[yith_ywraq_request_quote]
PRIVACY POLICY
(Information note regarding the processing of personal data)
avastarmeat.com
Version in force starting with the date of 29.04.2026
AVA STAR SRL attaches great importance to the protection of the personal data of the people who interact with our Website. This Privacy Policy (hereinafter referred to as the "Policy") explains in a transparent, complete and easy-to-understand manner how we collect, use, store, transfer and protect your personal data, as well as the rights you benefit from.
The policy is developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("GDPR"), Law no. 190/2018 regarding measures to implement the GDPR in Romania and the national legislation implementing the GDPR in the EU member states where we process data.
1. WHO WE ARE (DATA CONTROLLER)
The operator of personal data collected through the Website is:
AVA STAR SRL
Registered office: Str. 1 Mai 72, Loc. Pascani, jud. Iasi, Cod 705200
ORC registration number: J1994002589225
EUID: ROONRC.J1994002589225
WHO: 6500293
E-mail: dpo@avastar.ro
⚠ Important — Domeniul de activitate al Societatii (B2B)
AVA STAR SRL este un PRODUCATOR comercial in industria alimentara (carne) si se adreseaza EXCLUSIV publicului profesionist B2B (parteneri comerciali, distribuitori, retaileri, importatori, profesionisti HoReCa). Website-ul are scop strict informativ si de prezentare comerciala B2B — nu este o platforma de e-commerce, NU vindem direct catre consumatori finali (persoane fizice), NU procesam comenzi online si NU incheiem contracte de vanzare-cumparare prin acest Website. Intregul continut al prezentei Politici trebuie interpretat in acest context: prelucram doar datele tehnice strict necesare functionarii site-ului si datele de contact furnizate voluntar prin formulare de catre potentiali parteneri B2B care doresc sa ne contacteze pentru oferte comerciale.
Ce NU facem:
- NU trimitem newslettere si NU desfasuram campanii de email marketing;
- NU trimitem comunicari comerciale nesolicitate (spam) catre vizitatori sau parteneri;
- NU stocam date pentru profilare comerciala, remarketing sau publicitate personalizata;
- NU vindem produse direct catre persoane fizice prin Website (e-commerce B2C);
- NU procesam plati online si NU stocam date bancare ale vizitatorilor;
- NU vindem, NU inchiriem si NU partajam date cu terti pentru scopuri comerciale.
Ce facem:
- Raspundem la solicitarile de informatii si oferte comerciale primite voluntar prin formularele B2B;
- Pastram datele de contact strict cat este necesar pentru a finaliza dialogul comercial B2B initiat;
- Folosim cookie-uri tehnice strict necesare functionarii site-ului si, optional cu consimtamant, cookie-uri analitice agregate pentru imbunatatirea experientei tehnice (NU profilare individuala).
1.1. Responsible for Data Protection / Point of Contact
For any questions or requests related to the processing of personal data, you can contact us:
- Dedicated email: dpo@avastar.ro (with the mention "GDPR" in the subject)
- Mailing address: Str. 1 Mai 72, Loc. Pascani, jud. Iasi, Cod 705200
2. SCOPE OF THE POLICY
This Policy applies to all natural persons who interact with avastarmeat.com and the related subdomains, regardless of the country of access, in the following situations:
- Vizitarea sau navigarea pe Website (in scop informativ B2B);
- Completarea formularelor de contact B2B sau de cerere oferta din partea unui partener comercial;
- Comunicarea cu noi prin email, telefon sau alte canale electronice in cadrul unei relatii comerciale B2B;
- Utilizarea cookie-urilor strict tehnice necesare functionarii site-ului.
The policy does not apply to the processing of data as an employee, candidate for employment or contractual partner of the Company, situations for which there are separate information notes.
Audienta vizata: Website-ul se adreseaza profesionistilor B2B (companii, distribuitori, retaileri, profesionisti HoReCa, importatori, autoritati). Persoanele fizice care nu actioneaza in calitate profesionala (consumatori finali) nu fac obiectul unei relatii comerciale prin acest Website.
