Privacy Policy
Privacy and Data Security Policy of Asociația 2Celsius
Asociația 2Celsius provides this Privacy Policy to help you understand the type of personal data we collect about you, the reasons for collecting it, and to explain how we process and protect your personal data. Additionally, it clarifies how you can exercise your rights when you entrust us with your personal data. We request that you take a few moments to carefully read this Privacy Policy and familiarize yourself with its content. If you have any questions, please contact us using the contact information provided at the end.
Please note that the website may contain links to and from websites that may be owned by partner companies. If you access these websites, you should know that they have their own privacy policies, and we do not assume responsibility for the processing of your personal data by these websites.
Name and Address of the Data Controller
In accordance with the provisions of the General Data Protection Regulation (EU) 679/2016 – GDPR or the Regulation on the protection of natural persons with regard to the processing of personal data and the free movement of such data, Asociația 2Celsius is a data controller and processes personal data based on current laws and for legitimate purposes.
Asociația 2Celsius Cugir, Al. Sahia Street No. 18, Building C, Apartment 5, Alba County CIF: 26934505 Romania Email: office@2celsius.org Website: www.2celsius.org
General Information on Personal Data Processing
Generally, we record only the personal data you disclose when contacting us through the Contact page on our website www.2celsius.org or when subscribing to our newsletter.
We process your personal data responsibly, complying with legal requirements and under conditions that ensure security, confidentiality, integrity, availability, transparency, and respect for your rights.
This privacy and security policy for the protection of individuals with regard to personal data processing applies to all categories of individuals whose personal data is collected through the official website and processed for various purposes.
Through our website activities, we do not process sensitive personal data such as racial or ethnic origin, political opinions, religious or philosophical beliefs, health, sexual life, or sexual orientation. If you voluntarily provide such personal data through interactions with the website or through correspondence with us, by phone, email, or any other means, this data will not be recorded or will be deleted from our information system.
Legal Basis for Processing Personal Data
With the consent of the individuals concerned for the processing of personal data, Article 6 (1) (a) of the General Data Protection Regulation (GDPR) serves as the legal basis for processing personal data. For the processing of personal data necessary for the performance of a contract to which the individual is a party, Article 6 (1) (b) of the GDPR serves as the legal basis. This also applies to processing necessary to carry out pre-contractual actions. To the extent that processing personal data is necessary to fulfill a legal obligation to which Asociația 2Celsius is subject, Article 6 (1) (c) of the GDPR serves as the legal basis. If vital interests of the individual or other natural persons require the processing of personal data, Article 6 (1) (d) of the GDPR serves as the legal basis. If processing is necessary to protect legitimate interests of our organization or a third party, and if the interests, fundamental rights, and freedoms of the individual do not take precedence over these legitimate interests, Article 6 (1) (f) serves as the legal basis for processing.
Purposes of Processing Personal Data
We process your personal data for various technical, administrative, and operational reasons, such as:
- To present the website content in the most efficient manner and inform you about news related to the organization’s services that might be of interest to you;
- For website administration, maintenance, improvement, and security;
- For specific activities of the Human Resources/Volunteers department, if you are interested in joining our team.
When we request personal data to comply with legal or contractual obligations, providing such personal data by you is mandatory. This means that if such personal data is not provided, we will not be able to manage contractual relationships or comply with legal obligations imposed on us. In all other cases, providing personal data is optional, and you are not obligated to provide it.
Specifically, we will use your personal data as follows:
- To provide our services, we may process personal data such as identification data, contact data, residence data, and other personal data you may provide directly;
- We may process personal data to offer you information about services we believe may interest you. If you are already a beneficiary, we will only contact you via email with information about services or news in the field, as reflected through the newsletter, but only if you have subscribed and therefore given your explicit consent for such processing. We will not disclose your personal data to third parties for marketing purposes without your explicit consent.
Retention Period of Personal Data
We will retain your personal data for the period necessary to fulfill the purposes listed in this Policy or for the period imposed by national legislation, in accordance with the minimum legal retention periods and/or as long as necessary to exercise the legitimate rights of Asociația 2Celsius (and the legitimate rights of other individuals).
If you are a beneficiary, we will retain your personal data for the duration of the contractual relationship with you. If we have a relationship with you as a partner, we will continue to retain this personal data until the end of our relationship and for the minimum retention period imposed by law.
Disclosure of Personal Data
Within Asociația 2Celsius, staff members who process your personal data are subject to confidentiality obligations regarding personal data. Asociația 2Celsius will not disclose your personal information to third parties. If we transfer data to other countries or international organizations, such situations will be subject to special notifications, strictly adhering to the provisions of the Regulation and adopting all necessary technical and organizational measures to secure your data during transfer.
However, your personal data may be disclosed to public authorities or third parties as follows:
- To public authorities, tax authorities, and/or law enforcement agencies if required by applicable laws or if necessary to exercise our rights, including terms of use, or to protect our legitimate interests (including the legitimate interests of third parties) in accordance with applicable laws;
- To partners and subcontractors, with justification, to execute all contracts we enter into with you or on your behalf, to provide the requested services;
- To external consultants (e.g., doctors, lawyers, auditors) for specific purposes, when necessary, with your prior notice and based on your consent.
