Privacy Policy

Last updated: September 2026

1. About this Privacy Policy

This Privacy Policy explains how personal data is collected, used, stored and protected when you visit scosym2027.org, register for ScoSym 2027, submit scientific content, subscribe to our communications, or otherwise interact with us in connection with the symposium.

We process personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and other applicable Romanian and European data protection legislation.

2. Who We Are

The data controller responsible for the processing of personal data through this website and in connection with ScoSym 2027 is:

Asociația Terapie pentru Mișcare
CIF: 35597239
Registered address: 21–23 Bulevardul Mărășești, District 4, Bucharest, Romania
Website: scosym2027.org
Privacy contact: hello@scosym2027.org

In this Privacy Policy, “ScoSym”, “ScoSym 2027”, “we”, “us” and “our” refer to Asociația Terapie pentru Mișcare in its capacity as organiser and data controller, as applicable.

We have not appointed a Data Protection Officer. Questions or requests regarding the processing of your personal data may be sent to hello@scosym2027.org.

3. Personal Data We May Collect

Depending on how you interact with us, we may process the following categories of personal data:

3.1. Event registration data

When you register for ScoSym 2027, we may collect:

first and last name;

email address;

telephone number;

country and location information;

professional title, profession or specialty;

institution, organisation or employer;

professional or academic affiliation;

registration category;

information concerning workshops, sessions or other activities for which you register;

information relating to your participation in the event;

correspondence relating to your registration.

3.2. Billing and transaction data

When payment or invoicing is required, we may collect information necessary for processing your registration and issuing the relevant financial documents, including:

name and surname;

billing address;

company or organisation name;

fiscal identification information;

company registration details, where applicable;

billing email address;

other information reasonably required for issuing an invoice in accordance with applicable legislation;

information regarding the transaction, such as amount, currency, payment status, transaction reference and date.

We request only the billing information necessary for processing the transaction, issuing financial documents and complying with applicable accounting and tax obligations.

Online card payments are processed through NETOPIA Payments. We do not normally receive or store your complete payment card details. Payment information necessary to authorise and process the transaction is handled by the payment service provider in accordance with its own legal and security obligations.

Invoices and related financial documents may be generated and managed using SmartBill.

3.3. Scientific programme and abstract submissions

If you submit an abstract, scientific paper, poster or other contribution to ScoSym 2027, we may process information including:

name and surname;

email address;

professional and academic affiliation;

institution;

professional or academic title;

ORCID or other researcher identifiers, where provided;

biography or professional profile, where required;

names and affiliations of co-authors;

abstract title and content;

information necessary for scientific review, correspondence and programme preparation.

Where you provide personal data relating to co-authors or collaborators, you should ensure that they have been appropriately informed about the submission and the processing of their information.

Selected abstracts or scientific contributions may subsequently be included in the scientific programme, symposium materials, website, abstract book, proceedings or a scientific publication.

Where publication is planned, relevant authors will be informed about the applicable publication arrangements before publication.

3.4. Newsletter data

If you voluntarily subscribe to the ScoSym newsletter or other promotional communications, we may process:

your name, where provided;

your email address;

subscription and consent information;

information relating to the delivery and management of our communications.

Newsletter subscriptions are managed separately from event registration.

Registering for ScoSym 2027 does not automatically subscribe you to marketing communications.

3.5. Communications with us

If you contact us by email, telephone, WhatsApp or another communication channel made available on the website, we may process your contact details and any information you voluntarily provide as part of your request.

Please avoid sending sensitive personal information unless it is necessary for us to address your request.

3.6. Website and technical data

When you access our website, certain technical information may be processed automatically, including:

IP address;

browser and device information;

operating system;

date and time of access;

pages or resources requested;

technical logs and security information;

cookie identifiers and similar technologies, where applicable.

For more information regarding cookies and similar technologies, please consult our separate Cookie Policy.

4. Why We Process Your Personal Data

We may process personal data for the following purposes:

Event registration and administration – to process registrations, manage participant records, confirm participation, manage workshops and symposium activities, issue tickets or confirmations and provide information necessary for participation.

Payment and invoicing – to process registration fees, verify payments, issue invoices and other financial documents, maintain accounting records and comply with fiscal obligations.

Event communications – to send registered participants organisational information concerning ScoSym 2027, including registration confirmations, programme information, schedule changes, venue information, workshop details, access instructions, online participation information and other information necessary for attending the event.

These communications form part of the event service and are not considered newsletter subscriptions or general marketing communications.

Scientific programme administration – to receive, review and manage abstracts and other scientific submissions, communicate with authors and reviewers, prepare the scientific programme and administer presentations.

Newsletter and promotional communications – to send information about ScoSym, related educational activities, future editions or other relevant scientific and professional events where you have separately agreed to receive such communications.

Event documentation and communication – to photograph, film or otherwise document the symposium and communicate information about the event through our website, social-media channels, reports and other communication materials.

Online participation and streaming – where an online or hybrid participation option is offered, to provide access to livestreams, online sessions and related digital services.

