Data Protection Policy (GDPR)
1. Purpose of this Policy
This Data Protection Policy explains the principles and measures applied by European Ectopic Association when processing personal data in connection with:
the European Dental Awards;
the website www.europeandentalawards.com;
event access passes;
competition registrations;
clinical case submissions;
jury evaluation;
online payments;
customer support;
marketing communications; and
attendance at European Dental Awards events.
This Policy complements our Privacy Policy, which provides detailed information about:
the categories of personal data we collect;
the purposes for which data is used;
the legal bases for processing;
the recipients of personal data;
retention periods; and
your data-protection rights.
2. Data controller
The controller responsible for the processing of personal data is:
Legal name: European Ectopic Association
Legal form: Association
Registered address: București, Sector 1, Strada Bratocea, nr.13, CP 012158
Registration number: 33110298
International tax identification number: RO51253474
E-mail: office@ectopicsociety.com
Telephone: +40745201912
Website: www.europeandentalawards.com
Hereinafter referred to as the “Organizer”, “EDA”, “we”, “us” or “our”.
Questions or requests concerning personal data may be sent to office@ectopicsociety.com.
3. Applicable data-protection framework
We process personal data in accordance with:
Regulation (EU) 2016/679, the General Data Protection Regulation or GDPR;
applicable Romanian data-protection legislation;
applicable electronic communications and cookie legislation;
accounting, tax and consumer-protection requirements; and
other legal obligations applicable to our activities.
Where services are offered to individuals located in other countries, additional mandatory local data-protection requirements may apply.
4. Our data-protection principles
We process personal data according to the following principles.
4.1 Lawfulness, fairness and transparency
Personal data is processed only where an appropriate legal basis exists.
We aim to explain clearly:
what information is collected;
why it is collected;
how it is used;
who may receive it;
how long it is retained; and
what rights are available to the individual.
4.2 Purpose limitation
Personal data is collected for specified, explicit and legitimate purposes.
We do not use personal data for an incompatible purpose unless:
the new use is permitted by law;
the individual has been properly informed; or
new consent has been obtained where required.
4.3 Data minimization
We collect only personal data that is reasonably necessary for the relevant purpose.
Registration forms, checkout fields, competition forms and submission requirements should not request information that is unnecessary for:
processing an Order;
providing an access pass;
administering the competition;
evaluating a clinical case;
verifying eligibility;
complying with legal obligations; or
communicating with the individual.
4.4 Accuracy
We take reasonable steps to ensure that personal data is accurate and current.
Individuals are responsible for providing accurate information and for informing us when important information changes.
Inaccurate information will be corrected or deleted where appropriate.
4.5 Storage limitation
Personal data is retained only for as long as necessary for:
the purpose for which it was collected;
the performance of a contract;
accounting or tax obligations;
dispute resolution;
fraud prevention;
legal claims;
competition integrity; or
another lawful purpose.
Detailed retention periods are described in our Privacy Policy and internal retention procedures.
4.6 Integrity and confidentiality
We apply reasonable technical and organizational measures designed to protect personal data against:
unauthorized access;
unlawful disclosure;
accidental loss;
alteration;
destruction;
misuse; and
unauthorized copying.
4.7 Accountability
We are responsible for complying with applicable data-protection requirements and for being able to demonstrate the measures taken to support compliance.
5. Legal bases for processing
Depending on the activity, we may process personal data on one or more of the following legal bases.
5.1 Performance of a contract
Processing may be necessary to:
create and manage an Account;
process an Order;
provide an electronic access pass;
administer a competition registration;
provide access to the case-submission platform;
manage a team submission;
evaluate a registered case;
communicate operational information; or
provide customer support.
5.2 Compliance with a legal obligation
Processing may be necessary to comply with:
accounting and tax requirements;
invoicing obligations;
lawful requests from public authorities;
consumer-protection requirements;
data-protection obligations; or
court and regulatory requirements.
5.3 Legitimate interests
We may process personal data where necessary for legitimate interests such as:
organizing and improving the European Dental Awards;
maintaining the fairness and integrity of the competition;
preventing fraud and unauthorized transactions;
protecting the Website and user Accounts;
responding to requests and complaints;
documenting the Event;
maintaining records of finalists and winners;
protecting our legal rights; and
establishing, exercising or defending legal claims.
