Who we are
Asociația Grupul Verde (Tax ID/CIF 44109108), a non-governmental organisation based in Adjud, Vrancea County, Romania, is the controller of your personal data within the meaning of Art. 4(7) of Regulation (EU) 2016/679 (GDPR).
- E-mail: office@grupulverde.ro — for any request concerning personal data, with the subject line “Data protection”
- Phone: +40 374 962 748
- Correspondence address: Adjud, Vrancea County, Romania
The association is not required to appoint a data protection officer (Art. 37 GDPR). Your requests are handled directly by the association’s management, which is responsible for compliance with this policy.
Who this concerns
This policy applies to everyone whose data we process:
- visitors to the grupulverde.ro website;
- people who write to us or call us (questions, press, partnerships);
- participants in our programmes — pupils, young people, adults and older people — and, for minors, their parents or legal representatives;
- volunteers, mentors and trainers;
- donors, sponsors and taxpayers who redirect 3.5% through Form 230;
- contact persons at partners, schools, city and town halls and funders.
What data we process and why
We collect only the data needed for each purpose (the data minimisation principle, Art. 5 GDPR). For each activity below you will find the data, the purpose, the legal basis and the retention period.
Visiting the website
- Data
- IP address, browser and device type, page visited, date and time — recorded automatically in the server logs.
- Purpose
- Operation, security and abuse prevention.
- Legal basis
- Legitimate interest in ensuring a secure website — Art. 6(1)(f) GDPR.
- Retention
- The log retention period set by the hosting provider, usually no more than 30 days, except when investigating an incident.
Correspondence by e-mail, phone and the contact form
- Data
- Name, e-mail address or phone number, the content of your message and any information you choose to send us.
- Purpose
- To reply to you and act on your request (enrolment, volunteering, partnership, press).
- Legal basis
- Legitimate interest in replying — Art. 6(1)(f); pre-contractual steps at your request — Art. 6(1)(b).
- Retention
- 3 years from the last communication, unless the request becomes a contractual relationship.
Enrolment and participation in programmes
- Data
- Name, age or date of birth, school and class, locality, contact details (of the participant or parent), attendance, progress, results and certificates obtained.
- Purpose
- Organising courses, workshops and expeditions (Cisco Networking Academy, Code.org, robotics, AI literacy, environment), issuing certificates, reporting to funders and evaluating impact.
- Legal basis
- Performance of the participation agreement — Art. 6(1)(b); reporting obligations under funding contracts — Art. 6(1)(c) and (f); for minors under 16, the consent of the parent or legal representative.
- Retention
- For the duration of the programme and, afterwards, for the archiving period required by the funding contract (usually between 3 and 10 years after the project closes). Public impact reports contain only aggregated data.
Photos and video recordings
- Data
- The image and, where applicable, the voice of participants at events.
- Purpose
- Documenting activities, reporting to funders and public communication (website, social media, presentation materials).
- Legal basis
- Consent — Art. 6(1)(a) GDPR; for minors, the consent of the parent or legal representative, in compliance with child rights protection law.
- Retention
- Until consent is withdrawn; materials under our control are removed within 30 days of the request at most.
Volunteering
- Data
- Identification and contact details from the volunteering contract, skills, availability, volunteering hours and, for activities with minors, the certificate of good conduct (criminal record check for work with children).
- Purpose
- Concluding and performing the volunteering contract, issuing the volunteering certificate and protecting children.
- Legal basis
- The contract — Art. 6(1)(b); legal obligations (Law no. 78/2014 on volunteering, Law no. 118/2019) — Art. 6(1)(c).
- Retention
- For the duration of the contract and afterwards for the statutory archiving periods.
Donations and sponsorship
- Data
- Name, contact details, amount, date and bank statement details (including IBAN), the sponsorship contract.
- Purpose
- Receiving and recording donations, issuing documents, thanking donors.
- Legal basis
- The contract — Art. 6(1)(b); statutory accounting and tax obligations (Accounting Law no. 82/1991, Law no. 32/1994 on sponsorship) — Art. 6(1)(c).
- Retention
- The periods set by accounting law (currently 5 years for supporting documents and 10 years for registers and financial statements).
Form 230 (redirecting 3.5%)
- Data
- Only if you hand us the completed form for us to file: surname, first name, personal numeric code (CNP), address, e-mail and phone (optional) and signature.
- Purpose
- Filing the form with ANAF on your behalf.
- Legal basis
- Your express request and the obligations under the Fiscal Code and the ANAF procedure — Art. 6(1)(b) and (c).
- Retention
- No more than 5 years, in line with the statutory archiving periods; the data are not used for any other purpose.
Partners and funders
- Data
- Name, job title, organisation and professional contact details.
- Purpose
- Building and running partnerships and funded projects.
- Legal basis
- Legitimate interest — Art. 6(1)(f); the contract — Art. 6(1)(b).
