GDPR Policy — Personal Data Protection
Last updated: 04.10.2026
1. Legal Framework
The Clever Lab S.R.L. complies with the provisions of Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as "GDPR"), as well as applicable national legislation (Law No. 190/2018).
2. Our Commitment
We commit to:
- Process personal data lawfully, fairly, and transparently.
- Collect data only for specified, explicit, and legitimate purposes.
- Ensure that collected data is adequate, relevant, and limited to what is necessary.
- Keep data accurate and up to date.
- Retain data only for as long as necessary for the established purposes.
- Ensure data security through appropriate technical and organizational measures.
3. Implemented Security Measures
To protect your data, we have implemented the following measures:
- SSL/TLS Encryption: All connections to the website are secured via SSL certificate (HTTPS).
- Secure payment processing: Payments are processed through NETOPIA Payments, a PCI-DSS certified system. We do not store or have access to your card data.
- Restricted access: Access to personal data is limited to authorized personnel only.
- User passwords are stored encrypted (hashed) and cannot be recovered or viewed by anyone.
- Regular backups of the database to prevent data loss.
4. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right to information — to be informed about data processing.
- Right of access — to obtain confirmation of processing and a copy of the data.
- Right to rectification — to request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — to request deletion of data, subject to legal obligations.
- Right to restriction of processing — under certain conditions provided by GDPR.
- Right to data portability — to receive data in a structured, commonly used, and machine-readable format.
- Right to object — to oppose processing in certain situations.
- Right to lodge a complaint with ANSPDCP (www.dataprotection.ro).
5. Exercising Your Rights
To exercise any of the rights mentioned above, you may contact us at:
- Email: [email protected]
We will respond to your request within a maximum of 30 calendar days from receipt of the request.
6. Data Security Breach
In the event of a personal data security breach that poses a risk to the rights and freedoms of data subjects, we will notify the National Supervisory Authority (ANSPDCP) within 72 hours, in accordance with Art. 33 GDPR. If the breach poses a high risk, we will also notify the affected data subjects.
7. Contact — Data Protection Officer
The Clever Lab S.R.L.
Strada Sinaia, Nr. 17
Ștefăneștii de Jos, 077175, Ilfov, Romania
Email: [email protected]