Privacy Policy
Last updated: August 2026
1. Data controller
The data controller for personal data is Gourmet Divino SRL, a Romanian legal entity, with:
- Registered office: Bucharest, Sector 3, Mihai Bravu Road no. 255, floor S, unit MOD. S156, postal code 030302, Romania
- Tax ID (CUI): 51551438
- VAT registration number: RO51551438
- Trade Register number: J2025023221003
For any request regarding your personal data:
- Email: contact@gourmetdivino.com
- Phone: +40 748 111 805
2. What data we collect
2.1. Data collected when placing an order
- Identification data: first name, last name
- Contact data: email address, phone number
- Delivery data: complete address, county, city, postal code, delivery notes
- Billing data: name, address, VAT number and trade registration (for legal entities)
- Transactional data: ordered products, value, order history
2.2. Data collected automatically when you visit the website
Audience measurement, without cookies. To know how many people visit us and which pages they read, we record each page load. For every visit we keep only:
- the page opened and the language you read it in
- the site you came from, domain name only (for example
google.com), never the full address - the time of the visit
- a technical fingerprint, in the form of a code computed from your IP address and your browser type
The IP address is not stored. It is used once, to compute the fingerprint, and the resulting code cannot be turned back into your address. The computation also includes a secret value that changes every day, so the same person gets a different fingerprint the next day and cannot be tracked from one day to the next.
We use no cookies for this measurement, we store nothing on your device and we read nothing from it. The data stays on our servers and is not shared with anyone. We do not build profiles and we do not track you across other websites.
The legal basis is our legitimate interest (Art. 6.1.f GDPR) in understanding how our own website is used. You may object to this processing at any time by writing to us at contact@gourmetdivino.com — see section 8.6.
Cookies. Separately from the above, the website uses strictly necessary cookies and, only with your agreement, additional cookies. For complete details, consult the Cookie Policy.
2.3. Data received from third parties
- Payment status from Netopia Payments
- Delivery status, shipping document number (AWB) and tracking link, from AltExpress and from the courier company
- Invoice series and number, from SmartBill
2.4. Data collected through the partnership form (B2B)
If you send us a partnership request through the form on our contact page, we collect the details you fill in there:
- Company name and type of business (distributor, restaurant, shop, hotel)
- Name of the contact person
- Email address and phone number
- Any details you choose to write in the message field
These are professional contact details, collected on the basis of your explicit consent (the checkbox in the form) and our legitimate interest in answering a commercial enquiry. We use them solely to contact you about the request you sent and to share our partner offer. We do not use them for the newsletter and we do not pass them on to anyone else.
Afterwards, in our internal records, we may add the company's tax identification number (CUI), obtained from public sources (the ANAF register), in order to prepare the commercial offer.
2.5. What we DO NOT collect
- Bank card data — these are processed exclusively by Netopia Payments, under PCI-DSS security conditions
- Sensitive data (health, political opinions, religious, sexual orientation, etc.)
- Personal identification numbers (CNP), except in specific cases when required for invoicing
3. Processing purposes and legal bases
| Purpose | Legal basis (GDPR) | Storage period |
|---|---|---|
| Processing and delivering orders | Contract performance (Art. 6.1.b) | Contract duration + legal terms |
| Issuing invoices and tax documents | Legal obligation (Art. 6.1.c) | 10 years (Tax Code) |
| Marketing communications (newsletter) | Consent (Art. 6.1.a) | Until consent withdrawal |
| Website audience measurement (cookie-free) | Legitimate interest (Art. 6.1.f) | 14 months |
| Website security and fraud prevention | Legitimate interest (Art. 6.1.f) | Maximum 12 months |
| Response to support requests | Contract performance / Legitimate interest | 24 months |
| B2B partnership requests | Consent (Art. 6.1.a) + Legitimate interest (Art. 6.1.f) | 24 months from last contact |
4. Cookies
Our website uses cookies and similar technologies. For complete details, consult the Cookie Policy.
At first visit, we will request your consent for non-essential cookies through the consent banner.
5. Who we share data with
We may transmit your data to authorized processors who help us provide services:
5.1. Payment processor
- Netopia Payments — for online payment processing
- Operator: Netopia Financial Services SA, Bucharest
5.2. Logistics and delivery
- AltExpress (SC Alt Express SRL) — our logistics partner, which stores the products, prepares the parcels and generates the shipping documents. Receives: first and last name, phone number, delivery address, email address, order contents and, for cash-on-delivery, the amount to collect.
- The courier company performing the actual delivery (currently DPD Romania). Receives the data on the shipping document: name, phone, address and, for cash-on-delivery, the amount to collect.
Without these transfers the order cannot be delivered, so the processing is necessary for the performance of the contract (Art. 6(1)(b) GDPR).
