Applicable from 25 May 2018

By accepting this Privacy Policy, you expressly consent to our use of your personal data for the purposes and under the conditions set out in this document.

This Privacy Policy applies to Personal Data we collect, when you access or use this website, which is made available by Eventya.

Eventya collects, processes and stores personal data in the EU, being able to demonstrate at all times compliance with European Union law and the principles set out in this document.

All personal data processing activities carried out by Eventya are in line with the provisions of Regulation (EU) 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Directive).

Contact Data

Eventya Co SRL
Address: 1 Onisifor Ghibu Street, Sibiu, Romania
Email: contact@eventya.net

Terms and definitions

1. ”Personal Data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person

2. ”Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction

3. ”Consent” means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her

4. ”Controller” is Eventya, supplier of Eventya platform, which processes personal data in the EU, according to the legislation and the present policy

5. ”User” means individual, with the minimum age of 16 (or the legal minimum age at which someone can join an online service without the controller having to obtain parental consent), which expresses its consent to the use of the Application under the operator’s policies and whether or not it is authenticated in the Application by creating a profile

6. ”Supervisory Authority” means an independent public authority which is established by a Member State according to Regulation (EU) 2016/679

7. ”Your App”, hereinafter referred to as the Application, means the mobile application available for iOS and Android operating systems, owned by the You and running on the Eventya Publishing Platform

8. ”Eventya Publishing Platform”, hereinafter referred to as the Platform, means an integrated system, consisting of a suite of web-based software applications and mobile applications that are subject to copyright law, being registered in the National Register of Computer Programs according to the certificate series 799029BM no. 09135

Principles

The Privacy Policy of Eventya is based on the following principles:

1. Personal data is processed lawfully, fairly and in a transparent manner in relation to the data subject.

2. Personal data is collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

3. Personal data is adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.

4. Personal data is accurate and, where necessary, kept up to date.

5. Personal data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed.

6. Personal data is processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.

Who is responsible for processing personal data?

The responsibility for the processing of personal data rests with the application’s provider. It decides what data is processed, for what purpose and how this processing takes place.

The owner of the Platform on which the application is running, may be responsible for the processing of personal data in those cases where it acts to perform the obligations set forth in the contract.

The owner of the Eventya Publishing Platform is Eventya Co SRL, a company with Romanian private capital, based in Sura Mare, 18 Florilor Street, Sibiu County, registered with the Trade Registry Office attached to the Sibiu Court with the number J32/408/2013, Unique Registration Code: RO31611012.

The legal basis of the processing of personal data

Personal data is processed with the express and unambiguous consent of the Application’s user, in accordance with the provisions of the legislation in force and under the terms of this policy.

It may be the basis for processing: a contract, a user’s request before entering into a contract, the need to comply with a legal obligation, the legitimate interest of the operator or of a third party, the need to protect the vital interests of the user or other individual, fulfilling a task that serves a public interest.

What data do we collect and for what purpose?

We collect personal data from both users who sign in to their accounts in mobile apps as well as those who access the apps non-authenticated.

In the case of authentication, we collect the following personal data:

  • first and last name – used to create the user account, visible in the Application;
  • photo – the profile picture is automatically taken from the social profile when the user logs into the Application with his/hers Facebook, Google, Apple Account. Once authenticated, regardless of the authentication method, the user can add or change the profile picture;
  • email address – is automatically collected from your Facebook, Google and Apple account, when the user logs in through one of the 3 platforms. It can be manually entered by the user when logging in with email and password. A user’s email address is not visible anywhere in the Application, being used only for authentication;
  • information about the device of the user (operating system, type of smartphone (model), the network he uses, GPS location (optionally, if it has given its consent in the Application), this information being used for statistical purposes only;

For unauthenticated users, the following data is collected:

  • information about the device of the user (operating system, type of smartphone (model), the network he uses, GPS location (optionally, if it has given its consent in the Application), this information being used for statistical purposes only;

In addition to the personal data we referred to above, we obtain data from the analysis of how our services are used, as follows:

  • information about the device of the user (operating system, type of smartphone (model), the network he uses, GPS location (optionally, if it has given its consent in the Application), this information being used for statistical purposes only;
  • data collected in Matomo Analytics, used for statistical purposes to determine patterns in user behavior;
  • data obtained by using the “REMINDER” function at events is stored for statistical purposes to make charts with popular events;
  • data obtained by creating collections with locations and events are stored for statistical purposes to determine popular locations or events.

Eventya doesn’t process through Eventya Platform personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.

What data do we collect for creating profile in the Application and what do we make public?

When creating a user profile in the Application, the following personal data is required:

  • First and last name;
  • Email address;
  • Profile picture (when logging in through one of two social platforms: Facebook or Google).

In the user account, which is public in the Application, we publicly display the following information:

  • First and last name;
  • Profile picture

What is the purpose for which personal data is processed?

We process personal data for:

  • user validation, by sending a confirmation SMS when using the incident reporting module to the city halls;
  • geolocation, in the case of the user who accepted the availability of his/hers GPS location to view / order different locations on the map or list, depending on its distance from them. In the lists of locations we display the distance in kilometers from the user’s location to the point of interest.

When using the Incident Reporting Module in the Eventya Platform, the purpose of the GPS location processing is to automatically determine the location of the reported incident on the map.

