Privacy Policy
Website: https://www.coresi.ro
Online Store: Librăria Constelații
Operator: CORESI PUBLISHING HOUSE S.R.L.
Document version: 2.0
Effective date: 01 August 2026
Last updated: 01 August 2026
1. General Information
This Privacy Policy (the “Policy”) describes how CORESI PUBLISHING HOUSE S.R.L. (the “Operator” or “we”) collects, uses, stores, discloses, and protects the personal data of individuals who use the website available at https://www.coresi.ro (the “Website”).
The Operator processes personal data in accordance with:
- Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data (the “GDPR”);
- Law No. 190/2018 on measures for implementing the GDPR;
- Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector;
- as well as any other applicable legislation.
Respecting privacy and protecting personal data are priorities for the Operator. Data are processed in accordance with the principles set out in Regulation (EU) 2016/679, namely lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, as well as the principle of accountability, with the Operator being able to demonstrate compliance with these principles.
This Policy applies to all individuals who:
- visit the Website;
- create a user account;
- place orders;
- request information;
- communicate with the Operator by any means;
- use the services available through the Website.
Where certain services are accompanied by additional information concerning data protection, that information supplements this Policy.
2. Identity of the Operator
The operator of the personal data is:
CORESI PUBLISHING HOUSE S.R.L.
Unique Registration Code (CUI): 38064877
Trade Registry No.: J40/13941/2017
Registered office:
Strada Viitorului nr. 125
Camera 2, Etaj 1, Apartament 6
Sector 2, 020301 Bucharest
Romania
Publishing Office (correspondence and customer relations):
Strada Agricultori nr. 37–39
Etaj 4, Birou 401
Sector 2
Bucharest
Romania
Telephone: +40 (722) 156408
E-mail: [email protected]
Website: https://www.coresi.net
The Operator determines the purposes and means of processing personal data and is responsible for compliance with the obligations provided by applicable data protection legislation.
3. Contact Details Concerning Data Protection
For any request concerning the processing of personal data or for exercising the rights provided by the GDPR, data subjects may contact the Operator using the following contact details:
E-mail: [email protected]
Telephone: +40 (722) 156408
Correspondence address:
Strada Agricultori nr. 37–39
Etaj 4, Birou 401
Sector 2, Bucharest
Romania
As of the date of publication of this Policy, the Operator is not legally required to appoint a Data Protection Officer (DPO).
Data protection requests are handled directly by the Operator, in compliance with the time limits and conditions provided by Regulation (EU) 2016/679.
4. Categories of Data Subjects
This Policy applies to the following categories of individuals whose personal data may be processed:
- visitors to the Website;
- users who create an account;
- customers who place orders;
- recipients of ordered products;
- individuals who request information through the contact form, e-mail, or telephone;
- individuals who submit complaints, return requests, or requests concerning the legal guarantee of conformity;
- individuals who subscribe to the newsletter or other commercial communications;
- representatives, employees, or contact persons of corporate customers and commercial partners;
- individuals who publish reviews or other materials on the Website, where this functionality is available.
The Operator does not intentionally seek to collect personal data belonging to children and does not conduct marketing activities directed at them.
If the Operator determines that personal data of a minor have been collected in violation of the applicable legal provisions, such data will be deleted or anonymised without undue delay, except where their retention is required by law.
5. Categories of Data Processed
The Operator processes exclusively the personal data necessary for providing the services offered through the Website, performing contracts concluded with customers, complying with legal obligations, and protecting its legitimate interests.
Depending on how the Website is used, the Operator may process the following categories of data:
5.1. Identification Data
Depending on the services used, the following data may be processed:
- first and last name;
- company name, in the case of legal entities;
- contact person;
- unique registration code (CUI), VAT number, and other information necessary for invoicing legal entities;
- billing address;
- delivery address.
5.2. Contact Data
The Operator may process:
- e-mail address;
- telephone number;
- postal address;
- other information voluntarily provided in communications.
