Privacy policy
1 Introduction
Thank you for your interest in our association and our products and/or services.
The protection and confidentiality of personal data are of great importance to us. When you enter into any type of relationship with us, you entrust us with your information. The information presented in this document (hereinafter referred to as the “Privacy Policy” or the “Document”) is important.
We recommend that you read it carefully. The purpose of this Privacy Policy is to explain what data we process (collect, use, share), why and how we process it, your rights under the GDPR, and how you can exercise those rights. When collecting this information, we act as the Data Controller and are legally required to provide you with these details.
Fully aware that your personal information belongs to you, we make every effort to store it securely and process it with care. We do not share information with third parties without informing you in accordance with legal requirements. We do not make decisions based solely on automated processing that have a significant impact on you.
By visiting our website/application (www.rominas.ro), interacting with us by any means, and/or using any communication channel (e-mail, telephone, social media, etc.), you agree to this Privacy Policy. If you do not agree with the terms described in this Privacy Policy, please do not interact with the “CULTURAFT” Cultural Association, which acts as a data controller within the meaning of the General Data Protection Regulation (GDPR).
2 DEFINITIONS
1.1. “GDPR”, “RGPD”, or “the Regulation” means REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
1.2. “The Controller” or “We” means the “CULTURAFT” CULTURAL ASSOCIATION, with its registered office at: Corbeanca Village, Corbeanca Commune, 43B Viitorului Street, 1st Floor, Room 3, Ilfov County, Tax Identification Code 28664343.
1.3. “Data subject” means any identified or identifiable natural person whose data is processed by us in the capacity of controller, such as clients, potential clients, or website visitors.
1.4. “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
1.5. “Consent” means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her by the Controller;
1.6. “Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Other terms used in this document have the meaning ascribed to them by the GDPR and other applicable legal provisions.
3 other services
This Privacy Policy does not cover third-party applications and websites that you may reach by accessing links on our website. This is beyond our control. We encourage you to review the privacy policy of any website and/or application before providing personal data.
4 WHO WE ARE?
The “CULTURAFT” Cultural Association, with its registered office at 43B Viitorului Street, 1st Floor, Room 3, Corbeanca Village, Corbeanca Commune, Ilfov County, and Tax Identification Number 28664343, is responsible for processing the personal data we collect directly from you or from other sources.
Under the law, our organization acts as a personal data controller. To ensure your data is processed securely, we have made every effort to implement reasonable and appropriate technical and organizational measures to protect your personal data.
5 Who you are?
Acording to the law, you—as an individual interacting with us, a website visitor, or someone with whom we have any type of relationship—are a “data subject,” meaning an identified or identifiable natural person. To ensure full transparency regarding data processing and to enable you to easily exercise your rights at any time, we have implemented measures to facilitate the exercise of those rights.
6 Our commitment
Protecția informațiilor dvs. personale este foarte importantă pentru noi. De aceea, ne-am luat Our commitment is to comply with European and national legislation regarding personal data protection—specifically Regulation (EU) 679/2016, known as the GDPR—and to adhere to the following principles:
✓ Lawfulness, fairness, and transparency
We process your data lawfully and fairly. We are always transparent about the information we use, and you are duly informed.
✓ You remain in control
Within the limits of the law, we provide you with the opportunity to review, modify, or delete the personal data you have shared with us and to exercise your other rights.
✓ Data integrity and purpose limitation
We use data only for the purposes described at the time of collection or for new purposes compatible with the original ones. In all cases, our purposes comply with the law. We take reasonable measures to ensure that personal data is accurate, complete, and up-to-date.
✓ Security
We have implemented reasonable security measures for personal data processing to protect your personal information as effectively as possible. However, please note that no website, application, or internet connection is completely secure.
7 CHANGES
We may change this Privacy Policy at any time. All updates and amendments to this Policy are effective immediately; therefore, please always read this Privacy Policy.
8 YOUR INFORMATION. PURPOSES. LEGAL GROUNDS.
When you browse our website, send us an email inquiry, or contact us for any other purpose and via any other communication channel, you may provide us with the following personal data, which we collect directly from you or from other sources, as explained in the table below.
