Politica de confidențialitate
Ultima actualizare: 8 august 2026Ne dai pe mână un obiect personal — ochelarii tăi — și, uneori, prescripția primită de la opticianul tău. E normal să vrei să știi exact ce se întâmplă cu informațiile pe care ni le lași. Politica de mai jos explică ce date prelucrăm când folosești site-ul lentilo.ro, când plasezi o comandă sau când ne trimiți rama la atelier, de ce le prelucrăm, cui ajung și ce poți cere de la noi în orice moment.
Am scris-o cât se poate de simplu. Respectă Regulamentul (UE) 2016/679 (GDPR), Legea nr. 190/2018 privind măsurile de punere în aplicare a GDPR, Legea nr. 506/2004 privind prelucrarea datelor cu caracter personal în sectorul comunicațiilor electronice și Legea nr. 365/2002 privind comerțul electronic.
1. Operatorul de date
Site-ul lentilo.ro este administrat de OKRALIS S.R.L. Societatea este comerciantul și vânzătorul serviciului și, în sensul art. 4 pct. 7 din GDPR, este operatorul datelor tale cu caracter personal — adică cel care stabilește de ce și cum sunt prelucrate.
- Denumire
- OKRALIS S.R.L.
- Formă juridică
- Societate cu răspundere limitată (S.R.L.)
- CUI / CIF
- 51286544 — societatea este neplătitoare de TVA
- Registrul Comerțului
- J2025010018003
- Sediul social
- Șos. Giurgiului nr. 277–279, Sector 4, București, România
- CAEN principal
- 4791
- office@lentilo.ro
- Telefon
- 0721 864 095 — și pe WhatsApp
Comenzile se execută în atelierul din Strada Sfânta Maria 47, București, unde poți lăsa rama și personal, de luni până vineri, între 9:00 și 18:00. Indiferent dacă ne trimiți ochelarii prin curier sau îi aduci la atelier, răspunderea pentru datele colectate prin site și pentru comanda ta rămâne la OKRALIS S.R.L.
Magazinul online funcționează pe platforma Shopify, iar comanda se finalizează în checkout-ul Shopify. Shopify prelucrează datele comenzii în numele nostru, ca împuternicit, nu în interes propriu; operatorul rămâne OKRALIS S.R.L. Ce anume face Shopify și ce pleacă în afara Europei îți spunem pe larg în secțiunile 5 și 6.
Nu avem obligația legală de a desemna un responsabil cu protecția datelor (DPO): nu suntem o autoritate publică, nu monitorizăm sistematic și pe scară largă persoane și nu prelucrăm pe scară largă categorii speciale de date, așa cum cere art. 37 din GDPR. Ca să nu rămâi fără interlocutor, toate cererile și întrebările privind datele tale merg direct la office@lentilo.ro sau la 0721 864 095 și sunt tratate de administratorul societății.
2. Ce date prelucrăm
Colectăm strict ce ne trebuie ca să preluăm rama, să facem lentilele și să ți le aducem înapoi. Nimic „pentru mai târziu”, nimic din curiozitate.
Date de identificare și de contact
Numele și prenumele, adresa de e-mail și numărul de telefon. Ne spun cu cine avem contract, ne permit să confirmăm comanda, să stabilim ridicarea prin curier și să te anunțăm când lucrarea e gata. Dacă ne scrii pe WhatsApp, prelucrăm și numărul de la care ne contactezi, împreună cu mesajele schimbate.
Datele completate la finalizarea comenzii
Checkout-ul Shopify îți cere numele, adresa de e-mail, numărul de telefon și adresa: strada și numărul, localitatea, județul sau sectorul și codul poștal, plus indicațiile pe care le lași în câmpul de observații (etaj, interfon, interval orar potrivit). Fără ele comanda pur și simplu nu poate fi executată — la acea adresă ajunge coletul cu ochelarii gata lucrați.
Prin Shopify se organizează numai drumul de la atelier la tine. Dacă preluăm rama de la tine prin curier, ridicarea o organizăm separat, cu un partener din afara platformei, folosind aceleași date de contact și de adresă. Dacă preferi să lași rama personal la atelier și să o ridici tot de acolo, spune-ne — atunci adresa nu mai este folosită pentru livrare.
Date despre comandă
- tipul lucrării — lentile pentru ochelari de vedere sau pentru ochelari de soare;
- marca ramei, aleasă din lista de pe site, pentru că de ea depinde prețul la ochelarii de soare;
- culoarea și finisajul lentilei (uni, degrade sau oglindă);
- opțiunea de recreare a gravurii producătorului — disponibilă doar la ochelarii de soare și doar când lentila originală are deja o gravură;
- tratamentele alese pentru lentilele de vedere — protecția UV400, tratamentul de durificare, tratamentul antireflex, filtrul pentru lumina albastră;
- un indicator care spune doar dacă lucrarea are sau nu dioptrii — „Cu dioptrii — rețeta pe e-mail” ori „Fără”. Pe comandă nu ajung nici valorile dioptriilor, nici documentul de prescripție;
- limba în care ai folosit site-ul când ai completat comanda, română sau engleză, ca să îți răspundem în aceeași limbă;
- momentul — data și ora — la care ai bifat în configurator cererea expresă de a începe lucrarea, salvat pe comandă ca marcaj de timp;
- descrierea și starea ramei pe care ne-o încredințezi, inclusiv observațiile atelierului după verificarea ei și, uneori, fotografii ale ramei sau ale lentilelor originale;
- prețul comenzii și prețul final confirmat după ce atelierul vede rama, metoda de plată aleasă, numărul comenzii din Shopify și datele la care s-au făcut pașii (preluarea ramei, începutul lucrării, expedierea returului).
Prescripția, dacă ai nevoie de lentile cu dioptrii
Dacă alegi lentile cu corecție, ne trimiți prescripția eliberată de opticianul sau de medicul tău prin e-mail ori pe WhatsApp, iar apoi te sunăm ca să confirmăm împreună valorile. Sunt date privind sănătatea și merită explicate separat: le-am dedicat secțiunea 3, imediat după aceasta.
Date de plată
La finalizarea comenzii poți alege plata cu cardul, în checkout-ul Shopify, sau plata ramburs la curier.
Lentilo nu vede și nu stochează datele complete ale cardului tău. Numărul cardului, data expirării și codul de securitate (CVV/CVC) sunt preluate și procesate de Shopify Payments (Shopify International Limited), în mediul lui securizat, în pagina de plată. Noi primim și păstrăm doar rezultatul tranzacției: dacă a fost aprobată sau refuzată, suma, moneda, data, metoda de plată și, dacă platforma ni le pune la dispoziție, ultimele cifre ale cardului — strict ca să putem identifica plata în contabilitate. La plata ramburs, curierul încasează suma și ne transmite confirmarea; nu vedem în niciun moment instrumentele tale de plată.
Dacă ceri factură pe firmă, prelucrăm și datele societății pe care ne-o indici (denumire, CUI, nr. de ordine în registrul comerțului, sediu, cont bancar) — acestea nu sunt date personale în sine, dar pot include numele reprezentantului.
Corespondența cu noi
Mesajele pe care ni le trimiți pe e-mail sau pe WhatsApp — inclusiv cel prin care ne trimiți prescripția — notele lăsate la comandă și răspunsurile noastre, împreună cu ce ne spui la telefon și notăm în dosarul comenzii. Nu înregistrăm convorbirile telefonice.
Date tehnice despre vizita pe site
Site-ul rulează pe platforma Shopify, iar platforma prelucrează date tehnice despre vizita ta: adresa IP, momentul cererii, paginile deschise, tipul de browser și de dispozitiv, pagina de la care ai venit. O parte dintre ele sunt strict necesare — fără ele coșul, checkout-ul și protecția împotriva abuzurilor nu funcționează. Restul sunt date de analiză, din care Shopify ne compune rapoartele magazinului: câte vizite au fost, ce pagini s-au citit, unde se opresc oamenii înainte de a comanda.
Site-ul setează cookie-uri proprii, iar analiza vizitelor este activă. Bannerul de cookie-uri are patru categorii: strict necesare — blocate pe „pornit”, pentru că fără ele site-ul nu ar funcționa — plus analiză, preferințe și marketing. Cele trei categorii opționale se instalează numai după ce le accepți în banner, iar dacă refuzi, site-ul și comanda merg mai departe normal. Alegerea ta nu rămâne o formalitate: o transmitem platformei Shopify prin interfața ei de consimțământ, iar platforma este cea care oprește efectiv cookie-urile opționale — de analiză, de preferințe și de marketing — până când le accepți. Lista completă și exactă, cu rolul și durata fiecăruia, se află în Politica de cookie-uri.
Jurnalele tehnice ale platformei și ale rețelei de distribuție a conținutului sunt ținute de Shopify, potrivit propriilor lui reguli de păstrare. Nu noi le administrăm, nu le putem citi în mod obișnuit și nu îți promitem în numele lui un anumit termen.
În afara platformei, paginile nu cheamă niciun server străin. Tipografiile site-ului sunt găzduite la noi și se livrează odată cu paginile, ca fișiere proprii; browserul tău nu cere nimic de la Google Fonts și nu contactează niciun alt furnizor terț când deschizi o pagină, așa că adresa ta IP nu ajunge la nimeni în afara platformei pe care rulează magazinul.
Ce se întâmplă dacă nu ne dai aceste date
Datele de identificare, de contact, adresa și datele despre comandă sunt necesare pentru încheierea și executarea contractului: fără ele nu putem prelua comanda. Datele de facturare sunt o cerință legală, nu o opțiune. Prescripția este necesară doar dacă alegi lentile cu corecție — fără ea nu avem după ce tăia și comanda rămâne în așteptare. Restul — abonarea la newsletter și cookie-urile din cele trei categorii opționale, analiză, preferințe și marketing — sunt complet opționale, iar refuzul lor nu are niciun efect asupra comenzii tale și nu costă nimic.
Date primite din alte surse
De regulă primim datele direct de la tine. Există însă situații în care ajung la noi indirect, iar art. 14 din GDPR ne cere să ți le spunem:
- când comanda e plasată de altcineva pentru tine — un părinte pentru copil, un soț, o rudă, un coleg. Primim de la acea persoană numele, contactul, adresa și, dacă e cazul, prescripția purtătorului, iar cel care plasează comanda ne confirmă că are dreptul să ni le comunice;
- de la firma de curierat — starea expedierii, data și ora ridicării și ale livrării, eventualele mențiuni consemnate la livrare;
- de la Shopify și de la Shopify Payments — confirmarea sau refuzul plății, referința tranzacției și indicatorul automat de risc de fraudă atribuit comenzii, despre care îți vorbim în secțiunea 8;
- din registre publice — doar dacă ne ceri factură pe firmă și trebuie să verificăm datele de facturare.