3. THE CATEGORIES OF DATA WE PROCESS
We exclusively process the data necessary for the purposes described in this Policy, in accordance with the principle of data minimization (art. 5(1)(c) GDPR). The categories of data we can process are:
3.1. Date furnizate direct de dumneavoastra (numai prin formularul B2B de contact)
Datele furnizate direct sunt limitate strict la informatiile minime necesare pentru a putea raspunde unei solicitari B2B:
- Date de identificare profesionala: nume, prenume (in calitate de reprezentant al unei organizatii);
- Date de contact profesional: adresa de email business, eventual numar de telefon;
- Date privind organizatia: denumire companie, functie, oras/tara;
- Continutul mesajelor B2B transmise prin formulare sau email (cerere de oferta, intrebare comerciala etc.).
NU colectam si NU stocam: preferinte pentru newsletter, optiuni de marketing, profile comportamentale, identificatori publicitari, date pentru remarketing sau pentru profilare individuala.
3.2. Data collected automatically when accessing the Website
- IP address (pseudonymized where technically possible);
- Browser type and version, operating system, device type;
- Country/region of origin (generally, without precise location);
- Pages visited, duration of the visit, pages of origin (referrer);
- Date and time of access;
- Cookie identifiers and similar technologies (only with your consent, for cookies that are not strictly necessary).
3.3. Special categories of data
We do NOT intentionally collect and do NOT request through the Website sensitive data (data regarding health, racial or ethnic origin, political opinions, religious beliefs, biometric data, data regarding sex life or sexual orientation, etc.). Please do not send us such data through the contact forms. If, however, you choose to voluntarily send us such information, we will delete it at the first opportunity or, if it is necessary to respond to you, we will only process it based on explicit consent, according to art. 9(2)(a) GDPR.
3.4. Data on minors
Conform Art. 8 GDPR si legislatiei nationale aplicabile, Website-ul nu este destinat persoanelor sub 16 ani. Pentru utilizatorii sub aceasta varsta, prelucrarea datelor cu caracter personal pe baza consimtamantului este conditionata de autorizarea sau aprobarea titularului raspunderii parintesti. Nu colectam constient date de la copii sub varsta minima aplicabila. Daca aflam ca am colectat din eroare astfel de date, le vom sterge prompt. Parintii/tutorii care suspecteaza o astfel de situatie pot contacta dpo@avastar.ro.
Nota: Varsta minima de 16 ani este specifica jurisdictiei aplicabile acestui site. In UE, varsta variaza intre 13 ani (Danemarca) si 16 ani (Romania, Germania, Olanda, Polonia, Ungaria); 14 ani (Austria, Italia, Spania); 15 ani (Franta, Cehia).
4. PURPOSES AND LEGAL BASIS OF THE PROCESSING
We process personal data exclusively on the basis of a legal legal basis and for specific purposes. The table below summarizes the main processing situations:
| Scope | Legal basis (GDPR) | Processed data | Storage duration |
|---|---|---|---|
| Raspuns la solicitari B2B transmise prin formular contact / cerere oferta | Art. 6(1)(b) – demersuri precontractuale; Art. 6(1)(f) – interes legitim al Societatii de a raspunde solicitarilor partenerilor B2B | Nume, email business, telefon, continut mesaj, date companie (NU date personale extinse) | 3 ani de la ultima interactiune (sau perioada mai lunga in caz de litigiu/contract semnat) |
| Technical functioning of the Website (strictly necessary cookies) | Art. 6(1)(f) – legitimate interest | Identificatori sesiune, preferinte tehnice (NU IP raw stocat — doar hash pentru rate-limit) | Session duration or max. 12 months |
| Analiza trafic agregata, statistici tehnice (cookie-uri analitice optionale) | Art. 6(1)(a) – consimtamant explicit (optional, prin banner) | Identificatori cookie agregati, IP pseudonimizat, NU profilare individuala | According to the Cookie Policy (max. 24 months) |
| Compliance with legal obligations (fiscal, accounting, control authorities) | Art. 6(1)(c) – legal obligation | Relevant data according to applicable law | According to the legal terms (usually 5-10 years) |
| Establishing, exercising or defending a right in court | Art. 6(1)(f) – legitimate interest | All relevant data | During the litigation + limitation periods |
| Prevention of fraud, abuse, cyber attacks; IT security | Art. 6(1)(f) – legitimate interest; Art. 32 GDPR | IP, technical logs, security indicators | Max. 12 months, except in case of incident |
When processing data based on legitimate interest, we performed a balancing test and concluded that your rights and freedoms are not disproportionately harmed. You have the right to contest this analysis and to object to the processing (see section 8).
