Privacy policy
Services in Romania and in the Republic of Moldova are provided by different legal entities. The document below applies to the operator selected here.
Operator for the selected country: ITERRA KIDS TECH S.R.L., CUI 55363550.
This Policy explains which personal data we collect on iterrakidsacademy.eu, why we process it, who we share it with, how long we keep it and how you can manage your data. The Policy is drawn up in accordance with Regulation (EU) 2016/679 (GDPR) and Romanian data protection law.
Contents
- The data controller
- What data we collect
- Purposes and legal bases
- Children's data
- Who we share data with
- International transfers
- Retention periods
- Cookies and tracking technologies
- Your rights
- How to make a request
- Automated decisions
- Data security
- Complaint to the supervisory authority
- Changes to the Policy
1. The data controller
The controller that determines the purposes and means of processing your personal data is:
Name: ITERRA KIDS TECH S.R.L.
Legal form: Societate cu răspundere limitată (S.R.L.)
Registration number: ONRC J2026048080004
CUI: 55363550
Administrator: Roman Luca
Registered office: Str. Matei Basarab nr. 4A, bl. 2, sc. A, et. 1, ap. 9, Voluntari, jud. Ilfov, România
E-mail: iterraacademy@gmail.com
Phone: +40 747 772 377
Website: iterrakidsacademy.eu
Personal data contact: iterraacademy@gmail.com
We have not appointed a data protection officer (DPO): our activity does not involve regular and systematic monitoring of individuals on a large scale, nor large-scale processing of special categories of data. The internal owner of privacy processes is the head of the academy, and enquiries are received at iterraacademy@gmail.com.
2. What data we collect
We collect only the data that is genuinely needed for a specific purpose.
2.1. Data from site forms
- Free IT mission request: parent's name, phone or WhatsApp, child's name, child's age, city, preferred language and format of study, interest in Certiport preparation, preferred start date, how you heard about us, and a comment.
- Contact form: name, phone and the text of the enquiry.
- Mentor consultation request: name and phone.
- Partnership request: name, phone and organisation name.
- Personal data request: request type, name, email and a description of the request.
2.2. Technical data
- IP address and information about your browser, device and operating system.
- Identifiers of the cookies needed for the site to work.
- The pseudonymous identifier of your cookie consent and the categories you chose.
- Server logs of requests to the site.
2.3. Consent records
For every form submitted and every choice made in the cookie banner we store the date and time, the version of the documents in force at that moment and the options you selected. These records are needed to demonstrate that processing is lawful and are used for that purpose only.
We do not ask for or collect through the site the parent's date of birth, personal numeric code (CNP), passport details, health data, payment cards or any other excessive information. If such data is required to conclude a contract, it is collected separately and outside the site.
3. Purposes and legal bases
Every processing operation has its own legal basis.
| Purpose of processing | Data | Legal basis |
|---|---|---|
| Handling the trial lesson request, choosing a group and contacting you | Data from the request form | Steps prior to entering into a contract, at your request — Art. 6(1)(b) GDPR |
| Replying to enquiries through the contact form or a mentor consultation | Name, phone, text of the enquiry | Our legitimate interest in answering enquiries — Art. 6(1)(f) GDPR |
| Reviewing partnership requests | Name, phone, organisation | Steps prior to entering into a contract — Art. 6(1)(b) GDPR |
| Providing educational services and running the courses | Parent and child data stated in the contract | Performance of the contract — Art. 6(1)(b) GDPR |
| Accounting and tax records | Payer details and payment documents | Legal obligation — Art. 6(1)(c) GDPR |
| Marketing and informational messages | Name, phone, email | Your separate consent — Art. 6(1)(a) GDPR |
| Running the site, protection against spam and abuse | IP address, browser data, server logs | Our legitimate interest in site security — Art. 6(1)(f) GDPR |
| Optional cookies and external services | Cookie identifiers | Your prior consent — Art. 6(1)(a) GDPR |
| Keeping proof of consent | Date, time, document version, selected options, IP address | Legal obligation to demonstrate GDPR compliance — Art. 6(1)(c), Art. 7(1) GDPR |
| Handling personal data requests | Request type, name, email, description | Legal obligation — Art. 6(1)(c) GDPR |
Handling your request is not based on consent: without your contact details we simply cannot reach you or pick a suitable group. We ask for consent separately, and only for marketing messages and optional cookies. Declining marketing has no effect whatsoever on your ability to book a class.
4. Children's data
iTerra Kids Academy teaches children, so we process minors' data. We do so under the following rules:
- Requests on the site are submitted only by a parent or other legal guardian of the child. Data about the child is provided by them, not by the child.
- About the child we ask for the minimum: name and age. Age is needed to choose a programme at the right level of difficulty.
- We do not show advertising to children, do not build advertising profiles of children and do not use their data for profiling.
- We do not ask a child to provide data about parents, friends or other children.
- Photographs and work by students are published only with separate written consent from the legal guardian, which can be withdrawn at any time.
If you believe a child has given us their data on their own and without your knowledge, write to iterraacademy@gmail.com — we will delete that data.