Personal data processed* | Scop/Scopuri* | Grounds/Legal Grounds |
Names Address
|
· For the purpose of creating an account on the site. · For invoicing. · To comply with the legislation. · For the prevention of fraud and other crimes. · For direct marketing (only if we have your prior consent). |
· Conclusion or performance of a contract – Art. 6 (1) b GDPR. · legal obligation – Art.6 (1) c GDPR. · consent – Art.6 (1) a) – (only for direct marketing).
|
· For the purpose of creating an account on the site/application. · For invoicing. · To comply with the legislation. · For the prevention of fraud and other crimes. · For direct marketing (only if we have your prior consent). |
· Conclusion or performance of a contract – Art. 6 (1) b GDPR. · consent – Art.6 (1) a) – (direct marketing only). · legitimate interest – Art.6 (1) f) GDPR. | |
IP address | · to defend against cyber attacks. · for fraud prevention. · for the operation of the network. | · legitimate interest – Art.6 (1) f) GDPR |
We collect most information directly from you (for example, by filling out a form on the website). While most of the information is as described above, there may be situations where we collect data from third parties (e.g., partners, platforms).
In addition to the information indicated above, we may also collect the following information, depending on the circumstances:
- How you interact with our website(s) (for example, information about how and when you access our site or the device you use to access it). For more information on this, please read our Cookie Policy.
- The content of messages sent via messaging systems and email.
In addition to the purposes listed in the table in the previous section, we also process personal data for the following purposes:
- To answer your questions and requests and to provide customer support;
- For marketing purposes, but only where we have your prior consent or where a legal exception to obtaining consent applies;
- To provide and improve the services we offer;
- To diagnose or resolve technical issues;
- To defend against cyberattacks;
- To comply with the law—for example, tax legislation requiring us to retain accounting records for a period of 10 years;
- In the unlikely event of a dispute, to establish or assert a legal right in court..
8.1 OTHER INFORMATION REGARDING LEGAL BASES
(a) Legitimate interest. When relying on legitimate interest, we conduct a legitimate interest analysis (balancing test) to weigh our interests against yours. If our interests prevail, we will rely on legitimate interest. If your interests prevail, we will not rely on legitimate interest, and—unless we can identify another valid legal basis—we will not carry out the processing activity in question.
(b) Consent. Please note that obtaining consent is not mandatory; we will only seek your consent in situations where we cannot rely on another legal basis. Currently, we use consent only for email marketing.
(c) Vital interest. In the unlikely event of a medical emergency or other exceptional circumstance, processing may be necessary to protect your vital interests or those of another natural person.
9 STORAGE PERIOD
We store your personal data only for the period necessary to fulfill the purposes, but for no longer than 5 years following the termination of the contract or your last interaction with us.
Upon the expiration of this period, the personal data will be destroyed or deleted from our IT systems, or anonymized for use in scientific, historical, or statistical research.
Please note that in certain specifically regulated situations, we store the data for the period mandated by law.
10 DATA TRANSFERS
We may disclose your data to business partners or other third parties in compliance with applicable law. We make continuous, reasonable efforts to ensure that these third parties have implemented appropriate protection and security measures. We maintain contractual clauses with these third parties to ensure your data is protected. In such situations, we will ensure that any transfer is lawful under the legislation.
We may also transmit data to other parties with your consent or in accordance with your instructions—for example, when you exercise your right to data portability.
We may also provide your personal information to the public prosecutor’s office, the police, courts of law, and other competent state authorities, based on and within the limits of legal provisions and in response to specific requests.
The transfer of personal data to a third country may take place only if the destination country ensures an adequate level of protection.
Transferring data to a country whose legislation does not provide a level of protection at least equal to that offered by the General Data Protection Regulation (GDPR) is possible only if there are sufficient safeguards regarding the protection of the data subjects’ fundamental rights. We will establish these safeguards through contracts concluded with the service providers to whom your personal data is transferred.
Whenever we transfer your personal data outside the EEA, we will ensure that a similar level of protection exists through one of the following safeguard mechanisms:
- we will transfer your personal data to countries that the European Commission has determined provide an adequate level of protection for personal data.
- when engaging certain service providers, we may use standard contractual clauses provided and approved by the European Commission, which offer personal data the same level of protection as in Europe..
11 Data security
We understand the importance of personal data security and take the necessary measures to protect our customers—and other individuals whose data we process—against unauthorized access to personal data, as well as against the unauthorized alteration, disclosure, or destruction of the data processed during our day-to-day operations.