Categoriile de date primite astfel sunt aceleași cu cele descrise mai sus. Dacă primim date despre tine de la altcineva și nu ești deja în contact direct cu noi, îți comunicăm informațiile din această politică în cel mult o lună de la obținerea lor sau la primul contact, oricare intervine mai devreme.
3. Prescripția: date privind sănătatea
Dacă vrei lentile cu dioptrii, avem nevoie de prescripția eliberată de opticianul sau de medicul tău. Este singura categorie de date sensibile pe care le prelucrăm — date privind sănătatea, în sensul art. 9 din GDPR — așa că îți explicăm separat, în detaliu, tot ce se întâmplă cu ea.
Cum ajunge la noi
Plasezi comanda pe site ca pe oricare alta. Apoi ne trimiți prescripția prin e-mail, la office@lentilo.ro, sau pe WhatsApp, ca fotografie ori ca fișier.
Site-ul nu are niciun câmp de încărcare a fișierelor și niciun câmp în care să scrii dioptriile. Documentul de prescripție și valorile din el nu trec prin lentilo.ro, nu se încarcă nicăieri pe site și nu ajung în Shopify. Aterizează direct în cutia poștală a atelierului sau în conversația noastră de WhatsApp, adică într-un loc pe care îl citesc oamenii care lucrează la comanda ta.
Înainte să tăiem ceva, te sunăm și confirmăm împreună valorile pe care le-am citit din prescripție. Notăm în dosarul comenzii ce am confirmat și când. Nu înregistrăm convorbirea.
Ce prelucrăm efectiv
- documentul de prescripție așa cum ni-l trimiți — fotografia sau fișierul, cu tot ce scrie pe el: valorile pentru fiecare ochi, distanța interpupilară, data eliberării, numele și ștampila celui care l-a eliberat și, uneori, mențiuni medicale pe care documentul le conține deja;
- valorile pe care le folosim efectiv la tăiere, transcrise în dosarul comenzii;
- ce ai confirmat sau ai corectat la telefon.
Nu îți cerem un diagnostic, un istoric medical sau alte acte medicale și nu avem nevoie de ele. Dacă prescripția ta conține și mențiuni care nouă nu ne trebuie, nu le folosim la nimic, nu le transcriem în dosar și nu le transmitem nimănui.
De ce
Ca să tăiem lentilele corect. Fără valorile din prescripție nu se poate executa o lentilă cu corecție — nu e o formalitate, e chiar informația după care se lucrează. Telefonul de confirmare există tot pentru asta: o cifră citită greșit înseamnă o pereche de lentile aruncată.
Pe ce temei
Prelucrarea are nevoie de două lucruri: un temei din art. 6 și, pentru că sunt date privind sănătatea, o condiție din art. 9 alin. (2) din GDPR.
- Art. 6 alin. (1) lit. b) — executarea contractului dintre noi. Ai comandat o pereche de lentile făcute după dioptriile tale; fără ele contractul nu poate fi executat.
- Art. 9 alin. (2) lit. a) — consimțământul tău explicit. Îl dai prin însuși faptul că ne trimiți prescripția, după ce ți-am spus limpede — aici și în mesajul prin care ți-o cerem — ce prelucrăm din ea, în ce scop și cât o ținem. Nu îl deducem din altceva: dacă nu ne trimiți documentul, nu avem consimțământ și nu prelucrăm nimic. Îl poți retrage oricând, scriindu-ne la office@lentilo.ro, cu mențiunea că, dacă îl retragi înainte de tăiere, nu putem executa lentile cu corecție și comanda se oprește.
- Art. 9 alin. (2) lit. f) — dacă apare o reclamație sau un litigiu despre lucrare, păstrăm valorile după care am tăiat ca să putem constata, exercita sau apăra un drept în justiție, chiar dacă între timp ți-ai retras consimțământul.
Cine o vede
Doar oamenii din atelier care lucrează efectiv la comanda ta: cine preia comanda, cine citește prescripția, cine te sună, cine taie și montează lentilele. Documentul trece însă și prin canalul pe care îl alegi tu ca să ni-l trimiți: dacă ne scrii pe e-mail, prin infrastructura furnizorului de e-mail al atelierului; dacă ne scrii pe WhatsApp, prin serviciul operat de Meta Platforms Ireland Limited. Pe amândoi îi găsești în secțiunea 5, iar dacă vrei să eviți complet WhatsApp, trimite-ne documentul pe e-mail.
Documentul de prescripție și valorile dioptriilor nu ajung în Shopify, la curier, la contabil, la xConnector sau la FGO — pe factură nu apar valorile dioptriilor, iar coletul nu poartă nicio informație medicală. Ca să fim exacți până la capăt: pe comandă ajunge totuși un singur indicator, de tip da/nu — dacă lucrarea are sau nu dioptrii („Cu dioptrii — rețeta pe e-mail” ori „Fără”). Este, în sine, o informație despre sănătatea ta, așa că nu o ascundem: acest indicator este înregistrat pe comanda din Shopify, circulă odată cu comanda prin fluxul de facturare (xConnector și FGO) și este citit de oamenii din atelier, pentru că de el depinde felul în care se lucrează. Ce nu pleacă nicăieri sunt documentul și cifrele: ele rămân în cutia poștală a atelierului sau în conversația de WhatsApp și în dosarul comenzii. Prescripția nu o folosim niciodată în marketing.
Cât o păstrăm și cum o ștergem
Documentul primit pe e-mail sau pe WhatsApp îl păstrăm 12 luni de la livrarea comenzii — atât cât durează, în practică, refacerile și ajustările de după livrare — apoi îl ștergem din cutia poștală și din conversație, inclusiv din folderul de elemente șterse. Nu ținem documentul ca să ne apărăm de reclamații târzii, pentru că ele pot veni și mai încolo: pentru asta ne folosim de valorile transcrise în dosarul comenzii și de ce ai confirmat la telefon, adică exact datele după care am tăiat. Acestea rămân cu dosarul, pe durata garanției legale de conformitate și a termenului general de prescripție de 3 ani, pentru că fără ele nu ne putem apăra dacă ne reclami lucrarea.
Dacă ne ceri ștergerea sau îți retragi consimțământul, ștergem documentul din cutia poștală și din conversația de WhatsApp în cel mult o lună de la cerere și îți confirmăm în scris că am făcut-o. Valorile transcrise în dosarul comenzii sunt altceva și nu le ștergem la cerere: le păstrăm pe temeiul art. 9 alin. (2) lit. f) din GDPR, pe durata garanției legale de conformitate și a termenului de prescripție de 3 ani, chiar dacă între timp ți-ai retras consimțământul, pentru că fără ele nu ne putem apăra dacă ne reclami lucrarea. Le ștergem când fereastra aceasta se închide, iar dacă la momentul acela există o reclamație sau un litigiu în curs, le ținem până se soluționează definitiv și le ștergem după. Alte două lucruri pe care nu ți le promitem, ca să nu îți promitem imposibilul: copiile din sistemele de backup ale furnizorului de e-mail se suprascriu în ciclul lor normal și dispar la următoarea rotație, nu manual, la cerere; iar factura și documentele contabile nu pot fi șterse, pentru că legea ne obligă să le păstrăm — pe ele, însă, nu apar valorile dioptriilor.
4. Scopurile și temeiurile juridice
Fiecare prelucrare pe care o facem are un scop precis și un temei juridic. Tabelul de mai jos le arată pe toate, împreună cu durata pentru care păstrăm datele.
