Last updated: August 2026
1. Introduction
1.1. Scope
This Privacy Policy explains how ASOCIAȚIA SPHERIK (“we”, “us”, or “the Organisation”) collects, uses, stores, and protects personal data in accordance with Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”) and national data protection laws.
It applies to all digital platforms and affiliated brands owned, managed, or operated by ASOCIAȚIA SPHERIK (collectively referred to as the “Platforms”), including websites, mobile applications, and social media accounts.
By accessing our Platforms, registering for programs or events, making purchases, or engaging in any interaction with us, you acknowledge that you have read and understood this Policy.
1.2. Who We Are
ASOCIAȚIA SPHERIK
Registered office: 21 Garii Street, Cluj-Napoca, jud. Cluj, postal code 400267.
Registration number: 203/2013
Unique Identification Code (CUI): 32694261
Email: contact@spherikaccelerator.com
1.3. Affiliated Brands
This Privacy Policy applies equally to all brands, projects, and initiatives owned or managed by ASOCIAȚIA SPHERIK, including sub-brands and programs operated under its umbrella.
1.4. Complaints
If you have questions, concerns, or wish to exercise your data protection rights, please contact us at contact@spherikaccelerator.com.
You may also lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP):
B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, 010336, Bucharest, Romania
Email: anspdcp@dataprotection.ro
Website: https://www.dataprotection.ro
2. Data Collection
2.1. Definition of Personal Data
Personal data means any information relating to an identified or identifiable natural person. This may include identifiers such as name, identification number, email address, or other factors specific to one’s identity.
2.2. Categories of Data We Collect
Depending on the context of your interaction with us, we may collect:
- Identification data: name, surname, organisation name, registration number, role, country, preferred language.
- Contact data: email, telephone number, billing and delivery addresses.
- Transactional data: payment confirmations, invoices, tickets, proof of purchase, and donation details.
- Technical data: IP address, browser type and version, operating system, login data, and online identifiers.
- Usage data: information about how you interact with our Platforms and digital services.
- Marketing preferences: your consent for receiving communications.
- Audio-visual data: photographs, recordings, or video materials captured during events or programs (when applicable).
We do not collect or process sensitive data such as racial or ethnic origin, political opinions, religious beliefs, or health data.
3. How Data Is Collected
Data is collected:
- Directly from you, when you:
- register for a program or event;
- purchase a ticket, product, or digital service;
- make a donation;
- subscribe to newsletters;
- contact us or submit forms;
- participate in events or surveys.
- Automatically, via cookies and analytics tools, when you browse our Platforms.
- From third parties, such as payment processors, service providers, or publicly available sources, strictly when permitted by law.
4. How Data Is Used
We process your data for the following purposes:
- To register you for events, programs, or services.
- To process payments, issue invoices, and deliver digital products.
- To provide access to purchased or subscribed content.
- To manage communications, respond to inquiries, or handle complaints.
- To send newsletters, updates, or promotional materials (when consent was given).
- To comply with legal obligations (e.g., tax and accounting requirements).
- To improve user experience and platform functionality.
We ensure that data is used only for legitimate, specific purposes and never in ways incompatible with the initial reason for collection.
5. Legal Basis for Processing
Personal data is processed based on one or more of the following legal grounds:
- Performance of a contract: e.g., participation in programs, purchase of tickets or services.
- Legal obligation: compliance with fiscal and reporting duties.
- Consent: for newsletters, marketing, or optional communications.
- Legitimate interest: to improve services, prevent fraud, or ensure platform security.
6. Sharing Data with Third Parties
Your data may be shared only when necessary, with:
- Payment processors and financial institutions (for transactions).
- Event management and logistics partners (for ticketing and access control).
- IT and communication service providers.
- Legal, accounting, or regulatory authorities, when required by law.
All third parties are contractually bound to ensure confidentiality and GDPR-compliant data protection standards.
6.1. Analytics and Monitoring Services
We may use third-party service providers to monitor, analyse, and improve the performance and usage of our digital platforms.
Google Analytics
Our website utilises Google Analytics, a web analytics service provided by Google LLC, which helps us understand how visitors interact with our website. Google Analytics collects information such as your IP address, device information, and browsing behaviour, which is used to generate statistical reports on website activity and improve user experience.