We have implemented the following technical and organizational measures to ensure the security of personal data:
- a) Dedicated policies. We adopt and constantly review our internal practices and policies regarding personal data processing (including physical and electronic security measures) to protect our systems against potential unauthorized access or other security threats. These policies are subject to ongoing review to ensure compliance with legal requirements and the proper functioning of our systems.
- b) Data minimization. We ensure that the personal data we process is limited to what is necessary, adequate, and relevant for the purposes stated in this Policy.
- c) Restricting data access. We strive to limit access to the personal data we process to the absolute minimum necessary—specifically to employees, collaborators, and other individuals who require access to such data to process it and perform a service. Our partners and collaborators are subject to strict confidentiality obligations (whether contractual or statutory).
- d) Specific technical measures. We use technologies designed to ensure our customers’ security, always striving to implement optimal data protection solutions. We also perform periodic data backups to enable recovery in the event of an incident and have implemented periodic security audit procedures for the equipment we use. However, no website, application, or internet connection is completely secure or invulnerable.
- e) Ensuring the accuracy of your data. We may occasionally ask you to confirm the accuracy or currency of your data to ensure it reflects reality.
- f) Staff training. We constantly train and test our employees and collaborators regarding legislation and best practices in the field of personal data processing.
- g) Data anonymization. Wherever possible, we attempt to anonymize or pseudonymize the personal data we process so that the individuals to whom the data relates can no longer be identified.
Nevertheless, despite our constant efforts to ensure the security of the data you entrust to us, unfortunate events—such as security incidents or breaches—may still occur. In such cases, we will strictly follow the security incident reporting and notification procedures and take all necessary measures to restore the situation to normal as quickly as possible.
12 DIRECT MARKETING
Provided we have obtained your prior consent or you are already a customer of the company, we may use direct marketing technologies leveraging the information collected about you. We currently send commercial messages via email (email marketing) to individuals who have previously given their consent to do so.
13 TOUR RIGHTS
Your rights under the GDPR are as follows:
(a) The right to be informed about the processing of your data.
(b) The right of access to data. You have the right to obtain confirmation from us as to whether or not personal data concerning you is being processed and, where that is the case, access to said data and the information specified in Art. 15 para. (1) of the GDPR;
(c) The right to rectify inaccurate or incomplete data. You have the right to obtain from us, without undue delay, the rectification of inaccurate personal data concerning you;
(d) The right to erasure (“right to be forgotten”). In the situations provided for in Art. 17 of the GDPR, you have the right to request and obtain the erasure of personal data;
(e) The right to restriction of processing. In the cases provided for in Art. 18 of the GDPR, you have the right to request and obtain the restriction of processing;
(f) The right to transmit the data we hold about you to another controller (“right to data portability”).
(g) The right to object to data processing. In the cases provided for in Art. 21 of the GDPR, you have the right to object to the processing of data;
- h) The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you;
- i) The right to seek judicial redress for the protection of your rights and interests;
- j) The right to lodge a complaint with a supervisory authority.
Name | Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal |
Adress | B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, cod poștal 010336, București, România |
Phone: | +40.318.059.211 sau +40.318.059.212 |
Please note that:
(1) You may withdraw your consent for direct marketing at any time by following the unsubscribe instructions included in every email.
(2) The rights listed above are not absolute. There are exceptions; therefore, each request received will be assessed to determine whether it is well-founded. If the request is well-founded, we will facilitate the exercise of your rights. If the request is unfounded, we will reject it but will inform you of the reasons for the refusal and of your right to lodge a complaint with the Supervisory Authority and to seek judicial redress.
(3) We will endeavor to respond to the request within one month. However, this timeframe may be extended depending on various factors, such as the complexity of the request, the volume of requests received, or the inability to identify you within a reasonable time.
(4) If, despite our best efforts, we are unable to identify you and you do not provide us with additional information to enable such identification, we are not obliged to comply with the request.
14 Questions, requests and exercise of rights
If you have questions or concerns regarding the processing of your information, wish to exercise your legal rights, or have any other concerns regarding the privacy of the data you provide to us, you may contact us at our company address or via email: [email protected]
Last update: 01.10.2026
