LATEST VERSION: 19 November 2021

WHO WE ARE
We are the company IFN ROMCOM SA, with its registered office in Oradea, str. Gheorghe Doja, nr. 49/A, Bihor county, J05/103/2006, CUI 18297835, registered in the General Register of the National Bank of Romania under number RG-PJR-05-110179/23.02.2011, registration number in the Special Register of the BNR RS-PJR-05-110127/03.08.2021, share capital: 16,042,200 Lei, legally represented by Vlad Mihuț, hereinafter referred to as the „Controller”.

We have a designated data protection officer who oversees the processing of personal data carried out by our company and is tasked with maintaining the relationship between us and the National Supervisory Authority for Personal Data Processing and with maintaining the relationship between us and the data subjects. Thus, our data protection officer is Ms Anca Ioan and she can be contacted at the e-mail address anca@litconsulting.ro or at the postal address Drm Lunca Prutului 61, sector 3, Bucuresti.

We process your personal data in accordance with the provisions of Regulation (EU) No 679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), in good faith and in pursuit of the purposes specified in this Policy on confidentiality and the processing of personal data (the „Policy”).

This Policy describes the types of personal data collected for the contracting of credit facilities, the guaranteeing of loans, the use of the romcom.ro website, subscription to the newsletter, as well as the types of data collected through the online forms completed by you. We assure you that we strictly respect the confidentiality of your data in your capacity as existing or potential clients or users/visitors of the romcom.ro web page, and we undertake not to transmit your personal data to third parties unlawfully and to use it exclusively in accordance with the purposes specified in the Policy. We also declare that we will collect your data only if it is provided voluntarily.

DATA PROCESSING PRINCIPLES
In processing personal data, the Controller and the persons authorised by it strictly observe the data processing principles set out in the EU General Data Protection Regulation (Article 5), namely: the lawfulness, fairness and transparency of processing, the limitation of processing to the intended purpose, the minimisation of the data processed, the accuracy of the data processed, the security, integrity and confidentiality of the processing operations and of the data processed.

WHAT PERSONAL DATA WE PROCESS
We will collect and process, namely record, organise, structure, store, adapt or alter, retrieve, consult, use, disclose by transmission, disseminate or otherwise make available, align or combine, restrict, erase or destroy, the following personal data:

  • surname, first name;
  • date of birth;
  • marital status;
  • domicile/residence and correspondence address;
  • personal numeric code. The personal numeric code is requested for the purpose of identifying the client or the legal representative of the client, in accordance with the provisions of Regulation No 9 of 3.07.2008, published in the Official Gazette, Part I 527 14.jul.2008, on know-your-customer requirements for the purpose of preventing money laundering and terrorist financing;
  • telephone number;
  • country code and passport series/number in the case of non-resident persons, citizenship;
  • data relating to profession and place of work;
  • data regarding education;
  • banking data;
  • sources of income;
  • signature;
  • image;
  • the number of enquiries: indicates the number of Credit Reports issued by the Credit Bureau;
  • copy of identity card;
  • the IP addresses of website users;
  • assets held by the surety/guarantor: inventory items, vehicles, equipment;
  • Also, in accordance with the provisions of Law 129/2019 on the prevention and combating of money laundering and terrorist financing, we apply know-your-customer measures. In this regard, we will proceed with the identification of the client/beneficial owner and the verification of the identity of the legal representatives, including by means of electronic identification provided for by EU Regulation 910/2014, we assess the purpose and nature of the lending relationship and we monitor the drawdowns relating to the credit facilities and the repayment of the loans by the client.

HOW WE PROCESS PERSONAL DATA
The aforementioned data is processed by the Controller in the sense that it is collected by completing forms either at the Controller’s registered office or through the website (with the help of cookies or by completing the forms existing on the website), it is recorded and stored in our databases and on our terminals, organised and structured, adapted or altered in accordance with the internal procedure, retrieved and consulted when we wish to undertake activities involving this data, used for the purposes described in this Policy, disclosed by transmission and made available to authorised persons as described in this Policy, restricted, erased or destroyed.

