GENERAL PRIVACY NOTICE
WHO WE ARE
UPGRADE EDUCATION S.R.L. , headquartered in Bucharest, Sector 2, Dimitrie Pompeiu Boulevard, No. 10A, Conect Building 1, Floor 1, Office 10, registered with the Trade Register under no. J40/6278/2017, Unique Registration Code RO37497210 (hereinafter referred to as “Upgrade Education” or “the Company ”), processes personal data in accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 (the Regulation) and other applicable legal provisions regarding personal data processing. This General Privacy Notice describes why and how we process personal data and provides information regarding your rights when the Company acts as a Data Controller.
HOW CAN YOU CONTACT US?
You can contact us by:
- Sending an email to: contact@neoversity.ai OR
- Sending a letter to our registered office address: Bucharest, Sector 2, Dimitrie Pompeiu Blvd., No. 10A, Floor 1, Office10.
PERSONAL DATA OR CATEGORIES OF PERSONAL DATA PROCESSED BY THE COMPANY
Our policy is to collect personal data necessary for the purposes determined by the Company ’s activities, and we ask our clients and partners to provide the personal data required for these purposes. Due to the diversity of the services and/or products we offer, we may process several categories of personal data, which may vary depending on the type of product/service/activity or purpose of processing.
The main data/categories of data processed by the Company may include, as appropriate and depending on the associated processing purposes, data such as:
- In situations where you wish to benefit from the Company ’s services and associated or related activities, we may process, as necessary, data such as: (i) first and last name, (ii) contact information such as address, email address(es), telephone number, (iii) age/date of birth, (iv) information regarding completed studies, specifically regarding target universities, preferences related to the types of services and products offered by the Company, (v) possibly the position/function within the client company (if the potential client/client is a legal entity), (vi) information in the context of consultancy provided, (vii) details from the ID card, (viii) signature. If you access our platform to benefit from the Company’s services, such as mentorship for students applying to foreign universities, we may also process, in addition to the above, data such as photo images, video/audio recordings, and/or transcripts, as applicable, from the sessions.
- In cases where you wish to participate in a demo: (i) first and last name, (ii) contact information such as home address, email address(es), phone number, (iii) age/date of birth, (iv) education-related data, diplomas, experience, etc., (v) information about target universities, desired projects, (vi) signature, (vii) demo execution details (period, conditions, etc.), and possibly impressions/feedback.
- In the context of the Company managing legal relationships with you through certain electronic systems/applications such as PandaDoc, in addition to the personal data contained in documents circulated through PandaDoc (data/categories of data you can find listed above depending on the applicable situation), we may process data reported by the system/application provider, such as document status with timestamp, name and surname, email address, IP address.
- Regarding the payment for goods and services, such as accessed services/purchased goods, billing address; bank account number or card number/IBAN code, as applicable; the name and surname of the bank account holder or cardholder (may differ from you if someone else has paid an invoice on yourbehalf).
- In connection with the organization of events, contests, sweepstakes, similar actions, the main data/categories of data processed by the Company may include, as appropriate and depending on the purposes of processing, data such as: (i) first and last name, (ii) contact information such as email address(es), phone number, (iii) processing of photo and/or video images and audio recorded during events organized by the Company, possibly including partial or full publication if consent has been obtained from you in this regard, (iv) age/date of birth, (v) home address, signature for declared winners, and possibly personal identification number for tax purposes, if applicable, (vi) other identification data (from ID/passport, as applicable, for prize winners), (vii) possibly information regarding position and/or employer for both participants in the action and family members, as appropriate, given the conditions of participation established by the action ’s regulations. If you participate in one of our loyalty programs, we may process data such as name, surname, home address, mobile phone, email, age, relationship history with us, and the number of accumulated points or similar, benefits granted within the loyalty programs, data required by law for filing any tax statements related to the loyalty programs, signature.
- Testimonials and Feedback Feedback on the types of services and products offered by the Company, including potential data received/collected through social media platforms such as social network usernames, satisfaction levels related to the services and products offered by the Company, or expressions of likes, dislikes, comments, opinions, etc.
- Data Related to IT&C Security Measures The Company takes specific IT&C security measures to protect personal data within its systems, such as IP addresses and access logs in our IT&C systems.
- When You Visit Our Website When you visit our website and/or our pages on various platforms, we may process certain information about your browser and operating system, including the date and time of the visit, access status (for example, whether you could access a web page or if you received an error message), use of web page functionalities, search terms you may have entered, frequency of access to individual web pages, file names accessed, the volume of data transmitted, the web page from which you accessed our web pages, and the page you visited from our web pages. If you clicked on links on our web pages or entered a domain directly into the input field of the same tab (or the same window) of the browser in which you opened our web pages, we may also collect other data obtained from visiting our online pages and platforms (such as the online identifier of people accessing one or more of the Company ’s websites or pages, potential data received/collected through social media platforms). This data is processed for the purposes mentioned in the cookie policy for that specific page/website or for security purposes, specifically for the prevention and detection of attacks on our web pages or fraud attempts.
