Privacy Policy
This Privacy Policy explains how NICMAR-DANCI SRL collects and processes personal data when you visit our website or contact us for business purposes, including B2B inquiries, requests for quotation and supplier discussions.
1. Data Controller
NICMAR-DANCI SRL is the data controller for the processing of personal data described in this Privacy Policy.
Company details
S.C. NICMAR-DANCI S.R.L.
Drumul Cetății, nr. 85, 420063 Bistrița, Bistrița-Năsăud, Romania
EUID: ROONRC.J1999000062066 · CUI: RO11548999
Email: office@nicmardanci.ro
Data Protection Contact: office@nicmardanci.ro
2. Categories of personal data
- Identity and contact data: name, company, job title, email address and phone number.
- Business communication data: inquiry details, RFQ content, technical files submitted and email correspondence.
- Technical data: IP address, browser/device information, access logs and security logs.
- Analytics data: website usage data collected through Google Analytics 4 only after your explicit consent.
3. Sources of personal data
- Directly from you, when you contact us by form, email, phone, meeting or RFQ submission.
- From your organization, where you act as a representative, employee or contact person.
- From our website, through technical logs and, if accepted, analytics technologies.
4. Purposes of processing
- To respond to inquiries, RFQs and business requests.
- To prepare quotations and carry out technical or feasibility reviews.
- To manage B2B communication, follow-up and customer or supplier relationships.
- To operate, secure and improve our website.
- To prevent spam, abuse and automated submissions through security tools such as reCAPTCHA.
- To comply with applicable legal, tax, accounting or audit obligations.
5. Legal bases under GDPR
- Legitimate interests — Article 6(1)(f) GDPR: B2B communication, responding to requests, relationship management, website security, service improvement and spam/fraud prevention.
- Contractual necessity — Article 6(1)(b) GDPR: steps prior to entering into a contract and performance of a contract, where applicable.
- Legal obligations — Article 6(1)(c) GDPR: compliance with applicable legal obligations.
- Consent — Article 6(1)(a) GDPR: analytics cookies and Google Analytics 4, only when you explicitly accept them through the cookie banner.
6. Third-party services and data sharing
We do not sell personal data. The third-party services below may process personal data in connection with the website. Where required, appropriate contractual safeguards are used with these providers.
| Service | Provider | Purpose | Data | Legal basis | Transfer |
|---|---|---|---|---|---|
| Google Analytics 4 (GA4) | Google Ireland Limited | Website analytics, loaded only after consent. | IP address with anonymization, browser information, pages visited and session data. | Consent | EU/USA safeguards |
| Google reCAPTCHA v3 | Google Ireland Limited | Spam and bot prevention on the RFQ/contact form. | IP address, browser information and interaction data. | Legitimate interest | EU/USA safeguards |
| Google Maps | Google Ireland Limited | Displaying the location map in the contact section. | IP address and browser information. | Legitimate interest | EU/USA safeguards |
| Google Fonts | Google Ireland Limited | Serving the Montserrat typeface used by the website. | IP address and browser information transmitted on page load. | Legitimate interest | EU/USA safeguards |
| Website hosting | Cloud Agency SRL or another hosting provider | Hosting, serving and securing the website. | Server logs, IP address, timestamp, accessed pages and contact form submissions. | Legitimate interest | Romania/EU |
Google Analytics 4 is configured with IP anonymization enabled and Google Signals / ad personalization disabled.
7. International transfers
Some service providers, especially Google services, may process data outside the European Economic Area. In such cases, we rely on safeguards required by GDPR, including Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
8. Retention periods
- RFQ and B2B communication data: retained for the duration of the business relationship and up to 5 years thereafter for traceability, legal or audit purposes.
- Technical and security logs: retained for up to 12 months.
- GA4 analytics data: retained for 14 months, according to the GA4 data retention settings.
- reCAPTCHA data: retained according to Google’s applicable retention policies.
- Cookie consent choice: stored in your browser local storage until you change or delete it.
9. Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure or destruction. These measures include HTTPS encryption, access controls, server-side security and spam prevention tools. However, no online transmission can be guaranteed to be fully secure.
10. Your rights
Subject to GDPR and applicable law, you have the following rights:
- Right of access to your personal data — Article 15 GDPR.
- Right to rectification of inaccurate or incomplete data — Article 16 GDPR.
- Right to erasure, where applicable — Article 17 GDPR.
- Right to restriction of processing — Article 18 GDPR.
- Right to data portability for processing based on consent or contract — Article 20 GDPR.
- Right to object to processing based on legitimate interests — Article 21 GDPR.
- Right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal — Article 7(3) GDPR.
To exercise your rights, contact us at: office@nicmardanci.ro. We will respond within 30 calendar days of receiving your request.
11. Cookies and analytics
For full details about cookies used on this website, please read our Cookie Policy.
Google Analytics 4 is loaded only after your explicit consent through the cookie banner. If you reject analytics cookies, no GA4 script is loaded and no analytics data is collected. You may change your analytics preference at any time by opening Cookie settings.
12. Complaints
If you consider that your rights have been violated, please contact us first. You also have the right to lodge a complaint with the Romanian supervisory authority or with your local supervisory authority in the EU/EEA.
-
ANSPDCP — Romanian National Supervisory Authority for Personal Data Processing
www.dataprotection.ro · anspdcp@dataprotection.ro · +40 31 805 9211
13. Children
This website is intended for business users and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe that such data has been collected accidentally, please contact us immediately.
14. Updates to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The “Last updated” date indicates the most recent revision.
15. Contact
For all privacy-related requests or questions, please contact us at:
NICMAR-DANCI SRL
Drumul Cetății, nr. 85, 420063 Bistrița, Bistrița-Năsăud, Romania
Email: office@nicmardanci.ro
Phone: +40 (0) 740 411 862