5.3. Order Data
For the purpose of processing orders, the Operator may process:
- order number;
- products ordered;
- quantities ordered;
- order value;
- discounts applied;
- promotional codes used;
- payment method;
- delivery method;
- order history;
- order status;
- information concerning returns, cancellations, or complaints.
5.4. User Account Data
Where an account is created on the Website, the Operator may process:
- e-mail address used for authentication;
- password stored exclusively in encrypted form;
- login history;
- saved addresses;
- user preferences;
- order history associated with the account.
5.5. Payment Data
Depending on the payment method used, the Operator may process:
- confirmation that payment has been made;
- transaction identifier;
- transaction value;
- payment status.
In the case of online payment, the Operator may process information communicated by authorised payment service providers exclusively to the extent necessary to confirm the transaction. In the case of cash on delivery, only the information necessary to confirm receipt of payment by the courier operator is processed.
The Operator does not store and does not have access to complete bank card details, which are processed exclusively by authorised payment service providers.
5.6. Technical Data
During use of the Website, the following may be collected automatically:
- IP address;
- date and time of access;
- device type;
- operating system;
- browser type and version;
- screen resolution;
- session identifiers;
- cookie identifiers;
- pages visited;
- duration of the visit;
- actions performed on the Website;
- access logs;
- information concerning technical errors;
- referring URL (referrer), where available.
5.7. Data Resulting from Communications
Where the data subject contacts the Operator, the following may be processed:
- content of messages sent;
- correspondence conducted by e-mail;
- requests submitted through the contact form;
- complaints;
- return requests;
- requests concerning the exercise of rights provided by the GDPR;
- other information voluntarily communicated.
The Operator does not request and does not seek to collect special categories of personal data referred to in Article 9 of Regulation (EU) 2016/679.
6. Purposes of Data Processing
Personal data are processed exclusively for specific, explicit, and legitimate purposes.
Depending on the services used, the Operator may process data for:
- administration of the Website;
- creation and administration of user accounts;
- identification of users;
- processing orders;
- confirming orders;
- issuing invoices;
- processing payments;
- delivery of ordered products;
- handling returns;
- handling complaints;
- providing the legal guarantee of conformity;
- communicating with customers;
- sending order-related notifications;
- preventing fraud;
- preventing misuse of the Website;
- ensuring the security of information systems;
- improving the operation of the Website;
- conducting internal statistics;
- complying with legal obligations;
- defending the Operator’s rights and legitimate interests in judicial or administrative proceedings;
- sending commercial communications, exclusively under the conditions provided by law and only where there is an appropriate legal basis.
The Operator does not use personal data for purposes incompatible with those for which they were collected.
7. Sources of Personal Data
The personal data processed by the Operator originate, as applicable, from the following sources:
- data provided directly by the data subject through the creation of an account, placement of an order, completion of forms available on the Website, or communication with the Operator;
- data generated automatically through use of the Website, including technical information and data collected through cookies, under the conditions provided by the Cookie Policy;
- data communicated by payment service providers exclusively to the extent necessary to confirm transactions;
- data provided by courier operators in connection with the delivery of orders or the handling of returns, where this is necessary for the performance of the contract.
The Operator does not collect personal data from public sources and does not purchase personal data databases for commercial purposes.
8. Mandatory Nature of Providing Data
Providing certain personal data is necessary for concluding and performing the sales contract, issuing tax documents, delivering ordered products, and complying with the Operator’s legal obligations.
Refusal to provide data marked as mandatory may make it impossible to process orders, issue invoices, deliver products, or provide other requested services.
For processing activities based on consent, such as subscribing to the newsletter or using certain categories of cookies, providing data is voluntary, and refusal to give consent does not affect the ability to use the essential functionalities of the Website.
9. Legal Bases for Processing
The Operator processes personal data only where there is a legal basis provided by Article 6 of Regulation (EU) 2016/679.