If we obtain your personal data from a third party, we will provide all relevant information about the processing, including the source from which we obtained it, as soon as possible, but no later than one month from obtaining your personal data, or by email at the first communication if we use personal data only for communication with you.
Asociația 2Celsius conducts an appropriate prior assessment when selecting third-party service providers and requires them to maintain appropriate technical and organizational security measures to protect personal data and process personal data only according to the specific instructions provided by Asociația 2Celsius.
Personal Data Security
In accordance with the provisions of Regulation 679/2016, Asociația 2Celsius constantly strives to ensure an appropriate level of security and to reduce/eliminate risks that may affect processed personal data, and to maintain the ability to ensure the confidentiality, integrity, availability, and resilience of processing systems and services.
Storage of Personal Data and Transfer Outside the Country
The website www.2celsius.org is managed by Asociația 2Celsius. We use Mailchimp for subscription and email marketing services, an American company with the following identification data: The Rocket Science Group, LLC 675 Ponce de Leon Ave NE Suite 5000 Atlanta, GA 30308 USA The safety measures described in their privacy policies can be found here: Mailchimp Privacy Policy
Creation of Log Files
Each time you visit the website, our system automatically collects the following data and information from the computer accessing it:
- Technical data, such as the IP address used to connect your computer to the internet, the URL of the connecting site, browser type and version, browser extension types and versions, date and time of access, visited page, amount of data transferred, access status (file transferred, file not found, etc.), operating system, device type, and mobile device brand. These data are collected and processed on our behalf through third-party cookie files, and more information can be found in the Cookie Policy.
Legal Basis for Data Processing
The legal basis for the temporary storage of data and log files is provided by Article 6 (1) (f) GDPR.
Purpose of IP Address Data Processing
Temporary storage of the IP address by the system is necessary to deliver services to the user’s computer and ensure the functionality of the web page. For this purpose, the user’s IP address must be stored for the duration of the session. Additionally, the data is used to optimize the website and ensure the security of our IT systems. In this context, the processing of personal data is purely statistical and not for marketing purposes. Asociația 2Celsius reserves the right to store IP addresses and log files to prevent or resolve abuse situations and, on a case-by-case basis, to transfer data to investigative authorities for this purpose. Apart from this, any other analysis of data is done anonymously as much as possible. After this period, the IP address and log files are completely deleted unless there are mandatory statutory retention requirements or specific ongoing investigation procedures for prosecution and abuse. These purposes also constitute our legitimate interest in processing personal data under Article 6 (1) (f) GDPR.
Duration of Storage
Your data is deleted as soon as it is no longer necessary to fulfill the purpose for which it was collected. In the case of data collection for web page delivery, data is deleted after the respective session ends. If data is stored in log files, it is deleted within 30 days. However, storage may be longer if IP addresses are deleted or distorted, making it impossible to attribute the calling client.
Your Rights
As an individual, you have specific rights regarding the personal data we collect and process. Asociația 2Celsius ensures your rights are respected and facilitates their exercise. We have detailed below your rights regarding the processing of personal data.
Right to Information and Access
You have the right to request confirmation of whether your personal data is being processed and, if so, to request access to your data and information such as the purpose of processing, the data categories, data recipients, the retention period, the source of data, and the existence of automated decision-making, including profiling.
Right to Rectification
You have the right to obtain rectification of inaccurate or incomplete personal data concerning you.
Right to Erasure (“Right to be Forgotten”)
You have the right to request the deletion of your personal data if:
- Data is no longer necessary for the purposes for which it was collected;
- You withdraw consent for data processing and no other legal ground for processing exists;
- You object to processing and there are no overriding legitimate grounds for processing;
- Data is processed unlawfully;
- Data must be deleted to comply with a legal obligation.
Right to Restriction of Processing
You have the right to request restriction of data processing if:
- You contest the accuracy of the data, for a period enabling us to verify data accuracy;
- Processing is unlawful, and you oppose the erasure of the data and request restriction instead;
- We no longer need data for processing, but you need it to establish, exercise, or defend legal claims;
- You object to processing pending verification of whether our legitimate grounds override your rights.
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and have the right to transmit this data to another controller if processing is based on consent or contract and carried out by automated means.
Right to Object
You have the right to object, at any time, to processing your data for direct marketing purposes. You also have the right to object, on grounds relating to your particular situation, to processing based on legitimate interests.
Right to Withdraw Consent
If data processing is based on your consent, you have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to Lodge a Complaint with a Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data infringes GDPR.
Changes to Privacy Policy
We reserve the right to modify this Privacy Policy at any time. Any updates or changes will be effective immediately upon posting the revised Privacy Policy on the website. We encourage you to periodically review this page for the latest information on our privacy practices.
For any questions, requests, or concerns regarding this Privacy Policy, please contact us at:
Asociația 2Celsius Cugir, Al. Sahia Street No. 18, Building C, Apartment 5, Alba County CIF: 26934505 Romania Email: office@2celsius.org Website: www.2celsius.org