In short
- We only collect what we need to answer you, run our projects and send the newsletter you asked for.
- We never sell or rent your data, or share it for commercial purposes.
- Our website sets no tracking cookies. YouTube videos and Google Maps load only if you click on them.
- You can see, correct or delete your data, and unsubscribe from the newsletter at any time.
- If you think we got something wrong, you can complain to the Romanian data protection authority (ANSPDCP).
Your privacy matters to us. This policy explains, in plain language, what personal data we collect, why we need it, who helps us handle it and what rights you have. We have put technical and organisational measures in place to keep your data safe.
A few terms explained
- GDPR: the General Data Protection Regulation (Regulation (EU) 2016/679), the EU law that protects your personal data and gives you control over it.
- Personal data: any information about a person who can be identified, such as your name, address, phone number, date of birth or email address.
- Lawful basis: every use of personal data needs a legal reason under the GDPR. We list ours below.
- Data controller: the organisation that decides why and how personal data is used. For this website and our projects, that is us.
- Processor: a company that handles data on our behalf and only on our instructions, such as our email or hosting provider.
Who we are
Asociația Elemdiar is a non-profit youth organisation in Romania. We run non-formal education activities (learning by doing, outside a classroom): Erasmus+ youth exchanges and training courses that we host, sending young people aged 18 to 25 to projects abroad with our partner organisations, and local workshops. On this website we share information about our projects, calls for participants and opportunities to work with us.
In this policy, "we", "our" and "us" mean Asociația Elemdiar.
Data controller:
- Organisation: Asociația Elemdiar
- Based in: Bilbor, Harghita county, Romania
- Fiscal code: 48213682
- Email, also for any data protection request: [email protected]
Everyone who works with us, staff and collaborators, must keep your data confidential and follow the GDPR.
What we collect and why
We only collect personal data that we need for our activities and to communicate with you. Depending on how you interact with us, this can include:
- details that let us reply when you ask about our activities or projects;
- what we need when you apply to one of our Erasmus+ projects, such as your application, contact details and background;
- information to assess you as a possible partner organisation or team member;
- feedback and evaluations that help us improve our projects;
- data needed for Erasmus+ administration and reporting;
- information that helps us ensure equal access, gender balance and non-discrimination in our activities;
- health, dietary or emergency information needed for your safety and wellbeing during a project;
- photos and testimonials that help us show what Erasmus+ and non-formal learning can do.
We collect this through our website forms, by email, or in person during activities.
Through our website forms
These are the forms on our website and what each one asks for:
- Register your interest (Go abroad with us): your name, email, age, town and county, what you are interested in, why you want to join, and, only if you choose to tell us, anything that could make it harder for you to take part (for example costs, health or a disability).
- Contact form: your name, email, who you are (for example a young person or an organisation) and your message.
- Partnership form: your organisation, country, name, email and your project idea.
- Newsletter: your email address.
When you are selected for a project, we ask for more in a separate application, such as your date of birth, phone number, dietary needs, allergies or medical information relevant to your safety, and your experience with Erasmus+. We tell you why we need each piece of information when we ask for it.
How our website works
We want our website to be useful without watching you. Here is exactly what happens behind the scenes.
Hosting: Cloudflare Pages
Our website is hosted on Cloudflare Pages, run by Cloudflare, Inc. When you visit, Cloudflare's servers handle your request. Like any web server, they process technical data such as your IP address and browser type to deliver the page and protect the site from attacks.
Cloudflare is a US company. Transfers of this data to the United States are covered by the EU-US Data Privacy Framework, under which Cloudflare is certified. Cloudflare keeps these technical logs only for a limited time, for security and operation.
Visitor statistics: Cloudflare Web Analytics
We use Cloudflare Web Analytics to understand how many people visit our pages and which pages are popular. It does not use cookies and does not store anything on your device. It shows us totals (like page views, countries and referring websites), not who you are.
Contact and application forms: Web3Forms
When you send a form on our website, it goes through Web3Forms, a form service that forwards your submission to our email inbox. Web3Forms acts as a processor for us. It is run by Web3Creative, a company based in India, on servers in the United States. According to Web3Forms, submissions may be kept on its servers for up to 30 days and server logs for about two months.
This means the data in our forms is transferred outside the EU. We tell you this next to every form, and we only send it with your explicit consent, which you give by ticking the consent box. If you prefer that your data does not leave the EU, simply email us at [email protected] instead of using a form.
Our inbox, [email protected], is hosted by Microsoft (Microsoft 365). Microsoft is certified under the EU-US Data Privacy Framework.
