1. Data Controller / 1. Operator de date
Heart Line Romania · office@heartlineromania.org
1207 Delaware Ave #1782, Wilmington, Delaware 19806, USA
2. Data Protection Officer (DPO) / 2. Responsabil cu protecția datelor (DPO)
Our DPO can be reached at / DPO-ul nostru poate fi contactat la office@heartlineromania.org (subject: 'DPO request'). / (subiect: „solicitare DPO”).
3. Legal Bases per Processing Purpose / 3. Temeiuri legale per scop de prelucrare
| Purpose · Scop | Legal basis · Temei | Special categories · Categorii speciale |
|---|---|---|
| Account creation & authentication | Art. 6(1)(b) – contract | — |
| Adoption-record search & reunification | Art. 6(1)(b) contract; Art. 6(1)(e) public-interest task (Romanian Law 273/2004) | Art. 9(2)(a) explicit consent; Art. 9(2)(g) substantial public interest |
| Communications with partner agencies & courts | Art. 6(1)(c) legal obligation; Art. 6(1)(b) contract | Art. 9(2)(f) legal claims |
| KYC / identity verification | Art. 6(1)(c) legal obligation; Art. 6(1)(f) legitimate interest in preventing fraud | — |
| Portal security, audit logging, abuse prevention | Art. 6(1)(f) legitimate interest | — |
| Donations & financial records | Art. 6(1)(c) legal obligation (tax/accounting) | — |
| Newsletter & service emails | Art. 6(1)(a) consent; Art. 6(1)(f) legitimate interest (service emails) | — |
4. Retention Schedule / 4. Termen de păstrare
| Data category · Categorie | Retention · Păstrare | Reason · Motiv |
|---|---|---|
| Case records (adoption, birth) | Life of case + 10 years | Romanian Law 273/2004 |
| KYC / ID documents | 5 years from verification | AML / fraud prevention |
| Audit logs & security events | 7 years | Security, legal claims |
| Account profile | Until account closure + 90 days | Account recovery |
| Email correspondence | 3 years after case closure | Service quality, legal claims |
| Financial records (donations) | 10 years | Tax / accounting (RO + US IRS) |
| Marketing email subscription | Until unsubscribe | Consent withdrawal at any time |
5. Categories of Recipients & Subprocessors / 5. Categorii de destinatari și subîmputerniciți
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase (database, auth, storage) | App data & user accounts | EU (Frankfurt) primary; US redundancy |
| Cloudflare | Hosting, CDN, DDoS, WAF, Turnstile CAPTCHA | Global edge; EU primary |
| Resend | Transactional email delivery | US (DPA + SCCs) |
| OPSWAT MetaDefender | Upload malware scanning | US |
| Zoom (when used) | Board meetings only — no case data | US/EU |
| Romanian government registries | Authorized record retrieval per your consent | Romania |
| Partner adoption agencies | Only those you authorize in writing | Romania, US, other |
All subprocessors are bound by Data Processing Agreements. EU→US transfers rely on Standard Contractual Clauses (Commission Decision 2021/914). / Toți subîmputerniciții sunt obligați prin acorduri de prelucrare. Transferurile UE→SUA folosesc Clauzele Contractuale Standard (Decizia 2021/914).
6. International Transfers (Chapter V) / 6. Transferuri internaționale (Capitolul V)
Transfers from the EEA to the United States are governed by Standard Contractual Clauses (Commission Decision 2021/914), supplemented with encryption-in-transit (TLS 1.3), encryption-at-rest (AES-256), and contractual restrictions on government access requests. / Transferurile din SEE către SUA sunt reglementate de Clauzele Contractuale Standard (Decizia 2021/914), completate cu criptare în tranzit (TLS 1.3), criptare în repaus (AES-256) și restricții contractuale privind cererile guvernamentale.
7. Security Measures (Art. 32) / 7. Măsuri de securitate (Art. 32)
- Pseudonymisation and encryption of personal data. / Pseudonimizare și criptare a datelor cu caracter personal.
- Row-level access control and least-privilege staff access. / Control la nivel de rând și acces minim pentru personal.