| Scop | Date | Temei juridic | Durata păstrării |
|---|---|---|---|
| Preluarea comenzii și executarea lucrării: preluarea ramei, verificarea ei în atelier, tăierea și montarea lentilelor, expedierea la adresa ta | Identificare, contact, adresă, date despre comandă | Art. 6 alin. (1) lit. b) — executarea contractului la care ești parte | Pe durata executării comenzii și 3 ani după finalizarea ei — termenul general de prescripție, art. 2517 din Codul civil |
| Executarea lentilelor cu corecție pe baza prescripției trimise de tine și confirmarea telefonică a valorilor înainte de tăiere (secțiunea 3) | Documentul de prescripție primit pe e-mail sau pe WhatsApp, valorile transcrise în dosarul comenzii, ce ai confirmat la telefon | Art. 6 alin. (1) lit. b) — executarea contractului, coroborat cu art. 9 alin. (2) lit. a) — consimțământul tău explicit pentru datele privind sănătatea; pentru reclamații și litigii, art. 9 alin. (2) lit. f) | Documentul: 12 luni de la livrare. Valorile din dosarul comenzii: pe durata garanției legale de conformitate și a termenului de prescripție de 3 ani |
| Comunicarea despre comandă: confirmări, coordonarea ridicării, telefonul prin care confirmăm valorile, anunțul că lucrarea e gata | Contact, corespondență, date despre comandă | Art. 6 alin. (1) lit. b) — executarea contractului | Ca mai sus, împreună cu dosarul comenzii |
| Înregistrarea cererii tale exprese de a începe lucrarea: în configurator bifezi o casetă obligatorie prin care ne ceri să începem executarea și recunoști că îți pierzi dreptul de retragere odată ce lucrarea este executată. Fără bifa aceasta comanda nu poate fi trimisă, iar momentul bifării se salvează pe comandă | Bifa și marcajul de timp (data și ora) atașat comenzii, împreună cu numărul comenzii | Art. 6 alin. (1) lit. c) — obligație legală (art. 9 alin. (1) și art. 16 lit. a) din OUG nr. 34/2014), coroborat cu art. 6 alin. (1) lit. f) — interesul nostru legitim de a putea dovedi că ne-ai cerut-o | Împreună cu dosarul comenzii |
| Gestionarea dreptului de retragere în 14 zile și a anulărilor cerute înainte de începerea tăierii, inclusiv returul ramei. Cererea o poți trimite oricând din funcția „Retrage-te din contract”, aflată permanent în subsolul fiecărei pagini; formularul înregistrează cererea automat, cu data și ora, iar confirmarea pe suport durabil ți-o trimite pe e-mail un om din atelier, nu un răspuns automat | Identificare, contact, adresă, date despre comandă, referința plății pentru rambursare; din formularul de retragere — numele, adresa de e-mail cu care ai plasat comanda, numărul și data comenzii și, dacă vrei să ni-l spui, motivul | Art. 6 alin. (1) lit. c) — obligație legală (OUG nr. 34/2014 privind drepturile consumatorilor) | 3 ani, împreună cu dosarul comenzii; documentele de rambursare, odată cu evidențele contabile |
| Facturare — factura se generează automat prin xConnector și se emite prin FGO în momentul în care coletul pleacă spre tine — evidență contabilă, îndeplinirea obligațiilor fiscale și transmiterea facturii către ANAF | Identificare, date de facturare, date despre comandă, confirmarea plății | Art. 6 alin. (1) lit. c) — Legea contabilității nr. 82/1991 și Codul fiscal | 5 ani de la data încheierii exercițiului financiar în cursul căruia au fost întocmite documentele (art. 25 din Legea nr. 82/1991, în forma modificată prin Legea nr. 36/2023) |
| Încasarea prețului, cu cardul prin Shopify Payments sau ramburs la curier | Rezultatul tranzacției, suma, data, metoda de plată — fără datele complete ale cardului | Art. 6 alin. (1) lit. b) — executarea contractului, coroborat cu art. 6 alin. (1) lit. c) pentru evidența plăților | Odată cu documentele contabile aferente |
| Garanția legală de conformitate, reclamațiile și remedierea problemelor la lucrare | Date despre comandă, corespondență, fotografii ale ramei și ale lentilelor | Art. 6 alin. (1) lit. c) — OUG nr. 140/2021 privind vânzarea de bunuri și garanțiile asociate și OG nr. 21/1992 privind protecția consumatorilor | Pe toată durata garanției legale de conformitate prevăzute de OUG nr. 140/2021, la care se adaugă termenul general de prescripție prevăzut de art. 2517 din Codul civil, ca să ne putem apăra dacă apare o reclamație la limita termenului |
| Comunicări de marketing: newsletter, noutăți despre culori și finisaje, oferte | Prenume, adresă de e-mail și, dacă ni-l dai, numărul de telefon | Art. 6 alin. (1) lit. a) — consimțământul tău, pe care îl poți retrage oricând, la fel de ușor cum l-ai dat | Până la retragerea consimțământului sau dezabonare; dovada consimțământului se păstrează încă 3 ani după retragere, ca să putem demonstra că prelucrarea a fost legală |
| Analiza vizitelor prin rapoartele Shopify: ce pagini sunt citite, de unde vin vizitatorii, unde se opresc înainte de a comanda — prelucrare activă, numai pentru vizitatorii care au acceptat categoria de analiză în bannerul de cookie-uri | Date tehnice: adresă IP, browser, dispozitiv, pagini vizitate, durata vizitei, pagina de proveniență | Art. 6 alin. (1) lit. a) — consimțământ, coroborat cu art. 4 alin. (5) din Legea nr. 506/2004, care cere acord prealabil pentru cookie-uri | Cel mult 13 luni de la instalarea cookie-ului; după expirare, îți cerem din nou acordul |
| Funcționarea și securitatea magazinului: jurnalele tehnice ale platformei, prevenirea abuzurilor | Date tehnice | Art. 6 alin. (1) lit. f) — interesul nostru legitim de a menține magazinul funcțional și sigur | Jurnalele sunt ținute de Shopify, potrivit regulilor lui de păstrare. Nu sunt jurnalele noastre și nu îți putem promite în numele lui un anumit termen |
| Verificarea automată a riscului de fraudă la comenzile plasate în checkout, urmată de decizia unui om din atelier (secțiunea 8) | Date despre comandă, date tehnice (adresă IP, dispozitiv), potrivirea dintre adresa de livrare și cea de facturare, semnalele primite de la procesatorul de plăți, indicatorul de risc calculat de platformă | Art. 6 alin. (1) lit. f) — interesul nostru legitim de a preveni frauda, recunoscut de considerentul (47) din GDPR | Împreună cu dosarul comenzii |
| Constatarea, exercitarea sau apărarea unui drept în instanță ori în fața unei autorități, inclusiv în procedurile ANPC | Categoriile de date relevante pentru neînțelegerea respectivă | Art. 6 alin. (1) lit. f) — interesul nostru legitim de a ne apăra drepturile | Până la soluționarea definitivă a cauzei și epuizarea căilor de atac |
Despre interesul legitim. Când ne întemeiem pe art. 6 alin. (1) lit. f), facem în prealabil un test de echilibru: verificăm dacă scopul este real și necesar, dacă nu îl putem atinge cu mai puține date și dacă interesul nostru — să ținem site-ul în funcțiune și să ne putem apăra dacă apare un litigiu — nu este depășit de drepturile și libertățile tale. Concluzia noastră este că nu: prelucrăm minimul necesar, nu construim profiluri de marketing și nu combinăm datele în alte scopuri. Singura evaluare automată care atinge comanda ta este analiza de risc de fraudă a platformei, iar decizia finală o ia tot un om — o explicăm în secțiunea 8. Poți cere oricând, la office@lentilo.ro, un rezumat al acestei evaluări și te poți opune prelucrării, potrivit art. 21 din GDPR.
Regulile comerciale ale comenzii — inclusiv momentul în care începe tăierea lentilelor și efectul acestui moment asupra dreptului de retragere — sunt explicate în Termeni și condiții.
5. Cine primește datele
Nu vindem datele tale, nu le închiriem și nu le dăm nimănui pentru marketingul altcuiva. Ajung doar la partenerii de care avem nevoie ca să executăm comanda și la autorități, atunci când legea ne obligă. Îi enumerăm pe categorii și, acolo unde partenerul este deja ales și fix, cu numele lui:
- Shopify International Limited (Irlanda) — platforma pe care rulează magazinul și checkout-ul. Prelucrează, în calitate de împuternicit, datele pe care le completezi la comandă, datele contului de client dacă îți faci unul, notificările trimise pe e-mail despre comandă și datele tehnice despre vizita ta. Nu primește documentul de prescripție și nici valorile dioptriilor; pe comandă îi ajung opțiunile alese în configurator — marca ramei, culoarea și finisajul lentilei, gravura, tratamentele — împreună cu indicatorul da/nu despre existența dioptriilor, limba interfeței și marcajul de timp al cererii tale exprese de a începe lucrarea, toate atașate liniei de comandă.
- Shopify Payments (Shopify International Limited) — procesatorul plății cu cardul. Preia direct datele cardului, în mediul lui securizat, și ne trimite doar rezultatul tranzacției. Pentru datele cardului, procesatorul acționează potrivit propriei politici de confidențialitate și regulilor de securitate din industria plăților.
- xConnector — soluția prin care factura se generează automat. Este conectată la curier și la furnizorul de facturare și primește datele de facturare, datele comenzii și datele de expediere.
- FGO — furnizorul prin care se emite și se păstrează factura. Primește datele de facturare și liniile comenzii, deci și indicatorul da/nu despre existența dioptriilor, care face parte din linia comenzii. Pe factură nu apar valorile dioptriilor și nu ajunge niciodată documentul de prescripție.
- Firma de curierat — primește numele, telefonul și adresa ta, ca să îți aducă acasă coletul cu ochelarii. La plata ramburs primește și suma de încasat. Când preluăm rama de la tine, ridicarea se face printr-un partener separat, în afara platformei, care primește aceleași date. Curierul nu află ce lucrare ai comandat și nu primește niciodată documentul de prescripție sau valorile dioptriilor.
- ANAF — facturile emise se transmit autorității fiscale prin Spațiul Privat Virtual, așa cum cere legea.
- Furnizorul de e-mail al atelierului — găzduiește cutia poștală în care ajung corespondența ta și, dacă ai comandat lentile cu dioptrii și alegi e-mailul, prescripția.
- Meta Platforms Ireland Limited (WhatsApp) — dacă alegi să ne scrii pe WhatsApp, conversația trece prin serviciul lui, inclusiv atunci când ne trimiți pe acolo prescripția, adică date privind sănătatea. Conținutul mesajelor este criptat cap la cap, deci furnizorul nu îl poate citi, însă prelucrează numărul tău de telefon și datele despre comunicare — cu cine, când, cât de des — în calitate de operator de sine stătător, potrivit propriei politici de confidențialitate. Noi nu primim aceste date de la el. Dacă preferi ca nimic să nu treacă prin WhatsApp, scrie-ne pe e-mail: canalul îl alegi tu.
- Contabilul sau firma de contabilitate — primește facturile și documentele justificative, ca să ținem evidența pe care ne-o cere legea.
- Furnizorii de servicii IT — dacă e cazul, atunci când intervin pentru mentenanță sau depanare și pot vedea incidental date, sub obligație de confidențialitate.
- Autoritățile publice — ANAF, ANPC, ANSPDCP, poliția, instanțele de judecată sau alte autorități, strict atunci când legea ne obligă să răspundem unei solicitări legitime.
Cu fiecare furnizor care prelucrează date în numele nostru avem încheiat un contract de prelucrare conform art. 28 din GDPR: poate folosi datele doar pentru ce îi cerem noi, trebuie să le protejeze, să impună confidențialitate personalului său, să nu apeleze la un alt subîmputernicit fără acordul nostru și să șteargă sau să ne returneze datele la finalul colaborării. Fiecăruia îi transmitem numai minimul de date de care are nevoie ca să își facă treaba. Îți comunicăm oricând, la cerere, denumirea exactă a fiecărui furnizor din categoriile de mai sus, așa cum este ea la data la care ne întrebi; scrie-ne la office@lentilo.ro și îți răspundem cu numele societăților, nu cu generalități.
6. Transferuri în afara SEE
De când magazinul rulează pe Shopify, o parte din infrastructura pe care o folosim funcționează și în afara Spațiului Economic European. Nu ascundem asta. Mai jos îți spunem exact ce pleacă, către cine și în ce temei din capitolul V al GDPR.
- Shopify Inc., Canada. Datele comenzii sunt prelucrate de Shopify International Limited, societate din Irlanda, care le poate transmite mai departe societății-mamă, Shopify Inc., din Canada. Transferul se întemeiază pe decizia de adecvare a Comisiei Europene pentru organizațiile comerciale canadiene supuse PIPEDA (art. 45 din GDPR): Comisia a constatat că nivelul de protecție este comparabil cu cel european, așa că nu sunt necesare garanții suplimentare.
