Privacy policy
regarding the processing of personal data through the beautik.ro website
February 2026
Green Net SRL, with its registered office in Bucharest, Calea Dorobanților, No. 187B, 4th Floor, Sector 1, with CUI: RO 12163923 and registration number in the Trade Register: J1999007800401, as the controller of personal data processed through the website www.beautik.ro (hereinafter referred to as the "website"), hereby informs you of the conditions under which it processes personal data when you access the website and use its features.
This privacy policy is based on the provisions of Regulation No. 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC ("General Data Protection Regulation" or "GDPR") and applicable national legislation.
The GDPR defines personal data as: "any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person."
Green Net undertakes, through the provisions of this policy, to implement the highest standards of confidentiality and transparency with regard to the personal data it processes in its current activity. Protection and transparency with regard to the processing of your personal data in our activity is our priority.
Your use of our services is subject to this policy, the terms and conditions of use of the Site and the Cookie Policy[AL1] . By using our site, you accept these terms and conditions of use of the Site.
- What categories of personal data do we process?
Depending on the circumstances in which your personal data is transmitted to us, we may process the following categories of personal data:
- Information you provide to us directly as a result of submitting a general request for information: first name, last name, email address, and/or phone number.
- · Information you provide directly when creating a customer account on the website: first name, last name, email address, phone number, consent to marketing communications, and agreements regarding terms and conditions and privacy policy.
- Information you provide when placing an order for products on the website: delivery address, contact details of the person receiving the delivery (if the products are delivered to another person).
- Information you provide us with, without creating a customer account, when you subscribe to marketing communications via the newsletter subscription button: email address and subscription date.
- Information you provide us with when requesting a refund for returned products: IBAN account.
- Information we observe about you when you use the website: IP address, type of device used to log into your customer account, time and duration of each session in your customer account, actions taken in the customer account, order history, products added to the favorites list or shopping cart (when you do not complete the order process).
- Information we calculate based on your behavior and preferences on the website and your purchasing behavior, in order to send you personalized commercial communications.[AL2]
- Purposes and grounds for processing
- Resolving your requests
We collect personal data relating to your name, email address, telephone number, and job title (if applicable) in order to maintain correspondence with you. Thus, if you make a request, we will process your data in order to resolve it. In this context, if necessary, we may forward your contact details to financial and government institutions, transport companies, the postal service, or other entities that provide services to Green Net.
The basis for processing your data in this context is your consent – Art. 6(1)(a) of the GDPR. If additional processing operations become necessary, the basis for processing may be the legitimate interest of Green Net – Art. 6(1)(f) of the GDPR.
- Creating and managing customer accounts
We collect and process the personal data of users who request the creation of an account in order to generate the account and allow users to place orders in the online store on the website. In addition to the data provided when creating the account, we store information about the session initiated by the customer, their actions (changes to contact details, county, city, address, password changes).
The basis for processing your data in this context is Article 6(1)(b) of the GDPR – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. In order to facilitate the placement of orders and reduce the time allocated for placing orders, users can define favorite delivery addresses, which are associated with their customer account in the online store.
The basis for processing your data in this context is your consent – Art. 6 para. (1) lit. a of the GDPR.
- Order management, including order acceptance, validation, dispatch, and invoicing
The basis for processing your data in this context is Art. 6 para. (1) lit. b of the GDPR – processing is necessary for the performance of a contract to which the data subject is party. With regard to the preparation of invoices for user purchases, the processing of personal data is carried out on the basis of Art. 6 para. (1) lit. c of the GDPR – legal obligations in tax matters, OMFP 2634/2015 on financial and accounting supporting documents.
- Resolving cancellations or problems of any kind relating to an order, purchased goods or services, including returns and refunds for returned products
The basis for processing your data in this context is Article 6(1)(b) of the GDPR – the sales contract concluded between Green Net and the user (customer).
- Implementing and auditing website protection measures and implementing measures to prevent and detect fraud attempts, including the transmission of information to the competent public authorities
In this case, the basis for processing your data is the legitimate interest of the controller – Art. 6 para. (1) lit. f) of the GDPR. Given that the implementation of security measures and measures to prevent and detect fraud attempts are measures whose main purpose is to ensure the confidentiality of personal data belonging to customers and users of the website, the legitimate interest of the controller prevails over the rights of the data subjects.
- Improving the services offered to customers and their experience in the online store by sending them satisfaction surveys regarding their shopping experience on the website
In this case, the basis for processing your data is the legitimate interest of the controller – Art. 6(1)(f) of the GDPR.