We consider whether these interests are overridden by the rights and freedoms of the individual before relying on this basis.
5.4 Consent
Consent may be used for activities such as:
newsletter subscriptions;
selected promotional communications;
optional interviews;
certain photographs or video recordings;
the publication of optional profile details;
non-essential cookies; or
processing identifiable patient-related health data where explicit consent is required.
Consent may be withdrawn at any time.
Withdrawal does not affect processing that was lawful before consent was withdrawn.
5.5 Protection of vital interests
In exceptional circumstances, personal data may be processed where necessary to protect someone’s life or physical safety.
5.6 Legal claims and special-category data
Where special-category personal data is involved, processing will take place only where both:
a valid legal basis under Article 6 GDPR exists; and
an applicable condition for special-category data under Article 9 GDPR is satisfied.
6. Special-category and health-related data
Clinical case submissions may contain dental or medical information relating to a patient.
Such information may qualify as health-related personal data and requires a higher level of protection.
Contestants must:
remove direct patient identifiers;
submit only information necessary for evaluation;
obtain all required patient permissions or consents;
comply with professional confidentiality requirements;
avoid including names, contact details, identity numbers or medical-record numbers;
remove identifying labels and unnecessary metadata; and
ensure that the submission is lawful.
The submission platform is not intended to collect directly identifiable patient records.
Where a case contains unnecessary or unlawfully disclosed patient data, we may:
restrict access to the submission;
request a corrected version;
remove identifying information;
reject the submission;
delete the affected files; or
take other appropriate protective measures.
7. Privacy by design and by default
We aim to consider data protection when designing or modifying:
Website forms;
checkout processes;
user Accounts;
submission workflows;
jury dashboards;
databases;
marketing tools;
access-pass systems; and
Event-accreditation procedures.
Where reasonably possible, our systems and processes are designed so that:
only necessary information is requested;
access is limited according to role;
identifying information is separated from jury materials;
optional fields are clearly distinguished;
non-essential cookies are disabled until consent;
personal data is not publicly displayed by default; and
information is retained only for an appropriate period.
8. Access controls
Access to personal data is limited to persons who require it for a legitimate organizational purpose.
Depending on their role, authorized users may include:
Event administrators;
competition administrators;
customer-support personnel;
finance personnel;
technical administrators;
jurors;
professional advisers; and
approved service providers.
Access permissions may be separated according to function.
For example:
jurors may receive case materials without contestant-identifying information;
finance personnel may access billing details without needing clinical case files;
technical providers may access systems only where necessary for support;
Event staff may receive only the attendee information required for accreditation.
Access rights may be removed or modified when a person’s role changes or their involvement ends.
9. Jury confidentiality and anonymous evaluation
Where anonymous evaluation is required, reasonable measures will be used to prevent jurors from receiving unnecessary identifying information about:
the Contestant;
the Case Leader;
Team Members;
the clinic;
the workplace; or
the patient.
Contestants are responsible for removing identifying information from submitted files.
Jurors and reviewers may be required to:
maintain confidentiality;
use submission data only for evaluation;
avoid downloading or copying materials unnecessarily;
declare conflicts of interest;
protect Account credentials; and
delete or return materials when instructed.
Complete anonymity cannot be guaranteed where the content of a case independently allows a person to recognize its author or origin.
10. Payment data and NETOPIA Payments
Online card payments are processed through NETOPIA Payments.
The payment provider may process information required to:
authorize the transaction;
verify the payment instrument;
prevent fraud;
perform security checks;
complete the payment;
process a refund;
investigate a disputed transaction; and
comply with financial and regulatory obligations.
We do not intentionally store:
complete payment-card numbers;
card security codes;
online-banking passwords; or
other complete card credentials.
We may receive limited transaction information such as:
payment status;
transaction reference;
amount;
currency;
date;
payment-method category; and
refund status.
NETOPIA Payments processes personal data in accordance with its own legal obligations and privacy information.
11. Processors and external service providers
We may appoint external providers to process personal data on our behalf.
These providers may support:
website hosting;
cloud storage;
website maintenance;
e-mail delivery;
newsletter distribution;
ticketing;
accreditation;
database management;
customer support;
analytics;
backups;
cybersecurity;
payment processing; and
Event operations.