Newsletter
If you sign up for our newsletter, your email address reaches our inbox through Web3Forms (see above), together with your consent. We keep the list of subscribers ourselves and use it only to send you news about our projects, open calls and those of our partners.
- We never show your address to other subscribers: we send newsletters with your address hidden (in BCC) or through an email service.
- Unsubscribe anytime: reply to any newsletter or write to [email protected], and we remove you from the list.
- We plan to move the newsletter to Brevo, an email service based in France, in the EU. When we do, we will update this policy and tell subscribers before their address is moved.
YouTube videos and Google Maps: only after you click
Some pages show YouTube videos or a Google Map. These do not load automatically. You see a placeholder first, and the video or map loads only when you click it. Once you click, Google (which runs YouTube and Google Maps) receives data such as your IP address and may set its own cookies, under Google's privacy policy.
Instagram and other links
We link to our Instagram profile and other websites. These are simple links: nothing from Instagram loads on our site until you click. Once you leave our website, the other site's privacy policy applies, and we are not responsible for how it handles your data. We recommend reading the privacy policies of any site you visit.
Why there is no cookie banner
Our website does not set any non-essential cookies, and nothing that tracks you loads before you choose it (by clicking a video or map). Because of this, we do not need to ask for cookie consent when you arrive.
Photos and videos
We sometimes take photos and videos during our activities to document and share our work, including on our website, social media and newsletter. We never use them for commercial purposes.
We always ask for your consent under the GDPR before publishing photos or videos that show you. You can ask us at any time to remove a photo or video of you.
Why we use your data
We use personal data to:
- give you the information or services you asked for;
- assess and communicate with applicants, partners and team members;
- run our Erasmus+ projects;
- make sure our projects are equal and accessible;
- keep every participant healthy and safe;
- promote our projects and share good practice in non-formal education and volunteering.
Our legal reasons (lawful basis)
We use your data on one or more of these grounds:
- Consent: when you clearly agree, for example to receive our newsletter, to load a YouTube video or map, or to share information voluntarily.
- A contract, or steps before one: when you apply to or take part in one of our projects.
- Legal obligation: when Erasmus+ rules or Romanian administrative rules require us to process data.
- Legitimate interest: to keep our website secure and running, and to count visits in an anonymous way.
Health information (such as allergies, medical needs or a disability) is a special category of data under the GDPR. We only process it with your explicit consent, which you give by choosing to tell us, and only to keep you safe and support you.
How we protect your data
We use administrative, physical and technical security measures to protect your data from accidental, unlawful or unauthorised access, loss, change or misuse. Only team members who need your data for their work can access it.
How long we keep your data
We keep personal data only as long as we need it for the reason we collected it, or as long as the law requires.
- Erasmus+ project records (applications, participant lists, reports): 5 years after the end of the project's contractual period, as our Erasmus+ grant agreements require.
- Contact form messages: 5 years after the end of the contractual period of the project they relate to.
- Applications from people who were not selected: 5 years after the end of the project's contractual period.
- Newsletter subscription: until you unsubscribe. When you unsubscribe, we delete your address from the list.
- Photos and videos: 5 years after the end of the project's contractual period, unless you ask us to remove them earlier.
Your rights
Under the GDPR you have the right to:
- Access: ask what data we hold about you, and get a copy.
- Correction: ask us to correct or update data that is wrong. We will do it as soon as possible.
- Erasure ("right to be forgotten"): ask us to delete your data when we no longer need it.
- Restriction: ask us to limit how we use your data.
- Data portability: ask us to send your data to another organisation.
- Objection: object to us using your data based on legitimate interest.
- Withdraw consent: withdraw your consent at any time. This does not affect anything we did before you withdrew it.
- Complain: file a complaint with a data protection authority if you think your rights have been violated (see below).
If you withdraw your consent, we will delete your data unless we must keep it for legal or administrative reasons, such as Erasmus+ archiving.
To use any of these rights, write to [email protected]. We reply within one month, as the GDPR requires.
We never sell, rent or share your data with third parties for commercial purposes.
Making a complaint
If you are unhappy with how we handle your data, please talk to us first, and we will try to fix it. You also have the right to complain to the Romanian data protection authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) Website: www.dataprotection.ro
If you live in another EU country, you can also complain to the data protection authority there.
Learn more
You can read the full text of the GDPR on the EU's official website: Regulation (EU) 2016/679.
Questions?
Write to us at [email protected].
