Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
General Data Protection Regulation
If you visit or communicate with KUMA ROMANIA, we are taking care about your personal data in our activities as a SME’s.

Personal data are collected only with your consent/acceptance, if they are offered knowingly, willingly, on your own initiative, or at the request of KUMA ROMANIA, for example through contractual documents, through one of the online forms used, respectively the online contact form, by subscribing to the newsletters, participating in different contests, by completing the account registration data on KUMA

This applies, for instance, when you contact KUMA directly or by email as a Client/Supplyer/Public Entity/Employee/Prospective employee/Consultant/Foundation/Owner  or when you contact us on Facebook/Instagram/Linkedin/website www.kumaromania.ro.

KUMA RO processes the data that you send us for different issues and our departments are instructed to keep confidentiality upon them.

KUMA process ordinary personal data : names/addresses/contact information/ID serial-number/Personal Identification Number

or

the company dates like CVR/name/address/contact informations, are used for:

  • Commercial purpose/ Funding purpose
  • Managing relations with Clients , Supplyers, Authorities, Third parts
  • Invoices/CMR’s/Packing Lists
  • Contracts/Agreements/Audits
  • Labour Contracts
  • Resolutions of disputes and litigations/arbitration decisions/court orders

If you visit KUMA and you are outside or inside the sections close to exits, you could be filmed by our surveillance cameras.We have special signs for this purpose to draw your attention.

When you visit our websites and accept cookies, KUMA will collect data about you.  Cookie policy here.

For how long will KUMA keep the personal/company dates?

We are following the applicable legislation in force about Invoices/Contracts/Personell Files. After the legal period they are entering in KUMA Archive- which is externatized & digitalized ,respecting the rules.

We do not communicate further the dates collected, only in case a Public Authority will request them, we have the obligation to disclose the information.

Legal basis

KUMA processes personal data in compliance with a number of general rules which apply to all companies-in Romania:

  • 31 July 2018, Law No 190/2018 regarding measures for implementing Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation GDPR)
  • This law sets out the measures necessary to implement at national level, in particular, the provisions of Article 6 para. (2), art. 9 par. (4), Art. 37-39, 42, 43, Art. 83 para. (7), Art. 85 and Art. 87-89 of the General Data Protection Regulation/GDPR
  • Law No 190/2018 published on the Authority’s website under Legislation, can also be consulted here.
  • Applicable is also the Law on Archiving-Law 36/2023-Accounting Documents and Annex 6/Law 16-1996 on archiving of employment contracts and other human resources documents.

 

KUMA ROMANIA

Camelia Olesen-Executive Director

Document revised/03 Jan.2024

GDPR Compliance & Data Security

Regulation (EU) 2016/679 of the European Parliament and of the Council — S.C. KUMA ROMANIA S.R.L.

