Home>Privacy Policy

Privacy Policy

Preamble

This Privacy Policy governs the manner in which MDMaison collects, uses, maintains, and discloses information collected from the users of its website. This Privacy Policy only covers information collected through MDMaison’s Website www.mdmaison.com and it does not apply to third-party websites or external links that our website could redirect you to.

MDMaison is committed to ensuring that your privacy is protected, and we are compliant with the General Data Protection Regulation (EU) 2016/679 and applicable law. By using our website (www.mdmaison.com), or by purchasing any products from it you agree that you have read and accepted MDMaison’s Privacy Policy. If you do not agree with this Privacy Policy, we advise you to cease using our Website immediately.

Regulation 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation in this document - GDPR, Regulation or RGPD) was adopted by the European Parliament and the Council of the European Union on 27 April 2016, its provisions being directly applicable as of 25 May 2018. This Regulation expressly repeals Directive 95/46/EC, thus replacing the provisions of Romanian Law no. 677/2001 (currently repealed).

The regulation is directly applicable in all Member States, protecting the rights of all natural persons located within the territory of the European Union. From a material point of view, the Regulation applies to all operators who process personal data. The Regulation does not apply to the processing of personal data concerning legal persons and, in particular, undertakings with legal personality, including the name and type of legal person and the contact details of the legal person.

Personal data is defined as any information about an identified or identifiable natural person ("data subject"); an identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifying element, such as a name, an identification number, location data, an online identifier or one or more specific elements of his physical, physiological, genetic, mental, economic, cultural, or social identity.

The processing of personal data involves any operation or set of operations performed on personal data or data sets, with or without the use of automated means such as collecting, recording, organizing, structuring, storing, adapting or modifying, extracting, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, deletion or destruction.

Different Types of Personal Data That We May Collect

Information Regarding Personal Identification and Non-Personal Identification

We can collect personal identification information from our Users in a variety of ways, including, but not limited to, when Users visit our Site, register on the Site, place an order (either online or via phone call), fill out a form, respond to a survey, subscribe to our newsletter, and in connection with other activities, services, features, or resources we make available on our Site.

We will only collect personal identification information from our Users if they voluntarily submit such information to us. Users can always refuse to supply personal identification information. If you choose not to submit personal information to us, please take into consideration that this action may prevent you from accessing certain Website-related activities or engaging in certain privileged areas of our website (such as the User Control Panel Menu).

You have control over the personal data information that you provide us with. For example, we can collect your personal information in the following manners:

  • When you create an account on www.mdmaison.com, you provide us with your name/surname, your e-mail address, and/or a phone number.
  • In the User Control Panel Menu from our website, you have the option to add different other personal information which will make your experience on our website better (such as, but not limited to: date of birth, the city where you live, the address where you prefer your packages to be delivered, the preferred payment method, alternate phone number, etc.).
  • When you place an order, either online or via phone call, we can collect information such as: your name/surname, e-mail address, payment method, delivery address, etc.

We may collect non-personal identification information from you whenever you interact with our website. This type of information may consist of:

  • The type of browser from which you accessed our website.
  • The IP address of the device you used to connect to our website.
  • The website which redirected you to www.mdmaison.com.
  • The operating system of the device.
  • The Internet service provider used.

Web Browser Cookies

We use "cookies" to enhance an advanced and user-friendly experience on our website. The web browser you are using can also place cookies on your hard drive. You have the option to set the web browser to refuse storing cookies, or to alert you when cookies are being sent. If you choose to activate that option, please take into consideration that some parts of our Website may not function properly.

The Legal Basis of Processing Personal Data

The legal basis of processing the personal data stated above resides in article 6 letter c) and f) of the General Data Protection Regulation of E.U. 2016/679, in particular because all the personal data we request from you: i) is necessary for compliance with a legal obligation to which MDMaison is subject and ii) is intended to accomplish our legitimate interests. Furthermore, the legal basis of processing data collected through cookies (if you accept cookies) resides in article 6 letter a) from the Regulation, meaning that you give us your express consent regarding this type of data processing.

Duration of the Processing

As a general rule, we will store your personal data as long as you have an account on our website. You can ask us at any time to delete certain information and we will respond to these requests, subject to the preservation of certain information including after closing the account, in cases where applicable law or our legitimate interests require it. We review the data collected, at least every two years, analyzing the extent to which their retention is necessary for the purposes mentioned, your legitimate interests, or the fulfillment of legal obligations by MDMaison.

