Privacy policy
NORDIC PRIME
Privacy Policy
Version 1.1
Last updated: 8 September 2026
1. About this Policy
This Privacy Policy explains how NORDIC CHOICE SRL, through its commercial division Nordic Prime, collects, uses, stores, transfers and protects the personal data of individuals who interact with the website www.nordicprime.ro, as well as with Nordic Prime products, services and commercial activities.
This Policy applies, as appropriate, to:
visitors to the website;
users who create an account;
individual customers;
customers and representatives of B2B companies;
individuals requesting a quotation;
individuals who contact Nordic Prime;
suppliers and their representatives;
manufacturers and prospective partners;
individuals submitting a request through the Become a Partner;
individuals involved in complaints, returns or other commercial relationships with Nordic Prime.
This Policy has been prepared in accordance with Regulation (EU) 2016/679 – GDPR, as well as applicable Romanian legislation on personal data protection and electronic communications.
2. Data Controller
The controller of personal data is:
NORDIC CHOICE SRL
CUI 51172035
Cod TVA: RO51172035
Trade Register No.: J2025004517000
EUID: ROONRC.J2025004517000
Registered office:
Mun. București, Str. Nicolae Caramfil no. 54, ground floor, Sector 1, Romania
Place of business:
13 Mizil Street, Iași, Romania
Website: www.nordicprime.ro
Contact
General contact and data protection:
office@nordicprime.ro
Sales / HoReCa / quote requests:
vanzari@nordicprime.ro;
Support / complaints:
suport@nordicprime.ro
Nordic Prime is the Food & Beverage commercial division of Nordic Choice SRL.
In this Policy, the terms “Nordic Choice”, “Nordic Prime”, “we”, “us” or “the Controller” refer, as appropriate, to NORDIC CHOICE SRL.
3. Data Protection Principles
We process personal data in accordance with the principles laid down in the GDPR:
lawfulness, fairness and transparency;
collection for specified, explicit and legitimate
data minimisation;
accuracy;
storage limitation;
integrity and confidentiality;
accountability of the Controller.
We collect only personal data that is reasonably necessary for the activities described in this Policy.
4. Personal Data We May Collect
The personal data we collect varies depending on how you interact with Nordic Prime.
4.1. Identification and Contact Data
We may process:
first name;
last name;
email address;
telephone number;
billing address;
delivery address;
other contact details provided by you.
4.2. Customer Account Data
If you create an account on the website, we may process:
your name;
email address;
saved addresses;
order history;
account information;
account preferences;
technical identifiers required for authentication and security.
Passwords are managed through secure technical mechanisms and are not available to Nordic Prime personnel in readable form.
4.3. Order Data
We may process:
products ordered;
quantities;
prices;
order value;
order date;
order status;
delivery address;
billing address;
delivery method;
payment method;
transaction identifiers;
information relating to returns, refunds or complaints.
Where payment is made through a specialised payment processor, Nordic Choice SRL does not normally receive full payment card details.
4.4. B2B Data
For customers, suppliers, distributors, manufacturers and commercial partners, we may process:
company name;
CUI / VAT ID;
registration number;
registered office;
places of business;
billing details;
bank account details, where necessary;
name of the representative;
job title;
business telephone number;
business email address;
contractual information;
history of the commercial relationship.
4.5. Quotation Requests and Forms
If you use:
the contact form;
Request a Quote;;
forms intended for HoReCa;
Become a Partner;;
collaboration forms;
other forms available on the website,
we may process the data entered in the form, together with any information or documents voluntarily submitted.
4.6. Manufacturer and Partner Data
For the purpose of assessing a potential collaboration, we may process, as appropriate:
representative details;
company details;
job title;
contact details;
product information;
portfolio;
brands;
certifications;
commercial documents;
production information;
logistics information;
commercial terms;
other information provided during the assessment and negotiation process.
4.7. Complaint Data
In the event of a complaint, we may process:
identification data;
contact details;
order number;
product details;
batch information;
photographs or documents provided;
correspondence;
information required to investigate the complaint.