Personal Data Controller
Controller name:
S.C. KUMA ROMANIA S.R.L.
CUI:
RO 11266580
Trade Reg. No.:
J1998001339298
Registered office:
Str. Stupini nr. 85B, Loc. Banesti, 107050, jud. Prahova
DPO / Contact Email:
office@kumaromania.com
Phone:
+4 0244-348-596
Supervisory authority:
ANSPDCP — National Supervisory Authority for Personal Data Processing
Compliance Implementation Status
Prior Consent
Implemented
Cookie banner with 3 options: Accept / Reject / Granular settings across 4 categories
Consent Withdrawal
Implemented
Persistent button + "Withdraw All Consent" option + automatic cookie deletion
Consent Proof
Implemented
Each consent: unique ID, IP hash, timestamp, policy version, integrity hash
Data Minimization
Implemented
IP anonymized at 90 days, user agent deleted, full deletion at 365 days
Script Blocking
Implemented
4 independent protection layers: server-side filtering, queue removal, HTML interception, real-time JS monitoring
Audit Trail
Implemented
Anonymized log of all deletions and anonymizations, exportable as PDF/CSV
Implemented GDPR Articles
Article 5 — Principles relating to processing of personal data
Art. 5(1)(a) — Lawfulness, fairness and transparency
“Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the data subject.”
Implementation: Cookie banner visible on first visit. Clear text about the purpose of each category. Direct links to GDPR Policy and Cookie Policy. The user is informed before any processing takes place.
Article 5(1)(b)
Purpose limitation
“Personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.”
Implementation: Cookies are strictly classified into 4 categories (necessary, analytics, marketing, functional). Each category has a clearly explained purpose. Scripts are blocked until the specific category is accepted.
Article 5(1)(c)
Data minimisation
“Personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.”
Implementation: IP addresses are automatically anonymized after 90 days (replaced with 0.0.0.0). The user agent is deleted. Only the IP hash is retained for uniqueness, with no possibility of re-identification.
Article 5(1)(e)
Storage limitation
“Personal data shall be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.”
Implementation: Maximum retention: 365 days. After this period, all records are automatically deleted. Before deletion, an anonymized log report with aggregated statistics is saved as proof of compliance.
Article 5(2)
Accountability
“The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1.”
Implementation: Dashboard with real-time statistics. Audit log with history of all deletions and anonymizations. PDF and CSV export for documentation. Automatic monthly backups. Scheduled email reports.
Article 7 — Conditions for consent
Art. 7(1) — Proof of consent
“Where processing is based on consent, the controller shall be able to demonstrate that the data subject has consented to processing of his or her personal data.”
Implementation: Each consent receives a unique ID. Recorded: IP hash, exact date/time, cookie policy version, SHA-256 integrity hash, page URL. Exportable as proof in PDF and CSV format.
Article 7(2)
Separation of consent
“If the data subject's consent is given in the context of a written declaration which also concerns other matters, the request for consent shall be presented in a manner which is clearly distinguishable from the other matters.”
Implementation: Dedicated banner exclusively for cookies — separate from any other content. Granular settings allow enabling/disabling each category independently.
Article 7(3)
Withdrawal of consent
“The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, the data subject shall be informed thereof. It shall be as easy to withdraw as to give consent.”
Implementation: Persistent button (gear icon) on all pages. Clicking opens the settings modal with the revocation option. Upon revocation: the consent cookie, all tracking cookies are deleted and scripts are re-blocked.
Article 25
Data protection by design and by default (Privacy by Design & Default)
“The controller shall implement appropriate technical and organisational measures [...] which are designed to implement data-protection principles, such as data minimisation, in an effective manner and to integrate the necessary safeguards into the processing.”
Implementation: By default, all non-essential cookies are blocked (opt-in, not opt-out). Google Consent Mode v2 with denied as default. 4 blocking layers. Automatic anonymization and deletion. Zero configuration required from the user.
ePrivacy Directive 2002/58/EC — Art. 5(3)
Storing of information on terminal equipment
“Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information.”
Implementation: No tracking cookie is set without explicit consent. Scripts are completely blocked at both server and client level. Existing cookies are automatically deleted upon rejection or revocation.
Technical and Cybersecurity Measures
Encryption / Hashing
SHA-256 + SSL/TLS
IP addresses are hashed with SHA-256 and a unique salt. Communication is encrypted via SSL/TLS. Integrity hash for data protection.
Access Control
Session + 2h Timeout
Dashboard protected with authentication. Sessions automatically expire after 2 hours of inactivity. Access only via SSL.
Anonymization
Automatic at 90 days
The IP hash and user agent are automatically deleted via a daily cron job. Records become fully anonymous.
Automatic Deletion
After 365 days
Records are fully automatically deleted after the retention period. Only an anonymized log report is retained.
Audit Trail
Anonymized Log
Each deletion and anonymization operation is logged with aggregated statistics. The log contains no personal data.
Backup
Automatic Monthly
Automatic monthly backups stored in a protected directory. Backup retention: 12 months. Server-side access only.
Technical Security Details
Script Blocking — 4 Independent Layers Layer 1: Server-side filtering — automatic modification of tracking scripts before sending to the browser. Layer 2: WordPress queue removal — deactivating third-party tracking plugin scripts. Layer 3: Full HTML interception — scanning and neutralizing all inline and external scripts. Layer 4: Real-time monitoring — blocking scripts dynamically injected after page load.
Consent Data Storage and Protection Dedicated database with optimized indexes. IP hashing via SHA-256 with unique WordPress salt — impossible to reverse. SHA-256 integrity hash on consent data + timestamp + IP hash — detects any unauthorized modification.
Google Consent Mode v2 Implemented with default values of "denied" for analytics_storage, ad_storage, ad_user_data and ad_personalization. Values are automatically updated to "granted" only after the user's explicit acceptance of the corresponding categories.
National Legislation Compliance Law no. 506/2004 on the processing of personal data and protection of privacy in the electronic communications sector. Supervisory authority: ANSPDCP — National Supervisory Authority for Personal Data Processing.

Cookie Settings

Choose which cookies you accept on this website. Under GDPR Art. 7.3, you can withdraw your consent at any time.

Necessary

Essential for the website to function. We recommend keeping these enabled.

Analytics

Google Analytics – anonymous traffic statistics.

Marketing

Facebook Pixel, Google Ads – personalized advertising.

Functional

Chat, maps, video – advanced website features.