Politica de Confidentialitate Privacy Policy π
Cum colectam, procesam si protejam datele tale personale in conformitate cu GDPR How we collect, process, and protect your personal data in accordance with GDPR
Ultima actualizare: Ianuarie 2025 Last Updated: January 2025
π 1. Introducere 1. Introduction
Aceasta Politica de Confidentialitate explica modul in care Early Alpha Engineering Academy ("EAEA") colecteaza, proceseaza si protejeaza datele personale in legatura cu serviciile noastre de ateliere de robotica si electronica. This Privacy Policy explains how Early Alpha Engineering Academy ("EAEA") collects, processes, and protects personal data in connection with our robotics and electronics workshop services.
π’ 2. Operator de Date si Contact 2. Data Controller and Contact
Early Alpha Engineering Academy actioneaza ca Operator de Date pentru informatiile de cont si abonament. Pentru datele userilor de pe locurile cumparate de o institutie (scoala, afterschool), institutia este operatorul, iar EAEA este persoana imputernicita si prelucreaza datele doar dupa instructiunile ei β vezi capitolul 12 din Termenii Atelierului. Un acord de prelucrare a datelor (DPA) se semneaza la cerere. Early Alpha Engineering Academy acts as Data Controller for account and subscription information. For the data of the users on seats bought by an institution (school, afterschool), the institution is the controller and EAEA is the processor, handling the data only on the institution's instructions β see chapter 12 of the Workshop Terms. A data processing agreement (DPA) is signed on request.
Contact Contact : contact@eaea.ro Β· office@eaea.ro
Adresa Address : Bucuresti, Romania Bucharest, Romania
π 3. Categorii de Date Procesate 3. Categories of Data Processed
Mai jos e lista datelor pe care le tinem cu adevarat, grupate dupa cui apartin, fiecare cu scopul pentru care exista. Below is the list of the data we actually hold, grouped by whom it belongs to, each with the purpose for which it exists.
a) Date de cont (cumparator, profesor, coordonator) a) Account data (buyer, teacher, coordinator)
- Numele si adresa de email β crearea contului, autentificarea si mesajele despre licenta (confirmari, avertizarea de dinaintea stergerii). Name and email address β creating the account, logging in, and the messages about the licence (confirmations, the warning before deletion).
- Numarul de telefon, daca il completezi in formularul de contact sau in cererea de oferta β ca sa putem raspunde cererii tale. Phone number, if you fill it in on the contact form or the quote request β so that we can answer your request.
- Parola, pastrata doar sub forma de hash, si β daca alegi sa intri cu Google β identificatorul contului Google si adresa de email de acolo. Ambele servesc numai la autentificare. The password, stored only as a hash, and β if you choose to sign in with Google β the Google account identifier and the email address from it. Both serve only for authentication.
- Rolul in cont (cumparator, profesor, coordonator) si licentele, grupele si locurile de care raspunde β ca fiecare cont sa vada doar ce e al lui. The role in the account (buyer, teacher, coordinator) and the licences, groups and seats it is responsible for β so that each account sees only what belongs to it.
b) Date de facturare b) Billing data
- Forma legala (persoana fizica sau juridica) si, la firme si institutii, denumirea, CUI-ul, numarul de la registrul comertului, adresa sediului si reprezentantul legal β emiterea facturii si a contractului. Legal form (natural person or legal entity) and, for companies and institutions, the name, the tax code (CUI), the trade register number, the registered address and the legal representative β issuing the invoice and the contract.
- Facturile, dovezile de plata si istoricul abonamentului β obligatiile noastre fiscale si contabile. Invoices, proof of payment and the subscription history β our tax and accounting obligations.
- Dovada acceptarii termenilor: versiunea termenilor pe care ai bifat-o, momentul acceptarii si adresa IP de la care a venit β dovada ca a existat un contract si in ce forma. The record of terms acceptance: the version of the terms you ticked, the moment of acceptance and the IP address it came from β proof that a contract existed and in what form.
- Datele cardului nu ajung la noi. Plata se face pe pagina gazduita de Stripe, care le vede; noi primim doar confirmarea platii si datele de facturare. Card data never reaches us. Payment happens on Stripe's hosted page, which sees it; we only receive the payment confirmation and the billing details.
c) Date ale userilor minori de pe locuri c) Data of the underage users on the seats
- Prenumele sau pseudonimul de pe loc, numele afisat in atelier si username-ul β identificarea locului. Introdu doar ce e necesar; un prenume sau un pseudonim ajunge. The first name or nickname on the seat, the display name shown in the workshop and the username β identifying the seat. Enter only what is necessary; a first name or a nickname is enough.
- Codul PIN, pastrat doar sub forma de hash, si grupa din care face parte locul, impreuna cu profesorul care raspunde de grupa β intrarea in atelier si organizarea clasei. The PIN, stored only as a hash, and the group the seat belongs to, together with the teacher responsible for that group β entering the workshop and organising the class.
