Privacy Policy

Privacy Policy on the Processing of Personal Data

We consider ensuring the right to personal data protection as a fundamental commitment of SPEARHEAD COFFEE SRL. Therefore, we will dedicate all necessary resources and efforts to process your data in full compliance with Regulation (EU) 2016/679 (the "General Data Protection Regulation" or "GDPR"), as well as any other applicable legislation in Romania. Since transparency is one of the essential principles of this legal framework, we have prepared this document to inform you about how we collect, use, transfer, and protect your personal data when you interact with us regarding our products and services, including through our website or mobile applications.

We reserve the right to periodically update and modify this Privacy Policy to reflect any changes in how we process your personal data or any changes in legal requirements. In the event of any such changes, we will display the modified version of the Privacy Policy on our website, so please check the content of this Privacy Policy periodically.

Who We Are and How to Contact Us

SPEARHEAD COFFEE SRL is the trade name of SPEARHEAD COFFEE SRL, a legal entity of Romanian nationality, with its place of business at STR. COPILULUI, NR. 16, ET. 2, SECT. 1, BUCHAREST, BUCHAREST COUNTY, registered in the Trade Register under number J23/3470/2023 (hereinafter referred to as "SPEARHEAD COFFEE SRL" or "we"). In terms of data protection legislation, we act as the data controller when processing your personal data.

As we are always open to hearing your opinions and providing any additional information you might need regarding the processing of your data, we encourage you to contact the SPEARHEAD COFFEE SRL Data Protection Officer at the email address comenzi@spearhead.coffee or by mail or courier at the address STR. COPILULUI, NR. 16, 2nd FLOOR, DISTRICT 1, BUCHAREST, BUCHAREST COUNTY, with the mention: to the attention of the SPEARHEAD COFFEE SRL Data Protection Officer.

Categories of Personal Data We Process

In general, we collect your personal data directly from you, allowing you to control the type of information you provide us. For example, we receive information from you as follows:

When you create an account with SPEARHEAD COFFEE SRL, you provide us with: your email address, first and last name.

Within your personal page (My Account) on the SPEARHEAD COFFEE SRL platform, you can add additional information, such as: photo, gender, nickname, mobile phone number, landline number, date of birth, education level, delivery addresses, alternative email address, bank card details, etc.

When you place an order, you provide us with information such as: the desired product, first and last name, delivery address, billing details, payment method, phone number, bank card details, etc.

We also offer you the option to register on the SPEARHEAD COFFEE SRL platform through your Facebook or Google account. If you choose one of these options, you will be redirected to a page managed by Facebook Inc. or Google LLC, where they will inform you about the transfer of your data to SPEARHEAD COFFEE SRL. You can review the Facebook and Google privacy policies using the following links:

https://www.facebook.com/about/privacy 

https://policies.google.com/privacy

We may also collect and process certain information about your behavior while visiting our website or using the smartphone application, to personalize your online experience and provide you with offers tailored to your profile. We invite you to learn more about this by consulting the section on the purposes of processing below.

On our website and in the smartphone application, we may store and collect information through cookies and similar technologies, in accordance with our Cookie Policy.

We do not collect or otherwise process sensitive data, as defined by the General Data Protection Regulation in special categories of personal data. Additionally, we do not wish to collect or process data from minors under the age of 16.

Purposes and Legal Grounds for Processing

We will use your personal data for the following purposes:

  1. To Provide SPEARHEAD COFFEE SRL Services to You

This general purpose may include, as appropriate, the following:

  1. Creating and managing your account on the SPEARHEAD COFFEE SRL platform;
  2. Processing orders, including receiving, validating, shipping, and billing them;
  3. Resolving cancellations or issues of any kind related to an order, goods, or services purchased;
  4. Returning products in accordance with legal provisions;
  5. Refunding the value of the products in accordance with legal provisions;
  6. Providing support services, including responding to your questions regarding your orders or SPEARHEAD COFFEE SRL goods and services or those of SPEARHEAD COFFEE SRL partners.

