1. Introduction
This Privacy Policy (“Policy”) establishes the framework and conditions under which Alpine Ridge Solutions S.R.L., headquartered in the EU and specialized in cold-chain logistics, processes personal data collected through its own website, intended for users and individual customers located within the territory of the European Union. The Policy aims to ensure transparency and compliance with data protection rights, in accordance with Regulation (EU) 2016/679 (“General Data Protection Regulation” or “GDPR”), Law 190/2018, and other relevant EU legislation, including Directives and guidelines issued by the European Data Protection Board and National Supervisory Authorities.
Through this Policy, Alpine Ridge Solutions informs you about the nature of the personal data collected, the purpose, legal grounds, your rights, the use of cookie files, international transfers, security measures, and the data retention period. The Policy applies to any online interaction through our website, regardless of the user’s geographical location, except for cases otherwise regulated through specific contractual agreements.
2. Contact Details of the Data Controller
Data Controller:
Alpine Ridge Solutions S.R.L.
Address: Bld Gării 2, Brașov, ROMANIA
Company ID (CUI): 48134727
E-mail: contact@alpinelogistics.ro
Phone: +40747869558
Data Protection Officer (DPO):
E-mail DPO: contact@alpinelogistics.ro
Phone DPO: +40747869558
These details may be used for any request regarding the exercise of your rights related to personal data protection.
3. Scope of the Policy
This Policy applies to all personal data processing operations carried out by Alpine Ridge Solutions through the online platform, whether users access the services from Romania or any other EU Member State.
Specifically, the processed data concerns customers and potential customers (individuals), legal representatives or contact persons of legal entities, website visitors, collaborators, partners, service providers, and any other third parties with whom contractual or non-contractual relationships are established through the digital platform.
The Policy does not apply to irreversibly anonymized data, data of legal entities, or data collected offline, except in cases detailed in separate policies.
4. Categories of Personal Data Collected
Alpine Ridge Solutions collects only relevant and necessary data, in compliance with the principle of data minimization. Depending on context and website functionality, we may process the following categories of data:
• Identification data: name, surname, home/residence address, postal code, electronic or handwritten signature (for contracts), national identification data when required by law (e.g., personal identification number, ID card/passport series and number).
• Contact data: phone number, email address, mailing address, delivery/pick-up addresses.
• Professional data: job title, represented company, field of activity, tax details for invoicing.
• Connection and online activity data: IP addresses, access logs, devices used, sessions, language preferences and geolocation (based on IP), necessary and optional cookies, browsing history, unique online identifiers.
• Transactional/commercial data: data regarding ordered products or services, date and time of transactions, value and payment method, bank account details for invoicing and payments.
• Data collected via contact forms, chat, or newsletter: any information voluntarily entered in forms, sent messages, feedback.
• Consent-related data: expressions of consent/refusal for data processing, cookie settings, date and time of consent.
• Security and audit data: successful/failed authentications, administrative actions, data necessary for security incident investigation.
• Other data: any other information voluntarily provided by the user (e.g., CVs for recruitment, personalized requests).
Alpine Ridge Solutions does not routinely collect special categories of data (race, ethnicity, religious beliefs, health data, or sexual orientation), except where explicitly required by law or voluntarily provided by the user with explicit consent.
5. Purposes and Legal Grounds for Processing
Processing of any data by Alpine Ridge Solutions is carried out strictly for legitimate, clearly defined, and documented purposes, in compliance with GDPR principles.
5.1 Processing Purposes
• User account registration and management
• Provision of cold-chain logistics services
• Handling requests for offers, contact, technical assistance, or customer support
• Sending commercial and marketing communications, including newsletters (based on explicit consent)
• Managing contractual, administrative, accounting, and fiscal relations
• Fulfilling legal obligations (archiving, reporting to authorities, preventing money laundering, labor/tax compliance, fraud detection)
• Service analysis and improvement, online experience personalization
• Website and IT system security
• Recruitment and application processing (based on explicit consent)
5.2 Legal Grounds for Processing
Data is processed based on the following GDPR legal grounds:
• Contract performance – Art. 6(1)(b)
• Legal obligation – Art. 6(1)(c)
• Explicit consent – Art. 6(1)(a)
• Legitimate interest – Art. 6(1)(f)
• Public/vital interest obligation – in special cases
The legal basis and purpose are communicated explicitly at the time of data collection.
