Privacy Policy of The 4th edition of The International Medical Students’ Congress of Bucharest

Dated: 01.09.2020

Introduction

Please read this Privacy Policy carefully prior to accessing our Platform and create an account. If you have any questions, please contact us at: contact@imscbucharest.com.

Data protection is one of the major concerns for ASOCIAȚIA SOCIETATEA STUDENȚILOR ÎN MEDICINĂ DIN BUCUREȘTI.

This Privacy Policy (the „Policy”) details when and why we, ASOCIAȚIA SOCIETATEA STUDENȚILOR ÎN MEDICINĂ DIN BUCUREȘTI, having the headquarters in 8 Eroii Sanitari Bvd, District 5, Bucharest (hereinafter referred to as „the ASSMB” or „we”), as a controller, process your personal data, the conditions under which we can disclose your personal data to others, how safely do we store the personal data, which are your rights as an individual and how you can exercise these rights.

When processing your personal data, ASSMB is responsible for complying with European and national legislation on data protection, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC ( „GPDR” ).

Your access to our Platform and use of ASSMB Services is also governed by our Terms and Conditions. This Privacy Policy should be read together with our Terms and Conditions and our Cookie Policy.

1. Definitions

  • „Abstract” means the authentic scientific paper submitted and presented by an Active Participant;
  • „Active Participants” means the participants at the Congress which, apart from the usual mandatory scientific events (conferences, workshops), must also present an authentic scientific paper (abstract);
  • „Ambassador” means the participant to the Congress whose registered as an Ambassador and was given a referral code and who’s main role is to promote the IMSCB worldwide;
  • „Controller” means a natural or legal person, the public authority, agency or other institution which, alone or together with others shall determine the purposes and means of processing personal data;
  • „Data Processing” means any operation or set of operations carried out on personal data or personal data sets, with or without the using of automatic means, such as collecting, recording, organizing, structuring, storage, adaptation or modification, extraction, consultation, use, disclosure by transmission, distribution or otherwise making available, alignment or combination, restriction, deletion or destruction;
  • „Data subject” means an identified or identifiable natural person, directly or indirectly, in particular by reference to an identification item, such as name, identification number, location data, an online identifier, or to one or more specific items, physical identity, physiological, genetic, psychic, economic, cultural or social.
  • „Passive Participants” means the participants at the Congress, which must attend the conferences and workshops assigned to them based on their choice in order to receive the certificate of participation and they do not submit any Abstract.
  • „Personal data” means any information relating to an identified or identifiable natural person.
  • „Platinum Participants” means the Active Participant or the Passive Participant who will have access to all of the scientific events from International Medical Students’ Congress of Bucharest 2020 and bought the platinum package designed especially for this year’s edition.
  • „Presenting Author” means the Active Participant who submitted an Abstract.
  • „Scientific Committee” is the committee assigned to evaluate an Abstract.

For the extensive definition of terms specific to the field of data protection, please refer to EU Regulation 2016/679.

2. The categories of data we process

In the following description of our activities we refer to each category of personal data that we process. A category includes several types of personal data, which are usually processed together for the purposes mentioned in point 3 below.

We generally process the following categories of personal data for the following reasons:

Category of personal data

 

Type of personal data Reason
 

Profile Data (Account data)

 

Name and surname, country of origin, university, faculty, study year, e-mail address, pseudonymised information about the user password, User ID

 

This data is your master data, which we absolutely need for our services. Without an email address and a password, country of origin, faculty and study year you will not be able to create your account.

Ambassadors personal data First name, last name, university, faculty, city, country, year of study, email address, Facebook profile link, telephone number.

 

This data is essential for us in order to give every participant that wants to become an Ambassador the referral code that he/she will use when promoting the event.
 

Device information and access data

 

 

Device ID, device operating system and corresponding version, time of access, configuration settings, information on Internet connection (IP address)

 

Each time you access your account this information is stored by us for technical reasons. We also use parts of this information to detect suspicious behaviour at an early stage and to avert damage.

Delivery information First name and last name, delivery address, telephone number We need this information in order to deliver the Goodie Bag at your doorstep. This Goodie Bag is a part of the Platinum premium package, that you bought.
 

