PRIVACY AND COOKIE POLICY

Asociația ȘCOALA DE VALORI

Who Will Process Your Data?

The personal data that you provide to us will be processed by Asociația ȘCOALA DE VALORI, a non-profit organisation registered in the National Register of Associations and Foundations under no. 12507/A/2010, Tax Identification Number 26781002, with the following contact details: correspondence address – 50A Șos. Pipera Street, 1st floor, Office 15, Sector 2, Bucharest, postal code 020112; email address: office@scoaladevalori.ro; telephone: +40 737 548 712.

Our projects have nationwide coverage, are aimed both at young people over the age of 16 and at children under the age of 16 and, as is typical of educational projects, are carried out over extended periods of time. For these reasons, pursuant to Article 37(1)(b) of the GDPR, we have appointed a Data Protection Officer who coordinates the collection and processing of personal data and ensures that such processing is carried out lawfully and securely, in accordance with the applicable legal requirements. The Data Protection Officer may be contacted using the contact details provided in the preceding paragraph or directly by email at date@scoaladevalori.ro.

What Categories of Individuals Are Covered by Our Activities?

Like any journey, the “journey” through life must be carefully prepared so that the road taken follows the desired route and the “traveller” following the winding paths of life may encounter only joy and beautiful “scenery”. Preparation for the journey through life takes place through education, which naturally begins in childhood.

Our educational activities and projects are intended for children, young people and adults who understand that, for as long as one can learn and play, the spirit remains young regardless of the age stated in one’s identity document. Where the data collected and processed relate to children under the age of 16, we also request information concerning their parents, so that we may inform them of how their children’s data will be processed and enable them to exercise the rights provided by applicable law.

Adaptability and cooperation are among the prosocial behaviours that we encourage and develop through our projects. We also demonstrate the power of the words “together” and “team” by personal example, working with partners from all sectors in order to ensure the successful implementation of our projects, including NGOs, public authorities and representatives of the business community. Accordingly, another category of individuals from whom we collect and whose personal data we process consists of representatives of our partners. These individuals are generally over the age of 18 and are employees or collaborators of those partners.

Education can take place in the traditional manner, through play or even through work. The happiest situation is work carried out with such pleasure and passion that it feels like play—or, conversely, play that produces tangible results. Understanding this, many young people who initially take part in our projects as beneficiaries choose to become volunteers in future projects and activities. We encourage young people to become involved as volunteers. Consequently, another category of data subjects consists of persons aged at least 16 who may be, are, or have previously been volunteers in our activities and projects.

What Data Do We Process, on What Legal Basis, for What Purposes and for How Long?

Because “in the beginning was… the word”, the first data we collect are those that enable us to communicate with you. These are the minimum contact details required, namely first name, surname, email address, Facebook, Instagram, LinkedIn or other social-media account identifier, and telephone number.

We process these data pursuant to Article 6(1)(f) of the GDPR, on the basis of our legitimate interest in communicating with you with a view to involving you in our projects as a beneficiary, participant, volunteer or collaborator. We retain these data for as long as education and the development of young people remain a principal objective under the Association’s Articles of Association. This is because, irrespective of age, you may continue to join our activities and we may therefore send you proposals and information that we consider relevant to your interests—provided, of course, that you allow us to do so.

We may obtain these data from information that you have voluntarily made public on the Internet or on social-media pages, from our collaborators acting on the basis of permissions you have granted to them, from the contact information you enter into forms available on websites managed by us, or from messages and telephone calls through which you contact us.

When communication develops into a legally regulated collaboration, applicable legislation requires us to collect and process additional information needed to conclude legally valid agreements and contracts or to provide information to public authorities through specific documents, such as tax declarations or employment contracts.

Such data are processed pursuant to Article 6(1)(b) or Article 6(1)(c) of the GDPR and vary from case to case depending on the applicable legal requirement. We endeavour to limit these data to identification information, adding only your address to your contact details. However, in certain cases, we are required to collect the series and number of an identity document, the Romanian Personal Numerical Code, or information concerning employment.

We may also be required to collect special categories of personal data, such as health data, information concerning racial or ethnic origin, or other information of this kind. Where such data are not collected in fulfilment of a legal obligation, but on the basis of Article 6(1)(a), (b) or (f) of the GDPR, we use them only when organising activities involving people from diverse ethnic backgrounds. These data allow us to organise the activities and adapt the educational content to the specific culture of each participant, so that our programmes may be readily accepted and understood.

The retention period for such data depends on the legal provisions requiring us to collect them and may range from three years—the limitation period applicable to most commercial contracts—to 75 years, in the case of data held in personnel files relating to individual employment contracts. Where such processing is based on your consent under Article 6(1)(a) of the GDPR, the data are retained for the period specified in that consent.

