Privacy policy

1. Controller

Personal data collected through this website is processed by DELTAMED S.R.L., Str. Muncii 33–37, Gilău, RO-407310, Cluj County, Romania, trade register number J1997000845120, tax identification number RO9434372, telephone +40 264 371 568.

For anything concerning your personal data, write to dpo@deltamed.ro. Requests about job applications and CVs can also be sent to hr@deltamed.ro.

2. What this policy covers

This policy describes how we handle personal data collected through this website: when you create an account, place an order, request a quote, apply for a job, contact us, or simply browse. Personal data means any information relating to an identified or identifiable person, including names, contact details, addresses and online identifiers such as an IP address.

3. What we collect, why, and on what legal basis

Account and orders. Name, e-mail, telephone, billing and delivery address and, for company accounts, company name and VAT or registration number. We use this data to create your account, process and deliver orders, issue invoices and provide customer service. Legal basis: performance of the contract (Article 6(1)(b) GDPR) and, for invoicing and accounting, compliance with a legal obligation (Article 6(1)(c)).

Company data verification. When you register a company account or enter a VAT number, we query the public registers of the Romanian tax authority (ANAF) and the European Commission (VIES) to confirm that the number is valid and to determine the correct VAT treatment. Legal basis: legal obligation and legitimate interest in preventing incorrect invoicing.

Payments. Card payments are processed by our payment provider on its own infrastructure. We receive confirmation that a payment succeeded or failed, never your card number. Legal basis: performance of the contract.

Loyalty programme. Your order history, points balance and level. Legal basis: performance of the contract, since the programme is part of the terms you accept.

Returns and complaints. The description of the request, any documents or photographs you upload, and — where a refund is made by bank transfer — the account holder’s name and IBAN. Legal basis: performance of the contract and compliance with consumer protection law.

Quote requests. The contact details and technical specifications you send us through the configuration form. Legal basis: steps taken at your request prior to entering into a contract (Article 6(1)(b)).

Job applications. The data in your application and CV. Legal basis: steps prior to a possible employment contract and your consent for storage beyond the current recruitment process.

Contact messages. The message and the data attached to it, processed until the matter is settled. Legal basis: legitimate interest in answering enquiries.

Technical data. Our server and our security provider record the IP address, browser type, date and time of access and the pages requested. This data is used to keep the website available and secure. Legal basis: legitimate interest in the security and stability of the service.

4. How long we keep it
  • Account data: for as long as your account exists. When you close it, we delete the account and keep only the order and invoicing records the law obliges us to keep.
  • Orders, invoices and accounting records: for the retention periods required by Romanian accounting and tax legislation.
  • Returns and complaints: three years from the closing of the request.
  • CVs and job applications: maximum three years, unless you ask us to delete them earlier — write to hr@deltamed.ro.
  • Quote requests and contact messages: until the matter is settled, and afterwards only where a legal obligation requires it.
  • Technical logs: for a short period, for security and troubleshooting.

5. Who else sees your data

We do not sell or rent personal data. We share it only with the service providers we need in order to run the website and fulfil orders, each acting on our instructions and under a data processing agreement:

  • the provider of the infrastructure on which this website runs, and Cloudflare, our network security provider;
  • Netopia Payments, for card payments;
  • DPD, our carrier — name, address and telephone number, so that the parcel can be delivered;
  • the service that delivers our transactional e-mails.

We also disclose data where the law requires it, to public authorities acting within their powers, and to our accountants and auditors in the context of our statutory obligations. In the event of a merger, acquisition or insolvency, data may pass to the successor entity; we would announce this on the website.

6. Transfers outside the European Economic Area

Our providers process data within the European Economic Area. Cloudflare operates a global network and may process limited technical data outside the EEA; those transfers take place under the standard contractual clauses adopted by the European Commission.

7. Your rights

You have the right to obtain access to your data, to have inaccurate data corrected, to have data erased, to obtain the restriction of processing, to receive the data you provided in a structured, commonly used and machine-readable format and have it transmitted to another controller, and to object to processing based on our legitimate interests. Where processing is based on consent, you can withdraw it at any time; this does not affect the lawfulness of processing carried out before the withdrawal.

Much of this you can do yourself: the details in your account can be edited at any time, and orders and invoices remain available there.

To exercise any of these rights, write to dpo@deltamed.ro. We reply within one month; if the request is complex, we may extend that period by two further months and will tell you why.

You also have the right to lodge a complaint with the Romanian supervisory authority — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, B-dul G-ral. Gheorghe Magheru 28–30, Bucharest, dataprotection.ro — or with the supervisory authority of the country where you live.

8. Security

The website runs over an encrypted connection. Access to personal data inside the company is limited to the people who need it for their work. Passwords are stored in hashed form and cannot be read by our staff. We do not store card data.

9. Automated decisions

We do not take decisions about you based solely on automated processing, and we do not profile you.

10. Children

This website is not addressed to children. Accounts may only be created by persons over 18.

11. Changes to this policy

We update this policy whenever the way we process data changes. Last updated: 30 August 2026.