5. WHO RECEIVES YOUR DATA
We treat data confidentially and never sell them to third parties. In certain situations, it is necessary to disclose data to limited categories of recipients, who process data only on the basis of clear instructions and contractual guarantees (Data Processing Agreements - DPA, according to art. 28 GDPR):
5.1. Authorized persons (processors) of the Company
- Furnizori de servicii de gazduire web si infrastructura IT (servere, baze de date);
- Furnizori de servicii email tranzactionale (NUMAI pentru transmiterea raspunsurilor la solicitarile dumneavoastra primite prin formular B2B — NU folosim platforme de email marketing si NU trimitem comunicari comerciale nesolicitate);
- Furnizori de servicii analitice web pentru statistici tehnice agregate (numai cu consimtamant explicit, in versiune anonimizata; NU pentru profilare individuala sau publicitate);
- Providers of IT maintenance and security services;
- Distribuitori si reprezentanti comerciali B2B, exclusiv pentru a da curs solicitarilor dvs. specifice ca partener comercial (ex.: cerere oferta pentru o anumita piata nationala).
5.2. Associated or independent operators
- Companies from the AVA STAR group (as applicable);
- External professional advisers (lawyers, accountants, auditors, tax advisers) - based on the applicable professional confidentiality obligations.
5.3. Public authorities
We can disclose data to the competent public authorities when we have a legal obligation to do so (eg: fiscal authorities, consumer protection authorities, sanitary-veterinary authorities, courts of law, criminal prosecution bodies, ANSPDCP or equivalent authorities from other EU member states).
5.4. Possible successors
In case of merger, acquisition, sale of a part of the activity or corporate reorganization, the data may be transferred to the successor entity, with its obligation to comply with this Policy and GDPR. We will inform you in advance about such transfers, according to the law.
6. DATA TRANSFER OUTSIDE THE SEA
We process data with priority on servers located in the European Union or the European Economic Area (EEA). In certain situations - especially for the use of cloud or analytical services provided by global companies - data can be transferred to countries outside the EEA.
In these cases, we ensure that the transfer is carried out with adequate guarantees, according to Chapter V GDPR:
- Adequacy decisions of the European Commission (art. 45 GDPR), for countries that offer an adequate level of protection;
- Standard contractual clauses (SCC) adopted by the European Commission (art. 46(2)(c) GDPR), accompanied, as the case may be, by additional technical and organizational measures (Schrems II / EDPB Recommendations 01/2020);
- Mandatory corporate rules (BCR), when applicable;
- For transfers to the USA, we evaluate the applicability of the EU-US Data Privacy Framework (DPF) where the supplier is certified and apply additional guarantees in the light of CJEU jurisprudence (Schrems II and subsequent jurisprudence).
You can obtain a copy of the guarantees applicable to the relevant transfers by written request to dpo@avastar.ro.
7. HOW LONG WE KEEP YOUR DATA
We keep personal data only for the duration necessary to achieve the purposes for which they were collected or for the duration imposed by legal obligations, according to the principle of storage limitation (art. 5(1)(e) GDPR).
The standard duration is indicated in the table in section 4. When the deadlines expire, the data are either securely deleted or irreversibly anonymized for aggregated statistical use.
Certain data can be kept longer in the following situations, based on valid legal grounds:
- Existence of a legal obligation to archive (eg: fiscal, accounting documents);
- The need to defend a right in court or to establish/exercise it (until the statute of limitations expires);
- The existence of a litigation, investigation or official control in progress;
- Express request of a competent authority.
