{CommunityName} Privacy Policy
This Privacy Policy explains how {CommunityName} processes the personal data of users and other individuals who interact with {CommunityName} services, in accordance with applicable data protection and privacy laws.
Identity of the Data Controller
The controller of personal data, for data generated in connection with the community within the Application (content, membership, communication with Members), is the Mentor who operates {CommunityName}.
For personal data protection enquiries, including requests to exercise rights regarding personal data, you may contact the Mentor at {MentorContactEmail}.
Data associated with the TOKERO SocialFI account (authentication, identification, account data) is processed by TOKERO SocialFI, as a separate data controller, in accordance with TOKERO SocialFI's own privacy policy, available separately. This document does not govern the processing of that data.
Scope
This Policy applies to data processed in connection with the use of the Application, including joining the community, publishing and interacting with Content, communication between Members and the Mentor, and support requests submitted to the Mentor.
This Policy does not govern processing carried out independently by TOKERO SocialFI (in connection with the authentication account) or by other third parties, such as providers of related services, third-party platforms, social networks, or websites that may be linked from the Application.
To provide the Application, the Mentor collaborates with specialized third parties (including TOKERO SocialFI), who provide the technical infrastructure and data hosting, acting as processors (persons who process data on behalf of the Mentor), under a data processing agreement.
Categories of Personal Data Processed
Depending on the services used, the type of account, the level of verification, the transactions carried out and applicable compliance requirements, {CommunityName} may process the following categories of personal data:
- identification and contact data;
- account, authentication and security data;
- data relating to Membership of the community (date of joining, membership status, invitation used);
- technical data and platform usage data;
- content generated by the Member within the community (posts, messages, comments, poll responses);
- data contained in communications, support requests and complaints;
- data relating to marketing, campaigns, competitions, surveys and referral programmes;
- data required for tax compliance and reporting, where such obligations apply.
The Mentor does not intentionally collect special categories of personal data. If documents or information submitted by users incidentally contain such data, it will be processed only to the extent necessary for the purpose for which it was provided and subject to appropriate safeguards.
Purposes, Grounds for Processing and Retention Periods
| Purpose and categories of personal data | Grounds for processing | Retention period* |
|---|---|---|
Purpose: Creating and administering Membership of the community. Categories of data: name, email address, date of joining, membership status, invitation used. |
Performance of the Terms and Conditions accepted upon joining. |
For as long as Membership continues and thereafter for the period necessary to resolve any disputes or comply with applicable legal obligations. |
Purpose: Providing the Application's features (content, discussions, polls, communication within the community). Categories of data: content generated by the Member (posts, messages, comments, poll responses). |
Performance of the Terms and Conditions. Legitimate interest in ensuring the community functions properly. |
For as long as Membership continues; thereafter, to the extent necessary to resolve disputes or for legal compliance. |
Purpose: Support, complaints and correspondence with the Mentor. Categories of data: name, email address, content of the request, documents voluntarily provided, communication history. |
Performance of the Terms and Conditions. Legitimate interest in resolving requests and documenting interactions. |
For as long as necessary to resolve the request and thereafter for the applicable limitation period (generally up to 3 years, or another period required by law). |
Purpose: Security and proper technical functioning of the Application. Categories of data: minimal technical data (access logs, error information, device data), processed by the technical infrastructure provider, on behalf of the Mentor. |
Legitimate interest in maintaining the security and functioning of the Application. |
For as long as necessary for security, incident investigation, and the protection of legal rights. |
Purpose: Protecting and enforcing legal rights, conducting audits and internal controls, meeting reporting requirements and cooperating with authorities. Categories of data: information relevant to audits, litigation, investigations, complaints, transactions, communications and supporting documents. |
Legitimate interests. Legal obligations. Establishment, exercise or defence of legal claims. |
For as long as necessary for the relevant purpose and thereafter for any applicable statutory limitation, archiving, audit or reporting period. |
Purpose: Security, fraud prevention and protection of the platform. Categories of data: IP address, device data, sessions, logs, security events, risk indicators, transaction data, alerts and incident history. |
Legitimate interests in maintaining the security and integrity of {CommunityName} services. Legal obligations relating to security, reporting or cooperation with authorities, where applicable. |
For as long as necessary for security, audits, incident investigations and the protection of legal rights, in accordance with internal policies and applicable retention periods. |
Purpose: Operational communications regarding the community (notifications, changes to the Terms and Conditions, incidents). Categories of data: contact data, membership data. |
Performance of the contract. Legitimate interests in responding to requests and documenting interactions. Legal obligations, where applicable. |
For as long as necessary to resolve the request and thereafter for any applicable limitation, audit or legal claims period, generally three years or such other period as may be required by applicable law. |
Purpose: Operational communications concerning accounts, security, assessments, transactions, changes to terms or policies, and incidents. Categories of data: contact data, account data, transaction information and status updates, alerts and notifications. |
Performance of the Terms and Conditions. Legitimate interest in informing Members and ensuring continuity of the community. |
For as long as Membership continues. |
Purpose: Analysis, measurement, development and improvement of services. Categories of data: technical data, logs, aggregated or pseudonymised data, errors, statistics and interactions with platform features. |
Legitimate interest in developing, securing and optimising the platform. Consent for analytics or tracking technologies where required. |
For as long as necessary for analysis and service improvement, taking into account applicable retention rules and user preferences. |
Purpose: Marketing, news, campaigns, promotions and commercial communications. Categories of data: first name, last name, email address, telephone number, communication preferences, consent records, interactions with communications and campaign participation. |
Consent, where required, or legitimate interests in sending communications to existing users about similar services, to the extent permitted by applicable law. Users may unsubscribe from commercial communications or object to receiving them at any time. |
Until withdrawal of consent, unsubscription or objection, as applicable. |
Purpose: Events, webinars, surveys, competitions and promotions. Categories of data: first name, last name, email address, telephone number, account type, photographs and audio or video recordings, survey responses and participation information. |
Consent, performance of the applicable campaign or event terms and conditions, or legitimate interests in organisation and communication. Legal obligations, where applicable. |
For the duration of the activity and thereafter for as long as necessary to document participation, award prizes, comply with tax obligations or defend legal rights. |
*Retention periods may vary depending on the category of data, the type of service, applicable legal or contractual requirements, associated risks, the existence of requests, investigations or disputes, and the need to protect the rights of {CommunityName}, users or third parties.
