Privacy Policy
INFORMATION NOTICE REGARDING THE PROCESSING OF PERSONAL DATA
MCG DEVELOPMENT SYSTEMS SRL
WHAT THIS INFORMATION NOTICE COVERS.
This Information Notice is designed to inform you about the aspects related to the processing of your personal data and about your rights regarding this processing in accordance with General Regulation 2016/679 on data protection ("GDPR") and the national legislation in force.
We, the company MCG DEVELOPMENT SYSTEMS SRL. (the "Company"), wish to inform you about the processing of your personal data in connection with certain operations carried out by the Company.
In this information notice we explain how your personal data is processed by MCG DEVELOPMENT SYSTEMS SRL and how we ensure that your personal data is processed responsibly and in accordance with the applicable personal data protection legislation.
This notice contains important information. Therefore, please take the time necessary to read it in full and carefully and to make sure that you fully understand it, as we want it to be clear to you how we use your data and how we protect it.
To make the document easier to navigate, we have included at the end of this notice a glossary explaining the main concepts used (e.g. “personal data”, “processing”, etc.).
HOW YOU CAN CONTACT US
The content of this information notice is purely informative and does not affect the rights granted to you by law. We will do everything possible to make it easier for you to exercise them. If you have any comments, suggestions, or questions regarding any information in this notice or regarding any other aspects related to the processing of your data that we carry out, please do not hesitate to contact our data protection officer at any time. Depending on your preferences, you can contact us through any of the communication channels below:
Full name: MCG DEVELOPMENT SYSTEMS SRL.
Registered office: CALEA MOSILOR 158 E
Telephone number: +40 743 444 963
Email address: office@mcgsystems.ro
Contact details of our data protection officer (this is the person you should contact regarding any matters related to the protection of your personal data):
Correspondence address: CALEA MOSILOR 158 E
Email address: office@mcgsystems.ro
Our information notice has been public since 08 November 2025 and applies to our website: www.mcgsystems.ro and to our email.
THE CATEGORIES OF PERSONAL DATA THAT WE PROCESS
The data of yours that we will process is ordinary personal data obtained directly from you or from third parties who had permission to exchange information with us, and may include the following categories of data:
- surname; first name; sex; date of birth / age; citizenship; home / residence address, mobile/landline telephone number, fax number; email address;
- video recordings (on our premises where we have CCTV video surveillance cameras installed – where these exist, they are indicated by visible signs); personal numerical code (CNP); the rest of the information from your identity document (including the issue date, the expiry date of the document, the place of birth);
- your contact with us such as requesting a quote, an email, or other records of a contact with us;
- payment-related data: billing address, bank account or bank card number / IBAN code, the surname and first name of the holder of the bank account or bank card (this may be someone other than you if someone else made the payment of an invoice on your behalf and for you); the date from which the bank card is valid; the expiry date of the bank card
- professional data: employer; position.
- opinions and views (may include sensitive data), such as: any opinions and views you send us or any opinions and views you post publicly about us on social media or make known through other public channels;
- data related to purchases and interaction with us, such as: records of your interactions with us; details related to the history of your purchases from us;
We will collect your ordinary personal data when, for example:
- You buy or use any of our products and services (upkeep and maintenance);
- You subscribe to newsletters, alerts or other services offered by us;
- You contact us through various channels, or request information from us regarding a product;
- You visit or browse our website;
- You have given permission to other companies, such as our commercial partners or our associates, as well as in situations where we transmit such data to third-party suppliers or contractors of ours, insofar as we have legal grounds, for example: banking financial institutions, accounting service providers, public authorities or institutions, notaries, lawyers, etc.;
- When your personal data is public;
- We use cookies (small text files stored in your browser) and other techniques such as web beacons (small, transparent image files used to track your movements on our website).
Our respect for your data includes the fact that we give it the necessary human attention, through our staff. Under current conditions, you will not be subject to a decision of ours based solely on the automated processing of your data (including profiling) that produces legal effects concerning you or that affects you in a similar way.
THE GROUNDS ON THE BASIS OF WHICH WE PROCESS YOUR DATA
MCG DEVELOPMENT SYSTEMS SRL. will process your ordinary personal data on the basis of the following grounds:
- The performance or conclusion of the contract with you. For example, with a view to initiating, conducting and finalizing negotiations in order to be able to conclude a contract with you, at your request, or to perform a contract concluded with you;
- The consent that you grant. For example, with respect to our marketing communications, we process your data on the basis of consent to processing for this specific purpose.
