PRIVACY POLICY

INFORMATION NOTE

We provide this Privacy Policy to explain how we process and protect your personal data when you use our site.

When we collect this data about you, we act as a personal data controller and we have a legal obligation to inform you about the processing of personal data as a user of our site, namely: what data we collect, from whom, for what purpose, the rights you have and how you can contact us with any question related to Regulation 679/2016 and data protection. This document also includes a Cookie Policy.

According to the requirements of Law no. 190/2018 on measures for the implementation of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing of Directive 95/46 / EC (General Data Protection Regulation) and of Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector we have the obligation to manage safely and only for the specified purposes, the personal data you provide us about you, a member of your family or another person.

CONTENT OF THE INFORMATION

  1. Who we are ?
  2. What is personal data?
  3. Who are the people targeted?
  4. What personal data do we collect?
  5. Purpose of data processing
  6. Duration of data processing
  7. Data storage
  8. Transfer of personal data
  9. The rights of data subjects
  10. Cookies policy
  11. Data security
  12. Privacy Policy Updates
  13. Contacts.

 1.WHO ARE WE?

The Association for Health and Medical Programs (hereinafter referred to as “the Association” or “ASPM”), headquartered in Bucharest, Calea Plevnei, no. 222, et. 1, Sector 6, CIF 43916975, bank account RO23 BACX 0000 0021 1580 6001 opened at UniCredit Bank Bucharest, is the owner of the website: https: // www .aspm.ro which is the subject of this information.

The site www.aspm.ro is an online community that brings our services to you. This information note explains why we need certain personal data in order to provide certain services. Please read it carefully, because this way you will understand and control as you wish the type and volume of personal data that will be processed in your online environment.

2. WHAT ARE PERSONAL DATA?

As explained in Regulation 679/2016, “personal data” means any information concerning an identified or identifiable natural person (“data subject”). An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifying element, such as a name, an identification number, location data, an online identifier or one or more specific elements, specific to his physical, physiological, genetic, mental, economic, cultural or social identity.

Personal data are, but are not limited to:

  • name and surname,
  • address,
  • national identification number – identity card, passport, CNP, driver’s license, etc.
  • email address
  • IP address
  • location data
  • bank card details
  • certain types of cookies.

Thus, personal data are considered to be those that allow the identification of a person, or that together with other data sets allow the operator to identify the data subject.

Identification data belonging to a legal entity are NOT personal data.

3. WHO ARE THE PERSONS TARGETED?

The persons covered by this processing are:

  • Our contractual partners such as suppliers, customers (“Business Partners”);
  • Visitors and users of our site https://www.aspm.ro (“Users”);

4. WHAT PERSONAL DATA DO WE COLLECT?

We collect and process personal data from the information you provide us, directly, as follows:

  • in case of subscribing to our newsletter,
  • punctual or recurring donations through the site
  • redirection of a tax rate to us by completing the Declaration 230
  • by sending messages to the departments in the Contact section of our site,
  • in case of participation in our events
  • by correspondence with us by telephone, e-mail or in any other way.

In these situations, data will be collected such as: name and surname, address, telephone number, information about the bank card with which you will make the payment, identification data of the company, what you want to send us, etc.

  • From the information we obtain when you use our services

Every time you visit the website https://www.aspm.ro, we automatically collect the following data:

  • technical data, for example this may include the Internet Protocol (IP) address used to connect your computer to the internet, login information, browser type and version, time zone setting, browser extension types and versions (plug-ins), system and operating platform, device type and mobile device brand; this data is collected and processed on our behalf through third-party cookies and you can find more information about this at Cookies Policy
  • data about your visit, for example this may include data about the URL, sequence of clicks to, through and from the website https://www.aspm.ro (including date and time), information or services that you you have viewed or searched the site (links, images, banners, boxes, videos), the interaction with the messages received by you in the e-mail box (viewing, clicking on newsletters)

If we obtain your personal data from a third party, we will provide you with all relevant information about their processing as soon as possible, but no later than one month after obtaining your personal data.

  • through cookies. When you use our site to search for our events and services and to view the information we provide, a number of cookies are used by us (first party cookies) and third parties (third party cookies). to allow the operation of the site, to collect useful information about visitors and to give you the best experience in using the site https://www.aspm.ro See the Policy on the use of cookies

5. PURPOSE OF DATA PROCESSING AND LEGAL BASIS

When we request personal data in order to comply with legal or contractual obligations, the provision of such personal data by you is mandatory. This means that if such personal data is not provided, we will not be able to manage the contractual relations or comply with the legal obligations imposed on us. In all other cases, the provision of personal data is optional and you are not obliged to provide it.

  • Name, surname, address are required when you donate or redirect a tax rate to us by completing the Declaration 230. We may also request other tax information in accordance with the law. The processing of this data is based on the legal obligation. We store this data for a period of 3 years.
  • We use the information to check the details of the bank card with which you want to make the donation on the site. We request this information to process your payment. Your bank card details are sent to a third party payment processor based in the EU. We do not keep your bank card information.
  • Your phone may be requested for various services that require direct contact with you. We process this data in order to deliver the services you have chosen (newsletters, messages and requests to us). The legal basis of this processing is the entry and execution of the contract between us and you, a contract in which you are a party every time you access the site https://www.aspm.ro by accepting the Terms and Conditions. We store this data for a period of 3 years.
  • When you send us a message through the website https://www.aspm.ro we collect and process your data based on the legitimate interest to respond to your request. We store this data for a period of 3 years. We may send you an email several times after you make a request to ensure that we have answered your question and to improve our user experience.
  • If you voluntarily provide us with personal data (including sensitive personal data) through your interaction with the website https://www.aspm.ro or by correspondence with us by phone, e-mail or in any other way, of our own free will and not at our request, we will delete such personal data from our systems if we do not consider that their processing is necessary for a legitimate purpose of ASPM, unless you have made this data public ( in which case we will delete this data from our site only if the law requires it or if we do not want to keep it.
  • We use the information we obtain when you access the site https://www.aspm.ro based on the legitimate interest to observe how you can optimally navigate the pages of the site, to what extent these pages correspond to the display needs of your particular device, to diagnose any problems that our servers have when delivering pages to certain types of devices, to analyze trends, etc. This information allows us to present the content of the site in the most efficient way for you, to improve the site and its functionality and to manage it efficiently. The information is also required for internal operations, including for troubleshooting, data analysis, testing, research, statistics and research purposes and another very important reason to keep the website https://www.aspm.ro in good condition. safety;
  • We may use the information you provide for advertising and marketing, including for specific marketing purposes, so that we provide interesting content, including personalized content. In this case we will process personal data only with your consent. In these cases, we will ask for your consent separately, in a transparent manner. Therefore, categorically, the processed data is not used to send marketing communications unless you explicitly opt for it by giving consent.

In this case, the website https://www.aspm.ro provides you with an easy-to-use option to withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of the processing that took place before its withdrawal.

We may process your personal data, such as identification data, contact details and address of residence, and for the purpose of the possible exercise of our rights or claims against you in the future. This processing is based on our legitimate interest, and it is necessary to exercise our rights in the event of any disputes.

Specifically, we will use your personal information as follows:

Users and customers:

In order to provide the services, and make payments based on your donations, we may process your personal data, such as identification data, contact details, bank details.

This processing is based on:

  • Execution of a contract to which Users (especially customers) are party, or
  • A legal obligation that is imposed on us.

We may process personal data so that we can provide you with information about services that we believe are of interest to you. If you are an existing user, we will only contact you by e-mail, telephone or postal address (depending on your choice), with information about services similar to those that have been the subject of a previous interest or with information on the main news in the social field , charitable or economic, as reflected in the media through the newsletter.

If you are a new user, we will contact you by electronic means only if we have your prior consent. Whether or not you want us to use your data in this way, check the appropriate box on the form by which we collect your data.

We will not pass on your personal data to third parties for marketing purposes without your explicit consent.

We may also use your personal data to measure or understand your preferred content related to our products and to make suggestions and recommendations to other Users of our site about products that may be of interest to you.

Candidates for jobs published by ASPM:

In connection with your participation in the recruitment and selection process for one or more of the jobs listed as available, within ASPM, we may collect and process your personal data, (for example, the data in the CV that we send it), for the purpose of selection, evaluation of professional skills for the job / jobs you apply for, as well as for communication with you, during the recruitment process. This processing is based on the legitimate interest of ASPM. We will only keep this data for 6 months.

Through our work on the website https://www.aspm.ro, we will not collect or process sensitive personal data about you (for example, information about racial or ethnic origin, political opinions, religion or philosophical beliefs). .

We do not use the information you provide to make automated decisions that could affect you.

6. DURATION OF DATA PROCESSING

We will retain your personal data for the period necessary to fulfill the purposes listed in this Policy or for the period required by applicable national law, in accordance with the applicable minimum legal retention periods and / or as long as is necessary to exercise our legitimate rights ( and the legitimate rights of others).