Communication data

 

Name, email address, device ID

 

If you contact us, we collect this data because we need to know who we are talking to and what we have been talking about so that we can help you with your reason for contacting us.

 

 

 

 

 

 

Payment information First name and last name, phone number, e-mail, transaction details To activate your account we must make sure that you have made the payment for the chosen access package. Also, in order to be able to issue the invoice with the correct paid amount, the payment processor will provide us with a report that will contain the aforementioned data.
Personal data regarding the Abstracts submitted Full name of each Author/ Co-authors of the Abstract submitted, name and surname of the scientific coordinators, position of the scientific coordinators, Author/ Co-authors affiliated institution, video recording that captures the image, voice and behaviour of the Presenting Author. We need this information in order to ensure your access/participation to the oral debates and studies presentation audition .

 

 

Personal data regarding the Certificate of participation

 

Ø  For every participant we will process the first name and the last name of the participant, country of origin, university, faculty, study year.

Ø  For the participants who submit and present an Abstract we will process the first name and last name of the presenting Author/ Co-authors, the affiliated institution, country of origin, university, faculty, study year, name and surname of the scientific coordinators, position of the scientific coordinators.

 

 

 

We need this information, in order to issue the Certificates that reflect your activity and attendance in the Congress.

3. The purposes for which we process the data

We process your personal data only in accordance with the legal requirements. We pay attention to the fact that all principles for the processing of personal data are taken into account.

In order to participate in the 4th edition of the International Medical Students’ Congress of Bucharest, you need to go through the process of registration which implies the creation of an account on our website. In order to create an account you have to share with us your personal data. Please, share with us only the necessary data that we need to fulfill our obligations.

The purposes for which we process your personal data are as follows:

Account creation

When creating a Participant account, you will be asked to enter your Profile Data. This action is essential and necessary as we cannot create a Participant Account without this data. Your email address is particularly important, as we can use this information to identify you in our system the next time you want to log in.

We kindly ask you to choose your password carefully. Please don’t share neither your password nor your email address with anyone else.

When you create a Participant account, we process the following categories of personal data:

  • Profile Data (Account data);
  • Device information and access data.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR:  „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Personalizing the Participant account

The next step following the validation of your account is to select your account type:

  1. Active Participant (Bronze, Silver, Gold, Platinum);
  2. Passive Participant (Bronze, Silver, Gold, Platinum).

After selecting the type of account, you will have to fill in your address and billing information in order to complete the payment process.

We mention that the payment process is carried out by NETOPIA Payments, an entity that is a controller, according to GDPR. Thus, in order to perform the payment, the processing of your personal data need is carried out according to NETOPIA Payments Privacy Policy.

After choosing the type of account you want and after the purchase of one of the packages, your registration process is complete and you can enjoy our amazing event.

When you personalize your account, we process the following categories of personal data:

  • Profile Data (Account data);
  • Device information and access data;
  • Payment information.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

 Platinum experience

If you are a Platinum Participant we will process a series of additional personal data in order to be able to offer you the platinum experience with all the surprises and gifts that we have prepared especially for this package. This processing is essential so we can deliver at your doorstep the gifts and products prepared especially for this year’s Congress. The gifts include IMSCB merchandise, souvenirs from Romania and special gifts from our Coordinators.

In order to deliver the gifts and products prepared especially for this (2020), we process the following categories of personal data:

  • Profile Data (Account data);
  • Delivery information.

For any other surprises included in the platinum premium package, we will process your Profile Data.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Ambassadors’ activity

If you want to promote the IMSCB world-wide, encourage students to participate at this Congress and get a discount you can register as an Ambassador.

In order to become an Ambassador, you must fill in the form when the Ambassadors registration begins, starting the 1st of September. After registration we will give you a referral code. When encouraging students from your university and friends to participate at the event you will communicate your referral code to students/doctors to use it for their registration as a Participant.

In order for us to be able to identify you as an Ambassador and give you a referral code, we will process the following categories of personal data:

  • Ambassadors personal data;

The legal basis for this processing purpose is art. 6 para. 1 (f) GDPR: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

Our legitimate interest is promoting the event so that as many medical professionals as possible attend the Congress.

