Privacy Policy

Last updated 10 th of May 2019

Your privacy is one of our fundamental commitments, and therefore, we take utmost care to process your personal data in accordance with the principles set forth in the applicable legislation, including without limitation the General Data Protection Regulation no. 679/2016 ("GDPR"). We recognize the importance of maintaining the confidentiality, integrity and security of your personal information ("Personal Data") and have written this privacy policy ("Policy") to explain how your Personal Data is collected, stored, used and disclosed by Asociatia Codette, an NGO registered under the Romanian law, having its headquarters in Bucharest, sector 6, Str. Dr. Ernest Djuvara, Nr. 14, Room 1, Et. 1, Tax Code 37952744, registered with the Special Registry under no. 63/27.06.2017, ("Asociatia Codette", "us"), as a data controller, with respect to (i) your access and use of our website available at the URL stepfwd.today ("Site"), and to (ii) the provision of our services, irrespective whether they are provided online or offline.

Each time we are required by the applicable law or, otherwise, want to use this legal basis, we will request your free, informed, specific and unequivocal consent for the processing of your Personal Data. By expressing your consent, you agree that we can collect, use, reveal, process and transfer your Personal Data in accordance with this Policy.

We reserve the right to amend the provisions of this Policy from time to time. If we make changes to this Policy, we will make the updated version available on the Site and we will update the "Last updated” date. We will also inform you on the changes that have occurred, to ensure that you are aware of how we use your Personal Data. Any amendments to this Policy will apply on the date that they are made, with the exception of changes which require your prior consent, and which will apply as of the moment when you express such consent.

1.   APPLICABILITY

This Policy shall apply to the processing operations performed only by Asociatia Codette, as a data controller.

For the avoidance of doubt, the Policy shall not apply in relation to any other processing operation performed by any other natural or legal person, including any other entity or an affiliate or other third party organizing an event or project with Asociatia Codette.

2.   CATEGORIES OF PERSONAL DATA, PURPOSES OF PROCESSING, AND LEGAL GROUNDS
A. ATTENDING THE Asociatia Codette EVENTS (AS SPEAKERS OR PARTICIPANTS)

Asociatia Codette hosts events throughout the year that can be attended by any person who applies as a participant and is selected by the organizers. These events include meetups, office hours, workshops, hackathons, conferences, accelerators.

2.1. Registration as participants to the Asociatia Codette events

On our Site, you can register as a participant to an event organized by Asociatia Codette. When you do so, we process the following Personal Data: first name, last name, e-mail address, team, role and any other personal data indicated in the LinkedIn profile and CV. We might also use your Personal Data in order to communicate event changes, such as time schedule.

When you register to such an event, we might also require you to provide information about the company you represent. In this case, the information we collect does not necessarily represent Personal Data. However, in case the information might be identified as a natural person and, as a result, might be qualified as Personal Data, this Policy becomes applicable.

Purpose of processing Legal ground
The purpose of this processing operations is to perform the event registration and to understand the participants' profiles to better tailor our products and services to meet their needs.
  • Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract (art. 6 para. 1, let. b GDPR);
  • Our legitimate interest in performing the events logistic and in defining the type of participants to our events in order to develop and grow our business (art. 6 para. 1, let. f GDPR);
2.2. Registration as a presenter (speaker) at Asociatia Codette events

If you are a presenter at one of our events, we will collect your first name, last name, e-mail address, function, company and any other personal data indicated in the LinkedIn profile.

Purpose of processing Legal ground
The purpose of this processing is so we can facilitate the event and provide you with an acceptable service. Your consent ( art. 6 para. 1, let. a GDPR);
2.3.Taking photos during the Asociatia Codette events

During our events, we will take pictures of the audience and speakers. Further, some of the pictures could be published on social media platforms in order to promote our events. In this context, we will use the following Personal Data: image.

Further, if you agree, we will also tag you on the social media platform, in which case we will use your first name and last name.

Purpose of processing Legal ground
Taking pictures of the Asociatia Codette event audience for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);
Publishing the pictures on social media platforms for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);
Tagging you in the pictures published on the social media platforms for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);

If you for any reason do not wish to be included in any photo, please inform us at privacy [at] stepfwd [dot] today.

2.4. Recording the Asociatia Codette events

During our events, we will record the presentations held by our speakers. Sometimes, we might publish the presentation on social media platforms. In this context, we will use the following Personal Data: image, voice, first name, last name, function, company and any other personal data indicated in the LinkedIn profile.

Further, if you agree, we will also tag you on the social media platforms, in which case we will use your first name and last name.

