GDPR Compliant

Privacy Policy

Ultima actualizare: August 2026

1. Introduction

Transilvania Marketing (“we”, “our” or “the Company”) respects the confidentiality of your personal data and is committed to protecting it in accordance with Regulation (EU) 2016/679 (GDPR) and Law no. 190/2018.

This policy explains what data we collect, how we use it, who we share it with and what rights you have.

Data controller

Transilvania Marketing
Calea Dumbravii 24, Sibiu, Romania
Place of business: Global City Business Park, Pipera, Bucharest
Email: contact@transilvaniamarketing.ro
Phone: +40 750 435 030, +40 735 424 787

2. The data we collect

We collect the following categories of personal data:

2.1 Data you provide directly

  • Identification data: first name, last name
  • Contact data: email address, phone number
  • Professional data: company name, job title, company website
  • Content of communications: messages sent through the contact form

2.2 Data collected automatically

  • Technical data: IP address, browser type, operating system
  • Usage data: pages visited, time spent on the site, traffic source
  • Cookie data: in accordance with the Cookie Policy

3. The purposes and legal grounds for processing

PurposeLegal ground
Responding to your requestsConsent / Legitimate interest
Providing the contracted servicesPerformance of the contract
Sending offers and news (newsletter)Consent
Improving the site and servicesLegitimate interest
Statistical analysis and marketingConsent / Legitimate interest
Compliance with legal obligationsLegal obligation

4. Sharing data with third parties

We do not sell your personal data. We may share data with:

  • Service providers: hosting (Cloudflare), email marketing, CRM, web analytics
  • Advertising platforms: Google, Meta (Facebook/Instagram), TikTok — as part of campaigns managed for clients
  • Public authorities: when the law requires it
  • Professional advisers: lawyers, accountants — under confidentiality obligations

All our providers are carefully selected and contractually obliged to protect data in accordance with GDPR.

5. International data transfers

Some of our providers may store data outside the European Economic Area (EEA). In such cases, we make sure that adequate safeguards are in place:

  • Adequacy decisions of the European Commission
  • Standard contractual clauses approved by the EU
  • Certifications (e.g. Data Privacy Framework for the USA)

6. Storage period

We keep your data only for as long as necessary:

  • Contact form data: 2 years from the last communication
  • Contractual data: for the duration of the contract + 5 years (tax obligations)
  • Marketing data (newsletter): until consent is withdrawn
  • Analytics data: 26 months (Google Analytics)
  • Technical logs: maximum 12 months

7. Your rights

Under GDPR, you have the following rights:

◉

The right of access

You can request a copy of the data we hold about you.

✎

The right to rectification

You can ask for inaccurate or incomplete data to be corrected.

⌫

The right to erasure

You can request the deletion of data (“the right to be forgotten”).

◐

The right to restriction

You can limit the processing of data in certain situations.

⇄

The right to portability

You can receive your data in a structured, usable format.

⊘

The right to object

You can object to processing for direct marketing purposes.

To exercise your rights, contact us at contact@transilvaniamarketing.ro. We will respond within 30 days.

8. Data security

We implement technical and organisational measures to protect data:

  • SSL/TLS encryption for all communications
  • Restricted access to data (the “need-to-know” principle)
  • Regular and secure backups
  • Monitoring and periodic auditing
  • Staff training on data protection

9. Cookies

We use cookies for the operation of the site and for analytics. For full details about the types of cookies used and how you can manage them, see the Cookie Policy.

10. Shopify apps

This section applies to the "Transilvania Marketing PPC" app (and any other Shopify app published by Transylvania Marketing LTD SRL), which agency clients install in their own Shopify store. The rest of this policy (controller, contact, your rights, security, supervisory authority) applies here as well.

What the app does. It reads, read-only, daily aggregated reports from your store — sessions, cart additions, checkouts reached, checkouts completed, order count, gross, net and total sales, discounts and returns — to compare them with your Google Ads and Meta Ads campaign results in our reporting platform (PPC Center). It writes nothing to your store and changes nothing in checkout.

What we do NOT read. The app does not request, receive, store or display data about your store's customers: names, addresses, e-mail addresses, phone numbers, order contents or individual identifiers. Every figure is a daily total. Why we still request "Level 2" protected customer data access: Shopify's reporting interface (ShopifyQL) requires that access level as a technical precondition for any sales report, regardless of the fields requested. It is a platform requirement, not a processing we perform.

What we store.

  • The daily totals above, per store and per day, together with the raw report response (also aggregated per day).
  • Connection data: your store domain, install status and the access token Shopify issues for your store.
  • Technical logs: installs, uninstalls, sync calls, errors.

Who is controller and who is processor. For the data from your store, you are the controller and we process as your processor under Article 28 GDPR, on the basis of the services agreement between us and solely for campaign reporting. For the app account data (store domain, install status, technical logs) we are the controller, on the basis of contract performance — Article 6(1)(b) GDPR.

Where the data is and who can access it. The data is stored in our Odoo system, hosted on infrastructure we administer at Hetzner Online GmbH, Falkenstein, Germany (European Union), backups included. The access token is visible only to users with the administrator role of the reporting platform. We do not transfer your store data outside the European Economic Area and do not share it with other clients or third parties.

How long we keep it.

  • Access token: deleted as soon as you uninstall the app (and in any case on the shop/redact notice sent by Shopify).
  • Daily totals: for the duration of the agreement and at most 3 years after it ends, as reporting history; deleted in full on the shop/redact notice Shopify sends after uninstall.
  • Technical logs: at most 12 months.

Your customers' requests. If a customer of your store exercises their GDPR rights, Shopify forwards the request to us automatically (customers/data_request, customers/redact). Because we store no data about individuals, there is nothing to return or erase; we confirm this within the time Shopify requires. You remain responsible towards your customers as controller; we assist on request.

Security and incidents. Communication with Shopify and with our platform is encrypted (HTTPS/TLS). Access to the platform is limited to staff who need it and is logged. If a security breach affecting your store data occurs, we notify you without undue delay and no later than 72 hours after becoming aware of it, so you can meet your obligations as controller.

Uninstalling. You can uninstall the app at any time from your Shopify admin. Contact for apps: sebastian@transilvaniamarketing.ro.

11. Changes to the policy

We may update this policy from time to time to reflect changes in our practices or in legislation. We will notify you of significant changes by email or by displaying a notice on the site. The date of the last update is shown at the beginning of the document.

12. The right to lodge a complaint

If you consider that the processing of your data infringes GDPR, you have the right to lodge a complaint with the supervisory authority:

Supervisory authority

The National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest
www.dataprotection.ro

13. Contact

For questions about this policy or to exercise your rights, contact us: