Privacy Policy
Last updated: 28 August 2026
Version 2.0 — replaces version 1.0 of 6 November 2025.
1. Introduction
This Privacy Policy describes how S.C. MASAT DIGITAL S.R.L. (“the Company”, “We” or “MASAT”), through the website www.masat.ro and the application https://app.masat.ro, collects, uses and protects personal data.
The Company complies with Regulation (EU) 2016/679 (GDPR) and national data protection legislation.
2. Data Controller
Name: S.C. MASAT DIGITAL S.R.L.
Trade Registry No.: J2025066544008
Tax ID (CUI): 52437661
Registered Office: Ilfov County, Bragadiru, 59 Ghidiceni Street
E-mail for data protection matters: office@masat.ro
3. Who this policy applies to
- visitors to www.masat.ro;
- Users of the MASAT Application (representatives of eMAG sellers);
- people who contact us by e-mail, forms or support channels;
- participants in the affiliate programme.
4. Our two roles: controller and processor
It is important to distinguish between two different situations.
a) MASAT is the CONTROLLER for the data we collect directly from you as a user of the platform: account data, billing data, support data, traffic data and marketing communications. This Policy describes that processing.
b) MASAT is a PROCESSOR for the personal data held in your eMAG seller account which we retrieve on your behalf — in particular the data of your end customers contained in orders (name, delivery address, telephone, e-mail, order details). For that data you are the controller and we act solely on your instructions.
The second situation is governed by the Data Processing Agreement (DPA), which you accept when you create your account.
5. What data we collect and why (MASAT as controller)
Account identification data — first name, last name, e-mail, password (stored as a hash). Purpose: creating and administering your account. Legal basis: performance of the contract, Art. 6(1)(b).
Company data — company name, tax ID (CUI), trade registry number, billing address, representative. Purpose: invoicing and issuing tax documents. Legal basis: legal obligation, Art. 6(1)(c), and performance of the contract, Art. 6(1)(b).
Payment data — the last four digits of the card, transaction history, Stripe customer ID. Full card details are handled exclusively by Stripe (PCI-DSS); MASAT never sees or stores them. Legal basis: performance of the contract and legitimate interest in fraud prevention.
Application usage data — actions in the application, features used, access logs. This also includes product analytics and session recordings of how the application is used, collected through PostHog. Recordings help us find bugs and improve the interface; they are not used to monitor individual people, and you can ask us to exclude your account from recording by writing to office@masat.ro. Purpose: operating the service, support, security and product improvement. Legal basis: performance of the contract and legitimate interest.
Technical and traffic data — IP address, browser type, operating system, cookie identifiers. Purpose: security, abuse prevention and analytics. Legal basis: legitimate interest, and consent for non-essential cookies.
Support data — the content of your messages and attachments. Legal basis: performance of the contract.
Marketing data — e-mail, preferences, newsletter interactions. Legal basis: consent, or legitimate interest for existing customers, with a right to object at any time.
Affiliate programme data — identification data, affiliate code, conversions, commission payment details. Legal basis: performance of the contract.
eMAG integration credentials — the username and password of your eMAG seller account. The eMAG API requires these for authentication; there is no alternative mechanism. Legal basis: performance of the contract. See Section 6.
6. Your eMAG credentials
To connect your seller account, the eMAG API requires the username and password of that account, together with the addition of our partner IP address in your eMAG panel, under My Account → Profile → Technical details. This is the mechanism imposed by eMAG, not a design choice on our part.
How we handle those credentials:
- they are encrypted in transit and at rest and stored separately from application data, with encryption keys managed independently;
- they are not visible in clear text to MASAT personnel and do not appear in logs, reports, exports or support tickets;
- access is restricted to a small number of technical staff, for maintenance purposes only, and every access is logged;
- they are used exclusively to connect to your own account and are never used to access any other seller’s data.
Read-only operation. MASAT retrieves and displays data. It does not create, modify or delete anything in your eMAG account.
You can disconnect the integration at any time from the Integrations section of the application. After disconnection, the credentials and associated data are deleted within a maximum of 30 days, or immediately on written request. We also recommend regenerating your eMAG password and removing the partner IP address from your technical settings.
7. How we use the data
- to provide access to the MASAT platform;
- to process payments and issue invoices;
- to establish and maintain the connection to your eMAG account;
- to generate listing suggestions and images through the Listing Optimizer (see Section 9);
- to provide technical support;
- to prevent fraud, abuse and unauthorised access;
- to send administrative communications and, with your consent, commercial ones;
- to improve the product, including through aggregated and anonymised statistics.
