Data controller: Patronatul Furnizorilor Privați de Servicii Sociale (PFPSS), tax ID (CUI) 50457026, registered office: Phoenicia Business Center, Corp A, interfon 14, Str. Turturelelor 11b, bl. A, sc. A, et. 1, ap. a14, Sector 3, București. Contact: office@pfpss.ro, 0732 009 000.
1. What data we collect
Membership application: organisation details (name, CUI, registration number, address, county, service types, capacity), legal representative details (name, role, personal identification number / CNP), contact email and phone.
Uploaded documents:CUI / ONRC certificate, licence / accreditation, membership application form and a copy of the representative's ID card (contains CNP and photograph). They are stored encrypted, with restricted access, and used solely to validate membership.
Petition signatures: organisation name and CUI, signatory name and role, email, phone and IP address (stored only in pseudonymised / hashed form).
Contact form: name, email, subject, message and IP address.
Strictly necessary technical data: cookie preference and, when you sign in, the account session (stored locally in the browser). Analytics tools load only after consent. See the Cookie policy.
The legal representative's personal identification number (CNP) is processed solely to verify identity on joining and to prepare membership documents, under GDPR art. 6(1)(b) and with the safeguards of art. 4 of Romanian Law no. 190/2018 (restricted access, designated staff, limited retention). The ID card copy may undergo automatic verification (OCR) involving a processor outside the EEA (Google) only if you give explicit consent at upload; otherwise the document is checked manually only. The CNP is never shown publicly.
2. Purpose and legal basis
- Processing membership applications and enquiries — basis: pre-contractual steps and our legitimate interest in responding (GDPR art. 6(b) and (f)).
- Ongoing communication with members and partners — basis: performance of membership (GDPR art. 6(b)).
- Possible site usage statistics — basis: consent given in the cookie banner (GDPR art. 6(a)).
3. Retention
Contact data of applicants is kept for up to 24 months from the last interaction. Member data is kept for the duration of membership and for 5 years after it ends, in line with legal obligations.
4. Recipients and processors
Data is accessed by PFPSS staff and by the following service providers acting as processors under confidentiality terms:
- Vercel Inc. — website hosting (global infrastructure, including the USA). Transfer outside the EEA under Standard Contractual Clauses.
- Supabase — database and document storage, hosted in the European Union (Ireland).
- Resend — transactional email (confirmations, notifications). Transfer outside the EEA under Standard Contractual Clauses.
- Stripe — membership fee card payments. Transfer outside the EEA under Standard Contractual Clauses.
- Cloudflare — anti-bot protection (Turnstile) on public forms.
- ANAF — company data checks by CUI via the National Agency for Fiscal Administration public service (independent public controller).
- Google— automatic OCR of uploaded documents, only with explicit consent for the ID card. Transfer outside the EEA under Google's safeguards.
We do not sell or rent your data to third parties.
5. Your rights
Under the GDPR you have the right to:
- access your personal data;
- rectification or erasure;
- restriction of processing;
- data portability;
- object to processing;
- withdraw consent at any time;
- lodge a complaint with the National Supervisory Authority for Personal Data Processing (dataprotection.ro).
You may exercise your rights in the platform under Account settings → My rights (GDPR) (export or deletion request), or by email. We respond within 30 days under GDPR art. 12, after verifying identity.
6. Transfers outside the EEA
Some providers (Vercel, Resend, Stripe, Google) may process data outside the European Economic Area. Such transfers rely on the European Commission's Standard Contractual Clauses or other appropriate safeguards under GDPR arts. 44–49.
7. Automated document checks
To speed up membership validation, some documents may be analysed automatically (OCR) by an external processor. The ID card (which contains the CNP) is analysed automatically only with your explicit consent; otherwise it is checked manually. We do not take decisions with legal effects based solely on automated processing — membership decisions rest with the secretariat and the association's governing bodies.
8. Security
We apply appropriate technical and organisational measures: encrypted transmission (HTTPS), role-based access, row-level security in the database, sensitive documents (including ID documents) stored in private spaces with temporary signed URLs, IP pseudonymisation and regular backups.
9. Minors
The platform is aimed at organisations and their adult representatives. We do not knowingly collect data about minors through this platform.
10. Updates
We may update this policy. Significant changes will be announced in the platform, and the last-updated date appears at the top.
11. Contact
Controller: Patronatul Furnizorilor Privați de Servicii Sociale. To exercise any right or ask about your data, write to office@pfpss.ro with „GDPR” in the subject line, or call 0732 009 000.