- Lanțul de subîmputerniciți ai Shopify. Pentru găzduirea în cloud, rețeaua de distribuție a conținutului (CDN), jurnalizarea erorilor și analiza vizitelor, Shopify folosește la rândul lui furnizori care pot prelucra date în afara SEE, inclusiv în Statele Unite. Pentru aceste transferuri se aplică clauzele contractuale standard adoptate de Comisia Europeană (art. 46 alin. (2) lit. c) din GDPR), completate cu măsuri tehnice și organizatorice suplimentare, iar acolo unde furnizorul american este certificat, decizia de adecvare privind Cadrul UE-SUA pentru confidențialitatea datelor (art. 45).
- E-mailul atelierului. Corespondența și, dacă alegi acest canal, prescripția ajung în cutia poștală a atelierului. Dacă furnizorul nostru de e-mail prelucrează date și în afara SEE, transferul se face pe baza unei decizii de adecvare (art. 45) sau a clauzelor contractuale standard (art. 46 alin. (2) lit. c)). Scrie-ne și îți spunem exact ce furnizor folosim și ce garanții se aplică.
- WhatsApp (Meta Platforms Ireland Limited). Dacă alegi să ne scrii pe WhatsApp — inclusiv ca să ne trimiți prescripția — datele despre comunicare sunt prelucrate de societatea din Irlanda și pot ajunge, în interiorul grupului, și pe servere din Statele Unite. Temeiul este decizia de adecvare privind Cadrul UE-SUA pentru confidențialitatea datelor (art. 45), completată cu clauzele contractuale standard ale Comisiei (art. 46 alin. (2) lit. c)), potrivit politicii proprii a furnizorului. Conținutul mesajelor este criptat cap la cap, deci furnizorul nu îl poate citi. Poți evita complet acest transfer trimițându-ne totul pe e-mail.
Ce nu pleacă prin site. Documentul de prescripție și valorile dioptriilor nu trec prin lentilo.ro și nu ajung în Shopify: nu există niciun câmp de încărcare și niciun câmp în care să scrii dioptriile, deci platforma nu are ce transfera. Ele circulă doar între tine și atelier, pe canalul pe care îl alegi tu — e-mailul atelierului sau WhatsApp. Pe comandă rămâne doar indicatorul da/nu despre existența dioptriilor, explicat în secțiunea 3.
Pentru orice transfer care ar apărea în viitor se aplică aceleași reguli: fie o țară acoperită de o decizie de adecvare (art. 45), fie clauzele contractuale standard aprobate de Comisie (art. 46 alin. (2) lit. c)), însoțite, unde este necesar, de măsuri tehnice suplimentare de protecție. Nu ne întemeiem pe derogările din art. 49. Poți cere oricând la office@lentilo.ro informații despre garanțiile aplicabile și o copie a acestora.
7. Cât păstrăm datele
Păstrăm fiecare categorie de date exact atât cât ne trebuie pentru scopul ei, apoi le ștergem sau le anonimizăm. Duratele exacte sunt în tabelul de la secțiunea 4, iar pe scurt arată așa: dosarul comenzii și corespondența se păstrează pe durata lucrării și 3 ani după finalizarea ei, termenul general de prescripție; datele de care depinde apărarea noastră dacă ne reclami lucrarea — valorile după care am tăiat, ce ai confirmat la telefon, observațiile despre starea ramei și fotografiile ei — se păstrează mai mult, pe toată durata garanției legale de conformitate prevăzute de OUG nr. 140/2021, la care se adaugă termenul general de prescripție de 3 ani, exact ca în secțiunile 3 și 4; documentul de prescripție, 12 luni de la livrare, așa cum am explicat în secțiunea 3; facturile și documentele justificative rămân 5 ani, pentru că așa cere legea contabilității și cea fiscală, iar aici nu avem libertatea de a le șterge mai devreme; datele de marketing rămân până când te dezabonezi; cookie-urile de analiză, cel mult 13 luni.
Dacă apare un litigiu, păstrăm datele relevante până la soluționarea lui definitivă, chiar dacă termenul obișnuit s-a împlinit între timp. Când ne ceri ștergerea și nu există un motiv care să ne oblige să păstrăm datele — o obligație legală ori nevoia de a ne apăra într-o reclamație, cum este cazul valorilor din prescripție — le ștergem fără întârziere. Copiile de siguranță se suprascriu în ciclul lor normal, iar datele șterse dispar și din ele la următoarea rotație.
8. Decizii automate și analiza riscului de fraudă
Nu facem profilare în scopuri de marketing și nu luăm decizii automate cu efecte juridice sau similare asupra ta. Există totuși o prelucrare automată despre care trebuie să știi, pentru că atinge fiecare comandă plasată pe site.
Shopify analizează automat riscul de fraudă al comenzii. Când plasezi o comandă, platforma o compară cu tiparele de fraudă pe care le cunoaște și îi atribuie un indicator de risc — de regulă scăzut, mediu sau ridicat — însoțit de câteva semnale care explică indicatorul: dacă adresa de livrare se potrivește cu cea de facturare, dacă de pe același dispozitiv sau de pe aceeași adresă IP au mai venit comenzi, dacă plata a fost încercată de mai multe ori, ce spune procesatorul de card despre tranzacție. Analiza se face în platformă, automat, fără intervenția noastră.
Temeiul este art. 6 alin. (1) lit. f) din GDPR — interesul nostru legitim de a preveni frauda și de a nu tăia lentile plătite cu un card furat. Considerentul (47) din GDPR recunoaște expres prevenirea fraudei ca interes legitim.
Indicatorul nu decide nimic singur. Nu anulăm și nu refuzăm nicio comandă doar pentru că platforma a marcat-o. Un om din atelier se uită la comandă, te sună dacă e ceva neclar și decide. Dacă alegem totuși să nu executăm o comandă din acest motiv, îți spunem, îți returnăm banii dacă au fost încasați și poți cere să o reevaluăm, scriindu-ne la office@lentilo.ro. Pentru că decizia finală o ia un om, nu ne aflăm în situația reglementată de art. 22 din GDPR — dar îți dăm oricum aceleași garanții: intervenție umană, dreptul de a-ți exprima punctul de vedere și dreptul de a contesta rezultatul.
Indicatorul de risc și semnalele care îl însoțesc rămân în dosarul comenzii și nu sunt folosite în alt scop. Nu construim din ele un profil despre tine, nu le transmitem nimănui și nu le folosim ca să îți refuzăm automat comenzile viitoare.
9. Drepturile tale
GDPR îți dă un set de drepturi pe care le poți exercita oricând, gratuit și fără să justifici de ce:
- Dreptul de acces (art. 15) — poți afla dacă prelucrăm date despre tine și poți primi o copie a lor, împreună cu explicații despre scopuri, destinatari și durate.
- Dreptul la rectificare (art. 16) — dacă o valoare din prescripție, o adresă sau un nume sunt greșite ori incomplete, le corectăm și le completăm de îndată. Dacă ne prinzi înainte de tăiere, corectăm și lucrarea.
- Dreptul la ștergere (art. 17) — îți ștergem datele când nu ne mai sunt necesare, când îți retragi consimțământul sau când te opui întemeiat prelucrării. Nu putem șterge, în schimb, facturile și documentele pe care legea ne obligă să le păstrăm și nici valorile după care am tăiat lentilele: pe acelea le ținem pe temeiul art. 9 alin. (2) lit. f) din GDPR, pe durata garanției și a termenului de prescripție, în condițiile explicate în secțiunea 3.
- Dreptul la restricționarea prelucrării (art. 18) — dacă ne contești exactitatea datelor sau legalitatea prelucrării, putem „îngheța” datele: le păstrăm, dar nu le mai folosim până se lămurește situația.
- Dreptul la portabilitate (art. 20) — datele pe care ni le-ai furnizat tu și pe care le prelucrăm automat, în baza contractului sau a consimțământului, ți le dăm într-un format structurat, uzual și care poate fi citit automat, ori le transmitem direct altui operator, dacă este tehnic posibil.
- Dreptul la opoziție (art. 21) — te poți opune oricând prelucrărilor întemeiate pe interesul nostru legitim, arătând motivele legate de situația ta. Dacă te opui marketingului direct, ne oprim imediat, fără nicio condiție și fără să cerem explicații.
- Dreptul de a-ți retrage consimțământul (art. 7 alin. (3)) — oricând și la fel de simplu cum l-ai dat: linkul de dezabonare din fiecare e-mail de marketing, butonul „Setări cookie-uri” din subsolul fiecărei pagini sau un mesaj la office@lentilo.ro. Când schimbi alegerea din banner, noua opțiune este transmisă imediat platformei Shopify, care oprește efectiv cookie-urile refuzate. Retragerea nu afectează legalitatea prelucrării făcute înainte de ea. Retragerea din contract este altceva decât retragerea consimțământului: pentru ea ai, tot în subsolul fiecărei pagini, funcția „Retrage-te din contract”.
- Dreptul de a nu face obiectul unei decizii automate (art. 22) — nu poți fi supus unei decizii bazate exclusiv pe prelucrare automată care să producă efecte juridice sau efecte similare semnificative asupra ta.
Nu luăm decizii automate cu efecte juridice sau similare asupra ta și nu facem profilare. Prețul afișat pe site nu se calculează în funcție de tine, ci de tipul lucrării și de marca ramei, iar fiecare comandă este verificată și confirmată de un om din atelier, după ce vede rama. Singura prelucrare automată care atinge comanda este analiza de risc de fraudă a platformei, descrisă în secțiunea 8, iar și acolo decizia o ia tot un om.
Atunci când rectificăm, ștergem sau restricționăm date, comunicăm acest lucru fiecărui destinatar căruia i le-am transmis, în afară de cazul în care ar fi imposibil sau ar presupune eforturi disproporționate, și îți spunem cine sunt acei destinatari dacă ne ceri (art. 19).
Cum îți exerciți drepturile. Scrie-ne la office@lentilo.ro, sună la 0721 864 095 sau trimite-ne o cerere scrisă la sediul social. Spune-ne ce drept vrei să exerciți și, dacă poți, la ce comandă se referă — ne ajută să găsim mai repede datele. Îți răspundem în cel mult o lună de la primirea cererii. Dacă cererea este complexă sau avem mai multe cereri în lucru, putem prelungi termenul cu maximum două luni, dar te anunțăm în prima lună și îți explicăm de ce. Exercitarea drepturilor este gratuită; doar dacă o cerere este vădit nefondată sau excesivă, în special prin caracterul ei repetitiv, putem percepe o taxă rezonabilă sau putem refuza să dăm curs, motivat (art. 12 alin. (5)). Dacă avem îndoieli întemeiate cu privire la identitatea celui care cere, îți putem solicita informații suplimentare — nu ca să îngreunăm procesul, ci ca să nu dăm datele tale altcuiva (art. 12 alin. (6)).
