GDPR Policy - Personal Data Security

Last updated: 31.08.2026

1. Our commitment

MPR GROUP S.R.L. (J26/970/2023, tax ID RO48381201, Str. Borzești no. 12/A, Târgu Mureș, Mureș County, Romania) processes personal data in accordance with Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018 and Law no. 506/2004.

This document describes how we protect personal data. What data we collect, for what purposes and on what legal basis is set out in the Privacy Policy.

Data protection contact: contact@mprfamily.com · +40 730 711 870

2. The principles we apply

  • Lawfulness, fairness and transparency – we process data only on clear legal bases, communicated in advance.
  • Purpose limitation – data collected for an order is not reused for incompatible purposes.
  • Data minimisation – we ask only for what is needed for delivery, invoicing and legal compliance.
  • Accuracy – you can correct your data at any time in your account or by writing to us.
  • Storage limitation – we apply the retention periods in the Privacy Policy, after which data is deleted or anonymised.
  • Integrity and confidentiality – we apply the measures in section 3.
  • Accountability – we document our processing activities and can demonstrate compliance.

3. Technical and organisational measures

Technical:

  • encrypted traffic between the user and the Site via SSL/TLS certificate (HTTPS);
  • hosting on an e-commerce platform with recognised security certifications and regular backups;
  • payments processed exclusively through PCI-DSS compliant authorised processors; we do not store full card details;
  • mandatory two-factor authentication (2FA) for administrative accounts;
  • strong passwords, stored only in encrypted form;
  • regular updates of applications and third-party modules;
  • logging of access to the admin panel;
  • anti-malware protection and filtering of suspicious traffic.

Organisational:

  • role-based access, limited to what is strictly necessary ("need to know");
  • confidentiality undertakings for everyone with access to personal data;
  • periodic staff training on data protection;
  • data processing agreements (DPAs) with all processors;
  • annual review of the processor list and of security measures;
  • an internal procedure for handling data subject requests;
  • an internal procedure for handling security incidents.

4. Processors and sub-processors

We work only with providers offering sufficient guarantees regarding the security of processing, under contracts concluded in accordance with Article 28 GDPR. The main categories are:

Category Role
E-commerce platform and hosting storing orders and accounts
Payment processor collecting online payments
Courier companies delivering orders
E-mail marketing provider sending the newsletter, based on consent
Web analytics tools usage statistics, based on consent
Accounting firm accounting and tax records
Legal advisers, auditors advice and representation

A detailed list of providers is available on request at contact@mprfamily.com.

5. International transfers

Where a provider processes data outside the European Economic Area, the transfer takes place only on the basis of an adequacy decision of the European Commission or Standard Contractual Clauses, supplemented where necessary by additional technical measures (encryption, pseudonymisation, access restrictions).

6. Security incidents

In the event of a personal data breach we:

  1. contain the incident and limit its effects;
  2. assess the risk to the rights and freedoms of the individuals concerned;
  3. notify ANSPDCP within 72 hours of becoming aware of the breach, where it is likely to result in a risk;
  4. inform the individuals concerned without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
  5. document the incident, its effects and the remedial action taken.

7. Automated decisions and profiling

We do not take decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.

If you consent to marketing cookies, you may be shown personalised product recommendations or advertising. You can withdraw that consent at any time in your cookie settings.

8. Handling data subject requests

Your rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent) are described in full in the Privacy Policy.

Our internal procedure:

  1. we receive the request at contact@mprfamily.com and log it;
  2. we verify the requester's identity, to avoid disclosure to unauthorised persons;
  3. we review the request and identify every system in which the data appears;
  4. we respond within one month, extendable by up to two further months for complex requests, telling you within the first month;
  5. we keep a record of requests and responses, to demonstrate compliance.

Requests are free of charge. For manifestly unfounded or excessive requests, in particular repetitive ones, we may charge a reasonable fee or refuse with reasons, under Article 12(5) GDPR.

9. Minors

The Site sells alcoholic beverages and is intended solely for persons aged 18 and over. We do not knowingly collect data from minors. If we identify such data, we delete it without delay.

10. Complaints

If you believe the processing of your data infringes the GDPR, you can contact us first at contact@mprfamily.com, or go directly to the supervisory authority:

Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania Phone: +40 318 059 211 · E-mail: anspdcp@dataprotection.ro · www.dataprotection.ro

If you live in another EU/EEA country, you may also complain to your local supervisory authority. You also have the right to an effective judicial remedy.

11. Review

This policy is reviewed at least annually and whenever there are legislative changes or changes in the way we process personal data.