Privacy policy
How Asociația Haide Gabriele! processes the personal data of people who visit this website, write to us, apply as volunteers or make a donation.
Last updated: September 2026

1. Who the data controller is
The data controller is Asociația Haide Gabriele!, a non-governmental organisation governed by Romanian law.
Registered office: Satul Zăuan, Comuna Ip, Nr. 112, Jud. Sălaj, Romania
Nr. Reg. Național 1081/A/2024 · CIF 49990903
Email: info@haidegabriele.ro · Phone: +40 770 161 876
For any question about the protection of your data, you can write to info@haidegabriele.ro.
2. What data we process and why
We only process the data we need for the purposes described below. The website has no restricted areas, does not require registration and does not use analytics, profiling or advertising tools.
Browsing the website
The website is hosted on Cloudflare. When you visit it, Cloudflare automatically processes some technical data (IP address, date and time, page requested, browser type) to deliver the pages to you and to protect the website from attacks and abuse. We do not use this data for any other purpose, and Cloudflare keeps it for a limited time.
Contact form
If you write to us through the form, we process your name, email address, subject and message text, solely to reply to you. The message reaches us by email through the FormSubmit service.
Volunteer applications
If you apply, we process your name, email address, areas of interest, availability, start date and whatever you tell us about yourself, in order to assess your application and contact you. Please do not include health data or other sensitive information: if it is needed, we will talk about it in person.
Donations
For a bank transfer, we receive your name, IBAN, the amount and the payment reference from the bank. For ongoing support, card payments are handled by Stripe: we receive your name, email address and the amount, never your full card details. Donations through the Philanthropic Fund are handled by the Fondazione Dono per il Dono, which is an independent controller of the data and has its own privacy policy.
Email, phone and WhatsApp
If you contact us directly, we process the data you send us (name, contact details, content of the message) in order to reply to you. If you use WhatsApp, WhatsApp’s privacy policy also applies.
3. Legal bases and retention periods
| Purpose | Legal basis (GDPR) | How long |
|---|---|---|
| Operation and security of the website | Legitimate interest, Art. 6(1)(f) | For the limited technical periods set by Cloudflare |
| Replying to messages | Consent, Art. 6(1)(a), which can be withdrawn at any time | Up to 12 months after the last exchange |
| Assessment of volunteer applications | Consent and pre-contractual measures, Art. 6(1)(a) and (b) | Up to 24 months; if you become a volunteer, for the duration of the volunteering contract and for the periods required by law |
| Recording donations | Legal obligation, Art. 6(1)(c) | For the period required by Romanian accounting law (Legea nr. 82/1991) |
4. Who receives the data
The data is processed by the authorised members of the association and is never sold. It may be received, only to the extent necessary, by:
- Cloudflare, Inc., which hosts and protects the website, as data processor: Cloudflare’s privacy policy;
- the provider of our email mailbox, as data processor;
- FormSubmit, which forwards the messages sent through the forms to our email address;
- Stripe Payments Europe Ltd. (Ireland), for card payments: Stripe’s privacy policy;
- the Fondazione Dono per il Dono, for donations to the Philanthropic Fund: perildono.it;
- our bank and accounting advisers, for legal obligations;
- public authorities, only when required by law.
5. Transfers outside the European Union
Some providers are based in the United States or may process data outside the European Economic Area: Cloudflare, FormSubmit and, only if you choose to load their content, Google and Microsoft. In these cases the transfer takes place only with the safeguards provided for by the GDPR, such as an adequacy decision of the European Commission or standard contractual clauses.
6. Cookies and external content
The website does not use its own cookies, nor analytics or advertising cookies, which is why you will not find a cookie banner. Fonts and icons are hosted together with the website, without connections to Google Fonts or other services. Cloudflare may set technical cookies that are strictly necessary for security, for example to recognise automated traffic (bots).
If you choose a language from the language selector, your browser remembers it in local storage (localStorage, entry hg-lingua). This is technical information that stays on your device and is not sent to us. The short notice you see on your first visit is only there to tell you that there are no tracking cookies here: when you close it, your browser remembers this in local storage (localStorage, entry avviso-privacy), which stays on your device and is not sent to us.
The Google Maps map and the Microsoft Forms forms load only if you click the corresponding button: from that moment Google or Microsoft receive your IP address and may use cookies in accordance with their privacy policies. The Ongoing support and Philanthropic Fund pages include the payment services of Stripe and of the Fondazione Dono per il Dono, which are necessary in order to donate.
7. Minors
If you are under 16, you may write to us or apply only with the consent of a parent or guardian. For volunteering by minors, we always ask for the written agreement of the parents.
8. Your rights
Under the GDPR (Articles 15–22) you have the right to:
- know whether we process your data and receive a copy of it;
- have it corrected or updated;
- request its erasure;
- request the restriction of its processing;
- object to processing based on legitimate interest;
- receive the data you have provided to us in a readable format (portability);
- withdraw your consent at any time, without affecting processing already carried out.
To exercise them, simply write to info@haidegabriele.ro. We reply within one month. If we are not sure of your identity, we may ask you to confirm it.
9. Complaints
If you believe that we are processing your data incorrectly, you can lodge a complaint with the Romanian supervisory authority, the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), or with the authority of the country where you live, for example the Garante per la protezione dei dati personali in Italy.
10. Security
The website uses an encrypted connection (HTTPS). Access to the data is limited to the people in the association who need it to carry out their tasks.
11. Changes to this policy
We may update this policy, for example if we add new services to the website. The date of the last update is shown at the top of the page.
Any questions? Contact us.