Last updated: 7 September 2026
This policy explains how the Romanian Association of Sanitation and Waste Management processes the personal data of people who contact us, of the representatives of our member organisations, and of visitors to this website.
1. Who we are
The data controller is the Romanian Association of Sanitation and Waste Management — A.R.S.M.D.
- Registered office: 22–24 Calea Șerban Vodă, Building D2, ground floor, District 4, 040211 Bucharest, Romania
- Tax identification number: 14035360
- Registration number: 143/PJ/2001
- E-mail: office@arsmd.ro
- Telephone: +40 (0)21 316.27.69
For any question about your data, and to exercise the rights provided by Regulation (EU) 2016/679, you can write to us at office@arsmd.ro.
2. Scope of this policy
This policy applies to data processed through the www.arsmd.ro website, through correspondence addressed to the association, and in the administration of our relationship with member organisations. It does not apply to third-party websites we link to; those have their own policies.
3. What we process, for what purposes and on what legal basis
3.1. Messages sent through the contact form
We collect your name, e-mail address and message. All three are needed for us to receive and handle your enquiry; without them the message cannot be sent.
- Purpose: receiving, recording and handling your enquiry.
- Legal basis: Article 6(1)(f) of Regulation (EU) 2016/679 — the association’s legitimate interest in responding to those who contact it.
- Where your enquiry concerns membership, a collaboration or other steps you have requested yourself, processing may also rely on Article 6(1)(b), to the extent applicable.
- Where the law requires us to retain or disclose information, the basis is Article 6(1)(c).
3.2. Direct correspondence by e-mail
Messages sent to the institutional address office@arsmd.ro are processed for the same purpose — receiving and handling your enquiry — on the same legal bases as above. The association’s e-mail service runs on Google Workspace.
3.3. Membership applications
Joining the association is done through correspondence and documents, not through automatic online enrolment. We process the contact details of the people who submit or support the application, in order to assess it and to build the membership file. Legal basis: Article 6(1)(b) and (c), and the association’s legitimate interest in administering its membership under Article 6(1)(f).
3.4. Administering the relationship with member organisations
The members of the association are organisations. To conduct the associative relationship we process the professional contact details of the representatives and contact persons they designate — typically name, position, work e-mail address and work telephone number.
The legal basis is the legitimate interest of the association and of the member organisation in maintaining functional institutional communication, under Article 6(1)(f), together with the legal obligations incumbent on the association, under Article 6(1)(c). Membership belongs to the organisation; we do not assume that the designated individual is personally a party to the associative relationship.
3.5. Accounts and member-only sections
The website has sections and materials reserved for members. Access to them is through an account, with a username and password. We process the authentication data and the technical data needed to maintain the session and the security of the account.
Legal basis: Article 6(1)(b) — performance of the associative relationship with the member organisation — and Article 6(1)(f) — the legitimate interest in protecting access to reserved content. Public self-registration is not active; accounts are created within the relationship with the member organisation.
3.6. Technical operation, access control and security
The servers hosting the website record standard technical data — IP address, browser type, the time and type of the request, and any errors. This data is used to operate the website, to control access to protected areas, and to prevent and investigate security incidents.
Legal basis: Article 6(1)(f) — the legitimate interest in keeping the website functional, available and secure.
3.7. Association publications
To the extent that dispatching the magazine or other publications involves delivery data, that data is processed strictly to prepare and hand over the dispatch. Legal basis: Article 6(1)(b) and (f).
3.8. Events
There is currently no active event registration form on the website. When an event registration form is activated, participants will receive a specific privacy notice covering the data collected, the purposes, the legal bases and the retention period.
3.9. Communications
The association sends its members and partners institutional communications related to its activity — convocations, professional updates, association materials. These arise from the associative relationship and from the association’s legitimate interest in informing its members, and are distinct from marketing communications addressed to the general public.
The data you send us through the contact form is not used for marketing.
We do not carry out profiling and we do not take automated decisions producing legal effects concerning you.