How to collect and process personal data?

The collection of personal data is done:

  • automatically, when creating a new user account through social platforms (Facebook or Google), including: name, surname, email, photo, device data, GPS location (optional)
  • manually, when creating a new user account through email and password, including name, surname, email; the photo can be added later – optional. The user’s phone number is added when using the Incident Reporting Module, for additional validation.

The processing of personal data is done:

  • automatically, through Matomo Analytics for statistical purposes;
  • manually, in order to prepare marketing reports.

User statistics remain anonymous and are not made public.

For what period do we store personal data?

Personal data is stored for an indefinitely period of time.

The user may at any time request the modification or deletion of personal data by using the contact form in the Application.

Deleting your user account involves automatically deleting your personal data (name, surname, email, picture, password, phone number), collections created, and followed pages.

Currently, we are working on introducing an account deletion button, which will allow the user to delete his / hers account (and all the personal data referred to above).

To whom do we transfer personal data and for what purpose?

We transfer personal data to:

Matomo Analytics – On premise software (https://matomo.org/), where user’s device data is stored for analytics purposes (sessions, location, usage, content access); This software is on-premise – meaning all the information mentioned above is stored on our servers.

One Signal (https://onesignal.com/) – non EU, service we use for sending Push Notifications to the users who accepted to receive Push Notifications. No users personal data is sent to OneSignal, only the smartphone type, operating system, etc …

Amazon AWS (https://aws.amazon.com/websites/) – Frankfurt, EU, where the users’ profile pictures are stored (when that’s the case), Amazon being a private storage service;

Google Cloud (https://cloud.google.com/) – EU, where our server and database are located.

Branch (https://branch.io) – UK, non-EU. We use this service to generate deep-links or dynamic links to open in-app pages or web-pages, depending on the type of device the user uses. The information stored by this service is device related. It does not store user or personal information.

BugSnag (GDPR BugSnag) – used for platform crashes monitoring. It does not store user or personal information.

What security measures have we implemented?

We are constantly concerned with the implementation of the necessary security measures to minimize the risks of unauthorized access to data and implicitly the impact on the privacy of the users:

  • SSL standard for the encryption of data flow;
  • OAUTH standard for user authentication;
  • HMAC – is used to verify (authenticate) that the data has not been altered or replaced.
  • limiting the number of IPs from which the server where we have the database and the web server can be accessed;
  • limited server access by using private SSH keys.

User Rights

The Regulation gives the user a series of rights, which we briefly present in the following:

1. right to information and access to personal data, by virtue of which the user can obtain from us a confirmation as to whether or not personal data are being processed, and, where that is the case, access to the personal data and the information about the methods and the purposes of processing;

2. right to rectification of personal data that can be invoked in order to obtain without undue delay the rectification of inaccurate personal data or completing of incomplete personal data;

3. right to erasure (‘right to be forgotten’) by virtue of which the user can obtain the erasure of personal data without undue delay where one of the following grounds applies:

i.the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
ii.the user withdraws consent on which the processing is based and there is no other legal ground for the processing;
iii.the user objects to the processing and there are no overriding legitimate grounds for the processing;
iv.the personal data have been unlawfully processed;
v.the personal data have to be erased for compliance with a legal obligation;
vi.the personal data have been collected in relation to the offer of information society services.

4. right to restriction of processing where one of the following applies:

i.the accuracy of the personal data is contested by the data subject, for a period enabling us to verify the accuracy of the personal data;
ii.the processing is unlawful and the user opposes the erasure of the personal data and requests the restriction of their use instead;
iii.we no longer need the personal data for the purposes of the processing, but they are required by the user for the establishment, exercise or defence of legal claims;
iv.the user has objected to processing pending the verification whether the legitimate grounds of the controller override those of the user.

5. right to object, by virtue of which the user can object, on grounds relating to his or her particular situation, at any time to processing of personal data, including profiling, where:
• the processing is necessary for the performance of a task carried out in the public interest; or
• the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.

The controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, the user shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.

6.   right to data portability that gives permission to a user to receive the personal data concerning him or her, which he or she has provided to us, in a structured, commonly used and machine-readable format and to transmit those data to another controller, where the processing is based on consent or on a contract and the processing is carried out by automated means.

By virtue of this right, personal data concerning the user can be transmitted directly from one controller to another, where technically feasible.

Change of the Privacy Policy

This Privacy Policy may be updated as a result of relevant changes in the legislation or changes in the Platform’s structure and functions.

If changes to the Privacy Policy are made, users will be notified via e-mail, mobile app notifications, or through the website before the changes take effect.

We encourage users to check this page periodically to keep up-to-date on our privacy practices.

How can you contact us?

For questions about processing your personal data, you can contact Eventya through email contact@eventya.net.

If you wish to make complaints about the processing of your personal data, you can write to the same address, and we will respond within the legal term of correspondence in accordance with our internal policies and procedures.

In the unlikely event that you believe your rights to the processing of personal data have been violated and Eventya did not treat the complaint properly, you can address a Supervisory Authority for Personal Data Processing. The address of the National Supervisory Authority for Personal Data Processing: 28 – 30 Gen. Gheorghe Magheru Bld., District 1, 010336 Bucharest, Romania.

X