Depending on the circumstances, processing may be based on one or more of the following legal bases:
9.1. Performance of a Contract
Under Article 6(1)(b) GDPR, the Operator processes data necessary for:
- creating and administering the user account;
- processing orders;
- confirming orders;
- issuing commercial documents;
- delivering products;
- processing returns;
- handling complaints;
- providing services requested by the Customer.
9.2. Compliance with a Legal Obligation
Under Article 6(1)(c) GDPR, the Operator may process data for:
- issuing, transmitting, and retaining tax invoices, in accordance with applicable tax legislation;
- complying with accounting and tax obligations;
- complying with consumer protection legislation;
- complying with obligations imposed by competent authorities;
- fulfilling other obligations provided by applicable legislation.
9.3. Consent of the Data Subject
Under Article 6(1)(a) GDPR, the Operator may process data for:
- sending newsletters;
- marketing communications;
- using cookies that require consent;
- other activities for which the law requires prior consent.
Consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal.
9.4. Legitimate Interest
Under Article 6(1)(f) GDPR, the Operator may process data for:
- ensuring the security of the Website;
- preventing fraud;
- protecting IT infrastructure;
- administering and improving the services provided;
- defending the Operator’s rights and legitimate interests;
- resolving disputes;
- recovering debts;
- maintaining internal records;
- conducting internal statistical analyses, to the extent that these do not disproportionately affect the rights and freedoms of data subjects.
In all situations where processing is based on legitimate interest, the Operator seeks to maintain a balance between its legitimate interests and the fundamental rights and freedoms of data subjects, applying appropriate measures to protect them.
9.5. Automated Decision-Making and Profiling
The Operator does not make decisions based solely on automated processing of personal data and does not carry out profiling of data subjects within the meaning of Article 22 of Regulation (EU) 2016/679, insofar as such processing produces legal effects or similarly significantly affects the data subjects.
10. Recipients of Personal Data
The Operator may transmit personal data only to the extent necessary to fulfil the purposes described in this Policy, perform the Contract, comply with legal obligations, or protect the Operator’s legitimate interests.
Depending on the services used, personal data may be disclosed to the following categories of recipients:
- hosting and IT infrastructure service providers;
- Website maintenance and administration service providers;
- information security service providers;
- authorised payment service providers used by the Operator (for example, Stripe Payments Europe, Ltd., PayPal (Europe) S.à r.l. et Cie, S.C.A., or other equivalent providers, as applicable), as well as courier operators, to the extent that processing cash-on-delivery payments requires the exchange of the necessary data;
- banking institutions involved in processing transactions;
- courier and postal service operators used by the Operator (for example, Cargus S.R.L., Compania Națională Poșta Română S.A., or other equivalent providers, as applicable), for delivery of orders and handling returns;
- e-mail and electronic communications service providers;
- Website analytics and performance monitoring service providers;
- marketing service providers, exclusively under the conditions provided by law;
- accounting, tax, and audit service providers;
- legal advisers;
- public authorities, state institutions, criminal investigation bodies, or courts, where disclosure is required by law or lawfully requested.
The Operator uses exclusively providers that offer sufficient guarantees regarding the implementation of appropriate technical and organisational measures for the protection of personal data. Where necessary, the Operator enters into data processing agreements with them, in accordance with Article 28 of Regulation (EU) 2016/679.
The Operator may modify or replace the service providers used for the operation of the Website without requiring an amendment to this Policy, provided that they offer adequate guarantees concerning the protection of personal data and act in accordance with applicable legislation.
The Operator does not sell, rent, or disclose personal data to third parties for commercial purposes.
11. Transfer of Data Outside the European Economic Area
In principle, data are processed within the European Union or the European Economic Area. To the extent that certain services used by the Operator involve the transfer of data to countries outside the EEA (for example, through international payment service providers or infrastructure providers), such transfers are carried out exclusively in compliance with Chapter V of the GDPR.
International transfers may take place only if at least one of the following conditions is met:
- an adequacy decision adopted by the European Commission exists;
- Standard Contractual Clauses (SCCs) approved by the European Commission are used;
- other appropriate safeguards provided for by Article 46 GDPR are implemented;
- one of the derogations provided for by Article 49 GDPR applies, where applicable.
