2026-06-17T08:57:27+03:00

Privacy Policy

(Notice on the processing of personal data)

1. Controller of personal data

Name: SC FOR HAPPY SOULS SRL Tax ID/VAT No. (CUI/CIF): 43193320 ONRC Registration No.: J 29/1899/2020 Registered office: Sinaia, Str. Stânjeneilor 5, Bl. 3, Ap. 5 Phone: 0771.261.275 E-mail: forhappysouls@gmail.com Website: www.whitelilynaturals.ro

SC FOR HAPPY SOULS SRL processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Romanian legislation (including Law No. 190/2018). The purpose of this "Privacy Policy" ("Policy") is to inform each Customer (defined below) about the processing of data through which that Customer is identified or may be identified.

For the purposes of this Policy, "Customer" means any natural person who is a party to a contract with the Company for the sale of goods, as well as any natural person who has expressed the intention to enter into pre-contractual relations with the Controller and/or any user of the White Lily Naturals online store, accessible on the internet at: www.whitelilynaturals.ro, as well as any director, manager, representative, proxy, employee, partner, shareholder, or beneficial owner of a legal entity or other organization using the Online Store.

2. What personal data do we process?

In its capacity as data controller, the Company processes the following categories of Customer data:

  • Identification and contact data — first name, last name, delivery/billing address, phone number, e-mail address;
  • Account/registration data (if applicable) — login credentials, order history, preferences;
  • Transaction data — products purchased, order value, payment status, invoice;
  • Technical data — IP address, cookie identifiers, browser type, operating system, pages visited, website usage data;
  • Payment data — the Company does not store full card data; this is processed by payment processors. In certain situations, we may receive limited payment information (e.g., transaction confirmation/ID).

Personal data is collected by the Controller from the individuals concerned and/or from their interactions with the Online Store.

3. How do we collect personal data?

We collect personal data:

  • during the registration process on the Online Store website and when using the Online Store without registration;
  • in the course of correspondence with the Customer (written, including electronic, and/or oral);
  • through cookies and similar technologies, when using or browsing our website;
  • from third-party sources (e.g., courier/payment processor), strictly to the extent necessary for contract performance;
  • from public sources, in limited and legally justified cases.

Our website may collect data in log files, such as: IP address, internet service provider, browser, operating system, time of visit, and pages visited.

Our website uses cookies. Cookies are small information files that a website sends to a visitor's browser. The browser stores this information in a text file on the user's device. They help us make the website work properly and better for you. You can read more about our use of cookies in our Cookie Policy, published on the Online Store website: White Lily Naturals.

4. Do we process special categories of data?

The Company does not intentionally process special (sensitive) categories of personal data (e.g., health data, political opinions, religious beliefs, etc.).

5. For what purposes do we process the data?

The Company processes Customers' personal data for the following purposes:

  • providing the information and assistance requested;
  • creating/managing the account (if applicable);
  • placing, processing, and delivering orders;
  • issuing related documents (invoice, warranty, return form, etc.);
  • communications related to orders (confirmations, delivery status, support);
  • handling returns, complaints, and warranty claims;
  • preventing fraud and ensuring the security of our systems;
  • complying with applicable legal requirements (accounting, taxation, consumer protection);
  • defending the Company's rights in the event of a dispute and cooperating with the competent authorities, to the extent required by law;
  • marketing (newsletters, offers) only where consent or another applicable legal basis exists.

If we do not process this data, we may be unable to provide you with our services or the assistance requested.

6. On what legal bases do we process the data?

Customers' personal data is collected, processed, and used on the basis of the following:

  • performance of a contract or pre-contractual steps (order, delivery, support);
  • compliance with a legal obligation (e.g., accounting/tax obligations);
  • the legitimate interest of the Company or of a third party, where the rights and freedoms of the data subjects do not override that interest (e.g., security, fraud prevention, defense in legal disputes);
  • consent (e.g., marketing, certain cookies), where required by law.

7. How long do we store the data?

The Company stores personal data for the duration of the contractual relationship and until any contractual claims have lapsed, as well as for a further transitional period necessary to comply with legal obligations (e.g., archiving and retaining accounting records).

In particular, financial-accounting documents are retained in accordance with applicable legislation, generally for 10 years, starting from the date set by law for the retention period.

Where data is processed on the basis of consent, it will be processed until the consent is withdrawn or until the purpose for which it was given has been achieved, as applicable.

8. To whom do we disclose the data? Do we transfer it to third countries?

The Company may transfer some or all personal data to processors (persons who process data on our behalf) in order to fulfill the purposes of processing, in compliance with the GDPR.

The Company may share personal data with:

  • contracted service providers: hosting, IT maintenance, e-mail/SMS, support services, automation platforms;
  • couriers/carriers, for delivery purposes;
  • payment processors/financial institutions, for carrying out and confirming payments;
  • public authorities (tax, judicial, administrative, or law enforcement), where we have a legal obligation or receive a valid request.

This list is not exhaustive. There may be other legitimate situations for disclosing data, within the limits of the law.

Transfers outside the EEA (third countries): If certain services involve transfers to countries outside the European Economic Area, the Company will ensure the safeguards required by the GDPR (e.g., an adequacy decision, standard contractual clauses) and will inform data subjects in accordance with the law, where applicable.

9. Is personal data protected?

The Company implements and maintains appropriate technical and organizational measures to protect personal data against unauthorized access, unlawful use, loss, alteration, disclosure, or accidental destruction. These measures are reviewed periodically to maintain an appropriate level of security.

10. Do we carry out automated decision-making?

The Company does not carry out decision-making based solely on automated processing, including profiling, that produces legal effects significantly affecting the Customer, based on the data processed.

11. What rights do Customers have?

Customers may exercise their rights by submitting a written request to the Company using the contact details above.

  • The right to withdraw consent (where processing is based on consent);
  • The right of access to data and information about its processing;
  • The right to rectification of inaccurate/incomplete data;
  • The right to erasure ("the right to be forgotten"), under the conditions set out in the GDPR;
  • The right to restriction of processing, in the cases provided by the GDPR;
  • The right to object, in particular to processing based on legitimate interest and to direct marketing;
  • The right to data portability, under the conditions set out in the GDPR;
  • The right to lodge a complaint with the competent supervisory authority.

Competent authority in Romania: ANSPDCP (National Supervisory Authority for Personal Data Processing) E-mail: anspdcp@dataprotection.ro Website: www.dataprotection.ro Address: Bd. G-ral. Gheorghe Magheru No. 28-30, Sector 1, 010336, Bucharest, Romania

12. What happens in the event of changes?

In the event of a significant change in the way the Company processes Customers' personal data and/or in the types of data processed and/or in any other aspect covered by this Policy, the Company will notify Customers appropriately and will publish an updated version of the Policy on its website.

We use cookies to ensure that our website works well for you, respecting all rules and good practices for the privacy of your personal data. Agreement page