1. Data controller
The data controller is Asociația Alpha Leadership, tax identification number 35543352, registered in the Romanian Register of Associations and Foundations under no. 134/2015.
For questions or to exercise your data-protection rights, write to us through the contact page .
2. Data we process
Depending on how you use the website, we may process:
- for the contact form: your name, email address and the content of the message you choose to send;
- for applications: the applicant’s name, the adult applicant’s email address, optional phone number, age group, selected programme, motivation and confirmation of the conditions;
- for applicants under 18: the parent or legal guardian’s name, email address and confirmation;
- for a member account and membership application: name, email address, motivation, acceptance of the terms, confirmation that the privacy policy was read, locale, account and application status, and related timestamps;
- for passwordless authentication: SHA-256 hashes of unique and session tokens; we do not collect or store passwords;
- any other information you voluntarily include in correspondence;
- technical data needed to deliver and secure the website, such as IP address, request date and time, requested page, browser type and network information;
- Please do not use the forms to send sensitive data or information about other people unless necessary and you are entitled to do so.
3. Forms and member accounts
When you submit a form, the data is transmitted securely to the Cloudflare infrastructure serving this website and sent through Brevo, our transactional email provider, to the Association’s contact address. Replies go to the adult applicant or, for a minor, to the legal guardian. Addresses are not automatically added to a marketing list.
Completing and submitting a form is optional. Fields marked as required are needed to manage the message or review the application; without them, the form cannot proceed. A selected applicant’s data is not automatically shared with a third-party organiser; any sharing required for participation will be explained separately before it occurs.
Account data, the membership application, its status and SHA-256 token hashes are stored in Cloudflare D1. Brevo sends unique verification and sign-in links and account notifications. Verifying the email address activates access to the account and enables sign-in, but does not automatically approve the membership application.
4. Purposes and legal bases
The website does not use this data for advertising, analytics, profiling or solely automated decisions and sends no marketing communications without a separate legal basis. Programme and membership applications are reviewed by people.
| Purpose | Legal basis |
|---|---|
| Answering questions and managing correspondence | Legitimate interest in communicating with interested people and, where relevant, steps taken at your request before an agreement |
| Reviewing the application, communicating the outcome and preparing participation | Steps taken at the applicant’s request before an agreement and legitimate interest in administering the application process |
| Creating and managing the account, verifying the email address and reviewing the membership application | Steps taken at the applicant’s request before joining and legitimate interest in securely administering the membership process |
| Delivering, operating and protecting the website | Legitimate interest in security, availability and technical diagnostics |
| Meeting legal obligations and defending rights | Legal obligation or legitimate interest, as appropriate |
5. Recipients of data
Depending on the process, data may be handled, strictly to the necessary extent, by:
- Brevo, which delivers unique links, notifications and other transactional emails;
- Cloudflare, which provides infrastructure, D1 storage, delivery and security for the website;
- public authorities where disclosure is required by law.
Providers may use international infrastructure. Transfers outside the European Economic Area must rely on the mechanisms in Chapter V GDPR, according to the conditions applicable to each service. Read the Cloudflare privacy policy and Brevo privacy policy.
6. Retention
Correspondence is kept for as long as needed to resolve the request and afterwards only where justified by the relationship, legal obligations, or the establishment, exercise or defence of legal claims. Technical data is retained according to the infrastructure provider’s configuration and periods, limited to what is needed for operation, security and incident investigation.
Unique verification and sign-in tokens expire after 15 minutes, and sessions after no more than 30 days. Member-account and membership-application data is retained for as long as needed to review and administer the process, meet legal obligations and defend rights, and until an erasure request where the right applies.
7. Your rights
Subject to the GDPR, you may request:
- access to your data and a copy;
- correction of inaccurate data or completion of incomplete data;
- erasure or restriction of processing;
- objection to processing based on legitimate interest;
- data portability where the legal conditions are met.
We will answer within the period prescribed by law and may request reasonable information to confirm your identity. If you believe your rights have not been respected, you may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing.
8. Applicants under 18
The form does not request the minor applicant’s email address; the only contact details collected are the parent or legal guardian’s name and email address, together with their confirmation. Do not include information about the minor’s health, education or personal circumstances. Before any participation, the guardian’s identity and authorisation will be confirmed separately, and any additional information required will be explained before collection.
9. Security and updates
We use reasonable technical and organisational measures to protect data, but no internet transmission can be guaranteed risk-free. We may update this policy when the website, processing or legal framework changes. The current version and update date appear on this page.
Legal reference: Regulation (EU) 2016/679 .