Privacy Policy
Thank you for your interest in our services. When you enter into any kind of relationship with us, you entrust us with your information. The information presented below is important. We recommend that you read it carefully.
The purpose of this notice is to explain what data we process (collect, use, share), why we process it, how we process it, your rights under the GDPR and how you can exercise those rights. In collecting this information, we act as a controller and, by law, we are required to provide you with this information. If you do not agree with what is described below, please do not use our services or products.
BOOKR TECHNOLOGIES S.R.L., a Romanian legal entity, with its registered office at Cluj-Napoca, Calea Dorobanților no. 25, ap. 33, Cluj county, having sole registration code 43550695 and trade register number J12/129/13.01.2021, is a personal data controller.
According to the law, you — the individual who benefits from our products and/or services, the representative or contact person of a company, or the person in any kind of relationship with our company — are a “data subject”, that is, an identified or identifiable natural person.
We use the data only for the purposes described at the time of collection or for new purposes compatible with the original ones. In all cases, our purposes are compatible with the law. We take reasonable measures to ensure that personal data is accurate, complete and up to date.
If you have questions or concerns about the processing of your data or wish to exercise your legal rights in relation to the data we hold, or if you have concerns about how we handle any privacy matter, you can write to us at the following contact details:
Bookr contact details
E-mail: [email protected]
We process the following personal data: first and last name (mandatory), e-mail address, phone number (mandatory), password, photographs (mandatory), location.
We collect most information directly from you (for example, by filling in a form on the website/application). Most of the information is described above, but there may be situations in which we collect data from third parties (i.e. partners, advertising platforms), such as, for example, information about purchases and interests.
Access to the information on your device will be requested only for better and personalized operation of the application. You may refuse this access, accepting that certain features of the application or of the website will not be available to you.
In addition to the information indicated above, we may also collect the following information, depending on the circumstances:
- How you interact with our website or with advertisements (for example, information about how and when you access our website or which device you use to access the site);
- Information provided when you fill in forms or questionnaires;
- The content of messages sent through messaging and e-mail systems;
- The interactions between you and us on social networks (for example, likes, shares, comments);
- Information we collect about you from other group companies or third parties that have obtained your consent or have another legal right to share this information with us (including publishing or advertising partners/platforms and data aggregators that have obtained that right).
Where you make purchases, certain payment information (card details) will be collected, but it will be stored by our processing partners in a way that we cannot read and to which we cannot have access. We will only be informed whether the purchase was completed successfully.
We may collect data through cookies or other similar technologies, such as:
- IP address
- Internet browser
- Location
- The web pages you access on our website
- Other data
We collect personal information for the following purposes:
- To respond to your questions and requests and to provide you with customer support;
- For marketing purposes;
- To provide and improve the services and products we offer;
- To diagnose or fix technical problems;
- To defend against cyber attacks;
- To comply with the law, such as complying with tax legislation that requires us to keep accounting documents for a period of 10 years;
- To establish or assert a right in court;
- For analytical and research purposes;
- To run promotions and contests;
- To prevent crimes, deception or fraud.
We may rely on the following legal bases, depending on the specific case:
- Consent for the processing of personal data;
- Processing is necessary for the purposes of our legitimate interests or those of another party, except where your interests, rights or freedoms override them;
- Processing is necessary to fulfil legal obligations;
- In some situations, processing may be necessary to protect your vital interests or those of another natural person.
We store your personal data only for the period necessary to fulfil the purposes, but no longer than one year from the last interaction with us. After the period ends, personal data will be destroyed or deleted from the IT systems or turned into anonymous data to be used for scientific, historical or statistical research purposes. Please note that in certain expressly regulated situations, we store the data for the period imposed on us by law. We may disclose your data, in compliance with applicable law, to business partners or other third parties. We continuously make reasonable efforts to ensure that these third parties have implemented adequate protection and security measures. With these third parties we have contractual clauses so that your data is protected. In these situations, we will ensure that any transfer is legitimate, based on your consent or another legal basis.