- Retention
- For the duration of the collaboration and for 3 years after it ends.
Online donations are paid on Stripe’s secure page: you enter your card details directly with Stripe, and we never see or store them. The contact form and the personal data request form send your message directly to office@grupulverde.ro and email you an automatic confirmation; the data are kept under the “Correspondence” rules, or for 3 years after a GDPR request is resolved, so we can show that we replied (Art. 5(2)).
Who we share data with
We do not sell, rent out or exchange personal data. We share it only when necessary, with:
- processors (Art. 28 GDPR), who process the data only on our instructions: the web hosting provider and the e-mail and cloud storage provider (Google Workspace); the online payment processor Stripe Payments Europe Ltd. (Ireland), for card donations made on the website: it receives your name, email, the amount and, for companies, the company name and Tax ID; you enter your card details directly on the Stripe page, and we never see or store them;
- the educational platforms used in our courses — Cisco Networking Academy, Code.org — where the participant’s account is also governed by the platform’s own policy;
- funders and managing authorities of projects (for example, the National Agency for Community Programmes in Education and Vocational Training for Erasmus+, funding foundations), only to the extent required by the funding contract;
- public authorities (ANAF, courts, inspection bodies), where the law requires us to;
- auditors, accountants and legal advisers, who are bound by confidentiality.
Transfers outside the EEA
Some providers (Google, Cisco, Code.org, Stripe) may process data in the United States. Transfers take place only with appropriate safeguards, in line with Chapter V of the GDPR: the European Commission’s adequacy decision on the EU–US Data Privacy Framework (10 July 2023), for certified companies, and/or the standard contractual clauses approved by Decision (EU) 2021/914. You can ask us for a copy of the applicable safeguards.
How long we keep data
We keep data only for as long as necessary for the purpose for which it was collected, or for as long as the law or funding contracts require (the periods are given for each activity above). When the period expires, the data are deleted or irreversibly anonymised. Public impact statistics (for example, “560+ young people trained”) are always aggregated and do not allow individuals to be identified.
Children’s data
Most of our beneficiaries are children and young people, so we apply stricter rules:
- for minors under 16, enrolment and any consent (for example, for photos) are given by the parent or legal representative;
- we do not publish a minor’s full name, school and image together without explicit consent;
- we do not use children’s data for marketing, profiling or advertising;
- volunteers and trainers who work with minors present a certificate of good conduct and commit to confidentiality.
How we protect data
- encrypted HTTPS connection across the whole site, and access to data only for the people who need it;
- two-step verification on the association’s e-mail and storage accounts;
- confidentiality training for our team and volunteers;
- data minimisation and anonymisation in impact reports;
- in the event of a personal data breach, we notify ANSPDCP within 72 hours at most (Art. 33 GDPR) and inform you directly if there is a high risk to your rights (Art. 34).
Automated decisions and artificial intelligence
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly affect you (Art. 22 GDPR). Although we teach AI literacy, we do not enter participants’ personal data into public generative AI tools.
Your rights
You can exercise your rights free of charge at any time. We reply within one month of receiving your request at most; this can be extended by a further two months for complex requests, and we will let you know (Art. 12 GDPR). We may ask for additional information only to confirm your identity.
Art. 15AccessFind out what data we hold about you and receive a copy.Send request → Art. 16RectificationWe correct inaccurate data or complete it.Send request → Art. 17ErasureWe delete data when there is no longer a basis for keeping it.Send request → Art. 18RestrictionWe temporarily suspend processing, for example while we look into an objection.Send request → Art. 20PortabilityYou receive your data in a structured format, or we transfer it to another controller.Send request → Art. 21ObjectionYou object to processing based on our legitimate interest.Send request → Art. 7 (3)Withdrawing consentAs easy as giving it, without affecting earlier processing.Send request → Art. 22No automated decisionsYou are not subject to decisions made solely by automated means.Send the request → Complaint to ANSPDCP
If you believe your rights have been infringed, please write to us first — we resolve most situations quickly. You always have the right to lodge a complaint with the supervisory authority (Art. 77 GDPR) or to go to court (Art. 79 GDPR).
Changes and legal basis
We review this policy at least once a year and whenever our activities or the law change. The version in force is the one published on this page; we announce significant changes on the website. Version 1.0 · last updated: 26 September 2026.
Regulation (EU) 2016/679General Data Protection Regulation (GDPR)
Law no. 190/2018Measures implementing the GDPR in Romania
Law no. 506/2004Processing of personal data and protection of privacy in electronic communications
Directive 2002/58/ECThe ePrivacy Directive on electronic communications
EDPB Guidelines05/2020 on consent · 03/2022 on deceptive design patterns · 2/2023 on the technical scope of Art. 5(3) of the ePrivacy Directive
Law no. 78/2014 · Law no. 82/1991Volunteering · accounting and document archiving