Privacy Policy
Last updated: April 27, 2026
Data Controller
Record Keepers SRL (operating the "Cordo" store) respects your privacy and protects your personal data. For the purposes of the GDPR and applicable local laws, the Data Controller is Record Keepers SRL, registered in Romania. Our store runs on an e-commerce platform supplied by a third-party hosting provider, which gives us the online infrastructure needed to sell our products.
1. Personal Information We Collect
Contact & transaction data (name, billing/shipping addresses, email, phone, payment details) — to process orders; basis: performance of contract. Account data (username, password, history) — to manage your account; basis: contract and consent. Device & usage data (IP, browser, time zone, navigation) — for functionality, fraud prevention, analytics; basis: legitimate interests and consent for non-essential cookies. Marketing data — for newsletters and offers; basis: consent, withdrawable anytime.
2. How We Disclose Your Data
We do not sell your personal data. We share it only with trusted third parties to provide our services: our e-commerce hosting provider (to operate the store), payment processors (e.g. Stripe, PayPal), courier and fulfillment companies, and IT/cloud providers. We may disclose data to comply with legal obligations or valid requests from authorities.
3. Cookies
We use cookies to power the site and improve your experience. Essential cookies are necessary (e.g. keeping items in your cart). Non-essential cookies (analytics/marketing) are only placed with your explicit consent via our cookie banner.
4. International Transfers
Your data may be transferred and processed outside the EEA, specifically by certain of our hosting and service providers. In such cases we rely on recognized legal mechanisms (the European Commission's Standard Contractual Clauses or adequacy decisions).
5. Data Retention
Financial and order records: 10 years (Romanian tax law). Marketing data: until you withdraw consent. Account data: as long as your account is active; you may request deletion anytime.
6. Your Rights (GDPR)
You have the rights of access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and withdrawal of consent. To exercise them, contact us; we respond within 30 days. You may lodge a complaint with the Romanian DPA, ANSPDCP (dataprotection.ro).