriction of data processing
You can ask us to restrict the processing of personal data, but only if:
- their accuracy is disputed (see the rectification section), to enable us to verify their accuracy;
- the processing is unlawful, but you do not want the data to be deleted;
- they are no longer necessary for the purposes for which they were collected, but you need them to establish, exercise or defend a legal claim;
- you have exercised your right to object, and verification of whether our rights prevail is ongoing.
We may continue to use your personal data following a restriction request if:
- we have your consent;
- to establish, exercise or defend a right in court;
- to protect the rights of another natural or legal person.
Data portability
You can ask us to provide your personal data in a structured, commonly used and machine-readable format, or you can request that it be "ported" directly to another data controller, but in each case only if:
- the processing is based on your consent or the conclusion or performance of a contract with you;
- processing is carried out by automated means.
Opposition
You may object at any time, for reasons relating to your particular situation, to the processing of your personal data on the basis of our legitimate interest, if you consider that your fundamental rights and freedoms prevail over this interest.
You may also object at any time to the processing of your data for direct marketing purposes (including profiling), without giving any reason, in which case we will stop such processing as soon as possible.
Automatic decision-making
You can ask not to be subject to a decision based solely on automatic processing, but only when that decision:
- produces legal effects with respect to you;
- otherwise affects you in a similar way and to a significant extent.
This right does not apply if the decision reached as a result of the automatic decision making:
- is necessary for us to enter into or perform a contract with you;
- is authorised by law and there are adequate safeguards for your rights and freedoms;
- is based on your explicit consent.
Complaints
You have the right to lodge a complaint with the supervisory authority about the processing of your personal data. In Romania, the contact details of the data protection supervisory authority are as follows:
- National Supervisory Authority for Personal Data Processing;
- B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, Bucharest, Romania;
- Telephone: +40.318.059.211 or +40.318.059.212;
- E-mail: anspdcp@dataprotection.ro
Without prejudice to your right to contact the supervisory authority at any time, please contact us in advance, and we promise to make every effort to resolve any issues amicably.
We remind you that you can contact the Todome Officer at any time with data protection by sending your request by any of the following means:
- by e-mail to: contact@todome.ro
- by post or courier to the address: Aleea 2 Henry Ford nr 2A, Craiova, Dolj - with a mention to the attention of the Data Protection Officer Todome.