INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA ISSUED BY THE CONTROLLER EVENTRIUM SRL, IN ACCORDANCE WITH ARTICLE 13 OF EU REGULATION NO. 679/2016 AND THE COMPANY’S OWN POLICIES ON PERSONAL DATA PROCESSING

Eventrium SRL, acting as Personal Data Controller, processes personal data in good faith, by automated and manual means, in compliance with the legal provisions in the field of personal data protection and for the purposes specified in this Information Notice, pursuant to the provisions of Regulation (EU) No. 679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

The personal data processed include: full name, home address, ID / passport series, number and issuing authority, phone number, email address, image, signature, or any other personal data necessary to fulfil the purposes listed below.

PURPOSES of Processing

Personal data are processed for the following purposes:

• concluding and performing the contractual relationship with Eventrium SRL based on the request for services or products offered by Eventrium SRL;

• sending newsletters and/or other commercial communications, as well as promoting the company’s products/services through communication channels such as email, SMS, or telephone, where such consent has been provided;

• processing hotel registrations and bookings for events organized by Eventrium SRL in its capacity as PCO – Professional Congress Organizer;

• sending communications related to the event for which registration / accommodation / abstract submission was performed via email or telephone (registration confirmations, payment reminders, requests for supporting documents, requests for abstract clarifications, logistical details of participation, etc.);

• facilitating virtual interaction in the case of online events organized by Eventrium SRL (virtual meetings with other participants and/or partners and exhibitors through video access, teleconferences, text messaging between participants/partners, online sharing of contact details, participation in Q&A sessions, feedback questionnaires for sessions or events);

• providing collected data to third parties for: the evaluation of scientific abstracts, the development of the scientific program by a committee of specialists designated by the scientific organizer, creation of the abstract book, CME accreditation by authorized national and international institutions.

LEGAL GROUNDS for Processing

Personal data are processed on the following legal bases:

• based on freely given consent, under Article 6(1)(a) of Regulation (EU) No. 679/2016;

• for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract (e.g., provision of requested products/services, communication for contract performance), under Article 6(1)(b);

• for compliance with a legal obligation to which Eventrium SRL is subject (e.g., reporting to competent authorities, preparing and archiving financial-accounting documents such as invoices), under Article 6(1)(c);

• for the purposes of legitimate interests pursued by Eventrium SRL or third parties (e.g., improving Eventrium’s services, promoting its own services, recovering receivables arising from contractual relations, ensuring the security of individuals), provided that the interests or fundamental rights and freedoms of the data subject are not overridden, under Article 6(1)(f) of Regulation (EU) No. 679/2016.

Refusal to provide personal data or to allow the processing of personal data will prevent Eventrium SRL from properly fulfilling its obligations, which may result in the inability to provide the requested services.

Consent given for the collection and processing of personal data may be withdrawn at any time by submitting a written, dated, and signed request to contact@eventrium.ro or by postal mail to Cluj-Napoca, Str. Frunzișului, no. 50. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Data Retention Period

Personal data may be disclosed or transferred for the above purposes to the employees, collaborators, partners, and suppliers of Eventrium SRL or to affiliated companies, all of which are similarly bound by obligations of confidentiality.

Data Recipients, Controllers, and Processors

Personal data will be processed for the entire validity period of the consent provided for collecting and processing personal data, and until such consent is withdrawn by the data subject. In the event that consent is withdrawn, the personal data will no longer be processed for the purpose for which they were collected.

Personal data may also be disclosed to public authorities in accordance with their competencies and applicable legislation (e.g., tax authorities, labor authorities, the National Supervisory Authority for Personal Data Processing, criminal investigation bodies), for fulfilling obligations regarding fiscal, labor, or other applicable laws.

RIGHTS of Data Subjects (Articles 15–21 of Regulation (EU) No. 679/2016)

Each participant has the following rights with respect to their personal data:

• the right of access and the right to obtain a copy of their data;

• the right to rectification;

• the right to request the erasure of data;

• the right to restriction of processing;

• the right to data portability;

• the right to object to data processing;

• the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing.

Additionally, under Article 7(3) of Regulation (EU) No. 679/2016, each participant has the right to withdraw their consent at any time for receiving newsletters or marketing communications.

To exercise these rights or for any other request related to personal data, a written, dated, and signed request may be sent to the Data Protection Officer of Eventrium SRL at:

Cluj-Napoca, Str. Frunzișului, no. 50,

or by email at contact@eventrium.ro.

If a request is submitted for exercising personal data rights, Eventrium SRL will respond within 30 days, under the conditions provided by Regulation (EU) No. 679/2016.

If it is considered that the rights regarding personal data have been violated, a complaint may be submitted to the National Supervisory Authority for Personal Data Processing, headquartered in Bucharest, Sector 1, Bd. General Gheorghe Magheru no. 28-30.