Where a provider acts as our processor, it must process personal data only on documented instructions and provide appropriate confidentiality and security commitments.
We assess providers according to factors such as:
the nature of the service;
the types of personal data involved;
security measures;
processing locations;
access requirements;
subcontractor use; and
data deletion or return arrangements.
12. Independent controllers
Certain recipients may process personal data as independent controllers rather than solely on our instructions.
These may include:
NETOPIA Payments;
banks and card networks;
accountants and auditors;
legal advisers;
insurers;
public authorities;
regulatory bodies; and
other entities that determine their own legal processing obligations.
Independent controllers are responsible for providing their own privacy information where required.
13. International data transfers
Some providers may process personal data outside Romania or outside the European Economic Area.
Where an international transfer requires safeguards, we may rely on:
an adequacy decision adopted by the European Commission;
European Commission Standard Contractual Clauses;
supplementary contractual, organizational or technical measures;
another legally recognized transfer mechanism; or
an applicable legal exception.
We consider the destination, provider, type of information and applicable safeguards before using a service that involves an international transfer.
14. Technical and organizational security measures
Depending on the nature and sensitivity of the information, measures may include:
HTTPS-encrypted Website connections;
strong Account authentication;
password hashing;
role-based access permissions;
restricted administrator access;
software and security updates;
backups;
malware and intrusion protection;
monitoring of suspicious activity;
secure payment processing;
confidentiality commitments;
separation of administrative and jury information;
secure file-transfer methods;
access logging;
incident-response procedures; and
secure deletion or anonymization.
Security measures are reviewed and adjusted where reasonably necessary.
No system connected to the internet can be guaranteed to be completely secure.
15. Account and password security
Account holders are responsible for:
using a strong and unique password;
protecting their login credentials;
not sharing access with unauthorized persons;
logging out of shared devices;
keeping their e-mail Account secure; and
reporting suspected unauthorized access.
We may temporarily suspend an Account where necessary to:
protect the Account holder;
investigate suspicious activity;
prevent unauthorized access;
respond to a payment dispute; or
address a possible security incident.
16. Personal data breaches
A personal data breach may include unauthorized access, disclosure, loss, alteration or destruction of personal data.
Where a suspected breach is identified, we will take reasonable steps to:
contain the incident;
identify the affected systems and information;
assess the potential consequences;
preserve relevant evidence;
limit further unauthorized access;
restore availability where appropriate;
document the incident;
notify the competent supervisory authority where legally required; and
inform affected individuals where legally required.
Service providers must inform us of relevant security incidents in accordance with their contractual and legal obligations.
17. Data-protection impact assessments
We may carry out a data-protection impact assessment where a planned activity is likely to create a high risk to the rights and freedoms of individuals.
An assessment may consider:
the purpose of the processing;
the necessity and proportionality of the activity;
the categories of data involved;
the number and vulnerability of affected individuals;
possible risks;
access arrangements;
retention periods; and
measures intended to reduce the risks.
18. Records of processing activities
We may maintain internal records describing relevant processing activities, including:
the purposes of processing;
categories of individuals;
categories of personal data;
recipients;
international transfers;
retention criteria; and
security measures.
These records may be reviewed when systems, providers or processing activities change.
19. Data retention and deletion
Retention periods are determined according to:
contractual requirements;
competition timelines;
accounting and tax obligations;
complaint and chargeback periods;
limitation periods;
security requirements;
consent status;
historical value; and
the need to establish, exercise or defend legal claims.
When personal data is no longer necessary, it may be:
securely deleted;
anonymized;
restricted;
archived where legally permitted; or
retained only in a minimal form required for compliance.
Detailed retention periods are available in our Privacy Policy.
20. Marketing and communication preferences
Operational communications may be sent where necessary to manage:
Orders;
access passes;
Accounts;
payments;
submissions;
deadlines;
Event changes;
finalist participation; or
customer-support matters.
These messages are necessary for the requested service and are separate from marketing.
Marketing communications are sent only where an appropriate legal basis exists.
Individuals may stop receiving direct marketing by:
using an unsubscribe link;
adjusting available Account preferences; or
contacting office@ectopicsociety.com
An unsubscribe request does not prevent essential service-related communications.
21. Cookies and similar technologies
The Website may use cookies and similar technologies for:
essential Website functions;
Account authentication;
security;
checkout;
remembering user preferences;
analytics;
embedded media; or
marketing.
