Skip to content

Privacy Policy

Last updated: February 2026

1. Data controller

COAB Bucharest ("the controller") processes the personal data of visitors and members through this website. For any data-protection questions, please reach us through the contact form on this site.

2. What data we collect

We collect the data you voluntarily provide through the site's forms:

• Contact form: name, company, job title, email, phone (optional), subject, message

• Membership interest form: name, job title, company, email, phone (optional), LinkedIn, company website, industry, markets, motivation, contribution, referral (optional)

• Event registration: name, email, company, job title

• Member account: email, password (stored hashed), name

We do not collect or store bank card data. We do not sell or rent your data.

3. Purpose and lawful basis

Contact and membership forms: your data is processed on the basis of your consent (Art. 6(1)(a) GDPR) to respond to your enquiry and assess community fit.

Event registrations: your data is processed for performance of the participation contract (Art. 6(1)(b) GDPR).

Member accounts: your data is processed for administration of your membership (Art. 6(1)(b) GDPR).

4. Who has access

Data is stored on a Hetzner server in Germany (EU). Access is restricted to COAB Bucharest administrators. Transactional emails (password reset, registration confirmation) are sent via Brevo (France, EU) as a data processor. We do not transfer data outside the European Economic Area.

5. How long we keep it

Contact messages: 12 months from last correspondence.

Membership enquiries: 12 months from completion of the review process.

Event registrations: 12 months from the event date.

Member accounts: for the duration of active membership. Deactivated accounts are deleted on request.

6. Your rights

Under the GDPR you have the right to:

• Access your data (Art. 15)

• Rectify inaccurate data (Art. 16)

• Erasure — "right to be forgotten" (Art. 17)

• Restrict processing (Art. 18)

• Data portability (Art. 20)

• Object to processing (Art. 21)

Exercise these rights via the contact form or by email. We respond within 30 days.

7. Cookies and analytics

The site uses one strictly necessary cookie (payload-token) for member and administrator authentication sessions. This cookie does not track activity across other sites. See the Cookie Policy for details. We do not use marketing or tracking cookies.

8. Security

Data is transmitted exclusively over HTTPS. Passwords are stored hashed (bcrypt). Database access is restricted to the server's internal network. We take daily encrypted backups.