1. Controller and contact
Asociația Alpha Leadership is responsible for the purposes and means of the personal-data processing described in this policy. The Association’s tax identification number is 35543352 and its entry in the Register of Associations and Foundations is no. 134/24.11.2015.
For questions or requests concerning your personal data, email roxana.szekely@alphaleaders.ro or use the contact page . Describe the request and your relationship with the Association so we can identify the relevant processing.
2. Data categories and sources
Most information is supplied directly by you. A parent or legal representative may provide information about a minor applicant. Technical information is generated when the device communicates with the website and its infrastructure.
- Contact: name, email address and the message you choose to send.
- Programme applications: applicant’s name, age group, selected programme, motivation, acceptance of the conditions and optional telephone number; the adult applicant’s email address or, for a minor, the legal representative’s name, email address and confirmation.
- Membership: name, email address, motivation, language, account and application status, recorded acceptance of the terms and acknowledgement of the privacy policy, document versions and associated timestamps.
- Account security: verification and sign-in token records, session identifiers stored as SHA-256 hashes, their creation and expiry times and records of use or revocation. Account passwords are not collected.
- Technical operation: information such as IP address, requested URL, request time and network or browser information processed by the infrastructure to deliver and protect the service.
- Any additional information you voluntarily provide in correspondence. Do not send sensitive information, identity documents or other people’s data unless necessary for the request and you are entitled to provide it.
3. Required information and your choices
Browsing public information does not require a member account or submitting a form. If you choose to contact us or apply, the required fields enable us to reply, identify the request and carry out the relevant process. Without the required information, the form cannot be submitted or the requested service cannot be provided.
A telephone number in a programme application is optional. Acknowledging that you have read this policy is an information step, not blanket consent to all processing. Acceptance of the terms concerns the relevant request and is not a subscription to marketing messages.
4. Purposes and legal bases
The legal basis depends on the purpose of the processing. Where we rely on legitimate interests, those interests must be balanced against your rights and interests, with particular attention to children.
| Processing purpose | Legal basis and relevant interest |
|---|---|
| General questions and correspondence | Article 6(1)(f) GDPR: legitimate interest in answering people interested in the Association and managing their requests. |
| Evaluating a programme application and preparing participation | Article 6(1)(b) GDPR: steps requested before a possible participation arrangement. For a representative’s contact details, Article 6(1)(f): communicating with the person responsible for the minor’s application. |
| Creating the requested account, verifying email and processing membership applications | Article 6(1)(b) GDPR: providing the requested account service and taking steps towards possible membership. |
| Preventing abuse, protecting access and diagnosing incidents | Article 6(1)(f) GDPR: legitimate interest in the security and availability of the website, accounts and communications. |
| Responding to data-rights requests and legally required disclosures | Article 6(1)(c) GDPR: complying with applicable legal obligations. |
| Establishing, exercising or defending legal claims | Article 6(1)(f) GDPR: legitimate interest in protecting the Association’s and other persons’ rights where necessary. |
5. Contact and programme application handling
Contact and programme application forms are received through the Cloudflare infrastructure and sent via Brevo’s transactional email service to the Association’s contact address. These forms do not create a member account and their messages are not saved in the membership database. The content reaches the Association’s correspondence system and the providers involved in delivery.
Replies use the adult applicant’s address or the legal representative’s address for a minor. Submitting a form does not automatically subscribe the address to a marketing list. Any additional data or disclosure needed for an accepted participant’s attendance will be explained before that separate step; the form does not automatically forward the application to an event organiser.
6. Member accounts and authentication
Cloudflare D1 stores member-account and application information, document versions acknowledged at submission, status and relevant timestamps. Brevo delivers verification links, sign-in links and transactional notifications. The membership decision is separate from email verification and is made by people.
Sign-in uses single-use links rather than account passwords. The database stores hashes of authentication and session identifiers. Security measures also include request limits and access checks. These measures protect the service and do not evaluate the merits of a programme or membership application.
7. Applicants under 18
For a minor’s programme application, we collect the applicant’s name, age group, programme choice and motivation, together with the representative’s contact details and confirmation. The form does not request the minor’s own email address. Its optional telephone field should be used only if a contact number is needed.
A representative may provide the minor’s information, so the data may come from that person rather than directly from the child. Please make this policy available to the minor in a way they can understand. Do not include health information or unnecessary details about schooling or family circumstances. Any further information or authorisation needed for participation will be addressed separately.
8. Who receives the data
Data is available to the people acting for the Association who need it to handle the request or administer the relevant process. Service providers process information to the extent required for their services.
- Cloudflare: website hosting, delivery, protection and D1 storage for member accounts.
- Brevo: transactional delivery of contact messages, applications, verification links, sign-in links and related notifications.
- Authorities or other legally entitled recipients where disclosure is required by law or necessary to establish, exercise or defend a legal claim.
The presence of a partner’s name or logo on the website does not itself give that partner access to submitted forms or member-account data.
