Privacy policy
This policy explains what personal data this site collects, why, who we share it with and what rights you have. It describes exactly what the site does today — it is not a generic template.
Last updated:
1. Who the controller is
The data controller is Asociația pentru Inovație Digitală și Cercetare în Inteligență Artificială (AIDCIA), a Romanian non-profit legal entity, tax identification number 55535770.
For any question about your personal data, or to exercise the rights described below, you can contact us through the contact form on this site.
The association is not legally required to appoint a data protection officer, as it does not process data on a large scale and carries out no systematic monitoring. Requests are handled directly by the Board of Directors.
2. The principles we process data by
- Minimisation: we ask only for the data without which your request cannot be handled. Our forms contain no fields \u201cjust in case\u201d.
- Specified purpose: every item of data we collect has a purpose declared in the table below, and is not used for anything else.
- No profiling: we do not build behavioural profiles, we do not track visitors across sites, and we take no automated decisions producing legal effects on anyone.
- No selling: we do not sell, rent or trade personal data with anyone.
- Limited retention: data is deleted when the periods in the table expire, not \u201cwhen we remember\u201d.
3. What we collect, why and for how long
We collect only the data you enter into a form. The site uses no analytics, tracking pixels or profiling.
| Processing | Data | Legal basis | Retention |
|---|---|---|---|
| Newsletter subscription | Email address, optionally your name; IP address, date and time of consent and the consent text | Consent (Art. 6(1)(a) GDPR) | Until you unsubscribe. Proof of consent is kept for a further 12 months afterwards. |
| Contact form | Name, email, optionally phone and organisation, subject, message, IP address, user agent | Legitimate interest in replying to your request (Art. 6(1)(f) GDPR) | 24 months from the last exchange. |
| Membership application | Name or organisation name, applicant type, email, optionally phone, field of expertise, form of involvement, motivation | Steps prior to entering into a membership relationship (Art. 6(1)(b) GDPR) | 36 months, or for the duration of membership. |
| Partnership proposal | Name, organisation, email, optionally phone, proposal type, description | Legitimate interest in assessing the proposal (Art. 6(1)(f) GDPR) | 36 months from the last exchange. |
| Job application | The data you voluntarily include in your message | Steps prior to entering into a contract (Art. 6(1)(b) GDPR) | 12 months after the selection ends, unless you ask for deletion sooner. |
| Financial support | Name, email, amount; for organisations: name, tax number, registration number and address, required for the invoice | Performance of the payment (Art. 6(1)(b)) and the legal obligation to issue and archive accounting documents (Art. 6(1)(c)) | As required by law for accounting records. |
| Admin panel | Administrator email address, action log, session IP address | Legitimate interest in application security (Art. 6(1)(f) GDPR) | 12 months for the action log; sessions expire after 7 days. |
IP addresses are retained in two situations: as proof of consent when subscribing, and to rate-limit form submissions from one source as anti-spam protection. We do not use them to identify or track visitors.
4. Payment data
Payments are processed entirely by Stripe. Card details are entered on Stripe's secure page and never reach our servers. We receive only the payment confirmation, the amount and the data needed to issue the invoice.
To issue the invoice, the billing data is passed to our invoicing provider. An invoice is an accounting document and is archived for the legally required period, independently of any deletion request — the legal obligation prevails over the right to erasure in this specific case.
5. Who we share data with
We do not sell or rent personal data. We pass it only to the providers we need in order for the services above to work, each as a processor under a data processing agreement:
| Provider | Role | Data shared | Location |
|---|---|---|---|
| Brevo (Sendinblue SAS) | Sending email and managing the newsletter | Email address, name, the content of messages sent | European Union (France) |
| Stripe Payments Europe, Ltd. | Payment processing | Name, email, amount, card details (directly, not through us) | European Union (Ireland) |
| Oblio Software SRL | Issuing invoices | Billing data and amount | Romania |
| Hetzner Online GmbH | Hosting the server and the database | All data stored by the site | Germany |
All providers are located in the European Union. We make no transfers of data outside the European Economic Area. If that changes, we will update this page before any transfer and state the safeguards applied.
Data may be disclosed to public authorities only at their express request and only to the extent the law provides.
6. Your rights
Under Regulation (EU) 2016/679 you have the following rights:
- right of access: you can find out what data we hold about you and receive a copy;
- right to rectification: you can ask us to correct inaccurate data or complete incomplete data;
- right to erasure (\u201cthe right to be forgotten\u201d), except for data the law requires us to keep;
- right to restriction of processing;
- right to data portability: you can receive your data in a structured, commonly used format;
- right to object to processing based on legitimate interest;
- right to withdraw consent at any time, without affecting the lawfulness of prior processing;
- right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), based in Bucharest.
To exercise any right, write to us through the contact form on this site. We reply within 30 days at most; if the request is complex we tell you within that period and extend it by no more than two months, explaining why. Exercising your rights is free of charge.
Unsubscribing from the newsletter takes one click from the footer of any message you receive — without contacting us and without giving a reason.
7. Data security
- All traffic is encrypted with HTTPS, with HSTS enabled.
- Admin account passwords are stored hashed with Argon2id, never in plain text.
- The database is not reachable from the internet; it talks only to the application, on the server's internal network.
- Access to the admin panel is limited to named accounts, with action logging and automatic lockout after repeated failed sign-ins.
- Forms are protected by rate limiting and anti-spam measures.
- Outgoing email is logged without content: we keep the recipient, the template and the provider's identifier, not the message text.
In the event of a security breach posing a risk to individuals' rights, we notify the supervisory authority within 72 hours and, where the risk is high, inform the affected individuals directly.
8. Children's data
This site's services are not directed at children under 16 and we do not knowingly collect their data. If we learn that we have received such data without a parent's or guardian's consent, we delete it.
9. Changes to this policy
If we change how we process data, we update this text and the date at the top of the page. Significant changes are also announced in the newsletter, at least 15 days before they take effect.
