Generate leads with conversational forms.
PICARD
© 2018 Picard. All rights reserved.
FOLLOW US ON
Grapefruit is a User Experience and Digital Consulting Agency from Romania.
powered by GRAPEFRUIT
Personal data protection notification
1. General information
a) Introduction
On the 25th of May 2018 the European 2016/679 regulation is published regarding the individual’s personal safety on data protection and privacy and its freedom of transfer (“Regulation”).
Its main purpose is to raise the level of protection for personal data and create a trustworthy environment where each individual has control over their own data.
Therefore, we consider the right moment to inform you how we protect your personal data and how we apply the Regulation’s terms.
The following notification regarding data protection is conceived to inform you how your personal data is been processed and your rights. All this according to the General Data Protection Regulation and the local legislation applied.
b) Data controller
We, Grapefruit SRL with office on Vasile Pogor 6 Street (Mansarda) from Iasi, Romania, we represent the data controller according to GDPR and, as a it suggests, we are responsible for processing the data described bellow. For questions and requests regarding data processing, we ask you to contact us using the following contact information
Address - mun. Iași, str. Vasile Pogor nr. 6, mansardă, jud. Iași, Romania
Email – dpo@grapefruit.ro
The data will be collected only with your consent. Your refusal makes it impossible for the data controller (Grapefruit SRL) to contact you regarding the product demo, inform you and transmit you the latest updates.
c) Personal data collected
Grapefruit SRL processed the following personal data:
2. Processing information
a) Types of data processing
“Processing” means any operation or set of operations done over personal data or over sets of personal data, with or without using automized means, like collecting, registering, organizing, structuring, storing, adapting o modifying, extracting, consulting, utilizing, transmtiting, analyzing or making available using other means, aligning or combining, restricting, deleting or destroying.
b) Principles of personal data processing
Grapefruit SRL is obliged to respect the personal data protection principles (named “Principles”) provided by GDPR, to make sure all data are:
c) Scope and purpose for data processing
We can send you our information via e-mail. This processing is based on Art 6, paragraph 1 thesis 1 letter a) GDPR
ii.For the purpose of user relationship to improve the client experience on our site and identify preferences and/or user behavior, including through automated processes, without human interference. We will always take into account your options. This processing feature is based on Article 6, Indentation 1, Letter a) from GDPR.
iii Data analysis and client profiling. This includes market research, client questionnaires, client analysis, client segmentation and client profile creation, to determine the navigation and client activity behavior. Is it possible for us to request feedback regarding our newsletter updates and to communicate to certain members of our team how to improve the services. Moreover, we can use notes from our online conversations, or phone or face-to-face. So that we personalize the information and services we provide. We will contact you for theses porposes via e-mail, SMS or phone. Through these, your data will be stored on our database and will be updated we new information we gather from public sources. It is necessary that we follow our legitimate interests to improve the services and client relationships, which represent a key factor in the product/project’s success. The data collected and stored helps us find out more about your interest and needs. This allows us to take into consideration acting in consequence, meaning to apply personalized communication. This processing is based on Article 6 paragraph 6 thesis 1 letter f) GDPR.
d) Data beneficiaries
To reach the scope of those mentioned above at section 2 letter c) we utilize service providers and authorized personel according to art 28 GDPR, for example our service providers for hosting, platform and service maintenance, for sending e-mails, external consultants, and all of these who are located in countries in Romania or outside Romania and the European Union/European Economic space.
We assure, for example, through contract reglementations, that these service providers process personal data according to the European legislation regarding data protection, to guarantee a high level of data protection (for example, standard contract clauses, mandatory corporate rules etc.) even if the personal data are transferred in a country where, by default, there’s another level of data protection for which there’s no compliant EU Comission decision.
We don’t transfer personal data to other recipients, with the exception when we are obligated by law. For more information on data protection through international data transfer (or a copy of it), we ask you contact our data protection officer via dpo@grapefruit.ro
e) Mandatory or voluntary supply of personal data and storage duration
Supplying the following data is necessary in order to make the contract with your behalf in order to contact for the purposes previously mentioned.