The processing of your data for these purposes is, in most cases, necessary for the conclusion and execution of a contract between SPEARHEAD COFFEE SRL and you. Additionally, certain processing activities related to these purposes are required by applicable legislation, including tax and accounting laws.

  1. To Improve Our Services

We constantly aim to offer you the best online shopping experience. For this, we may collect and use certain information regarding your purchasing behavior, invite you to complete satisfaction surveys after completing an order, or conduct market studies and research, either directly or with the help of partners.

We base these activities on our legitimate interest in conducting commercial activities, always ensuring that your fundamental rights and freedoms are not affected.

  1. For Marketing Purposes

We want to keep you updated on the best offers for products/services that interest you. In this regard, we may send you, on behalf of SPEARHEAD COFFEE SRL or any company within the SPEARHEAD COFFEE SRL Group, any type of message (such as email/SMS/phone/mobile push/web push/etc.) containing general and thematic information, information about similar or complementary products to those you have purchased, information about offers or promotions, information about products added in the "Account/My Cart" section or the "Account/Favorites" section, or products you have shown interest in purchasing, as well as other commercial communications such as market research and opinion surveys. We can also display personalized recommendations on the website and in the smartphone application. To provide you with information of interest, we may use certain data regarding your shopping behavior (e.g., products viewed/added to wishlist/purchased) to create a profile. We always ensure that these processes are carried out in compliance with your rights and freedoms and that decisions based on them do not have legal effects on you and do not similarly affect you in a significant manner.

In most cases, we base our marketing communications on your prior consent. You can change your mind and withdraw your consent at any time by:

  • Modifying the settings in your customer account;
  • Contacting SPEARHEAD COFFEE SRL using the contact details described above.

In certain situations, we may base our marketing activities on our legitimate interest in promoting and developing our commercial activities. In any situation where we use information about you for our legitimate interest, we take care and take all necessary measures to ensure that your fundamental rights and freedoms are not affected. Nevertheless, you can request at any time, through the means described above, that we stop processing your personal data for marketing purposes, and we will comply with your request.

  1. To Defend Our Legitimate Interests

There may be situations where we use or transmit information to protect our rights and commercial activities. These may include:

  • Measures to protect the website and users of the SPEARHEAD COFFEE SRL platform against cyber-attacks;
  • Measures to prevent and detect fraud attempts, including transmitting information to competent public authorities;
  • Measures to manage various other risks.

The general basis for these types of processing is our legitimate interest in defending our commercial activities, ensuring that all the measures we take guarantee a balance between our interests and your fundamental rights and freedoms.

Additionally, in certain cases, we base our processing on legal provisions, such as the obligation to secure goods and values as provided by the applicable legislation in this matter.

    5. For Recording Telephone Conversations with SPEARHEAD COFFEE SRL Representatives

When you interact with SPEARHEAD COFFEE SRL representatives via telephone, these conversations will be recorded to analyze the quality of our services and your level of satisfaction, with the aim of improving them. You will be informed of this before the call begins, and if you continue the call, we will consider that you have given your consent for the recording. If you do not agree with the recording of the telephone call, you can contact us through other dedicated channels mentioned in the Contact section available here.                                           

You can withdraw your consent at any time during or after the call. However, the withdrawal of consent will not affect the processing already carried out based on your consent, including the recording already made. Additionally, it is possible that the personal data thus recorded will continue to be retained based on legitimate interest or a legal obligation.

Furthermore, please note that to avoid repeated notifications about call recording and repeated requests for your consent for this processing activity ("information fatigue" / "consent fatigue"), for calls made less than 24 hours apart, we will consider the notification about the recording activity and the request for consent made during the first call.

The processing activities in this section are based on your consent for call recording, expressed by you through the continuation of the call. Additionally, the data thus collected will also be processed based on legitimate interest when we consider purposes such as verifying and improving the quality of services provided, measuring the performance of our agents, identifying fraud situations, transcribing and implementing statistical and mathematical models for such analyses.