The Operator adopts appropriate technical and organisational measures to protect transferred data and seeks to ensure that any provider involved offers a level of protection equivalent to that guaranteed within the European Union.
Where international transfers are based on Standard Contractual Clauses approved by the European Commission, the Operator may implement additional protective measures where necessary, in accordance with applicable legislation and the recommendations of competent data protection authorities.
At the request of the data subject, the Operator may provide a copy of the appropriate safeguards used for international data transfers, to the extent that these may be disclosed without affecting the rights and freedoms of other persons.
12. Data Retention Period
The Operator retains personal data only for the period necessary to fulfil the purposes for which they were collected or to comply with applicable legal obligations.
Depending on the category of data and the purpose of processing, the general retention periods are as follows:
| Data category | Retention period |
|---|---|
| Data relating to orders and contracts | for the duration of the performance of the contract and thereafter for the period necessary to comply with legal obligations and general limitation periods |
| Invoices and financial-accounting documents | for the period provided by applicable tax and accounting legislation (currently 10 years) |
| User accounts | until deletion of the account by the user or after a period of inactivity established by the Operator’s internal policies, where there are no legal retention obligations |
| Requests submitted through the contact form, e-mail, or telephone | for as long as necessary to resolve the request and defend any rights of the Operator |
| Data used for newsletters | until withdrawal of consent or exercise of the right to object |
| Technical logs and security logs | for the period necessary to ensure the security of the Website and prevent fraud, in accordance with internal security policies and applicable legal obligations |
| Cookies | according to the durations indicated in the Cookie Policy |
Upon expiry of the applicable periods, data are deleted, anonymised, or archived, under the conditions provided by applicable legislation.
Exercising the right to erasure does not affect the Operator’s obligation to retain certain documents and information where this is required by tax, accounting, or other applicable legal provisions.
13. Rights of Data Subjects
Individuals whose personal data are processed benefit from all rights provided by Regulation (EU) 2016/679 and applicable legislation.
Under the conditions provided by law, data subjects have the following rights:
13.1. Right to Information
The data subject has the right to receive clear and transparent information regarding how their personal data are processed.
13.2. Right of Access
The data subject may request confirmation as to whether the Operator processes data concerning them and may obtain a copy thereof, as well as the information provided for by Article 15 GDPR.
13.3. Right to Rectification
The data subject may request the correction of inaccurate data or the completion of incomplete data.
13.4. Right to Erasure
Under the conditions provided by Article 17 GDPR, the data subject may request the erasure of their personal data where there is no longer a legal basis for processing them.
This right is not absolute and may be limited in cases provided by law, including where retention of the data is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of a right in court.
13.5. Right to Restriction of Processing
The data subject may request restriction of processing in the situations provided for by Article 18 GDPR.
13.6. Right to Data Portability
Where processing is based on consent or on the performance of a contract and is carried out by automated means, the data subject may request that the data be transmitted in a structured, commonly used, and machine-readable format.
13.7. Right to Object
The data subject may object to processing based on the Operator’s legitimate interest, under the conditions of Article 21 GDPR.
Where data are processed for direct marketing purposes, the data subject has the right to object to such processing at any time.
13.8. Right to Withdraw Consent
Where processing is based on consent, consent may be withdrawn at any time, without affecting the lawfulness of processing carried out before the withdrawal.
13.9. Right to Lodge a Complaint
The data subject has the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) if they consider that the processing of their data violates the provisions of Regulation (EU) 2016/679 or applicable legislation.
Exercising this right does not limit the data subject’s right to bring proceedings before the competent courts.
13.10. Exercise of Rights
Requests concerning the exercise of rights may be submitted using the contact details indicated in this Policy.
The Operator will respond without undue delay and, in any event, within the period provided by Regulation (EU) 2016/679, except in situations where the legislation allows this period to be extended.
