Privacy Policy
Last updated: February 22, 2026
The Romanian version of this document is the legally binding one.
1. Data Controller Identity and Contact Information
The personal data controller is NIUA SRL, a Romanian legal entity, with its registered office in Calea Dudasului nr.49, Drobeta Turnu Severin, Romania.
- Email: contact@niualabs.com
- Phone: +40 779 215 919
For the purpose of Regulation (EU) 2016/679 (GDPR), NIUA SRL is the personal data controller for all processing described in this policy.
2. Categories of Personal Data Collected
Depending on your interaction with our website, we may collect the following categories of data:
- Identification data: first name, last name, email address, phone number
- Delivery data: postal address, county, city, postal code
- Billing data: company name, VAT ID, Trade Registry number, registered office address (for legal entities)
- Account Data: email address, password (encrypted), order history
- Technical Data: IP address, browser type, operating system, pages visited, visit duration (collected via cookies and analytics tools, only with your consent)
- Communication Data: content of messages sent via the contact form or email
3. Purposes of Data Processing
We process your personal data for the following purposes:
- To create and manage your user account on our platform
- To process and deliver your embroidery product and service orders
- To issue invoices and manage payments
- To communicate with you regarding orders, inquiries, or complaints
- To send commercial communications and promotional offers (only with your prior consent)
- To improve our website and services by analyzing browsing behavior (only with your consent)
- To comply with legal obligations (tax, accounting, reporting)
4. Legal Basis for Processing
We process your personal data based on the following legal grounds provided by Article 6 of the GDPR:
- Contract Performance (Art. 6 para. 1 lit. b): processing is necessary for the performance of a contract to which you are party (e.g., processing an embroidery order)
- Consent (Art. 6 para. 1 lit. a): for sending commercial communications and for the use of analytics cookies (PostHog). You have the right to withdraw your consent at any time, without affecting the legality of processing performed before the withdrawal
- Legal Obligation (Art. 6 para. 1 lit. c): for fulfilling tax and accounting obligations
- Legitimate Interest (Art. 6 para. 1 lit. f): for ensuring website security, fraud prevention, and improving our services
5. Recipients of Personal Data
Your personal data may be disclosed to the following categories of recipients, solely to the extent necessary to achieve the stated purposes:
- Hosting and Infrastructure Service Providers: Vercel Inc. (web application hosting)
- Database Providers: Convex (application data storage)
- File Storage Providers: Cloudflare R2 (storage of uploaded images and files)
- Email Service Providers: Resend (sending transactional and notification emails)
- Web Analytics Providers: PostHog (browsing behavior analysis, solely based on your consent)
- Authentication Providers: Better Auth (user account and session management)
- Courier Services: courier companies for order delivery
- Public Authorities: when legally required (e.g., tax authorities, courts)
All our service providers are contractually obliged to respect the confidentiality and security of your personal data, in accordance with GDPR requirements.
6. International Data Transfers
Some of our service providers are located or operate servers outside the European Economic Area (EEA), particularly in the United States. In these cases, data transfer is carried out with appropriate safeguards provided by GDPR:
- EU-US Data Privacy Framework: for providers certified under this mechanism
- Standard Contractual Clauses (SCCs): adopted by the European Commission, included in contracts with providers
Providers that may involve transfers outside the EEA: Vercel (USA), Convex (USA), Resend (USA), PostHog (USA). Cloudflare R2 operates a global network of servers, including in the EU.
7. Data Retention Period
Your personal data is stored only for the period necessary to fulfill the purposes for which it was collected:
- Account Data: for the entire duration of the account's existence. Upon request for account deletion, data is removed within 30 days
- Order and Invoice Data: 10 years from the date of issue, according to current tax and accounting legislation
- Communication Data: maximum 3 years from the last interaction
- Web Analytics Data: maximum 26 months from collection
- Marketing Data: until consent is withdrawn
After the storage period expires, data is irreversibly deleted or anonymized.
8. Your Rights
In accordance with GDPR, you have the following rights regarding your personal data:
- Right of Access (Art. 15): you have the right to obtain confirmation that your data is being processed and to access this data
- Right to Rectification (Art. 16): you have the right to request the correction of inaccurate data or the completion of incomplete data
- Right to Erasure (Art. 17): you have the right to request the deletion of your data under certain conditions provided by law
- Right to Restriction of Processing (Art. 18): you have the right to request the limitation of the processing of your data
- Right to Data Portability (Art. 20): you have the right to receive your data in a structured, commonly used and machine-readable format
- Right to Object (Art. 21): you have the right to object to the processing of your data in certain situations, including for direct marketing purposes
- Right not to be subject to automated individual decision-making (Art. 22): we do not use automated decision-making processes with legal effects
- Right to withdraw consent: at any time, without affecting the legality of previous processing
To exercise any of these rights, you may contact us at the email address contact@niualabs.com or by mail to our registered office address. We will respond to your request within a maximum of 30 days.
You also have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) , located at Bd. G-ral Gheorghe Magheru no. 28-30, Sector 1, Bucharest, Romania. More information can be found on the website: www.dataprotection.ro .
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or disclosure. Implemented measures include:
- Encryption of communications via HTTPS/TLS protocol across the entire site
- Storage of passwords exclusively in encrypted form (hashing)
- Restricted access to personal data, limited only to authorized personnel
- Use of service providers with recognized security certifications (SOC 2, ISO 27001)
- Periodic monitoring and updating of security measures
- Regular data backups
In the event of a data security breach posing a high risk to your rights and freedoms, we will notify you in accordance with Article 34 of the GDPR.
10. Privacy Policy Changes
We reserve the right to update this privacy policy as necessary to reflect changes in our data processing practices or applicable law. The date of the last update is indicated at the top of this page.
In the event of significant changes, we will inform you by email (if you have an active account) or through a visible announcement on our website before the changes take effect.
We recommend that you periodically review this page to stay informed about how we protect your personal data.
Contact Us
For any questions or requests regarding the processing of your personal data, you can contact us at:
- Email: contact@niualabs.com
- Phone: +40 779 215 919
- Address: Calea Dudasului nr.49, Drobeta Turnu Severin, Romania
Or visit our contact page .










