Privacy policy

Effective date: 03.02.2023 · Last updated: 28.09.2026 · Version: 2026.1

1. About this policy

This Privacy Policy explains which personal data Asociația Clusterul de Excelență în Securitate Cibernetică (CYSCOE) processes when you visit cyscoe.ro, write to us, subscribe to our updates or apply for membership, why we process it, how long we keep it and what rights you have.

We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), Law no. 190/2018 on measures implementing the GDPR and Law no. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector, as amended. This policy should be read together with our Cookie Policy, GDPR Policy and Terms of Service.

2. Who we are (data controller)

Asociația Clusterul de Excelență în Securitate Cibernetică (CYSCOE)
Registered office: Bd. Mareșal Alexandru Averescu nr. 8-10, et. 1, cam. 104, sector 1, 011455 București, Romania
Email:

CYSCOE is a Romanian non-profit, non-governmental association established under Government Ordinance no. 26/2000. We have not appointed a Data Protection Officer, as the conditions of Article 37 GDPR are not met. For any question about your personal data, write to .

3. What data we process, why, and on what legal basis

3.1 Visiting the website

When you access cyscoe.ro, the web server and our security services automatically record technical data: IP address, date and time of the request, page requested, referring page, browser and operating system, and security events (for example blocked or suspicious requests).

  • Purpose: delivering the website, protecting it against attacks and abuse, diagnosing errors.
  • Legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).
  • Retention: up to 90 days, unless a record is needed to investigate a specific security incident.

3.2 Website statistics (only with your consent)

If you accept statistics cookies in the cookie banner, we use Google Analytics 4 to understand, in aggregated form, how the website is used (pages visited, visit duration, approximate location at country or city level, device type). Before consent, no statistics cookies are set. Google Consent Mode is active: while consent is refused, Google receives only cookieless signals that do not identify you and are not used for advertising.

  • Legal basis: your consent (Art. 6(1)(a) GDPR and Art. 4(5) of Law no. 506/2004). You can withdraw it at any time from the Cookie Policy page or the consent button displayed on the website.
  • Retention: according to the retention period configured in Google Analytics, at most 14 months.

3.3 Contact form and email

When you use the contact form or write to us, we process your name, email address, telephone number (optional), the content of your message and any other information you choose to provide.

  • Purpose: answering your request and following up on proposals for partnerships, projects or membership.
  • Legal basis: steps taken at your request (Art. 6(1)(b) GDPR) or our legitimate interest in responding to correspondence (Art. 6(1)(f) GDPR).
  • How it is handled: messages sent through the form are delivered by email to the CYSCOE mailbox and a copy is stored in the website database.
  • Retention: form entries stored in the website database are deleted periodically, at least once every 12 months; correspondence is kept for up to 3 years after the last exchange, unless a longer period is required by law or to defend a legal claim.

3.4 Newsletter

If you subscribe to our newsletter, we process your name and email address to send you news about CYSCOE activities, projects and events.

  • Legal basis: your consent (Art. 6(1)(a) GDPR).
  • Retention: until you unsubscribe. You can unsubscribe at any time by replying to any of our messages or by writing to .

3.5 Membership applications and member relations

Organisations that wish to join CYSCOE complete a membership form and sign a non-disclosure agreement. In this context we process the identification and contact data of the organisation’s representatives, their role, and the information provided in the application.

  • Purpose: assessing the application, the vote in the Governing Board, invoicing the membership fee and organising the association’s activity.
  • Legal basis: steps prior to and performance of the membership relationship (Art. 6(1)(b) GDPR), legal obligations, including accounting obligations (Art. 6(1)(c) GDPR), and our legitimate interest in running the association (Art. 6(1)(f) GDPR).
  • Retention: for the duration of membership and up to 3 years afterwards; accounting documents are kept for the period required by accounting law.

3.6 Events, projects and public communication

CYSCOE takes part in conferences, workshops and European projects. When we publish news about these activities, articles may include the names, roles and photographs of speakers and participants.

  • Legal basis: our legitimate interest in informing the public about the association’s activity (Art. 6(1)(f) GDPR), or consent where required.
  • If you appear in material published on cyscoe.ro and want it corrected or removed, write to .

3.7 Embedded content

Some pages include YouTube videos or a Google Maps map. These are blocked until you accept the corresponding cookie category, and you can also load them individually. Once loaded, the provider (Google) may collect data according to its own policies.

4. Recipients and service providers

We do not sell personal data and we do not use it for advertising. Data may be accessed by the following categories of recipients, only to the extent necessary:

  • the website hosting provider, which stores the website and its database;
  • Cloudflare, Inc., which delivers the website and protects it against attacks (content delivery network and security);
  • Defiant, Inc. (Wordfence), the website firewall and security plugin;
  • Google Ireland Limited, for Google Analytics (only with consent), embedded YouTube and Google Maps content, and the Google Docs documents used for membership applications (membership form and NDA);
  • the technical provider that develops and maintains the website, which also receives copies of form notifications for technical support;
  • CYSCOE’s email service provider;
  • public authorities, when we are legally required to disclose data.

Service providers act as processors on our behalf, under contractual terms that include data protection obligations, or, where applicable, as independent controllers under their own terms.

5. Transfers outside the European Economic Area

Some providers (Google, Cloudflare, Defiant) are part of groups based in the United States. Where data is transferred to the United States, the transfer relies on the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, for certified companies, or on the Standard Contractual Clauses adopted by the European Commission.

6. Security

As a cybersecurity organisation, we apply technical and organisational measures proportionate to the risk: encrypted connections (HTTPS), a web application firewall, limitation of abusive requests, restricted administrative access, updated software and cookie consent management. No system is completely risk-free; if a personal data breach occurs that is likely to create a risk for you, we will notify the supervisory authority and, where required, the persons concerned, in accordance with Articles 33 and 34 GDPR.

7. Your rights

Under the GDPR, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data rectified;
  • have data erased, where the legal conditions are met;
  • restrict processing;
  • data portability, for data processed on the basis of consent or contract;
  • object to processing based on our legitimate interest;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise these rights, write to . We will answer within one month, which may be extended by two further months for complex requests, in which case we will inform you. We may ask for information to confirm your identity.

You also have the right to lodge a complaint with the Romanian supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, sector 1, 010336 București, , www.dataprotection.ro.

8. Automated decisions and children

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you. The website is addressed to organisations and professionals and is not intended for children under 16; we do not knowingly collect their data.

9. Changes to this policy

We review this policy whenever the processing carried out through the website changes, and at least once a year. The current version is always published on this page, with its update date. The Romanian version of this policy prevails in case of any discrepancy between language versions.