AIDCIA
RO

Privacy policy

This policy explains what personal data this site collects, why, who we share it with and what rights you have. It describes exactly what the site does today — it is not a generic template.

Last updated:

1. Who the controller is

The data controller is Asociația pentru Inovație Digitală și Cercetare în Inteligență Artificială (AIDCIA), a Romanian non-profit legal entity, tax identification number 55535770.

For any question about your personal data, or to exercise the rights described below, you can contact us through the contact form on this site.

The association is not legally required to appoint a data protection officer, as it does not process data on a large scale and carries out no systematic monitoring. Requests are handled directly by the Board of Directors.

2. The principles we process data by

  • Minimisation: we ask only for the data without which your request cannot be handled. Our forms contain no fields \u201cjust in case\u201d.
  • Specified purpose: every item of data we collect has a purpose declared in the table below, and is not used for anything else.
  • No profiling: we do not build behavioural profiles, we do not track visitors across sites, and we take no automated decisions producing legal effects on anyone.
  • No selling: we do not sell, rent or trade personal data with anyone.
  • Limited retention: data is deleted when the periods in the table expire, not \u201cwhen we remember\u201d.

3. What we collect, why and for how long

We collect only the data you enter into a form. The site uses no analytics, tracking pixels or profiling.

ProcessingDataLegal basisRetention
Newsletter subscriptionEmail address, optionally your name; IP address, date and time of consent and the consent textConsent (Art. 6(1)(a) GDPR)Until you unsubscribe. Proof of consent is kept for a further 12 months afterwards.
Contact formName, email, optionally phone and organisation, subject, message, IP address, user agentLegitimate interest in replying to your request (Art. 6(1)(f) GDPR)24 months from the last exchange.
Membership applicationName or organisation name, applicant type, email, optionally phone, field of expertise, form of involvement, motivationSteps prior to entering into a membership relationship (Art. 6(1)(b) GDPR)36 months, or for the duration of membership.
Partnership proposalName, organisation, email, optionally phone, proposal type, descriptionLegitimate interest in assessing the proposal (Art. 6(1)(f) GDPR)36 months from the last exchange.
Job applicationThe data you voluntarily include in your messageSteps prior to entering into a contract (Art. 6(1)(b) GDPR)12 months after the selection ends, unless you ask for deletion sooner.
Financial supportName, email, amount; for organisations: name, tax number, registration number and address, required for the invoicePerformance of the payment (Art. 6(1)(b)) and the legal obligation to issue and archive accounting documents (Art. 6(1)(c))As required by law for accounting records.
Admin panelAdministrator email address, action log, session IP addressLegitimate interest in application security (Art. 6(1)(f) GDPR)12 months for the action log; sessions expire after 7 days.

IP addresses are retained in two situations: as proof of consent when subscribing, and to rate-limit form submissions from one source as anti-spam protection. We do not use them to identify or track visitors.

4. Payment data

Payments are processed entirely by Stripe. Card details are entered on Stripe's secure page and never reach our servers. We receive only the payment confirmation, the amount and the data needed to issue the invoice.

To issue the invoice, the billing data is passed to our invoicing provider. An invoice is an accounting document and is archived for the legally required period, independently of any deletion request — the legal obligation prevails over the right to erasure in this specific case.

5. Who we share data with

We do not sell or rent personal data. We pass it only to the providers we need in order for the services above to work, each as a processor under a data processing agreement:

ProviderRoleData sharedLocation
Brevo (Sendinblue SAS)Sending email and managing the newsletterEmail address, name, the content of messages sentEuropean Union (France)
Stripe Payments Europe, Ltd.Payment processingName, email, amount, card details (directly, not through us)European Union (Ireland)
Oblio Software SRLIssuing invoicesBilling data and amountRomania
Hetzner Online GmbHHosting the server and the databaseAll data stored by the siteGermany

All providers are located in the European Union. We make no transfers of data outside the European Economic Area. If that changes, we will update this page before any transfer and state the safeguards applied.

Data may be disclosed to public authorities only at their express request and only to the extent the law provides.

6. Your rights

Under Regulation (EU) 2016/679 you have the following rights:

  • right of access: you can find out what data we hold about you and receive a copy;
  • right to rectification: you can ask us to correct inaccurate data or complete incomplete data;
  • right to erasure (\u201cthe right to be forgotten\u201d), except for data the law requires us to keep;
  • right to restriction of processing;
  • right to data portability: you can receive your data in a structured, commonly used format;
  • right to object to processing based on legitimate interest;
  • right to withdraw consent at any time, without affecting the lawfulness of prior processing;
  • right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), based in Bucharest.

To exercise any right, write to us through the contact form on this site. We reply within 30 days at most; if the request is complex we tell you within that period and extend it by no more than two months, explaining why. Exercising your rights is free of charge.

Unsubscribing from the newsletter takes one click from the footer of any message you receive — without contacting us and without giving a reason.

7. Data security

  • All traffic is encrypted with HTTPS, with HSTS enabled.
  • Admin account passwords are stored hashed with Argon2id, never in plain text.
  • The database is not reachable from the internet; it talks only to the application, on the server's internal network.
  • Access to the admin panel is limited to named accounts, with action logging and automatic lockout after repeated failed sign-ins.
  • Forms are protected by rate limiting and anti-spam measures.
  • Outgoing email is logged without content: we keep the recipient, the template and the provider's identifier, not the message text.

In the event of a security breach posing a risk to individuals' rights, we notify the supervisory authority within 72 hours and, where the risk is high, inform the affected individuals directly.

8. Children's data

This site's services are not directed at children under 16 and we do not knowingly collect their data. If we learn that we have received such data without a parent's or guardian's consent, we delete it.

9. Changes to this policy

If we change how we process data, we update this text and the date at the top of the page. Significant changes are also announced in the newsletter, at least 15 days before they take effect.