8. YOUR RIGHTS
According to the GDPR, you have the following rights in relation to your personal data:
8.1. The right of access (art. 15 GDPR)
You have the right to obtain confirmation whether or not we are processing data concerning you, to receive a copy of them and information about the processing (purposes, categories of data, recipients, duration, source, etc.).
8.2. The right to rectification (art. 16 GDPR)
You have the right to request the rectification of inaccurate data or the completion of incomplete data.
8.3. The right to erasure - "the right to be forgotten" (art. 17 GDPR)
You can request the deletion of the data if: (i) they are no longer necessary for the purposes; (ii) you have withdrawn your consent and there is no other reason; (iii) you oppose the processing and there are no compelling legitimate reasons; (iv) the data has been processed illegally; (v) deletion is necessary according to a legal obligation.
8.4. The right to restriction of processing (art. 18 GDPR)
You can request the restriction in the situations provided by the law (contesting accuracy, illegal processing, opposition under evaluation, etc.).
8.5. The right to data portability (art. 20 GDPR)
For data processed on the basis of consent or a contract and by automated means, you have the right to receive the data in a structured, common and automatically readable format (eg: JSON, CSV) and to transmit them to another operator.
8.6. The right to opposition (art. 21 GDPR)
Va puteti opune prelucrarii bazate pe interes legitim (art. 6(1)(f)) din motive legate de situatia dvs. specifica. Mentionam ca Societatea NU desfasoara marketing direct, profilare comerciala, remarketing sau publicitate personalizata — astfel ca nu exista astfel de prelucrari fata de care sa fie necesara o opozitie. Daca, totusi, considerati ca o anumita prelucrare bazata pe interes legitim (ex.: securitate, prevenire frauda) va afecteaza, ne puteti contacta si vom evalua de la caz la caz.
8.7. The right not to be subject to automated decisions (art. 22 GDPR)
We do not carry out automated decision-making processes through the Website, including profiling, which produce legal effects or which significantly affect you. If this practice changes, we will inform you in advance.
8.8. The right to withdraw consent
When the processing is based on consent, you can withdraw it at any time, without affecting the legality of the processing carried out prior to the withdrawal.
8.9. The right to lodge a complaint with a supervisory authority
You have the right to file a complaint with the competent authority in the EU member state where you have your usual residence, place of work or where the alleged violation took place. In Romania, the competent authority is:
EDPB — European Data Protection Board (international users)
Adresa: Rue Wiertz 60, B-1047 Brussels, Belgium
Telefon: +32 (0)2 283 19 17
Email: EDPB@edpb.europa.eu
Website: https://www.edpb.europa.eu
Autoritatea de supraveghere romaneasca (operator): Deoarece AVA STAR SRL este o societate inregistrata in Romania, plangerile pot fi adresate si la Autoritatea Nationala de Supraveghere (ANSPDCP), B-dul G-ral. Gheorghe Magheru nr. 28-30, Bucuresti — anspdcp@dataprotection.ro / dataprotection.ro.
Lista completa a autoritatilor de supraveghere din toate statele membre UE este disponibila pe website-ul Comitetului European pentru Protectia Datelor (EDPB): https://www.edpb.europa.eu
8.10. How to exercise rights
To exercise any of the above rights, please send us a written request, identifying yourself appropriately:
- Email: dpo@avastar.ro (with the mention "GDPR" in the subject)
- Mailing address: Str. 1 Mai 72, Loc. Pascani, jud. Iasi, Cod 705200
We will respond free of charge, within a maximum of one month after receiving the request. This term can be extended by a maximum of two months when necessary, taking into account the complexity and number of applications; we will inform you about the extension in the first 30 days.
In certain exceptional situations, we may request additional information to verify your identity (especially when the request raises suspicions of impersonation). Clearly unfounded or repetitive requests (e.g.: identical, sent systematically) may be charged with a reasonable fee or may be refused, according to art. 12(5) GDPR.
