Last updated: July 30, 2026

This notice explains transparently how Asociația „Investește pentru Viitorul Tău” Buzău processes personal data when you visit this site, contact us or use its functions. We adhere to the principles of legality, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality.

1. Operator and contact details

The data operator is Asociația „Investește pentru Viitorul Tău” Buzău, with its office at municipiul Buzău, Bd. Nicolae Bălcescu, bl. Crinul Alb, ap. 46, România.

Requests regarding personal data are handled through the contact details above and are directed internally to the person responsible for their resolution.

2. What data we process and where it comes from

Depending on how you use the site, we may process:

  • Contact details and correspondence: name, e-mail address, subject and content of the message sent via form or e-mail. The form sends the message to the email system and does not store it in the WordPress database; however, the message is kept and processed in the e-mail boxes and, to a limited extent, in the technical logs of the services involved.
  • Comments: chosen name, email address, website address if provided and the content of the comment. The commenter's IP address is not stored in the local WordPress database; some technical signals may be temporarily processed by the anti-spam service.
  • Authorized accounts: account identifiers, roles and information necessary to administer and secure access.
  • Technical and safety data: IP address, date and time, requested page, device/browser type, technical identifiers and security events, to the extent necessary for the operation, protection and diagnosis of the site.
  • Optional campaign statistics and measurement, by agreement only: WP Statistics locally processes visited pages, referrer, device/browser type, approximate location and aggregated technical data; the IP address is not stored in the clear, the pseudonymized identifier uses a periodically changed salt, the full browser agent is not stored, and the "Do Not Track" signal is respected. Separately, Google Analytics 4 and Google Ads can receive the page path and title, standard campaign parameters and click identifiers such as gclid, gbraid or wbraid, the parameterless referrer, browser/device information, and approximate location. We measure the event course_start_click only when accessing a NetAcad course, with the technical identifier of the course and the position of the button, and generate_lead only after successful submission of the form. We do not pass the full NetAcad URL, the parameter instance_id, button text, form fields or a User-ID. Google states that for traffic from the EEA the IP address is removed before registration.
  • Consent Preferences: the selected categories and policy version are retained in the browser to apply the choice. The current configuration does not create an individual consent registry on the server.
  • Data from external services: only if you enable "Statistics and campaigns" for GA4 and the measurement of Google Ad Grants or "External content" for embedded materials, the relevant providers can receive the technical data described in this information and in the Cookie Policy.

The data usually comes directly from you and the device/browser you are using. Please do not transmit sensitive data or data about other people unless it is necessary and you do not have an adequate basis.

WhatsApp, if you choose this channel: The external link does not load WhatsApp resources before you open it. After opening the link and sending a message, WhatsApp Ireland Limited processes data related to your use of the service under its policy, while the Association will process the visible number/profile and the message content to respond to your request. Do not send unnecessary sensitive data through this channel. Read the WhatsApp Privacy Policy.

3. Purposes and Legal Basis

  • Responding to messages and managing your relationship: the legitimate interest of the Association to communicate and carry out its activity — art. 6 para. (1) lit. f) GDPR; when the request concerns pre-contractual steps requested by the person, art. 6 para. (1) lit. b).
  • Posting and moderating comments: the legitimate interest to facilitate public dialogue and prevent abuse — art. 6 para. (1) lit. f) GDPR.
  • Account administration, maintenance and security: the legitimate interest to operate and protect the site — art. 6 para. (1) lit. f) GDPR.
  • Filtering unwanted messages and comments: the legitimate interest to protect the site and users — art. 6 para. (1) lit. f) GDPR.
  • Optional statistics and Google Ad Grants campaign measurement: your consent — art. 6 para. (1) lit. a) GDPR. Scripts and measurement requests are not executed before agreement. By agreement, analytics_storage, ad_storage and ad_user_data are enabled strictly for analysis, attribution of clicks and measurement of conversions of the free campaign. ad_personalization remains denied, and Google Signals, remarketing, ad profiling, and conversion audiences are disabled.
  • YouTube, Google Maps and other optional external content: your consent — art. 6 para. (1) lit. a) GDPR. The connection to the provider is not initiated before the "External Content" category is enabled.
  • Keeping and respecting cookie choices: the technical necessity to apply the requested option and the legitimate interest to respect and be able to explain the configuration of consent — art. 6 para. (1) lit. f) GDPR, in conjunction with art. 5 para. (2), art. 7 and the rules applicable to strictly necessary storage in the terminal.
  • Fulfilling legal obligations: resolving requests regarding rights, responding to authorities, managing incidents and keeping documents for the terms imposed by the applicable rules — art. 6 para. (1) lit. c) GDPR.

