Privacy policy

CONFIDENTIALITY

Thank you for visiting our website. When you visit www.heks-eper.ro, contact us, or use our services, you entrust us with your information.

The purpose of the Privacy Policy of the www.heks-eper.ro website is to explain what data we process, why we process it, how long we keep it, if and to whom we send it, and generally what we do with it. Your privacy is important. We do not sell or use your personal data for purposes other than those declared in accordance with this privacy policy. Your personal information belongs to you, so we do everything possible to collect it securely and process it carefully. We do not provide your personal data to third parties without informing you. The personal data of www.heks-eper.ro customers and users will only be used for the purpose for which it was provided.

Please read this document carefully.

By browsing the www.heks-eper.ro website or contacting us through various communication channels, you declare that you have been adequately informed about the processing of your personal data by reading this document called the “Privacy Policy.”

DEFINITIONS

Below we will define a few concepts to help you understand this Privacy Policy.

www.heks-eper.ro (or “the Site”) is a presentation site, email: romania@heks-eper.org.

When we say “GDPR,” we refer to Regulation (EU) 679/2016 regarding the protection of natural persons with regard to the processing of personal data and the free movement of such data and repealing Directive 95/46/EC.

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”).

UPDATES

This Privacy Policy may be updated and changed at any time. All updates and changes to this Policy are effective immediately upon notification, which we will make by posting on the site and/or notifying you via email.

QUESTIONS AND REQUESTS

If you have any questions or concerns regarding the processing of your personal data or wish to exercise your legal rights related to the data we hold, you can write to us at the email address: romania@heks-eper.org.

WHAT KIND OF INFORMATION DO WE COLLECT?

a) Information you voluntarily provide

If you are in any way part of our projects, whether you are one of our partners or one of our beneficiaries, you already know that we only collect personal data with your consent. Through our feedback forms, when you contact us by phone or email, or communicate with us in any way, you voluntarily give us the information we process. This information includes your name, surname, email address, phone number, and any other data you voluntarily provide as part of your identification.

This information is kept securely and confidentially in our database. We do not disclose or transfer information to third parties, except under the conditions stipulated in this Privacy Policy, with the exception of EU legislation or other internal legislation that obliges us to disclose personal data, or a final decision of a court in the EU or internally.

b) Information we collect automatically

When you browse our site, we may collect information about your visit. This information may include your IP address, operating system, browser, browsing activity, and other information about how you interacted with the site. We may collect this information using cookies or other similar technologies.

TYPES OF PERSONAL DATA WE COLLECT:

  • Contact information such as name, address, phone number, email address, and login details;
  • Data regarding satisfaction with our services, such as the results of beneficiary and partner satisfaction;
  • Data collected during your visit to our site, such as data collected through cookies and other automatically collected data to provide you with a good browsing experience;
  • Details such as traffic information, location data, and other communication data (including IP address and browser type) collected through your use of our services;
  • Device information, including the unique device identifier;
  • Pages visited and content viewed, links and buttons accessed, URLs visited before and after using our service.

For more information about cookies and how to manage them, read our Cookie Use Policy.

WHAT IS THE LEGAL BASIS FOR PROCESSING?

Regarding the data you voluntarily provide by filling out and submitting forms or by contacting us in any way, the legal basis is “to take steps at the request of the data subject before entering into a contract” (Article 6 (1)(b) of Regulation (EU) 679/2016). This includes actions such as contacting us for information and clarifications for submitting an offer, negotiations, actual contracting, and any other activities related to the proper conduct of the contract.

Regarding the data you voluntarily provide, such as by posting a comment on an article on our Facebook page, the basis for processing is our legal obligation to support the exercise of the right to information, as well as our legitimate interest in providing readers of the page with transparency and information.

According to current legislation, including GDPR (applicable from May 25, 2018), your consent is not required when processing is necessary for taking steps to enter into a contract, fulfilling a legal obligation, or legitimate interest.

Regarding the data we automatically collect through the use of cookies or other similar technologies, the basis for processing is consent. By accessing the site, you validly consent to the processing.

HOW WE COLLECT PERSONAL DATA:

  • Through contact forms;
  • From publicly available sources;
  • From social networks, e.g., Facebook, if you choose to use them to facilitate connection to our sites/applications.

You can choose not to provide certain types of personal data. However, this may affect our ability to provide certain services.

We may also combine the personal data you provide with other information collected online or offline, as permitted by applicable laws, including information provided by third parties, and use or share it for the purposes described in this Personal Data Policy. We may anonymize the information we collect (meaning it can no longer be associated with you and therefore no longer constitutes personal data).

FOR WHAT PURPOSES DO WE COLLECT DATA?

