1. General Information
This Privacy Policy explains how we collect, use, store, and protect the personal data of users who access the Atelier Toma website.
The data controller is:
PFA TOFAN M RUXANDRA
Tax Identification Number (CUI): 51239828
Trade Registry Number: F2025003513001
Registered in: Bucharest, Romania
Email: pielarit@gmail.com
Phone: +40 770 256 290
We comply with the EU General Data Protection Regulation (GDPR – Regulation 2016/679).
2. Data We Collect
We only collect data necessary for processing orders and ensuring the proper functioning of the website.
Data provided directly by the user
• Full name
• Delivery address
• Email address
• Phone number
• Billing details
• Messages sent through the contact form
• Personalization details for custom products (initials, text, preferences)
Data collected automatically
• IP address
• Device type
• Browser and operating system
• Pages visited
• Time spent on the website
• Essential cookies required for site functionality
We do not collect sensitive data.
3. Purpose of Data Collection
Personal data is used exclusively for:
• processing and delivering orders
• communicating with customers
• issuing invoices
• managing returns and warranty claims
• improving website performance and user experience
• preventing fraud
• fulfilling legal and accounting obligations
We do not sell or rent personal data to third parties.
4. Legal Basis for Processing
We process personal data based on:
• contract performance (order processing)
• consent (newsletter, optional cookies)
• legitimate interest (website security, fraud prevention)
• legal obligations (invoicing, accounting)
5. Data Sharing
Data may be shared only with partners essential to our operations:
• courier companies
• payment processors
• IT and hosting service providers
• accounting services
• authorities, only when legally required
All partners are required to protect personal data and comply with GDPR.
6. Data Storage
Data is stored securely and retained only for the necessary period:
• Order data: 5–10 years (legal and accounting requirements)
• Customer account data: until the account is deleted
• Newsletter data: until the user unsubscribes
• Contact form messages: as long as needed to resolve the request
7. Cookies
Our website uses cookies to ensure proper functionality and improve user experience.
Types of cookies:
• Essential cookies – required for the website to function
• Analytics cookies – used to understand how visitors interact with the site
• Marketing cookies – used only with user consent
Users can manage cookie preferences directly from their browser settings.
8. User Rights (GDPR)
Users have the following rights regarding their personal data:
• Right to access
• Right to rectification
• Right to erasure (“right to be forgotten”)
• Right to restrict processing
• Right to data portability
• Right to object
• Right to withdraw consent at any time
• Right to lodge a complaint with a supervisory authority
To exercise these rights, users may contact us at pielarit@gmail.com.
9. Data Security
We implement technical and organizational measures to protect personal data against:
• unauthorized access
• loss or theft
• alteration
• disclosure
However, no online transmission is 100% secure, and users acknowledge this inherent risk.
10. Third‑Party Services
Our website may include links to external websites. We are not responsible for their privacy practices. Users should review the privacy policies of those websites separately.
11. Updates to This Policy
We may update this Privacy Policy periodically. The latest version will always be available on this page. Continued use of the website implies acceptance of any updates.
12. Contact
For questions regarding this Privacy Policy or your personal data, please contact us at:
pielarit@gmail.com