4.8. Technical Data
When you use the website, certain information may be processed automatically, including:
IP address;
browser;
operating system;
device type;
date and time of access;
pages visited;
technical identifiers;
logs;
information relating to the security and operation of the website.
4.9. Cookies and Similar Technologies
The website uses cookies and similar technologies.
Details about the types of cookies used, their purposes and how consent is managed are available in:
Cookie Policy:
https://nordicprime.ro/politica-de-cookie-uri/
Cookies that are not strictly necessary are used only where an appropriate legal basis exists and, where applicable, after consent has been obtained.
5. Sources of Personal Data
Personal data may be obtained:
directly from the data subject;
from an account created on the website;
din comenzile plasate;
din formularele completate;
din corespondență;
de la societatea pe care persoana o reprezintă;
de la furnizori sau parteneri;
de la operatori implicați într-o comandă sau livrare;
din surse profesionale publice, în cazul relațiilor B2B, atunci când utilizarea acestora este justificată și legală;
automat, prin infrastructura site-ului.
Dacă datele nu sunt colectate direct de la persoana vizată, aceasta va fi informată conform art. 14 GDPR atunci când această obligație este aplicabilă.
6. Why We Process Personal Data
| Purpose | Main Categories of Data | Legal Basis |
|---|---|---|
| Creating and managing an account | identification, contact, account | performance of a contract / pre-contractual steps |
| Processing orders | identification, order, billing, delivery | performance of a contract |
| Processing payments | transaction data | performance of a contract and legal obligations |
| Billing and accounting | identification, tax data, order | legal obligation |
| Delivery | name, telephone number, address, order | performance of a contract |
| Quotation requests | contact data, professional data, request | pre-contractual steps |
| B2B relationships | contact details, company, portfolio, documents | contract, pre-contractual steps and/or legitimate interests |
| Become a Partner; | contact, companie, portofoliu, documente | pre-contractual steps and/or legitimate interests |
| Complaints and returns | identification, order, product, correspondence | contract, legal obligation and/or legitimate interests |
| Food safety and traceability | order, batch, customer, delivery | legal obligation and/or legitimate interests |
| Website security | IP address, logs, technical data | legitimate interests |
| Fraud prevention | order, transactions, technical data | legitimate interests |
| Protection of our rights | contractual data and correspondence | legitimate interests |
| Direct marketing | contact details and preferences | consent or, where permitted by law, another valid legal basis |
| Non-essential cookies | online identifiers | consent, where required |
7. Orders and Contracts
Order-related data is used for registering and confirming orders; checking product availability; preparing and processing orders; billing, payment and delivery; communicating with customers; handling any issues; returns and refunds; fulfilling contractual obligations.
The primary legal basis is Article 6(1)(b) GDPR – performance of a contract..
8. Customer Account
If an account is created, data is used for authentication; account management; displaying order history; saving addresses; simplifying future orders; managing requested services.
Users are responsible for maintaining the confidentiality of their login credentials.
9. B2B Relationships
Nordic Prime conducts commercial relationships with HoReCa businesses, retailers, distributors, traders, manufacturers, suppliers and other professional partners.
We may use the professional data of representatives of these organisations for responding to enquiries; presenting products; preparing quotations; negotiations; managing the commercial relationship; contracting; logistics; billing and support.
Where processing is based on legitimate interests, we take into account the professional nature of the relationship, the nature of the data and the reasonable expectations of the data subject.
10. Become a Partner
Data submitted through a partnership request may be used for assessing the company; evaluating products and the commercial opportunity; preliminary checks; requesting additional information; negotiations; preparing a potential contractual relationship.
Submitting a request does not constitute automatic acceptance of a collaboration and does not create any obligation for Nordic Choice SRL to enter into a contract.
11. Payments
Electronic payments may be made through specialised payment service providers. Data strictly necessary to complete the transaction may be transmitted to the selected provider.
The provider may have its own legal obligations relating to fraud prevention; financial services; transaction security; payment verification; record keeping.
