Our Latest News

Privacy Policy and information on the processing of personal data

Last updated: 9 September 2026

In brief: MAR-INA processes only the data needed to operate the website, manage orders and enquiries, comply with legal obligations, ensure security and, only where the required consent has been given, perform analytics and marketing. The website includes an AI assistant; conversations are processed automatically and may involve the technical providers identified in this policy. Do not enter passwords, national identification numbers, full payment card details, medical information or other sensitive data in the chat.

1. About this policy

1.1. This Privacy Policy explains how MAR-INA PRODPREST SRL (“MAR-INA”, “we”, “us”) collects, uses, discloses, retains and protects the personal data of people who visit mar-ina.ro, create an account, save products, place an order, request a quotation, submit drawings or technical requirements, make a complaint, request a return or warranty service, publish a review, subscribe to commercial communications, use the AI assistant or otherwise interact with MAR-INA.

1.2. Personal data is processed in accordance with Regulation (EU) 2016/679 (the “GDPR”), Romanian Law No. 190/2018, Romanian Law No. 506/2004 on privacy in the electronic communications sector and other applicable legislation.

1.3. This policy provides information; it does not, by itself, constitute consent to processing. Where processing requires consent, we request it separately through a clear, specific and freely given action.

1.4. This policy applies to mar-ina.ro and to channels managed by MAR-INA. Third-party services, pages and platforms are also governed by their own privacy notices.

1.5. Related documents: the Cookie Policy and the Terms and Conditions.

2. Who is the data controller?

2.1. The controller of your personal data is MAR-INA PRODPREST SRL, with registered office at Str. Săliște No. 20, Galați, Galați County, Romania, registered with the Trade Register under No. J1994000383179, unique registration/VAT identification number RO 5202760.

2.2. For privacy questions or to exercise your GDPR rights, you may contact us as follows:

  • Email: office@mar-ina.ro
  • Telephone: +40 758 064 028 (Monday–Friday, 08:30–17:00, Romanian time)
  • Postal address: MAR-INA PRODPREST SRL, Str. Săliște No. 20, Galați, Galați County, Romania
  • Online form: the contact form available on the website

2.3. Privacy requests are handled through the contact details above. If MAR-INA appoints, or becomes legally required to appoint, a Data Protection Officer, the relevant contact details will be published here.

3. What personal data do we process?

3.1. The categories of data depend on how you interact with MAR-INA. We may process, as appropriate:

  • Identification data: first and last name and other information supplied where needed for a contract, invoice or request;
  • Contact data: email address, telephone number, delivery address and billing address;
  • Professional and business data: company name, position, tax/VAT number, registration number and other information needed for invoicing, quotations or a business relationship;
  • Customer account data: profile information, saved addresses, order history, wishlists and the technical data required for authentication and account security;
  • Order and contract data: requested products and services, quantity, price, discounts, delivery method, order status, transaction history and information needed to handle returns, complaints or warranties;
  • Payment data: payment method, amount, transaction status and technical transaction identifiers. Where payment is handled by an authorised payment provider, MAR-INA does not receive or store the full card number, CVV or PIN;
  • Commercial and technical enquiry data: the product or service sought, intended use, dimensions, materials, quantities, tolerances, delivery requirements and any sketches, drawings, photographs or technical documents you submit;
  • Communication data: messages sent by email, forms, telephone, messaging platforms or other channels, together with attachments;
  • Review data: displayed name or alias, rating, title, comment, product concerned and publication date; account data may be used to administer a review without being displayed publicly;
  • AI assistant conversation data: messages and replies, products or requirements mentioned, contact details or order references you choose to enter, language, date and time, session identifier, the page from which the chat was opened and technical logs needed for operation and security;
  • Technical and security data: IP address, device type, operating system and browser, online identifiers, access date and time, pages and features used, errors, suspicious activity and security logs;
  • Marketing preference data: subscription and unsubscribe choices, consents, objections and, within the limits of your choices, interaction with commercial messages;
  • Data collected through cookies and similar technologies: identifiers, session, cart and preference information and, where you have consented, data for analytics, conversion measurement and advertising.

3.2. We do not normally request identity document copies, full payment card details or special-category data. Do not submit such information, including via the chatbot or free-text fields, unless it is strictly necessary and you have received clear instructions from MAR-INA.

3.3. Technical documents may contain personal data, confidential information or trade secrets. Use the channel specified by MAR-INA for sensitive documents and remove information that is not needed for your request.

4. Where do we obtain the data from?

4.1. Most data is obtained directly from you, for example when you create an account, place an order, request a quotation, complete a form, publish a review, use the chatbot, send a document or subscribe to commercial communications.

4.2. We may also receive data from third parties or systems involved in our relationship with you, including:

  • marketplaces or platforms through which you place an order or submit an enquiry;
  • payment providers and financial institutions, regarding confirmation and status of transactions;
  • couriers, carriers and logistics providers, regarding delivery, incidents and returns;
  • technical providers involved in hosting, security, website analytics and operation of the AI assistant;
  • public sources or authorities, only where there is a legal basis and the data is needed for a defined purpose.

4.3. Data not obtained directly from you is used only for purposes compatible with the context in which it was obtained and in accordance with the applicable transparency obligations.

5.1. We do not use all data for every purpose. Processing is limited to the information needed for the specific purpose concerned.

Purpose Examples of data Main legal basis
Creating and managing an account and wishlist Name, email, telephone, addresses, authentication data, saved products Performance of a contract or steps requested before entering into a contract – Article 6(1)(b) GDPR
Receiving, confirming and fulfilling orders Identification and contact data, products, delivery address, order information Performance of a contract – Article 6(1)(b) GDPR
Processing payments and confirming transactions Amount, payment method, status and transaction identifiers Performance of a contract – Article 6(1)(b) GDPR and, where applicable, legal obligations – Article 6(1)(c)
Issuing and retaining accounting and tax records Billing and order data, invoices and supporting documents Compliance with a legal obligation – Article 6(1)(c) GDPR
Delivering products and handling transport incidents Name, telephone, address, parcel and order data Performance of a contract – Article 6(1)(b) GDPR
Returns, withdrawals, complaints, warranties and after-sales requests Contact and order data, issue description, photographs or documents Performance of a contract, legal obligations and, where appropriate, the legitimate interest in handling and documenting the request – Article 6(1)(b), (c) and (f) GDPR
Responding to questions, quotation requests and technical projects Contact details, specifications, dimensions, quantities, drawings and correspondence Pre-contractual steps requested by the individual – Article 6(1)(b) GDPR and/or legitimate interests – Article 6(1)(f), depending on the request
Operating the AI assistant, understanding the question, searching the catalogue and generating an answer Message, recent history, session identifier, product or request, technical data Legitimate interest in providing prompt and accessible assistance – Article 6(1)(f) GDPR; pre-contractual steps or contract performance – Article 6(1)(b), where the question concerns an offer or contract
Transferring a conversation to a human agent at your request and checking AI response quality Conversation, data strictly needed to resolve the request, feedback and logs Article 6(1)(b), (c) or (f) GDPR depending on the request; for quality control, legitimate interests with limited access and data minimisation
Publishing and administering product reviews Displayed name or alias, rating, title, comment and date Consent – Article 6(1)(a) GDPR, given by voluntarily submitting the review for publication after receiving notice
Preventing fraud and protecting the website, accounts, networks and chatbot IP, technical identifiers, logs, errors and suspicious activity Legitimate interests in protecting the business and users – Article 6(1)(f) GDPR and, where applicable, legal obligations – Article 6(1)(c)
Establishing, exercising or defending legal claims Contracts, orders, payments, correspondence, complaints and relevant logs Legitimate interests – Article 6(1)(f) GDPR and legal obligations, where applicable
Commercial communications and newsletters Name, email, telephone, preferences and evidence of the choice made Consent – Article 6(1)(a) GDPR; for existing customers and similar products or services, only under the conditions permitted by Romanian Law No. 506/2004, with a simple and free opt-out at collection and in every message
Audience measurement and analysis through non-essential technologies Online identifiers, device information, pages and usage events Consent – Article 6(1)(a) GDPR and Article 4(5) of Romanian Law No. 506/2004
Online advertising, remarketing and conversion measurement, including enhanced conversions where enabled Online identifiers, conversion events and, where applicable, normalised and cryptographically transformed contact details Consent – Article 6(1)(a) GDPR and Article 4(5) of Romanian Law No. 506/2004
Complying with authority requests and other legal obligations Data strictly needed to meet the obligation Compliance with a legal obligation – Article 6(1)(c) GDPR

5.2. Where we rely on legitimate interests, we assess necessity and proportionality and balance MAR-INA's interests against your interests, rights and freedoms. You may ask for further information about this assessment.

5.3. Where processing is based on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before withdrawal or processing supported by another valid legal basis.

6. What happens if you do not provide certain data?

6.1. Certain information is required to enter into or perform a contract or to comply with the law. Without sufficient contact and delivery data, we cannot dispatch an order; without mandatory billing details, we cannot issue the required tax documents.

6.2. Mandatory fields are identified in the relevant forms. We do not require data for marketing, analytics or other consent-based purposes as a condition of purchase or use of essential shop functions.

6.3. Use of the AI assistant is optional. You may ask general questions without identifying yourself and may contact MAR-INA directly by email, telephone or contact form. Identifying an order, resolving a request or arranging follow-up may require additional data and identity verification.

6.4. Publishing a review, subscribing to the newsletter and accepting analytics or marketing cookies are voluntary. Refusing or withdrawing consent does not prevent use of the essential shop functions.

7. Who may receive the data?

7.1. MAR-INA does not sell the personal data of customers or website visitors.

7.2. Data may be accessed or disclosed, to the extent necessary, to:

  • authorised MAR-INA personnel, according to their duties and access rights;
  • couriers, carriers, logistics providers and postal services;
  • payment processors, banks and institutions involved in transactions;
  • hosting, server administration, database, CDN, IT maintenance, software development, security and backup providers;
  • email, communications, customer support, invoicing, accounting and archiving providers;
  • marketplaces and platforms through which orders or enquiries are received or managed;
  • Merior AI, the technical provider of the chatbot solution, and authorised providers and subprocessors involved in hosting, operating and securing it;
  • OpenAI and its authorised subprocessors when its services are used to generate chatbot responses;
  • Google and relevant Google entities for tag management, analytics and advertising services described in Section 9, within the limits of the applicable consent and configuration;
  • lawyers, auditors, consultants and other professionals where access is necessary for their services;
  • public authorities, courts, regulators or other institutions where disclosure is required or permitted by law.

7.3. Where a provider processes data on MAR-INA's behalf, it receives documented instructions, is subject to confidentiality and security duties and must provide the guarantees required by Article 28 GDPR. Access is limited to the data and period needed for the service.

7.4. Certain entities, such as banks, payment processors, couriers, marketplaces and online platforms, may act as independent controllers for their own activities. Their own privacy notices also apply in those circumstances.

8. Transfers outside the European Economic Area

8.1. Some providers used for infrastructure, security, analytics, advertising or artificial intelligence form part of international groups. Certain data or metadata may therefore be processed outside the European Economic Area (“EEA”), including in the United States. Depending on the actual architecture and contracts, this may concern Google, OpenAI and their subprocessors.

8.2. International transfers are made in accordance with Chapter V GDPR. Depending on the recipient, a transfer may rely on a European Commission adequacy decision, including the EU–US Data Privacy Framework only for certified recipients and covered transfers, or on the European Commission's Standard Contractual Clauses together with appropriate supplementary measures, where required.

8.3. Selecting a European region for the storage or processing of a service does not automatically mean that all system data, metadata, support or security operations remain within the EEA.

8.4. You may request information about the mechanism applying to a particular transfer and how to obtain a copy of the relevant safeguards by emailing office@mar-ina.ro.

9. Cookies, local storage, analytics and online advertising

9.1. The website uses cookies and similar technologies for operation, security, consent management, sessions, the shopping cart, authentication and other user-requested features. Strictly necessary technologies are not used for behavioural advertising.

9.2. Non-essential technologies for analytics, conversion measurement, remarketing and advertising rely on consent. They must be configured so that non-essential storage or access to information on the device, and the related processing, do not begin before the appropriate choice is made in the consent panel.

9.3. You may change or withdraw your choices at any time through “Control your Privacy” in the website footer. Withdrawal must be as easy as giving consent.

9.4. The exact list of technologies, providers, purposes and lifetimes must be kept up to date in the Cookie Policy and consent panel.

9.5. Technical, analytics and advertising services

Service Provider Purpose Applicable rule
Google Tag Manager Google Technical management of tags and communication of consent choices It does not, by itself, authorise non-essential tags; the configuration must respect the user's choices
Google Analytics 4 Google Audience measurement and analysis of website use Consent for the “Statistics” category
Google Ads Google Conversion measurement, remarketing and advertising Consent for the “Marketing” category
AI assistant and Deep Chat library MAR-INA, Merior AI and the technical providers involved Displaying the chat, transmitting messages and maintaining conversation continuity User-requested functionality; local storage and session data are described in Section 9.7 and Section 16.5

9.6. Enhanced conversion measurement

9.6.1. If “enhanced conversions” is actually enabled and you have accepted the marketing category, certain details supplied during checkout, such as your email address, telephone number or limited address information, may be normalised and transformed using the SHA-256 cryptographic hash function before being sent to Google to match a conversion with an earlier advertising interaction.

9.6.2. These transformed details are not sent in plain text. Hashing does not, however, make them anonymous where they can be matched with information held by the recipient. They remain personal data and are covered by all safeguards in this policy.

9.6.3. This feature must not be used without marketing consent and must be disabled for future events when consent is withdrawn.

9.7. Local storage of AI assistant conversations

9.7.1. To maintain continuity, the chat component may keep a limited local history on your device. The current widget configuration allows up to 80 messages to be stored under the technical key chat_history_mar-ina.ro. Depending on your browser, this local copy may remain until it is overwritten, deleted by you, removed through browser settings or discontinued by a website update.

9.7.2. This copy on your device is separate from temporary server-side retention by the providers involved in the chatbot. Deleting browser history does not automatically delete server copies or a request already sent to a human agent; Section 10 and the rights procedure apply to those records.

9.7.3. If you use a shared device, end your session and delete the site's local data to prevent other users from viewing the history displayed in the browser.

9.8. Provider policies

For Merior AI, you may consult the provider's information about the use of AI and Privacy Policy. Further information on Google's own processing is available in the Google Privacy Policy. Information on the controls applicable to data sent through the OpenAI API is available in OpenAI's API data controls documentation. Those documents do not replace MAR-INA's obligations for processing carried out on its behalf.

10. How long do we retain the data?

10.1. Data is not retained longer than necessary. The period is determined by purpose, the duration of the relationship, legal obligations, limitation periods, the need to resolve requests and security risks.

10.2. We mainly apply the following periods and criteria:

  • Customer account data: while the account is active and, if inactive, for no more than three years after the last login or order, after which the account is deleted or anonymised, except for data that must be retained separately by law or to defend a claim;
  • Order and contract data: during performance and afterwards, generally for the three-year general limitation period, without affecting longer periods applying to specific documents or situations;
  • Accounting and supporting documents: under Romanian accounting and tax law; documents governed by Article 25 of Romanian Accounting Law No. 82/1991 are generally kept for five years calculated from 1 July of the year following the financial year in which they were prepared, unless a special rule requires a different period;
  • Returns, complaints and warranties: while the request is handled and generally for three years after closure, or longer where required by law or litigation;
  • Quotation requests, projects and correspondence: while needed to resolve the matter and for no more than three years afterwards; material with no contractual or evidential relevance is deleted sooner when no longer useful;
  • Reviews: while the product and review remain published or until consent is withdrawn or a deletion request is granted; minimal evidence of the request may be kept to defend legal claims;
  • Wishlist: while the account is active and until the product is removed by the user or the account is deleted;
  • Commercial communication data: until unsubscribe, withdrawal of consent or objection; evidence of the choice and a suppression list may generally be retained for three years to demonstrate compliance and prevent further messages;
  • Technical and security logs: generally for no more than 12 months, except records needed to investigate an incident, fraud, litigation or a legal duty;
  • Chatbot conversations in systems operated by MAR-INA and Merior AI: conversation content and technical session data for no more than 30 days, and indexed conversational context used to continue a recent conversation for up to seven days, under the approved configuration; these periods depend on active, monitored deletion mechanisms and do not replace the retention periods applied by the AI model provider, described below;
  • Data sent through the OpenAI API: under OpenAI's published standard controls, customer content may be included in abuse-monitoring logs retained for up to 30 days. The Responses API may also retain application state for at least 30 days under the default configuration or when the store parameter is enabled. The effective organisation and project controls, and the applicable contractual terms, may change these periods and must be reviewed periodically;
  • Conversations transferred to a human agent: necessary data becomes part of the enquiry, quotation, order, complaint or ticket and follows the retention period for that record rather than the chatbot's general period;
  • Locally stored chatbot history: up to 80 messages, until overwritten or deleted, as described in Section 9.7;
  • Cookie and similar-technology data: for the lifetime of each technology, as shown in the consent panel and Cookie Policy.

10.3. At the end of the applicable period, data is deleted, anonymised or archived in accordance with the law. It may be retained longer only where required by a legal duty, incident, investigation, litigation or the establishment, exercise or defence of legal claims.

11. Your data protection rights

11.1. Subject to the conditions and limits of the GDPR, you have the following rights:

11.1.1. Right of access

You may ask whether we process your data, obtain access to it and to the information required by the GDPR, and receive a copy of the personal data concerned.

11.1.2. Right to rectification

You may request correction of inaccurate data and completion of incomplete data.

11.1.3. Right to erasure

You may request deletion in the circumstances set out in Article 17 GDPR, including where data is no longer needed, consent is withdrawn and no other basis applies, or the data has been unlawfully processed. This right is not absolute; some data must be retained to meet legal duties or establish, exercise or defend legal claims.

11.1.4. Right to restriction

You may request restriction in the circumstances set out in the GDPR, including while the accuracy of data or an objection is being verified.

11.1.5. Right to data portability

Where Article 20 GDPR applies, you may receive data you supplied in a structured, commonly used and machine-readable format and request its transmission to another controller where technically feasible.

11.1.6. Right to object

Where processing relies on legitimate interests, you may object on grounds relating to your particular situation. We will stop unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the data is needed for legal claims.

You may object to direct marketing at any time, without giving a reason and at no cost. After your objection, the data will no longer be used for that purpose.

11.1.7. Right to withdraw consent

Where processing relies on consent, you may withdraw it at any time as easily as it was given. For cookies, use “Control your Privacy”; for newsletters, use the unsubscribe link in each message.

11.1.8. Rights concerning automated decisions

In the situations covered by Article 22 GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you, subject to legal exceptions.

11.1.9. Right to complain and seek a judicial remedy

You may lodge a complaint with a competent supervisory authority and use the judicial remedies provided by law. ANSPDCP contact details appear in Section 18.

12. How to exercise your rights

12.1. Send your request to office@mar-ina.ro, through the contact form or by post to the address in Section 2. State the right you wish to exercise and information enabling us to locate the data, without submitting more information than necessary.