- Compliance with a mandatory legal requirement. For example, accounting and tax requirements that are subject to strict internal policies such as the retention period of tax/accounting documents. We may process your data for the fulfillment of our archiving obligations, our obligations to communicate certain information to public authorities upon request, or of other legal obligations.
- Our legitimate interest. There are also cases in which we process your data for maintaining network security, improving our services.
THE PURPOSES FOR WHICH WE PROCESS YOUR PERSONAL DATA
The purposes for which we process personal data relating to you are as follows:
- To provide our service. To provide the products and services you have purchased from us, as well as to keep you informed about the purchase process;
- Billing and customer relations. To bill you for the purchase of our products and services, to contact you in the event that the billing details you have provided to us are incorrect, about to expire or we cannot collect payment, to respond to any questions or concerns you may have regarding our products and services;
- Marketing communications. To the extent that you have given your consent, we will be able to keep you informed through various means (for example, email, mobile or landline telephone, telephone messages (SMS), post, messages sent on social media platforms or in person) about news regarding products, available services, offers regarding them, newsletter subscription or the provision of other information that might interest you. You can control your marketing permissions and the data we use to individualize these communications at any time on our website www.mcgsystems.ro or using the contact details in the ”How you can contact us” section above.
- Managing our communications and IT (information technology) systems. Managing our communications systems; managing our IT security; carrying out security audits on our IT networks, issuing reports to authorized institutions or repairing system errors;
- Fulfilling our legal obligations. Fulfilling our legal obligations regarding archiving, security, record-keeping and other obligations that the legislation imposes on us.
- Improving products and services. Identifying potential problems regarding our existing products and services with a view to improving them, resolving your reports;
- Surveillance of the premises in accordance with legal provisions. The CCTV systems installed for the surveillance of the premises related to access routes, areas with valuables, for monitoring and streamlining the activities carried out and for the protection of goods and personnel located in those office spaces, etc.
- Research and analysis. We use analysis methods for:
- market research and for carrying out research and statistical analyses;
- the provision of reports to third parties (these reports do not contain information that could identify you as a natural person). These may be provided to third parties, such as content providers and entities that advertise the products and services offered by us.
We have strict rules that ensure the anonymization or removal of identifying elements from personal data.
TO WHOM WE WILL DISCLOSE YOUR DATA
As a general rule, we do not disclose your data to other companies, organizations or persons in any country (including Romania). There are, however, certain situations in which, according to the law, we must communicate your data to other natural or legal persons.
We try, however, to be as transparent and specific as possible, and below we will present the categories of such recipients:
- In the event that you request us or give us consent to this effect;
- Persons who can demonstrate that they hold the legal authority to act on your behalf;
- Other companies in the group – for legitimate reasons related to our activity in accordance with applicable legislation;
- Public authorities: at their request or on our initiative, in accordance with applicable legislation;
- Accountants, auditors, lawyers and other external professional consultants, contractual partners, service providers of ours who act as processors or joint controllers – these will be obliged by a law or by the contract concluded with us to maintain the confidentiality of your data, e.g.: archiving, accounting, storage, destruction, premises surveillance services.
- An agency, bailiff or court in Romania – to the extent necessary for the establishment, exercise or defense of a legal right;
- in the event that it is our legitimate interest to do so in order to administer, expand or develop the commercial activity, for example in the event that we sell or transfer all or part of our shares, our assets or our business (including in the event of our reorganization, dissolution or liquidation), in which situation the personal data held by us will constitute one of the transferred assets – in this situation the potential acquirers will be bound by a confidentiality obligation.
When we use a natural or legal person as a processor for the processing of your personal data, we will ensure that it has concluded a Personal Data Processing Agreement through which it assumes, among other obligations that the personal data protection legislation provides, the obligations to (i) process personal data only in accordance with our written instructions provided to it in advance and to (ii) effectively implement measures to protect the confidentiality and ensure the security of personal data. We will also ensure that this contract between us and the processor provides for it at least all the other obligations provided by the applicable legislation regarding the protection of personal data.
HOW LONG WE WILL STORE YOUR DATA
We will store your data for as long as required by law. If there is no legal requirement we will store it only for as long as necessary for the processing of the data for the purposes mentioned above.
Except where the law provides otherwise, as a rule we will process your data for the duration of the existence of a contract or agreement between you and MCG DEVELOPMENT SYSTEMS SRL, plus a period of 3 years from its termination, for example for granting the lifetime warranty on the tubs purchased by you.
