Privacy Policy
1. Introduction
Transilvania Marketing (“we”, “our” or “the Company”) respects the confidentiality of your personal data and is committed to protecting it in accordance with Regulation (EU) 2016/679 (GDPR) and Law no. 190/2018.
This policy explains what data we collect, how we use it, who we share it with and what rights you have.
Transilvania Marketing
Calea Dumbravii 24, Sibiu, Romania
Place of business: Global City Business Park, Pipera, Bucharest
Email: contact@transilvaniamarketing.ro
Phone: +40 750 435 030, +40 735 424 787
2. The data we collect
We collect the following categories of personal data:
2.1 Data you provide directly
- Identification data: first name, last name
- Contact data: email address, phone number
- Professional data: company name, job title, company website
- Content of communications: messages sent through the contact form
2.2 Data collected automatically
- Technical data: IP address, browser type, operating system
- Usage data: pages visited, time spent on the site, traffic source
- Cookie data: in accordance with the Cookie Policy
3. The purposes and legal grounds for processing
| Purpose | Legal ground |
|---|---|
| Responding to your requests | Consent / Legitimate interest |
| Providing the contracted services | Performance of the contract |
| Sending offers and news (newsletter) | Consent |
| Improving the site and services | Legitimate interest |
| Statistical analysis and marketing | Consent / Legitimate interest |
| Compliance with legal obligations | Legal obligation |
4. Sharing data with third parties
We do not sell your personal data. We may share data with:
- Service providers: hosting (Cloudflare), email marketing, CRM, web analytics
- Advertising platforms: Google, Meta (Facebook/Instagram), TikTok — as part of campaigns managed for clients
- Public authorities: when the law requires it
- Professional advisers: lawyers, accountants — under confidentiality obligations
All our providers are carefully selected and contractually obliged to protect data in accordance with GDPR.
5. International data transfers
Some of our providers may store data outside the European Economic Area (EEA). In such cases, we make sure that adequate safeguards are in place:
- Adequacy decisions of the European Commission
- Standard contractual clauses approved by the EU
- Certifications (e.g. Data Privacy Framework for the USA)
6. Storage period
We keep your data only for as long as necessary:
- Contact form data: 2 years from the last communication
- Contractual data: for the duration of the contract + 5 years (tax obligations)
- Marketing data (newsletter): until consent is withdrawn
- Analytics data: 26 months (Google Analytics)
- Technical logs: maximum 12 months
7. Your rights
Under GDPR, you have the following rights:
The right of access
You can request a copy of the data we hold about you.
The right to rectification
You can ask for inaccurate or incomplete data to be corrected.
The right to erasure
You can request the deletion of data (“the right to be forgotten”).
The right to restriction
You can limit the processing of data in certain situations.
The right to portability
You can receive your data in a structured, usable format.
The right to object
You can object to processing for direct marketing purposes.
To exercise your rights, contact us at contact@transilvaniamarketing.ro. We will respond within 30 days.
8. Data security
We implement technical and organisational measures to protect data:
- SSL/TLS encryption for all communications
- Restricted access to data (the “need-to-know” principle)
- Regular and secure backups
- Monitoring and periodic auditing
- Staff training on data protection
9. Cookies
We use cookies for the operation of the site and for analytics. For full details about the types of cookies used and how you can manage them, see the Cookie Policy.
10. Shopify apps
This section applies to the "Transilvania Marketing PPC" app (and any other Shopify app published by Transylvania Marketing LTD SRL), which agency clients install in their own Shopify store. The rest of this policy (controller, contact, your rights, security, supervisory authority) applies here as well.
What the app does. It reads, read-only, daily aggregated reports from your store — sessions, cart additions, checkouts reached, checkouts completed, order count, gross, net and total sales, discounts and returns — to compare them with your Google Ads and Meta Ads campaign results in our reporting platform (PPC Center). It writes nothing to your store and changes nothing in checkout.
What we do NOT read. The app does not request, receive, store or display data about your store's customers: names, addresses, e-mail addresses, phone numbers, order contents or individual identifiers. Every figure is a daily total. Why we still request "Level 2" protected customer data access: Shopify's reporting interface (ShopifyQL) requires that access level as a technical precondition for any sales report, regardless of the fields requested. It is a platform requirement, not a processing we perform.
What we store.
- The daily totals above, per store and per day, together with the raw report response (also aggregated per day).
- Connection data: your store domain, install status and the access token Shopify issues for your store.
- Technical logs: installs, uninstalls, sync calls, errors.
Who is controller and who is processor. For the data from your store, you are the controller and we process as your processor under Article 28 GDPR, on the basis of the services agreement between us and solely for campaign reporting. For the app account data (store domain, install status, technical logs) we are the controller, on the basis of contract performance — Article 6(1)(b) GDPR.
Where the data is and who can access it. The data is stored in our Odoo system, hosted on infrastructure we administer at Hetzner Online GmbH, Falkenstein, Germany (European Union), backups included. The access token is visible only to users with the administrator role of the reporting platform. We do not transfer your store data outside the European Economic Area and do not share it with other clients or third parties.
How long we keep it.
- Access token: deleted as soon as you uninstall the app (and in any case on the
shop/redactnotice sent by Shopify). - Daily totals: for the duration of the agreement and at most 3 years after it ends, as reporting history; deleted in full on the
shop/redactnotice Shopify sends after uninstall. - Technical logs: at most 12 months.
Your customers' requests. If a customer of your store exercises their GDPR rights, Shopify forwards the request to us automatically (customers/data_request, customers/redact). Because we store no data about individuals, there is nothing to return or erase; we confirm this within the time Shopify requires. You remain responsible towards your customers as controller; we assist on request.
Security and incidents. Communication with Shopify and with our platform is encrypted (HTTPS/TLS). Access to the platform is limited to staff who need it and is logged. If a security breach affecting your store data occurs, we notify you without undue delay and no later than 72 hours after becoming aware of it, so you can meet your obligations as controller.
Uninstalling. You can uninstall the app at any time from your Shopify admin. Contact for apps: sebastian@transilvaniamarketing.ro.
11. Changes to the policy
We may update this policy from time to time to reflect changes in our practices or in legislation. We will notify you of significant changes by email or by displaying a notice on the site. The date of the last update is shown at the beginning of the document.
12. The right to lodge a complaint
If you consider that the processing of your data infringes GDPR, you have the right to lodge a complaint with the supervisory authority:
The National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest
www.dataprotection.ro
13. Contact
For questions about this policy or to exercise your rights, contact us: