Skip to main content

Privacy Policy

Last updated: 2026-05-11

1. Data controller

The data controller is Asociația Studenților Mediciniști din Craiova (CIMSC — Craiova International Medical Students' Congress organising body). You may contact us at any time about how we handle your personal data:

2. What data we collect

When you create an account and use our services, we collect:

  • Identity data: first name, last name
  • Contact data: email address, phone number
  • Location data: Romanian county and city/sector (used to plan accommodation logistics and to issue invoices)
  • Academic data: current study year and home faculty
  • Payment data: processed via Netopia Payments. We never see, store or transmit full card numbers or CVV codes — only a transaction reference, status, amount and timestamp.
  • Order history: packages purchased, workshops and conferences registered, plus invoice data issued via SmartBill
  • Submission data: if you submit an abstract or fill in the longevity questionnaire, we store the content you provide and link it to your account
  • Technical data: authentication cookies, IP address recorded with each request for security and abuse prevention (see Cookie Policy and section 9 of this document)
  • Operational data: audit log of administrative actions performed on your account (used for security investigations only)

3. Lawful basis for processing

  • Art. 6(1)(b) GDPR — performance of a contract: processing is necessary to register your account, sell you a participation package, deliver workshop and conference access, issue invoices and provide customer support.
  • Art. 6(1)(c) GDPR — legal obligation: retaining accounting records as required by Romanian Law 82/1991 on accounting and by tax legislation.
  • Art. 6(1)(a) GDPR — consent: required for non-essential cookies and for marketing communications — currently the platform does not use analytics or marketing cookies; see our Cookie Policy.
  • Art. 6(1)(f) GDPR — legitimate interests: abuse-prevention logging (rate limiting, audit trail) and platform security. We have weighed these interests against your rights and consider the impact minimal.

4. Retention

  • Order and invoice records: retained for 10 years to comply with Romanian accounting and tax legislation (Law 82/1991, art. 25).
  • Account data: retained for as long as your account remains active. You can request erasure at any time from your account page; remaining accounting data will be pseudonymised where retention is legally required.
  • Audit logs: retained for 2 years for security investigations.
  • Authentication cookies: retained for the duration of the session and up to the refresh-token expiry (24 hours).
  • Password-reset and email-confirmation tokens: 1 hour and 24 hours respectively; auto-deleted by the database.

5. Recipients of personal data

We share strictly necessary data with the following processors:

  • Netopia Payments (Netopia Financial Services S.A., Romania) — payment processing. Your card data is collected on Netopia's own interface, not ours.
  • SmartBill (Intelligent IT SRL, Romania) — invoicing and fiscal records. Receives invoice line items, payer name, email and address.
  • Gmail SMTP (Google Ireland Limited) — transactional email delivery. Receives recipient address and message content.

We do not sell personal data to third parties. We do not use the data for automated decision-making, including profiling, that produces legal effects concerning you.

6. International transfers

Most processing happens within the European Economic Area. Where a processor operates outside the EEA (for example Google for transactional mail delivery), transfers rely on the European Commission's Standard Contractual Clauses and supplementary measures where appropriate.

7. Your rights

Under the GDPR, you have the right to:

  • Access — obtain a copy of your personal data
  • Rectification — correct inaccurate or incomplete data
  • Erasure — have your data deleted (subject to legal retention requirements)
  • Restriction — limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing
  • Lodge a complaint with the Romanian supervisory authority ANSPDCP — National Supervisory Authority for Personal Data Processing (www.dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București).

8. How to exercise your rights

You can exercise most rights directly from your account page: view and update your details, export your data in JSON format (Art. 20) or delete your account (Art. 17). For other requests, write to [email protected]. We respond within 30 days of receipt; complex requests may be extended by up to 60 additional days, in which case we will let you know.

9. Security

We apply technical and organisational measures including:

  • HTTPS encryption in transit and HSTS pre-loaded for the production domain
  • Password storage using bcrypt with per-user salt
  • Role-based access controls; administrative actions logged to a tamper-resistant audit collection
  • Rate limiting and brute-force protection on login, signup, password reset and payment callback endpoints
  • Strict input validation, server-side HTML sanitisation, and rejection of MongoDB operator injection attempts
  • Strict Content-Security-Policy and other modern security headers

10. Children's data

The platform is aimed at university students — we do not knowingly process the data of minors under 16. If you believe a minor has registered, contact us and we will delete the account.

11. Changes to this policy

We may update this policy. Material changes will be communicated by email to registered users and via a banner on the site. The latest version is always available at /privacy.

12. Contact

CIMSC — Craiova International Medical Students' Congress
Email: [email protected]
Privacy enquiries: [email protected]

This policy is intended to reflect current practice. The CIMSC team reviews it with counsel periodically; if you spot anything that looks wrong or incomplete, please tell us.

CIMSC 28th edition of Craiova International Medical Students' Congress

Craiova International Medical Students' Congress - connecting students and advancing medicine, now in its 28th edition.

Get in Touch

Have questions about the congress? We'd love to hear from you.

Contact us

© 2026 CIMSC - Craiova International Medical Students' Congress. All rights reserved.

NETOPIA PaymentsSoluționarea Alternativă a LitigiilorSoluționarea online a litigiilor