- Progresul la lectii, reparatii, ghiduri si proiecte (ce a terminat si cu cate stele) si circuitele salvate, inclusiv cele publicate in biblioteca β continuarea muncii de la o sedinta la alta si urmarirea ei de catre profesor. Progress through lessons, repairs, guides and projects (what was completed and with how many stars) and the saved circuits, including the ones published to the library β continuing the work from one session to the next and letting the teacher follow it.
- Aprecierile date si primite pe circuite, prieteniile dintre locuri (cu codul de prieten) si avatarul ales (piesa, culoarea, tinuta) β partea sociala si de personalizare a atelierului. The likes given and received on circuits, the friendships between seats (with the friend code) and the chosen avatar (part, colour, outfit) β the social and personalisation side of the workshop.
- Jurnalul de intrari: cate o inregistrare, cu data si ora, la fiecare intrare reusita pe loc β ca profesorul sa vada prezenta si ritmul de lucru, inclusiv zilele in care userul a venit fara sa salveze nimic. The login journal: one entry, with date and time, for every successful login on the seat β so that the teacher can see attendance and working rhythm, including the days on which the user came without saving anything.
d) Date tehnice d) Technical data
- Adresa IP si datele de sesiune β securitate, limitarea incercarilor de autentificare si prevenirea abuzului. IP address and session data β security, limiting login attempts and preventing abuse.
- Limba aleasa (ro sau en), pastrata intr-un cookie de preferinta β ca site-ul sa se deschida in limba ta. Detalii in capitolul 9. The chosen language (ro or en), kept in a preference cookie β so that the site opens in your language. Details in chapter 9.
- Emailurile pe care ti le trimitem si faptul ca au fost trimise β dovada ca avertizarea de dinaintea stergerii a plecat la timp. The emails we send you and the fact that they were sent β proof that the warning before deletion went out in time.
π― 4. Scopuri si Temeiuri Legale 4. Purposes and Legal Bases
| Scop Purpose | Temei Legal Legal Basis |
|---|---|
| Procesarea cererii de abonament Subscription request processing | Contract |
| Comunicare cu userii majori Communication with adult users | Contract |
| Gestionarea programarilor Scheduling management | Interes legitim Legitimate interest |
π€ 5. Partajarea si Transferul Datelor 5. Data Sharing and Transfers
Toate datele sunt stocate in Spatiul Economic European (SEE). Nu vindem datele personale catre terti. All data is stored within the European Economic Area (EEA). We do not sell personal data to third parties.
ποΈ 6. Pastrarea si Stergerea 6. Retention and Deletion
- Datele userilor de pe locuri (conturi, progres, circuite salvate) sunt pastrate pe durata licentei active si inca 6 luni dupa expirarea ei, ca licenta sa poata fi reactivata fara sa se piarda nimic. The data of the users on the seats (accounts, progress, saved circuits) is retained for the duration of the active licence and for a further 6 months after it expires, so that the licence can be reactivated without losing anything.
- Cu 30 de zile inainte de stergere trimitem un email de avertizare catre cumparator. La capatul celor 6 luni datele se sterg definitiv si nu mai pot fi recuperate. We send a warning email to the buyer 30 days before deletion. At the end of the 6 months the data is permanently deleted and cannot be recovered.
- La cerere, datele pot fi sterse si mai devreme. Cererea se trimite pe email. On request, the data can be deleted earlier. The request is sent by email.
- Documentele de facturare (facturi, dovezi de plata, dovada acceptarii termenilor) se pastreaza mai mult decat cele 6 luni, atat cat cer legile fiscale si contabile, indiferent de soarta licentei. Billing records (invoices, proof of payment, the record of terms acceptance) are kept longer than those 6 months, for as long as tax and accounting law requires, regardless of what happens to the licence.
π‘οΈ 7. Securitate 7. Security
Enumeram doar masurile pe care le avem cu adevarat astazi. We list only the measures we actually have in place today.
- Parolele conturilor si codurile PIN ale userilor de pe locuri nu sunt pastrate niciodata in clar: le pastram doar sub forma de hash (bcrypt, cost 12). Nu apar nici in jurnalele aplicatiei, iar un PIN uitat nu poate fi citit de nimeni, ci doar resetat. Account passwords and the PINs of the users on the seats are never stored in the clear: we keep only a hash (bcrypt, cost 12). They do not appear in the application logs either, and a forgotten PIN cannot be read by anyone, only reset.
- Datele cardului nu ajung pe serverele noastre. Plata se face pe pagina gazduita de Stripe; noi primim doar confirmarea platii si datele de facturare. Traficul catre site si catre platforma este criptat in transport (HTTPS). Card data never reaches our servers. Payment happens on Stripe's hosted page; we only receive the payment confirmation and the billing details. Traffic to the website and to the platform is encrypted in transit (HTTPS).