This Policy will be updated when a specific payment processor becomes operational and identifying that processor is relevant to transparency regarding the processing of personal data.
12. Billing and Accounting
Necessary data may be used for issuing invoices; maintaining accounting records; tax reporting; transmitting documents through applicable tax systems; archiving financial and accounting documents; complying with the legal obligations of Nordic Choice SRL.
We may use specialised billing and accounting service providers.
13. Delivery and Logistics
For the purpose of fulfilling an order, we may disclose necessary data to couriers, carriers, logistics operators, warehouse operators and suppliers involved in preparing or delivering products.
Only the data necessary to provide the relevant service is disclosed.
14. Food Safety and Traceability
Given the nature of Nordic Prime's activities, certain data may be processed for product traceability; identifying batches and recipients of certain products; investigations relating to food quality or safety; product withdrawals or recalls; communicating food safety incidents; complying with obligations towards competent authorities.
In such cases, the retention and use of certain data may be mandatory even after the commercial relationship has ended.
15. Complaints, Returns and Refunds
Data may be used for registering complaints; verifying orders; identifying products and batches; investigating the matter; communicating with customers; replacing products; issuing refunds; resolving disputes; protecting the rights of Nordic Choice SRL.
For the applicable commercial terms, please refer to:
Refund and Returns Policy:
https://nordicprime.ro/politica-de-rambursari-si-returnari/
16. Direct Marketing
We may use contact details to send commercial communications only where a valid legal basis exists and in compliance with applicable legislation on personal data protection and electronic communications.
Where the law requires prior consent, commercial communications will not be sent before such consent has been obtained. Where the law permits communications to be sent without separate prior consent, the data subject will be provided with a clear, simple and free means of objecting to such communications.
Consent may be withdrawn at any time. Withdrawal does not affect orders, the account, communications necessary for the performance of a contract, or the lawfulness of processing carried out before withdrawal.
The data subject may object at any time to the processing of their data for direct marketing purposes.
17. Legitimate Interests
In certain situations, we process data on the basis of the legitimate interests of Nordic Choice SRL, including managing B2B relationships; website security; fraud and abuse prevention; protecting the company and its assets; handling complaints; managing disputes; protecting legal rights; professional communications; business continuity.
Where necessary, we assess whether our legitimate interests are proportionate and whether the interests, rights and fundamental freedoms of the data subject override those interests.
18. Recipients of Personal Data
Depending on the relevant activity, data may be disclosed to hosting, IT, website infrastructure, e-commerce, email, payment and billing service providers; accountants, auditors, consultants and lawyers; couriers, carriers, logistics operators and warehouse operators; suppliers and manufacturers, where necessary; tax, veterinary and food safety, consumer protection, judicial and supervisory authorities; courts and other entities where disclosure is required by law.
Nordic Choice SRL does not sell or rent personal data to third parties for the purpose of commercialising such data.
19. Service Providers and Their Roles
Depending on the service provided, an external provider may act as:
Processor – where it processes personal data on behalf of Nordic Choice SRL and in accordance with our instructions. Where required by the GDPR, we use contractual terms compliant with Article 28 GDPR.
Independent Controller – where the provider determines its own purposes and means of processing for certain operations, particularly where it is subject to its own legal obligations.
Joint Controller – where the purposes and means of processing are jointly determined with another entity, with the respective responsibilities established in accordance with Article 26 GDPR.
The legal classification depends on the activities actually carried out, not merely on the contractual terminology used by the parties.
20. Services and Technical Infrastructure
The website uses technical solutions for content management; e-commerce; forms; cookie consent management; website translation; performance and caching; security; hosting and email.
The use of a provider within the website infrastructure does not mean that it automatically receives all Nordic Prime data. Access is limited, as far as reasonably possible, to what is necessary to provide the relevant service.
21. Transfers Outside the European Economic Area
Certain providers may process data or operate infrastructure located outside the European Economic Area.