6. Methods of Data Collection
Data is collected directly from you through:
• Online forms (contact, offer request, user account, order, newsletter)
• Email, phone, or online chat
• Website browsing (cookies, IP addresses, online identifiers)
• Electronically or handwritten signed contractual documents
• Digital consent forms/options
• Participation in promotional campaigns/events
Automated data collection may occur through web analytics tools or third-party platforms, within legal limits.
7. Data Recipients and Data Transfers
Personal data may be disclosed, confidentially and only as necessary, to:
• Employees and collaborators of Alpine Ridge Solutions
• Service providers and contractual partners (transporters, payment processors, IT companies, security or accounting consultants)
• Public authorities, courts, tax authorities, regulators
• Third-party digital service providers (hosting, email, CRM, cloud, communication platforms)
• Independent consultants, auditors, insurers
Data is not sold or transferred for marketing purposes without explicit consent and is not transferred outside the EU/EEA except under legal conditions with appropriate safeguards.
8. Cookies and Tracking Technologies Policy
Details provided regarding:
• Types of cookies (necessary, analytics, marketing, third-party)
• Consent requirements and mechanisms
• User control over cookie preferences
8.1 Tipuri de cookie-uri utilizate
• Cookie-uri strict necesare/funcționale: esențiale pentru funcționarea site-ului, nu necesită consimțământ.
• Cookie-uri de analiză/performanță: colectează date agregate privind utilizarea site-ului (Google Analytics sau instrumente similare, doar cu consimțământ).
• Cookie-uri de marketing/personalizare: utilizate pentru afișarea de reclame sau comunicări comerciale targetate, exclusiv cu consimțământ.
• Cookie-uri de la terți: plasate de platforme externe (rețele sociale, furnizori plug-in-uri), doar cu consimțământ.
8.2 Mecanismul de informare și consimțământ
• La prima accesare a website-ului, utilizatorul va fi informat despre folosirea cookie-urilor și va avea opțiunea de a accepta sau respinge cookies-urile non-esențiale printr-un banner dedicat.
• Consimțământul trebuie să fie liber, specific, informat și neechivoc, obținut separat pentru fiecare categorie de cookie-uri opționale.
• Preferințele privind cookie-urile pot fi modificate oricând de utilizator din interfața website-ului.
8.3 Controlul asupra cookie-urilor
Utilizatorii pot administra preferințele privind cookie-urile direct din browser sau platformă, iar refuzul cookie-urilor non-esențiale nu afectează accesul la funcționalitățile de bază ale site-ului.
Pentru detalii complete, vă recomandăm să consultați Politica noastră de Cookie-uri disponibilă permanent pe site.
9. International Data Transfers
Alpine Ridge Solutions depune toate diligențele pentru a nu transfera datele cu caracter personal în afara Spațiului Economic European (SEE), cu excepția situațiilor în care acest lucru este necesar pentru furnizarea serviciilor (ex: parteneri IT, cloud, management contracte globale) sau atunci când este impus de lege.
Transfers outside the EEA occur only when necessary and under GDPR safeguards:
• Adequacy decisions
• Standard Contractual Clauses (SCC)
• Risk assessments and additional measures
• Explicit consent
The updated list of adequate countries is available from the European Commission.
10. Data Retention Period
Data is stored only as necessary, depending on legal and operational requirements:
• Consent-based data: until withdrawal
• Contractual data: duration of contract + legal archiving periods (3–5 years)
• Accounting/tax data: 5 years (invoices), up to 50 years (payroll)
• Security/audit data: up to 3 years
• Unselected job applications: up to 12 months
• Traffic/log data: up to 24 months
Criteriile și termenele exacte de ștergere sunt documentate în registrul intern al operatorului. După depășirea perioadelor de păstrare, datele sunt șterse, anonimizate sau arhivate cu acces restricționat.
11. Rights of Data Subjects
You benefit from all GDPR rights:
Operatorul vă garantează, în mod transparent și accesibil, următoarele drepturi:
1. Right to information
2. Right of access
3. Right to rectification
4. Right to erasure (“right to be forgotten”)
Excepții: date păstrate pe baza unei obligații legale, pentru apărarea drepturilor în justiție sau în interes public.
5. Right to restriction
6. Right to data portability
7. Right to object
8. Right not to be subject to automated decision-making
9. Right to withdraw consent
10. Right to lodge a complaint with ANSPDCP or competent EU authority
Requests are handled within one month (extendable by two months if necessary).
12. Consent and Documentation
Pentru orice prelucrare care nu are ca temei legal obligația contractuală, legală sau interesul legitim clar demonstrat, Alpine Ridge Solutions va solicita consimțământul dumneavoastră expres, liber, informat și specific, conform normelor GDPR.