9. DATA SECURITY
We apply appropriate technical and organizational measures to ensure a level of security appropriate to the risk, according to art. 32 GDPR. These measures include, but are not limited to:
- Encryption of connections (HTTPS/TLS) for data transmission between browser and server;
- Strict access control policies, the "need to know" principle and multifactor authentication for personnel with access to data;
- Regular staff training in data protection and IT security;
- Internal procedures for managing security incidents, including a formal process of notification of violations within 72 hours to the supervisory authority, according to art. 33 GDPR;
- Periodic backups and business continuity plans;
- Audits and periodic testing of technical measures;
- Confidentiality agreements and GDPR clauses with all partners who have access to data.
However, no computer system can be 100% secure. In case of an incident that could have a high risk for your rights and freedoms, we will notify you without undue delay, according to art. 34 GDPR.
10. COOKIES AND SIMILAR TECHNOLOGIES
The website uses cookies and similar technologies (web beacons, pixels, local storage, etc.). Complete details on the types of cookies used, their purposes, duration and management options are presented in the Cookie Policy, accessible separately on the Website.
For cookies that are not strictly necessary for the functioning of the Website (analytical, functional, marketing), we request your prior consent through a transparent interface (Consent Management Platform - CMP). This consent is expressed through a clear affirmative action (e.g., pressing the "Accept" button for the respective category), non-acceptance being as simple as acceptance, in accordance with the EDPB guidelines on "dark patterns" and valid consent.
You can withdraw your consent at any time by accessing the cookie preferences on the Website.
10.1. Cross-domain aggregated internal reporting
In the situation where AVA STAR SRL operates several websites (national versions of the same brand), we use an internal centralized reporting system for GDPR compliance and aggregated internal analysis.
Privacy-by-Design (Art. 25 GDPR): The system transmits ONLY aggregated-numeric data between sites, without information that can identify any person. Concrete:
- TO BE TRANSFERRED: domain name, reported period, total counters (eg: 1234 consents this week), category percentages, number of deletion requests received (count, without details), number of security events, anonymization/automatic deletion counters.
- NOT TRANSFERRED: IP addresses (not hashed), names, emails, user-agents, visited URLs, individual cookie identifiers or any other personal identifier.
Technical measures:
- Transport HTTPS only (refuse transmission via HTTP).
- HMAC-SHA256 signature with shared secret (verified at reception).
- Replay protection: timestamp + nonce per request (5 minute expiration).
- Whitelist authorized domains at the hub.
- Audit trail: each transfer (success/failure) recorded in the security log.
- Hub retention: 12 months (audit period), then automatic deletion.
Legal basis: Art. 6(1)(f) GDPR — legitimate interest of the operator (internal compliance reporting, cross-domain monitoring). Balancing test carried out: no personal data is processed, so the impact on the rights of the persons concerned is null.
11. CHANGES TO THIS POLICY
We may periodically update this Policy to reflect changes in legislation, our practices or the technologies we use. The version in force will always be published on the Website with the indication of the date of entry into force.
Pentru modificari substantiale (de ex., un nou scop de prelucrare sau categorii noi de destinatari), va vom informa in prealabil intr-un mod adecvat — prin afisare proeminenta pe Website. Recomandam verificarea periodica a Politicii.
12. GLOSSARY (RELEVANT GDPR DEFINITIONS)
- "Personal data": any information regarding an identified or identifiable natural person (eg name, email, phone, IP address).
- "Processing": any operation on the data (collection, registration, storage, modification, consultation, transmission, deletion, etc.).
- "Operator": the entity that establishes the purposes and means of processing - in the present case, AVA STAR SRL.
- "Authorized person": the entity that processes the data on behalf of the Operator, based on a contract.
- "Consignee": the entity to which data is disclosed, regardless of whether it is a third party or not.
- "Consent": manifestation of free will, specific, informed and unambiguous, by which the person accepts the processing of his data.
13. CONTACT
For any questions, requests or complaints regarding the processing of your personal data:
- Email: dpo@avastar.ro
- Mailing address: Str. 1 Mai 72, Loc. Pascani, jud. Iasi, Cod 705200
Thank you for your trust and for the attention with which you have gone through this Policy. We are committed to treating your data with the utmost care and transparency.
— End of Privacy Policy —