Privacy — this website

Last updated: September 13, 2026

Information under Article 13 of Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”) on the processing of personal data on the website ianomahou.com.

Controller

IA NO MAHOU S.R.L. (“we”). Registered office: Aleea Cristalului, Nr. 5, Camera 1, Etaj 8, Ap. 22, Municipiul Timișoara, Jud. Timiș, Romania. Fiscal code (CUI): 55261003. Trade register number: J2026045566000. Email: legal@ianomahou.com.

Contact for data protection matters: the contact form at https://ianomahou.com/contact/, topic “Privacy and my data”.

Provision of the website

Personal data
IP address and technical data transmitted by the device used to access the website.
Purpose
Delivering the website and ensuring its security and stability.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is providing a functional and secure website.
Recipients
The company that hosts the website.
Storage period
As long as necessary for these purposes.
Provision of data
Necessary to access the website.

Security check of the contact form

Personal data
Your IP address and technical information sent by your browser (for example, browser type and version), read automatically when the contact page is opened.
Purpose
Recognising automated programs that send spam, so that the contact form only accepts messages from people.
Legal basis
Article 6(1)(f) GDPR. Our legitimate interest is protecting the contact form against spam.
Recipients
The company that provides the security check.
Storage period
We do not store this data.
Provision of data
Necessary to send the contact form.

Messages sent through the contact form

Personal data
The topic, the product (if chosen), your email address, your message and any other personal data you include.
Purpose
Answering your message and sending you an automatic confirmation.
Legal basis
Article 6(1)(f) GDPR, our legitimate interest in answering messages. If your message concerns a contract or steps prior to entering into a contract: Article 6(1)(b) GDPR.
Recipients
The company that sends the contact form’s emails on our behalf, and the company that provides our mailbox.
Storage period
As long as necessary to handle your message. Longer only where the law requires it, or to establish, exercise or defend legal claims.
Provision of data
The topic, email address and message are required. Without them, we cannot answer.

Emails sent directly to our email address

Personal data
Your email address, your message and any other personal data you include.
Purpose
Answering your message, and an automatic reply pointing you to the contact form.
Legal basis
Article 6(1)(f) GDPR, our legitimate interest in answering messages.
Recipients
The company that provides our mailbox.
Storage period
As long as necessary to handle your message. Longer only where the law requires it, or to establish, exercise or defend legal claims.
Provision of data
Voluntary. Without it, we cannot answer.

Service providers and authorities

Service providers process personal data on our behalf and under our instructions (Article 28 GDPR). Personal data is disclosed to public authorities only where we are legally obliged to do so.

Transfers outside the European Economic Area

Service providers may process personal data outside the European Economic Area. Such transfers take place only on the basis of an adequacy decision of the European Commission (Article 45 GDPR) or appropriate safeguards (Article 46 GDPR), such as standard contractual clauses. A copy of the safeguards can be requested through the contact form at https://ianomahou.com/contact/.

Your rights

Under the conditions of the GDPR, you have the right of access (Article 15), rectification (Article 16), erasure (Article 17), restriction of processing (Article 18) and data portability (Article 20), and the right to object to processing based on legitimate interests (Article 21).

To exercise these rights, use the contact form at https://ianomahou.com/contact/ and choose the topic “Privacy and my data”.

Right to lodge a complaint

You can lodge a complaint with a supervisory authority, in particular in the Member State where you live or work or where the alleged infringement took place (Article 77 GDPR). The supervisory authority competent for us: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), https://www.dataprotection.ro.