Privacy policy

Privacy policy
  1. Purpose of the document
  2. Introduction
  3. Policy on personal data processing
  4. Definitions
  5. Principles regarding personal data processing
  6. Rights of data subjects
  7. Consent
  8. Privacy by design
  9. Transfer of personal data
  10. Person responsible for personal data processing
  11. Information security
  12. Security breaches
  13. Data retention
  14. GDPR compliance
  15. Changes to this policy

Purpose of the document

This document sets out the responsibilities and policy of TĂȘULEASA SOCIAL ASSOCIATION regarding the confidentiality and protection of personal data processing.

The policy illustrates TĂȘULEASA SOCIAL ASSOCIATION commitment to respecting fundamental rights and freedoms, confidentiality, and the protection of personal data. TĂȘULEASA SOCIAL ASSOCIATION ensures that personal data is processed fairly, lawfully, and with full transparency.

This policy establishes the principles and guidelines followed for the protection of personal data and aims to inform about:

  • personal data collected by TĂȘULEASA SOCIAL ASSOCIATION and the purposes of that collection;
  • how personal data is used;
  • the rights of data subjects over personal data.

The policy applies to all personal data processed as part of providing TĂȘULEASA SOCIAL ASSOCIATION services and products. All personal data operations must comply with this policy.

This policy may be updated over time, especially to take account of regulatory changes or to indicate changes in TĂȘULEASA SOCIAL ASSOCIATION practices regarding personal data.

Introduction

TĂȘULEASA SOCIAL ASSOCIATION uses in its commercial activities a variety of data relating to natural persons, including data about:

  • Current, former, and potential employees
  • Customers
  • Suppliers
  • Users of its websites
  • Visitors to the company premises

In collecting and processing this data, the organization is subject to various laws that control how such activities may be carried out and the safeguards that must be applied.

The purpose of this policy is to set out the relevant legislation and describe the measures that TĂȘULEASA SOCIAL ASSOCIATION applies to ensure compliance with it.

This control applies to all systems, people, and processes that make up the organization information systems, including board members, employees, suppliers, and other third parties who have access to TĂȘULEASA SOCIAL ASSOCIATION systems.

Policy on personal data processing

Regulation (EU) 2016/679 on the protection of natural persons with regard to personal data processing and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation) is one of the most significant pieces of legislation affecting how TĂȘULEASA SOCIAL ASSOCIATION carries out its information processing activities.

Definitions

Of the 26 definitions mentioned in the GDPR, the most relevant for this policy are the following:

  • "personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier;
  • "processing" means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, restriction, erasure, or destruction;
  • "controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of processing personal data;
  • "processor" means the natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller;

Principles regarding personal data processing

Personal data will be:

  • Processed lawfully, fairly, and transparently in relation to the data subject (lawfulness, fairness, and transparency);
  • Collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes; further processing for archiving, scientific, historical, or statistical purposes is not considered incompatible with the original purposes;
  • Adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (data minimization);
  • Accurate and, where necessary, kept up to date; every reasonable step will be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased or rectified without delay;
  • Kept in a form that permits identification of data subjects only for as long as necessary for the purposes for which the personal data is processed; personal data may be stored for longer periods where it is processed solely for archiving, scientific, historical, or statistical purposes, subject to appropriate safeguards;
  • Processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (integrity and confidentiality).

The controller is responsible for complying with the principles above, and compliance must be demonstrable at all times.

TĂȘULEASA SOCIAL ASSOCIATION will ensure that it complies with all these principles both in the processing it currently carries out and as part of introducing new processing methods.

Rights of data subjects

Data subjects benefit from the following rights under applicable legal provisions:

  • the right to withdraw consent to processing at any time, where processing is based on consent, without affecting the lawfulness of processing based on consent before its withdrawal;
  • the right to request access to personal data;
  • the right to request rectification of personal data;
  • the right to request erasure of personal data
  • the right to restriction of processing;
  • the right to object to processing, under the conditions provided by law;
  • the right to data portability;
  • the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing.

To ensure respect for each of these rights, TĂȘULEASA SOCIAL ASSOCIATION implements appropriate procedures that allow the necessary measures to be taken within the legal deadlines.

Except where necessary for a reason permitted by the GDPR, the company will obtain explicit consent from a data subject to collect and process their data. Transparent information about the use of personal data will be provided to data subjects when consent is obtained.

If personal data is not obtained directly from the data subject, this information will be provided within a reasonable period after obtaining the data and no later than one month.

Privacy by design

TĂȘULEASA SOCIAL ASSOCIATION has adopted the privacy by design principle and will ensure that the definition and planning of all new or significantly modified systems that collect or process personal data are subject to due consideration of privacy issues, including carrying out one or more data protection impact assessments.

