Privacy Policy
Last updated: 24 September 2026
This policy explains which personal data we process through the customer portal shop.mdtrade.ro, for what purposes, on what legal basis and what rights you have, under Regulation (EU) 2016/679 (“GDPR”) and applicable Romanian law.
1. Who we are
The data controller is MD TRADE CONCEPT SRL, registered office at 30 Șantierului Street, Buftea, Ilfov County, Romania, Trade Register no. J2020000119155, VAT/Tax ID RO36004143, share capital RON 200. For any question about personal data you can contact us at phone +40 721 337 466, email vanzari@mdtrade.ro or by post at our registered office. We are not required to appoint a data protection officer; requests are handled directly by the company's management.
2. Who the portal is for
The portal is intended exclusively for businesses (B2B customers): installers, joinery and glass manufacturers, builders, architects and distributors. The personal data we process are mainly the contact details of the people who work for or represent these businesses.
3. What data we process, why and on what basis
- B2B account request: first and last name of the contact person, email, phone, company details (tax ID, name, trade register no., address), estimated purchase volume, your message, the submission date and IP address (to protect against abuse). Purpose: reviewing the request and opening the account. Basis: steps prior to entering into a contract and our legitimate interest in verifying who requests access (Art. 6(1)(b) and (f) GDPR).
- Customer account: name, login email, password (stored only in encrypted form), phone, login history (date, device, IP address). Purpose: secure access to the portal. Basis: performance of the contract and our legitimate interest in security (Art. 6(1)(b) and (f)).
- Quotations, orders, deliveries and invoices: contact person, delivery address, products, prices, payments, correspondence with the sales agent. Purpose: fulfilling orders and keeping accounting records. Basis: performance of the contract and legal obligations (Art. 6(1)(b) and (c)).
- Debt collection: notices about overdue invoices sent to the company's contact persons. Basis: performance of the contract and our legitimate interest in collecting amounts due (Art. 6(1)(b) and (f)).
- Emails about products, offers and news, sent to existing customers about products similar to those purchased (Art. 12(2) of Romanian Law 506/2004) or to those who have consented. Every email has an unsubscribe link and you may object at any time, free of charge. In these emails we measure whether the message was opened and which links were clicked (using a tracking image and redirected links), to learn which information is useful; if you do not want this, you can unsubscribe or write to us. Basis: our legitimate interest in informing our customers (Art. 6(1)(f)) and, where applicable, consent.
- Reminders about open quotations, at most two per quotation, with the option to opt out from the link in the email. Basis: legitimate interest (Art. 6(1)(f)).
- Support and complaints: messages sent by email, phone or through the portal. Basis: performance of the contract and legal obligations regarding warranty.
- Establishing or defending legal claims and legal obligations (accounting, tax, archiving). Basis: Art. 6(1)(c) and (f).
4. Your own customers' data (configurator and quotations)
In the configurator you can prepare quotations for your own customers and record their name, contact details and site address. For these data your company is the controller and MD TRADE CONCEPT SRL acts as processor: we keep them only to generate, save and display the quotation, we do not use them for our own purposes and we do not disclose them to anyone except the hosting provider. Our obligations as processor are set out in the B2B Terms and Conditions. Please enter only the data you need and inform your customers about the processing.
5. Who receives the data
- The provider of the Odoo platform (Odoo S.A., Belgium), which hosts the portal and the database.
- Courier companies (FAN Courier, Dragon Star) — only the data needed for delivery.
- The card payment processor (Banca Transilvania) — for online payments.
- Providers of email services and of software used internally (including messaging tools for internal approvals and software assistants), our accountant and advisers, under contract and bound by confidentiality.
- Public authorities (for example the Romanian tax authority ANAF), where required by law.
We do not sell personal data. Some software providers may process data outside the European Economic Area; in such cases we only use providers offering the safeguards required by the GDPR (adequacy decisions, for example the EU-US Data Privacy Framework, or standard contractual clauses).
6. How long we keep the data
- Account requests that are rejected or not completed: at most 12 months.
- Account and business relationship data: for the duration of the relationship and 3 more years after it ends (the general limitation period).
- Accounting documents (invoices, delivery documents): 10 years, as required by Romanian Accounting Law 82/1991.
- Unsubscribed addresses: we keep only the email address on a suppression list, so that we do not write to you again.
- Login history and technical security data: at most 12 months.
7. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability, the right to object (including, at any time, to marketing emails) and the right to withdraw consent, without affecting earlier processing. You can write to us at vanzari@mdtrade.ro; we reply within one month. You can also view and correct your account data directly in the portal, under “My profile”.
You have the right to lodge a complaint with the Romanian supervisory authority (ANSPDCP), 28-30 G-ral Gheorghe Magheru Blvd, Sector 1, Bucharest, www.dataprotection.ro, or with the supervisory authority of the EU country where you live or work.
8. Security
Access to the portal requires an account and password over an encrypted connection (HTTPS). Passwords are stored only in encrypted form. Employees' access to data is limited to what they need for their work.
9. Cookies
We only use the cookies needed for the portal to work and to remember your preferences. Details in the Cookie Policy.
10. Changes
We may update this policy; the version in force is the one published on this page, with the date of the last update shown above. We will notify you of significant changes by email or in the portal.