How Long We Retain Your Personal Data

As a general rule, we will store your personal data as long as you have an account on the SPEARHEAD COFFEE SRL platform. You can request the deletion of certain information or the closure of your account at any time, and we will comply with these requests, subject to retaining certain information even after the account is closed, in situations where applicable law or our legitimate interests require it.

To Whom We Transmit Your Personal Data

Depending on the case, we may transmit or provide access to certain personal data to the following categories of recipients:

  • Companies within the same group as SPEARHEAD COFFEE SRL;
  • SPEARHEAD COFFEE SRL partners;
  • Courier service providers;
  • Payment/banking service providers;
  • Marketing/telemarketing service providers;
  • Market research service providers;
  • IT service providers;
  • Other companies with which we can develop joint programs to market our goods and services.

If we have a legal obligation or if it is necessary to defend a legitimate interest, we may also disclose certain personal data to public authorities.

We ensure that access to your data by third-party private legal entities is carried out in accordance with legal data protection and confidentiality provisions, based on contracts concluded with them.

In Which Countries We Transfer Your Personal Data

As a general rule, your personal data is stored and processed within the European Union and the European Economic Area (EEA).

If your personal data is transferred outside the European Union or EEA, the transfer will be made:

(a) based on a decision of the European Commission that the third country in question ensures an adequate level of protection,

(b) based on binding corporate rules, or 

(c) based on standard contractual clauses adopted by the European Commission. 

Additionally, if we identify that one of these measures is not sufficient to ensure an adequate level of protection, we will adopt additional technical and/or organizational security measures in accordance with the European Commission's recommendations..

You can contact us at any time, using the contact details provided above, to find out more information about the countries to which we transfer your data, as well as the safeguards we have implemented for these transfers.

How We Protect the Security of Your Personal Data

We are committed to ensuring the security of personal data by implementing appropriate technical and organizational measures, according to industry standards.

Your personal data is transmitted using state-of-the-art encryption algorithms and stored on secure servers, ensuring data redundancy.

For payments, we use the services of the payment processor INGPOS. Any payment information is encrypted using HTTPS technology with TSL 1.2 encryption.

Despite the measures taken to protect your personal data, we draw your attention to the fact that transmitting information over the Internet, in general, or through other public networks, is not completely secure, and there is a risk that data may be seen and used by unauthorized third parties. We cannot be responsible for such vulnerabilities in systems that are not under our control.

What Rights You Have

The General Data Protection Regulation recognizes several rights you have regarding your personal data. You can request access to your data, correction of any errors in our records, and/or object to the processing of your personal data. Additionally, you can exercise your right to lodge a complaint with the competent supervisory authority or seek judicial remedies. Depending on the case, you may also benefit from the right to request the deletion of your personal data, the right to restrict the processing of your data, and the right to data portability.

More information about each of these rights can be obtained by consulting the table below.

To exercise your rights, you can contact us using the contact details provided above. Please note the following aspects if you wish to exercise these rights:

Identity. We take the confidentiality of all records containing personal data seriously. For this reason, please send your requests regarding such records using the email address associated with your SPEARHEAD COFFEE SRL account. Otherwise, we reserve the right to verify your identity by requesting additional information aimed at confirming your identity.

Fees. We will not charge a fee to exercise any of your rights concerning your personal data unless your request for access to information is unfounded, repetitive, or excessive, in which case we will charge a reasonable amount in such circumstances. We will inform you of any applicable fees before processing your request.

Response Time. We aim to respond to any valid requests within a maximum of one month unless this is particularly complicated or if you have made several requests, in which case we will respond within a maximum of two months. We will notify you if we need more than one month. We may ask you if you can specify what exactly you want to receive or what specifically concerns you. This will help us act faster and shorten the response time to your request.

Third-Party Rights. We are not required to comply with a request if it would adversely affect the rights and freedoms of other data subjects.

Data Subject Rights
Access

You can ask us to:

- Confirm whether we are processing your personal data;

- Provide you with a copy of these data;

- Provide you with other information about your personal data, such as what data we have, what we use it for, to whom we disclose it, whether we transfer it abroad and how we protect it, how long we retain it, what rights you have, how you can make a complaint, and where we obtained your data from, to the extent that this information has not already been provided to you through this notice.