WHY AND HOW WE PROCESS PERSONAL DATA – PURPOSES

  • the provision of financial services by the Controller at the request of the data subject/representative of the potential legal-person client, for the purchase of a financing service or product from the Controller. This purpose involves carrying out, within the specific relationship with each data subject, all activities related to the conclusion and/or modification and/or performance of the financing/guarantee contract (Article 6(1)(b) of the EU Regulation); – carrying out the know-your-customer analysis, the risk analyses, and the reporting of suspicious transactions (Article 6(1)(b) and (c) of the EU Regulation), namely for the conclusion of the contract and for the fulfilment of a legal obligation, in conjunction with the legislation on know-your-customer requirements for the purpose of preventing money laundering and terrorist financing. We inform you that in certain situations we carry out an analysis of you in terms of your financial potential, thereby creating a profile of you. In this regard, we do not use an automated decision-making process. Following the establishment of the profile, the necessary decisions will be taken. The aforementioned decisions will not be taken until at least one human intervention upon the automatically established profile has occurred. The decisions are communicated to you, you may express your point of view on them and you may contest them by submitting a request to this effect.
  • the fulfilment of fiscal obligations related to the performance of the financing/guarantee contract;
  • the fulfilment of the obligations imposed by law upon us in our capacity as a financial institution;
  • informing you in connection with our offer, services/products and events.

FROM WHOM AND HOW WE COLLECT PERSONAL DATA
We collect personal data from you through the credit application, credit contract, guarantee contract, completion of the contact form or newsletter form. Processing is also carried out through the use of cookies, or other similar technologies activated by accessing our website. For more information, consult the cookie policy available on our website romcom.ro.

WHAT IS THE LEGAL BASIS FOR PROCESSING PERSONAL DATA
The processing of personal data is carried out, as the case may be:

  • in order to take steps at your request prior to entering into a contract as well as for the conclusion of the credit/guarantee contract (Article 6(1)(b) of the EU Regulation);
  • the processing is necessary in order to fulfil a legal obligation incumbent upon the Controller (Article 6(1)(c) of the EU Regulation);
  • the processing is necessary in order to pursue legitimate interests: simple marketing and communication purposes, handling of complaints, the design, development, testing and use of existing or new information systems and IT services, the establishment, exercise or defence of rights in court, as well as the constitution of evidence to this effect (Article 6(1)(f) of the EU Regulation).
  • on the basis of your consent, consent which you grant by voluntarily completing the newsletter form on the website and by accepting cookies when accessing the website (Article 6(1)(a) of the EU Regulation);

NEWSLETTER
If you have subscribed in the Newsletter section, your personal data will be used for the following purposes:

  • informing you in connection with our products, competitions, events, etc., and carrying out promotional activities of a commercial nature;
  • carrying out advertising, marketing and publicity activities, with regard to the products and services of third parties in Romania or abroad, which offer products and services similar to or complementary to the services of IFN ROMCOM SA.

Your personal data will be erased immediately when you cancel your subscription from the Newsletter section of the Controller. You may unsubscribe at any time through the link attached to the Newsletter received.

FOR HOW LONG WE PROCESS AND RETAIN PERSONAL DATA
Personal data is processed and stored until the fulfilment of the purpose for which it was collected and processed.

We may retain your personal information for a certain period of time after you have ceased to be a client, in order to safeguard our legitimate interests in the event of disputes or in accordance with the law. Normally, we retain your personal data for the period of time necessary, taking into account the purposes for which it was collected; firstly in order to fulfil our contractual relationships with you, to exercise our legitimate interests or to comply with the storage deadlines provided for by law.

In the event that a financing contract is concluded with us, IFN ROMCOM SA will store the personal data for the duration of the contractual relationships, as well as after the cessation of these relationships, for a period of a maximum of 10 years.

