Updated 5 September 2026

Privacy policy

How EfiMag treats your data.

This policy explains what personal data EfiMag processes, why, for how long and what rights you have. It applies to everyone who deals with the platform: merchants who open a store, buyers in the hosted stores, and visitors to the efimag.ro site.

The controller is AIROD EOOD, EIK 208679904, with its registered office at 16 Tsarkovna Nezavisimost St., fl. 2, of. 9, 7000 Ruse, Bulgaria. Write to us at contact@efimag.ro.

The “In short” column on the right renders each section in two or three sentences. The section's own text is what counts.

Your data is yours

We use it only to provide you with the service. We do not sell it, rent it out, or pass it on for advertising.

We protect it from others

Encryption in transit, access only for those who need it, servers in the European Union, backups.

We keep it only as long as needed

No longer than the service or the law requires. When you close your account you can take it with you, and then we delete it.

We answer you in plain words

Write to us, we tell you what we hold about you and do what you ask — within 30 days at the latest.

1. What we stand for

Four things we believe, before any legal paragraph:

In shortYour data is yours, we protect it, we keep it only as long as needed, and we answer you clearly.

2. For everyone: what “personal data” means" and the legal bases

  1. “Personal data” means any information about an identified or identifiable person: name, e-mail, phone, address, but also the IP address or order history. “Processing” means anything we do with it: collection, storage, transmission, deletion.
  2. We process data on four legal bases: the contract (to provide the service you asked for), a legal obligation (invoices, accounting, requests from the authorities), legitimate interest (platform security, fraud prevention, improving the service — weighed against your rights), and consent (newsletter, measurement cookies), which you may withdraw at any time.
  3. The data sits on servers in the European Union. Where a provider processes it outside the EU (for example an AI service), it does so under the European Commission's standard contractual clauses or an adequacy decision.
  4. Our providers (“processors”) are: hosting (data centres in the EU), e-mail delivery, the payment processor for subscriptions, and the AI service for the analysis and assistant features. Each has a contract with us and processes only what is necessary.
  5. We do not sell data, we do not rent it out, and we do not use it for other people's advertising.
In shortWe process data to provide the service, to meet legal obligations, for security, and — only with your consent — for the newsletter or measurement. Servers in the EU, providers under contract.

3. For merchants

What data we hold about you

  1. On the account: name, e-mail, phone, password (hashed — we cannot read it), your company and billing details, the subscription payment method (held by the payment processor, not by us).
  2. When you use the admin: technical logs (IP address, browser, the time of important actions — sign-ins, settings changes), so we can fix errors and spot unauthorised access.
  3. In support: the messages you send us and, if you allow it, temporary access to your admin so we can see the problem.

Why we use it

  1. To provide the service (contract), to issue and keep invoices (legal obligation), to send you service announcements — outages, changes to the terms, invoices (contract), to keep the platform secure (legitimate interest) and, if you subscribed, the newsletter (consent).

Your customers' data

  1. The orders, addresses, accounts and messages of your store's customers are processed by us on your behalf: you are the controller, we are the processor. We use it only to run your store, following your instructions in the admin, and we do not use it for our own purposes. We will send you the data processing agreement (Art. 28 GDPR) on request.
  2. The third-party services you switch on (processors, couriers, marketplaces, marketing tools) receive from us only the data they need in order to work, and they process it under their own policies; you choose what you switch on.

The AI features

  1. The AI analysis, the assistant in the admin and the product descriptions send an AI service (Anthropic) the text and figures required: aggregated store figures, product copy, your question. We do not send your customers' identifying data in these requests. The provider does not use the data to train its models.

How long we keep it

  1. Account data: for as long as you have an account, plus the period the law requires for accounting documents. Technical logs: 12 months at most. When an account is closed, the store's data remains for 30 days so you can export it, then it is deleted from the active systems; backups rotate within 90 days at most.
In shortWe hold your account and company data, technical logs and whatever you write to us. Your customers' data we process on your behalf, on your instructions. The AI receives figures and text, not customer identities. On leaving: 30 days to export, then deletion.