10. Dreptul de a depune plângere
Dacă ești nemulțumit de felul în care îți prelucrăm datele, scrie-ne întâi nouă: de cele mai multe ori lucrurile se rezolvă într-un schimb de mesaje. Nu ești însă obligat să treci pe la noi. Te poți adresa oricând autorității de supraveghere:
- Autoritate
- Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
- Adresă
- Bd. G-ral Gheorghe Magheru nr. 28-30, Sector 1, București
- Website
- www.dataprotection.ro
Ai, de asemenea, dreptul la o cale de atac judiciară eficientă împotriva autorității de supraveghere (art. 78) și împotriva noastră, ca operator (art. 79), precum și dreptul de a cere despăgubiri pentru prejudiciul material sau moral suferit (art. 82). Aceste drepturi sunt independente: le poți exercita chiar dacă ai depus deja plângere la ANSPDCP.
Pentru neînțelegeri legate de comandă, nu de date, există și soluționarea alternativă a litigiilor, potrivit OG nr. 38/2015: platforma SAL a ANPC.
11. Securitate
Luăm măsuri pe măsura riscului real al unui atelier mic, care lucrează cu obiecte personale. Iată exact ce facem:
- Conexiune criptată. Tot site-ul, inclusiv checkout-ul, funcționează prin HTTPS/TLS, așa că ce completezi nu circulă în clar.
- Zero date de card la noi. Numărul cardului și codul de securitate ajung direct la Shopify Payments; noi nu le stocăm, nu le vedem și nu le putem recupera.
- Prescripția nu stă pe site. Nu există câmp de încărcare a fișierelor și niciun câmp pentru dioptrii, deci documentul tău și valorile din el nu ajung pe server și nu ajung în Shopify. Rămân în cutia poștală a atelierului sau în conversația de WhatsApp, la care au acces doar oamenii care lucrează la comenzi.
- Acces limitat. La dosarul comenzii ajung doar persoanele care lucrează efectiv la ea — cine preia comanda, cine taie și montează lentilele, cine emite factura. Conturile sunt individuale și protejate prin parole.
- Minimizare. Fiecare partener primește strict ce îi trebuie: curierul, o adresă și un telefon; contabilul, o factură. Prescripția rămâne în atelier.
- Grijă fizică pentru rama ta. Ramele primite sunt ținute în atelier, ambalate și identificate printr-un număr de comandă, nu printr-un bilet la vedere cu datele tale personale.
- Copii de siguranță ale datelor de comandă și ale corespondenței, ca o defecțiune tehnică să nu ducă la pierderea informațiilor.
- Confidențialitate asumată de oricine are acces la date, fie că este angajat sau colaborator.
Nu promitem imposibilul. Nicio măsură tehnică nu oferă securitate absolută, iar transmiterea de date prin internet implică întotdeauna un risc rezidual. Nu deținem certificări de securitate și nu pretindem că avem. Ce putem promite este că, dacă apare o încălcare a securității datelor care riscă să îți afecteze drepturile, o notificăm ANSPDCP în cel mult 72 de ore de la momentul în care o aflăm (art. 33) și te informăm direct, în cuvinte clare, dacă riscul pentru tine este ridicat (art. 34).
12. Minori
Serviciul nostru nu se adresează copiilor. Site-ul este destinat persoanelor de cel puțin 16 ani și nu colectăm cu bună știință date de la copii sub această vârstă în baza consimțământului lor.
Asta nu înseamnă că nu lucrăm la ochelarii copiilor — o facem des. În aceste cazuri, comanda este plasată de părinte sau de reprezentantul legal, care ne trimite prescripția purtătorului și celelalte date necesare și răspunde de exactitatea lor. Tot el ne dă, prin trimiterea prescripției, consimțământul explicit pentru prelucrarea datelor privind sănătatea copilului. Contractul se încheie cu adultul, iar comunicarea, plata și livrarea se fac tot cu el.
Dacă aflăm că am primit datele unui copil fără implicarea părintelui sau a reprezentantului legal, le ștergem fără întârziere. Dacă ești părinte și crezi că s-a întâmplat asta, scrie-ne la office@lentilo.ro și rezolvăm imediat.
13. Cookie-uri
Bannerul are patru categorii. Prima este cea a cookie-urilor strict necesare, fără de care site-ul nu ar funcționa — coșul și sesiunea de checkout ale platformei Shopify, plus alegerea ta privind cookie-urile, pe care site-ul o păstrează în browserul tău sub numele lentilo-consent; aceasta este, de altfel, singura valoare pe care site-ul o scrie el însuși în browser. Categoria este blocată pe „pornit”. Celelalte trei sunt opționale și le poți accepta sau refuza separat: analiză, preferințe — aici intră cookie-ul propriu al platformei Shopify, shopify_override_user_locale, care ține minte limba pe care ai ales-o, ca să nu o mai selectezi la fiecare vizită; limba nu mai este reținută de site, ci de platformă — și marketing. Toate trei se instalează numai după ce le accepți în banner, așa cum cer art. 4 alin. (5) din Legea nr. 506/2004 și art. 6 alin. (1) lit. a) din GDPR. Nimic nu este bifat dinainte.
Alegerea ta este transmisă platformei Shopify prin interfața ei de consimțământ, iar platforma este cea care oprește efectiv cookie-urile din categoriile pe care le-ai refuzat — bannerul nu este un ornament. Poți accepta tot, refuza tot sau alege pe categorii, iar decizia o poți schimba oricând din butonul „Setări cookie-uri” aflat în subsolul fiecărei pagini. Refuzul nu îți blochează accesul la site și nu are niciun efect asupra comenzii tale.
Lista completă a cookie-urilor, cu rolul și durata fiecăruia, se află în Politica de cookie-uri.
14. Modificări ale politicii și contact
Putem actualiza această politică atunci când se schimbă legea, serviciile noastre sau partenerii cu care lucrăm. Versiunea în vigoare este întotdeauna cea publicată pe această pagină, iar data ultimei actualizări apare în partea de sus. Dacă modificăm ceva important — un scop nou, un temei juridic nou, o categorie nouă de destinatari sau o durată de păstrare mai lungă — te anunțăm vizibil pe site înainte ca schimbarea să producă efecte, iar dacă prelucrarea se bazează pe consimțământ, îți cerem din nou acordul. Nu folosim o modificare a politicii ca să facem, pe tăcute, ceva pentru care ți-am cerut acordul altădată.
Pentru orice întrebare despre datele tale, despre această politică sau pentru a-ți exercita drepturile, scrie-ne — răspundem noi, oameni din atelier, nu un formular automat:
- Operator
- OKRALIS S.R.L., CUI 51286544, J2025010018003
- office@lentilo.ro
- Telefon
- 0721 864 095
- wa.me/40721864095
- Atelier
- Strada Sfânta Maria 47, București
- Sediul social
- Șos. Giurgiului nr. 277–279, Sector 4, București
- Program
- Luni–vineri, 9:00–18:00
Privacy Policy
Last updated: 8 August 2026You hand us something personal — your own glasses — and sometimes the prescription your optician gave you. It is only fair that you know exactly what happens to the information you leave with us. This policy explains what personal data we process when you use lentilo.ro, when you place an order or when you send your frame to the atelier, why we process it, who receives it, and what you can ask of us at any time.
We have kept it as plain as we could. It complies with Regulation (EU) 2016/679 (GDPR), Romanian Law no. 190/2018 implementing the GDPR, Law no. 506/2004 on personal data processing in the electronic communications sector, and Law no. 365/2002 on electronic commerce.
1. The data controller
The lentilo.ro website is operated by OKRALIS S.R.L. The company is the trader and seller of the service and, within the meaning of art. 4(7) GDPR, it is the controller of your personal data — the one that decides why and how it is processed.
- Company name
- OKRALIS S.R.L.
- Legal form
- Limited liability company (S.R.L.)
- Tax ID (CUI / CIF)
- 51286544 — the company is not registered for VAT
- Trade Register no.
- J2025010018003
- Registered office
- Șos. Giurgiului nr. 277–279, Sector 4, Bucharest, Romania
- Main NACE code
- 4791
- office@lentilo.ro
- Phone
- 0721 864 095 — also on WhatsApp
Orders are carried out at the atelier at Strada Sfânta Maria 47, Bucharest, where you can also drop off your frame in person, Monday to Friday between 9:00 and 18:00. Whether you send your glasses by courier or bring them in yourself, responsibility for the data collected through the website and for your order stays with OKRALIS S.R.L.
The online shop runs on the Shopify platform, and orders are completed in Shopify's own checkout. Shopify processes the order data on our behalf, as a processor, not for its own purposes; the controller remains OKRALIS S.R.L. What Shopify does, and what leaves Europe, is set out in full in sections 5 and 6.
We are not legally required to appoint a Data Protection Officer: we are not a public authority, we do not monitor people systematically and on a large scale, and we do not process special categories of data on a large scale, which are the conditions set by art. 37 GDPR. So that you are never left without someone to talk to, every request and question about your data goes straight to office@lentilo.ro or 0721 864 095 and is handled by the company's director.
2. What data we process
We collect strictly what we need in order to pick up your frame, make the lenses and bring them back to you. Nothing "for later", nothing out of curiosity.
Identification and contact data
Your first and last name, email address and phone number. They tell us who we have a contract with and allow us to confirm the order, arrange the courier pickup and let you know when the work is finished. If you write to us on WhatsApp, we also process the number you contact us from, together with the messages exchanged.
What you fill in at checkout
The Shopify checkout asks for your name, email address, phone number and address: street and number, town, county or sector and postcode, plus any instructions you leave in the notes field (floor, intercom, a time slot that suits you). Without them the order simply cannot be carried out — that address is where the parcel with your finished glasses goes.
Only the leg from the atelier to you is arranged through Shopify. If we collect the frame from you by courier, we arrange that pickup separately, with a partner outside the platform, using the same contact and address details. If you would rather drop the frame off at the atelier and collect it there, tell us — the address is then no longer used for delivery.