If the law imposes a retention/archiving period for your data, the data will be retained until the expiry of that period. It is possible that, following the fulfilment of the legal archiving periods, we may order the anonymisation of the data, thereby depriving it of its personal character, and continue the processing of the anonymous data for statistical purposes.

The processing of data (including storage) in the event that a contractual relationship has not been concluded with you will be carried out for a period of 5 years in accordance with the legislation on know-your-customer requirements, for the prevention and sanctioning of money laundering, as well as for the establishment of measures for the prevention and combating of the financing of acts of terrorism.

In accordance with the legal provisions on the keeping of accounts, the supporting documents underlying the entries are retained for 10 years, starting from the date of closure of the financial year during which they were drawn up.

In the event that the processing of data is carried out on the basis of your consent and you decide to withdraw it, the data will be processed until the withdrawal of consent. We specify that the withdrawal of consent does not affect the lawfulness of the processing carried out prior to the withdrawal.

If you request the erasure of the data, in accordance with your right to make such a request for erasure, we will proceed with the erasure of the data, except in those situations in which we are obliged to retain it pursuant to the law or on the basis of other legal grounds.

TO WHOM WE TRANSFER AND DISCLOSE PERSONAL DATA
The recorded information is intended for use by IFN ROMCOM SA and is communicated only to the following recipients: contractual partners, joint controllers, processors.

Thus, personal data may be transmitted to:

  • Insurance companies;
  • The Credit Risk Centre;
  • Biroul de Credit S.A.;
  • If payments are made by card – as the case may be Mastercard, VISA, etc.;
  • Courier companies (only in the situation of deliveries of ordered products or materials);
  • Suppliers of software/hardware products and the provision of technical assistance/consultancy/administration necessary for such products;
  • State institutions;
  • Other contractual partners.

Also, in the event that the shareholders of IFN ROMCOM SA change or in the event of division, reorganisation, dissolution, insolvency, we may transfer your data to the new owners or administrators/liquidators.

Personal data is not transferred to countries outside the EU or the EEA, or to international organisations.

We do not encourage SPAM, and therefore we do not sell, offer or exchange e-mail addresses obtained through this website, nor do we disclose your e-mail address to other persons who access the pages of this website.