Where an international transfer of personal data takes place within the meaning of the GDPR, we use, as appropriate, the mechanisms provided for under Chapter V GDPR, including adequacy decisions adopted by the European Commission; Standard Contractual Clauses; other appropriate safeguards provided for under applicable law.
Where necessary, additional data protection measures may also be assessed and implemented.
Further information regarding applicable safeguards and, where relevant, how to obtain a copy may be requested at:
22. How Long We Retain Personal Data
We do not retain data for longer than necessary for the purposes for which it was collected, except where applicable law requires or permits a longer period.
Customer account: for the duration of the account and thereafter where applicable legal obligations or legitimate interests exist; Orders: for the duration of the contract and thereafter in accordance with legal obligations and applicable limitation periods; Invoices and financial/accounting documents: in accordance with applicable tax and accounting legislation; Quotation requests: for the duration of negotiations and thereafter for as long as a justified commercial purpose exists; B2B relationships: for the duration of the commercial relationship and thereafter for as long as retention remains legally justified; Become a Partner: for the duration of the assessment and negotiations and thereafter where a justified commercial interest exists; Complaints and returns: until resolution and thereafter within the applicable legal limitation periods; Traceability data: in accordance with legal obligations relating to food safety and traceability; Consent-based marketing: until consent is withdrawn or the purpose ceases; Technical logs: for as long as reasonably necessary for operation, security and incident investigation.
At the end of the applicable retention period, data is, as appropriate, deleted, anonymised or archived where a legal obligation or another valid legal basis applies.
23. Data Security
Nordic Choice SRL implements technical and organisational measures appropriate to the risks associated with processing, which may include HTTPS and encryption of communications; access controls and authentication; restrictions on access rights; software updates; backups; security measures applied to hosting services; account protection; anti-fraud measures; technical monitoring; security incident procedures.
Although we implement measures appropriate to the identified risks, the absolute security of information systems cannot be guaranteed.
24. Data Protection by Design and by Default
When developing or modifying processes, services or functionalities involving the processing of personal data, we seek to apply the principles of data protection by design and by default – privacy by design and privacy by default.
Depending on the risk, measures may include data minimisation; limiting access and retention periods; privacy-friendly default settings; assessing service providers; additional security measures.
Where required by applicable law, a Data Protection Impact Assessment – DPIA may be carried out.
25. Personal Data Breaches
In the event of a personal data breach, Nordic Choice SRL assesses the incident; limits its effects; documents it; assesses the risk to affected individuals; makes the notifications required by the GDPR.
Where the conditions of Article 33 GDPR are met, the competent supervisory authority will be notified without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where the breach is likely to result in a high risk to the rights and freedoms of natural persons, affected individuals will be informed in accordance with Article 34 GDPR.
26. Special Categories of Personal Data
As a general rule, Nordic Prime does not request special categories of personal data, including data concerning racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data used for the purpose of uniquely identifying a person; health data; a person's sex life or sexual orientation.
Please do not provide such information unless it is strictly necessary in a specific situation and an appropriate legal basis exists for its processing.
27. Personal Data Relating to Minors
The Nordic Prime website and services are not specifically intended for minors.
We do not seek to intentionally collect data from children in relation to commercial activities for which they cannot legally enter into a contract or provide valid consent.
If products subject to statutory age restrictions are introduced, Nordic Choice SRL may implement additional verification procedures.
28. Automated Decision-Making and Profiling
As of the date of this Policy, Nordic Choice SRL does not use decision-making processes based solely on automated processing, including profiling, that produce legal effects concerning an individual or similarly significantly affect that individual.
If such technologies are introduced, this Policy will be updated and data subjects will be provided with the information required under the GDPR.
29. Rights of the Data Subject
Subject to the conditions laid down in the GDPR, you have the following rights:
Right of access: you may request confirmation as to whether we process personal data concerning you and may obtain access to that data.
Right to rectification: you may request the correction of inaccurate personal data and the completion of incomplete personal data.
Right to erasure: you may request the erasure of personal data in the circumstances provided for under the GDPR. This right is not absolute and may be limited, for example, by legal retention obligations.