- Sending marketing communications to the email addresses of customers and users
For website users and customers who haven't placed orders, the basis for processing personal data is the consent of these people, shown by checking the box on the customer account creation form, or by filling in their email address in the pop-up window and clicking the "Subscribe" button – Art. 6(1)(a) of the GDPR.
For customers who have placed orders through the website, the basis for processing is the legitimate interest of the controller in maintaining the contractual relationship already established – Art. 6(1)(f) of the GDPR.
In any of the above situations, unsubscribing or exercising the right to object can be expressed by simply accessing the unsubscribe link available in any commercial communication.
In the case of communications regarding orders/their status/complaints/reports, there is no possibility to unsubscribe.
Pursuant to Art. 6 para. (1) lit. a) of the GDPR – user consent, we may collect and use certain information about your behavior on the website through cookies and other tracking technologies. Details about the cookies placed, their storage duration, and purpose can be found in the Cookie Policy.
- How long we keep your personal data
As a general rule, the processing of personal data based on consent ceases when consent is withdrawn, which is equivalent to deleting your data from our databases. Please note that exercising your right to withdraw consent only has effect for the future, which means that processing prior to exercising this right remains valid.
If a customer account is inactive for a period greater than or equal to 2 (two) years from the date of the last login to the account, the personal data provided for the purpose of creating the account will be deleted.
In the case of processing based on legitimate interest, the storage period for your data is 3 years from the date of the last contact with you.
For processing based on a contract, the duration is 3 years from the date of the last contact with the customer. The storage period for your data based on a contract may be extended if there are legal provisions requiring the storage of such data for a certain period of time, such as legal obligations in tax matters.
If a dispute arises between Green Net and you, your personal data will be stored in our systems until the dispute is finally resolved.
- Recipients of your personal data
Where appropriate, we may transfer or provide access to certain of your personal data to the following categories of recipients:
- companies within the same group of companies as Green Net – for internal administrative purposes or for auditing and monitoring our internal processes. Access to your personal data is limited to those employees who need to know the personal data and who are subject to strict confidentiality commitments;
- courier service providers;
- marketing/telemarketing service providers, website hosting and maintenance service providers;
- payment processing service providers;
- market research service providers;
- other companies with which we may develop joint programs to offer our goods and services on the market;
- third-party purchasers, to the extent that Green Net's business is transferred (in whole or in part) and personal data is part of the assets subject to such a transaction, or to other companies in the group to which Green Net belongs, which will comply with Green Net's instructions regarding the processing of your personal data;
- public institutions or authorities that request the provision of personal data in order to fulfill their legal duties.
- To which countries do we transfer your personal data
We currently store and process your personal data in Romania.
- How we ensure the security of your personal data
Ensuring the confidentiality of the personal data you provide to us is an important concern for us. We have implemented technical and organizational measures to maintain the confidentiality and security of your personal data, in accordance with our internal procedures regarding the storage, disclosure, and access to personal data. Personal data may be stored on our personal data technology systems, those of our contractors, or in printed form.
Your personal data is transmitted using state-of-the-art encryption algorithms and stored on secure servers, while ensuring data redundancy.
The information you provide through this website is transmitted and verified automatically, in encrypted form, using an SSL (Secure Socket Layer) protocol. We do this to prevent the misuse of data by third parties.
With regard to other situations in which we process your personal data, we are constantly taking measures to increase employee training in compliance with data protection regulations, and Green Net employees are subject to strict confidentiality commitments.
- Your rights
The GDPR has established a series of rights for data subjects with regard to the processing of their data by controllers. In this context, you may request access to your data, the correction of any errors in our files, and/or you may object to the processing of your personal data in certain cases. In the cases provided for by the GDPR, you may also have the right to data portability.
You may also exercise your right to lodge a complaint with the competent Supervisory Authority or to seek legal redress. Where applicable, you may also have the right to request the erasure of your personal data, the right to restrict the processing of your data, and the right to data portability.
To exercise your rights, you can contact us:
– by email at:[email protected]
When submitting requests to exercise your rights under the GDPR, please send us your requests regarding such records using the email address/identification data you use in your relationship with us. Otherwise, we will need to ask you for additional information to verify your identity.
We will respond to any legitimate requests within a maximum of one month, unless the facts or complexity of your request require an extension of this period.
You also have the right to contact the National Supervisory Authority for Personal Data Processing (ANSPDCP) for the above-mentioned cases, if you have any questions or complaints, at the following addresses: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336 or[email protected].
- Changes to the privacy policy
We periodically review our Privacy Policy to reflect changes in our services and legislation regarding the processing of personal data. Whenever possible, we will inform you of any changes, but please check the content periodically. The date of publication and version number are displayed at the beginning of this policy.














