1. GENERAL PROVISIONS
1.1 This policy of "UNATC" regarding the processing and protection of personal data (hereinafter referred to as the privacy policy) was adopted in order to comply with the legislation regulating relations related to the processing of personal data, ensuring respect for the rights and freedoms of persons subject to personal data, respecting the confidentiality of personal data and ensuring the security of their processing processes and published in order to ensure unlimited access using the means of the information and telecommunications network "Internet" for the purpose of: familiarizing an unlimited number of persons with the provisions of this Policy.
1.2 This Policy defines the purposes and legal grounds for the processing of personal data, the volume and categories of personal data processed, the categories of data subjects, the procedure and conditions for processing personal data, as well as the relations related to the updating, correction, deletion and destruction of personal data, determines the procedure for providing responses to requests from data subjects for access to personal data.
1.3 This Policy uses the following basic concepts with the following meanings:
- personal data – any information relating to a directly or indirectly identified or identifiable natural person (personal data subject);
- personal data controller (Controller) – National University of Theatre and Cinematography “IL Caragiale”, legal address: Matei Voievod 75-77
- processing of personal data – any action (operation) or set of actions (operations) with personal data performed with or without the use of automation tools. Processing of personal data includes, but is not limited to: collection, registration, systematization, accumulation, storage, clarification (update, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction.
- automatic processing of personal data – processing of personal data using information technology;
- dissemination of personal data – actions aimed at disclosing personal data to an undetermined number of people;
- provision of personal data – actions aimed at disclosing personal data to a specific person or a specific circle of persons;
- blocking personal data – temporary cessation of the processing of personal data (except in cases where processing is necessary for the clarification of personal data);
- destruction of personal data – actions as a result of which it becomes impossible to restore the content of personal data in the personal information system and (or) as a result of which the material media of personal data are destroyed;
- depersonalization of personal data – actions as a result of which it becomes impossible, without the use of additional information, to determine the ownership of personal data of a particular personal data subject;
- personal data information system – a set of personal data contained in databases and information technologies and technical means that ensure their processing;
- cross-border transfer of personal data – transfer of personal data on the territory of a foreign state to an authority of a foreign state, a foreign natural person or a foreign legal person
- For requests admitere@unatc.ro
2. PURPOSES AND LEGAL BASIS FOR THE PROCESSING OF PERSONAL DATA
2.1 The processing of personal data is carried out for the purpose of:
- ensuring the fulfillment of obligations related to the holding of exhibitions, events, cultural and educational projects, including lectures, masterclasses, the provision of other services provided by the Operator, as well as obligations arising from employment contracts, civil contracts and government contracts;
- sending invitations and providing information about events organized by the Operator;
- sending targeted advertising, as well as information about the Operator's activities and events organized by the Operator;
- exercising the rights and obligations of the employer, training the Operator's employees, ensuring the personal safety of employees, the safety of the Operator's property, keeping personnel records;
- organizing and ensuring access control at the Operator's headquarters;
- identifying the subject of personal data and establishing feedback with him/her through the Operator's websites: in the *.unatc.ro domain (hereinafter referred to as the "websites");
- providing the subject of personal data with access to use the functionality and content of the Operator's websites, conducting electronic correspondence, conducting statistical and other studies based on anonymized personal data;
- conducting analyses on the composition of the website audience in order to understand its needs and to improve the products, services and information content (content) of the websites;
- fulfilling other duties assigned to the Operator by law.
2.2 Your personal data is processed to fulfill the legal obligations of the controller (UNATC), according to Article 6 paragraph 1 letter c) and e) of the GDPR.
To the extent that special categories of personal data are necessary, ANSPDCP will request your consent in accordance with the provisions of art. 9 para. (2) letter (a) of the GDPR.
The legislation that mainly governs the activities carried out by the services/offices/compartments within ANSPDCP are the following:
- Regulation 2016/679/EU, Directive 2016/680/EC, Directive 2002/58/EC
- Law 102/2005, amended and supplemented, Law no. 190/2018, Law no. 506/2004
- Law no. 544/2004, Government Ordinance no. 27/2002
- Civil Procedure Code.