Promoting our activities is an integral part of every project we carry out. On the one hand, promotion enables young people who could not take part as participants, for various reasons, to benefit from the educational content of the project being promoted. On the other hand, it enables other young people to “find” us and join our activities.

Promotion generally involves media content—audio recordings, photographs and video recordings—published, sometimes live, on the most open and extensive communications network in the world: the Internet, particularly on social-media platforms such as Facebook, Twitter, YouTube and Instagram.

A separate category of data therefore consists of images, films and audio-video recordings in which the principal “actors” are both us and you—the participants in our projects and the partners who help us bring our ideas and hopes to life.

Although Article 9(2) of Romanian Law no. 190/2018 permits certain forms of such processing without the participants’ consent, you will always be informed when this type of processing may become public or may take place live, thereby giving you the opportunity to express your consent before the data are published. Where material intended for publication on social media also relates to minors, we will first obtain the consent of their parents or legal representatives.

The period for which these data remain publicly available corresponds to the period during which the projects may continue to be of interest, generally no more than five years following the last activity of the type being promoted. The lawfulness of this processing is also based on Article 6(1)(f) of the GDPR.

Given the complex public-health context that we must learn to manage personally, emotionally and professionally, most of our activities take place online. One of the principal advantages of digitised information is the ability to reproduce a recorded event in an identical, objective and unaltered manner, regardless of how much time has passed since it took place.

For this reason, most workshops and educational activities are recorded for the purpose of analysing and improving trainers’ performance, the educational content and the project itself. As in the case of recordings made to promote our activities, you will always be informed when an online event is being recorded for internal use.

Such materials are processed on the basis of our legitimate interest in continuously improving the educational content of our activities, pursuant to Article 6(1)(f) of the GDPR. They will be stored on our information systems for no more than three years and will be reviewed only by a limited number of persons who are, have been, or will be involved in activities similar to the recorded event.

Lastly, collaborators who provide financial support for certain projects may request activity reports, including multimedia materials such as photographs, audio recordings and video recordings. Such materials may be processed within their own data networks or, in some cases, may be published and promoted under the name and brand of the partner providing the support.

You will also be informed whenever photographs, audio recordings or video recordings may be processed in this way, before you take part in the activity or join the project, so that you may make an informed decision about whether to participate. Such processing is lawful under Article 6(1)(c) of the GDPR because these obligations are always imposed by the sponsorship agreements concluded with our partners.

Because we strive for excellence, a distinct category of information consists of anonymous data collected automatically from visitors to our websites. Why is it distinct? Because it does not directly identify you as an individual, but because it may be associated with an identifiable individual, the GDPR treats it as personal data.

What does such information have to do with excellence? Quite simply, it enables us continuously to improve our online presence by analysing the geographical areas in which our activities have an impact, identified by IP address; the type of platform preferred by visitors, such as a PC, mobile telephone or tablet; and the pages most frequently accessed.

We optimise our content both by continuously adapting it in line with these statistical data and through the use of cookies, which are explained at the end of this document.

Anonymous data also include information obtained from you that is permanently anonymised, so that it can no longer be associated with the relevant individuals, and is used in studies and research concerning the impact of our projects.

All such processing is carried out pursuant to Article 6(1)(c) of the GDPR and for as long as education and the development of young people remain a principal objective under the Association’s Articles of Association.

How Do We Ensure the Security of the Data You Provide?

We process your data through our own information systems, through websites, through partners that provide us with information-technology services and through our own servers.

Even when we are eager to reach you, we act carefully and patiently when using these systems, complying with rules designed to ensure the confidentiality, integrity and availability of the data you provide.

We apply strict rules to ensure that only authorised persons have physical access to our information systems; that the systems may be used only by persons entitled to use them; that users have access only to the data strictly necessary for the activities they perform; and that data are not lost and can be restored in the event of a security incident. We also have procedures for managing such incidents if they occur.

To Whom Do We Disclose the Data We Hold About You?

As a general rule, the data you provide are processed only within the Association.

Where we work as a team with various partners, or where such data are requested from us, the data will be disclosed to our collaborators only after they have undertaken, pursuant to Article 26 or Article 28 of the GDPR, to comply with confidentiality and data-protection obligations at least equivalent to those that we assume towards you.

Such partners may include trainers with whom we collaborate, sponsors who are able and willing to provide material or financial support for certain projects, or providers of services connected with our activities.

Do We Process Personal Data From or Outside Romania?

Yes. Our activities sometimes involve participants from other countries or collaborators established in other countries.

Where processing takes place in Member States of the European Union, the GDPR applies consistently in those states.

However, where processing takes place in countries that are not members of the European Union, we will request your explicit consent. This is because the processing of personal data in such countries may involve additional risks. It may not be possible to guarantee that you will be informed whenever your data are processed, that an independent authority exists to ensure compliance with data-processing principles, or that you will be able to lodge complaints if your rights are infringed.

In addition, in countries that are not—or are no longer—members of the European Union and are therefore not required to apply the GDPR, entities holding and processing your data may make decisions based on profiling or automated processing that may have legal or similarly significant effects, without giving you the right to request human intervention. The GDPR guarantees that right throughout the EU under Article 22.

Do We Use Automated Decision-Making or Profiling That Could Produce Legal or Similarly Significant Effects for Data Subjects?

No. Automated processing or profiling carried out by us will never produce legal effects concerning you.

Where the outcome of processing may have such effects—for example, validation of the results of competitions, tests or interviews—the information will no longer be processed exclusively by automated means. Decisions will be made only after the data have been reviewed by human operators.

What Rights Do You Have in Relation to the Data We Hold About You?

Right to Information and Access to Personal Data

When we obtain personal data directly from you—or within a maximum of 30 days where the data are obtained indirectly from third parties or from the Internet—we provide you with all the information contained on this web page, either in a separate document or in a concise notice containing a link to this page.

Knowing who holds and processes your personal data enables you to exercise your right of access. By submitting a simple request, you may exercise this right in relation to any legal entity established in the European Union that you know or merely suspect holds data concerning you.

That entity must respond within 30 days and provide information of the kind presented on this web page, together with the source from which your data were obtained.

Right to Rectification or Erasure

This right enables you to request the correction of inaccurate personal data that we hold about you or, where the conditions laid down in Article 17(1) of the GDPR apply, the complete erasure of those data.

We will be required to erase the data unless Asociația ȘCOALA DE VALORI is subject to a legal obligation requiring their continued processing. Any such legal obligation will take precedence over the right to erasure.

Right to Restriction of Processing

You may request the restriction of any processing pursuant to Article 18 of the GDPR until any objections raised in connection with the exercise of this right have been resolved, including objections concerning the accuracy of the data, the lawfulness of the processing, or an objection to processing carried out exclusively by automated means.

Right to Object to Processing or Withdraw Consent

You may object at any time to processing carried out on the basis of our legitimate interest in fulfilling the Association’s objectives. You may do so by sending us a request or by using our information systems—for example, the unsubscribe mechanism included in informational messages concerning particular topics.

Where processing is based on your prior consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the consent was withdrawn.

Right to Data Portability

In the relatively rare situations in which personal data have been supplied in a structured, commonly used and machine-readable format, you have the right to request that Asociația ȘCOALA DE VALORI transmit those data to another controller without hindrance from us.

What Can You Do If You Believe We Have Not Responded Properly to a Request Concerning the Data We Hold About You?

Where you submit a request based on your rights regarding personal data and believe that our response is inadequate, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing.

The Romanian National Supervisory Authority for Personal Data Processing may be contacted by telephone at +40 318 059 211, by email at anspdcp@dataprotection.ro, or through its website, www.dataprotection.ro.

Cookies: What Are Cookies?

Cookies are small files saved on a user’s computer. They are designed to store a very small amount of data relating to a particular visitor and the website accessed by that visitor.

They may be accessed both by the person who owns the computer on which the cookies have been stored automatically and by the website that transmitted the file.

This type of processing enables a server to provide a web page tailored to a particular user or even to transmit information from a visit to one website to another similar website operated by the same owner.

How Can I Find Out Whether Cookies Are Enabled in My Browser?

To check whether your browser is configured to allow cookies, look in the browser settings for the section dedicated to cookies, generally found under “Privacy and security”.

That section will also contain information on enabling or disabling cookies, deleting cookies and, in many cases, viewing their contents.

What Information Is Stored in a Cookie?

Each cookie file is, in reality, a small table or a line of text containing pairs of values—keys and data—for example, (first name, John) and (surname, Smith).

Once the cookie has been read by code on the server or the client computer, the information can be retrieved and used to personalise the web page as appropriate.

When Are Cookies Created?

Data are usually written to a cookie when information is submitted to the website being accessed. For example, after you click a “submit” button, the page processing the data may store certain values in a cookie.

Where the user has chosen to disable cookies, the write operation will fail. Subsequent visits that would otherwise retrieve information already submitted through the cookies will either operate according to the default procedure for new visitors or ask the user to re-enter the information that would have been stored in the cookie.

Why Are Cookies Used?

Cookies provide a convenient way of associating information with the way in which a website is used, without requiring the website itself to store large amounts of data concerning every visitor.

In addition, storing data on a server without using cookies would require every user to be recognised solely through authentication based on a username and password.

The use of cookies also reduces the amount of personal data processed within controllers’ own systems because a cookie is stored on the information system owned by the individual concerned by that processing.

How Long Is a Cookie Processed?

A cookie’s expiry date may be set when the cookie is created.

By default, a cookie is “destroyed” when the browser window is closed, although it may be designed to remain in place for a period after the website has been accessed.

Cookies may be deleted by the user at any time.

Who Can Access Cookies?

When a cookie is created, its visibility may be controlled by setting the primary domain of the website that uses it. The file will then be accessible to any website belonging to that domain.

For example, the domain may be set to “primarydomainname.ro”, in which case the cookie will be available to websites at “primarydomainname.ro”, “xyz.primarydomainname.ro” or other sites within the same domain.

This may be used to enable related pages to “communicate” with one another.

How Secure Are Cookies?

There are many concerns about privacy and security on the Internet.

Cookies do not in themselves constitute a threat to privacy because they can be used only to store information that the user has voluntarily provided or that the web server already holds.

Although it is possible for such information to be made available to certain third-party websites, this does not create risks beyond those inherent in storing information in a central database.

Where you are concerned that information supplied to a web server may not be treated confidentially, you should consider whether it is genuinely necessary to provide that information.

What Are Tracking Cookies?

Some commercial websites contain embedded advertising supplied by a third-party website. Such advertisements may store a cookie for that third-party website.

The cookie may contain information including the name of the website, particular products viewed, pages visited and similar information.

When the user later visits another website containing a similar advertisement embedded by the same third party, the advertiser may read the cookie and use it to determine certain information about the user’s browsing history.

This enables publishers to display advertisements targeted to a user’s interests, thereby theoretically increasing the likelihood that the advertisements will be relevant.

However, many people regard tracking cookies as an invasion of privacy because they allow advertisers to build user profiles without the users’ consent or knowledge.

How Can Cookies Be Managed or Deleted?

Where a website does not offer mechanisms for selecting or rejecting cookies, the storage of cookies on a computer can be controlled through the browser option that allows cookie files to be refused.

Browser settings may therefore be used either to prevent cookies from being accepted or to allow cookies only from particular websites.

Please bear in mind that disabling or deleting certain cookies may adversely affect or limit certain website functions.

To control how cookies are accepted in your browser, follow the steps below. These instructions may become outdated as browser applications are changed by their developers.

Google Chrome

Click the menu button with the three dots in the upper-right corner of the browser window and select Settings.

Select Advanced and then Content settings.

Click Cookies and then “Allow sites to save and read cookie data”.

Mozilla Firefox

Click the “Open menu” button with three horizontal lines in the upper-right corner of the browser window.

Select Options and then Privacy & Security.

Locate the heading “Block cookies and site data”.

Microsoft Internet Explorer 11 (Windows 10)

Select Settings in the upper-right corner of the browser window, choose Internet Options and then click the Privacy button.

Select Privacy.

Under Settings, select Advanced and choose whether to allow or block first-party cookies and third-party cookies.

Safari

Click Safari at the top of the browser window and select Preferences.

Click Privacy.

Select “Allow from websites I visit”.

Opera

Click Settings, then select Preferences > Advanced > Cookies.

Select one of the available options:

Accept cookies
Accept cookies only from the sites I visit
Do not accept cookies
Manage cookies

Microsoft Edge

In Microsoft Edge, go to More > Settings.

Select View advanced settings.

Under Privacy and services > Cookies, select the appropriate option:

“Block all cookies” prevents all websites from saving cookies on your computer.

“Block only third-party cookies” allows cookies from the website that you currently have open but blocks cookies from external web services, such as advertising embedded in the web pages you visit.

Deleting Cookies

For up-to-date information on deleting cookies, you may consult the following links:

Google Chrome
https://support.google.com/chrome/answer/95647?hl=en-GB

Mozilla Firefox
https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectlocale=en-US&redirectslug=delete-cookies-remove-info-websites-stored

Internet Explorer
https://support.microsoft.com/ro-ro/help/17442/windows-internet-explorer-delete-manage-cookies

Safari
https://support.apple.com/ro-ro/guide/safari/sfri11471/mac

Opera
https://help.opera.com/en/latest/security-and-privacy/

Microsoft Edge
https://support.microsoft.com/ro-ro/help/4468242/microsoft-edge-browsing-data-and-privacy