For example, we could provide your data to other companies, such as IT or telecommunications service providers, accounting, legal services and other third parties with whom we have a contractual relationship. These third parties are selected with particular care so that your data is processed only for the purposes we indicate.
We could also share your data with business partners as a result of a joint effort to offer a product or a service.
Although unlikely, we could in the future sell the business or part of the business, a situation that will include the transfer of your data.
We may transmit the data to other parties with your consent or according to your instructions, for example, where you exercise a portability request.
We will also be able to provide your personal information to the prosecutor’s office, police, courts and other authorized state bodies, based on and within the limits of the legal provisions and following expressly formulated requests.
We will ensure, within reasonable limits, that your data does not leave the European Economic Area, but, to the extent that we transfer data to states outside the EEA, we will ensure, in all cases, that the transfers are legitimate, based on your explicit consent or another legal basis.
We may use direct marketing and targeted advertising technologies, using the information collected about you regarding interests, preferences, purchases, age, location etc. For example, we could send e-mails, display advertisements inside our website or on social media, or place advertisements on third-party sites, in applications or on other internet-connected devices.
In order to carry out direct marketing or targeted advertising activities, we could use the following information:
- Information collected through cookies and other similar technologies (location, device, browser, age etc.);
- Your purchases, how you interacted with our goods and services and the feedback received from you;
- Age, country, region, gender;
- Other information obtained from our third-party marketing partners, information that they obtained with your consent.
Our marketing partners help us deliver marketing to you based on the information collected by them directly from you and with your consent. In some cases, we even share information that we have collected from you. We ensure, in all cases, that these transfers are lawful.
Our partners may place advertisements regarding our services and products, based on the data previously collected from you (interests, preferences) on other sites and/or services. Our marketing partners may also use the information collected about you to improve the services and/or the algorithms (including algorithms based on artificial intelligence).
You may object to direct marketing and/or withdraw your consent regarding the processing of your data at any time by following the instructions for deleting the user account or by sending a request to that effect to the e-mail address [email protected].
Your rights under the GDPR are the following:
- The right to withdraw consent. You may withdraw your consent regarding the processing of your data at any time by sending a request to that effect to the e-mail address. Please note, however, that to the extent we have identified another legal basis for processing your data, we will continue to process your data on the basis of that legal basis. We have the legal possibility to rely on one or more grounds for processing your data.
- The right to be informed about the processing of your data;
- The right of access to the data;
- The right to rectify inaccurate or incomplete data;
- The right to erasure (“the right to be forgotten”);
- The right to restriction of processing;
- The right to transmit the data we hold about you to another controller (“the right to portability”);
- The right to object to the processing of the data;
- The right not to be subject to a decision based solely on automated processing, including profiling, with legal effects or with similarly significant effects on you;
- The right to go to court to defend your rights and interests;
- The right to lodge a complaint with a Supervisory Authority.
By creating a user account, purchasing our services or those of the Businesses on the platform, or by interacting with us by any means and/or through any communication channel (e-mail, phone, social networks etc.), you agree with the aspects we have mentioned and you also consent to the use of your data for advertising or marketing purposes, as well as to the processing of the data, to the extent that it is necessary for the continuation of our interaction and collaboration.
Provisions applicable to Businesses
If you are a Business, the following provisions regarding the processing of personal data also apply:
- The purpose of this procedure is to establish what data is processed for the purpose of performing the obligations between the parties, the reason for processing, the manner of processing, the recipients of the data and the retention period. The procedure also establishes the rights and obligations of the parties and the manner of lawfully exercising them. The parties expressly declare that they take confidentiality seriously and will not process personal data outside the purpose of performing the contract between the parties. The parties also declare that they will do everything possible to ensure the security of the personal data communicated during the performance of the contract between them.
- According to the law, Bookr and the Business are joint controllers from the perspective of the legislation on the processing of personal data, but the parties are also independent personal data controllers from the point of view of the relevant legislation in the field, depending on the data actually processed. So that personal data is processed safely, the parties will make every effort to implement reasonable measures to protect personal information.