  • To provide you with services within our projects;
  • To help develop, test, improve, and modify our services;
  • To interpret your feedback when you evaluate our services;
  • To respond to your questions and requests;
  • To defend against cyber attacks.

HOW LONG DO WE STORE DATA?

We will retain your personal data as long as required by law or as mentioned above. If there is no legal requirement, we will keep information about you only as long as necessary for the purpose or purposes for which it was collected.

Once the processing period indicated above expires, and www.heks-eper.ro no longer has legal or legitimate reasons to process your personal data, the data will be deleted according to our procedures, which may involve archiving, anonymizing, or destroying them.

HOW DO WE DISCLOSE YOUR INFORMATION?

We will not disclose your data to third parties for their own purposes without your consent. However, for the purposes of the Processing mentioned above, we may share or disclose your personal data to the following entities:

  • Service providers. We may disclose your information to other companies that provide services to us and act as processors, such as companies that help us with billing, accounting, payments, shipping, financing, communication, promotion, or that send emails on our behalf. These entities are carefully selected to ensure they meet specific personal data protection requirements and do not use it for other purposes than those declared.
  • Courts, prosecutors, or other public authorities to comply with the law or in response to a binding legal procedure.
  • Other parties with your consent or at your instructions.

WHAT ARE YOUR RIGHTS?

If you are in the EU or if your personal data is processed by our company in any way other than what is stated in this policy, you have the following rights:

Right to Withdraw Consent

If the processing is based on consent, you can withdraw your consent at any time and at no cost by sending an email to romania@heks-eper.org with the subject “withdraw consent.”

Right to File a Complaint with a Supervisory Authority

You have the right to file a complaint with a supervisory authority.

Right to Legal Recourse

You have the right to seek legal recourse.

Right of Access

You have the right to obtain confirmation from us as to whether or not personal data concerning you is being processed and, if so, to access that data.

Right to Rectification

You have the right to obtain from us the rectification of inaccurate personal data concerning you without undue delay. Considering the purposes for which the data was processed, you have the right to complete any incomplete personal data, including by providing a supplementary statement.

Right to Erasure (“Right to be Forgotten”)

In certain situations, you have the right to obtain the erasure of personal data concerning you without undue delay, particularly if:

  1. The data is no longer necessary for the purposes for which it was collected.
  2. You withdraw your consent and there is no other legal basis for processing.
  3. You object to the processing and there are no overriding legitimate grounds for processing.
  4. The personal data has been unlawfully processed.

Right to Restrict Processing

You have the right to obtain from us the restriction of processing if one of the following applies:
(a) You contest the accuracy of the data, for a period enabling us to verify the accuracy of the data.
(b) The processing is unlawful, and you oppose the erasure of the personal data and request the restriction of its use instead.
(c) We no longer need the personal data for processing purposes, but you require it for the establishment, exercise, or defense of legal claims.
(d) You have objected to processing pursuant to Article 21(1) of the GDPR, pending the verification of whether our legitimate grounds override yours.

Right to Data Portability

You have the right to receive your personal data that you have provided to us in a structured, commonly used, and machine-readable format and to transmit that data to another controller without hindrance from us if:
(a) The processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the GDPR, or on a contract pursuant to Article 6(1)(b) of the GDPR.
(b) The processing is carried out by automated means.

Right Not to Be Subject to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

This right does not apply if the decision is authorized by Union or Member State law applicable to the controller and which also lays down suitable measures to safeguard your rights, freedoms, and legitimate interests.

If you have questions about these rights or wish to exercise any of these rights, you can do so in writing, by email, or through the contact form on www.heks-eper.ro.

Please note that exercising these rights may affect our ability to provide you with certain products, features, or services.

SECURITY OF YOUR PERSONAL DATA

www.heks-eper.ro will take appropriate technical and organizational measures, considering the nature of the information and the costs of implementation, in accordance with applicable data protection laws, including requiring service providers, partners, or professional consultants to use appropriate measures to protect your personal data.

PLEASE NOTE THE FOLLOWING:

We will endeavor to respond to any requests within 30 days. However, this period may be extended for specific reasons related to the legal right involved or the complexity of your request.

Restriction of Access:

In certain situations, we may not be able to provide access to all or some of your personal data due to legal provisions. If we refuse your access request, we will inform you of the reason for the refusal.

Inability to Identify You:

In some cases, we may not be able to search for your personal data due to the identifiers you provide in your request. An example of personal data we cannot consult when you provide us with your name and email address is data collected through browser cookies.

In such cases, if we cannot identify you as the data subject, we are not in a position to comply with your request unless you provide additional information that allows for identification.

HOW TO EXERCISE YOUR RIGHTS

To exercise your legal rights, please contact us at the email address romania@heks-eper.org.