8. Sub-processors and service providers
We do not sell your data. We disclose it only to providers who help us deliver the service, under contract and subject to confidentiality obligations. The current providers are:
- Amazon Web Services — hosting of the application and databases, EU region;
- Stripe Payments Europe, Ltd. — payment processing;
- OpenAI — text generation in the Listing Optimizer;
- Google — image generation in the Listing Optimizer (Gemini models) and the YouTube videos embedded on our website;
- Nitrosend — e-mail marketing and newsletters;
- FirstPromoter — administration of the affiliate programme (referral tracking, commissions);
- PostHog — product analytics and session recording inside the application;
- Meta Platforms Ireland Ltd. — advertising campaign measurement (Meta Pixel);
- Public authorities — only where required by law.
The up-to-date list, with each provider’s role and place of processing, is published at masat.ro/sub-processors. We announce any change at least 30 days in advance, by e-mail and on that page. You may object; if your objection makes it impossible for us to provide the service, you may terminate with a refund of the unused period.
9. Use of artificial intelligence
The Listing Optimizer uses artificial intelligence models to generate suggestions for titles, descriptions, keywords and product images:
- text suggestions are generated using OpenAI models;
- product images are generated using Google image models;
- the content sent to these providers is limited to product data. No personal data of your end customers is sent to them.
- generated results are indicative and must be checked by you before publication;
- content generated automatically is marked as such in the interface.
MASAT does not take automated decisions producing legal or similarly significant effects concerning you, within the meaning of Art. 22 GDPR.
10. How long we keep data
- Account and usage data — for as long as the account is active, plus 30 days after deletion.
- Invoices and accounting records — 10 years, as required by Romanian Accounting Law no. 82/1991 and the Fiscal Code.
- eMAG credentials — for the duration of the active integration, plus a maximum of 30 days.
- Data retrieved from eMAG — for the duration of the active integration, plus a maximum of 30 days.
- Order data, including end-customer data — according to your instructions as controller; see the DPA.
- Security and access logs — 12 months.
- Support correspondence — 24 months after the ticket is closed.
- Marketing data — until consent is withdrawn, plus 30 days.
- Records of consent — 3 years after withdrawal, as evidence.
Important. Deleting your account does not delete documents we are required by law to keep, principally invoices and accounting records. These remain archived, with restricted access, solely for the purpose of meeting our legal obligations.
11. Data security and incidents
We apply appropriate technical and organisational measures, including: encrypted HTTPS/TLS connections and encryption of sensitive data at rest (AES-256); storage of integration credentials separately from application data, with independently managed keys; role-based access control following the principle of least privilege, with logging of administrative access; two-factor authentication for internal team access; regular encrypted backups with tested restore procedures; and servers located in the European Union.
Incident notification. In the event of a personal data breach that may affect your rights, we will notify you without undue delay and within 72 hours at most of becoming aware of it, and we will notify the Romanian supervisory authority (ANSPDCP) in accordance with Art. 33 GDPR. Our notification will describe the nature of the incident, the data affected, the likely consequences and the measures taken.
If an incident affects eMAG integration credentials, we will notify you within 24 hours, invalidate the stored credentials, suspend the affected integrations and recommend that you change your eMAG password immediately.
You can report a vulnerability or a suspected incident to office@masat.ro.
12. Transfers outside the European Union
Data is stored and processed within the European Union. Certain providers (Stripe, Google, Meta, OpenAI) may process data in the United States; in those cases the transfer is based on the Standard Contractual Clauses approved by the European Commission and/or the EU–US Data Privacy Framework, with supplementary measures where necessary.
You may request a copy of the applicable safeguards at office@masat.ro.
13. Your rights under the GDPR
- Right of access — to find out what data we hold about you;
- Right to rectification — to correct inaccurate data;
- Right to erasure (“right to be forgotten”), within the limits of our legal archiving obligations;
- Right to restriction of processing;
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format;
- Right to object to processing based on legitimate interest, and at any time and without justification to direct marketing;
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing;
- Right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects.
To exercise your rights, write to office@masat.ro. We respond within 30 days, a period which may be extended by a further two months for complex requests, with notice to you.
14. Cookies
The website and the application use cookies. Full details, including the list of cookies and their duration, are in the Cookie Policy. You can change or withdraw your consent at any time through the preferences banner accessible from the website footer.
15. Complaints
If you believe your rights have been infringed, please write to us first at office@masat.ro. You also have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest — www.dataprotection.ro.
16. Changes to this Policy
We update this Policy periodically. For substantial changes we will notify you by e-mail and in the application 30 days in advance. The date of the last revision appears at the top of the document. Previous versions are available on request.
17. Contact
S.C. MASAT DIGITAL S.R.L.
Ilfov County, Bragadiru, 59 Ghidiceni Street
E-mail: office@masat.ro
www.masat.ro