Website operation and security – to operate, maintain and secure the website, prevent abuse, troubleshoot technical problems and protect our systems and users.

Legal and regulatory compliance – to comply with accounting, tax, regulatory, judicial and other obligations imposed by applicable law.

Defence of legal claims – where necessary to establish, exercise or defend legal rights.

5. Legal Bases for Processing

Depending on the processing activity, we rely on one or more of the following legal bases under Article 6 GDPR:

Performance of a contract or steps taken before entering into a contract

We rely on Article 6(1)(b) GDPR where processing is necessary to:

process your registration;

administer your participation;

provide access to the symposium or workshops;

manage payments;

provide online access, where applicable;

communicate essential information relating to your registration and participation.

Compliance with a legal obligation

We rely on Article 6(1)(c) GDPR where processing is necessary to comply with legal obligations, including accounting, tax, financial and regulatory requirements.

Legitimate interests

We may rely on Article 6(1)(f) GDPR where processing is necessary for our legitimate interests or those of a third party, provided that these interests are not overridden by your fundamental rights and freedoms.

Such interests may include:

organising and administering a professional scientific event;

maintaining the security and integrity of our website and systems;

responding to enquiries;

preventing fraud and misuse;

maintaining appropriate organisational records;

documenting and communicating the symposium;

protecting and defending our legal rights.

Consent

We rely on Article 6(1)(a) GDPR where you have provided consent, particularly for:

newsletter and promotional communications;

non-essential cookies or similar technologies;

specific uses of photographs, recordings or other personal data where consent is the appropriate legal basis.

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

6. Event Photography, Video and Recording

ScoSym 2027 is a professional and scientific event and may be photographed, filmed, livestreamed or otherwise recorded.

Photographs and audiovisual materials may capture speakers, organisers, exhibitors and attendees and may be used to document and communicate the symposium, including through:

the ScoSym website;

official social-media channels;

symposium reports and presentations;

promotional materials concerning ScoSym and future editions;

professional and scientific communications.

Where appropriate, participants will be informed at the event that photography or filming is taking place.

We will seek to balance our legitimate interest in documenting and communicating the event with the privacy and reasonable expectations of participants.

Where an image or recording focuses specifically on an identifiable individual, is intended for a separate promotional purpose, or otherwise requires consent under applicable law, additional consent may be requested.

If you have concerns regarding being photographed or filmed, please contact the organising team at hello@scosym2027.org or speak with a member of the organising team during the event.

Requests concerning a particular photograph or recording will be assessed taking into account the circumstances of its use, applicable data protection rules and other relevant legal rights.

7. Livestreaming and Recorded Scientific Content

Some sessions may be livestreamed or recorded for online participants or subsequent educational use.

Speakers, moderators and other individuals whose presentations or contributions are specifically recorded will be informed separately about the recording and intended use of their contribution where appropriate.

Participants attending sessions should be aware that questions, comments or other participation may potentially be captured in the recording.

Additional information will be provided if recorded sessions are subsequently made available on demand or through another platform.

8. Newsletter and Marketing Communications

Subscription to our newsletter is voluntary and separate from registration for ScoSym 2027.

Newsletter subscriptions may be managed using NewsMAN or another communication service provider acting on our behalf.

Where required, we may use confirmation mechanisms such as double opt-in to verify newsletter subscriptions.

Every promotional email will provide a mechanism allowing you to unsubscribe.

You may also withdraw your consent at any time by contacting hello@scosym2027.org.

Withdrawal from marketing communications does not affect essential communications relating to an event for which you have registered.

9. Who May Receive Your Personal Data

We do not sell personal data.

Where necessary for the purposes described in this Privacy Policy, personal data may be disclosed or made accessible to:

website hosting and IT service providers;

WordPress and WooCommerce-related service providers;

payment service providers, including NETOPIA Payments;

invoicing and accounting service providers, including SmartBill;

newsletter and email communication providers, including NewsMAN;

event registration and event-management service providers;

audiovisual, streaming and technical service providers;

scientific committee members and reviewers involved in abstract evaluation;

venues and event service providers where information is necessary for providing a requested service;

professional advisers, accountants, auditors or legal advisers;

competent public authorities, courts or regulatory bodies where disclosure is required by law.

Service providers processing personal data on our behalf are required, where applicable, to process such information only in accordance with our instructions and applicable data protection requirements.

Some third-party providers, particularly payment providers, may also process certain information as independent data controllers for purposes determined by them, such as fraud prevention, payment security or compliance with financial regulations.

10. Third-Party Content and Services

Our website may contain or embed content provided by third parties, including services such as:

YouTube or Vimeo;

Google Maps;

social-media platforms;

payment providers;

livestreaming or video-conferencing platforms.

These services may process information about your device or interaction with their content.

Where required by applicable law, third-party content capable of setting non-essential cookies or tracking users will be blocked until you provide the relevant cookie consent.

For further information, please consult our Cookie Policy and the privacy information provided by the relevant third-party service.