When we rely on legitimate interest, we assess the necessity of the processing, the impact on the individual and the measures to reduce it. You can object to such processing in accordance with section 7.

4. To whom we can communicate the data

Access is limited to authorized persons and, to the extent necessary, to the following categories of recipients:

  • contracted hosting, email, maintenance, security and backup providers, as assignees or recipients, as applicable;
  • Automatic/Akismet, for filtering unwanted messages and comments;
  • Google Ireland Limited, as a provider of Google Analytics 4 and Google Ads for campaign measurement only after consent for "Statistics and Campaigns", and Google/YouTube and Google Maps only after consent for "External Content";
  • professional consultants, authorities or courts, when communication is necessary to fulfill a legal obligation or defend a right.

We do not sell or rent personal data. For Akismet, Automattic publishes the use of standard contractual clauses and information regarding its processing agreement in Akismet GDPR documentation. For optionally activated Google services, Google explains the use of the EU-US data protection framework for certified entities and standard contractual clauses where necessary in his transfer information. The applicable mechanism depends on the entity, the service and the specific context of the transfer. For information or a copy of the guarantee relevant to a processing under the control of the Association, you can contact us at the address in section 1. External services can also act as independent operators for their own activities.

5. How long we keep the data

  • ordinary correspondence: for the duration of the settlement, then only for the limited period justified by the pursuit of the request, the fulfillment of an obligation or the ascertainment, exercise or defense of a right; the need for retention is periodically reviewed;
  • financial-accounting documents, contractual or required by law: for the periods provided by the applicable legislation;
  • the comments: how long they remain published or are they necessary for the moderation and management of possible complaints;
  • data submitted to the Akismet anti-spam service: according to the provider's documentation, most spam-related data is kept between 14 and 90 days, and certain information may be kept longer to combat abuse and improve the service;
  • authorized accounts: as long as access is necessary, then they are disabled or deleted, with limited retention of logs necessary for security;
  • detailed local statistics data: maximum 180 days, after which they are deleted or aggregated;
  • Google Analytics cookies: maximum 390 days from creation, without extension with each visit; Google campaign measurement cookies (_gcl_*): maximum 90 days; user and event level GA4 data uses the property's standard 2-month period. The reports imported into Google Ads are kept only as long as they are necessary for the evaluation of the nonprofit campaign, they are reviewed at least annually and are deleted or anonymized when they are no longer needed, subject to the technical and legal requirements applicable to the provider;
  • consent preferences: typically a maximum of 365 days, unless you change your choice sooner;
  • technical logs: only until the end of the rotation cycle configured by the service involved, based on the volume and the need to investigate incidents; older files are overwritten or deleted if they do not need to be isolated for an incident or a legal obligation;
  • automatic backups and those created for maintenance: only as necessary for recovery and verification, with restricted access and periodic review of the need; if a copy is restored, valid deletion or restriction requests are reapplied.

At the end of the applicable period, the data is deleted, anonymized or kept separately only if there is an obligation or a valid legal basis. Deletions are propagated to backups as they rotate.

6. Cookies and external services

Strictly necessary cookies preserve functionality and requested options. "Statistics and campaigns" and "External content" are disabled by default and can be enabled separately. The refusal does not prevent access to the basic content of the site. You can withdraw or change your consent at any time via the "Manage Consent" button in the footer; opting out has effects for the future and deletes primary measurement cookies that the site may remove.

