Privacy
Policy

SummitSphere respects the privacy and protection of your personal data. Please read this policy carefully.

PERSONAL DATA PROTECTION AND PRIVACY POLICY

1. General Provisions

1.1. SummitSphere SRL, as a Personal Data Controller, headquartered in Bucharest, 23 Chitilei Road, Sector 1, CUI RO48728824, assumes full compliance with the provisions of Regulation (EU) 2016/679 ("GDPR") and applicable national legislation on data protection.

1.2. This Policy regulates the methods of collection, use, processing, storage, transfer, and protection of personal data provided by Participants during organized events.

1.3. By participating in SummitSphere SRL events, the Participant declares that they have been fully, explicitly, and detailedly informed regarding all aspects of the processing of their personal data.

2. Categories of Processed Data

2.1. SummitSphere SRL may process the following categories of personal data:

  • Identification data: name, surname;
  • Contact data: e-mail address, phone number;
  • Professional data: role, organization/institution, specialty;
  • Participant's image: photographs, video materials captured during events;
  • Billing data: billing addresses, tax codes (for legal entities);
  • Feedback, survey responses, comments, or opinions expressed during or after the event.

2.2. The processing of these data is necessary and mandatory to ensure participation in the event, to comply with the Organizer's contractual and legal obligations, and to achieve its legitimate interests.

3. Purposes of Processing

3.1. Personal data are processed for the following legitimate and justified purposes:

  • Registration and participation in the event;
  • Communicating organizational details (location, agenda, changes);
  • Billing, issuing accounting and supporting documents;
  • Fulfilling legal obligations regarding financial and tax records;
  • Documenting and promoting the event through photographs and recordings;
  • Sending invitations to future events or commercial communications, only with prior consent.

4. Legal Grounds

4.1. The data processing is based on the following grounds:

  • Article 6(1)(b) GDPR – performance of a contract to which the Participant is a party;
  • Article 6(1)(c) GDPR – compliance with the Organizer's legal obligations;
  • Article 6(1)(a) GDPR – explicit consent for marketing and use of image;
  • Article 6(1)(f) GDPR – the Organizer's legitimate interests regarding the conduct and promotion of its activities.

5. Recipients and Data Transfers

5.1. Data may be disclosed, under strictly controlled conditions, to:

  • Employees and collaborators of the Organizer involved in the organization;
  • Ancillary service providers (IT hosting, email marketing, accounting, video services);
  • Public authorities and institutions, in accordance with legal obligations.

5.2. In the event of a data transfer outside the European Economic Area (EEA), SummitSphere SRL will ensure the implementation of additional protective measures, such as standard contractual clauses approved by the European Commission.

6. Retention Period

6.1. Personal data are kept:

  • For the duration necessary to organize and complete the event;
  • For the duration of legal archiving obligations (minimum 5 years);
  • For commercial communications, until consent is withdrawn.

6.2. At the end of the retention period, the data will be deleted or, where applicable, irreversibly anonymized.

7. Participant's Rights

7.1. The Participant has the following rights guaranteed by the GDPR:

  • Right of access to personal data;
  • Right to rectify incorrect data;
  • Right to erasure ("right to be forgotten");
  • Right to restriction of processing;
  • Right to data portability;
  • Right to object to processing for direct marketing purposes;
  • Right to withdraw consent at any time, without affecting the lawfulness of prior processing;
  • Right to lodge a complaint with the ANSPDCP.

7.2. The exercise of these rights is carried out by a written request sent to the Organizer's correspondence address or by e-mail, accompanied by identification elements for data protection.

8. Privacy Policy

8.1. SummitSphere SRL undertakes to maintain the confidentiality of all information provided by Participants, using high-level technical and organizational measures, including antivirus protection, firewall, data encryption, and strict internal procedures.

8.2. Information will not be shared, disclosed, or used for purposes other than those declared, except as expressly regulated by law or authorized by the Participant.

8.3. The use of the Participant's image (photographs, audio-video materials) for marketing and promotion purposes will be done exclusively based on expressed consent, which can be withdrawn at any time without affecting prior lawfulness.

8.4. SummitSphere SRL will treat with utmost responsibility all security incidents regarding personal data, informing the competent authorities and, where applicable, the data subjects, within the deadlines provided by GDPR.

9. Liability and Compensation

9.1. If the Participant considers that their rights have been violated, they may request moral or material compensation, according to the legal procedures in force.

9.2. SummitSphere SRL limits its liability to the Participant, in all cases, to proven and direct damages, expressly excluding any liability for indirect damages, damage to image, loss of profit, or lost opportunities.

10. Policy Changes

10.1. SummitSphere SRL reserves the right to unilaterally modify this Policy depending on legislative changes or internal practices.

10.2. Updates will be communicated by publication on the Organizer's website and will take effect from the date of publication.