- The protection of personal information is very important to us. That is why we have committed to comply with European and national legislation on the protection of personal data, in particular Regulation (EU) 679/2016, also known as the GDPR, and the following principles:
- Lawfulness, fairness and transparency. We process personal data lawfully and fairly. We are always transparent about the information we use and we inform each other appropriately.
- Control belongs to the data subjects. Within the limits of the law, we offer the possibility to examine, modify, delete the personal data provided and we ensure the lawful exercise of the other rights.
- Data integrity and purpose limitation. We use the data only for the purposes described at the time of collection or for new purposes compatible with the original ones. In all cases, our purposes are compatible with the law. We take reasonable measures to ensure that personal data is accurate, complete and up to date.
- Security. We have implemented reasonable security and encryption measures in order to protect the information as best as possible. However, we are aware that no website, no application and no internet connection is completely secure.
- In some situations, processing may be necessary to protect the vital interests of the data subjects or of other natural persons. Obtaining consent is not mandatory in this situation, and the parties will proceed to obtain the consent of the data subjects only in situations where they cannot rely on another legal basis.
- Bookr and the Business will keep personal data only for the period necessary to fulfil the purposes, but no longer than one year from the end of the relationship between them. After the end of the period, personal data will be destroyed or deleted from the IT systems or turned into anonymous data to be used for scientific, historical or statistical research purposes.
- However, in certain expressly regulated situations, the storage of the data will take place for the period imposed by law, such as keeping accounting documents for a period of 10 years.
- We may disclose personal data, in compliance with applicable law, to business partners or other service providers such as the accounting firm, the lawyers or the consultants of the parties on any matter.
- The parties declare that they have the right to transmit personal data covered by this procedure to each other and undertake to limit the transmission of personal data to the minimum necessary in order to fulfil the mutual obligations. The parties also undertake to bring to the attention of the data subjects the existence and essence of this agreement. Where one of the parties considers that personal data that does not fall within the purposes established by this procedure has been communicated to it, that party will immediately delete the personal data received, with prior notice to the party that transmitted the respective data.
- The parties undertake to communicate to each other any changes to the personal data transmitted between them. The parties undertake to make reasonable efforts to identify these changes.
- The parties will continuously make reasonable efforts to ensure that the third parties to whom the personal data covered by this procedure is transmitted have implemented adequate protection and security measures. With these third parties the parties declare that they have agreed, through agreements or contractual clauses, to protect personal data at the same level to which the parties have mutually committed through this procedure. The parties will inform each other about the identity of these companies before transmission or within a reasonable time and will ensure that any transfer is legitimate, based on the legal grounds provided by this procedure or by law.
- In the case of the assignment of contractual rights or obligations, or in the case of the merger, division or sale of the business by the parties, the transfer of the collected personal data is implicit.
- The parties will also be able to provide personal information to the prosecutor’s office, police, courts and other authorized state bodies, based on and within the limits of the legal provisions and following expressly formulated requests.
- The parties will ensure, within reasonable limits, that the data does not leave the European Economic Area, but, to the extent that data is transferred to states outside the EEA, the parties will ensure, in all cases, that the transfers are legitimate, based on the explicit consent of the data subjects or another legal basis.
- The parties will try to respond to requests regarding the processing of personal data within 30 days of receiving the request. However, the term may be extended depending on various aspects, such as the complexity of the request, the large number of requests received or the impossibility of identifying the data subject within a useful time.
- Failure to comply with this Policy by the employees of the parties may lead to their disciplinary sanctioning (including termination of the employment contract) and, depending on the circumstances, to court action for the full recovery of the damage caused as a result of the failure to comply with this Policy.
- Failure to comply with this Policy by business partners may lead to the termination of the business relationship and, depending on the circumstances, to court action for the full recovery of the damage caused to the Company as a result of the failure to comply with this Policy.