Strictly necessary technologies may operate without consent where permitted by law.
Non-essential cookies will be activated only after the required consent has been obtained.
Cookie choices can be managed through the Website’s cookie-preference panel.
Additional details are available in the Cookie Policy.
22. Photographs and video recordings
European Dental Awards events may be photographed, filmed or otherwise recorded.
General audience and Event-atmosphere material may be processed for:
Event documentation;
news and reporting;
communication with participants;
promotion of the current or future editions; and
maintenance of an Event archive.
Where a person is the primary focus of promotional content and consent is required, separate consent will be requested.
Individuals may contact us regarding a specific image or recording using office@ectopicsociety.com.
We will assess each request according to:
the legal basis used;
the context of the recording;
the individual’s rights;
the Organizer’s legitimate interests;
whether the material has already been published; and
applicable legal obligations.
23. Data relating to other persons
A person who provides personal data relating to another individual, such as a Team Member, must:
have a lawful basis or appropriate authority to provide it;
provide accurate information;
inform the other person about the disclosure;
direct them to our Privacy Policy; and
provide only information necessary for the relevant purpose.
The Organizer may contact the other person to:
confirm their involvement;
provide privacy information;
provide Event instructions;
deliver an invitation or access code; or
verify the accuracy of the information.
24. Individual rights
Subject to the conditions and limitations provided by law, individuals may have the right to:
receive information about the processing of their data;
obtain access to their personal data;
request correction of inaccurate information;
request deletion;
request restriction of processing;
receive certain data in a portable format;
object to processing based on legitimate interests;
object to direct marketing;
withdraw consent;
obtain information about certain automated decisions; and
lodge a complaint with a supervisory authority.
Detailed information about these rights is available in our Privacy Policy. The rights recognized by the Romanian supervisory authority include access, rectification, erasure, restriction, portability, objection and protection in relation to solely automated decisions. (Data Protection)
25. Exercising data-protection rights
Requests may be sent to:
E-mail: office@ectopicsociety.com
Postal address: București, Sector 1, Strada Bratocea, nr.13, CP 012158
The request should include enough information to identify:
the requester;
the relevant Account, Order or registration;
the data or processing concerned; and
the right being exercised.
We may request reasonable additional information to verify identity and prevent unauthorized disclosure.
Requests will normally be handled within one month. Where permitted by law, this period may be extended by up to two additional months if the request is complex or numerous, and the requester will be informed of the extension. (Data Protection)
26. Complaints to the supervisory authority
Individuals may lodge a complaint with the competent supervisory authority.
In Romania, the competent authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP
A complaint may also be submitted to the supervisory authority in the EU or EEA country where the individual:
lives;
works; or
believes a data-protection infringement occurred.
We encourage individuals to contact us first so that we have an opportunity to investigate and address the concern.
27. Responsibilities of personnel and collaborators
Persons who receive access to personal data on behalf of the Organizer must:
use the information only for authorized purposes;
respect confidentiality;
follow security procedures;
avoid unnecessary copies;
protect login details;
report suspected incidents;
respect retention and deletion instructions; and
complete appropriate data-protection guidance or training where required.
These obligations may continue after the person’s involvement with the Event ends.
28. Policy review
This Policy may be reviewed when:
a new service is introduced;
the Website or submission platform changes;
a new provider is appointed;
new categories of information are processed;
an international transfer is introduced;
a security incident identifies a need for improvement;
legal requirements change; or
our internal processes are updated.
The current version will be published on the Website with its latest revision date.
29. Relationship with the Privacy Policy
This Policy describes our general GDPR compliance and data-governance framework.
The Privacy Policy provides the detailed information intended for Website users, customers, contestants, attendees and other individuals.
Where the two documents address the same subject, they should be interpreted together.
Mandatory data-protection law will prevail in the event of any inconsistency.
30. Contact
For questions, concerns or requests concerning personal data, please contact:
Legal name: European Ectopic Association
Legal form: Association
Registered address: București, Sector 1, Strada Bratocea, nr.13, CP 012158
Registration number: 33110298
International tax identification number: RO51253474
E-mail: office@ectopicsociety.com
Telephone: +40745201912
Website: www.europeandentalawards.com