GDPR Policy

How we process and protect personal data, in accordance with the GDPR and Law 190/2018.

1. Legal basis

This GDPR Policy is drawn up in accordance with:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation – GDPR);
  • Law No. 190/2018 on the implementing measures for the GDPR in Romania;
  • Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector;
  • Directive 2002/58/EC (the ePrivacy Directive), transposed into Romanian law.

2. The personal data controller

PRT CONCEPT S.R.L., a Romanian legal entity, with registered office: Argeş County, Stăneşti Village, Corbi Commune, No. 43, Romania, Tax ID RO54299506, registered with the Trade Register under J2026018622003.

Data Protection Officer (DPO): office@delaideelasucces.ro

Supervisory authority: the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul Magheru 28-30, Sector 1, 010336, Bucharest.

3. Categories of data processed and purposes

3.1. Identification and contact data

  • Types: first name, last name, email, phone;
  • Purpose: account creation, communication, event access;
  • Legal basis: performance of the contract (Art. 6(1)(b) GDPR).

3.2. Billing data

  • Types: address, Tax ID, banking data (processed by NETOPIA);
  • Purpose: issuing tax invoices, accounting compliance;
  • Legal basis: legal obligation (Art. 6(1)(c) GDPR).

3.3. Professional data

  • Types: company name, role, industry, turnover (when provided);
  • Purpose: personalizing the networking experience, participant segmentation;
  • Legal basis: consent or legitimate interest.

3.4. Image data and video recordings

  • Types: photographs, video and audio recordings;
  • Purpose: promotion, event documentation, production of educational materials;
  • Legal basis: explicit consent given at purchase or on-site.

3.5. Browsing and cookie data

  • Types: IP, browser, pages visited, session duration;
  • Purpose: technical operation of the platform, analysis and optimization;
  • Legal basis: consent (non-essential cookies) or legitimate interest (essential cookies).

3.6. Communication data

  • Types: the content of emails and contact forms;
  • Purpose: handling requests and complaints;
  • Legal basis: performance of the contract or legitimate interest.

4. Consent

4.1. Giving consent

Where data processing is based on consent, that consent is:

  • Freely given — we do not condition attendance at the Event on marketing consents;
  • Specific — separate for each purpose (e.g. newsletter, image);
  • Informed — explained in detail before being given;
  • Unambiguous — given through an explicit action (ticking a box).

4.2. Withdrawing consent

Consent may be withdrawn at any time, free of charge, by: (a) unsubscribing from the newsletter (link in every email), (b) email to gdpr@delaideelasucces.ro, (c) a request in your online account. Withdrawal does not affect the lawfulness of processing carried out beforehand.

5. Security of processing

5.1. Technical measures

  • SSL/TLS encryption for all communications;
  • Restricted access based on the need-to-know principle;
  • Multi-factor authentication for internal systems;
  • Regular data backups in redundant locations;
  • Continuous monitoring of access and alerting on anomalies.

5.2. Organizational measures

  • Internal data protection policies;
  • Confidentiality commitments for all employees and collaborators with data access;
  • Periodic data protection training;
  • Periodic risk assessments (DPIA where applicable).

5.3. Handling security incidents

In the event of a security incident (data breach):

  • The Operator will notify the ANSPDCP within 72 hours of becoming aware;
  • Affected individuals will be informed without undue delay where there is a high risk;
  • The Operator will immediately take remediation measures and document the incident.

6. Processors and third-party recipients

Data may be transmitted to the following processors, under contractual data protection obligations (DPA):

  • NETOPIA Payments S.A. — payment processing, based in Romania, authorized by the BNR;
  • Email marketing service providers (e.g. MailerLite, Mailchimp, etc.) — with adequate safeguards for EEA/US transfers (Standard Contractual Clauses);
  • Hosting and cloud service providers — located in the EU or with adequate safeguards;
  • Ticketing providers — under GDPR contractual obligations.

We do not transmit data to third parties for their own marketing or commercial profiling purposes.

7. The rights of data subjects

You have the right to exercise the following rights at any time, free of charge:

  • Right of access (Art. 15 GDPR): receive confirmation of whether your data is processed and a copy of it;
  • Right to rectification (Art. 16 GDPR): correction of inaccurate data or completion of incomplete data;
  • Right to erasure (Art. 17 GDPR): erasure of data when it is no longer necessary or if you withdraw consent;
  • Right to restriction of processing (Art. 18 GDPR): limiting processing in certain situations;
  • Right to data portability (Art. 20 GDPR): receive the data in a structured, machine-readable format;
  • Right to object (Art. 21 GDPR): objection to processing based on legitimate interest or for direct marketing;
  • Rights related to automated decisions and profiling (Art. 22 GDPR).

7.1. Procedure for exercising rights

  • Send the request to office@delaideelasucces.ro indicating the right requested and your identification data;
  • We respond within 30 calendar days (extendable to 90 days in complex cases, with notice);
  • The request is free for the first copy; reasonable fees may be charged for additional copies or manifestly unfounded requests.

7.2. The right to lodge a complaint

You have the right to lodge a complaint with the ANSPDCP (www.dataprotection.ro) or with the competent courts.

8. Cookies and similar technologies

8.1. Types of cookies used

  • Strictly necessary cookies: technical operation (authentication, shopping cart, security). No consent required;
  • Performance/analytics cookies: Google Analytics or equivalent, to understand user behaviour. Consent required;
  • Functionality cookies: user preferences (language, region). Consent required;
  • Marketing cookies: targeted ads (LinkedIn Insight Tag, Meta Pixel). Explicit consent required.

8.2. Managing cookies

On your first visit to the Platform, you are presented with a cookie consent banner. You can adjust your preferences from your browser or from your account settings. Refusing non-essential cookies does not affect access to the Platform.

9. Direct marketing

Marketing communications (newsletter, event announcements, offers) are sent solely to individuals who have given their explicit consent.

Every commercial communication contains an unsubscribe link. Unsubscribing takes effect within a maximum of 2 business days.

10. Processing of minors' data

The Platform and the Events are intended solely for persons aged at least 18. We do not knowingly collect data about minors. If we find that we have collected data about a person under 18, we will delete it immediately.

11. Policy updates

This GDPR Policy is updated periodically, at least annually or when relevant legislative or technological changes occur. The updated version will be published on the Platform.

12. DPO contact

Data Protection Officer: office@delaideelasucces.ro

PRT CONCEPT S.R.L., a Romanian legal entity, with registered office: Argeş County, Stăneşti Village, Corbi Commune, No. 43, Romania, Tax ID RO54299506, registered with the Trade Register under J2026018622003.

We use cookies to give you the best experience on our site. Learn more

Strictly necessary

Essential for the site to function. Always on.

Analytics

Anonymous statistics about site usage (Google Analytics).

Marketing

To show you relevant ads (Meta Pixel).

Questions? 👋 Message us on WhatsApp — quick answers about events, tickets and partnerships.