5. Who we share data with
We do not sell your data and do not pass it to third parties for their own advertising purposes. Access is limited to the categories of recipients without whom the service is not possible:
- the hosting provider and cloud infrastructure where the site and the database are hosted;
- the site developer and technical support service — to the extent needed for maintenance;
- the email provider through which we answer enquiries;
- the accounting service — for contractual and payment documents;
- Google Ireland Limited — the spreadsheet where form requests are recorded, and the measurement and advertising tools, which load only after your consent;
- public authorities — only where disclosure is expressly required by law.
With providers that process data on our behalf we conclude data processing agreements (DPA) under Art. 28 GDPR. The current list of specific providers can be requested at iterraacademy@gmail.com.
6. International transfers
We aim to store and process data on servers located in the European Economic Area.
If a particular provider is outside the EEA, the transfer only takes place where a Chapter V GDPR mechanism is in place: an adequacy decision of the European Commission, Standard Contractual Clauses, or another permitted mechanism, supplemented where necessary with encryption and access restrictions. A copy of the applicable safeguards can be requested at iterraacademy@gmail.com.
7. Retention periods
We do not keep data indefinitely. Once the period expires, data is deleted or anonymised.
| Category of data | Retention period |
|---|---|
| A request that did not lead to a contract | 12 months from the last contact |
| Enquiries through the contact form and consultations | 12 months from the date of reply |
| Partnership requests | 24 months from the last contact |
| Contract documents and student data | The duration of the course plus 3 years after it ends — the general limitation period |
| Accounting and tax documents | 10 years under Romanian accounting law |
| Consent to marketing messages | Until consent is withdrawn, with a review every 24 months |
| Proof of withdrawn consent and records of marketing opt-outs | 3 years — so that you are not added back to a mailing |
| Cookie consent log | 24 months from the date of the record |
| Personal data requests and our replies | 3 years from the date of reply |
| Server security logs | 6 months |
| Backups | Up to 30 days, in line with the backup rotation cycle |
Deleting data from active systems does not always mean immediate deletion from backups: deleted records disappear from backups during the scheduled rotation and are not used before that.
8. Cookies and tracking technologies
The site uses cookies. Strictly necessary cookies are set without consent because the site does not work without them. All other categories are enabled only after your explicit consent and are off by default.
The full list of cookies used, their purpose and lifetime is described in the Cookie policy. You can change or withdraw your choice at any time.
9. Your rights
In relation to your personal data you have the right:
- to be informed about how we process your data;
- to obtain access to your data and a copy of it;
- to rectify inaccurate data or complete incomplete data;
- to have data erased when there is no longer a legal basis for keeping it;
- to restrict processing while we verify your objection or the accuracy of the data;
- to object to processing based on our legitimate interest;
- to receive your data in a structured, machine-readable format and transfer it to another controller;
- to withdraw consent given earlier at any time, which does not affect the lawfulness of processing before the withdrawal;
- to opt out of direct marketing at any time, without giving reasons;
- not to be subject to a decision based solely on automated processing;
- to lodge a complaint with the supervisory authority and to go to court.
An erasure request does not always mean that every record is deleted. We are obliged to keep certain data for accounting and tax records or for the defence of legal claims. In our reply we always explain what has been deleted, what has been restricted and on what basis some information remains.
10. How to make a request
Send your request through the personal data request form or by email to iterraacademy@gmail.com.
We reply within one month of receiving the request. If the request is complex or there are several requests, the period may be extended by up to two further months — in that case we will tell you about the extension and its reasons within the first month.
So that we do not disclose data to the wrong person, we may ask clarifying questions to confirm your identity. We ask for the minimum of information and do not require copies of documents where we can manage without them. Handling a request is free of charge.
11. Automated decisions
We do not take decisions based solely on automated processing that would produce legal effects concerning you or similarly significantly affect you. We do not use scoring, automated customer assessment or advertising profiling.
The course selection quiz on the site shows a recommendation based on the child's age and interests directly in the browser. It is a suggestion, not a decision: the final choice of programme is made by the parent together with the academy's course adviser.
12. Data security
We apply technical and organisational measures proportionate to the risks and to the nature of the data processed:
- data transmission over the secure HTTPS protocol;
- service cookies with the Secure, HttpOnly and SameSite attributes;
- protection of forms against cross-site request forgery and rate limiting on submissions;
- server-side validation of all data received from forms;
- individual staff accounts and separation of access rights;
- access to data only for staff who need it for their work;
- encryption and separate storage of backups;
- regular updates of the server, framework and libraries.
If an incident occurs that creates a high risk to your rights, we will notify the supervisory authority without undue delay and, where feasible, within 72 hours, and we will inform you as well.
13. Complaint to the supervisory authority
If you believe we are infringing your rights, write to us first — we will try to resolve the matter directly. You also have the right to lodge a complaint with the supervisory authority competent for the operator named above.
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Registered office: B-dul G-ral. Gheorghe Magheru 28-30, sector 1, București, România
Website: www.dataprotection.ro
14. Changes to the Policy
We update the Policy when our processes, services or legal requirements change. Every version has a number and an effective date, shown at the top of the page. We announce substantial changes on the site and, where processing is based on consent, we ask for consent again.
Questions about this Policy should be sent to iterraacademy@gmail.com.
Book the first