Order data
- the type of work — lenses for optical glasses or for sunglasses;
- the frame brand you select from the list on the site, because for sunglasses the price depends on it;
- the lens colour and finish (solid, gradient or mirror);
- whether you want the manufacturer's engraving recreated — available for sunglasses only, and only where the original lens already carries one;
- the treatments you choose for optical lenses — UV400 protection, hard coat, anti-reflective coating, blue-light filter;
- an indicator saying only whether the work involves dioptres or not — "With prescription — sent by email" or "None". Neither the dioptre values nor the prescription document ever reach the order;
- the language you were using the site in when you placed the order, Romanian or English, so that we answer you in the same one;
- the moment — date and time — at which you ticked the express request in the configurator asking us to begin the work, stored on the order as a timestamp;
- the description and condition of the frame you entrust to us, including the atelier's notes after inspecting it and, sometimes, photos of the frame or of the original lenses;
- the order price and the final price confirmed once the atelier has seen the frame, the payment method chosen, the Shopify order number and the dates of each step (frame pickup, start of work, dispatch of the return).
Your prescription, if you need corrective lenses
If you choose corrective lenses, you send us the prescription issued by your optician or doctor, by email or on WhatsApp, and we then call you to confirm the values together. That is health data and it deserves a separate explanation: we have given it section 3, immediately after this one.
Payment data
At checkout you can pay by bank card, inside the Shopify checkout, or cash on delivery to the courier.
Lentilo neither sees nor stores your full card details. The card number, expiry date and security code (CVV/CVC) are captured and processed by Shopify Payments (Shopify International Limited), in its own secure environment, on the payment page. We receive and keep only the outcome of the transaction: whether it was approved or declined, the amount, currency, date, payment method and, if the platform makes them available to us, the last digits of the card — strictly so that we can match the payment in our accounts. With cash on delivery, the courier collects the money and sends us the confirmation; at no point do we see your means of payment.
If you ask for an invoice in a company's name, we also process that company's details (name, tax ID, trade register number, registered office, bank account) — these are not personal data as such, but they may include the representative's name.
Your correspondence with us
The messages you send us by email or WhatsApp — including the one carrying your prescription — the notes you leave with the order and our replies, along with what you tell us on the phone and we write down in the order file. We do not record phone calls.
Technical data about your visit
The site runs on the Shopify platform, and the platform processes technical data about your visit: IP address, time of the request, pages opened, browser and device type, the page you came from. Some of it is strictly necessary — without it the cart, the checkout and the protection against abuse would not work. The rest is analytics data, from which Shopify builds the shop reports we read: how many visits there were, which pages were read, where people stop before ordering.
The site sets cookies of its own, and visit analytics are switched on. The cookie banner has four categories: strictly necessary — locked on, because without them the site would not work — plus analytics, preferences and marketing. The three optional categories are set only after you accept them in the banner, and if you refuse, the site and your order carry on exactly the same. Your choice is not a formality: we pass it to Shopify through the platform's own consent interface, and it is the platform that actually holds back the optional cookies — analytics, preferences and marketing — until you accept them. The full, exact list, with the role and lifespan of each, is in our Cookie Policy.
The technical logs of the platform and of the content delivery network are held by Shopify, under its own retention rules. We do not run them, we cannot read them in the ordinary course, and we will not promise you a particular period on Shopify's behalf.
Outside the platform, the pages call no foreign server at all. The site's typefaces are hosted by us and are delivered together with the pages, as our own files; your browser requests nothing from Google Fonts and contacts no other third-party provider when you open a page, so your IP address reaches no one beyond the platform the shop runs on.
What happens if you don't give us this data
Identification, contact, address and order data are necessary to enter into and perform the contract: without them we cannot take the order. Invoicing data is a legal requirement, not an option. The prescription is needed only if you choose corrective lenses — without it we have nothing to cut to, and the order waits. Everything else — newsletter sign-up and the cookies in the three optional categories, analytics, preferences and marketing — is entirely optional, and refusing has no effect whatsoever on your order and costs you nothing.
Data we receive from other sources
As a rule we get your data directly from you. There are, however, situations where it reaches us indirectly, and art. 14 GDPR requires us to tell you about them:
- when someone else places the order for you — a parent for a child, a spouse, a relative, a colleague. We receive the wearer's name, contact details, address and, where applicable, their prescription from that person, who confirms to us that they are entitled to share them;
- from the courier company — shipment status, the date and time of pickup and delivery, and any remarks recorded on delivery;
- from Shopify and Shopify Payments — confirmation or refusal of the payment, its reference, and the automated fraud-risk indicator assigned to the order, which we describe in section 8;
- from public registers — only if you ask for a company invoice and we need to verify the billing details.
The categories of data received this way are the same as those described above. If we receive data about you from someone else and you are not already in direct contact with us, we provide you with the information in this policy within one month of obtaining it, or at our first contact with you, whichever comes first.
3. Your prescription: health data
If you want lenses with dioptres, we need the prescription issued by your optician or doctor. It is the only category of sensitive data we process — health data within the meaning of art. 9 GDPR — so we explain separately, and in detail, everything that happens to it.
How it reaches us
You place the order on the site like any other. Then you send us the prescription by email, to office@lentilo.ro, or on WhatsApp, as a photo or as a file.
The site has no file upload field and no field for typing in dioptres. The prescription document and the values on it do not pass through lentilo.ro, are not uploaded anywhere on the site and do not reach Shopify. They land directly in the atelier's mailbox or in our WhatsApp conversation — that is, somewhere read by the people working on your order.
Before we cut anything, we call you and confirm together the values we read from the prescription. We note in the order file what was confirmed and when. We do not record the call.
What we actually process
- the prescription document as you send it — the photo or the file, with everything written on it: the values for each eye, the pupillary distance, the date of issue, the name and stamp of whoever issued it and, sometimes, medical remarks the document already carries;
- the values we actually use for cutting, written into the order file;
- what you confirmed or corrected on the phone.
We do not ask you for a diagnosis, a medical history or any other medical paperwork, and we have no need of them. If your prescription also carries remarks we do not need, we make no use of them, we do not copy them into the order file and we pass them to no one.
Why
So that we cut the lenses correctly. Without the values in the prescription a corrective lens cannot be made — this is not a formality, it is the very information the work is based on. The confirmation call exists for the same reason: one digit misread means a pair of lenses in the bin.
On what legal basis
This processing needs two things: a basis under art. 6 and, because it is health data, a condition under art. 9(2) GDPR.
- Art. 6(1)(b) — performance of the contract between us. You ordered a pair of lenses made to your dioptres; without them the contract cannot be performed.
- Art. 9(2)(a) — your explicit consent. You give it by the very act of sending us the prescription, after we have told you plainly — here and in the message asking for it — what we process from it, for what purpose and how long we keep it. We infer it from nothing else: if you do not send us the document, we have no consent and we process nothing. You can withdraw it at any time by writing to office@lentilo.ro, bearing in mind that if you withdraw it before cutting, we cannot make corrective lenses and the order stops.
- Art. 9(2)(f) — if a complaint or a dispute about the work arises, we keep the values we cut to in order to establish, exercise or defend a legal claim, even if you have withdrawn your consent in the meantime.
Who sees it
Only the people at the atelier actually working on your order: whoever takes the order, whoever reads the prescription, whoever calls you, whoever cuts and fits the lenses. The document does, however, travel through whichever channel you choose to send it on: if you write to us by email, through the infrastructure of the atelier's email provider; if you write on WhatsApp, through the service operated by Meta Platforms Ireland Limited. Both are listed in section 5, and if you would rather avoid WhatsApp altogether, send us the document by email.
The prescription document and the dioptre values do not reach Shopify, the courier, the accountant, xConnector or FGO — no dioptre values appear on the invoice, and the parcel carries no medical information. To be exact to the end: one thing does reach the order — a single yes/no indicator saying whether the work involves dioptres ("With prescription — sent by email" or "None"). That is in itself information about your health, so we will not hide it: the indicator is recorded on the Shopify order, travels with the order through the invoicing chain (xConnector and FGO) and is read by the people at the atelier, because how the work is done depends on it. What goes nowhere are the document and the figures: they stay in the atelier's mailbox or in the WhatsApp conversation and in the order file. We never use the prescription for marketing.
How long we keep it and how we delete it
We keep the document received by email or WhatsApp for 12 months from delivery of the order — as long as remakes and adjustments after delivery realistically take — and then we delete it from the mailbox and from the conversation, including the deleted-items folder. We do not keep the document in order to defend ourselves against late complaints, because those can arrive later than that: for that we rely on the values written into the order file and on what you confirmed on the phone, which is exactly what we cut to. Those stay with the order file, for the duration of the legal guarantee of conformity and the general 3-year limitation period, because without them we cannot defend ourselves if you complain about the work.
If you ask us to delete it or you withdraw your consent, we delete the document from the mailbox and from the WhatsApp conversation within one month of your request and confirm in writing that we have done so. The values written into the order file are a different matter and we do not delete them on request: we keep them on the basis of art. 9(2)(f) GDPR, for the duration of the legal guarantee of conformity and the 3-year limitation period, even if you have withdrawn your consent in the meantime, because without them we cannot defend ourselves if you complain about the work. We delete them once that window closes, and if a complaint or dispute is under way at that point, we hold them until it is finally resolved and delete them afterwards. Two further things we will not promise you, so as not to promise the impossible: copies in our email provider's backup systems are overwritten on their normal cycle and disappear at the next rotation, not manually on request; and the invoice and accounting documents cannot be deleted, because the law requires us to keep them — no dioptre values appear on those, however.