4. For buyers

  1. When you buy from a store hosted by EfiMag, the controller of your data is the merchant — the store you are buying from. Their privacy policy says what they do with your data; we process it on their behalf, as the platform provider.
  2. Your order data (name, address, phone, e-mail, products, payment) reaches the merchant and, through them, the courier and payment processor they chose. We do not use it for our own purposes and we do not sell it.
  3. Visit measurement in the stores is done by the platform without cookies and without IP addresses: we keep a session identifier that dies when you close the tab, the page visited, the source (for example, Google), the device type and the language. We cannot identify you from this data.
  4. Third-party measurement tools (Google Analytics, Meta or TikTok pixels) are switched on only by the merchant, and only with your consent from the store's cookie banner.
  5. To exercise your rights (access, correction, deletion) over an order, you contact the merchant. If they do not respond, write to us and we will help them respond.
In shortYou buy from the merchant, so they answer for your data; we hold it for them. We measure visits without cookies and without IPs. For your rights, go to the merchant first.

5. For visitors to efimag.ro

  1. The efimag.ro marketing site uses no tracking cookies and asks for no cookie consent. The server keeps ordinary technical logs (IP address, page requested, time), held for 30 days at most, for security.
  2. The free tools at efimag.ro/unelte run in your browser; what you type into them does not reach us — except for the name and slogan generators, which send the text you enter to the AI service in order to get suggestions, without us storing it.
  3. The forms and e-mails you send us (contact, migration, partnership) we keep for as long as we need in order to answer you and, if you become a customer, on your account.
  4. If you register for a trial store, the merchants' section applies.
In shortNo tracking cookies on efimag.ro. The tools run in your browser. What you write to us we keep for as long as we need in order to reply.

6. Your rights

  1. You have the right to request: access to your data and a copy of it; correction of inaccurate data; erasure (the “right to be forgotten”), when we no longer have a basis for keeping it; restriction of processing; portability of the data in a structured format; objection to processing based on legitimate interest; withdrawal of consent, at any time, without affecting what was done beforehand.
  2. Write to us at contact@efimag.ro. We reply within 30 days at the latest; if the request is complex, we will tell you we need more time. For your own protection, we may ask you to confirm your identity.
  3. You have the right to lodge a complaint with the supervisory authority in your country — in Romania, ANSPDCP (dataprotection.ro); in Bulgaria, CPDP (cpdp.bg).
  4. We take no automated decisions with legal effects on you. The AI analysis in the admin is an aid for the merchant, not a decision about a person.
In shortAccess, correction, erasure, portability, objection, withdrawal of consent. Write to us, we reply within 30 days. You may complain to the supervisory authority.

7. How we protect the data

  1. Encrypted transmission (HTTPS) everywhere; passwords are hashed irreversibly; access to each store's data is isolated at database level, so that one merchant cannot reach another's data.
  2. Our team's access to data is limited to what is necessary and is logged. The platform's admin panel cannot change prices or delete merchants' orders.
  3. We take regular, encrypted backups, within the European Union.
  4. If a security breach occurs that may affect your rights, we notify you without delay and, where the law requires it, we notify the authority within 72 hours.
In shortEncryption, isolation between stores, limited and logged access, backups in the EU. If something happens, you hear about it quickly.

8. Changes and contact

  1. When we change this policy, we publish the new version here with the update date, and we notify you in the admin or by e-mail if the change concerns you.
  2. Data protection contact: write to us at contact@efimag.ro, with the subject “Personal data”.
  3. Controller: AIROD EOOD, EIK 208679904, 16 Tsarkovna Nezavisimost St., fl. 2, of. 9, 7000 Ruse, Bulgaria.
In shortThe new version appears here, with its date. For any question about data: contact@efimag.ro.
AIROD EOOD · EIK 208679904
16 Tsarkovna Nezavisimost St., fl. 2, of. 9, 7000 Ruse, Bulgaria
E-mail: contact@efimag.ro