WHAT ARE YOUR RIGHTS REGARDING DATA PROTECTION

  • The right to information – the right to be informed about the matters relating to the processing of your personal data and about the rights you have in connection with it.
  • The right of access to the data processed in accordance with Article 15 of the Regulation – the right to obtain from the Controller, on request and free of charge for one request per year, confirmation as to whether or not your data is being processed by us. In the event that we process personal data concerning you, we will communicate to you information regarding the data subject to processing, the origin of the data, the purposes of the processing, the recipients or categories of recipients to whom the data is disclosed, the principles of operation of the mechanism by which any automated processing of your data is carried out, the existence of the right of intervention upon the data and of the right to object, as well as the conditions under which they may be exercised, the possibility of lodging a complaint with the supervisory authority, as well as of bringing an action before the court for challenging the decisions of IFN ROMCOM SA, in accordance with the provisions of the EU Regulation.
  • The right to rectification of the data or its completion in accordance with Article 16 of the Regulation – the right to obtain from the Controller, on request and free of charge, the rectification and updating of the data, as well as the completion of incomplete or inaccurate data.
  • The right to erasure of the data in accordance with Article 17 of the Regulation – the right to request the erasure of your data processed by the controller, without undue delay. The right to erasure of the data is not an absolute one and applies only if: the data is no longer necessary for the fulfilment of the purposes for which it was collected or processed, you have withdrawn the consent previously granted to the Controller and there is no other basis for processing, you object to the processing and there are no legitimate grounds which prevail, the data has been processed in breach of the law, the data must be erased in order to comply with a legal obligation incumbent upon the Controller.
  • The right to restriction of the data in accordance with Article 18 of the Regulation – the right for the processing of your data to be restricted in the event that: (i) you have contested the accuracy of the data (applies during the period in which the verification of its correctness is carried out), (ii) the processing is unlawful and you object to the erasure of the data but wish the restriction of its processing, (iii) the Controller no longer needs the data, but you request it from us for the establishment or ascertainment of a right in court, (iv) if you have objected to the processing (applies during the period in which it is verified whether the legitimate rights of the Controller prevail over those belonging to you).
  • The right to data portability in accordance with Article 20 of the Regulation – the right to receive from the Controller your data processed by us in a structured, commonly used and machine-readable format (for example a file in PDF format), as well as the right for this data to be transmitted directly to another controller, where this is technically feasible.
  • The right to object with regard to the processing of data in accordance with Article 21 of the Regulation – the right to object to the processing of the data. The right applies only where the processing is carried out on the basis of a legitimate interest of the controller, and where the processing is for the purpose of direct marketing, you have the right to object to the processing at any time.
  • The right not to be subject to an automated individual decision, including profiling, in accordance with Article 22 of the Regulation. We inform you that, for the purpose of concluding the financing/credit contract with us, if you have requested this, we carry out an analysis of you in terms of your financial potential, thereby creating a profile of you. In this regard, we do not use an automated decision-making process. Following the establishment of the profile, a decision will be made as to whether or not to enter into a contractual relationship with you, namely your possibility of accessing our products and services. The aforementioned decision will not be taken until at least one human intervention upon the automatically established profile has occurred. The decision is communicated to you, you may express your point of view on it and you may contest it by submitting a request to this effect. You have the right not to be subject to a decision based solely on automated processing (including profiling), which produces legal effects.
  • The right to lodge a complaint when you consider that your rights are being infringed: directly with us at the details indicated below and/or before the supervisory authority – the National Supervisory Authority for Personal Data Processing – www.dataprotection.ro.

HOW YOU CAN EXERCISE YOUR RIGHTS
In order to exercise these rights, you may address a written request, dated and signed by hand, either (i) at the Controller’s registered office in Oradea, str. Gheorghe Doja, nr. 49/A, Bihor county, indicating as recipient on the correspondence envelope „IFN ROMCOM S.A. – The Data Protection Officer”, or (ii) at the e-mail address: anca@litconsulting.ro, or (iii) at the correspondence address of the data protection officer. In accordance with the legal provisions, we will process your requests regarding the Personal Data and, as the case may be, the measures taken, at the address indicated in the request or at the one held in the Controller’s records, within 30 days of the receipt of the request by the Controller, under the conditions provided for by the Regulation. This period may be extended by two months where necessary, taking into account the complexity of the request.

The contact details of the Data Protection Officer Anca Ioan are: email- anca@litconsulting.ro; telephone: 0755039163, office- Bucuresti, Drm Lunca Prutului 61B, sector 3, postal code 032357.

ACCESS BY MINORS
The content of the website and of the materials held by us is not intended for minors, but its content is not harmful to them.

SECURITY MEASURES
The security of personal data is important to us. We maintain appropriate administrative, technical and physical measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, use and all other lawful forms of processing of the personal data in our possession.

IFN ROMCOM SA has the obligation to administer, under conditions of safety and only for the specified purposes, the personal data that you provide to us about yourself.

This website uses security measures against the loss, alteration or misuse of the information that is under our control.

FEEDBACK
We offer website users the possibility of sending comments, questions and suggestions. Any information that is sent through the contact forms will be used taking into account the right to confidentiality and to the image of persons.

AMENDMENTS TO THE PRIVACY POLICY
To the extent that we consider that a change to the confidentiality rules is necessary, we will publish the respective amendments on this page in order to inform you regarding the types of information that we collect and the manner in which we use it. To the extent that you have subscribed to our newsletter, we will send you a notification regarding the update of this policy.

If you have questions regarding our Policy, please contact us at the e-mail address: office@romcom.ro.