GDPR-compliant privacy practices protecting your personal data
This Privacy Policy describes how Homelyf SRL ("we," "us," or "our") collects, uses, and protects your personal information when you use our website homelyf.shop and our services.
We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and Romanian data protection laws. This policy explains your rights and how we handle your personal data.
| Data Category | Examples | Purpose | Retention |
|---|---|---|---|
| Identity Data | Name, date of birth, gender | Account management, age verification | Account lifetime + 3 years |
| Contact Data | Email, phone, address | Communication, delivery | Account lifetime + 3 years |
| Financial Data | Payment card details, bank info | Payment processing | Not stored (processed by payment providers) |
| Transaction Data | Order history, preferences | Order fulfillment, customer service | 7 years (legal requirement) |
| Technical Data | IP address, browser, device ID | Security, analytics, improvement | 2 years |
| Marketing Data | Preferences, campaign responses | Personalized marketing | Until consent withdrawn |
You can withdraw your consent for marketing and analytics at any time through your account settings, email unsubscribe links, or by contacting us directly.
Under GDPR, we process your personal data based on the following legal grounds:
| Legal Basis | Processing Activities | Examples |
|---|---|---|
| Contract Performance | Essential for providing our services | Order processing, delivery, customer support |
| Legal Obligation | Required by EU or Romanian law | Tax records, anti-money laundering, consumer protection |
| Legitimate Interest | Necessary for business operations | Fraud prevention, security, website analytics |
| Consent | Opt-in activities | Marketing emails, non-essential cookies, surveys |
Where we rely on legitimate interest, we have conducted balancing tests to ensure our interests don't override your fundamental rights and freedoms. You can request details of these assessments.
| Service Type | Data Shared | Purpose | Safeguards |
|---|---|---|---|
| Payment Processing | Name, address, payment details | Transaction processing | PCI DSS compliance, encryption |
| Shipping & Logistics | Name, address, phone, order details | Order delivery | Data processing agreements |
| Email Marketing | Email address, preferences | Newsletter delivery | GDPR-compliant platforms |
| Analytics | Anonymized usage data | Website improvement | Data minimization, anonymization |
| Customer Support | Contact details, inquiry history | Support ticket management | Confidentiality agreements |
We never sell, rent, or trade your personal information to third parties for their marketing purposes. All data sharing is limited to the purposes described in this policy.
We retain personal data only as long as necessary for the purposes outlined in this policy:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Until account deletion + 3 years | Customer service, legal obligations |
| Order Records | 7 years from purchase | Legal requirement (tax, warranty) |
| Marketing Data | Until consent withdrawn | Marketing communications |
| Website Analytics | 26 months | Performance analysis |
| Support Tickets | 3 years from resolution | Quality improvement |
| Security Logs | 12 months | Fraud prevention, security |
In case of a data breach affecting your personal information, we will notify you and the relevant authorities within 72 hours as required by GDPR, along with steps we're taking to address the issue.
Under GDPR, you have the following rights regarding your personal data:
Request a copy of the personal data we hold about you, including how it's processed.
Correct inaccurate personal data or complete incomplete information.
Request deletion of your personal data in certain circumstances ("right to be forgotten").
Limit how we process your data while disputes are resolved.
Receive your data in a machine-readable format to transfer to another service.
Object to processing based on legitimate interests or for direct marketing.
To protect your privacy, we may need to verify your identity before processing rights requests. We may ask for additional information or documentation.
Email: dpo@homelyf.shop
Address: Homelyf SRL, Str. Smeurei 63, Arges, Romania
Phone: +40 742 389 567
If you're not satisfied with our response to your privacy concerns, you can lodge a complaint with:
We may update this Privacy Policy periodically. We'll notify you of significant changes by email or through our website. The "Last Updated" date at the top indicates when the policy was last revised.