12.2. To prevent disclosure to unauthorised persons, we may request additional information strictly needed to verify identity where we have reasonable doubts. For order or conversation data, merely knowing another person's name, telephone number, email address or order number does not establish a right of access.

12.3. We respond without undue delay and, in any event, within one month. Depending on complexity and the number of requests, this may be extended by up to two further months; we will notify you of the extension and reasons within the first month.

12.4. Exercising rights is generally free. For manifestly unfounded or excessive requests, particularly repetitive ones, we may take the measures permitted by the GDPR, including charging a reasonable fee based on administrative costs or issuing a reasoned refusal.

12.5. Certain choices can be managed directly: changing account and address data, removing wishlist items, unsubscribing through the link in a message and changing cookie preferences in the consent panel. These options do not limit your right to submit a request.

13. Children's data and special categories of data

13.1. The website, shop and chatbot are intended mainly for adults and business customers. MAR-INA does not seek to collect children's data and does not intentionally direct marketing to people it knows are minors.

13.2. Where Article 8 GDPR applies to an information-society service offered directly to a child and processing relies on consent, the relevant threshold in Romania is 16 years. Below that age, consent must be given or authorised by the holder of parental responsibility.

13.3. If you learn that a child has submitted data through the website or chatbot without the necessary legal conditions, notify us at office@mar-ina.ro. We will assess the situation and delete or restrict the data without undue delay where appropriate.

13.4. We do not normally request special categories of data under Article 9 GDPR or criminal-conviction and offence data. Do not enter health data, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, sex-life or sexual-orientation information in forms or the chatbot.

13.5. If we accidentally receive sensitive information that is not needed, we restrict access and take appropriate deletion or other handling measures according to the circumstances and legal obligations.

14. Automated decisions, profiling and AI recommendations

14.1. MAR-INA does not ordinarily make decisions based solely on automated processing that produce legal effects or similarly significantly affect an individual.

14.2. The AI assistant automatically generates answers and indicative recommendations using your message, catalogue information and MAR-INA rules. It is identified as an AI system, may make mistakes and is not a human agent. It does not automatically accept or reject orders, returns, warranties, complaints or data-subject requests and cannot legally bind MAR-INA.

14.3. Recommendations concerning products, metal fabrication or fire-safety equipment do not replace document checks, assessment of the actual circumstances and, where necessary, confirmation by an authorised specialist. Ask a MAR-INA human agent to verify important decisions.

14.4. Analytics and advertising tools may perform segmentation, measurement, personalisation or profiling in a broad sense, only in accordance with your choices. These activities are separate from decisions covered by Article 22 GDPR and can be stopped for the future by withdrawing consent.

14.5. Payment providers and other independent controllers may use their own fraud-prevention or automated assessment systems under their policies and legal duties. Where such an operator makes a relevant decision, it must provide the applicable notice.

15. Data security

15.1. MAR-INA applies technical and organisational measures appropriate to the risk to protect data against unauthorised access, loss, destruction, alteration or unlawful disclosure, taking account of the nature, purposes and context of processing and technological developments.

15.2. Depending on the system and risk, measures include access and permission controls, account protection, HTTPS encryption in transit, security updates, backups, logging, role separation, confidentiality obligations, incident-response procedures and limiting access to personnel and providers who need the data.

15.3. No information system can eliminate every risk. Do not provide unnecessary data, do not reuse passwords and do not disclose passwords, authentication codes, full card details or confidential documents through the chatbot.

15.4. If you suspect unauthorised account access or accidental disclosure, contact us immediately at office@mar-ina.ro.

16. Website features, modules and third-party services

16.1. The website may link to pages, social networks, marketplaces or services operated by third parties. When you access them, those operators may receive technical data and process information under their own policies. MAR-INA does not control their independent processing.