- If You Are a Representative of One of Our Business Partners, Clients, or Suppliers The main data/categories of data processed by the Company in connection with your request may include data such as: name, surname, contact information (email address(es), phone numbers, etc.), and your position within the employer’s company.
- When You Complete an Online/Offline Form or Contact Us by Call Center or Email The main data/categories of data processed by the Company in connection with your request may include: (i) name, surname, (ii) contact information such as email address(es), phone number, (iii) age/date of birth, (iv) your preferences indicated in the relevant form (such as request for an offer, opt-in for newsletter, consent for commercial communications, etc.), (v) potentially a signature (in the case of offline forms).
WHAT TYPES OF DATA PROCESSING DOES OUR COMPANY CARRY OUT?
- Our Company processes personal data for the purposes outlined in this Privacy Notice, and each purpose may involve one or more data processing operations, as applicable, such as collecting, recording, organizing, structuring, storing, adapting or modifying, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing, or destroying.
- The Company may create and analyze profiles using the personal data collected, such as your evaluation of our products and services, segmenting potential clients/customers based on various criteria such as age, gender, nationality, etc., which may be used to send you personalized communications and offer information we believe may be of interest to you about us and/or our partners.
PURPOSES FOR WHICH PERSONAL DATA IS PROCESSED
The Company processes personal data for multiple purposes, and the collection methods, legal basis for processing, use, disclosure, retention periods, etc., may vary depending on each purpose.
We may use personal data for one or more of the purposes described in this Privacy Notice. If the Company subsequently processes personal data for a purpose other than those about which you have been informed and which is incompatible with the purposes for which the data was originally collected or made known to you, the Company will provide information regarding the secondary purpose and any other relevant information.
We process your personal data primarily for the following purposes:
- Conducting and managing pre-contractual correspondence necessary for establishing legal relationships between you and our Company as a result of a request received for this purpose (unrelated to any subsequent commercial communications carried out for marketing purposes), in order to conclude the legal relationship/contract.
- Providing goods and services to our potential and existing clients in relation to the Company ’s business activity.
- Fulfilling contractual obligations and commitments to you.
- Managing relationships with our potential clients and clients, improving services for them, identifying their needs, improving the Company ’s activity and services in relation to our clients and partners, conducting surveys, identifying potential issues with our existing services to improve them (including through audits); testing improvements made to our services or our new services; and resolving your complaints.
- Managing risks associated with our business activities, including detecting, investigating, and resolving security threats, where personal data may be processed within the applications we use and/or by conducting background checks on individuals in relation to the provision of goods/services.
- Commercial Communications: We provide our existing and potential clients, who have given their consent, with information about us and/or other legal entities, including in connection with services and/or products that are similar to those purchased by our clients or for which they have expressed interest in purchasing. In accordance with applicable law, we use client contact information to directly or indirectly provide information we consider of interest to clients/potential clients, for marketing and advertising activities, for post-sale contact for testimonials and feedback, etc.
- Event Organization and Management For organizing and managing events for which you have registered, enabling your participation in these events. Subsequently, if you have provided consent, we may use your data to send further commercial communications and to promote the Company ’s activities by posting event images (photos, videos) or your statements/testimonialsonline.
- Website Visits When you visit our website and pages, we may process certain information for the purposes mentioned in the Cookie Policy displayed on the relevant site/page and/or to prevent and detect attacks on our webpages or fraud attempts. Managing Damages Handling damages resulting from situations such as breaches of terms and conditions or violations of rules applicable to specific situations.
- Compliance with Legal/Regulatory Requirements Compliance with legal and regulatory requirements, such as tax or archiving requirements.
- Legal Proceedings Establishing, exercising, or defending a legal right in court. In this context, data is also processed for resolving potential disputes.
- Financial-Administrative Management Issuing receipts, invoices, and payment records; receiving payments from you, including recording payments made by another person on your behalf; debt collection; refunding amounts to you; sending notifications; filing tax declarations related to loyalty programs; preparing activity reports.
- Internal Statistics Internal data analysis.
- M&A Transactions In the future, the Company may grant access to its databases without explicitly disclosing your data within the context of potential mergers and/or share acquisitions by third parties, but only after signing confidentiality agreements with those parties.
LEGAL GROUNDS AND CONDITIONS FOR DATA PROCESSING
The legal grounds for data processing are based on the provisions of the GDPR and laws concerning personal data processing adopted in Romania, the applicable legislation in the Company’s field of activity, particularly laws governing service marketing, consumer protection, Civil Code, Tax Code, and related fiscal legislation. Processing is based on at least one of the following legal conditions:
- Processing may be necessary to establish or perform a legal relationship/contract with you.