4. Purposes and legal bases
Every processing operation we carry out has a precise purpose and a legal basis. The table below sets them all out, together with how long we keep the data.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Taking the order and carrying out the work: collecting the frame, inspecting it at the atelier, cutting and fitting the lenses, dispatch to your address | Identification, contact, address, order data | Art. 6(1)(b) — performance of the contract you are party to | For the duration of the order and 3 years after completion — the general limitation period, art. 2517 of the Civil Code |
| Making corrective lenses from the prescription you send us, and confirming the values with you by phone before cutting (section 3) | The prescription document received by email or WhatsApp, the values written into the order file, what you confirmed on the phone | Art. 6(1)(b) — performance of the contract, read together with art. 9(2)(a) — your explicit consent for health data; for complaints and disputes, art. 9(2)(f) | The document: 12 months from delivery. The values in the order file: for the duration of the legal guarantee of conformity and the 3-year limitation period |
| Communicating about your order: confirmations, arranging the pickup, the call in which we confirm the values, and the message that the work is ready | Contact data, correspondence, order data | Art. 6(1)(b) — performance of the contract | As above, together with the order file |
| Recording your express request that we begin the work: in the configurator you tick a mandatory box asking us to start and acknowledging that you lose your right of withdrawal once the work is carried out. Without that tick the order cannot be submitted, and the moment you ticked it is stored on the order | The tick and the timestamp (date and time) attached to the order, together with the order number | Art. 6(1)(c) — legal obligation (art. 9(1) and art. 16(a) of GEO no. 34/2014), together with art. 6(1)(f) — our legitimate interest in being able to prove that you asked | Together with the order file |
| Handling the 14-day right of withdrawal and cancellations requested before cutting begins, including returning the frame. You can send the request at any time from the "Withdraw from your contract" function, permanently present in the footer of every page; the form registers the request automatically, with the date and time, and the confirmation on a durable medium is then sent to you by email by a person at the atelier, not by an automated reply | Identification, contact, address, order data, payment reference for the refund; from the withdrawal form — your name, the email address the order was placed with, the order number and date and, if you want to tell us, the reason | Art. 6(1)(c) — legal obligation (GEO no. 34/2014 on consumer rights) | 3 years, together with the order file; refund documents, together with the accounting records |
| Invoicing — the invoice is generated automatically through xConnector and issued through FGO at the moment the parcel leaves for you — bookkeeping, meeting our tax obligations and filing the invoice with the tax authority | Identification, billing details, order data, payment confirmation | Art. 6(1)(c) — Accounting Law no. 82/1991 and the Fiscal Code | 5 years from the end of the financial year in which the documents were drawn up (art. 25 of Law no. 82/1991, as amended by Law no. 36/2023) |
| Collecting payment, by card through Shopify Payments or cash on delivery to the courier | Transaction outcome, amount, date, payment method — without full card details | Art. 6(1)(b) — performance of the contract, together with art. 6(1)(c) for the record of payments | Together with the related accounting documents |
| The legal guarantee of conformity, complaints and putting right any problem with the work | Order data, correspondence, photos of the frame and lenses | Art. 6(1)(c) — GEO no. 140/2021 on the sale of goods and associated guarantees, and Government Ordinance no. 21/1992 on consumer protection | For as long as the legal guarantee of conformity under GEO no. 140/2021 runs, plus the general limitation period set by art. 2517 of the Civil Code, so that we can defend ourselves if a complaint arrives near the deadline |
| Marketing messages: newsletter, news about colours and finishes, offers | First name, email address and, if you give it to us, phone number | Art. 6(1)(a) — your consent, which you can withdraw at any time, as easily as you gave it | Until you withdraw consent or unsubscribe; proof of consent is kept for a further 3 years after withdrawal, so we can show the processing was lawful |
| Analysing visits through the Shopify reports: which pages are read, where visitors come from, where they stop before ordering — an active purpose, and only for visitors who have accepted the analytics category in the cookie banner | Technical data: IP address, browser, device, pages viewed, length of visit, referring page | Art. 6(1)(a) — consent, read together with art. 4(5) of Law no. 506/2004, which requires prior consent for cookies | No more than 13 months from when the cookie is set; after that we ask for your consent again |
| Keeping the shop running and secure: the platform's technical logs, preventing abuse | Technical data | Art. 6(1)(f) — our legitimate interest in keeping the shop functional and safe | The logs are held by Shopify under its own retention rules. They are not our logs and we cannot promise you a particular period on its behalf |
| Automated fraud-risk checking of orders placed at checkout, followed by a decision taken by a person at the atelier (section 8) | Order data, technical data (IP address, device), the match between delivery and billing address, signals from the payment processor, the risk indicator calculated by the platform | Art. 6(1)(f) — our legitimate interest in preventing fraud, expressly recognised by recital (47) GDPR | Together with the order file |
| Establishing, exercising or defending a legal claim, in court or before an authority, including ANPC proceedings | The categories of data relevant to the dispute | Art. 6(1)(f) — our legitimate interest in defending our rights | Until the matter is finally resolved and all appeals are exhausted |
About legitimate interest. Whenever we rely on art. 6(1)(f), we first carry out a balancing test: we check that the purpose is real and necessary, that we cannot achieve it with less data, and that our interest — keeping the site running and being able to defend ourselves if a dispute arises — is not overridden by your rights and freedoms. Our conclusion is that it is not: we process the bare minimum, we do not build marketing profiles and we do not combine the data for other purposes. The only automated assessment that touches your order is the platform's fraud-risk analysis, and even there the final decision is taken by a person — we explain it in section 8. You can ask us at any time, at office@lentilo.ro, for a summary of that assessment, and you can object to the processing under art. 21 GDPR.
The commercial rules of the order — including the moment cutting begins and what that moment means for your right of withdrawal — are explained in our Terms and Conditions.
5. Who receives your data
We do not sell your data, we do not rent it out and we do not give it to anyone for someone else's marketing. It reaches only the partners we need in order to carry out your order, and the authorities where the law obliges us. We list them by category and, where the partner is already chosen and fixed, by name:
- Shopify International Limited (Ireland) — the platform the shop and the checkout run on. As a processor, it handles what you fill in at checkout, your customer account details if you create one, the order notifications sent to you by email, and the technical data about your visit. It does not receive the prescription document or the dioptre values; what reaches the order is the options you chose in the configurator — the frame brand, the lens colour and finish, the engraving, the treatments — together with the yes/no indicator of whether there are dioptres, the interface language and the timestamp of your express request that we begin the work, all attached to the order line.
- Shopify Payments (Shopify International Limited) — the card payment processor. It captures your card details directly, in its own secure environment, and sends us only the transaction outcome. For the card details themselves, the processor acts under its own privacy policy and the security rules of the payments industry.
- xConnector — the service through which the invoice is generated automatically. It is connected to the courier and to the invoicing provider, and receives the billing details, the order data and the shipment data.
- FGO — the provider through which the invoice is issued and stored. It receives the billing details and the order lines, and therefore also the yes/no indicator of whether there are dioptres, which is part of the order line. No dioptre values appear on the invoice, and the prescription document never reaches it.
- The courier company — receives your name, phone number and address so it can bring the parcel with your glasses to your door. With cash on delivery, it also receives the amount to collect. When we collect the frame from you, that pickup is arranged through a separate partner, outside the platform, which receives the same data. The courier is not told what work you ordered and never receives the prescription document or the dioptre values.
- ANAF, the tax authority — the invoices we issue are filed with it through the Virtual Private Space (SPV), as the law requires.
- The atelier's email provider — hosts the mailbox where your correspondence and, if you ordered corrective lenses and choose email, your prescription arrive.
- Meta Platforms Ireland Limited (WhatsApp) — if you choose to write to us on WhatsApp, the conversation travels through its service, including when you send us your prescription that way, which is health data. Message content is end-to-end encrypted, so the provider cannot read it, but it does process your phone number and the data about the communication — with whom, when, how often — as a controller in its own right, under its own privacy policy. We receive none of that data from it. If you would rather nothing went through WhatsApp, write to us by email: the channel is yours to choose.
- Our accountant or accounting firm — receives invoices and supporting documents so that we keep the records the law requires.
- IT service providers — where applicable, when they carry out maintenance or troubleshooting and may incidentally see data, under a duty of confidentiality.
- Public authorities — the tax authority, the consumer protection authority, the data protection authority, the police, the courts or other bodies, strictly where the law obliges us to answer a legitimate request.
With every supplier that processes data on our behalf we have a processing agreement under art. 28 GDPR: it may use the data only for what we ask, it must protect it, impose confidentiality on its staff, not engage another sub-processor without our approval, and delete or return the data when our collaboration ends. We send each of them only the minimum data they need to do their job. At any time, on request, we will tell you the exact name of each supplier in the categories above, as it stands on the day you ask; write to office@lentilo.ro and we will answer with the companies' names, not with generalities.
6. Transfers outside the EEA
Now that the shop runs on Shopify, part of the infrastructure we use also operates outside the European Economic Area. We are not hiding that. Below is exactly what leaves, to whom, and on what basis under Chapter V GDPR.
- Shopify Inc., Canada. The order data is processed by Shopify International Limited, an Irish company, which may pass it on to its parent, Shopify Inc., in Canada. The transfer relies on the European Commission's adequacy decision for Canadian commercial organisations subject to PIPEDA (art. 45 GDPR): the Commission found the level of protection comparable to the European one, so no additional safeguards are required.
- Shopify's chain of sub-processors. For cloud hosting, the content delivery network (CDN), error logging and visit analytics, Shopify in turn uses suppliers that may process data outside the EEA, including in the United States. Those transfers rely on the standard contractual clauses adopted by the European Commission (art. 46(2)(c) GDPR), supplemented by additional technical and organisational measures and, where the US supplier is certified, on the adequacy decision for the EU–US Data Privacy Framework (art. 45).
- The atelier's email. Your correspondence and, if you choose that channel, your prescription arrive in the atelier's mailbox. If our email provider processes data outside the EEA as well, that transfer relies on an adequacy decision (art. 45) or on the standard contractual clauses (art. 46(2)(c)). Write to us and we will tell you exactly which provider we use and which safeguards apply.
- WhatsApp (Meta Platforms Ireland Limited). If you choose to write to us on WhatsApp — including to send us your prescription — the data about the communication is processed by the Irish company and may also reach servers in the United States within the group. The basis is the adequacy decision for the EU–US Data Privacy Framework (art. 45), supplemented by the Commission's standard contractual clauses (art. 46(2)(c)), under the provider's own policy. Message content is end-to-end encrypted, so the provider cannot read it. You can avoid this transfer entirely by sending us everything by email.
What does not travel through the site. The prescription document and the dioptre values do not pass through lentilo.ro and do not reach Shopify: there is no upload field and no field for typing in dioptres, so the platform has nothing to transfer. They move only between you and the atelier, on the channel you choose — the atelier's mailbox or WhatsApp. All that stays on the order is the yes/no indicator of whether there are dioptres, explained in section 3.
The same rules apply to any transfer that may arise in future: either a country covered by an adequacy decision (art. 45), or the standard contractual clauses approved by the Commission (art. 46(2)(c)), accompanied where necessary by supplementary technical safeguards. We do not rely on the derogations in art. 49. You can ask us at office@lentilo.ro for details of the safeguards in place and for a copy of them.