Full name (first and last name) and e-mail address
In case you do not transmit one of the solicited data we can’t transmit the personalized offer.
Supplying the following data is optional:
You are not obliged to supply all the personal data, and this data is not a legal requirement or based on contract or a necessary requirement to close a contract. If you do not supply the personal data, there will be no consequences what so ever.
We collect personal data:
Only children with ages 16 and over can give their consent. For children under this age, it is required to have parent consent or of a legal tutor.
f) Data storage duration
Grapefruit SRL can keep the processed data for different periods of time, considered to be reasonable, according to the scopes previously defined. We keep your data only for the required amount of time to reach that scope, for which we store the data, to satisfy your needs and to validate the obligations requested by law. To determine the duration for safe keeping, we take into consideration the quantity, nature and sensitivity of personal data, the scopes for which we process them and if we can reach those scopes through other means.
We must take into account the time periods for which we need to keep the personal data in order to fulfill legal obligations, handle complaints, questions and to protect the legal rights in case of any claims.
In order for us to know how long we need to keep your data, we use the following criterias:
When we don’t need your personal data anymore, we will safely delete or destroy them. Moreover, we will take into consideration if and how we can minimize (in time) the quantity of personal data that we use and if we can assure the anonymization of your personal data, so that the data is no longer associated with you or able to identify you, case in which we can use that information without notifying you in advance.
3. Your rights
As individual advised, you can contact our data protection officer at any moment and free of charge, with a notification, using the contact details mentioned above at section 1 c) in order to exercise your rights according to GDPR. These are the following rights:
We can process personal data that allow identifying your preferences and/or your behavior, including automated processes, which don’t require human intervention. For this, and for direct marketing, we will take into account your preferences.
You can honor these rights, either individual, or grouped, by sending a request at our office indicated at section 1 letter b) or via e-mail at office@grapefruit.ro |
. |
4. Processing security
Grapefruit SRL adopted technical and organisational measures to process data, updated according to GDPR guidelines, with the scope to protect your personal data against any unauthorized access, innapropriate use or transfer, unauthorized changes, distruction or accidental loss. All Grapefruit SRL employees and collaborators such as third parties that act in the name of or on behalf of Grapefruit SRL are obliged to respect your data confidentiality and the GDPR requirements, according to the present policy.
5. Personal data security
We apply strict procedures for storing and unveiling your personal data and to protect them against loss, distruction or accidental deterioration. The data you provide us are protected via SSL (Secure Socket Layer). SSL is a standard method in the encryption industry for personal data and information, so that it can be transferred safely on the internet.
All submission details are transmitted via a SSL connection with the help of a dedicated network infrastructure (Multiprotocol Label Switching – MPLS) and are stored according to Data Security standards.
It is possible for us to unveil your information to a trustworthy third party in scopes established through this privacy policy. We ask all third parties to apply technical and operational security measures for in order to protect your personal data, according to the Irish and UE legislation regarding data protection norms.
6. Processing contact and submission forms
Grapefruit SRL will use the information you provide in the site’s contact form exclusively to process your request.
By submitting personal data through picard.grapefruit.ro you understand and agree that your data will be processed via Grapefruit SRL’s DPP policies.
We ask you take into account the fact that in order to process your requests submitted via the submission form, it’s possible that, in some circumstances, we are obliged to send your data to Grapefruit SRL partners or to other third party service suppliers that Grapefruit works with.
With all this in mind, Grapefruit SRL adopted proper technical and organizational measures to assure the safety of data transfers, this also includes data processing according to GDPR requirements by the previously mentioned entities.
Grapefruit SRL is obliged not to process personal data in other scopes than the ones that were communicated, with the exception of cases where your consent exists for those purposes.
7. Personal data processing with partnerships
Part of the personal data processed through picard.grapefruit.ro can be transferred to other parties and you express your full consent to proceed in this manner, including the case when there’s a legal obligation towards Grapefruit SRL to proceed this way.
picard.grapefruit.ro can contain, at a certain time, access links to other sites with other/different data processing policies.