Ambassador‘s discount

In order to promote our event, we select people who want to become an Ambassador and give them a discount on their participation package or a free participation.

The activity of an Ambassador will be taken into account only if participants register using his/her referral code. In order for a participant to be linked to his/her ambassador, he/she must submit the Ambassador’s referral code in the Registration Form. Depending on the number of participants who register using the Ambassador ‘s referral code, the Ambassador will receive a discount or a free participation in the 4th edition of the International Medical Students’ Congress of Bucharest, according to the Terms and Conditions, available here.

In order to grant the discount or the free participation to the Ambassador, we process the following categories of personal data:

  • Ambassador’s personal data;
  • Ambassador’s referral code;
  • Profile Data (for every participant that uses the Ambassador’s referral code).

The legal basis for this processing purpose is art. 6 para. 1 (f) GDPR: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

Booking the Events

After purchasing the selected package (Bronze, Silver, Gold or Platinum) a number of tokens will be available in your account to be used for booking the scientific events, depending on the type of package you have selected. The tokens will be available after the general period of registration.

In order to issue the tokens you are entitled to (according to the type of package you purchased) and to assign them to your account, we will process the following categories of personal data:

  • Profile Data (Account data);
  • Device information and access data;
  • Payment information;
  • Type of Account.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Also, when you book a scientific event we will process your Profile Data in order to make sure you attended the mandatory number of events according to your account type, as specified in the Terms and Conditions, available here.

Login

If you already have an existing Participant account, you will need to enter your email address and password to login. In case we detect irregularities during registration (for example entering a wrong password several times) we will take appropriate measures to prevent damage to you and us.

When you login, we process the following categories of personal data:

  • Profile Data (Account data);
  • Device information and access data.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Attending the Events

Whether you are a Passive participant, an Active participant or a Platinum Participant, when registering to your profile we monitor your behaviour on our platform. In order to issue the Participant Certificate, we have to make sure that you attend the events you’ve signed for.

We will process the following categories of personal data:

  • Profile Data (Account data);
  • Device information and access data.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

 

Submitting and presenting an Abstract

Apart from the usual mandatory scientific events, the Active Participants will also present an authentic scientific paper.

This implies that the Author will share his authentic scientific paper with:

  • other Active Participants;
  • other Passive Participants;
  • members of the Organisation Committee;
  • volunteers of the IMSCB Scientific Department
  • professors of the Scientific Committee in order to achieve the contest awards.

Every Active Participant will receive the link for the Zoom Meeting via the e-mail address used for the registration process.

In order to make possible that every Active Participant can present his paper as an oral presentation and that the other participants can attend, we process the following categories of personal data:

  • Profile Data (Account data);
  • Communication data;
  • Device information and access data;
  • Personal data regarding the Abstracts submitted (for the Active Participant presenting the Abstract).

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Managing your Participant Account

You can log in to your profile and change your personal data, such as name, email address, at any time.

In order to make changes to your profile when you login, we process the following categories of personal data:

  • Profile Data (Account Data);
  • Device information and access data;
  • Communication data;

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Communication of existential issues

In order to ensure a proper delivery of our services, sometimes we have to send you some information regarding the events date or the speakers, for example. In order to be able to communicate to you, this information we must process your personal data.

The categories of personal data processed for the purpose above mentioned are:

  • Communication data.

 The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

 

Issuance of participant certificates

To be granted the certificate of participation, as a participant you must attend the mandatory events included in the package you purchased. By not attending all the mandatory events, you will not be granted the certificate of participation.

In order for us to be able to issue the participant certificates, we must process the following categories of personal data:

  • Profile Data (Account data);
  • Personal data regarding the Certificate of participation.

The legal basis for this processing purpose is art. 6 para. 1 (b) GDPR: „ processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Advertising and marketing

Newsletter

If you have provided us with your email address when purchasing one of the packages (Bronze, Silver, Gold, Platinum), we provide you with newsletter regarding this Congress and we reserve the right to send you offers and other information regarding other Scientific Conferences or regarding the next International Medical Students’ Congress of Bucharest.

If automated decision making leads to a negative result for you and you do not agree with this, you can contact us at office@imscbucharest.com . In this case, we will individually assess the circumstances of your case.

