Legal
Privacy Policy
Last updated: June 2026 · IRONIX SMART TRADE S.R.L.
IRONIX SMART TRADE S.R.L. is committed to protecting the personal data of individuals who interact with our website or communicate with us for business purposes. This Privacy Policy explains how we collect, use, store and protect personal data, and describes your rights under the General Data Protection Regulation (GDPR) and applicable Romanian law.
1. Data Controller
The data controller responsible for the processing of your personal data is:
IRONIX SMART TRADE S.R.L.
CUI: 54264923
Registration No.: J2026017521000
Registered office: București Sector 3, Drumul Gura Caliței, Nr. 4-32, Bloc 5, Scara A, Apartament B23, Romania
Phone: 0773858052
For any data protection inquiries, please contact us at the address listed above or by phone.
2. Scope and Legal Basis
This Privacy Policy applies to all personal data processed through the website ironixsmartrade.ro and through any direct B2B communication channels.
We process personal data in accordance with:
— Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR)
— Romanian Law No. 190/2018 on measures for the implementation of the GDPR
— Directive 2002/58/EC (ePrivacy Directive) as implemented in Romanian law
3. Personal Data We Collect
We may collect and process the following categories of personal data:
Contact form data: company name, contact person name, business email address, phone number, country, product enquiry details and estimated quantity.
Technical data: IP address, browser type, operating system, page visit timestamps — collected through server logs and/or analytics tools for security and operational purposes.
Communication data: messages, emails or phone call records related to B2B enquiries and cooperation discussions.
We do not collect sensitive categories of data (health, political opinions, biometric data, etc.).
4. Purposes and Legal Bases for Processing
We process personal data for the following purposes:
a) Responding to B2B enquiries and requests
Legal basis: Article 6(1)(b) GDPR — processing necessary for pre-contractual measures taken at the request of the data subject.
b) Managing business relationships and cooperation
Legal basis: Article 6(1)(b) GDPR — performance of a contract to which the data subject is party.
c) Compliance with legal obligations
Legal basis: Article 6(1)(c) GDPR — compliance with applicable Romanian and EU law.
d) Legitimate business interests (website security, fraud prevention, basic analytics)
Legal basis: Article 6(1)(f) GDPR — legitimate interests pursued by the controller.
We do not process personal data for automated decision-making or profiling purposes.
5. Data Retention
We retain personal data only as long as necessary for the purpose for which it was collected:
— Contact form submissions: up to 2 years from the date of submission, unless a business relationship is established.
— Contractual data: up to 5 years following the end of the contractual relationship, in accordance with Romanian accounting and commercial law.
— Server logs: up to 90 days from collection.
After the retention period expires, data is securely deleted or anonymised.
6. Data Sharing and Transfers
We do not sell or rent personal data to third parties.
We may share data with:
— IT service providers and web hosting companies acting as data processors under appropriate Data Processing Agreements (DPAs).
— Accounting and legal service providers, where required by law.
— Public authorities, if legally required (e.g., tax authority, courts).
Any transfer of personal data outside the European Economic Area (EEA) is conducted only with appropriate safeguards in place (e.g., Standard Contractual Clauses approved by the European Commission).
7. Your Rights Under GDPR
As a data subject, you have the following rights:
— Right of access (Art. 15 GDPR): request confirmation of whether we process your data and obtain a copy.
— Right to rectification (Art. 16 GDPR): request correction of inaccurate or incomplete data.
— Right to erasure / "right to be forgotten" (Art. 17 GDPR): request deletion of data under certain conditions.
— Right to restriction of processing (Art. 18 GDPR): request that we limit how we use your data.
— Right to data portability (Art. 20 GDPR): receive your data in a structured, commonly used format.
— Right to object (Art. 21 GDPR): object to processing based on legitimate interests.
— Right to withdraw consent: where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at the address listed in Section 1. We will respond within 30 days. You also have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Website: www.dataprotection.ro
8. Cookies
This website may use cookies and similar technologies. For full details, please see our Cookie Policy page. You can manage your cookie preferences at any time through the cookie banner displayed on your first visit.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction or alteration. These measures include secure hosting, access controls and regular security reviews.
No method of data transmission over the internet is 100% secure. If you believe your personal data has been compromised, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The current version is always available on this page. The date of the last update is shown at the bottom of this page. We encourage you to review this Policy periodically.