Details are available in Cookie Policy.

7. Your Rights

Under GDPR, you have the right to:

  • to information and access to data;
  • when rectifying inaccurate data and completing incomplete ones;
  • to deletion and restriction of processing, when the legal conditions are met;
  • to data portability, for processing based on consent or contract and carried out automatically;
  • to opposition to processing based on legitimate interest;
  • to withdraw consent at any time, without affecting the legality of the processing previously carried out;
  • not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you. The site does not currently use such decisions.

To exercise your rights, write to office@investestepentruviitorultau.ro. We respond without undue delay and in any case within one month of receiving the request. For complex or numerous requests, the deadline can be extended by a maximum of two months, with information and reasons for the extension in the first month. Only if there are reasonable doubts about the applicant's identity can we ask for additional information strictly necessary to confirm the identity.

If you consider that the processing violates the law, you can file a complaint at The National Supervisory Authority for the Processing of Personal Data (ANSPDCP) or to the competent supervisory authority for the place of residence, the place of work or the place of the alleged violation. This right does not affect access to other administrative or judicial remedies.

8. Mandatory nature of the data

Fields marked as mandatory in the form are required to receive and process the message. If you don't provide them, we can't respond through that channel. Consent for "Statistics and Campaigns" and "External Content" is optional; refusal does not condition the use of basic functions.

9. Security and Incidents

We apply technical and organizational measures proportionate to the risks, including access control, updates, backups, data minimization, encrypted connections and technical monitoring. No system connected to the Internet can guarantee zero risk. Incidents are documented and evaluated; when GDPR requires it, we notify the supervisory authority without undue delay and, if possible, within 72 hours at most, and affected individuals are informed when there is a high risk.

10. Updates and Regulatory Framework

We may update this information when site features, providers or legal requirements change. The current version and update date are permanently published on this page. If the change affects consent-based processing, we will ask for a new consent when necessary.

The main acts considered are Regulation (EU) 2016/679 (GDPR), Law no. 190/2018 and Law no. 506/2004.

Community map

Version dated 10 August 2026. The controller is Asociația „Investește pentru Viitorul Tău” Buzău, at Jud. Buzău, Mun. Buzău, Bld. Nicolae Bălcescu, BL. Crinul Alb, Ap. 46, Romania. For rights requests and manual withdrawal, contact office@investestepentruviitorultau.ro. The controller has not appointed a DPO; requests are handled by the controller through the same address.

What we publish and why

A person aged 18 or over may propose their own community profile. We collect first name, last name, locality and a short public text. The person may optionally attach a JPEG photograph showing only themselves. Every proposal is moderated; nothing is published automatically.

After approval, the first name, last name, locality, text and optional sanitised photograph become public. A moderator may assign the approximate centre of the locality for map placement; this is not the person’s position or address.

Do not provide data about children or third parties, special-category or criminal-offence data, email, telephone, social accounts, identifiers, street, building number, home address, precise coordinates or other contact data. A photograph must not include children, other people, documents, badges, vehicle plates or precise-address clues.

Consent and declaration

The legal basis for receiving, moderating and publishing the profile is your consent under Article 6(1)(a) GDPR. The form uses separate controls that are unchecked by default:

  1. consent to process and publish worldwide, for no more than 12 months, your first name, last name, locality and text;
  2. if you upload a photograph, separate consent to sanitise and publish worldwide the resulting JPEG;
  3. a separate declaration that you are at least 18, submit only your own data, the optional photograph shows only you, and you have the right to publish it.

The declaration is not consent and does not replace it. These consents are not bundled with cookie choices, Turnstile, loading OpenStreetMap or another purpose. You may browse the map/list without submitting a profile.

Worldwide visibility and copying

An approved profile is available worldwide without authentication. Search engines may index it, and third parties may copy, archive, redistribute or automatically collect it through scraping, including outside the European Economic Area. We can erase the origin and caches under our control, but cannot guarantee recall of copies previously made by third parties or immediate removal from every index.