Consent must be explicit, free, informed, and specific.
It may be withdrawn at any time.
Minors under 16 require parental/legal guardian approval.
• Lipsa consimțământului nu influențează accesul la funcționalitățile de bază ale platformei, unde acestea se bazează pe alte temeiuri legale.
• Niciodată nu veți fi supus automat proceselor decizionale pe bază de consimțământ, fără intervenție umană, cu excepția activităților de personalizare a comunicărilor de marketing, unde v-ați dat acordul explicit.
Consimțământul minorilor sub 16 ani necesită aprobarea părintelui/tutorelui legal, cu măsuri de verificare rezonabile.
13. Technical and Organizational Security Measures
Measures include:
• IT security (encryption, pseudonymization, firewalls, monitoring, updates)
• Controlled access (need-to-know, two-factor authentication)
• Backup and data recovery procedures
• Incident management and breach notification (within 72 hours)
• Staff training
• Regular auditing and testing
Operatorul revizuiește în mod regulat aceste măsuri și le actualizează pentru a minimiza riscurile de prelucrare neautorizată sau pierdere accidentală.
14. Multi-Jurisdictional Applicability in the EU
The Policy aligns with EU-wide GDPR requirements.
Alpine Ridge Solutions cooperates with ANSPDCP and relevant EU authorities.
Utilizatorii pot contacta autoritatea națională din România, precum și autoritățile sau rețelele de protecție a datelor din statul lor, iar Alpine Ridge Solutions cooperează cu Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) și cu orice autoritate din UE implicată.
15. Exceptions and Archiving Purposes
Exceptions may apply only under legal derogations, for:
• Legal retention requirements
• Public interest archiving, scientific or historical research
• Legal claims
Utilizatorii sunt informați proactiv atunci când astfel de excepții sunt aplicabile, cu explicarea motivelor și a drepturilor rămase.
16. Monitoring, Audit, and Policy Updates
The Policy is periodically updated according to legislation, technological changes, service modifications, or user feedback.
• Schimbările legislative la nivel UE sau național.
• Recomandările sau deciziile autorităților de reglementare (ANSPDCP, EDPB).
• Evoluții tehnologice, modificări ale serviciilor, introducerea de noi funcționalități sau fluxuri de prelucrare a datelor.
• Feedback-ul și observațiile utilizatorilor, incidentele de securitate și rezultatele auditurilor interne.
Orice modificare semnificativă este notificată utilizatorilor prin website sau email (după caz), iar politica actualizată este disponibilă la un link permanent pe site. Data ultimei revizuiri este specificată în antetul documentului.
17. National Supervisory Authority (ANSPDCP)
Romanian Data Protection Authority:
Address: Str. Olari nr. 32, Sector 2, Bucharest, postal code 024057
Tel: 021.252.55.99 / Fax: 021.252.57.57
E-mail: anspdcp@dataprotection.ro
Website: dataprotection.ro
Aveți dreptul să adresați orice plângere privind prelucrarea datelor către ANSPDCP sau către autoritatea competentă din statul membru UE de reședință.
18. Transparency, Information, and Updates
All relevant documents are available online in clear and accessible language.
Users are informed proactively about major changes.
• Orice prelucrare nouă sau modificare a funcționalităților va fi precedată de informare individuală proactivă (email, notificare în platformă).
• Operatorul răspunde tuturor solicitărilor privind informațiile detaliate despre fluxurile de prelucrare, destinatarii, perioada de păstrare și măsurile de securitate.
19. Contact
For any questions regarding the Privacy Policy, data protection, rights, or incident reporting:
E-mail: contact@alpinelogistics.ro
DPO: contact@alpinelogistics.ro
Phone: +40747869558
Adresa poștală: Bld Garii 2, Brasov, ROMANIA
Requests will be answered within 30 days, extendable by 60 days where justified.
20. Last Update Date
This Privacy Policy was last reviewed on [04 November 2025].
Annex: Defined Terms (Glossary)
• Personal data: any information relating to an identified or identifiable natural person
• Data subject: the natural person whose data is processed
• Controller: the entity determining purposes and means of processing
• Consent: freely given, specific, informed, and unambiguous indication of wishes
• DPO: responsabilul cu protecția datelor cu caracter personal (Data Protection Officer).
• Processing: any operation performed on personal data
• SCC: Standard Contractual Clauses (for international transfers)