Purpose of processing Legal ground
Recording the presentations held during our events for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);
Publishing the presentations on social media platforms for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);
Tagging you on the social media platforms for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);

If you for any reason do not wish to be included in any footage, please inform us at privacy [at] stepfwd [dot] today.

2.5. Live streaming the Asociatia Codette events

During our events, we might stream on Facebook the presentations held by our speakers. In this context, we will use the following Personal Data: image, voice, first name, last name, function, company and any other personal data indicated in the LinkedIn profile.

Further, if you agree, we will also tag you on the social media platform, in which case we will use your first name and last name.

Purpose of processing Legal ground
Live streaming on Facebook the presentations held during our events for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);
Tagging you on Facebook for promoting our events. Your consent ( art. 6 para. 1, let. a GDPR);

If you for any reason do not wish to be included in any footage, please inform us at privacy [at] stepfwd [dot] today.

B. OTHER PROCESSING OPERATIONS
2.6. Contact

You can contact us in different ways: by email, by phone, through feedback or support form. In this case, we will process the following Personal Data: first name, last name, email, phone number and any other information you voluntarily provide when you contact us.

Purpose of processing Legal ground
In this situation, we will use your Personal Data only to contact you in connection with the requested offer or in connection with the resolution of the problem.
  • Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract ( art. 6 para. 1, let. b GDPR);
  • Our legitimate interest in ensuring communication with our customers and providing the necessary support for the use of the Site ( art. 6 para. 1, let. f GDPR);
2.7. Feedback

In certain situations, we will ask for your feedback. In this case, we will process the following Personal Data: first name, last name, company name, and any other information included in the feedback form.

Purpose of processing Legal ground
In this situation, we will use your Personal Data to contact you for further details regarding the offered feedback. Your consent ( art. 6 para. 1, let. a GDPR);
2.8. Marketing messages

You can opt-in to receive marketing messages (e.g., newsletter) via e-mail. In this case, we will process your first name, last name, e-mail address.

Purpose of processing Legal ground
If you opt to receive such marketing messages, we will use your email address to send you marketing messages (newsletter) about our activities. Your consent ( art. 6 para. 1, let. a GDPR);

You can revoke your prior consent at all times and without any costs, with altering consequences for the future.

3.   PROCESSING PERSONAL DATA BASED ON OUR LEGITIMATE INTEREST

When we process on the lawful basis of legitimate interest, we apply the following test to determine whether it is appropriate:

The purpose test – is there a legitimate interest behind the processing?

Necessity test – is the processing necessary for that purpose?

Balancing test – is the legitimate interest overridden, or not, by the individual’s interests, rights or freedoms?

For more information on how we process the Personal Data on the lawful basis of legitimate interest, please contact us at privacy [at] stepfwd [dot] today.

4.   FAILURE TO PROVIDE PERSONAL DATA

You may refuse to provide certain Personal Data (indicated above) but, in such a case, you may not be able to benefit from certain services and features, including, but not limited to contacting you to solve your problem and to provide support.

5.   PAUTOMATIC PROCESSING OF PERSONAL DATA

Your Personal Data will not be processed for taking decisions based solely on automatic processing that would result in legal effects concerning you or could similarly significantly affect you.

6.   RETENTION PERIOD

The retention period of your Personal Data depends on the purpose of processing the respective Personal Data. As a rule, we will retain your Personal Data as follows:

Processing/Activity Retention period
Registration to Asociatia Codette events 3 years
Being a speaker at an Asociatia Codette event 3 years
Taking photos during the Asociatia Codette events 3 years
Recording the Asociatia Codette events 3 years
Live streaming the Asociatia Codette events 3 years
Contacting us 3 years
Feedback 3 years
Marketing messages As long as you do not revoke your consent.

We may also keep your Personal Data for longer periods of time so that we have accurate records of your dealings with us in the event of any complaints or challenges, or if we reasonably believe there is a prospect of litigation relating to your Personal Data or dealings.

7.   TRANSFER OF PERSONAL DATA

Your Personal Data is filed and stored on the servers of our contractual partners that are helping us to provide our services to you.

We may transfer Personal Data, as far as necessary, to the following categories of recipients:

  • contractual partners;
  • subcontractors;
  • companies offering courier services;
  • companies offering IT services;
  • marketing companies;
  • public authorities, courts of law or arbitral tribunals, and authorities competent to investigate criminal offence.

These recipients can be located in the European Union and/or in the European Economic Area. Where recipients are located outside the European Union and the European Economic Area, including in countries not recognized as ensuring an adequate level of protection, the transfer of Personal Data shall be carried out only if there are appropriate guarantees, in accordance with applicable law. In this respect, we rely on several guarantees, such as the Privacy Shield certificate or the standard contractual clauses issued by the European Commission. You may receive from us a list of recipients from third countries, as well as a copy of the agreed provisions that ensure an adequate level of protection of Personal Data. For any request to this effect, please contact us at the contact details mentioned below.

