Skip to content
  • Dispatched within 24h
  • 2-year warranty
  • Free delivery over 500 lei
Call to order+40 732 405 826

Privacy policy

Privacy policy

How Plastmach Machine S.R.L. collects, uses and protects your personal data, under Regulation (EU) 2016/679 (GDPR).

Last updated:

Who the data controller is

Plastmach Machine S.R.L., registered office at Strada Petőfi Sándor 1bis, Dumbrăvița 307160, județul Timiș, România, VAT number RO 44339298, registered with the Trade Register under no. J35/2134/2021 (referred to below as “Vorne” or “we”), is the controller of the personal data processed through vorne.ro.

For any question about how we handle your data, write to us at contact@vorne.ro or by phone on +40 732 405 826.

We have not appointed a Data Protection Officer, as our activity does not fall within the cases listed in Article 37 GDPR. Requests are handled at the contact details above.

What we collect

We collect only what we need to deliver what you ordered and to answer you when you write. Specifically:

Order data
your name, phone number, email address, delivery address and — for company orders — the company name, VAT number (CUI) and Trade Register number; the contents of the order and its history.
Account data
your email address, your password (stored only as a hash, never in plain text), saved addresses and billing preferences.
Contact form data
your name, the contact details you give us and the content of your message.
Technical data
IP address, browser and device type, pages viewed and when — collected automatically in server logs and, if you consent, through the analytics tools described in the cookie policy.

We do not process special categories of data (Article 9 GDPR) and we never ask for full card details: card payments run entirely on the payment processor’s infrastructure and we receive only the confirmation of the transaction.

Why we use it, and on what legal basis

Every processing operation has a stated purpose and a legal basis under Article 6 GDPR:

Processing, confirming and delivering orders
performance of the contract you are party to — Article 6(1)(b) GDPR.
Running your user account
performance of the contract — Article 6(1)(b) GDPR.
Issuing and keeping tax documents
compliance with a legal obligation — Article 6(1)(c) GDPR.
Replying to messages sent by form, email or phone
our legitimate interest in answering the enquiries we receive — Article 6(1)(f) GDPR.
Handling complaints, returns and warranty claims
performance of the contract and legal obligation — Articles 6(1)(b) and (c) GDPR.
Measuring traffic with analytics tools
your consent — Article 6(1)(a) GDPR, which you can withdraw at any time.
Preventing fraud and keeping the site secure
our legitimate interest — Article 6(1)(f) GDPR.

How long we keep it

  • Invoices and supporting accounting documents: 10 years from the close of the financial year, as required by Accounting Law no. 82/1991.
  • Order data with no tax relevance: 3 years from completion of the order, matching the general limitation period.
  • Account data: for as long as the account is active, plus 30 days after it is deleted.
  • Contact form messages: 12 months from our last reply.
  • Data collected through analytics cookies: 14 months at most.

Once those periods expire the data is deleted or irreversibly anonymised.

Who we share it with

We do not sell or rent your data. We disclose it only to the suppliers who provide services to us — “processors” within the meaning of Article 28 GDPR — under contracts that oblige them to process it solely on our instructions:

Vercel Inc.
hosting the website and its database
[card payment processor — to be confirmed]
processing card payments
[courier — to be confirmed]
delivering parcels to the address you give us
Google Ireland Limited (Google Analytics)
measuring traffic and how the site is used

We may also disclose it to public authorities where the law requires it, and to our accountants and legal advisers under a duty of confidentiality.

Transfers outside the European Economic Area

Some of the suppliers above are established outside the EEA or use infrastructure outside it. Those transfers rely on the Standard Contractual Clauses adopted by the European Commission or on an adequacy decision — for example the EU-US Data Privacy Framework. You can ask us for a copy of the safeguards that apply, at the email address above.

Your rights

As a data subject you have the following rights under Articles 15–22 GDPR:

Right of access
to find out whether we process your data and to receive a copy of it, together with the information in this policy.
Right to rectification
to have inaccurate data corrected and incomplete data completed.
Right to erasure (“right to be forgotten”)
to have your data deleted, to the extent the law does not require us to keep it — invoices being the usual case.
Right to restriction of processing
to have processing suspended while you contest the accuracy of the data or the lawfulness of the processing.
Right to data portability
to receive the data you gave us in a structured, commonly used, machine-readable format.
Right to object
to object, on grounds relating to your particular situation, to processing based on our legitimate interest.
Right to withdraw consent
at any time, without affecting the lawfulness of processing carried out before you withdrew it.
Right not to be subject to automated decisions
we take no automated decisions producing legal effects concerning you, and we do not profile you for that purpose.

To exercise any of these rights, write to us at contact@vorne.ro. We reply within 30 days of receiving the request.

If our answer does not satisfy you, you have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, sector 1, Bucharest, or at www.dataprotection.ro.

Security

The site runs over HTTPS only, passwords are stored as hashes, and access to order data is limited to the people who need it to do their job.

No system is infallible, though. If a breach occurs that is likely to affect your rights, we will inform you and notify ANSPDCP within 72 hours, as Articles 33–34 GDPR require.

Children’s data

This site is intended for adults. We do not knowingly collect data from anyone under 16. If you learn that a child has given us data, write to us at the address above and we will delete it.

Changes to this policy

We may update this policy when the services we use or the applicable law change. The version in force is the one published on this page, and the date of the last revision is shown at the top.