Privacy Policy

Last updated: August 6, 2026

This policy explains how Origio EDUNOVA processes personal data, in accordance with Regulation (EU) 2016/679 ("GDPR"), with Romanian Law no. 190/2018 implementing the GDPR, and with applicable Romanian law. We want everyone who interacts with us - pupil, student, parent, teacher, partner or supporter - to understand simply and fully what happens with their data.

1. Who we are (the data controller)

The controller of personal data is Asociația Origio EDUNOVA, a Romanian nonprofit legal entity, with its registered office in Bucharest, District 2, registered in the Romanian Register of Associations and Foundations under no. 32981/300/2025, Tax ID (CIF) 53807266, legally represented by Mihnea Andrei Constantin, as President. You can contact us on any data-protection matter at mihnea.constantin@origioedunova.com or by phone at 0744.876.466.

2. What data we process, for what purposes and on what legal grounds

a) Correspondence and contact. When you email us, fill in a contact form on the website, call us or reach out on social media, we process your name, contact details and the content of your message, in order to reply to you and manage our relationship with you. Legal grounds: our legitimate interest in communicating with the people who contact us and taking steps at your request (Art. 6(1)(b) and (f) GDPR).

b) Redirecting 3.5% of income tax (Form 230). If you choose to support us through Form 230, we process the data in the form: first and last name, personal numeric code (CNP, the Romanian national identification number), address, income-tax data and signature. The purpose is solely to file the form with the competent tax authority (ANAF, Romania's National Tax Administration), at your request. Legal grounds: your consent and steps taken at your request (Art. 6(1)(a) and (b) GDPR). Since the CNP is a national identification number, we apply the safeguards in Art. 4 of Law no. 190/2018: we collect only strictly necessary data, keep it securely with restricted access, and delete it according to the periods in section 6. The CNP is not used for any other purpose, does not appear in reports, statistics or communication materials, and is not shared with any third party other than ANAF.

The form can be filled in online, on the redirection page of our website. The online form is provided and technically operated by the platform formular230.ro, which acts as a processor within the meaning of Art. 28 GDPR and processes the data solely on our instructions, for the purpose described above. The platform has its own privacy policy, which we encourage you to read before filling it in. Alternatively, you can download the form, fill it in on paper and send it to us signed.

c) Photos and video recordings from workshops. During our educational activities we take photos and video recordings of participants, which we may use for educational purposes and to promote our projects: on the website, on our social media pages, in printed materials and in video materials. Legal grounds: the consent of the adult participant or, for minors, the consent of the parent/legal guardian, given through the photo-video consent signed before the activity (Art. 6(1)(a) GDPR). Declining the photo-video consent in no way affects the right to take part in activities, and consent can be withdrawn at any time (see section 7).

d) Partnerships and collaborations. To conclude and carry out partnership agreements with schools, foundations and other organizations, we process the professional contact details of their representatives (name, position, email, phone, signature). Legal grounds: performance of the agreement and our legitimate interest in running the educational projects (Art. 6(1)(b) and (f) GDPR).

e) Workshop participant feedback. At the end of workshops we ask participants to fill in a feedback questionnaire. It does not collect a name, email address or any other identifying element - we collect only aggregated answers about the quality of the workshop. This is a deliberate choice: most of our participants are minors, and any extra personal data collected would be a liability with no benefit to them.

f) Browsing the website. Our website does not use analytics or marketing cookies and does not display advertising. To understand how the site is used, we use a traffic-analytics tool that sets no cookies, does not track visitors across different sites and does not build individual profiles; the resulting data is aggregated and does not allow you to be identified as a person. Legal grounds: our legitimate interest in improving the website (Art. 6(1)(f) GDPR). Our hosting provider may automatically process, for strictly technical and security purposes, traffic data such as your IP address and browser type. Cookies that are strictly necessary for the technical functioning of the site may be used, which do not require consent under applicable law.

The only place on the website where sensitive personal data is entered is the 3.5% redirection form, described under point b). The platform formular230.ro may set its own cookies when you use the form; in that context, the platform's cookie policy applies.

