Skip to content
Personal data · GDPR · WhatsApp

Privacy Policy

What data we use, why it is needed, who may receive it and how you can exercise your rights.

Public documentUpdated 26 August 2026English translation
English translation

This English text is a faithful translation of the Romanian document. It does not limit mandatory rights under applicable law.

Controller and scope

EGO INDUSTRIAL GAS S.R.L., trading as EGO Refrigerants / EgoLog, controls personal data processed through egolog.ro, orders, customer support and the official WhatsApp Business channel. This policy covers visitors, quotation requests, customers and people who communicate with us. Provide another person's data only when authorised.

Data we may process

We may process buyer category, purchase purpose, name, company, email, phone, billing and delivery addresses, business tax identifiers, order and invoice data, payment status, buyer declaration details and fingerprint, VIES results, acceptance records and, for declared technical use, the certificate or attestation holder's name, number and issuing country. We may also process WhatsApp profile and messages, message identifiers, delivery status and security logs. Checkout does not request or store CNP, a certificate copy, the issuing authority or expiry date. Full card data is processed directly by the payment provider and is not stored by EgoLog. Browser local storage keeps language, cart and checkout draft data on the user's device.

Purposes and legal bases

Quotation, ordering, payment, delivery and support rely on pre-contractual steps and contract performance under Article 6(1)(b) GDPR. Invoicing and accounting rely on legal obligations under Article 6(1)(c). Security, fraud prevention and legal defence rely on legitimate interests under Article 6(1)(f), after considering individual impact. Optional activities use separate, informed and withdrawable consent under Article 6(1)(a). Writing to us on WhatsApp is not automatically treated as GDPR consent.

WhatsApp Business and AI assistance

WhatsApp Business Platform / Cloud API message content and associated technical data are used to receive and answer requests and keep the necessary history. When automation or AI is enabled, messages may be classified and replies may be generated or prepared by an AI system; users are informed in the conversation by the first interaction at the latest. A human operator may be requested. Customer support does not make decisions based solely on automated processing that produce legal or similarly significant effects.

Recipients and international transfers

Data is shared only as necessary with the applicable WhatsApp and Meta entities, payment processor, invoicing provider when enabled, carriers, an activated contractual container return/refill partner, hosting and IT providers, and automation or AI providers when those functions are enabled. Public authorities receive data only where legally required. Transfers outside the EEA require a documented GDPR mechanism such as an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses with supplementary measures where needed. We do not sell or rent personal data.

Retention

Support and WhatsApp data are kept for the request and only as long afterwards as justified for continuity, complaints or legal defence. Security logs are kept as needed to prevent and investigate incidents. Accounting records are generally retained for five years calculated from 1 July of the year following the relevant financial year, unless a special rule applies. Buyer declarations and orders follow applicable contractual, accounting and legal periods; rejected or abandoned requests are generally kept no longer than 90 days unless litigation, fraud prevention or law requires more.

Your rights

Subject to GDPR conditions, you may request access, correction, deletion, restriction, portability or object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting earlier lawful processing. Send requests to [email protected]. We respond without undue delay and within one month; complex or numerous requests may extend this by up to two months, with notice and reasons during the first month.

Security, complaints and updates

We use risk-proportionate technical and organisational measures including HTTPS, access control and non-public operational storage. No method guarantees absolute security; incidents are investigated and handled under legal duties. Complaints may be filed with the Romanian data protection authority, ANSPDCP, at dataprotection.ro, without affecting court remedies. This policy may be updated when services, providers or law change.

Want to know what data we hold or submit a GDPR request?

[email protected]