Purposes of Processing Personal Data

MDMaison collects and uses Users’ personal information for the following purposes:

  • To Improve Our Customer Service: The information we collect from you helps us to be more effective in response to your customer service requests and support needs. We aim to constantly improve our customer service to provide our users with the most efficient and intuitive online services.
  • To Personalize Your Experience on Our Website: We may use the information you provide us to understand how you use the services and resources provided on our Site, and what your preferences are regarding our products. We aim to create an intuitive interface that will make your experience online much easier and more helpful.
  • To Improve Our Website: We are engaged in continually improving our website offerings and options, based on the information and feedback we receive from our users. We strongly believe that by working closely with our customers, listening to their needs or preferences, we can provide a fully functional and well-organized website that will suit the majority of customers’ tastes.
  • To Process Transactions Regarding Your Order: We use the information you provide us with when placing an order on our website only to provide service to that order. We do not share this information with outside parties except to the extent necessary to provide the delivery service.
  • To Send Periodic Emails: When you make an online order on our website, among other personal data, you provide us your email address. The email address you provide us in this procedure will only be used to send you the information and updates relevant and helpful regarding your order. It may also be used to respond to your inquiries, and/or other requests or questions.
  • Newsletter Subscription: You will have the opportunity to opt-in to our newsletter (mailing list). If you choose to subscribe to our newsletter, you will receive emails that may include company news, updates, related product or service information, new arrivals, changes that occur on our website, etc. If at any given time you would like to unsubscribe from receiving our newsletter via email, we will include unsubscribe instructions at the bottom of each email or you may contact us via email at info@mdmaison.com. If you decide to write us an email to unsubscribe from our newsletter, please provide your full name, mailing address, email address, and phone number when sending this request.

How We Secure Your Personal Information

In order to secure the personal information which we collect, we adopt appropriate data collection, storage, and processing practices and security measures to protect against unauthorized access, alteration, disclosure, or destruction of your personal information, username, password, transaction information, and data stored on our Website.

Sensitive and private data exchange between our website and our users happens over an SSL secured communication channel and is encrypted and fully protected.

Your MDMaison account (if you choose to create one) information is password-protected for your privacy and security. MDMaison will never ask you for your password in an unsolicited phone call or email. You are responsible for maintaining the secrecy of your password and account information. Remember to sign out of your account and close your browser window when you have finished shopping to help ensure that others cannot access your personal information. MDMaison reserves the right to refuse service, terminate accounts, ban accounts, remove or edit content or cancel orders at any time if there are reasonable suspicions regarding a certain user account.

Regarding online payments, when you submit sensitive information via the checkout on our website, that information is encrypted and protected by Secure Sockets Layer (SSL) advanced encryption technology. In no circumstance will we store that type of information, nor will we be able to view your full payment details and hence we cannot retrieve any data related to your banking details.

Access to your personal information will only be granted to our authorized personnel and only for the purpose of fulfilling the duties specific to accomplishing the purposes we stated above. Our personnel have the legal and contractual obligation to keep your data secured and confidential.

If at any given time a data breach occurs on our website or on the servers where it is hosted, we will contact all users via email to notify them about the breach and the next measures/steps that need to be taken to maintain the security of their personal information. We will also notify the Romanian National Supervisory Authority for Personal Data Processing within 72 hours since the breach occurred.

Contact Form

If you send us questions via the contact form, we will collect the data entered in the form, including the contact details you provide, to answer your and other questions. We do not transfer this information without your permission. Therefore, we will process all data that you enter in the contact form only with your consent [in accordance with the provisions of art. 6 par. 1 a) GDPR]. You can revoke your agreement at any time, as an informal email will be sufficient. Data processed before your request is received may be legally processed. We will keep the data you provide on the contact form until you request data deletion, revoke your consent for their storage, or the purpose for its storage is no longer valid.

Google Analytics

We use Google Analytics, a web-analytics service, operated by Google Inc., 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. Google Analytics uses "cookies" to analyze the use of the website by you. The information generated by the cookie about your use of this website is usually transmitted to a Google server in the USA and stored there.

This website uses Google Analytics exclusively with the extension "_anonymizeIp()", which ensures an anonymization of the IP address by shortening it and excludes a direct personal relationship.

You can prevent these cookies from being stored by selecting the appropriate settings in your browser. However, doing so may mean you will not be able to enjoy the full functionality of this website. You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en.

