Privacy Policy

This site is operated by Societatea Studențească de Chirurgie din România — Filiala Craiova. We process personal data in accordance with the EU General Data Protection Regulation (GDPR). This page describes what we collect, why, how long we keep it, and who else sees it.

Data we collect

  • Account data — name, email, password (hashed), phone, university, faculty, year of study.
  • Participant category — whether you register as a student, resident or doctor. This is used for your badge, your certificate and aggregate reporting to the organising committee, and can reveal that you are a medical professional.
  • Workshop eligibility flags — previous KS / BSS participation, and the answers you give to the eligibility questionnaire.
  • Order and billing data — ticket type, amount paid, and the billing details you enter at checkout (name, address, and, for a company, its tax identification and registration number).
  • Attendance data — which conferences and workshops you scanned into, and when.
  • Abstracts — the title, authors, affiliation, body and any file you submit, plus the reviewers’ scores and the committee’s decision.
  • Security data — the IP address used to create your account, and the IP address recorded when you scan in to a conference or workshop.
  • Activity log — a record of the actions you take on your account (signing in and out, resetting your password, editing your profile, starting a checkout, registering for or cancelling a workshop, submitting or withdrawing an abstract, exporting or deleting your data), each stored with the time, the IP address and the browser and device you used. It is visible only to super-administrators, on your account’s support page, and is used to answer “what happened to this account, and from where” during a support request or a security investigation.
  • Payment records — a log of every message we receive from the payment processor about your order, whether the payment succeeded or not, used to reconcile orders against the processor’s settlement report.
  • Failed registration attempts — if a registration does not complete, we store the email address, name and IP address from the attempt, together with the reason it failed. We never store the password from a failed attempt. Because these attempts do not create an account, this data is not linked to any account and is not included in an account data export.

Why we collect it

  • To issue your ticket, badge and certificate.
  • To issue the fiscal invoice required by Romanian law, and to keep our accounts.
  • To enforce workshop eligibility rules and capacity.
  • To send you operational emails about your attendance.
  • To detect abuse and investigate account security incidents (legitimate interest, GDPR Art. 6(1)(f)). The IP addresses, the activity log and the record of failed registration attempts are all collected on this basis; the IP addresses and the activity log are visible only to super-administrators.

How long we keep it

  • Account, profile, tickets and attendance — for as long as you have an account. When you delete your account, this data is deleted or anonymised (see Your rights).
  • Invoices and the orders behind them — 10 years, as required by Romanian law, even after you delete your account. They are no longer linked to your name.
  • Activity log — 180 days, then deleted automatically.
  • Check-in IP addresses — 90 days, after which the IP is removed from the attendance record but the record itself is kept.
  • Failed registration attempts — 90 days, then deleted automatically.
  • Application and error logs — 90 days.
  • Email delivery logs — 180 days.

Your rights

  • Access & export — you can download your data, including your activity log, from your account at any time.
  • Erasure — you can delete your account. If you never bought a ticket, everything is deleted. If you did, your personal data (profile, sessions, activity log, IP addresses, submitted abstract files) is deleted and your name is removed from the orders and invoices we are legally required to keep.
  • Rectification — you can edit your profile at any time.
  • Opt out of marketing — toggle in your account settings. Newsletter emails have their own unsubscribe link. Operational emails about your order and attendance are always sent.
  • Complaint — you may lodge a complaint with the Romanian data protection authority (ANSPDCP).

Hosting & processors

Personal data is hosted in the EU on infrastructure operated by us. Two third parties process data on our behalf:

  • EuPlătesc — processes your card payment. We never see or store your card details.
  • Oblio — issues the fiscal invoice for your order and receives the billing details you enter at checkout (name, address, and any company tax identification).

Transactional emails are sent via our own self-hosted mail server. Error monitoring runs on our own infrastructure and records only an internal account identifier, never your name or email.

Contact

For privacy requests: contact@tacssyd.ro