Privacy Policy 
      
    Transparency and Care for Your Privacy
At SĂCRUM, we value your privacy and are committed to full transparency in how we collect, use, and protect your personal data. This privacy policy explains how we process your data, your rights, and how we ensure their protection in compliance with applicable laws, including the General Data Protection Regulation (GDPR, EU 2016/679), Directive 2011/83/EU on Consumer Rights, and relevant local regulations.
Before We Begin:
This policy provides all the information on how we use your data, regardless of whether you interact with us via our website, email, manager, or any other method. We will also provide additional details on each type of data processing as you engage with us.
When we refer to our Platform, we mean any channel or medium through which you interact with SĂCRUM, including our website and communications with managers.
1. Who We Are and Who Is Responsible for Your Data
Data Controller:
We are a registered European company acting as the data controller. We are responsible for processing and protecting your personal data. Payments are processed through another European company with which we have an agreement ensuring GDPR compliance.
Contact Us:
If you have questions or wish to exercise your rights, please email us at info@sacrum.design.
2. What Data We Collect
Depending on how you interact with us, we may collect the following data:
- 
Identification Data: Name, address, email, phone number, tax information (if required). 
- 
Financial Information: Payment details (e.g., card information for Stripe/PayPal payments, bank details for transfers). 
- 
Order Data: Information about your order, including cover choices, sofa configuration, and delivery address. 
- 
Interaction Data: Support requests, correspondence with managers, preferences (e.g., newsletter subscriptions). 
- 
Technical Data: IP address, device type, browser data, website interactions (e.g., viewed pages). 
- 
Job Applicants: If you apply for a position, we collect your name, contact details, CV, and information about your experience, education, and other relevant details for recruitment. 
We mark mandatory fields when collecting data (e.g., for order processing). If you do not provide this data, we may be unable to process your request or provide the service.
3. Why We Use Your Data
We process your data for the following purposes:
1. Order Management and Delivery:
- 
Processing your order, including manufacturing a custom sofa, invoicing, and arranging delivery. 
- 
Responding to your inquiries via customer support (e.g., delivery timeline clarifications). 
2. Marketing and Personalization:
- 
Sending personalized offers and updates if you’ve subscribed to our newsletter (e.g., about new cover collections). 
- 
Conducting promotions (e.g., contests, special offers). 
3. Service Quality Improvement:
- 
Conducting surveys to assess customer satisfaction and identify areas for improvement. 
- 
Analyzing website interactions (without creating user profiles) to enhance its performance. 
4. Compliance with Obligations:
- 
Fulfilling legal obligations (e.g., tax or accounting requirements). 
- 
Processing requests to exercise your rights (e.g., data deletion). 
5. Job Applicants:
- 
Processing job applications, including contacting you, verifying qualifications, and arranging interviews. 
- 
Storing data for future vacancies, with your consent. 
4. Legal Basis for Processing Your Data
We process your data based on the following legal grounds:
- 
Contract Performance: To process your order, deliver your sofa, and fulfill obligations (e.g., manufacturing the agreed-upon sofa). 
- 
Consent: When you subscribe to newsletters or provide data for marketing. You can withdraw consent at any time by emailing info@sacrum.design. 
- 
Legitimate Interest: To respond to inquiries, improve the website, and prevent fraud (e.g., during payment). We conduct assessments to ensure our interests do not override your rights. 
- 
Legal Obligations: To comply with tax, accounting, or other requirements (e.g., storing transaction data). 
5. How Long We Retain Your Data
Retention periods depend on the purpose of processing:
- 
Orders: Data is retained for the duration necessary to fulfill the order, including delivery and potential claims (typically 3 years after order completion). 
- 
Marketing: Data is retained until consent is withdrawn or for 10 years if you have not unsubscribed from the newsletter. 
- 
Customer Support: Data is retained until your inquiry is resolved. 
- 
Job Applicants: Data is retained for 1 year after application submission, unless specified otherwise. 
After the retention period, data is deleted unless further retention is required to meet legal obligations (e.g., tax retention periods, which may extend up to 10 years in some jurisdictions).
6. Who We Share Your Data With
We may share your data with the following parties:
- 
Service Providers: Logistics companies, carriers, payment systems (Stripe, PayPal), IT service providers. All are located within the European Economic Area (EEA) and comply with GDPR. 
- 
Legal Authorities: If required by law (e.g., tax authorities). 
- 
Job Applicants: If you apply for a position, data may be shared for verification (e.g., with previous employers or educational institutions), but only with your consent. 
We enter into agreements with providers to ensure data security, including Standard Contractual Clauses (SCC) approved by the European Commission, if necessary.
7. Your Rights
You have the following rights regarding your data:
- 
Access: Request information about the data we hold. 
- 
Rectification: Correct inaccurate data. 
- 
Erasure: Request deletion of data if it is no longer needed for the processing purposes. 
- 
Restriction: Restrict processing in certain cases. 
- 
Portability: Receive your data in a structured format or transfer it to another controller. 
- 
Objection: Object to processing based on legitimate interest (e.g., marketing). 
- 
Withdraw Consent: Withdraw consent for processing (e.g., unsubscribe from newsletters). 
To exercise your rights, email us at info@sacrum.design. We will respond within 30 days. If we need to verify your identity, we may request a copy of an identification document.
You also have the right to lodge a complaint with the data protection authority in your country (e.g., the data protection authority in your EU country of residence).
8. Data Security
We implement technical and organizational measures to protect your data from loss, alteration, unauthorized access, or disclosure. These include:
- 
Encryption during data transmission (SSL/TLS). 
- 
Access restricted to authorized personnel only. 
- 
Regular security audits and system updates. 
- 
Payment data is processed via certified systems (Stripe, PayPal) compliant with PCI DSS standards. 
We do not store your payment data on our servers—it is transmitted directly to payment systems.
9. Use of Cookies
We use cookies and similar technologies to enhance website functionality, analyze interactions, and personalize content. For details, see our Cookie Policy. You can manage cookie settings in your browser.
10. Changes to the Privacy Policy
We may update this policy as needed. For significant changes (e.g., in data processing purposes), we will notify you via email, allowing you to review the changes and object if necessary.
11. Job Applicants
If you apply for a position:
- 
We collect data from your CV, public sources (e.g., LinkedIn), and third parties (e.g., references from previous employers, with your consent). 
- 
We use the data to evaluate your application, contact you, and store it for future vacancies (with your consent). 
- 
Data is retained for 1 year after application submission, unless otherwise specified. 
Contact Us
If you have any questions, email us at info@sacrum.design.
We are here to ensure your experience with SĂCRUM is safe and inspiring.

