The security and confidentiality of your personal data is a priority for us. This document transparently sets out how we collect, use, store, share and protect your data when you access and make purchases on our platform.
1. Data Controller Identity
- Name: S.C. SAB Mobility S.R.L.
- Registered office: Drumul Gura Caliței, nr. 4-32, bl. 5, sc. A, ap. B23, sector 3, Bucharest
- CUI: RO54277788 · Trade Register: J2026017816007 · Share capital: 1000 RON
- GDPR contact email: mob_sab@yahoo.com
2. Data Categories, Purposes and Legal Bases
A. Order processing — name, delivery/billing address, phone, email. Purpose: receiving, validating, shipping and managing orders, including returns. Basis: Art. 6(1)(b) GDPR (contract performance).
B. Legal and tax obligations — name, billing address, transaction details. Purpose: invoicing, accounting and legal reporting. Basis: Art. 6(1)(c) GDPR (legal obligation).
C. Marketing (newsletter) — name, email, phone. Basis: Art. 6(1)(a) GDPR (consent, withdrawable anytime).
D. Platform maintenance and security — IP address, browser type, cookie identifiers. Basis: Art. 6(1)(f) GDPR (legitimate interest).
3. Data Recipients (processors)
- Courier companies (e.g. Sameday, FAN Courier, Cargus) — product delivery.
- Payment processor — Netopia Payments — secure card payment processing. Card data is never stored or accessed by our servers.
- Invoicing provider — Oblio — generating fiscal documents.
- Hosting/cloud providers — hosting within the European Economic Area.
- Public authorities (tax authority, ANPC, courts, police) — under legal obligations.
4. International Data Transfer
Data is stored on servers within the European Economic Area (EEA). Where providers transfer data outside the EEA, transfers are protected by EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
5. Retention Period
- Invoice data: 10 years (accounting obligation).
- Account and order history: while the account exists; on request the account is anonymized or deleted, except data subject to tax obligations.
- Marketing data: until consent is withdrawn.
6. Data Security
- Encryption of data flows via SSL certificates (HTTPS).
- Pseudonymization/tokenization of sensitive (payment) data.
- Strict access control and regular backups.
7. Your Rights (GDPR)
You have the right of access, rectification, erasure, restriction, portability and objection. Exercise them free of charge by emailing mob_sab@yahoo.com. You may also lodge a complaint with the Romanian Data Protection Authority (ANSPDCP), www.dataprotection.ro.