4. Where the data comes from
The data we process comes:
- directly from you, when you write to us or complete the contact form;
- from the member organisation, when it designates representatives or contact persons;
- automatically, through the technical operation of the website, through authentication and through security logs.
5. Who else has access to the data
We do not sell data and we do not pass it on for commercial purposes. To operate, the association uses providers that may process data on its behalf or may have technical access to it:
- ROMARG — website hosting and the associated infrastructure;
- Google Workspace — the association’s e-mail service and collaboration tools;
- ManageWP / GoDaddy — remote technical administration of the website;
- technical providers of the WordPress platform, to the extent that they actually have access to data;
- printing and dispatch providers, to the extent that dispatching publications involves delivery data;
- consultants and public authorities, where there is a legal basis or a legal obligation.
We disclose data to public authorities only where the law requires it or where it is necessary for establishing, exercising or defending a legal claim.
6. Transfers outside the European Economic Area
Some providers used by ARSMD may also process data outside the European Economic Area. In such cases, the mechanisms and safeguards provided by data protection legislation apply, depending on the provider and the service used.
The fonts displayed on this website are loaded from Google’s servers. When pages load, your browser transmits your IP address and technical information about your browser to Google.
7. How long we keep data
- Messages received through the contact form or by e-mail: no longer than 24 months from the resolution of the enquiry or from the last relevant correspondence.
- Data of representatives of member organisations: for the duration of membership, and thereafter for as long as required by statutory, tax, accounting or archiving obligations, or by the defence of a legal claim.
- Accounts and technical access to reserved sections: deactivated when access is no longer justified.
- Technical and security logs: retained in line with security needs and the technical policies applicable to the infrastructure.
Data may be kept beyond these periods where this is necessary to comply with a legal obligation, to defend a legal claim, or to resolve a dispute.
8. Cookies and similar technologies
The website uses a small number of cookies, necessary for it to work:
pll_language— remembers the language you have chosen, Romanian or English;- cookies strictly necessary for the authentication and security of the member-only sections, set only when you sign in to an account.
We currently use no web analytics tools, no advertising or tracking cookies, and we do not carry out profiling for marketing purposes. Because these cookies are strictly necessary for the website to function, we do not ask for your consent to them.
If we introduce services or cookies that are not strictly necessary, we will reassess the situation beforehand and implement an appropriate consent mechanism.
Your browser allows you to block or delete cookies. Blocking them may mean the site no longer remembers your chosen language, or that signing in to the member area does not work.
9. Your rights
Subject to the conditions and limits laid down by Regulation (EU) 2016/679, you have the following rights:
- the right of access to your data;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure;
- the right to restriction of processing;
- the right to data portability;
- the right to object to processing based on legitimate interests;
- the right to withdraw your consent, where processing is based on consent, without affecting the lawfulness of processing carried out beforehand.
These rights are not absolute. Their exercise may be limited where the law provides otherwise, or where retaining the data is necessary to comply with a legal obligation or to establish, exercise or defend a legal claim.
10. How to exercise your rights
You can write to us at office@arsmd.ro, stating what you are asking for. We reply within one month of receiving the request. If the request is complex, or if we receive several requests, that period may be extended by two months; in that case we will inform you within the first month and explain why.
We may ask for additional information if we have reasonable doubts about the identity of the person making the request.
11. Right to lodge a complaint
If you consider that the processing of your data infringes data protection legislation, you may contact the Romanian National Supervisory Authority for Personal Data Processing:
- 28–30 B-dul General Gheorghe Magheru, District 1, postal code 010336, Bucharest, Romania
- Telephone: +40 318 059 211 / +40 318 059 212
- Web: www.dataprotection.ro
You may also bring the matter before the competent courts.
12. Data security
We apply technical and organisational measures to protect data: encrypted HTTPS connection, administrative access through individual accounts, separation of public areas from member-only areas, periodic backups and platform updates. No security measure can offer an absolute guarantee.
13. Changes to this policy
We may update this policy when the way we process data changes, or when the applicable legal framework changes. The version in force and the date of the last update appear at the top of the page. We will flag substantial changes on the website.