For storing your data in electronic format, we use our own servers or those of other companies specialized in electronic archiving.
THE SECURITY OF YOUR DATA
We have implemented the following technical and organizational measures to ensure the security of personal data:
- Dedicated policies. We adopt and review our practices and policies for processing the data of our customers and other persons, including physical and electronic security measures, to protect our systems from unauthorized access and other possible threats to their security. We constantly check how we apply our own personal data protection policies and how we comply with data protection legislation.
- Data minimization. We have ensured that the personal data of yours that we process is limited to that which is necessary, adequate and relevant for the purposes stated in this notice.
- Restricting access to data. We strictly restrict access to the personal data we process to employees, collaborators and other persons who need to access it in order to be able to process it for us. All these companies and natural persons are subject to strict confidentiality obligations and we will not hesitate to hold them accountable and to cease collaboration with them in the event that they do not comply with the policies regarding the protection of your data and that of other persons.
- Specific technical measures. We use technologies that assure our customers and other persons that the security of their data is protected. To protect the security of your data, we recommend that you do not use public (unsecured) workstations or workstations with multiple access, and also that you not hand over to other persons the paper document on which your data or passwords are written.
- Back-ups and security audits. We carry out daily back-ups (archives), which we keep securely for a minimum of six (6) months. All the technical equipment we use for processing your data is secured and updated to protect the data. We also carry out, at regular time intervals, security audits on the IT systems we use for processing the personal data of our customers and other persons.
- Ensuring the accuracy of your data. It is possible that from time to time we may ask you to confirm the accuracy and/or the up-to-date status of the personal data relating to you that we process.
- Staff training. We constantly train and test our employees and collaborators regarding the legislation and best practices in the field of personal data processing.
- Data anonymization. In compliance with the law, we anonymize / pseudo-anonymize the personal data we process, so that the persons to whom it relates cannot be identified.
- Control of our service providers. We introduce into the contracts with those who process for us (processors) or together with us (other controllers – joint controllers) clauses for ensuring the protection of the data we process, in accordance with what the law imposes.
WHAT YOUR RIGHTS ARE AND HOW YOU CAN EXERCISE THEM
We treat with seriousness and full involvement the rights that you have in connection with the processing that we carry out on the data relating to you. Your rights are the following:
- The right of access to data. You have the right to request information related to the personal data we hold about you, including information related to the categories of data we hold or control, what these are used for, the source from which we collected them if we obtained them indirectly, and to whom this data is disclosed, if applicable. We will provide you with a copy of your personal data upon request.
- The right to rectification of data. You have the right to obtain the rectification of your data that we process, if it is not correct.
- The right to erasure of data (“the right to be forgotten”). You have the right to obtain from us the erasure of your data that we process or control. MCG DEVELOPMENT SYSTEMS SRL seeks to process and retain your data only for as long as this is necessary. We must comply with this request if we process your personal data, and if:
- the personal data is no longer necessary for the fulfillment of the purposes for which it was collected;
- you object to the processing for reasons related to your particular situation;
- your data has been processed unlawfully;
- the personal data must be erased for compliance with a legal obligation incumbent upon us;
except in the case where your data is still necessary:
- for the exercise of the right to freedom of expression and information
- to comply with a legal obligation that we have;
- for archiving purposes in the public interest, scientific purposes or for historical studies or for statistical purposes; or
- for the establishment, exercise or defense of a right in court.
- The right to restriction of data processing. You can obtain from us the restriction of the processing of your personal data, in the event that:
- you contest the accuracy of your personal data, for the period we need to verify the accuracy,
- the processing is unlawful, but you object to the erasure of the personal data, requesting instead the restriction of its use,
- there is no longer a need to retain your personal data but you request it for the establishment, exercise or defense of a right in court, or
- you object to the processing, for the time interval in which it is verified whether, from a legal point of view, the processing of the data is necessary.
- The right to object to the use of personal data. You have the right to object to the processing of your data by us or on our behalf. Where the processing is not based on your consent but on our legitimate interests or those of a third party, you can object at any time to the processing of your personal data for reasons related to your particular situation. In this case we will no longer process your personal data, except in the case where: (a) we can demonstrate legitimate and compelling reasons that justify the processing or (b) in the case where the purpose is the establishment, exercise or defense of a right in court.
If you object to the processing, please specify whether you also wish for your personal data to be erased, otherwise we will only restrict it.
You can always object to the processing of your personal data for marketing purposes, whatever your reason may be. If the marketing was based on your consent, you can withdraw your consent.