11. International Transfers of Personal Data

Some service providers used in connection with the website or symposium may process personal data outside Romania or the European Economic Area (EEA).

Where personal data is transferred outside the EEA, we will take appropriate measures required by applicable data protection law.

Depending on the recipient and destination, these safeguards may include:

an adequacy decision adopted by the European Commission;

Standard Contractual Clauses approved by the European Commission;

participation in an applicable recognised data-transfer framework;

other safeguards permitted under the GDPR.

The specific services used by ScoSym may evolve as the event infrastructure is finalised. This Privacy Policy will be updated where material changes affect the processing of personal data.

12. How Long We Keep Personal Data

We retain personal data only for as long as necessary for the purpose for which it was collected and to comply with applicable legal obligations.

As a general approach:

Registration and participation records – retained for the duration necessary to organise the event and for a reasonable period afterwards for administrative, reporting and legal purposes.

Financial and invoicing records – retained for the period required under applicable Romanian accounting and tax legislation.

Scientific submissions – retained for the duration necessary for review, programme administration, publication where applicable, scientific record-keeping and legitimate archival purposes.

Newsletter information – retained until you unsubscribe or withdraw your consent, subject to limited retention of information necessary to demonstrate or respect your opt-out.

General correspondence – retained for as long as necessary to resolve the relevant request and, where appropriate, for a reasonable period thereafter.

Photographs and audiovisual event documentation – may be retained for longer periods as part of the historical and professional archive of ScoSym, subject to applicable data protection requirements and individual rights.

Technical and security logs – retained only for the period reasonably necessary for website operation, security, troubleshooting and fraud prevention.

Where data is required in connection with a legal claim, investigation or legal obligation, it may be retained for the duration necessary for that purpose.

13. Is Providing Personal Data Mandatory?

Some personal information is necessary for us to provide the services you request.

For example, without the information required for registration and payment, we may be unable to register you for ScoSym 2027 or issue the necessary financial documents.

Information marked as optional does not need to be provided unless you choose to do so.

Newsletter subscription is entirely optional and is not a condition of registering for or participating in ScoSym 2027.

14. Your Rights

Subject to the conditions and limitations provided by the GDPR, you may have the right to:

obtain confirmation as to whether we process your personal data and request access to it;

request correction of inaccurate or incomplete personal data;

request deletion of your personal data;

request restriction of processing;

object to processing based on legitimate interests;

receive certain personal data in a structured, commonly used and machine-readable format and request its transmission to another controller where the legal requirements for data portability are met;

withdraw consent at any time where processing is based on consent;

lodge a complaint with the competent data protection supervisory authority.

These rights are not absolute and may be subject to exceptions provided by applicable law.

To exercise your rights, contact us at:

hello@scosym2027.org

We may request reasonable information necessary to verify your identity before responding to a request.

15. Right to Object

Where we process personal data on the basis of our legitimate interests under Article 6(1)(f) GDPR, you have the right to object to such processing on grounds relating to your particular situation.

Where personal data is processed for direct marketing purposes, you may object to such processing at any time.

16. Complaints

If you believe that your personal data has been processed in violation of applicable data protection legislation, we encourage you to contact us first at hello@scosym2027.org so that we can address your concerns.

You also have the right to lodge a complaint with the competent supervisory authority.

In Romania, the competent authority is:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Bucharest, Romania

You may also contact the data protection authority in the EU/EEA Member State of your habitual residence, place of work or place of the alleged infringement, where applicable.

17. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, accidental or unlawful destruction, loss, alteration, disclosure or other unlawful processing.

Access to personal data is limited to persons and service providers who require such access for legitimate organisational purposes.

However, no online transmission or electronic storage system can guarantee absolute security.

18. Automated Decision-Making

We do not currently use personal data collected through the ScoSym website to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you.

If this changes, this Privacy Policy will be updated accordingly.

19. External Websites

Our website may contain links to third-party websites.

We are not responsible for the privacy practices or content of websites operated independently by third parties. We recommend reviewing the privacy information provided by those websites before providing personal data.

20. Cookies

Our website uses cookies and similar technologies necessary for website functionality and may use additional technologies associated with embedded or third-party services.

Non-essential cookies and similar technologies will be used in accordance with your consent choices where consent is required.

Detailed information about the cookies and services used on this website, their purposes and how you can manage your preferences is provided in our separate Cookie Policy.

21. Changes to This Privacy Policy

We may update this Privacy Policy where necessary to reflect changes to the symposium, website functionality, service providers, legal requirements or our data-processing practices.

The current version will always be published on scosym2027.org, together with the date of the latest update.

Where a change materially affects the way we process personal data, we will provide additional notice where required by applicable law.

22. Contact

For questions regarding this Privacy Policy or the processing of your personal data, or to exercise your data protection rights, please contact:

Asociația Terapie pentru Mișcare
21–23 Bulevardul Mărășești
District 4, Bucharest, Romania
CIF: 35597239
Email: hello@scosym2027.org
Whatsapp: +40726462050