For more information about how Google Analytics handles user data, see Google's privacy policy: https://support.google.com/analytics/answer/6004245?hl=en.

Contacting Us by Email or Telephone

If you contact us by email or telephone, your request, including any personal data you provide, will be stored and processed by us for the purpose of resolving your request, based on your consent.

We will keep the data you provide in this way until you request data deletion, revoke your consent for their storage, or the purpose for its storage is no longer valid, except for mandatory data retention periods.

Site Registration (User Account)

You can register on this website to access additional features and services offered by our company. The data you enter will be used and processed to use the service or functions for which you have registered. The required registration data must be provided by you in its entirety, otherwise, the registration operation will be rejected.

The processing of personal data provided in the registration procedure is done only with your consent and in compliance with the provisions of art. 6 par. 1 a) GDPR. You can revoke your agreement at any time by sending an informal email. We will continue to store data collected during registration as long as you remain registered on this website, but mandatory storage periods remain valid and will be respected.

Shipping & Delivery

We ensure, through courier services, the delivery of the products ordered by you. The personal data processed for the delivery of orders placed are protected by each provider of such services, in accordance with its own Privacy Policy. The legal basis for processing the data necessary for the processing of deliveries is represented by art. 6 par. 1 a) GDPR (you, as the data subject, have given your consent for the processing of personal data for the purpose of delivery of orders), art. 6 par. 1 b) GDPR (processing is necessary for the execution of a contract in respect of which you are the beneficiary) and art. 6 par. 1 f) - the processing is necessary for the purpose of the legitimate interests pursued by the controller or a third party, unless the interests or fundamental rights and freedoms of the data subject prevail, which require the protection of personal data, especially when the data subject is a child.

The purposes for which the personal data are processed are expressly set out in the Privacy Policy of the providers of such services.

Online Payments

We use secure encryption methods for online payments, and data is transmitted over high-security connections to financial units. The data you provide for payment is not passed on to third parties and is not saved in databases.

We offer the following payment methods:

  • Card Payment with Stripe: Secure payment can be made using Stripe. Stripe is a payment service provided by Stripe, Inc. which processes payments securely. When you make a payment through Stripe, your payment information is transmitted directly to Stripe and is subject to Stripe's privacy policy. For more information on how Stripe handles your data, please visit Stripe's Privacy Policy.
  • Bank Transfer: Once your order is confirmed, we will send you our bank details along with an invoice or a Stripe payment link for easy payment. Your order will be shipped within the specified delivery times for each product as soon as we receive your payment.

Your Rights

According to the General Data Protection Regulation 2016/679, you have the following rights:

  • The Right to Be Informed: You have the right to be informed about the collection and use of your personal data.
  • The Right of Access: You have the right of access to your personal data. You can ask for confirmation of whether your data is being processed or not, other supplementary information, or a copy of the personal data that is processed.
  • The Right to Rectification: You can ask the data controller to rectify inaccurate or incomplete data.
  • The Right to Erasure: You can ask the data controller to erase your personal information data that has been processed.
  • The Right to Restrict Processing: You have the right to limit the processing of your personal data in case you consider that the information is not accurate and in other circumstances as stated in the Regulation.
  • The Right to Data Portability: You have the right to receive your personal data which you have provided to the data controller, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
  • The Right to Object: You have the right to oppose any processing of personal data.
  • The Right to Not Be Evaluated Based on Automated Processing: You have the right not to be subject to a decision that is based solely on automated processing and which significantly affects you.

Changes to This Privacy Policy

We reserve the discretion to update this privacy policy at any time. When we update our policy, we will inform you at the top of the webpage when the document has been last modified. We strongly encourage and advise you to frequently check this page for any changes that may occur, to stay informed about how we are helping to protect the personal information we are collecting. Thus, you acknowledge and agree that it is your responsibility to review this privacy policy periodically and become aware of the changes that have been made to it over time.

Your Acceptance of These Terms

By using www.mdmaison.com, you accept this policy and our Terms and Conditions. If you do not agree to this policy, please cease using this website immediately. If you continue using our Website following the posting of changes to this policy, it will be considered that you have read and accepted the updated form of this policy.

Contacting Us

If you have any questions about this Privacy Policy, about how your data is being processed, or any other question regarding this matter, please contact us at:

  • Phone number: +372 602 7370
  • Email address: info@mdmaison.com