- The right to data portability. You have the right to receive your personal data that you have provided to us, and where it is technically feasible, to request that we transmit your personal data (that you have provided to us) to another organization.
These two rights are rights that you have if, cumulatively: (a) we process your personal data by automated means, (b) we base, in the processing of your personal data, on your consent or the processing by us of your personal data is necessary for the conclusion or performance of a contract to which you are a party; (c) your personal data is provided to us by you, and (d) the transmission of your personal data does not have a negative effect on the rights and freedoms of other persons.
You have the right to receive your personal data in a structured, commonly used and machine-readable format.
Your right to receive personal data must not have a negative effect on the rights and freedoms of other persons. This could happen if a transmission of your personal data to another organization also involves the transmission of the personal data of other persons (who do not give their consent for this transfer).
The right for your personal data to be transmitted by us to another organization is a right that you have if this transmission is technically feasible.
- The right to withdraw consent. In the situations in which we process your data on the basis of your consent, you have the right to withdraw your consent; you can do this at any time, at least as easily as you initially granted us consent. The withdrawal of consent will not affect the lawfulness of the processing of your data that we carried out before the withdrawal.
- The right to lodge a complaint with the supervisory authority. If you have a dissatisfaction regarding the way in which we process your data, please contact us directly so that we can resolve your problem. If you still have dissatisfactions, you can contact the National Supervisory Authority for Personal Data Processing (www.dataprotection.ro):
Address: B-dul G-ral. Gheorghe Magheru, Bucharest, Romania;
Telephone: 40.318.059.211/ +40.318.059.212
Fax: +40.318.059.602;
E-mail: anspdcp@dataprotection.ro
| Please note |
To exercise one or more of these rights or to address any question about any of these rights or other aspects of the processing of your data by us, please use whenever you wish the contact details in the ”How you can contact us” section above, as well as the support form available on our website www.mcgsystems.ro. At the same time, printed forms are also available at our registered office which you can fill in to request the exercise of one or more of the above rights.
We will try to respond to your request within one month, a period which may be extended by two months due to specific reasons related to the specific right invoked or to the complexity of your request. In any case, if this period is extended, we will inform you regarding the extension deadline and the reasons that led to this extension.
In certain situations we might not be able to grant you access to all or part of your personal data due to legal restrictions. If we refuse your request for access, we will communicate to you the reason for this refusal.
In certain cases, we might not be able to identify your personal data due to the identifying elements you provide to us in the request. In such cases, if we cannot identify you as the data subject, we cannot act on your request in accordance with this section, except in the case where you provide us with additional information that allows us to identify you. We will inform you and give you the possibility to provide us with such additional details.
WHAT MAY HAPPEN IF YOU DO NOT PROVIDE US WITH THE DATA
You have no obligation to provide us with your personal data that we have mentioned in this document. In this case we might not be able to provide you with the services you request from us.
CHANGES REGARDING THE INFORMATION NOTICE
We reserve the right to modify, to improve when necessary, our data protection practices and to update and modify this information notice at any time, in order to ensure that your data is safe. For this reason, we encourage you to check this information notice periodically.
THE MEANING OF SOME TERMS USED WITHIN THIS NOTICE
| What does processing of personal data mean? | Processing of personal data means any operation or set of operations performed on personal data or on sets of personal data, with or without the use of automated means, such as collection, recording, organization, structuring, storage, adaptation or modification, extraction, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
| What does personal data mean? | Personal data means any information regarding an identified or identifiable natural person (the "data subject"); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier, or to one or more specific elements proper to their physical, physiological, genetic, mental, economic, cultural or social identity. |
| What does personal data controller mean? | Personal data controller means the natural or legal person, public authority, agency or other body which, alone or together with others, establishes the purposes and means of processing personal data. |
| What does Processor mean? | The natural or legal person, authority or other body which alone or together with others decides why (for what purpose) and how (by what means) personal data is processed. According to the law, the responsibility for compliance with the legislation regarding personal data lies primarily with the controller. In the relationship with you, we are the controller, and you are the data subject. |
| What does Data subject mean? | The data subject is the natural person to whom (to whom certain personal data “belongs”) certain personal data refers. In the relationship with us (the controller), you are the data subject. |
| What is the Supervisory Authority? | An independent public authority which, according to the law, has responsibilities regarding the supervision of compliance with personal data protection legislation. In Romania, this supervisory authority for personal data processing is the National Supervisory Authority for Personal Data Processing (ANSPDCP) |