We ask you take into consideration consulting the personal data protection policies of other sites. picard.grapefruit.ro will not assume responsibility.
8. Accountability exoneration
picard.grapefruit.ro can have connections with other sites and/or pages which are not Grapefruit SRL property. Grapefruit SRL will not assume responsibility for the content of these websites, therefore, Grapefruit SRL cannot be held accountable for the content, advertisements, good, services, software, information or other resources made available on or through these sites. Grapefruit SRL will not be responsible for the loss of personal data, or for other negative effects on visitors’ personal data or other moral/patrimonial damages caused by accessing those websites.
9. Legal requests
We access, store and offer your information to regulatory authorities, implication factors of law or to other entities:
10. Automated data processing. Cookie
picard.grapefruit.ro uses cookies. Bellow you will find our Cookie Policy and you can exercise the right to deactivate cookies: This policy applies to using cookies on picard.grapefruit.ro, site managed by Grapefruit SRL.
What are cookies?
Cookie is a file in small size, formed out of letters and numbers, which will be stored on the computer, phone or other user devices that access the internet. Cookie is installed via a browser web-server request and it’s completely “passive” (it doesn’t include software, viruses or spyware and cannot access the information stored on the user’s hard drive).
What are cookies used for?
With these files the user’s device cand be recognized and the content can be displayed in a relevand manner, adapted to user preferences. Cookies assure the users have a pleasant navigation experience and support our efforts to offer comfortable services to the users (examples: online confidentiality preferences, shopping cart or relevant advertisements). Cookies are also used to prepare anonymous statistics, which helps us understand how a user interacts with our web page, thus allowing to improve structure and content, excluding so personal identification.
What cookies do we use?
We use two types of Cookies: temporary (limited per session) or persistent.
Temporary cookies are stored until the website or browser is closed. Persistent cookies are files that remain stored on the user’s device for an unlimited period of time until they are manually deleted by user.
What cookies are being used by picard.grapefruit.ro?
Grapefruti SRL uses cookies for the following scopes
Statistics
The website uses cookies for statistics/analytics in order to collect information about how visitors use the website and to detect possible navigation issues. The analytics tools store information about the pages visited, site visit duration, how the website is been accessed and page sections visited. Personal information is not stored, therefore, this information cannot be used to identify the user.
Grapefruit SRL uses analytics and statistics tools to track if the website meets the users' requests and to prioritize the ongoing processes.
Social media plug-ins
Our services use social media plugins. When you use a service that uses plugins, the information can be transferred directly from your device to the social media operator. We don’t have influence over the data collected by these plugins. If you are connected to your social media account, using our service can be linked to your social media account. If you interact with plug-ins such as “Like”, “Follow” or “Share”, or you submit a comment, the information might appear directly on your social media profile. If you are not connected to your social media account, it is possible that these plugins to transfer the IP address to the social media operators. We ask you to take into consideration this matter, when you use the websites. In our activity we use plugins from the following social media operators: Facebook, Linkedin, Twitter, Google MobilPay etc.
What information do cookies store?
Cookies store information in a small size text file, which allow a website to recognize a browser. The web server recognizes the browser until the cookie expires or it’s deleted. Cookies don’t request and don’t store personal data, to be used and, in most cases, they aren’t able to identify internet users. The personal data collected by using cookies can be collected to facilitate certain functionalities for the user. This data is encrypted in a way that makes impossible unauthorized access to them.
Why are cookies important?
Cookies represent the central stage of an efficient use of the Internet, helping generate a friendly navigation experience and adapted to the user’s preferences and interests. Refusing or deactivating cookies can make some websites impossible to use.
Refusing or deactivating the cookies doesn’t mean that you will not receive online advertisement – it means that it won’t take into account your preferences and interests, highlighted by your navigation behavior.