3. Children's data

We work with pupils and young people, including minors. We process minors' data (mainly photo-video images and activity-participation data) solely in the context of educational projects, with the prior consent of the parent or legal guardian and, where applicable, on the basis of agreements concluded with partner schools. The website is not intended to be filled in by minors, and we do not collect personal data from minors through it. We publish materials responsibly: we avoid combining, in the same post, a minor's full name, school and class, and we do not publish images that could put a child in a degrading or vulnerable situation. If you are a parent or legal guardian and believe we have processed your child's data without a basis, write to us - we'll check and delete within 30 days at most.

4. Who we may share data with (recipients)

ANAF (Romania's National Tax Administration) and other public authorities - for filing Form 230 and meeting legal obligations;

formular230.ro - the platform through which Form 230 is filled in online, acting as a processor;

Vercel Inc. - website hosting and aggregated traffic analytics;

Google Ireland Ltd. - email services and storage of the association's internal documents;

the social media platforms where we have official pages (for example Meta/Instagram) - for photo-video materials published with consent;

partner schools and organizations - strictly to the extent needed to run joint projects;

authorities and courts - when the law requires it.

All providers that process data on our behalf do so under contract, on our instructions and with confidentiality obligations. We do not sell, rent or transfer your data for commercial or marketing purposes to third parties.

5. Transfers outside the European Union

Our technical service providers (for example, website hosting and social media platforms) may store data on servers located outside the European Economic Area, including in the United States. Such transfers take place only to providers that offer adequate safeguards under the GDPR (standard contractual clauses approved by the European Commission or certification under the EU-U.S. Data Privacy Framework).

6. How long we keep data

Form 230 and related data (including the CNP): until it is filed with ANAF and at most 1 year after the end of the annual campaign, after which it is deleted/destroyed, except where the law requires longer retention;

ordinary correspondence: at most 3 years from the last interaction;

published photo-video materials: for as long as the projects and our communication channels exist, or until consent is withdrawn;

documents relating to partnership agreements: for the duration of the agreement plus the legal archiving periods;

aggregated website traffic data: at most 25 months.

7. Your rights

Under the GDPR, you have the following rights, which you can exercise free of charge:

the right of access - to find out what data about you we process and to receive a copy of it;

the right to rectification - to ask us to correct inaccurate data or complete incomplete data;

the right to erasure ("the right to be forgotten") - under the conditions of Art. 17 GDPR;

the right to restriction of processing - under the conditions of Art. 18 GDPR;

the right to data portability - to receive the data you provided in a structured, commonly used format;

the right to object - to processing based on legitimate interest;

the right to withdraw your consent - at any time, without affecting the lawfulness of processing carried out before withdrawal; withdrawing is as simple as giving consent: an email to the address below;

the right not to be subject to a decision based solely on automated processing - we note that we do not use automated decision-making or profiling.

To exercise any right, write to us at mihnea.constantin@origioedunova.com. We reply within one month of receiving the request; if the request is complex, the deadline may be extended by two months, in which case we will inform you. If you withdraw photo-video consent, we will stop future use of the materials and remove them, as far as possible, from our own channels; we note that materials already shared on social media platforms may be saved or re-shared by third parties, something that is not entirely within our control. A practical note: once filed with ANAF, a Form 230 falls under the tax authority's processing rules, and deleting it from there is not within our power.

8. The right to lodge a complaint

If you consider that the processing of your data breaches the law, you have the right to lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP): B-dul G-ral Gheorghe Magheru 28-30, District 1, postal code 010336, Bucharest; phone: 031.805.92.11; email: anspdcp@dataprotection.ro; web: www.dataprotection.ro. We do encourage you, though, to write to us first - we'll try to solve any issue directly and quickly.

9. Data security

We apply appropriate technical and organizational measures to protect data: restricted access to documents containing personal data, keeping documents with personal data separate from the operational ones the whole team can access, granting access through defined groups rather than individually, secure storage, minimizing the data collected and training the people who work with it. Volunteers' access ends automatically when the collaboration ends. The website uses an encrypted connection (HTTPS). If a security breach occurs that may affect your rights, we will inform you and notify ANSPDCP within the legal deadline of 72 hours.

10. Third-party links

The website may contain links to external platforms (for example, social networks). We are not responsible for their content or privacy policies - we encourage you to review them separately.

11. Updates to this policy

We may update this policy when the association's activity or the law changes. The current version, with the date of the last update, is published permanently on this page.