1. Introduction
This Privacy Policy explains how Global Fix IT collects, uses, stores, discloses and protects personal data when you visit https://globalfixit.com/ or interact with our online services.
Where applicable, processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR) and applicable data protection legislation.
2. Who Is the Controller
Cosmio Computers Shop & Services SRL, operating under the Global Fix IT brand.
- Registered office
- Str. Pechea 20, Sector 1, Bucharest, Romania
- Tax/VAT ID
- RO48614897
- General email
- [email protected]
- Privacy email
- [email protected]
- Data Protection Officer
- Not appointed
3. What Data We May Collect
Depending on how you interact with the website, we may collect:
- first and last name
- job title and company
- email address
- telephone number
- professional contact details
- information entered into forms
- the content of enquiries and communications
- information required for quotations and contracting
- technical data such as IP address, browser, operating system and device type
- information about website usage
- identifiers from cookies and similar technologies
- marketing preferences
- information required for security and abuse prevention
We do not intentionally request special categories of personal data unless there is a specific legitimate need and an appropriate legal basis and collection mechanism.
4. How We Obtain Data
Data may be obtained:
- directly from you
- automatically through your use of the website
- from our service providers
- from partners, where legally permitted
- from public sources, particularly in B2B contexts, where use is permitted by law
5. Purposes of Processing
We may process data for:
- responding to enquiries
- preparing quotations
- entering into and performing contracts
- providing services
- technical support
- communicating with customers
- website and systems security
- fraud and abuse prevention
- managing business relationships
- invoicing and compliance with legal obligations
- website performance analysis
- marketing, where the required legal basis exists
- improving our services
- handling data protection requests
6. Legal Basis
Where GDPR applies, we may rely on the following legal bases:
Performance of a Contract
For providing services or taking steps requested before entering into a contract.
Legal Obligation
For complying with tax, accounting, legal or regulatory obligations.
Legitimate Interests
For security, business administration, fraud prevention, service improvement, certain B2B communications and protection of our rights, where our legitimate interests are not overridden by your interests, rights or freedoms.
Consent
For activities where the law requires consent, including certain cookies, marketing technologies or commercial communications. Consent may be withdrawn at any time.
7. Contact Forms
Information submitted through forms is used to respond to the request and, where applicable, prepare a quotation or continue a business relationship. Our forms request only the data that is necessary for this purpose.
8. Marketing
Where we send marketing communications, we use the appropriate legal basis, and every marketing message provides a simple unsubscribe mechanism.
You may request that commercial communications stop at any time by contacting [email protected].
9. Analytics and Tracking Technologies
This website uses Google Tag Manager to load measurement tags and Google Analytics 4 to understand how the site is used. No advertising or profiling technologies are used.
Google Analytics is provided by Google Ireland Limited:
- Purpose
- Website traffic analysis, usage statistics, performance measurement and understanding how visitors interact with the website.
- Processing locations
- The European Economic Area and other countries or regions where Google and its service providers process data, as applicable.
- Privacy information
- https://policies.google.com/privacy
Analytics run under Google Consent Mode. Until you accept analytics in the consent banner, analytics and advertising storage stay denied: no analytics cookies are written and measurement hits are sent without identifiers. You can change or withdraw your choice at any time through the banner.
If we introduce another analytics or marketing tool, this section will be updated to name the provider, the purpose, the processing locations and the provider's own privacy information.
10. Cookies and Local Storage
We use what is necessary to operate the website and remember your own choices, together with analytics cookies once you allow them. No advertising or profiling technologies are used.
- gfi-country (cookie)
- Stores the two-letter country code supplied by our hosting provider so the site can open in the language of your region. Expires after 30 days.
- gfi-lang (local storage)
- Stores the language you select in the language switcher so your choice is respected on your next visit. Kept in your browser until you clear it.
- _ga and _ga_* (cookies)
- Set by Google Analytics, and only once you accept analytics in the consent banner, to distinguish visitors and sessions. Both expire after two years.
- Consent banner cookie
- Set by our consent provider to remember the choice you made in the banner, so you are not asked again on every page.
You can delete these at any time through your browser settings, and you can withdraw consent for analytics through the consent banner. Deleting the language entries simply returns the site to automatic language selection.
11. Service Providers and Processors
We may use providers for:
- hosting
- cloud services
- CDN and security
- CRM
- support
- forms
- analytics
- marketing
- payments
- AI
- other services necessary to operate the company
Providers act on our instructions under a data processing agreement where GDPR requires one. An up-to-date list is maintained internally and is available on request.
12. AI and Automated Services
If Global Fix IT uses AI tools to process data submitted through the website or as part of our services, we will assess:
- the purpose
- categories of data
- provider
- processing location
- retention period
- international transfers
- security measures
- whether profiling or relevant automated decision-making is involved
We will not use personal data for an incompatible purpose without an appropriate legal basis.
13. International Transfers
Global Fix IT may use providers or infrastructure located outside the European Economic Area.
Where GDPR applies, international transfers rely on an appropriate legal mechanism, such as an adequacy decision, Standard Contractual Clauses approved by the European Commission, or another safeguard provided by the GDPR.
The protection provided by the GDPR continues to apply to data transferred to third countries.
14. How Long We Keep Data
Data is kept only for as long as necessary for the purpose for which it was collected, subject to legal obligations.
- Website enquiries
- For as long as necessary to respond to and manage the enquiry, then deleted or archived unless a longer period is required for legal or contractual purposes.
- Customers and contracts
- For the duration of the business relationship and thereafter for as long as necessary to establish, exercise or defend legal claims and comply with applicable legal obligations.
- Accounting and invoicing
- For the period required by applicable tax and accounting legislation.
- Marketing
- Until consent is withdrawn or an objection is made, unless another lawful retention period applies.
- Support
- For as long as necessary to resolve and document the support matter, subject to applicable legal or contractual requirements.
- Security logs
- For a period proportionate to security, fraud-prevention and incident-response needs, subject to applicable law.
- Consent records
- For as long as necessary to demonstrate the lawfulness of the consent and to comply with applicable legal requirements.
15. Data Security
We implement appropriate technical and organizational measures to reduce the risk of unauthorized access, loss, alteration or disclosure.
Measures may include access controls, strong authentication, encryption, backups, monitoring, security updates and internal policies.
16. Your Rights
Where GDPR applies, you may have the right to:
- be informed
- access your data
- rectification
- erasure
- restriction of processing
- object
- data portability
- withdraw consent
- object to direct marketing
- rights relating to certain forms of profiling and automated decision-making
17. How to Exercise Your Rights
Send your request to [email protected], using the subject line "Data Protection Request".
We may request reasonable information to verify your identity.
18. Complaints
If you have concerns about the processing of your data, we encourage you to contact us first. You also have the right to lodge a complaint with the competent supervisory authority.
For Romania, this is the National Supervisory Authority for Personal Data Processing (ANSPDCP). Its contact details are: Bd. Gheorghe Magheru 28-30, Bucharest, Romania; website: https://www.dataprotection.ro/.
19. Children and Minors
The website is not intentionally directed at children, unless a specific page expressly states otherwise.
20. External Links
The website may contain links to external websites. We do not control their privacy policies.
21. Changes to This Policy
We may update this Policy when services, technologies, providers or legal obligations change. The current version is always published on the website.
