Legal

Privacy policy

Saitroc SRL, trading as Osmyum · Oradea, Romania · Draft of 24 June 2026 — not yet in force

1. Who we are

Saitroc SRL, trading as Osmyum, is the controller of the personal data described in this policy. Registered office: Parc Industrial I, nr. 5, 410605 Oradea, Romania. Romanian Trade Registry: RO37817128.

For any question about this policy, or to exercise your rights, write to hello (at) osmyum.com.

2. What this policy covers

This policy covers the personal data we receive through osmyum.com — principally the two forms on this site — and the correspondence that follows. It does not cover data you give us outside the website.

3. What we collect

We collect only what you type into a form or send us by email. This site runs no analytics, no advertising and no tracking of any kind.

  • Stock list submission (Sell to us) — company name, contact name, email address, phone number (optional), the stock list file you attach, estimated total value (optional), and any notes you write.
  • RFQ submission (Buy from us) — company name, contact name, email address, country, MPN list (typed or attached), total quantity, target price (optional), delivery deadline, intended end-use, and any notes.
  • Email correspondence — whatever you choose to include when you write to one of our published mailboxes.
  • Technical data — our hosting provider records standard information such as IP address, timestamp and browser type, for delivery and security. [Confirm the exact fields retained by Netlify.]

4. Why we use it, and on what legal basis

  • To respond to your submission, prepare a quote and carry out the resulting transaction — Article 6(1)(b) GDPR (steps taken at your request before entering a contract, and performance of that contract).
  • To keep the site and our mailboxes secure and working — Article 6(1)(f) GDPR (our legitimate interest in operating a secure service).
  • To meet accounting, tax and export-control record-keeping duties where a transaction takes place — Article 6(1)(c) GDPR (compliance with a legal obligation).

We do not use your data for marketing, profiling or automated decision-making.

5. End-use information

The RFQ form asks for intended end-use. We collect it because EU Regulation 2021/821 on dual-use items requires us to document end-use and end-user for controlled goods. We use it for that purpose and for the resulting transaction only. [Counsel to confirm the correct lawful basis and retention rule for export-control records.]

6. Who else sees it

  • Netlify — hosts this website, and also receives and stores the form submissions before notifying us by email. Netlify is based in the United States, so submitting a form involves a transfer of personal data outside the EEA. [Counsel to confirm the transfer mechanism — Standard Contractual Clauses and/or the EU–US Data Privacy Framework — and that Netlify's data processing agreement is accepted.]
  • Our email provider — stores the correspondence. [Name the provider.]
  • Professional advisers and authorities — where we are legally required to disclose.

We do not sell your data and we do not share it for anyone else's marketing.

Google Maps is not loaded automatically. The Contact page shows a placeholder with our address and a button; nothing is requested from Google, and no Google cookie is set, unless you press it. From the moment you do, Google's own privacy policy applies.

7. How long we keep it

  • Enquiries that do not lead to a transaction — kept only as long as needed to deal with them, and a short period afterwards. [Set a concrete period with counsel, e.g. 12 or 24 months.]
  • Records connected to a completed transaction — kept for the statutory accounting and export-control retention periods that apply to us in Romania. [Counsel to state the exact periods.]

8. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or provide it in a portable format. You can also object to processing we base on legitimate interests. Write to hello (at) osmyum.com and we will respond within one month.

If you believe we have handled your data incorrectly, you can complain to the Romanian supervisory authority, ANSPDCP (Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal), dataprotection.ro.

9. Security

The site is served over HTTPS and form submissions are transmitted encrypted. Access to the mailboxes that receive submissions is limited to the people who need it.

10. Changes

We update this policy when our processing changes. The version in force is the one published here, with the date shown at the top.

For the reviewing lawyer

Points that need a qualified decision before this page goes live:

  • Confirm the lawful bases in section 4, and whether legitimate interests requires a documented balancing test.
  • Confirm the export-control basis and retention rule for end-use data (section 5).
  • Confirm Netlify's transfer mechanism and that its DPA is accepted; same for the email provider (section 6).
  • Set concrete retention periods (section 7).
  • Confirm whether a Record of Processing Activities (Art. 30) and/or a DPO is required for this company's size and activity.
  • Confirm the site does not need a separate cookie consent mechanism — see the Cookie notice.
  • Set the effective date and remove this section before publishing.