- Accesul la date este limitat la administratorul unic al EAEA si la persoanele pe care institutia client le autorizeaza ea insasi in contul propriu (profesori, coordonatori). Acestia din urma nu sunt personal EAEA: institutia decide cui ii da acces si cui i-l retrage. Access to the data is limited to EAEA's sole administrator and to the people the client institution itself authorises inside its own account (teachers, coordinators). The latter are not EAEA staff: the institution decides who is given access and who has it withdrawn.
- Separarea conturilor este verificata la fiecare cerere: un cont vede doar propriile licente, grupe si locuri, niciodata pe ale altui client. Autentificarea si introducerea PIN-ului au un numar limitat de incercari, ca sa nu poata fi ghicite. Account separation is enforced on every request: an account sees only its own licences, groups and seats, never those of another client. Login and PIN entry allow only a limited number of attempts, so that they cannot be guessed.
- Tinem un jurnal de acces: de fiecare data cand cineva din partea noastra sau a institutiei deschide fisa unui user, ii reseteaza PIN-ul, ii sterge contul sau exporta o lista, ramane o inregistrare cu cine, ce si cand. Jurnalul se pastreaza 12 luni si serveste la doua lucruri: sa putem raspunde daca ne intrebi cine ti-a vazut datele, si sa putem afla intinderea unei probleme daca apare una. We keep an access log: every time someone on our side or on the institution's side opens a user's record, resets their PIN, deletes their account or exports a list, a record of who, what and when remains. The log is kept for 12 months and serves two purposes: answering you if you ask who has seen your data, and establishing the extent of a problem if one arises.
- Incercarile esuate de autentificare si de introducere a PIN-ului se scriu separat si se pastreaza 90 de zile, ca o campanie de ghicire a parolelor sa nu treaca neobservata. Parola sau PIN-ul incercat nu se scriu niciodata. Failed login and PIN attempts are recorded separately and kept for 90 days, so that a password-guessing campaign does not go unnoticed. The attempted password or PIN is never recorded.
Spunem la fel de clar si ce nu avem, ca sa nu te bazezi pe ce nu exista: datele nu sunt criptate la nivel de coloana in baza de date (numele si progresul userilor sunt lizibile pentru cine ajunge la baza), iar jurnalele de mai sus se citesc, nu declanseaza singure o alerta la fiecare fapta. Nu detinem certificari ISO sau SOC si nu facem teste de penetrare. EAEA nu are angajati; administratorul unic este si singura persoana din partea EAEA care poate ajunge la date. We are equally clear about what we do not have, so that you do not rely on something that does not exist: the data is not encrypted at column level in the database (users' names and progress are readable to anyone who reaches the database), and the logs above are read rather than raising an automatic alert on every event. We hold no ISO or SOC certification and we do not run penetration tests. EAEA has no employees; the sole administrator is also the only person on EAEA's side who can reach the data.
β 8. Drepturile Persoanelor Vizate 8. Data Subject Rights
Aveti dreptul de acces, rectificare sau stergere a datelor personale. Cererile se trimit la contact@eaea.ro. You have the right to access, rectify, or delete your personal data. Requests are sent to contact@eaea.ro.
πͺ 9. Cookie-uri 9. Cookies
Folosim cookie-uri esentiale β autentificare, sesiune si protectie CSRF β si un singur cookie de preferinta, numit lang, care retine limba aleasa (ro sau en) si traieste un an. Cookie-ul de limba se scrie doar in clipa in care alegi limba din antetul paginii; daca nu alegi, nu-l punem deloc, iar pagina se deschide dupa limba pe care o cere browserul tau.
We use essential cookies β authentication, session and CSRF protection β and a single preference cookie, named lang, which remembers the chosen language (ro or en) and lives for one year. The language cookie is written only at the moment you pick a language from the page header; if you never pick one we do not set it at all, and the page opens in the language your browser asks for.
Nu folosim cookie-uri de analiza a traficului si nici de publicitate: pe site nu exista Google Analytics sau vreun instrument asemanator. In timpul platii, Stripe poate seta cookie-uri proprii pe pagina lui, pentru securizarea tranzactiei. Detaliile sunt in Politica de Cookie-uri. We use no analytics cookies and no advertising cookies: there is no Google Analytics or any similar tool on the site. During payment, Stripe may set its own cookies on its own page, to secure the transaction. The details are in the Cookie Policy.
π 10. Reclamatii 10. Complaints
Reclamatiile pot fi depuse la ANSPDCP (Autoritatea Nationala de Supraveghere a Prelucrarii Datelor cu Caracter Personal) sau la autoritatea locala de supraveghere. Complaints can be lodged with the ANSPDCP (Romanian data-protection authority) or the local supervisory authority.
π 11. Actualizari 11. Updates
Aceasta politica poate fi actualizata periodic, cu notificare prin email sau pe site. This policy may be updated periodically, with notice provided via email or on the website.
Intrebari despre Confidentialitate? Questions About Privacy?
Suntem dedicati protejarii datelor tale. Contacteaza-ne daca ai intrebari despre practicile noastre de confidentialitate. We are committed to protecting your data. Contact us if you have any questions about our privacy practices.
π§ contact@eaea.ro