  • If you have chosen to make a donation for the purposes supported by ASPM, we will keep your personal data for the legally binding period.
  • If we have a relationship with you as a Partner we will continue to retain this personal data until the termination of our relationship and then for the minimum retention period required by law.
  • If you subscribe to our newsletter, we will retain your personal data for as long as you wish to receive this information.
  • We do not keep your bank card details
  • If you have sent us messages on the site in connection with a situation, event, question, question or any other purpose, we keep this data for 3 years.
  • If you are a candidate for one or more of the jobs published on one of the recruitment sites (Hipo, eJobs, Linkedin), we will keep your personal data throughout the recruitment and selection process, plus a period of 6 months after the end of the recruitment process (if the candidate has not been hired in ASPM).
  • If we process personal data under your consent, this personal data will only be processed for the period provided by your consent, unless you decide to withdraw or limit your consent before the expiration of this period. In such cases, we will cease the processing of such personal data for the relevant purposes, subject to any legal obligation to process such personal data and / or our need to process such personal data for the purpose of exercising our legitimate rights. (including the legitimate rights of others).

7. DATA STORAGE

The website https://www.aspm.ro is managed and maintained by Sensigo Software SRL and hosted by the servers of Herzner Online GmbH.

8. TRANSFER OF PERSONAL DATA

We will only disclose your personal data for the purposes mentioned above and for the employees, proxies, associated operators or third parties listed below. In this regard, we make every effort to ensure that all of them comply with the provisions of Regulation 679/2016 and Law 190/2018 so that your personal data is processed, secured and transferred in accordance with applicable law.

Your personal data is administered internally (general databases of sites, by donors, event participants, users of our services) for the provision of our services and based on the legal obligation for the situations governed by the tax code in force. Authorized employees have access to the internal databases, which have received the necessary training to comply with the security of the databases, from the accounting, technical, legal, marketing or sales department.

  • We transfer data to proxies or associated operators

Your personal data is transferred where it is absolutely necessary, based on the principle of “need to know” – the need to know, to companies that provide us with services, such as:

  • Companies that provide us with accounting, legal services, auditors and other external consultants who may need access to information or data to provide their services.
  • Media agencies through which we organize promotional campaigns
  • Market research agencies that provide us with the necessary data for the development of the site and for offering the products and services as close as possible to your needs
  • The companies that provide for us the services offered on the site: newsletter, online customer support, call center, sale on our behalf, etc.
  • Telecommunications companies, cybersecurity, archiving, back-up and data recovery, etc.
  • The courier companies we use to deliver documents to or from you
  • We transfer data to third parties

Your personal data may be transferred to third parties, as follows:

  • If we have your consent for this
  • If requested by a person who proves that you are legally represented
  • If the data are requested by state authorities or institutions or in order to respect national security or to combat illegal activity
  • If we are required to protect the rights, property or safety of ASPM or the website https://www.aspm.ro, our employees, customers, suppliers or any other entities with which we collaborate

We inform you that any employee, proxy, associated operator or third party who processes personal data is limited by law and contract (confidentiality, security) to use your data for purposes other than those specified by us.

Except in the cases shown above, ASPM will not disclose, sell, give for consultation, rent your personal data.

  • Data transfer outside the EU / EEA

We inform you that some of the proxies, associated operators or third parties listed above may transfer personal data outside the EU / EEA (European Economic Area).

In this case, ASPM has included in the Privacy Policy measures to ensure that the recipient of this data will in turn protect your information. Among the adequate protections for this situation we list:

  • a decision on the appropriateness of the European Commission regarding the country or countries of destination;
  • appropriate mandatory corporate rules;
  • (an approved code of conduct, together with the binding and enforceable commitments of the data controller or the person authorized by the data controller in the non-EU and EEA country;
  • an approved certification mechanism, together with the mandatory and enforceable commitment of the data controller or the person authorized by the data controller in a non-EU and EEA country to apply the appropriate guarantees; or
  • U standard contractual clauses approved by the European Commission.