5.3. Technical service providers
- Amazon Web Services (AWS) — for hosting the website, the database and the images (Stockholm region, Sweden)
- Cloudflare — for security and CDN optimization
- Resend — for transactional email service
5.4. Invoicing
- SmartBill (Intelligent IT SRL, Sibiu) — the platform through which we issue invoices. Receives the billing details you fill in at checkout: name or company name, billing address, email address and, for legal entities, the VAT/registration number and the Trade Register number.
- This processing is necessary to comply with legal invoicing obligations (Art. 6(1)(c) GDPR), so it cannot be refused as long as the order exists.
5.5. Public authorities
- ANAF (Romanian Tax Authority), according to legal obligations (e-Factura, tax reporting)
- Other authorities, in cases specifically provided by law
All these partners process data only according to our instructions and with adequate protection guarantees (Data Processing Agreements - DPA).
6. Data transfer outside the EU
6.1. Your data is stored mainly on AWS servers located in Stockholm, Sweden (European Union), according to the principle of proximity and GDPR compliance. Our logistics and invoicing partners (AltExpress, SmartBill) are Romanian companies and process the data within Romania.
6.2. In certain cases, data may be processed by providers based in the USA or other third countries. In these situations, transfers are made based on:
- Standard Contractual Clauses of the European Commission
- EU-US Adequacy Framework (Data Privacy Framework), if applicable
- Or with your explicit consent, if applicable
6.3. You can obtain a complete list of suppliers and data transfers by writing to us at contact@gourmetdivino.com.
7. Data security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss or disclosure:
- SSL/TLS encryption for all communications
- Daily encrypted backups
- Restricted access to personal data based on roles
- Continuous monitoring of infrastructure security
- Periodic updates of systems and applications
8. Your rights under GDPR
According to Regulation (EU) 2016/679 (GDPR), you have the following rights:
8.1. Right of access (Art. 15 GDPR)
You can request confirmation that we process data about you and a copy of this data.
8.2. Right to rectification (Art. 16 GDPR)
You can request correction of inaccurate data or completion of incomplete data.
8.3. Right to erasure ("right to be forgotten") (Art. 17 GDPR)
You can request the deletion of your data under certain conditions. Attention: for data required for legal obligations (invoices, accounting records), deletion may be limited.
8.4. Right to restriction of processing (Art. 18 GDPR)
You can request limitation of the use of your data in certain cases.
8.5. Right to data portability (Art. 20 GDPR)
You can request the transfer of your data in a structured format, to yourself or another controller.
8.6. Right to object (Art. 21 GDPR)
You can object to processing based on legitimate interest, including profiling for direct marketing.
8.7. Right to withdraw consent
At any time, without affecting the legality of prior processing.
8.8. Right not to be subject to automated decisions (Art. 22 GDPR)
We do not use automated decisions with significant legal effects on you.
8.9. How to exercise your rights
Send your request to contact@gourmetdivino.com with the subject "GDPR Request — [request type]".
We will respond within a maximum of 30 days, according to law. For complex requests, the term can be extended to 60 days, with prior notification.
We may ask you to prove your identity for data protection.
9. Automated decisions and profiling
We do not use automated decisions that produce significant legal effects on you.
We may analyze purchase patterns to recommend relevant products, but these recommendations do not represent automated decisions with significant impact and can be ignored by you.
10. Storage duration
We keep each category of data only for as long as necessary for the purpose it was collected for, or for as long as the law requires.
The complete retention periods are in the table in section 3, where they sit next to the corresponding purpose and legal basis. We keep them in a single place, so that there are no two lists that could drift apart.
When a period expires, the data is securely deleted or anonymized. Where the period is fixed, deletion happens automatically, through a daily process — for example in the case of audience measurement data.
If a legal obligation requires us to keep certain data longer than the period in the table (for example tax documents), the legal term takes precedence.
11. Complaints and authorities
11.1. National Supervisory Authority for Personal Data Processing (ANSPDCP)
If you have complaints about how we process your data, you can contact ANSPDCP:
- Website: dataprotection.ro
- Email: anspdcp@dataprotection.ro
- Phone: +40 318 059 211
- Address: B-dul G-ral. Gheorghe Magheru no. 28-30, Sector 1, Bucharest
11.2. National Authority for Consumer Protection (ANPC)
For consumer protection issues:
- Website: anpc.ro
- ODR Platform: ec.europa.eu/consumers/odr
12. Policy changes
We may update this policy periodically. The current version is displayed on this page with the last update date. We will inform you of substantial changes via email or through a notice on the website.
13. Contact for data protection
For any question or request regarding your personal data:
- Email: contact@gourmetdivino.com
- Phone: +40 748 111 805
- Address: Bucharest, Sector 3, Mihai Bravu Road no. 255, floor S, unit MOD. S156, postal code 030302, Romania
