MONDAY - FRIDAY: 9:00 - 17:00   +40.761.217.771
Personal Data Security Policy

Regulation (EU) 2016/679 on data protection (RGPD) is directly applicable in the Member States after May 25, 2018.

This document was prepared in order to define the policy regarding the security of personal data, practiced by the personal data controller Sarmis International  Go S.R.L. and to ensure compliance of data storage and use with  the provisions of Regulation (EU) no. 679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

According to the aforementioned document (chapter Definitions, point 12), “personal data breach” is defined as a security breach that leads, accidentally or unlawfully, to the destruction, loss, alteration, or unauthorized disclosure of personal data transmitted, stored or otherwise processed, or to unauthorized access to them.

Considering  the fact that Sarmis International carries out processing that Regulation 679/2016 defines as "large-scale", in order to provide its clients' and collaborators' data with the highest possible level of personal data security, Sarmis International S.R.L has established procedures regarding the retention of personal data.

In this regard:

  • We have precisely established which data we process, the processing methods and the departments that use personal data
  • We have ensured that the processed data are not subject to excessive collection considering the purpose of the processing
  • We have identified all recipients of personal data and have clearly established the way in which they come into contact with the processed data
  • We have considered the possible risks regarding data security and have assessed the impact on data protection.
  • We have drawn up procedures for situations related to security data
  • We have drawn up, in order to easily control the way in which the data is processed, the data processing register, which contains the following elements:
  • The purposes for which they were collected;
  • The categories of persons concerned;
  • The categories of personal data;
  • The categories of recipients;
  • Transfers to a third country or an international organization;
  • The deadline for deletion;
  • General description of the technical and organizational security measures.
  • We have established the conditions for access and use of IT programs (firewall, individual and strong passwords for access, authorizations) that manage the personal databases
  • We have taken organizational measures to ensure that there is no risk of unauthorized, illegal processing, accidental or unlawful loss or destruction and we have insured ourselves against any accidental or illegal damage.
  • We have established the persons in charge of verifying the security of data storage systems and discovering possible security breaches
  • We have trained the staff (accounting, human resources, shipping, etc.) and collaborators to apply internal standards and procedures regarding the storage of personal data
  • We have established specific tasks for the staff who come into contact with personal data, in the sense of limiting the collection of data to those that are absolutely necessary to fulfill their job duties

In the event of a security breach or incident, Sarmis International staff is trained to stop processing activities until the causes of the security incident, the affected compartments, the limits of the incident, its consequences and data recovery are discovered in order to return to the previous situation.

Security breaches can have different causes: from the non-functioning or improper functioning of information systems to human errors. A study by personal data supervisory authorities on security breaches shows that most security incidents are due to human error: situations in which documents or files containing personal data are forgotten or lost.

If we have a reasonable degree of certainty that a breach of personal data processing security has occurred, we analyze to what extent the security incident may affect personal data and if the impact is significant, we report the security incident to our company manager, to the data protection officer and, if applicable, to the data protection supervisory authority and to the persons concerned by the incident (by email, text message, verbally, in writing, etc.). Not every security breach must be notified to the supervisory authority, but only those that, following the case analysis, generate major risks to the rights and freedoms of the data subjects.

In cases where notification to the authority is mandatory, this must be done "without delay", in principle no later than 72 hours from the date on which the operator became aware of the existence of the breach.

In a short time, we proceed to discover and remedy the causes that were the basis of the incident and limit the occurrence of unwanted consequences.

We also interrupt the operation of personal data if a person raises an objection to them.

For preventive purposes, we have established the possible consequences of the security incident:

  • accidental or unlawful destruction of personal data,
  • accidental or unlawful loss of control over personal data,
  • accidental or unlawful loss of access to personal data,
  • accidental or unlawful alteration of personal data,
  • unauthorized disclosure of personal data,
  • unauthorized access to personal data.

Given our knowledge and assessment of these, we make every effort to mitigate the immediate risk of harm.

We are not obliged to inform you directly if:

  • we have taken measures to ensure that your personal data cannot be accessed by any unauthorized person,
  • immediately after the security incident, we have taken measures to ensure that the high risk to your rights and freedoms is no longer likely to occur or
  • would involve disproportionate efforts, in which case we will inform you through other contact options (tel, email, post, etc.).

In practice, access to our products and services and their sale is based on opening an account and is protected by passwords. We recommend that you do not reveal your password to anyone and that you log out when you are no longer using your account. We also advise you to close the browser window in which you were working at the end of your navigation on the sites or services provided by Sarmis International

Unfortunately, no data transmission over the Internet can be guaranteed to be 100% secure. Consequently, despite our efforts to protect your personal information, Sarmis International cannot ensure or guarantee the security of the information transmitted by you to us, to and from our online services or our products. We therefore warn you that any information sent to us will be done at your own risk.

When we receive the information transmitted by you, however, we guarantee that we will make every effort to ensure its security in our systems, according to the security standards imposed by the Romanian legislation in force and the contracts or collaboration agreements that we conclude with those who process the data in our interest. Our proxies, even if they process data for us, have the legal obligation to process it in full security conditions.

We achieve physical data protection by: limiting access to the spaces and computers where the databases are located; limiting access to archives and documents containing personal data; installation of alerting or monitoring systems in the spaces where the databases are located.

We have established individual access codes for persons authorized to use the data and to prevent unauthorized persons from accessing the data processing areas.

In order to prevent unauthorized reading, copying, modification or deletion of the data medium, we have established the persons who can access the databases; we have eliminated outdated access permissions; we have established strong access passwords, which we change regularly; we have provided encryption means for laptops and storage devices (USB keys, CDs, DVDs, etc.); we have configured periodic backups and stored the backup materials in a single place.

We control the storage of data by allowing access only to persons specifically designated to store them, based on the assignment of an individual user identity and a confidential access code to these persons; no other person can enter data into the system.

In order to allow the exercise of the rights of the data subjects ("right to be forgotten", right of access to information, right to be informed, etc.) we have ensured that the personnel designated with data management services know the physical location of each server through which they administer the databases in question. This is required because electronic documents are more difficult to find than documents in physical format, the former being able to be transferred through backup systems, archives or to third parties/entities (e.g., Dropbox).

For the same purpose (i.e., the exercise of rights by the data subjects), we will require the review of the backup and storage protocols used by the data management service providers with whom we collaborate in the field of data security.

Determining the exact location of the servers is also useful to determine the legislation applicable to the various operations.

We do not allow entry into the system, reading or transferring data other than to persons designated by law in this regard and only if there is a legal obligation in this regard. If data transmission is necessary, we only allow it by using appropriate encryption techniques, which ensure control of data transport.

We constantly monitor the effectiveness of the above-mentioned security measures and take the necessary organizational measures regarding internal monitoring to ensure compliance with the Regulation.

All our collaborators are obliged, by agreement, to take these measures.

Performing unauthorized operations on the data we hold and attempting to perform them, including: abusive use, fraudulent use, unauthorized access, modification, copying information for the purpose of marketing it, blocking access and others of this kind, will be punished according to the law.

This security policy is completed with the specific provisions  of Regulation 679/2016, as well as the internal procedures we have developed for situations related to data security.