My cart

Empty

Privacy Policy

iPiata Privacy Policy

Last updated: 28 March 2026

1. Data Controller

The data controller is BANA RARES-NICOLAE AUTHORIZED NATURAL PERSON (PFA), commercial name iPiata, VAT/CIF RO33388821, registration no. F2014000987292, professional address: Str. Natiunii no. 65, Ploiesti, Prahova, Romania. Contact: [email protected].

2. What Data We Collect and Legal Bases

Data CategoryExamplesPurposeLegal Basis (GDPR)
Identification dataFirst name, last name, emailAccount creation and managementArt. 6(1)(b) - contract performance
Contact dataAddress, phoneDelivery and communicationArt. 6(1)(b) - contract
Financial data (sellers)IBAN, VAT number, company detailsPayment processing, settlement, fiscal obligationsArt. 6(1)(b)(c) - contract and legal obligation
Usage dataIP, browser, pages visitedSecurity, platform improvementArt. 6(1)(f) - legitimate interest
CookiesSession ID, preferencesFunctionality and analyticsArt. 6(1)(a) - consent (non-essential cookies)
Marketing dataEmail preferencesNewsletter (if consented)Art. 6(1)(a) - consent, withdrawable at any time

3. International Data Transfers

Your data may be transferred to service providers outside the EEA (e.g. Stripe - USA). These transfers are protected by Standard Contractual Clauses (SCC) under art. 46 GDPR.

4. Retention Periods

  • Active account data: for the duration of the active account
  • Financial and fiscal data: minimum 10 years per Romanian accounting legislation
  • Marketing data: until consent is withdrawn
  • Security logs: maximum 12 months

5. Your Rights (GDPR art. 15-22)

  • Right of access to personal data (art. 15)
  • Right to rectification of inaccurate data (art. 16)
  • Right to erasure - right to be forgotten (art. 17)
  • Right to restriction of processing (art. 18)
  • Right to data portability (art. 20)
  • Right to object (art. 21)
  • Right to lodge a complaint with the Romanian supervisory authority (ANSPDCP) - dataprotection.ro, tel. +40.318.059.211

To exercise your rights, send a request to [email protected]. We respond within 30 calendar days.

6. Applicable Law

Data processing is governed by GDPR (Regulation (EU) 2016/679), Romanian Law no. 190/2018, and Law no. 506/2004.