Rectification

You can ask us to rectify or complete your inaccurate or incomplete personal data.

We may try to verify the accuracy of the data before rectifying it.

Data Deletion

You can ask us to delete your personal data, but only if:

- They are no longer necessary for the purposes for which they were collected; or

- You have withdrawn your consent (where the data processing was based on consent); or

- You exercise your legal right to object; or

- They have been processed unlawfully; or

- We have a legal obligation to do so.

We are not obligated to comply with your request to delete your personal data if the processing of your personal data is necessary:

- For compliance with a legal obligation; or

- For the establishment, exercise, or defense of legal claims.

There are certain other circumstances in which we are not required to comply with your request for data deletion, although these two are the most likely circumstances under which we could refuse this request.

Please note that:

- Before exercising this right, you should save all documents related to orders placed with SPEARHEAD COFFEE SRL from your SPEARHEAD COFFEE SRL account, regardless of whether the billing was done to you or another individual or legal entity (such as invoices, etc.). If you do not take this step before exercising your right to deletion, you will lose all these documents, and SPEARHEAD COFFEE SRL will be unable to provide them to you, as the data deletion process, including the deletion of the SPEARHEAD COFFEE SRL account with all associated data and documents, is irreversible.

Restriction of Data Processing
You can ask us to restrict the processing of your personal data, but only if:

- Their accuracy is contested (see the rectification section), to allow us to verify their accuracy; or

- The processing is unlawful, but you do not want the data to be deleted; or

- They are no longer necessary for the purposes for which they were collected, but you need them to establish, exercise, or defend a legal claim; or

- You have exercised your right to object, and the verification of whether our rights override yours is ongoing.

We may continue to use your personal data following a request for restriction if:

- We have your consent; or

- To establish, exercise, or defend a legal claim; or

- To protect the rights of SPEARHEAD COFFEE SRL or another natural or legal person.

Data Portability

You can ask us to provide your personal data in a structured, commonly used, and machine-readable format, or you can request that it be "ported" directly to another data controller, but in each case only if:

- The processing is based on your consent or on the conclusion or performance of a contract with you; and

- The processing is carried out by automated means.

Objection
You can object at any time, on grounds relating to your particular situation, to the processing of your personal data based on our legitimate interest if you believe that your fundamental rights and freedoms override this interest.
You can also object at any time to the processing of your data for direct marketing purposes (including profiling) without providing any reason, in which case we will cease this processing as soon as possible.
Automated Decision Making

You can request not to be subject to a decision based solely on automated processing, but only when that decision:

- Produces legal effects concerning you; or

- Otherwise significantly affects you in a similar manner.

This right does not apply if the decision reached through automated decision-making:

• Is necessary to enter into or perform a contract with you;

• Is authorized by law and there are adequate safeguards for your rights and freedoms; or

• Is based on your explicit consent.

Complaints

You have the right to lodge a complaint with the supervisory authority regarding the processing of your personal data. In Romania, the contact details of the data protection supervisory authority are as follows:

National Supervisory Authority for Personal Data Processing

28-30 Gheorghe Magheru Blvd, District 1, Postal Code 010336, Bucharest, Romania

Phone: +40.318.059.211 or +40.318.059.212

E-mail: anspdcp@dataprotection.ro

Without affecting your right to contact the supervisory authority at any time, please contact us first, and we promise to make every effort to resolve any issue amicably.

Reminder

Please remember that you can contact the SPEARHEAD COFFEE SRL Data Protection Officer at any time by submitting your request through any of the following methods:

- By e-mail at: comenzi@spearhead.coffee

- By mail or courier to the address: STR. COPILULUI, NR. 16, 2nd Floor, DISTRICT 1, BUCHAREST, BUCHAREST COUNTY – with the mention: to the attention of the SPEARHEAD COFFEE SRL Data Protection Officer.

Shopping Basket