16.2. If you interact with MAR-INA through a social network, messaging platform or marketplace, both MAR-INA and the platform operator may process data for their own purposes and according to their respective roles. Review the platform's privacy information before submitting data.

16.3. Product reviews

16.3.1. Submitting a review is voluntary and is not a condition of purchasing from or using the shop.

16.3.2. The name or alias entered, rating, title, comment and date may become public on the product page and may be indexed by search engines. Do not publish contact details, order numbers or information about other people. Account data or an email address used for administration is not displayed as part of the review.

16.3.3. Publication is based on the consent given by submitting the review for publication after notice. You may withdraw consent and request deletion by emailing office@mar-ina.ro and identifying the product and displayed name so that we can locate the review.

16.3.4. MAR-INA may moderate or remove unlawful, abusive, duplicate or irrelevant content. Moderation does not itself prove a purchase; a review will not be presented as a “verified purchase” unless a real technical verification and appropriate notice are in place.

16.4. Customer account and wishlist

16.4.1. Your account enables you to manage details, addresses and orders. The wishlist stores products you mark for later and is linked to your account. You may remove products or request account closure; data that must be retained for orders, invoicing or legal claims remains in separate records for the applicable period.

16.4.2. Keep authentication details confidential and never send your password by email, form or chatbot. MAR-INA will not ask for your full password or CVV to verify your identity.

16.5. MAR-INA AI assistant

16.5.1. The chat window is an AI assistant, not a person. Messages are processed automatically, and a human agent does not necessarily monitor the conversation in real time. Use of the chat is optional.

16.5.2. Depending on the enabled features, the chatbot may search for products, provide explanations and indicative recommendations, consult information available to the system and prepare or transmit an enquiry to the team. It does not automatically confirm an order, take payment, decide a return or warranty claim, or provide order data without appropriate requester verification.

16.5.3. To provide the service, the message, answer, recent history, technical data and information you enter may be processed. The solution is technically provided through Merior AI and uses OpenAI services for language generation. These providers may access data only within the limits of the applicable services and contracts.

16.5.4. MAR-INA does not use conversations to train its own AI model and does not voluntarily authorise API content to be used to train the provider's models. This does not exclude temporary processing needed to provide and secure the service, prevent abuse or comply with law.

16.5.5. In systems operated by MAR-INA and Merior AI, conversations and session data are retained for no more than 30 days, and indexed conversational context for a recent conversation for up to seven days, as stated in Section 10. The local browser copy may contain up to 80 messages and has a different lifetime, as explained in Section 9.7. The AI model provider may apply its own retention periods, described separately in Section 10.

16.5.6. Do not enter passwords, authentication codes, national identification numbers, card details, medical information, third-party data or unnecessary trade secrets and technical drawings. Use the channel specified by a human agent for confidential technical documents.

16.5.7. If you ask to be contacted by a human agent, the information strictly needed from the conversation may be transferred into an email, ticket, quotation, order, complaint or other record. From that point, the purpose and retention period for that record apply.

16.5.8. For a data protection request, the chatbot may explain the procedure or transmit the request only if the system actually confirms that action. It cannot state that data has been erased, rectified or restricted before MAR-INA has verified and resolved the request.

17. Changes to this policy

17.1. This policy may be updated when legislation, website or chatbot features, providers, data flows, retention periods or MAR-INA activities change.

17.2. The current version and last-updated date are displayed at the beginning. If a change is significant and the nature of processing requires it, we will use reasonable means to notify affected individuals and, where necessary, request fresh consent.

18. Right to lodge a complaint

18.1. If you believe that the processing of your data infringes data protection law, you may contact the competent supervisory authority directly. You do not have to contact MAR-INA before lodging a complaint.

18.2. In Romania, the competent authority is:

THE NATIONAL SUPERVISORY AUTHORITY FOR PERSONAL DATA PROCESSING (ANSPDCP)

18.3. Without limiting your right to contact an authority or court, you may email office@mar-ina.ro with any question about MAR-INA's processing of personal data.