When we send you a newsletter, we process the following categories of personal data:

  • Communication data;

The legal basis for this processing purpose is art. 6 para. 1 (f) GDPR: „Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

Data processing in this respect takes place solely on the basis of our legitimate interest in personalized direct advertising pursuant to Art. 6 Para. 1 (f) GDPR.

You are entitled to object to the use of your email address for the aforementioned advertising purposes at any time by sending an email with the subject „unsubscribe” to office@imscbucharest.com. Upon receiving of your objection, the use of your email address for advertising purposes will be discontinued immediately.

Social and Cultural Programme

Both Passive and Active Participants, as well as Platinum Participants have access to the Social and Cultural Program within the International Medical Students’ Congress of Bucharest.

Regarding this programme, we conduct a Participant survey and ask you to give us your opinion regarding the works of art included in the programme.

This survey will be conducted only with your prior consent. If you gave us your consent and do not wish to participate in this survey, you can withdraw your consent at any time, by sending an email to office@imscbucharest.com.

In order to conduct this survey, we process the following categories of personal data:

  • Communication data

The legal basis for this processing purpose is art. 6 para. 1 (a) GDPR: „The data subject has given consent to the processing of his or her personal data for one or more specific purposes.”

 

Cookies

In order to make the visit of our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your device. Some of the cookies we use are deleted after the end of the browser session, i.e. after closing your browser (so-called session cookies). Other cookies remain on your device and allow us or our affiliate to recognize your browser on your next visit (persistent cookies). You can set your browser so that you are informed about the setting of cookies and individually decide on their acceptance or exclude the acceptance of cookies for specific cases or in general. Failure to accept cookies may limit the functionality of our website.

The legal grounds for processing your personal data through cookies differ depending on the type of cookies used. In some cases, the processing takes place with your consent, so that the basis on which the processing takes place is art art. 6 Para. 1 (a) GDPR. Otherwise, the processing is based on our legitimate interest pursuant to art. 6 para. 1 (f) GDPR.

For more information regarding how we process personal data through cookies, please read our Cookie Policy, available here.

4. The ways we protect the information

We respect your right to data protection by making all reasonable efforts and taking all technical and administrative measures, so that we can ensure the proper confidentiality of your personal data.

The confidentiality and the protection of the data collected from you are a priority for us. ASSMB does not disclose the information collected, to third parties without your express and prior consent (except the cases indicated in point 6-The persons who access the information collected from you). Any traffic statistics on our users that we will provide to third-party advertising networks or to partner sites is only provided as a set of data and does not include any personally identifiable information about any individual user.

Unfortunately, no data transmission via the Internet can be guaranteed to be 100% secure. Therefore, despite our efforts to protect your personal information, ASSMB cannot ensure the security of the information you provide us with, to and from our online services or our products.

When we receive the information you send, we assure you that we will make every effort to ensure its security in our systems, according to the security standards imposed by the applicable legislation.

In this respect we have implemented adequate technical and organizational measures to preserve the confidentiality and security of your personal data. Regarding cyber security, data-processing operations, including data storage, shall be achieved by means of systems which ensure the security of processing, and the operations shall be carried out by competent persons who have been informed and instructed on the obligations regarding data protection.

5. Fraud prevention and security of our platform

In order to protect the participants and other users of our platform from possible attacks, we continuously monitor the activities on our website for all visitors. To this end, we use various technical measures to ensure that suspicious behavior patterns are detected at an early stage and prevented in good time. To achieve this goal, several monitoring mechanisms run in parallel and prevent potential attackers from accessing our website at all.

The decision-making process is automated and can have a legal effect on the person concerned or affect them in a similar way. If automated decision-making leads to a negative result for you and you do not agree with this, you can contact us at office@imscbucharest.com . In this case, we will individually assess the circumstances of your case.

In order to ensure the security of our platform we process the following categories of personal data:

  • Profile Data (Account data);
  • Device information and access data;
  • Communication data;
  • Billing information;
  • Payment information.

The legal basis for this processing is represented by the art. 6 para. 1 (f) GDPR: „Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

6. The persons who can access the information collected from you

Your personal data is processed for the purposes indicated in point 3-The purposes for which we process the data. This processing is carried out by ASSMB. Therefore, other natural or legal persons (except those indicated above and exceptional circumstances indicated below), will not have access to your personal data.