Optional photograph

The initial version accepts JPEG only: source up to 1.5 MiB, base64 representation up to 2.0 MiB, entire request body up to 2.1 MiB, and image up to 4 megapixels and 4,096 px on either side. The original is processed in memory only and is never stored. We re-render and re-encode it into a new JPEG with a maximum 800 px edge and maximum 400 KiB; only that result may be stored as a BLOB in the dedicated database.

Re-encoding removes EXIF, GPS, thumbnails and other metadata. We do not perform face recognition, face comparison, biometric templates, unique identification or inference. The photograph is served using a random identifier, only for a valid public profile, with a uniform 404 response and Cache-Control: private, no-store. There is no public file in the WordPress Media Library or webroot.

Consent evidence and withdrawal code

While the profile exists, we keep minimal evidence: opaque internal ID, notice/control versions, consent and declaration timestamps, and withdrawal/renewal state and timestamps. It does not include IP, full User-Agent, email, telephone, signature or the original photograph. After the profile is erased, the related evidence has a retention period of 0 days and is cascade-deleted, with no separate copy retained.

On submission, the server generates a 256-bit CSPRNG bearer code and displays it once. The server retains only its hash; the clear code is not sent by email, URL query, referrer, analytics or logs. You can use it to withdraw the profile without an account. If it is lost, contact office@investestepentruviitorultau.ro. Withdrawal is free and as easy as giving consent and does not affect the lawfulness of earlier processing.

Retention and erasure

  • pending proposals are erased after 29 days;
  • rejected proposals are erased 29 days after rejection;
  • published profiles expire after 12 months and are erased unless you actively renew the current consents;
  • the photograph expires and is erased with the profile;
  • withdrawal, erasure or expiry cascade-deletes the profile, photo BLOB and dependent data and starts purging caches under our control.

We do not collect a contact channel in the profile and do not promise an expiry reminder. Renewal is never inferred from a visit or silence and requires a new affirmative choice.

Backups and restoration

The dedicated database follows a separate backup policy with a maximum period of 30 days. Erasure does not immediately rewrite immutable backups; backups remain isolated, access-restricted and are not used for publication. A minimal suppression register, containing no name, text, photograph, bearer code or consent evidence, prevents reappearance after restoration and is erased after 60 days. After restoration, the service stays closed until suppressions, withdrawals and retention are reapplied, erased data is confirmed absent, caches are purged and stale secrets are rotated.

Contracted hosting, maintenance and backup providers may receive data only in the roles and within the limits needed to provide their services. You may ask the controller at the email address above for current information about this category of recipients.

Security and external services

We use rate limiting and Cloudflare Turnstile to prevent abuse, based on our legitimate interest in securing the service under Article 6(1)(f). The raw IP is not stored in the profile row. Cloudflare may process IP, TLS fingerprint, User-Agent, sitekey/origin and anti-abuse signals. Cloudflare describes a processor role for protecting the website and a separate controller role for improving Turnstile; processing and any transfers follow the applicable contractual mechanisms and the provider’s current subprocessor list.

The list works without external geographic services. Only after “Load map” does the browser connect to OpenStreetMap Foundation/Fastly and may disclose IP, User-Agent, referrer, date/time and requested tiles. If you then type a locality in the form, only the locality name is sent to OpenStreetMap’s Nominatim service to identify its approximate centre; first name, last name, profile text, photograph, withdrawal code and consent evidence are not sent. OSMF acts as an independent controller, not our processor. See the OSMF Privacy Policy and Turnstile Privacy Addendum.

Your rights

You may request access, rectification, erasure, restriction and portability where applicable, and may withdraw consent at any time. We will not request disproportionate additional data. Contact the controller at office@investestepentruviitorultau.ro or at the postal address above. The controller has not appointed a DPO. You may lodge a complaint with the Romanian data protection authority (ANSPDCP) or another competent supervisory authority.