- Processing may be necessary to fulfill a legal obligation of the Company (e.g., obligations related to managing fiscal documents, the obligation to secure premises and people in Company-owned facilities, etc.).
- Processing is necessary for the legitimate interests pursued by the Company or a third party, specifically:
- ○ Administering our business and improving our services, including but not limited to our relationship with mentors. ○ Managing risks associated with our activities.
- ○ Managing relationships with potential clients and clients, including but not limited to processing for direct marketingpurposes.
- Establishing, exercising, or defending a legal right in court handling complaints and issues related to our services/products to address any reported matters.
- Processing may rely on your consent only if we fall under one of the specific cases expressly provided for by the GDPR.
HOW LONG DO WE RETAIN PERSONAL DATA?
We retain processed personal data only as long as it is necessary for the purpose for which it was collected (including in accordance with applicable law or regulations), as follows:
- For the duration of the legal relationship/contract for personal data necessary for its execution, including any personal data the Company may encounter during the legal relationship.
- For the period stipulated by law when there are applicable legal norms (e.g., mandatory accounting records and supporting documents used in financial accounting).
- Until you exercise your right to object (opt-out) to receiving commercial communications containing information and offers about our services/products and those of our partners.
- For the duration of cookie validity and/or other online data collection and analysis tools or the existence of the relevant site/page, whichever ends first, for online identifiers of our clients and other data collected through cookies and similar tools on the Company ’s websites/pages, including on social networks.
- Until consent is withdrawn for data processing based solely on consent.
- For the archiving period specified by law or in the applicable policies of the Company, where applicable, for data contained in documents that law or the Company has designated for archiving.
YOUR RIGHTS AND HOW TO EXERCISE THEM
Our company is responsible for facilitating the exercise of any of your rights mentioned below. For the protection of your data and to prevent malicious individuals from accessing your data, our company may require you to follow preliminary identification steps to ensure that you are the person exercising the rights mentioned below through a request. If we receive a request from you regarding the exercise of any of the above rights, we may ask for additional information to verify your identity before acting on the request. If
the data subject submits an electronic request to exercise their rights, the information will also be provided electronically by our company, where possible, unless the data subject requests a different format.
Right of Access: You have the right to access and obtain confirmation from the Company as to whether it processes personal data concerning you and, if so, to obtain the information provided in the Regulation regarding the processing of your data. If personal data is transferred to a third country or an international organization, you have the right to be informed of the appropriate safeguards under Article 46 of the Regulation regarding the transfer. Upon your request, the Company provides a copy of the personal data undergoing processing.
Right to Rectification: You have the right to obtain from the Company the rectification of inaccurate personal data concerning you and to have incomplete data completed, including by providing an additional statement. When possible or necessary, we will make corrections (as applicable) based on updated information and inform you about it, if applicable.
Right to Erasure: You have the right to obtain from the Company the erasure of personal data concerning you, except in certain cases provided for by the Regulation, if one of the following grounds applies: a) the data is no longer necessary for the purposes for which it was collected or processed; b) you withdraw your consent on which the processing is based, to the extent that the processing is based solely on consent and there is no other legal ground for processing; c) you object to processing carried out for public interest or legitimate interests pursued by the Company or a third party, and there are no overriding legitimate grounds for processing or you object to processing for direct marketing purposes; d) the data has been unlawfully processed; e) the data must be erased for compliance with a legal obligation to which the Company is subject under Union or national law; f) other situations provided for by the Regulation, as applicable.
Right to Restriction of Processing: You have the right to obtain the restriction of processing in the following cases: a) You contest the accuracy of the data, for a period that allows the Company to verify the accuracy of the data; b) The processing is unlawful, and you oppose the erasure of the personal data, requesting instead the restriction of its use; c) The Company no longer needs the personal data for processing purposes, but you request it for the establishment, exercise, or defense of legal claims; or d) You have objected to processing pursuant to Article 21(1) of the Regulation, for the period necessary to verify whether the legitimate grounds of the controller override those of the data subject.
Right to Data Portability: You have the right to receive your personal data that you have provided to the Company in a structured, commonly used, and machine-readable format and to transmit those data to another controller without hindrance from the Company, where: (i) the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the Regulation or on a contract pursuant to Article 6(1)(b) of the Regulation, and (ii) the processing is carried out by automated means. When exercising the right to data portability, the personal data can be transmitted directly from the Company to another controller designated by you, where technically feasible.