8.   SECURITY

The security of your Personal Data is important to us. Your Personal Data will therefore be processed by applying reasonable technical and organizational measures to protect Personal Data, such as limiting access to Personal Data, encryption or anonymization of Personal Data, storage on secure environments. However, despite our efforts, we cannot always guarantee the effectiveness of the security measures implemented, and therefore we cannot guarantee the security of Personal Data at any time.

9.   RIGHTS IN CONNECTION WITH THE PROCESSING OF YOUR PERSONAL DATA
9.1. Your rights

You have the following rights in connection with the processing of your Personal Data:

Access right: You have the right to obtain from us confirmation that your Personal Data is processed by us, as well as information on the specific processing, such as: the purposes of processing, categories of processed Personal Data, recipients of Personal Data, the period for which Personal Data is stored, if we transfer the Personal Data abroad and how we protect it, your rights, the right to lodge a complaint before the supervisory authority, the source of your Personal Data.

Right to rectification: You have the possibility to request rectification of your Personal Data, provided that the applicable legal requirements are met. In the event of errors, after notification, we will immediately correct your Personal Data.

Right to erasure: In certain cases, you have the possibility to request the deletion of Personal Data, namely when: (i) the Personal Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; (ii) you withdraw consent on which the processing is based according and where there is no other legal ground for the processing; (iii) you exercise the right to object to the processing; (iv) the Personal Data has been unlawfully processed. We are not obliged to comply with your request when the processing is necessary (among others) for compliance with a legal obligation or for the establishment, exercise or defense of legal claims. There are also other circumstances in which we are not obliged to comply with this request for the deletion of Personal Data.

Restriction of processing: You may request us to restrict the processing of your Personal Data in the following circumstances: (i) you contest the accuracy of the Personal Data, for a period enabling us to verify the accuracy of the Personal Data; (ii) the processing is unlawful and you oppose to the erasure of the Personal Data and request the restriction of their use instead; (iii) we no longer need the Personal Data for the purposes of the processing, but you require them for the establishment, exercise or defense of legal claims; (iv) you have objected to processing, pending the verification whether our legitimate grounds override yours. However, we can continue to process your Personal Data (i) when you consent; (ii) for the establishment, exercise or defense of legal claims or (iii) for the protection of the rights of another natural or legal person.

Right to data portability: Insofar the Personal Data is processed based on your consent or on the execution of the agreement and the processing is carried out by automated means, you have the right to have your data Personal Data provided to you in a structured format, which is currently used and can be read automatically and you have the right to request us to transfer this Personal Data to another controller. This right shall not adversely affect the rights and freedoms of others.

Right to opposition: In certain situations, such as when we process your Personal Data on the basis of a legitimate interest, you have the right to object to the processing of your Personal Data by us. In the event of the unjustified objection, Asociatia Codette is entitled to continue processing Personal Data.

Objection to direct marketing: You can also object to the processing of your Personal Data for the purpose of sending marketing messages.

Revocation of consent: Insofar you consented to the processing of your Personal Data, you can at all times revoke your consent, without affecting the lawfulness of processing based on consent before its withdrawal.

Right not to be subject to any automatic individual decisions: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. Such right cannot be exercised when the decision: (i) is necessary for entering into, or performance of, a contract between you and us; (ii) is authorized by law which lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or (iii) is based on your explicit consent.

Right to lodge a complaint with the supervisory authority: You have the right to lodge a complaint with The National Supervisory Authority for Personal Data Processing ("DPA") in relation to any breach of your rights regarding the processing of your Personal Data. The contact details of the DPA are: 28-30 Gheorghe Magheru Boulevard, District 1, Postal Code 010336, Bucharest, Romania; e-mail: anspdcp @ dataprotection . ro

9.2. How to exercise your rights

To learn more about the manner in which you may exercise the aforementioned rights, please contact us at privacy [at] stepfwd [dot] today.

Identity verification: We take utmost care of the confidentiality of all Personal Data and we reserve the right to verify your identity if you make a request in relation to your Personal Data.

Fees: As a rule, you can exercise your rights free of charge. However, we reserve the right to request a reasonable fee if your claims are manifestly unfounded or excessive, in particular, because of their repetitive nature.

Response Time: We make every effort to respond to your request within one month of receiving the request. This period may be extended by two further months where necessary, taking into account the complexity and number of the requests, in which case we will inform you of any such extension and of the reasons for the delay.

10.   CONTACT

If you have any questions or concerns about this Policy or its implementation, you may contact us at: privacy [at] stepfwd [dot] today