Example of important cookie usages (which don’t require user authentification through an account):
Security and confidential issues
Cookies are NOT viruses! They use plain text formats. They don’t contain bits of code, therefore cookies cannot be “executed” or “auto-played”. In consequence, they can’t duplicate or replicate on other networks to run or replicate again. Because they don’t have these functions, cookies cannot be considered viruses.
Cookies can be used for negative purposes. Because they store information regarding user preferences and navigation history, both on a certain website and on many other websites, cookies can be used as a form of Spyware. Many anti-spyware products are aware of this and they constantly mark cookies to be deleted during anti-virus/anti-spyware scanning procedures.
Generaly speaking, browsers have confidential settings integrated which supply different levels of cookie acceptance, availability period and automated deletion after the user visited a certain website.
Other security mentions for cookies
Because protecting the identity is valuable and represents the right of each user on the internet, it is indicated to be aware and know the possible problems created by cookies. Because through them, data is being transferred both ways constantly (from browser to website and viceversa), and if an attacker or an unauthorized individual intervenes during these transfers, the information stored by cookies can be intercepted. Although very are, this fact can happen if the browser connects to a server using a network without encryption (example: unsecured WiFi network).
Other attacks based on cookies imply wrong settings for server cookies. If a website doesn’t request the browser to use only encrypted channels, the attackers can use this vulnerability to trick the browsers in sending information through unsecured channels. Attackers then use the information to access certain websites unauthorized. It is important to be careful in choosing the best method to protect personal data.
Advice for a safe and responsible navigation based on cookies
Due to their flexibility and to the fact that the majority of the most visited and biggest websites use cookies, they are almost inevitable. Deactivating the cookies won’t allow user access on some of the wide-spread and most-used websites such as Youtube, Gmail, Yahoo, others.
Here are some advices that make you navigate without concerns using cookies:
Many of the detection applications and spyware prevention include detecting attacks on websites. This way, the browser is being blocked to access websites which can exploit browser vulnerabilities, or download malware software. Make sure you have the browser updated. Many of the attacks based on cookies are done exploiting weaknesses from older browser versions.
Cookies are everywhere and cannot be avoided, if you wish to enjoy access on the best websites on the internet — local and international. With a clear understanding of their operating methods and of their benefits, you can take the necessary security measures, so that you can navigate safely on the internet.
Deleting cookies
In general, an application used to access web pages, allows saving Cookies on the device by default. These settings can be changed so that automated cookie management to be blocked on web browser, or that user to be informed each time cookies are send to his/her device. Details regarding the cookie management methods can be found in the browser settings. Limiting your cookies can affect certain web page functionalities.
How can we stop cookies?
Deactivating and refusal to receive cookies can make certain sites unusable or difficult to visit and use. Moreover, refusing to accept cookies doesn’t mean you won’t receive/see online advertisements.
It is possible to set up for the browser to not accept these cookies, or accept cookies from a certain website. But, for example, if you are not registered using cookies, you cannot leave comments.
All modern browsers offer the possibility to change cookie settings. These settings are found in the “options” or “preferences” sections of your browser.
To understand these settings, the following links can be useful. You might also check the “Help” section of your browser.
For cookie settings generated by third parties you can check the following website: http://www.youronlinechoices.com/ro/
Useful links
If you wish to find out more about cookies and how are they used and for what, we recommend the following links:
Details about the cookies used
Required cookies help a website be usable by activating basic functions, like page navigation and access to secured areas within the site. The website cannot properly function without these cookies.
Statistics cookies help owners of a site understand the way visitors interact with the websites by collecting and reporting anonymous information.
Marketing cookies are used to follow users from one site to the other. The intention is to display relevant and dynamic ads for individual users, therefore they are more valuable for advertising agencies and other advertising third parties.
List of cookies
Due to the possibility of changes in legislation, modifications of these notifications regarding data protection might become necessary. In this case, we will inform you of these modifications. In case a change alters a processing which has your consent, we will solicit a new consent, if necessary.
By checking the acceptance checkbox you express your agreement to process your personal data for the scopes presented above, which means we will use your personal data to send you information via e-mail, SMS, letter, phone or fax.