Right to Object to Processing for Legitimate Interests: You have the right to object, at any time, to processing carried out for public interest or legitimate interests pursued by the Company or a third party, including profiling. In such cases, the Company will no longer process your personal data for this purpose, unless it demonstrates compelling legitimate grounds for the processing that override your interests, rights, and freedoms or for the establishment, exercise, or defense of legalclaims.
Right to Object to Processing for Direct Marketing: When processing is for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, including profiling related to direct marketing.
Right to Withdraw Consent: If the processing is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. The withdrawal scenario is not applicable where the basis for processing is not consent.
Please also consider the following as a data subject:
- If you wish to exercise any of the rights mentioned above, you can do so by sending a written request assumed by you and addressed via the methods indicated in section II of this privacy notice. We will try to respond to your request within 30 days. However, this period may be extended depending on various aspects, such as the complexity of the request, the large number of requests received, or the inability to identify you within a reasonable timeframe.
- If we are unable to identify you when submitting a request, despite our efforts, and you do not provide additional information to help identify you, we may not be able to fulfill the request.
- If, due to legal provisions, our company cannot fully or partially fulfill a request from the data subject, the applicable exceptions will be communicated to the applicant through our response regarding the request in question.
RIGHT TO FILE A COMPLAINT OR REPORT
If you wish to report issues related to the use of your personal data, you can do so by sending a written complaint assumed by you and addressed via the methods indicated in section II of this privacy notice. We will review and respond to any complaint we receive.
You also have the right to file a complaint with the National Supervisory Authority for Personal DataProcessing(“ANSPDCP”).
SOURCE OF PERSONAL DATA AND, IF APPLICABLE, WHETHER THEY COME FROM PUBLIC SOURCES
In general, we collect personal data directly from you. We may receive personal data or have access to it from our corporate clients (e.g., regarding data belonging to their representatives), third parties, or public sources (such as the ONRC portal, social media sites prospecting), etc.
CONSEQUENCES OF REFUSING TO PROVIDE PERSONAL DATA
If personal data is collected directly from you, we inform you that, in general, you are not obligated to provide your personal information to the Company, except in cases where providing it constitutes a legal or contractual obligation or a requirement necessary for establishing a legal relationship/contract. Thus, if you opt for one or more of the Company ’s services, enter into a legal relationship with the Company, or benefit in another context from our services/products, providing personal data is necessary from the perspective of legal requirements and/or the legal relationship with us, as this information is required to fulfill the Company’s obligations towards you or to provide services and/or products to you. Therefore, in certain situations, depending on the data you refuse to provide, it may be that: our company is unable to conclude the contract or continue the contractual relationship with you, and/or our company is unable to fully or partially fulfill its obligations towards you.
RECIPIENTS OR CATEGORIES OF RECIPIENTS OF PERSONAL DATA:
The Company may grant access to/disclose personal data, mainly and only as necessary, to entities/persons such as:
- Public authorities and entities, regulatory and oversight bodies, courts/arbitration bodies/administrative organizations (e.g., tax authorities, other regulatory entities in the Company ’s field of activity, etc.);
- Service providers (professionals in various fields such as accountants, auditors, lawyers, other external consultants, debt collection service providers, specialized archiving services, etc.);
- The Company ’s data processors, such as mentors, IT&C service providers, event organizers, marketing service providers, and other agents processing personal data on behalf of the Company, following instructions from us and complying with this privacy notice, data protection laws, and confidentiality and security measures;
- Business partners related to the goods or services purchased or you intend to purchase;
- Third parties, investors, or regarding M&A transactions – in cases where we sell or transfer all or part of the Company ’s shares, assets, or business (including in the case of reorganization, dissolution, or liquidation) – they will be bound by a confidentiality obligation and tocomply with all provisionsof this privacynotice.
- Third parties concerning photo images, testimonials, and similar content that may be posted on the Company ’s website, IT systems, or its web pages available on the Internet, including on social media platforms, provided you have agreed to this; Data collected via cookies or other similar online tools may be transmitted to third parties according to the Cookie Policy if you have accepted third-party cookies (belonging to other entities than our company – e.g., cookies used by Google).
Transfers and disclosures are generally not made to entities outside the European Union. If the Company transfers your personal data to a third country or international organization, we will ensure they are adequately protected, meaning we will transfer data to a country ensuring an adequate level of protection as assessed by the European Commission. If that country does not have laws equivalent to EU data protection standards, we will require the third party to enter into a legally binding agreement/instrument that reflects these standards or provide other appropriate safeguards accordingly.
If you find the information contained herein to be ambiguous or unclear, you can request clarifications from us at any time using the contact details mentioned in section II of this notice.
With this Notice, you acknowledge the information provided by the Company under the Regulation and have been informed by the Company regarding the rights conferred by the Regulation and Romanian law concerning the protection of individuals about the processing of personal data and the free movement of such data.