7. How long we keep your data
We keep each category of data for exactly as long as its purpose requires, then delete or anonymise it. The precise periods are in the table in section 4; in short: the order file and the correspondence are kept for the duration of the work and 3 years after completion, the general limitation period; the data our defence depends on if you complain about the work — the values we cut to, what you confirmed on the phone, the notes on the condition of the frame and its photos — is kept longer, for as long as the legal guarantee of conformity under GEO no. 140/2021 runs, plus the general 3-year limitation period, exactly as set out in sections 3 and 4; the prescription document, 12 months from delivery, as explained in section 3; invoices and supporting documents stay for 5 years, because accounting and tax law require it and we are not free to delete them sooner; marketing data stays until you unsubscribe; analytics cookies, no more than 13 months.
If a dispute arises, we keep the relevant data until it is finally resolved, even if the usual period has expired in the meantime. When you ask us to delete data and there is no reason obliging us to keep it — a legal obligation, or the need to defend ourselves against a complaint, as with the prescription values — we delete it without undue delay. Backups are overwritten on their normal cycle, and deleted data disappears from them at the next rotation.
8. Automated decisions and fraud-risk analysis
We do not profile you for marketing purposes and we take no automated decisions with legal or similarly significant effects on you. There is, however, one automated processing operation you should know about, because it touches every order placed on the site.
Shopify analyses the fraud risk of the order automatically. When you place an order, the platform compares it against the fraud patterns it knows and assigns it a risk indicator — typically low, medium or high — together with a few signals that explain the indicator: whether the delivery address matches the billing address, whether other orders have come from the same device or the same IP address, whether payment was attempted several times, what the card processor says about the transaction. The analysis happens inside the platform, automatically, without any involvement from us.
The basis is art. 6(1)(f) GDPR — our legitimate interest in preventing fraud and in not cutting lenses paid for with a stolen card. Recital (47) GDPR expressly recognises fraud prevention as a legitimate interest.
The indicator decides nothing on its own. We do not cancel or refuse an order merely because the platform flagged it. A person at the atelier looks at the order, calls you if something is unclear, and decides. If we do choose not to carry out an order for this reason, we tell you, we refund you if payment was taken, and you can ask us to look at it again by writing to office@lentilo.ro. Because the final decision is taken by a person, we are not in the situation governed by art. 22 GDPR — but we give you the same safeguards anyway: human intervention, the right to express your point of view, and the right to contest the outcome.
The risk indicator and the signals behind it stay in the order file and are used for nothing else. We do not build a profile of you from them, we pass them to no one, and we do not use them to refuse your future orders automatically.
9. Your rights
The GDPR gives you a set of rights you can exercise at any time, free of charge and without having to justify yourself:
- Right of access (art. 15) — you can find out whether we process data about you and receive a copy of it, together with an explanation of the purposes, recipients and retention periods.
- Right to rectification (art. 16) — if a prescription value, an address or a name is wrong or incomplete, we correct and complete it straight away. If you catch us before cutting, we correct the work too.
- Right to erasure (art. 17) — we delete your data when we no longer need it, when you withdraw your consent, or when you successfully object to the processing. What we cannot delete are the invoices and documents the law obliges us to keep, and the values we cut the lenses to: those we hold on the basis of art. 9(2)(f) GDPR, for the duration of the guarantee and the limitation period, on the terms explained in section 3.
- Right to restriction of processing (art. 18) — if you contest the accuracy of the data or the lawfulness of the processing, we can freeze the data: we keep it but stop using it until the matter is clarified.
- Right to data portability (art. 20) — the data you provided to us and that we process by automated means, on the basis of the contract or of your consent, we give you in a structured, commonly used, machine-readable format, or transmit it directly to another controller where technically feasible.
- Right to object (art. 21) — you can object at any time to processing based on our legitimate interest, setting out the grounds relating to your situation. If you object to direct marketing, we stop immediately, unconditionally and without asking for reasons.
- Right to withdraw consent (art. 7(3)) — at any time and as easily as you gave it: the unsubscribe link in every marketing email, the "Cookie settings" button in the footer of every page, or a message to office@lentilo.ro. When you change your choice in the banner, the new setting is passed to Shopify straight away, and the platform actually stops the cookies you refused. Withdrawal does not affect the lawfulness of processing carried out beforehand. Withdrawing from the contract is a different thing from withdrawing consent: for that you have the "Withdraw from your contract" function, also in the footer of every page.
- Right not to be subject to automated decision-making (art. 22) — you cannot be subjected to a decision based solely on automated processing that produces legal effects or similarly significant effects on you.
We do not carry out automated decision-making with legal or similarly significant effects, and we do not profile you. The price shown on the site is not calculated from anything about you, only from the type of work and the frame brand, and every order is checked and confirmed by a person at the atelier once they have seen the frame. The only automated processing that touches your order is the platform's fraud-risk analysis, described in section 8, and there too the decision is taken by a person.
Whenever we rectify, erase or restrict data, we notify each recipient we disclosed it to, unless that proves impossible or involves disproportionate effort, and we tell you who those recipients are if you ask (art. 19).
How to exercise your rights. Write to office@lentilo.ro, call 0721 864 095, or send a written request to our registered office. Tell us which right you want to exercise and, if you can, which order it concerns — it helps us find the data faster. We reply within one month of receiving your request. If the request is complex, or we have several requests in hand, we may extend that period by up to two further months, but we will tell you within the first month and explain why. Exercising your rights is free; only if a request is manifestly unfounded or excessive, in particular because it is repetitive, may we charge a reasonable fee or refuse to act, giving reasons (art. 12(5)). If we have reasonable doubts about the identity of the person making the request, we may ask for additional information — not to make life difficult, but so that we do not hand your data to someone else (art. 12(6)).
10. Your right to complain
If you are unhappy with the way we handle your data, write to us first: most of the time it is sorted out in an exchange of messages. You are not obliged to come to us, though. You can go straight to the supervisory authority at any time:
- Authority
- National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Address
- Bd. G-ral Gheorghe Magheru nr. 28-30, Sector 1, Bucharest, Romania
- Website
- www.dataprotection.ro
You also have the right to an effective judicial remedy against the supervisory authority (art. 78) and against us as controller (art. 79), as well as the right to claim compensation for any material or non-material damage suffered (art. 82). These rights are independent: you can exercise them even if you have already complained to ANSPDCP.
For disagreements about your order rather than your data, alternative dispute resolution is also available under Government Ordinance no. 38/2015: the ANPC alternative dispute resolution platform.
11. Security
Our measures match the real risk of a small atelier handling personal objects. Here is exactly what we do:
- Encrypted connection. The whole site, including the checkout, runs over HTTPS/TLS, so what you type does not travel in the clear.
- No card data with us. Your card number and security code go straight to Shopify Payments; we do not store them, do not see them and cannot retrieve them.
- The prescription does not sit on the site. There is no file upload field and no field for dioptres, so your document and the values on it never reach the server and never reach Shopify. They stay in the atelier's mailbox or in the WhatsApp conversation, which only the people working on orders can open.
- Limited access. Only the people actually working on your order reach the order file — whoever takes the order, whoever cuts and fits the lenses, whoever issues the invoice. Accounts are individual and password-protected.
- Minimisation. Each partner receives strictly what it needs: the courier, an address and a phone number; the accountant, an invoice. The prescription stays in the atelier.
- Physical care for your frame. Frames we receive are kept at the atelier, packed and identified by an order number rather than by a visible note carrying your personal details.
- Backups of order data and correspondence, so that a technical failure does not mean lost information.
- Confidentiality undertaken by anyone with access to the data, whether employee or collaborator.
We will not promise the impossible. No technical measure offers absolute security, and sending data over the internet always carries a residual risk. We hold no security certifications and we do not claim to. What we can promise is that if a personal data breach occurs which is likely to affect your rights, we notify ANSPDCP within 72 hours of becoming aware of it (art. 33) and tell you directly, in plain words, if the risk to you is high (art. 34).
12. Children
Our service is not aimed at children. The website is intended for people aged at least 16, and we do not knowingly collect data from children below that age on the basis of their own consent.
That does not mean we do not work on children's glasses — we often do. In those cases the order is placed by the parent or legal guardian, who sends us the wearer's prescription and the other data we need and is responsible for its accuracy. By sending the prescription, that adult also gives the explicit consent for processing the child's health data. The contract is concluded with the adult, and communication, payment and delivery all happen with them.
If we learn that we have received a child's data without a parent or guardian being involved, we delete it without delay. If you are a parent and believe this has happened, write to office@lentilo.ro and we will sort it out immediately.
13. Cookies
The banner has four categories. The first is the strictly necessary one, without which the site would not work — Shopify's cart and checkout session, plus your cookie choice, which the site keeps in your browser under the name lentilo-consent; that is, in fact, the only value the site itself writes into your browser. This category is locked on. The other three are optional and you can accept or refuse each separately: analytics, preferences — this is where Shopify's own shopify_override_user_locale cookie belongs, the one that remembers the language you picked so you do not have to choose it on every visit; the language is no longer remembered by the site, but by the platform — and marketing. All three are set only after you accept them in the banner, as required by art. 4(5) of Law no. 506/2004 and art. 6(1)(a) GDPR. Nothing is pre-ticked.
Your choice is passed to Shopify through the platform's own consent interface, and it is the platform that actually holds back the cookies in the categories you refused — the banner is not an ornament. You can accept everything, refuse everything, or choose by category, and you can change your mind at any time using the "Cookie settings" button in the footer of every page. Refusing does not block your access to the site and has no effect on your order.
The full list of cookies, with the role and lifespan of each, is in our Cookie Policy.
14. Changes to this policy and contact
We may update this policy when the law, our services or the partners we work with change. The version in force is always the one published on this page, and the date of the last update appears at the top. If we change something significant — a new purpose, a new legal basis, a new category of recipients or a longer retention period — we will say so visibly on the site before the change takes effect, and where the processing relies on consent, we will ask for your agreement again. We do not use a policy update as a quiet way of doing something you agreed to for a different reason.
For any question about your data, about this policy, or to exercise your rights, write to us — you will get an answer from the people at the atelier, not from an automated form:
- Controller
- OKRALIS S.R.L., CUI 51286544, J2025010018003
- office@lentilo.ro
- Phone
- 0721 864 095
- wa.me/40721864095
- Atelier
- Strada Sfânta Maria 47, Bucharest
- Registered office
- Șos. Giurgiului nr. 277–279, Sector 4, Bucharest
- Opening hours
- Monday–Friday, 9:00–18:00