Privacy policy
Privacy Policy
Last updated 13/Mai/2026
1. Who we are
ASTRA VISION ONLINE S.R.L. is the data controller responsible for your personal data collected through polos.ro.
CUI: 54507208
Registration number: [J2026025479001]
Address: Bucureşti Sectorul 2, Șoseaua Mihai Bravu, Nr. 136, Bl. D20, Scara 2, Etaj 3, Ap. 39
Email: info@polos.ro
2. What data we collect
We collect the following categories of personal data:
- Identity data: first name, last name
- Contact data: email address, phone number, delivery address, billing address
- Transaction data: order details, payment method (we do not store card numbers), purchase history
- Technical data: IP address, browser type, device information, cookies
- Usage data: pages visited, time spent on site, clicks and interactions
- Marketing data: your preferences and communication history with us
3. How we collect your data
- Directly from you when you place an order, create an account, or contact us
- Automatically via cookies and tracking technologies when you browse our website
- From third-party services such as Google Analytics and Meta Pixel
4. Why we use your data (legal basis)
- Contract performance — to process and deliver your orders, issue invoices, and handle returns (Art. 6(1)(b) GDPR)
- Legal obligation — to comply with Romanian tax and consumer protection laws (Art. 6(1)(c) GDPR)
- Legitimate interest — to improve our website, prevent fraud, and manage our business (Art. 6(1)(f) GDPR)
- Consent — to send you marketing emails and use non-essential cookies. You may withdraw consent at any time (Art. 6(1)(a) GDPR)
5. Third parties we share data with
We share your data only when necessary, with the following trusted partners:
- Shopify Inc. — our e-commerce platform (data may be processed outside the EU under standard contractual clauses)
- Google LLC — Google Analytics (website analytics) and Google Ads (advertising)
- Meta Platforms Inc. — Facebook Pixel for advertising and remarketing
- Payment processors — [e.g. Stripe / PayU / Netopia] for secure payment processing. We do not store your card details.
- Email marketing — [e.g. Mailchimp / Klaviyo] for newsletters and promotional emails
- Courier & logistics partners — [e.g. FAN Courier / DPD / Cargus / Sameday] for order delivery
We do not sell your personal data to any third party.
6. Cookies
We use the following types of cookies:
- Essential cookies — required for the website to function (cart, session, security)
- Analytics cookies — Google Analytics, to understand how visitors use our site
- Marketing cookies — Meta Pixel and Google Ads, to show you relevant advertisements
- Preference cookies — to remember your language and display settings
You can manage or withdraw your cookie consent at any time via your browser settings or our cookie banner.
7. How long we keep your data
- Order & invoice data — 10 years (required by Romanian fiscal law)
- Account data — for as long as your account is active, plus 3 years after closure
- Marketing data — until you withdraw consent or unsubscribe
- Technical/cookie data — up to 24 months
8. Your rights under GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of your data
- Right to rectification — correct inaccurate data
- Right to erasure — request deletion of your data ("right to be forgotten")
- Right to restriction — limit how we process your data
- Right to data portability — receive your data in a structured format
- Right to object — object to processing based on legitimate interest or for direct marketing purposes (this right is absolute for marketing)
- Right to withdraw consent — at any time, without affecting prior processing
To exercise any of these rights, contact us at info@polos.ro. We will respond within 30 days.
9. International data transfers
Some of our third-party partners (such as Shopify, Google, and Meta) may process your data outside the European Union. In all such cases, transfers are carried out under appropriate safeguards, including EU Standard Contractual Clauses (SCCs), in compliance with GDPR Article 46.
10. Data security
We implement appropriate technical and organizational measures to protect your personal data, including SSL encryption, secure payment processing, and restricted access to personal data. In the event of a data breach affecting your rights, we will notify the Romanian Data Protection Authority (ANSPDCP) within 72 hours and inform affected users where required.
11. Children's privacy
Our website is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us at info@polos.ro and we will delete it promptly.
12. Complaints
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Romanian Data Protection Authority (ANSPDCP):
Website: www.dataprotection.ro
Address: B-dul Magheru 28-30, Sector 1, București
Email: anspdcp@dataprotection.ro
13. Changes to this policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated date. We encourage you to review this policy periodically.