- Regulation (EU) No. 679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC
- Directive (EU) 2016/680 on the protection of individuals with regard to the processing of personal data by competent authorities for the purposes of the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data
- Law no. 102/2005 on the establishment, organization and functioning of the National Supervisory Authority for Personal Data Processing, with subsequent amendments and supplements
- Law No. 506 of 17 November 2004 on the processing of personal data and the protection of privacy in the electronic communications sector
- Law No. 190 of 18 July 2018 on implementing measures for Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
- Law No. 363 of 28 December 2018 on the protection of individuals with regard to the processing of personal data by competent authorities for the purposes of preventing, detecting, investigating, prosecuting and combating criminal offences or the execution of penalties, educational and safety measures, and on the free movement of such data
- Government Emergency Ordinance No. 57/2019 on the Administrative Code
3. VOLUME AND CATEGORIES OF PERSONAL DATA PROCESSED. CATEGORIES OF PERSONAL DATA SUBJECTS
3.1 The volume and categories of personal data processed are determined in accordance with the purposes of personal data processing and also depend on the category of data subjects. The Operator processes personal data on the basis of preventing redundancy of the data processed for the declared purposes of processing. The maximum volumes of personal data processed are specified in clause 3.3 of this Policy.
3.2 This Policy establishes the following categories of persons subject to personal data:
- visitors and registered users of the site
3.3 This Policy defines the following volumes of personal data processed by the Operator:
- for the category: "visitors and registered users of the site": full name; Email address; addresses of pages on social networks on the Internet, automatically collected data (cookies) in accordance with Annex No. 1 to this Policy.
4. PROCEDURE AND CONDITIONS FOR PROCESSING PERSONAL DATA
4.1 The Operator does not process personal data relating to ethnicity, nationality, religious, philosophical and other beliefs, private life, political opinions, membership in public associations, political parties and trade unions.
4.2 Biometric personal data are not processed by the Operator.
4.3 The Operator does not carry out cross-border transfers of personal data. However, when the subject of personal data visits websites, his cookies will be used by web analytics services, including. from foreign developers. Information collected through cookies will be stored on the own servers of the said services. A description of the cookies used by web analytics services is provided in Appendix No. 1 to this Policy.
4.4 The method of obtaining (collecting) personal data depends on the category of personal data and can be done through:
- receiving personal data from the subject of personal data in the form of copies (originals) of documents, completed questionnaires, as well as special forms filled out by visitors to the Operator's websites;
- obtaining personal data from third parties in the cases and in the manner provided by law;
- obtaining personal data from publicly available sources.
4.5 With regard to personal data, the Operator performs the following actions, performed both with the use of automation tools and without the use of such means: collection, registration, systematization, accumulation, storage, clarification (update, modification), extraction, use, transfer (distribution, provision, access), depersonalization, blocking, deletion, destruction.
4.6 When storing personalized databases, the Operator uses databases located on the territory of Romania, with the exception of data saved by third-party processors specified in Annex 1.
4.7 This Policy establishes that the deadlines for processing personal data cannot exceed the deadlines established by:
- Romanian and EU legislation;
- the subject of personal data, expressed by written consent to the processing of his/her personal data or in a request to revoke consent to the processing of personal data.
- amendments, invalidation of regulations establishing the legal grounds for the processing of personal data;
- identification of illegal processing of personal data carried out by the Operator;
- withdrawal by the personal data subject of his/her consent to the processing of his/her personal data, if the processing of such personal data in accordance with the law is permitted only on the basis of the consent of the personal data subject.
4.8 The Operator has no right to disclose or distribute personal data to third parties without the written consent of the personal data subject, unless otherwise provided by this Policy and by law.
4.9 The operator has the right to transfer personal data to investigative and investigative bodies and to other authorized bodies, on the basis provided for by the legislation on the territory of Romania.
4.10 The Operator implements the following requirements for the protection of personal data:
4.10.1 appoints a person responsible for organizing the processing of personal data from among the Operator's employees;
4.10.2 when operating information systems with personal data, takes the following legal, organizational and technical measures to ensure the security of personal data during their processing, the implementation of which ensures the established levels of personal data security:
- ensures the safety of personal data carriers;
- approves the list of persons whose access to personal data processed in the information system is necessary for the performance of official (work) duties;
- uses information security tools that have passed the evaluation procedure in accordance with the requirements of the legislation on the territory of Romania in the field of information security, in cases where the use of such tools is necessary to neutralize current threats.