The data protection impact assessment will include:

  • Considering how personal data will be processed and for what purposes;
  • Assessing the processing of personal data from the point of view of necessity and proportionality to the purpose or purposes;
  • Assessing risks for data subjects;
  • The controls necessary to address identified risks and demonstrate compliance with the legislation.

The use of techniques such as pseudonymization or anonymization will be considered where applicable and appropriate.

Transfer of personal data

Transfers of personal data outside the European Union will be reviewed very carefully before the transfer takes place, to ensure that they fall within the limits imposed by the GDPR. This assessment depends partly on the European Commission adequacy judgment for the country receiving the data and may change over time.

International intragroup data transfers will be subject to legally binding agreements - binding corporate rules - that provide enforceable rights for data subjects.

Person responsible for personal data processing

Based on the criteria mentioned in the GDPR, TĂȘULEASA SOCIAL ASSOCIATION is not required to appoint a data protection officer. However, TĂȘULEASA SOCIAL ASSOCIATION has designated a person responsible for personal data processing.

The designated responsible person is permitted to hold other functions. Other tasks and duties may also be entrusted to this person, provided that they do not create a conflict of interest.

Information security

TĂȘULEASA SOCIAL ASSOCIATION uses a series of physical, electronic, and managerial measures to keep personal information safe, accurate, and up to date. These measures include:

  • educating and training relevant staff so that they are aware of our confidentiality obligations when handling personal information;
  • administrative and technical controls to restrict access to personal information based on contractual access needs;
  • technological security measures, including firewalls, encryption, and antivirus software; and
  • physical security measures, such as staff security passes for access to our premises.

Security breaches

TĂȘULEASA SOCIAL ASSOCIATION policy is to be fair and proportionate when considering the actions that must be taken to inform the affected parties about personal data breaches. Where a breach is likely to result in a risk to the rights and freedoms of natural persons, the relevant supervisory authority will be informed.

Data retention

The retention period for personal data varies depending on its nature and the purpose pursued by the processing concerned. Where personal data is no longer necessary for the purposes for which it was collected, it will be deleted or anonymized.

The main personal data retention periods used by TĂȘULEASA SOCIAL ASSOCIATION are:

  • for customer management and the products and services offered by TĂȘULEASA SOCIAL ASSOCIATION or its subsidiaries: the duration of the contractual relationship;
  • for commercial prospecting: 3 years from the last contact with the prospect or until consent is withdrawn;
  • for telephone call recordings in customer service: 6 months from the recording date;
  • for detecting, preventing, and combating fraud and cybercrime: 12 months from the fraud alert date;
  • for processing rights exercise requests: 5 years for data relating to the processing of your requests, and 1 year for identity documents;
  • for accounting records and financial obligations: 10 years from the end of the current financial year.

At the end of these periods, TĂȘULEASA SOCIAL ASSOCIATION will destroy the data in accordance with its internal policy or anonymize it for use for statistical purposes.

GDPR compliance

TĂȘULEASA SOCIAL ASSOCIATION will take the following actions to ensure that it continuously complies with the GDPR accountability principle:

  • The legal basis for personal data processing is clear and unambiguous
  • A data protection responsible person is appointed within the organization
  • All employees involved in personal data processing understand their responsibilities for complying with good data protection practices
  • Data protection training is provided to all staff
  • The consent rules are respected
  • Data subjects who wish to exercise their GDPR rights are provided with ways to do so, and such requests are handled effectively
  • Periodic reviews are carried out for procedures involving personal data processing
  • Privacy by design is ensured for all new or modified systems and processes
  • The following documentation regarding processing activities is recorded:
  • The name of the organization and relevant details
  • The purposes of personal data processing
  • Categories of persons and personal data processed
  • Categories of recipients of personal data
  • Agreements and mechanisms for transferring personal data to third countries, including details of controls in place
  • Procedures regarding the data retention period are implemented
  • Technical and organizational measures regarding personal data protection are implemented

These actions will be reviewed regularly as part of the review process for the information security management system.

Changes to this policy

TĂȘULEASA SOCIAL ASSOCIATION recognizes that transparency is an ongoing responsibility, so it will keep this privacy statement under regular review. This policy was last updated in February 2026.

To highlight changes made to the policy, the date at the top of this document will be changed. The new, amended, or modified policy will apply from the date of publication.

Donate
Contribute to the maintenance and development of the Via Transilvanica path, through a simple or recurring donation!
Let's stay in touch!
Follow the path that unites! Subscribe to the Via Transilvanica newsletter for news, stories, and special updates about the trail and our community.