9. International processing
Our providers operate international infrastructure and may involve subprocessors outside the European Economic Area. We do not represent that all information is processed exclusively in Romania or the European Union.
For transfers subject to GDPR, the applicable provider agreements describe safeguards such as adequacy decisions or standard contractual clauses and, where required, supplementary measures. You can contact the Association for information about the safeguards relevant to your data and how to obtain a copy.
Provider information: Cloudflare Data Processing Addendum and Brevo terms and Data Processing Agreement .
10. How long information is kept
Correspondence and programme applications are kept for the time needed to handle the request, communicate the outcome and organise any resulting participation. Further retention depends on the continuing relationship, applicable legal obligations or a specific need to establish, exercise or defend legal claims.
Account and membership-application information is retained as needed to evaluate the request, administer the account and any resulting membership, meet legal obligations and address relevant claims. An erasure request is assessed against those purposes and the conditions of the right; it does not automatically override a legal retention requirement.
Verification and sign-in links expire after 15 minutes and sessions after at most 30 days. These are access-validity periods, not promises that every related database record is deleted at that exact moment. Technical records and provider-held information follow the applicable service settings and retention arrangements, limited by their operational and security purposes.
11. Cookies and website storage
The website uses storage for functions such as language preference, remembering your ad measurement choice and keeping a signed-in account session. The Cookie policy identifies the cookies, their purposes and durations, and explains browser controls. Signing out or deleting the session cookie ends access through that browser session.
12. Your rights and their conditions
Depending on the processing and the conditions in GDPR, you can exercise the following rights:
- Access: confirmation of processing, information about it and a copy of your personal data.
- Rectification: correction of inaccurate information or completion of incomplete information.
- Erasure: deletion where the legal conditions apply, including where data is no longer necessary; exceptions may apply for legal obligations or claims.
- Restriction: limitation of processing in the circumstances provided by GDPR, for example while the accuracy of disputed data is checked.
- Objection: you may object on grounds relating to your situation to processing based on legitimate interests. We assess the objection under the applicable conditions.
- Portability: for data you supplied, where processing is automated and based on consent or a contract, receipt in a structured, commonly used, machine-readable format and transmission where technically feasible.
- Withdrawal of consent: where a particular processing activity relies on your consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
13. Making a request and complaints
Send your request to roxana.szekely@alphaleaders.ro or through the contact page . If we have reasonable doubts about identity, we may request proportionate additional information; do not send an identity-document copy unless it is needed and requested.
We respond without undue delay and within one month of receiving the request. Where its complexity or the number of requests makes this necessary, that period may be extended by up to two further months; we will inform you within the first month and explain why. If we cannot act on a request, we explain the reasons and available remedies.
Requests are normally handled free of charge. Only under the conditions in GDPR for manifestly unfounded or excessive requests may a reasonable fee be charged or a request refused.
You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or another competent supervisory authority, and seek a judicial remedy. Contacting us first does not remove or condition those rights.
14. Security and decision-making
Protection includes encrypted connections, restricted account access, hashed authentication identifiers and safeguards against abusive requests. No internet service can promise absolute security; if you suspect misuse of your data or account, contact us using the details above.
Programme and membership applications are evaluated by people. The website’s technical validation and abuse controls do not make admission decisions. The application process does not use solely automated decisions producing legal or similarly significant effects, or profiling to decide admission.
15. Updates and legal reference
The date above identifies this policy’s current version. We update the information when the described processing or applicable requirements change. New purposes requiring further information will be explained before that processing takes place.
Legal reference: Regulation (EU) 2016/679 (GDPR) .
16. Speaker Elite requests and orders
For Speaker Elite we process your name, email, required phone number, selected package and programme, page audience where applicable, language, acknowledgement of the privacy notice and request reference. When you continue to online payment, we also store order and payment-session references, price, amount and currency, the version and time of terms acceptance, and payment status. We use these data to respond, process the order and arrange participation, as requested pre-contractual steps or to perform the contract under GDPR Article 6(1)(b). No member account is created, and using the form does not grant consent to marketing or ad measurement.
Cloudflare hosts the service and stores order records in D1. Brevo delivers requests to the Association and, after successful payment is verified, transactional confirmations to the buyer and the Association. Stripe receives the data needed to process payment and hosts the payment fields; the Association does not store full card numbers or CVC codes. Stripe may also process data for its own security and fraud-prevention purposes, as described in its policy. This policy’s general rules on recipients, transfers and retention apply according to the handling of the request or contract, legal obligations and the defence of rights.
17. Google Ads measurement with your permission
With your consent under GDPR Article 6(1)(a), we send a Google Ads conversion only after the email service accepts your Speaker Elite request. The event contains a random reference for deduplication; we do not send your name, email, phone, package or form text to Google. The tag may process your IP address, page URL, browser information and click or cookie identifiers. Its purpose is to evaluate ads that bring requests, without remarketing or ad personalisation. You can refuse or withdraw consent in “Cookie preferences”. Google may process information outside the EEA; Google documentation and terms describe the applicable processing, retention and safeguards.