4.10.3 organizes periodic inspections of the conditions for processing personal data;
4.10.4 familiarizes employees who process personal data with the provisions of the legislation on personal data (including personal data protection requirements), local regulations on the processing of personal data and (or) organizes training for these employees;
4.10.5 informs the authorized body for the protection of the rights of data subjects about the processing (intention to process) of personal data;
4.10.6 in cases established by regulatory legal acts, in accordance with the requirements and methods established by the authorized body for the protection of the rights of personal data subjects, carries out the depersonalization of personal data processed in personal data information systems.
5. UPDATE, CORRECTION, DESTRUCTION OF PERSONAL DATA, RESPONSES TO REQUESTS FROM SUBJECTS FOR ACCESS TO PERSONAL DATA
5.1 In the circumstances of this Policy, the Operator has the right to destroy personal data, unless otherwise provided by the agreement to which the personal data subject is a beneficiary or guarantor or by an agreement between the Operator and the personal data subject.
5.2 If the inaccuracy of personal data or the illegality of their processing is confirmed, the personal data must be updated by the Operator and the processing must be stopped accordingly.
5.3 The operator is obliged to inform the subject of personal data or his representative about the processing of personal data of this subject at the request of the latter.
5.4 The requests specified in clause 5.3 of this Policy must be sent to the Operator in writing, to the address specified in clause 1.3 of this Policy and must provide the address to which the Operator must provide a response. The Operator undertakes to provide a response to the request of the data subject for personal data within a period not exceeding 30 (thirty) business days from the date of receipt of the request.
6. BASIC RIGHTS AND OBLIGATIONS OF THE OPERATOR AND THE SUBJECT OF PERSONAL DATA
6.1 The personal data subject has the right to receive information about the processing of his/her personal data by the Operator, except in cases provided for by law.
6.2 The data subject has the right to request the Operator to clarify his/her personal data, block them or destroy them if the personal data are inaccurate, outdated, incomplete, obtained in violation of the law or are not necessary for the stated purpose of processing the personal data.
6.3 The personal data subject has the right to withdraw consent to the processing of personal data where the Operator processes personal data based on the consent of the personal data subject.
6.4 When processing personal data, the Operator is obliged to comply with the requirements of the law and this Policy.
7. FINAL PROVISIONS
7.1 The Operator has the right to make changes to this Policy, ensuring that these changes are made known in the same way that interested parties are made familiar with this Policy.
7.2 In everything not provided for in this Policy, the Operator is guided by the requirements of the legislation in force.
7.3 No clause in this Policy may be considered as having the purpose of limiting the rights and legitimate interests of the data subjects.
APPENDIX NO. 1
"UNATC" POLICY ON THE PROCESSING AND PROTECTION OF PERSONAL DATA
List of cookies used by the Operator
Necessary cookies are essential for the basic functions of the website and the website will not function as intended without them. These cookies do not store personally identifiable data.
- Cookies__cf_bm
- Duration1 hour
- DescriptionCloudflare sets the cookie to enable the use of Cloudflare Bot Management.
- Cookies_abck
- Duration1 year
- Description This cookie is used to detect and defend when a client attempts to replay a cookie. This cookie manages the interaction with online bots and takes the appropriate actions.
- Cookie-uriak_bmsc
- Duration2 hours
- Description This cookie is used by Akamai to optimize site security by distinguishing between humans and bots
- Cookie-uribm_sz
- Duration4 hours
- Description This cookie is set by the provider Akamai Bot Manager. This cookie is used to manage the interaction with the online bots. It also helps in fraud prevention
- wpEmojiSettingsSupports cookies
- Session duration
- DescriptionWordPress sets this cookie when a user interacts with emojis on a WordPress site. It helps determine if the user's browser can display emojis properly.
Functionality cookies help perform certain functionalities, such as sharing website content on social media platforms, collecting feedback and other third-party features.
- Cookie-uriyt-remote-device-id
- Durationnever
- DescriptionYouTube sets this cookie to store the user's viewing preferences for embedded YouTube clips.