ASSMB is making every effort and has taken the necessary measures to ensure that third parties do not have access to your data, unless we are in the presence of an exceptional situation. Thus, there are situations in which, the access to your data is required by legal provisions or the carrying out of the company’s activity, or the proper working/maintenance of the website.

Therefore, in certain circumstances, we may disclose your personal data to:

  • persons who, under a contract, provide the maintenance of the website;
  • external advisors (e.g. auditors);
  • public authorities or institutions;
  • other natural or legal persons who contribute to/ensure the proper conduct of this Congress.

7. Prosecuting authorities and legal proceedings

Unfortunately, it can happen that a few of our partners or/and service providers do not behave fairly and want to harm us. In these cases, we are not only obliged to hand over personal data due to legal obligations but it is also our interest to prevent damage, to enforce our claims and to reject the unjustified ones.

8. Data transfer outside the EU or the EEA

ASSMB does not reveal and submit personal data collected from you to third countries outside the European Union or the European Economic Area.

Regarding the storing of the personal data, we mention that the server on which the personal data processed by us is stored is located in Belgium.

9. Retention period of the information collected

Your personal data will be processed as follows:

  • for the entire duration of the Congress, and for a period of one year after the ending of this Congress;
  • for the entire period stipulated in the provisions of the Romanian laws applicable to ASSMB.

If your personal data is longer required for the purpose of compliance with legal provisions or our legitimate interest, the data shall be deleted.

10. Data subject rights

In accordance with the provisions of the EU Regulation 2016/679 (GDPR), you have the following rights as the data subject:

  1. The right of access according to this right you can obtain from us a confirmation regarding the processing of personal data, as well as access to that data. For any other copy you require, we have the right to charge a reasonable fee, based on administrative costs. If you send the request in electronic format and unless you request another format, the information will be provided in an electronic format that is used currently;
  2. The right to rectification – according to this right you may obtain correction of your personal data, which is inaccurate, as well as the right to obtain completion of personal data which is incomplete;
  3. The right to erasure (‘right to be forgotten’) – You have the right to obtain the erasure of personal data that concerns you, without undue delay, and we are obliged to delete that data, when:
    1. personal data is no longer necessary for the purposes for which it was collected or processed;
    2. you withdraw your consent, when the processing is based on your previous consent and there are no other legal grounds for the processing;
    3. you object to data processing, and there are no other legal grounds for the processing;
    4. the processing was performed against legal provisions;
    5. personal data must be erased for complying with a legal provision, that we have to respect, according to European Union legislation.
  4. Restriction of processing – according to this right, you can restrict the processing of your personal data;
  5. The right to data portability – according to this right you can receive your personal data, in the form send to us, in a structured format, currently used and which can be read automatically and send this data to another controller under certain conditions;
  6. The right to object – according to this right you can object, on grounds relating to your situation, at any time, to the processing of personal data, including profiling;
  7. Automated individual decision-making, including profiling – you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you;
  8. The right to complain, according to article 77 from GDPR Regulation, to the appropriate supervisory authority at any time.
    1. The supervisory authority responsible for us is:
      • The National Supervisory Authority For Personal Data Processing
      • Address: 28-20 G-ral. Gheorghe Magheru Boulevard, District 1, Bucharest, Romania
      • Postcode City: 010336
      • Email Address: anspdcp@dataprotection.ro
      • To exercise your rights, you can contact contact@imscbucharest.com at any time.
  9. The right to withdraw the consent in any moment, without affecting the legality of data processing, made by us based on your consent before the consent was withdrawn.

If you wish to exercise any of the above rights, please contact us in one of the ways we will describe below, in point 11-How can you exercise your rights.

ASSMB works to ensure a faster response to your requests, but the reply term varies depending on the complexity of your request. The deadline for processing applications shall be 30 days.

11. How can you exercise your rights?

For your data processing requests please contact us in one of the following ways:

12. About our Cookie policy

You can find our Cookie Policy with all the cookies we use below.

13. Right of modification

We reserve the right to change this data protection declaration in compliance with the statutory provisions. We will inform you of any significant changes, such as changes of purpose or new purposes of processing.