The Operator may request additional information to verify the identity of the requester where there are reasonable doubts concerning the identity of the person submitting the request.
13.11. Right Not to Be Subject to an Automated Individual Decision
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them, under the conditions provided by Article 22 of Regulation (EU) 2016/679. As of the date of this Policy, the Operator does not use such automated decision-making processes.
14. Supervisory Authority
In Romania, the authority competent for supervising the application of data protection legislation is:
National Supervisory Authority for Personal Data Processing (ANSPDCP)
Bulevardul General Gheorghe Magheru nr. 28-30, Sector 1, Bucharest, Romania
Website: https://www.dataprotection.ro
The data subject has the right to lodge a complaint with the ANSPDCP or with the competent supervisory authority in the European Union Member State where they have their habitual residence, place of work, or place of the alleged infringement of personal data protection provisions.
Without prejudice to this right, data subjects are encouraged to contact CORESI PUBLISHING HOUSE S.R.L. first in order to seek an amicable resolution of any request concerning the processing of their personal data.
15. Data Security
CORESI PUBLISHING HOUSE S.R.L. implements appropriate technical and organisational measures to protect personal data against:
- unauthorised access;
- accidental or unlawful disclosure;
- destruction;
- loss;
- alteration;
- misuse.
The measures implemented may include, as applicable:
- use of secure connections (HTTPS/TLS);
- access control to information systems;
- user authentication and management of access rights;
- backups;
- monitoring of the security of the IT infrastructure;
- periodic updating of software systems;
- limiting employees’ access to data exclusively to the extent necessary for the performance of their duties.
Although reasonable security measures are implemented, no information system and no method of transmitting data over the Internet can guarantee absolute security. In the event of a security incident presenting a risk to the rights and freedoms of data subjects, the Operator will act in accordance with the obligations provided by the GDPR, including notifying the competent authority and, where applicable, the affected individuals.
For information concerning the cookies used, the purposes of processing, the retention period, and how consent may be withdrawn, users are invited to consult the Cookie Policy available on the Website.
The Operator periodically assesses security measures and adopts reasonable measures to prevent unauthorised access to data.
16. Processing of Data of Minors
The Website is intended for persons who have the legal capacity to enter into contracts.
CORESI PUBLISHING HOUSE S.R.L. does not knowingly collect personal data belonging to children and does not seek to process their data for marketing purposes.
If it is determined that data belonging to a minor have been collected in violation of applicable legal provisions, the Operator will take reasonable measures to delete them as soon as possible.
Parents or legal representatives who believe that a minor has provided personal data through the Website are requested to contact the Operator at [email protected].
17. Changes to the Privacy Policy
CORESI PUBLISHING HOUSE S.R.L. reserves the right to modify or update this Privacy Policy whenever this is necessary for:
- compliance with legislative changes;
- implementation of new services or functionalities;
- changes to the manner in which data are processed;
- improvement of security measures;
- adaptation to recommendations of competent authorities.
The updated version will be published on the Website and will take effect from the date indicated in the document.
Where the changes significantly affect the rights of data subjects or the manner in which data are processed, the Operator will take reasonable measures to inform users, to the extent required by applicable legislation.
18. Contact Details
For any questions concerning this Privacy Policy or the manner in which personal data are processed, you may contact us using the following details:
CORESI PUBLISHING HOUSE S.R.L.
Registered office
Strada Viitorului nr. 125
Camera 2, Etaj 1, Apartament 6
Sector 2, 020301 Bucharest
Romania
Publishing Office and correspondence
Strada Agricultori nr. 37–39
Etaj 4, Birou 401
Sector 2, Bucharest
Romania
E-mail: [email protected]
Telephone: +40 (722) 156408
Website: https://www.coresi.net
Document Information
Document name: Privacy Policy
Website: https://www.coresi.ro
Operator: CORESI PUBLISHING HOUSE S.R.L.
Document version: 2.0
Effective date: 01 August 2026
Last updated: 01 August 2026