- Cookie-uriytidb::LAST_RESULT_ENTRY_KEY
- Durationnever
- Description The cookie ytidb::LAST_RESULT_ENTRY_KEY is used by YouTube to store the last search result entry that was clicked by the user. This information is used to improve the user experience by providing more relevant search results in the future.
- Cookie-uriyt-player-headers-readable
- Durationnever
- Description The yt-player-headers-readable cookie is used by YouTube to store user preferences related to video playback and interface, enhancing the user's viewing experience.
- Cookies-uriyt-remote-connected-devices
- Durationnever
- DescriptionYouTube sets this cookie to store the user's viewing preferences for embedded YouTube clips.
- Cookies-uriyt-remote-session-app
- Session duration
- Description The yt-remote-session-app cookie is used by YouTube to store user preferences and information about the interface of the embedded YouTube video player.
- Cookies-uriyt-remote-cast-installed
- Session duration
- Description The yt-remote-cast-installed cookie is used to store the user's video player preferences using embedded YouTube video.
- Cookie-uriyt-remote-session-name
- Session duration
- Description The yt-remote-session-name cookie is used by YouTube to store the user's video player preferences using embedded YouTube video.
- Cookies-uriyt-remote-cast-available
- Session duration
- Description The yt-remote-cast-available cookie is used to store the user's preferences regarding whether casting is available on their YouTube video player.
- Cookies-uriyt-remote-fast-check-period
- Session duration
- Description The yt-remote-fast-check-period cookie is used by YouTube to store the user's video player preferences for embedded YouTube videos.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as number of visitors, bounce rate, traffic source, etc.
- Cookies_hjSessionUser_*
- Duration1 year
- DescriptionHotjar sets this cookie to ensure data from subsequent visits to the same site is attributed to the same user ID, which persists in the Hotjar User ID, which is unique to that site.
- Cookies_hjSession_*
- Duration1 hour
- DescriptionHotjar sets this cookie to ensure data from subsequent visits to the same site is attributed to the same user ID, which persists in the Hotjar User ID, which is unique to that site.
- Cookie-uriajs_anonymous_id
- Duration1 year
- Description This cookie is set by Segment to count the number of people who visit a certain site by tracking if they have visited before.
- Cookie-uriajs_user_id
- Durationnever
- Description This cookie is set by Segment to help track visitor usage, events, target marketing, and also measure application performance and stability.
- Cookies__tld__
- Session duration
- Description
- We try to store the _hjTLDTest cookie for different URL substring alternatives until it fails.
- It allows us to try to determine the most generic cookie path to use, instead of the page hostname.
- It means that cookies can be shared between subdomains (where applicable).
- After this check, the cookie is removed.
- Session duration.
- Boolean true/false data type.
- Cookies_hjCookieTest
- Session duration
- Description
- Checks if the Hotjar Tracking Code can use cookies. If it can, a value of 1 is set.
- Deleted almost immediately after it is created.
- Duration under 100 ms, cookie expiration time is set to the session duration.
- Boolean true/false data type.
- Cookies_hjTLDTest
- Session duration
- DescriptionTo determine the most generic cookie path that has to be used instead of the page hostname, Hotjar sets the _hjTLDTest cookie to store different URL substring alternatives until it fails.
Advertising cookies are used to provide visitors with personalized advertisements based on the pages they have previously visited and to analyze the effectiveness of the advertising campaign.
- CookiesYSC
- Session duration
- DescriptionYoutube sets this cookie to track views of video sequences embedded in Youtube pages.
- CookiesVISITOR_INFO1_LIVE
- Duration6 months
- DescriptionYouTube sets cookies to measure bandwidth, determining whether the user will use the new or old interface.
- Cookies VISITOR_PRIVACY_METADATA
- Duration6 months
- DescriptionYouTube sets this cookie to store the user's cookie consent state for the current domain.
- Cookies yt.innertube::requests
- Durationnever
- DescriptionYouTube sets this cookie to record a unique ID for the purpose of storing information about the YouTube videos the user has watched.
- Cookies yt.innertube::nextId
- Durationnever
- DescriptionYouTube sets this cookie to record a unique ID for the purpose of storing information about the YouTube videos the user has watched.