9. THE RIGHTS OF THE PERSONS CONCERNED

As a data subject, according to Regulation 679/2016 you have the following rights:

  • The right to information provided by art. 13 and 14 of the Regulation. This right allows you to know from the very beginning, when your data is collected, how it will be used, why, to whom it is transferred, the duration of the processing and your rights. Our privacy policy through this Information Note does just that.
  • The right of access to your data provided by art. 15 of the Regulation. This right allows you to obtain confirmation from us at any time whether or not your data is processed. If the data is processed, you can request a copy from us.
  • The right to rectify the data provided by art. 16 of the Regulation. This right allows you to request the rectification or completion of your data without undue delay.
  • The right to erasure of data (“the right to be forgotten”) provided in art. 17 of the Regulation. This right allows you to request the deletion of your data without delay. This right does not apply if further processing is necessary in the exercise of the right to free expression and information, if the processing is based on a legal obligation, if the data are processed in the public interest in the field of health, archiving, scientific, historical or statistical research. Also, the law does not apply if the data are necessary for the establishment, exercise or defense of an ASPM right in court.
  • The right to data restriction is provided by art. 18 of the Regulation. This right is temporary. You can ask us to restrict the data if you think they are inaccurate – while we are checking their accuracy or if the processing is illegal and you want to restrict and not delete the data; also, if we no longer wish to process this data but you request it from us in order to establish, exercise or defend a right in court. Following such a request, we will stop processing the data for a certain period of time. If the processing restriction is lifted, you will be notified.
  • The right to data portability is provided by 20 of the Regulation. This right refers to the possibility to receive your data provided in a structured, commonly used and automatically readable format and to transmit this data to another operator, without any opposition from us. The personal data referred to in this right are those obtained by us under the consent or on the basis of a contract or the processing of such data is carried out by automatic means. You have the right to request the direct transmission of your data to another operator, insofar as this can be done by us from a technical point of view.
  • The right to opposition is provided by art. 21 of the Regulation. You have the right at any time to oppose the processing of your data obtained on the basis of our legitimate interest (art. 6 paragraph 1 letters e and f) or the creation of profiles. If the purpose of the processing is direct marketing, the data subject has the right to object at any time to the processing.

The website https://www.aspm.ro always offers you the option to unsubscribe from the services we offer. The right to object to the processing of your data may be limited if we can demonstrate that we have legitimate reasons to process this data, which prevails over your interests.

  • The right not to be the subject of a decision based exclusively on automatic processing is provided by art. 22 of the Regulation. This right does not apply if the processing is legally based on the performance of a contract, or you have given us your consent to such processing, or the processing is authorized by national or EU law.
  • The right to withdraw your consent, at any time, without affecting the legality of the processing carried out on the basis of the consent before its withdrawal;
  • The right to file a complaint – art. 77 of the Regulation – to the National Authority for the Supervision of Personal Data Processing. B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania. +40.318.059.211 / +40.318.059.212, anspdcp@dataprotection.ro.

Please note that your rights may be limited in certain situations as set out in Article 23 of the Regulation and are subject to applicable laws and regulations regarding the protection of personal data.

Whenever you ask us to exercise these rights, you will need to prove your identity and provide us with other details to help us respond to your request. The answer to your request will be provided as soon as possible, within a maximum of 30 days and only in duly justified cases or if your request has a high degree of complexity, we will extend this period. You will be informed about the reasons and duration of the extension.

We will not charge a fee to respond to your request.

To exercise one or more of these rights, please contact us at the e-mail address gdpr@aspm.ro or by letter to ASPM: Calea Plevnei, no. 222, et. 1, Bucharest, Sector 6.

10. COOKIE POLICY

The https://www.aspm.ro website uses cookies to give you a better experience when browsing our site. This processing is based on your consent expressed on the site or through the settings in your browser. You can find more information about cookies at Cookies Policy.

11. DATA SECURITY

We keep your personal data on ours, located in Romania.

We use appropriate technical and organizational measures in order to protect personal data against loss, misuse, disclosure, alteration, unavailability, unauthorized access and destruction. Such measures include security of physical and logical access to servers, workstations, applications, staff accountability, encryption, passwords, security certificates, etc.

We have entered into contractual relationships with third parties that provide hosting services and these contracts include obligations regarding the organizational and technical security of personal data.

Data transmission over the Internet is not completely secure. Although we do our best to protect your data, we cannot guarantee 100% security of the data transmitted on our site; any transmission of personal data is at your own risk. Once we receive your data, we will use strict security procedures to try to prevent unauthorized access.

12. PRIVACY POLICY UPDATES

We regularly review and, as appropriate, regularly update this privacy policy when changes occur. We will update the version number and date of this document each time it is modified.

13. CONTACT DATA

You can contact us using any of the ways below:

  • By e-mail to gdpr@aspm.ro
  • By courier or mail to the address: Bucharest, Sector 6, Calea Plevnei, no. 222