The data collected through Google Analytics may be shared with other Google services. Google may use this information to personalise and contextualise the advertisements within its own advertising network.
You may opt out of Google Analytics tracking by installing the Google Analytics Opt-Out Browser Add-on, which prevents data collection through Google Analytics JavaScript (ga.js, analytics.js, and dc.js).
For further details regarding Google’s privacy practices, please refer to Google’s Privacy Policy.
We do not use analytics services for identifying individual users; the data collected is aggregated and anonymised where possible.
7. International Data Transfers
If data must be transferred outside the European Economic Area (EEA), we ensure that such transfers comply with GDPR requirements, using:
- Adequacy decisions from the European Commission, or
- Standard contractual clauses approved by the Commission.
You may request further details at contact@spherikaccelerator.com.
8. Data Security
We adopt both technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction.
These include:
- Encrypted connections and secure storage systems;
- Restricted access on a need-to-know basis;
- Regular data backups and audits;
- Employee training on data protection and confidentiality.
9. Data Storage
We retain personal data only as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.
Retention periods may vary:
- Contractual and transactional data: up to 5 years after the transaction.
- Newsletter or marketing data: until consent is withdrawn.
- Event participation records: until the end of the event or reporting period.
After expiration, data will be securely deleted or anonymised.
10. User Rights
ASOCIATIA SPHERIK undertakes to respect the confidentiality of your personal data and to ensure that you can exercise your rights in accordance with the General Data Protection Regulation (GDPR) and applicable national legislation.
As a data subject, you have the following rights regarding your personal data:
10.1. Right of Access
You have the right to obtain confirmation as to whether or not we process personal data concerning you, as well as access to such data. Upon request, we will provide a copy of the personal data undergoing processing, together with information regarding the purpose of processing, data categories, recipients, and storage periods.
10.2. Right to Rectification
You have the right to request the correction or completion of any inaccurate or incomplete personal data we hold about you, without undue delay.
10.3. Right to Erasure (“Right to be Forgotten”)
You have the right to request the deletion of your personal data where:
- the data is no longer necessary for the purposes for which it was collected;
- you withdraw your consent and there is no other legal basis for processing;
- you object to the processing and there are no overriding legitimate grounds;
- the data was processed unlawfully; or
- erasure is required to comply with legal obligations.
Please note that we may retain certain information if required by law or for legitimate business interests (e.g., legal claims or accounting obligations).
10.4. Right to Restriction of Processing
You have the right to request restriction of processing where:
- the accuracy of the personal data is contested;
- the processing is unlawful but you oppose erasure;
- we no longer need the data, but you require it for the establishment or defense of legal claims; or
- you have objected to processing pending verification of legitimate grounds.
10.5. Right to Data Portability
You have the right to request that we provide you, or a third party designated by you, with your personal data in a structured, commonly used, and machine-readable format. This right applies only to data processed by automated means and based on consent or contractual necessity.
10.6. Right to Object
You have the right to object at any time to the processing of your personal data where it is based on legitimate interests or carried out for direct marketing purposes.
If you object to processing for direct marketing, your personal data will no longer be processed for such purposes.
10.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before its withdrawal.
However, withdrawal of consent may limit access to certain features, services, or communications that depend on such consent.
10.8. Right to Lodge a Complaint
You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) if you believe that your rights have been violated.
Contact details:
ANSPDCP, B-dul G-ral. Gheorghe Magheru nr. 28–30, Sector 1, 010336, Bucharest, Romania
Email: anspdcp@dataprotection.ro
Website: www.dataprotection.ro
10.9. Exercising Your Rights
To exercise any of the rights listed above, you may send a written, dated, and signed request to contact@spherikaccelerator.com.
We will respond to your request within one month from receipt, in accordance with Article 12 of the GDPR, with the possibility of extending this period by two months when necessary due to the complexity or number of requests.
11. Changes to This Policy
We may update this Policy periodically. The latest version will always be available on our website.
Significant changes will be communicated via email or posted on the website. Continued use of our services after updates constitutes acceptance of the revised Policy.