PRIVACY POLICY — PARTNERS

Salons and specialists holding a business account on the STILIO platform

1. Introduction and who we are

1.1. This Policy explains how STILIO DIGITAL LIMITED LIABILITY COMPANY ("STILIO", "we"), IDNO 1022600029811, with its registered office at MD-2044, Chișinău municipality, 17 Mihail Sadoveanu St., office 249A, collects and processes the personal data of Partners (salons, specialists) in connection with the use of the STILIO platform.
1.2. We are committed to processing data lawfully, fairly, and transparently, in accordance with the principles of lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability.
1.3. Contact for data protection matters: [email protected].

2. Scope

2.1. This Policy is addressed to Partners and covers their business data. Data of clients that the Partner manages through the platform is governed separately (Art. 4 and the DPA). The processing of visitors and direct clients is described in the Privacy Policy for clients.

3. Definitions

a) "Personal data" — any information relating to an identified or identifiable natural person;
b) "Processing" — any operation performed on data (collection, storage, use, transmission, deletion, etc.);
c) "Controller" / "Processor" — as defined by Law No. 195/2024 and the GDPR;
d) "Applicable Law" — Law No. 195/2024 and, for users in the EU, the GDPR.

4. STILIO's roles (controller and processor)

4.1. With respect to the Partner's data, STILIO is the controller.
4.2. With respect to the data of clients that the Partner enters and manages through the platform, STILIO is the processor, and the Partner is the controller and is responsible for its lawfulness. This relationship is governed by the Data Processing Agreement (DPA).

5. How we collect data

a) directly from the Partner (at registration, when setting up the account, in correspondence);
b) automatically, through use of the platform (technical logs, IP address, usage data);
c) from third parties, where applicable (e.g. the payment processor confirms the payment status).

6. What data we process, for what purpose, on what legal basis, and for how long

6.1. The table below summarizes the main processing activities regarding the Partner's data:
Data categoryPurposeLegal basisRetention period
Business identification and contact details (name/company name, contact person, e-mail, phone, address)Creating and administering the account, service communicationsPerformance of the contractFor the duration of the account
Authentication dataSecurity of the account and accessPerformance of the contract; legitimate interestFor the duration of the account
Billing and tax data (payment history, subscriptions)Billing, accounting, tax obligationsLegal obligationFor the period required by accounting and tax legislation
Usage data and technical logs (IP, account actions)Operation, security, fraud prevention, improvementLegitimate interestFor the duration of the account
Marketing preferences and consentsMarketing communications to PartnersConsentUntil withdrawn
Correspondence with the STILIO teamSupport and handling requestsLegitimate interestFor the duration of the account

7. Legal bases explained

7.1. Performance of the contract — for providing the platform and the account.
7.2. Legal obligation — for billing, accounting, and tax obligations.
7.3. Legitimate interest — for security, fraud prevention, and improving the service; we carry out a balancing assessment between our interests and the Partner's rights, and the Partner may object (Art. 12).
7.4. Consent — for marketing and for non-essential cookies; it may be withdrawn at any time, without affecting the lawfulness of prior processing.

8. Marketing to Partners

8.1. We send marketing communications only to Partners who have given their consent, with an unsubscribe option in every message.
8.2. We may segment communications based on the Partner's country (Republic of Moldova, Romania, Italy). We do not carry out automated profiling and we do not use geolocation (GPS) for marketing purposes.

9. Automated decisions and profiling

9.1. We do not make decisions based solely on automated processing, including profiling, that would produce legal effects concerning the Partner or significantly affect them.

10. Cookies and similar technologies

10.1. The platform uses cookies in accordance with the Cookie Policy. Non-essential cookies and analytics/advertising tools, including Meta Pixel, are activated only based on the consent given through the cookie banner.

11. Recipients and sub-processors

11.1. Data may be processed by service providers (sub-processors) acting on behalf of STILIO, under contracts with equivalent protection obligations. Updated list: https://stilio.ro/en/subprocessor.
11.2. Data may be disclosed to authorities where required by law.

12. International transfers

12.1. The main infrastructure is located in the European Union. For providers outside the EU/Republic of Moldova, transfers are carried out with adequate safeguards: Standard Contractual Clauses approved by the European Commission and, where applicable, EU-U.S. Data Privacy Framework certification. A copy of the safeguards may be requested at the contact address.

13. How long we retain data

13.1. Termination of a paid subscription does not result in deletion of the account; the Partner switches to the free plan and remains an active user, and data is retained for as long as the account is active.
13.1. Termination of a paid subscription does not result in deletion of the account; the Partner switches to the free plan and remains an active user, and data is retained for as long as the account is active.

14. Data security

14.1. We apply technical and organizational measures appropriate to the risk: encryption in transit (TLS) and at rest at the infrastructure level, role-based access control, two-factor authentication for critical systems, access logging, backups, separation of production and testing environments, and hosting within the EU.

15. The Partner's rights

15.1. The Partner has the following rights:
a) the right of access to their data and to information about the processing;
b) the right to rectification of inaccurate or incomplete data;
c) the right to erasure ("the right to be forgotten"), under the conditions provided by law;
d) the right to restriction of processing;
e) the right to data portability — receiving their data in a structured, commonly used, machine-readable format;
f) the right to object, including to processing based on legitimate interest and to marketing;
g) the right to withdraw consent at any time, without affecting the lawfulness of prior processing;
h) the right to lodge a complaint with the supervisory authority.
15.2. Requests should be sent to [email protected]. We respond within one month, which may be extended by two months for complex requests, with prior notice to the Partner. We may request additional information to verify identity. Exercising these rights is, as a rule, free of charge.

16. Supervisory authority

16.1. The Partner has the right to lodge a complaint with the National Center for Personal Data Protection (CNPDCP), without prejudice to any other remedies.

17. Contact person for data protection

17.1. STILIO has designated a contact person for data protection, [email protected]. STILIO is not legally required to appoint a Data Protection Officer (DPO); should this change, the Policy will be updated accordingly.

18. Client data entered by the Partner

18.1. The Partner, as controller, is responsible for the lawfulness of the client data it enters, for informing those clients, and for obtaining consent where required. STILIO processes this data as processor, in accordance with the DPA.

19. Changes

19.1. This Policy may be updated. Changes are published on the platform, indicating the effective date; significant changes may also be communicated separately.

20. Contact

20.1. For any question regarding this Policy: [email protected].
Last updated: 23 August, 2026