Platform Use and Cookies
When you visit {CommunityName}, we may use cookies, pixels, local identifiers and similar technologies to collect technical information automatically, such as your IP address, browser type, operating system, device type, pages visited, session duration, how the platform is accessed and interactions with certain platform features.
Cookies are used to ensure the proper functioning of the platform, improve the browsing experience, enable certain features and remember user actions or preferences over time. Cookies other than those strictly necessary will be used only where the user has consented to their use.
Data Recipients
To provide, secure, and administer the Application, personal data may be disclosed to the following categories of recipients, strictly to the extent necessary for the purposes described in this Policy:
- the technical infrastructure provider (TOKERO SocialFI), which hosts and secures community data, acting as a processor on behalf of the Mentor;
- hosting, IT maintenance, and electronic communications (email) providers involved in the operation of the Application;
- consultants, lawyers, auditors, or other professionals subject to confidentiality obligations, where necessary;
- public authorities, courts, or law enforcement bodies, where disclosure is required by law or is based on a valid request.
Recipients are given access only to the data necessary for the relevant purpose. The Mentor seeks to ensure that partners involved maintain confidentiality, implement appropriate security measures, and process data solely for authorized purposes.
International Transfers
In carrying out the activities described above, certain personal data may be transferred to or accessed from outside Romania, including from other Member States of the European Union ("EU") or the European Economic Area ("EEA"), for example in the context of using IT infrastructure providers or data centers operated by service providers.
In all situations where data is transferred or processed within the EU or EEA, {CommunityName} ensures that these transfers comply with the applicable legal requirements established by Regulation (EU) 2016/679 (GDPR).
In certain cases, for the provision of specific services, personal data may be transferred to providers located outside the EU/EEA. Such situations may include the use of Zoom Video Communications video platforms for organizing online events or webinars, or email services provided by SendGrid (Twilio Inc.).
In these cases, the Application applies appropriate legal mechanisms to ensure an adequate level of protection of personal data, including standard contractual clauses adopted by the European Commission or, where applicable, binding corporate rules, in accordance with the provisions of the GDPR. {CommunityName} periodically reviews the framework applicable to these transfers and adopts additional measures, where necessary, to protect the rights and interests of data subjects.
Members' Rights
Depending on applicable law, Members may have the following rights regarding their personal data: the right of access, rectification, erasure, restriction of processing, data portability, the right to object, the right to withdraw consent, the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects them, and the right to lodge a complaint with the competent authority (in Romania, the National Supervisory Authority for Personal Data Processing - ANSPDCP).
These rights are not absolute. In certain circumstances, the Mentor may refuse or limit a request where data must be retained by law, or where retaining or using it is necessary to perform the Terms and Conditions, prevent fraud, ensure security, conduct investigations or audits, or establish, exercise, or defend legal claims.
To exercise rights regarding data processed in connection with the community, you may contact the Mentor at {MentorContactEmail}. For rights regarding TOKERO SocialFI account data, please contact [email protected].
To protect Members and their accounts, the Mentor may request additional information to verify the identity of the requester before responding to a request. Requests will be handled within the time limits required by applicable law.
Minors
{CommunityName} is intended exclusively for individuals who are at least 16 years of age, in accordance with the TOKERO SocialFI Terms and Conditions applicable to the creation and use of the SocialFI Account.
The Application does not intend and does not propose to deliberately collect or process personal data belonging to individuals who have not reached the age of 16. The creation of a SocialFI Account and the use of the Application's functionalities are conditional upon meeting this age requirement.
The Mentor does not knowingly collect or process personal data relating to individuals who do not meet the applicable age requirements. If the Mentor becomes aware that a Member does not meet these requirements, the Mentor may restrict, suspend, or exclude that Member from the community, subject to any applicable legal obligations to retain certain data.
Personal Data Security
The Mentor, together with the technical infrastructure provider, implements and periodically reviews reasonable technical and organizational measures designed to protect personal data against unauthorized access, misuse, disclosure, loss, alteration, or destruction.
These measures may include access controls, encryption of communications, secure password storage, monitoring, backups, and confidentiality obligations for authorized personnel.
Account security also depends on the precautions taken by the Member. We recommend using strong, unique passwords, keeping devices secure, and not sharing passwords or other authentication credentials with third parties.
The Mentor will never ask for your password or other sensitive information by email, telephone, or other unsecured channels.
Changes to This Privacy Policy
This Privacy Policy may be updated from time to time to reflect changes to the Application services, operational structure, applicable laws, compliance requirements, technologies or processing practices.
The version of this Privacy Policy published on the Application and in force at the time the services are used will apply.
Contact
For any questions regarding this Privacy Policy or data processed in connection with the community, you may contact the Mentor at {MentorContactEmail}.
For matters relating to the TOKERO SocialFI account, please use TOKERO SocialFI's own contact and support channels: [email protected], [email protected].