Privacy Policy
Last updated: August 2026. This policy describes how AWA FLOT SRL processes the personal data of AAFIT online store users.
1. Data controller
AAFIT is the brand under which AWA FLOT S.R.L., registered office at Bd. Pipera nr. 1/VII, Etaj 6, Camera 4, Voluntari, Ilfov, 077190, Trade Register no. J29/1364/2023, CUI RO48354568, operates www.aafit.ro and www.aafit.eu. Under the GDPR (Regulation (EU) 2016/679), AWA FLOT S.R.L. is the controller of your data. Contact us at comenzi@aafit.ro or the postal address above. We process data under the GDPR, Romanian Law 190/2018 and Law 506/2004.
2. What data we collect
- Identification: first/last name; for companies — name, VAT/registration numbers.
- Contact: e-mail, phone, delivery and billing address.
- Order data: products ordered, value, history, returns, support correspondence.
- Payment data: payment method and transaction confirmation. We do not store full card details — card payments are processed directly by authorised (PCI-DSS) processors.
- Account data: e-mail and hashed password, preferences, wishlist, saved addresses.
- Google login data: if you sign in with Google — name, e-mail and Google account ID (not your password).
- Browsing data (cookies): IP, device, browser, pages visited, traffic source, cookie identifiers. See the Cookie Policy.
- Marketing data: newsletter subscription status and e-mail interactions.
- Reviews: ratings and reviews you post, with the displayed name.
We do not seek to process special categories of data (health, ethnicity, religion, etc.).
3. Purposes and legal bases
- Processing, delivering and invoicing orders — basis: performance of the contract (Art. 6(1)(b)).
- Issuing invoices and legal obligations — basis: legal obligation (Art. 6(1)(c)), accounting and tax law.
- Creating and managing your account — basis: performance of the contract (Art. 6(1)(b)).
- Marketing communications (newsletter) — basis: consent (Art. 6(1)(a)), withdrawable anytime; legitimate interest for similar products to existing customers, with an unsubscribe option.
- Analytics and service improvement — basis: legitimate interest (Art. 6(1)(f)); for analytics/marketing cookies (GA4, Meta Pixel, TikTok Pixel), the basis is consent given via the cookie banner.
- Fraud prevention and security — basis: legitimate interest and/or legal obligation.
- Product reviews — basis: legitimate interest.
- Handling requests and disputes — basis: legitimate interest / legal obligation / performance of the contract.
4. How we collect data
We collect data directly from you (orders, account, newsletter, forms), automatically via cookies while browsing, and from third parties when you sign in with Google.
5. Recipients and processors
We disclose data only as needed, to recipients generally acting as processors under Art. 28 GDPR contracts:
- Courier: GLS — delivery, AWB, tracking.
- Invoicing: SmartBill.
- Payment processors: Stripe, PayPo, Klarna, TBI Bank — as independent controllers for the payment leg.
- E-mail: Brevo — transactional e-mail and newsletter.
- Analytics and advertising: Google (GA4), Meta (Pixel), TikTok (Pixel) and Google (Login) — only with consent.
- Hosting and IT, professional advisers, and public authorities where legally required.
We do not sell your data.
6. Transfers outside the EU/EEA
We process data primarily in the EU/EEA. Some providers (Google, Meta, TikTok) may process data outside the EU/EEA (e.g. the USA), with safeguards under Chapter V GDPR: adequacy decisions (Art. 45) and/or Standard Contractual Clauses (Art. 46). Ask for details at comenzi@aafit.ro.
7. Retention
- Order and customer data: for the contractual relationship + legal archiving terms.
- Accounting documents / invoices: per tax law (term confirmed by our accountant).
- AAFIT account: until account deletion.
- Marketing / newsletter: until unsubscribe or after a period of inactivity.
- Cookies: per the Cookie Policy.
- Correspondence and complaints: as needed + the limitation period (generally 3 years).
8. Your rights
Under GDPR (Art. 15-22) you have the rights of access, rectification, erasure, restriction, portability, objection (including, unconditionally, to direct marketing), withdrawal of consent at any time, and not to be subject to solely automated decisions with significant effects (we use none). You may also lodge a complaint with ANSPDCP (Section 11).
9. How to exercise your rights
Send a request to comenzi@aafit.ro or, if you have an account, use "My account" (update, export, delete). We may verify your identity. We respond within one month (extendable by up to two months for complex requests). Exercising your rights is, in principle, free.
10. Data security
We apply appropriate technical and organisational measures: HTTPS/TLS encryption, hashed passwords, role-based access control, logging, backups and processing agreements with our providers. No internet transmission is 100% secure; please protect your credentials.
11. Minors
AAFIT's services are intended for persons aged at least 16. We do not knowingly collect data of minors under 16 without a parent/guardian's consent. If you learn a minor has provided us data, contact comenzi@aafit.ro.
12. Complaint to ANSPDCP
If you believe processing infringes your rights, you may contact the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): B-dul G-ral Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest; +40.318.059.211 / +40.318.059.212; anspdcp@dataprotection.ro; www.dataprotection.ro. You may also go to the competent courts.
13. Changes
We may update this policy periodically. The version in force is the one published on the Site, with the last-updated date. We may inform you further of significant changes.