- MFA + WebAuthn passkeys for staff; HIBP-leaked-password protection on signup. / MFA + chei WebAuthn pentru personal; verificare parole compromise (HIBP) la înregistrare.
- Tamper-evident, append-only audit logging. / Jurnalizare de audit inalterabilă.
- Regular testing and evaluation of effectiveness. / Testare și evaluare periodică a eficacității.
8. Children's Data (Art. 8) / 8. Datele copiilor (Art. 8)
Many adoption case files necessarily relate to minors. Where the data subject is a child, we process such data only under Art. 6(1)(c)/(e) (legal obligation / public-interest task under Romanian Law 272/2004 on child protection and Law 273/2004 on adoption) combined with Art. 9(2)(g) (substantial public interest) and, where applicable, Art. 9(2)(a) (explicit consent of the holder of parental responsibility). The portal itself is intended for users aged 18 and over; account creation by minors is not permitted, and we do not knowingly collect personal data directly from children under 16 without verified parental consent. / Multe dosare de adopție privesc inevitabil minori. Atunci când persoana vizată este copil, prelucrăm datele exclusiv în temeiul Art. 6(1)(c)/(e) (obligație legală / sarcină de interes public conform Legilor 272/2004 și 273/2004) coroborat cu Art. 9(2)(g) (interes public substanțial) și, după caz, Art. 9(2)(a) (consimțământul titularului răspunderii părintești). Portalul este destinat utilizatorilor de peste 18 ani; minorii nu pot crea conturi, iar datele directe de la copii sub 16 ani nu sunt colectate fără consimțământ parental verificat.
9. Data Subject Rights (Art. 12–22) / 9. Drepturile persoanei vizate (Art. 12–22)
- Right of access (Art. 15). / Dreptul de acces (Art. 15).
- Right to rectification (Art. 16). / Dreptul la rectificare (Art. 16).
- Right to erasure / 'right to be forgotten' (Art. 17), subject to legal-retention exceptions. / Dreptul la ștergere / „dreptul de a fi uitat” (Art. 17), cu excepțiile legale de păstrare.
- Right to restriction (Art. 18). / Dreptul la restricționare (Art. 18).
- Right to data portability (Art. 20). / Dreptul la portabilitatea datelor (Art. 20).
- Right to object (Art. 21). / Dreptul la opoziție (Art. 21).
- Right not to be subject to automated decision-making (Art. 22) — we do not perform automated decision-making with legal effects. / Dreptul de a nu fi supus deciziilor automate (Art. 22) — nu folosim decizii automate cu efecte juridice.
- Right to withdraw consent at any time (Art. 7(3)). / Dreptul de retragere a consimțământului oricând (Art. 7(3)).
Submit any request to / Trimiteți orice cerere la office@heartlineromania.org. We respond within 30 days (extendable by 60 days for complex cases). / Răspundem în 30 de zile (prelungibil cu 60 pentru cazuri complexe).
10. Breach Notification (Art. 33–34) / 10. Notificarea încălcărilor (Art. 33–34)
Personal data breaches are notified to ANSPDCP within 72 hours and to affected data subjects without undue delay when the breach is likely to result in a high risk. / Încălcările sunt notificate la ANSPDCP în 72 de ore, iar persoanelor vizate fără întârziere nejustificată în caz de risc ridicat.
11. Supervisory Authority — Lodge a Complaint / 11. Autoritatea de supraveghere — Plângere
Romania (lead authority) / România (autoritate principală)
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București, 010336
Tel: +40.318.059.211 · Email: anspdcp@dataprotection.ro
https://www.dataprotection.ro/
You may also lodge a complaint with the supervisory authority of your EU member state of residence. / Puteți depune plângere și la autoritatea de supraveghere din statul UE de reședință.
12. Records of Processing (Art. 30) / 12. Evidența activităților de prelucrare (Art. 30)
We maintain Records of Processing Activities and a Data Protection Impact Assessment (DPIA) for case management and cross-border records retrieval. These are available to ANSPDCP on request. / Menținem Evidența activităților de prelucrare și o Evaluare de impact (DPIA) pentru gestionarea cazurilor și transferul transfrontalier de documente. Acestea sunt disponibile la cererea ANSPDCP.