Zan Perrion
Ars Amorata International S.R.L.
Effective 09-02-2026
1.1 The controller of personal data collected through this website is Ars Amorata International S.R.L., a company incorporated under the laws of Romania, having its registered office at Calea Moșilor 88, Sector 3, Bucharest, registered with the Trade Register under number J2023024518405 and having sole registration code (CUI) 49314839 (the "Controller", "we", "us" or "our").
1.2 Enquiries concerning this Notice or the processing of personal data may be addressed to the Controller at info@arsamorata.com.
1.3 Mr Sorin Dinca has been appointed as representative pursuant to Article 27 of Regulation (EU) 2016/679 and may be contacted at Calea Moșilor 88, Sector 3, Bucharest or info@arsamorata.com. Data subjects may address the representative on all matters relating to the processing of their personal data, in addition to or instead of the Controller.
2.1 This Notice applies to personal data processed by the Controller in connection with the website located at zanperrion.com (the "Site"), applications submitted through the Site, correspondence with the Controller, and the provision of the services described on the Site (the "Services").
2.2 This Notice does not apply to third-party websites accessible by hyperlink from the Site, which are governed by the privacy policies of their respective operators.
3.1 Applications. Where a data subject submits an application through the Site, the Controller processes the name, electronic mail address, age, place of residence, occupation and any information voluntarily supplied by the data subject concerning the matter in respect of which the Services are sought. The legal basis is Article 6(1)(b) of Regulation (EU) 2016/679, being the taking of steps at the request of the data subject prior to entering into a contract. Such data are retained for 12 months following submission, save where a contractual relationship results, in which case clause 3.4 applies.
3.2 Special categories. Information voluntarily supplied by a data subject in the course of an application or engagement may, depending upon its content, constitute a special category of personal data within the meaning of Article 9(1). Where this occurs, processing is carried out on the basis of the data subject's explicit consent pursuant to Article 9(2)(a), such consent being given by the voluntary act of supplying the information for the purpose of obtaining the Services. Data subjects are advised to disclose no more than is necessary for that purpose.
3.3 Correspondence. Electronic mail and messaging correspondence is processed for the purposes of responding to enquiries and maintaining records of the Controller's dealings. The legal basis is Article 6(1)(f), the legitimate interests of the Controller in conducting its business and maintaining accurate records, such interests having been balanced against the rights and freedoms of the data subject.
3.4 Client records. Where a contract for the Services is concluded, the Controller processes contact details, correspondence, engagement records and payment information for the purposes of performing that contract and complying with accounting and fiscal obligations. The legal bases are Article 6(1)(b) and Article 6(1)(c). Such records are retained for the period required by applicable Romanian accounting and fiscal legislation, being 10 years from the end of the financial year to which they relate.
3.5 Electronic communications. Where a data subject subscribes to receive periodic written communications, the Controller processes the electronic mail address supplied for that purpose. The legal basis is Article 6(1)(a), consent, which may be withdrawn at any time in accordance with clause 7.1(g). Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. Such data are retained until consent is withdrawn or until 12 months has elapsed without engagement, whichever occurs first.
3.6 Technical data. The Site and its hosting provider record internet protocol addresses, browser and device characteristics, and pages accessed. The legal basis is Article 6(1)(f), the legitimate interests of the Controller in the security and proper functioning of the Site. Cookies and equivalent technologies are addressed in the Cookie Notice.
4.1 The provision of personal data through the application forms on the Site is not a statutory requirement. It is, however, a requirement necessary in order to enter into a contract for the Services, and an application cannot be assessed in its absence.
4.2 No decision producing legal effects concerning a data subject, or similarly significantly affecting a data subject, is taken by automated means. Applications are assessed personally.
5.1 Personal data are not sold, let, traded or otherwise transferred to third parties for the purposes of those parties' own marketing.
5.2 Personal data may be disclosed to the following categories of recipient, each acting as a processor upon the documented instructions of the Controller pursuant to Article 28:
5.3 Personal data may further be disclosed to competent public authorities where such disclosure is required by law.
6.1 Certain recipients identified in clause 5.2 are established outside the European Economic Area. Where personal data are transferred to a third country, such transfer is effected on the basis of an adequacy decision of the European Commission pursuant to Article 45, or on the basis of standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c), together with such supplementary measures as may be appropriate.
6.2 A copy of the safeguards relied upon may be obtained by written request to the Controller.
7.1 Subject to the conditions and exceptions provided by Regulation (EU) 2016/679, a data subject has the right:
7.2 Requests may be addressed to the Controller at info@arsamorata.com or to the representative identified at clause 1.3. The Controller shall respond without undue delay and in any event within one month of receipt, which period may be extended by two further months where necessary, taking into account the complexity and number of requests.
7.3 A data subject who considers that the processing of his personal data infringes Regulation (EU) 2016/679 has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his habitual residence, place of work or place of the alleged infringement. The competent supervisory authority in Romania is the National Supervisory Authority for Personal Data Processing (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, www.dataprotection.ro.
8.1 In addition to and without prejudice to its obligations under Regulation (EU) 2016/679, the Controller undertakes that information disclosed by a client in the course of an engagement shall not be published, quoted, attributed or otherwise disclosed to any third party, save with the express prior written consent of that client or where disclosure is required by law.
8.2 No client is identified by name upon the Site. Where material originating from a client appears upon the Site, it appears with that client's consent.
9.1 The Controller implements appropriate technical and organisational measures pursuant to Article 32 to ensure a level of security appropriate to the risk, including encryption of data in transit and restriction of access to personal data to persons requiring such access for the purposes identified in clause 3.
9.2 No method of transmission or storage is entirely secure, and the Controller does not warrant absolute security.
10.1 The Site and the Services are directed exclusively to persons aged eighteen years or over. The Controller does not knowingly process the personal data of any person below that age. Where the Controller becomes aware that such data have been supplied, they shall be erased without undue delay.
11.1 The Controller may amend this Notice from time to time. The version in force is that published upon this page, bearing the version number and effective date set out above.
11.2 Where an amendment materially affects the rights of data subjects whose electronic mail addresses are processed pursuant to clause 3.5, notice of that amendment shall be given by electronic mail.
Back · Cookie Notice · Terms