Right to restriction of processing: you may request the restriction of processing under the conditions provided for by the GDPR.
Right to data portability: for certain processing activities, you may request to receive your personal data in a structured, commonly used and machine-readable format and, where possible, to have that data transmitted to another controller.
Right to object: you may object to processing based on legitimate interests on grounds relating to your particular situation.
Direct marketing: you may object at any time to the use of your personal data for direct marketing, and your personal data will no longer be processed for this purpose.
Withdrawal of consent: where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
Automated decision-making: in the circumstances provided for under Article 22 GDPR, you may have the right not to be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
Information about the source of the data: where the data has not been obtained directly from you and the information obligation applies, you may receive information about the source or the category of the source.
Right to lodge a complaint: you may lodge a complaint with the competent personal data protection authority.
30. How to Exercise Your Rights
Requests relating to personal data protection may be sent to [office@nordicprime.ro](mailto:office@nordicprime.ro)
Please describe your request clearly enough to allow us to identify the data and processing activities to which it relates. To protect your data, we may request additional information that is reasonable and necessary to verify the identity of the person making the request.
We will respond within the time limits laid down in the GDPR. The exercise of your rights is, in principle, free of charge. Where requests are manifestly unfounded or excessive, particularly because of their repetitive nature, Nordic Choice SRL may take the measures permitted under the GDPR.
31. Supervisory Authority
In Romania, the competent authority is the National Supervisory Authority for Personal Data Processing – ANSPDCP.
Data subjects may lodge a complaint with ANSPDCP if they consider that their data is being processed in breach of applicable law. This right does not affect the possibility of pursuing other administrative or judicial remedies.
32. Cookies and Consent Management
Nordic Prime uses a consent management mechanism for cookies and similar technologies.
Depending on the services in use, users may accept or reject non-essential cookies; select specific categories; save their preferences; change their choices later; withdraw consent.
Cookies that are strictly necessary for the operation of the website may be used without consent where permitted by applicable law.
For complete information:
Cookie Policy
https://nordicprime.ro/politica-de-cookie-uri/
33. Links to External Services
The website may contain links to manufacturers, suppliers, partners, social media platforms, external services and other websites.
When a user leaves nordicprime.ro and accesses a service operated by a third party, the processing of data is governed by that operator's own policies and terms.
Nordic Choice SRL does not control processing activities carried out independently by those operators.
34. Changes to this Policy
This Policy may be updated to reflect changes in legislation or to the website; new products, services, functionalities, payment methods or service providers; changes to logistics processes or to the way data is used.
The date of the most recent update is stated at the beginning of this document.
Where changes are significant and applicable law requires additional notice, we will use appropriate means to inform affected individuals.
35. Related Documents
This Policy should be read together with:
Nordic Prime Terms and Conditions
https://nordicprime.ro/termeni-si-conditii/
Cookie Policy
https://nordicprime.ro/politica-de-cookie-uri/
Refund and Returns Policy
https://nordicprime.ro/politica-de-rambursari-si-returnari/
These documents govern additional aspects of the relationship between Nordic Choice SRL, Nordic Prime and users of the website.
36. Language of this Policy
This Policy may be made available in several languages.
In the event of any discrepancy between the Romanian-language version and a translation, the Romanian-language version shall prevail to the extent permitted by applicable law.
This provision does not limit any mandatory rights granted to data subjects under applicable law.
37. Contact
For any questions regarding personal data protection:
NORDIC CHOICE SRL – NORDIC PRIME
Registered office: Mun. București, Str. Nicolae Caramfil no. 54, ground floor, Sector 1, Romania
Place of business: Str. Mizil no. 13, Iași, Romania
CUI: 51172035
VAT ID: RO51172035
Trade Register No.: J2025004517000
EUID: ROONRC.J2025004517000
Protecția datelor / contact general: office@nordicprime.ro
Vânzări / HoReCa / oferte: vanzari@nordicprime.ro;
Support / complaints: suport@nordicprime.ro
Website: www.nordicprime.ro