PRIVACY POLICY

Last updated: 03.08.2026

Your privacy matters to us. This document explains what personal data we process when you visit asiafest.eu, write to us, apply as an exhibitor or volunteer, or attend the festival — and what rights you have.

1. Who processes your data

Asociatia Creative Arts & Events, CUI: 38259852, email: office@media-events.ro.

referred to below as the “Organiser” or “we”, acting as data controller.

We have not appointed a Data Protection Officer, as our activity does not fall within the cases set out in Article 37 GDPR. For any question about personal data, write to us directly.

2. Our principles

We collect only the data we need, use it solely for the purposes we requested it for, keep it only as long as necessary, and never sell it.

3. What data we process, why, and on what legal basis

3.1 Contact form

Data: name, e-mail address, message content. [TO BE CONFIRMED once the form is live] Purpose: to reply to you. Legal basis: our legitimate interest in communicating with people who contact us (Art. 6(1)(f) GDPR).

3.2 Exhibitor application form

Data: entity name, contact details of the responsible person (name, e-mail, phone), description of activity and products, type of stand requested. Purpose: assessing the application, contacting you, organising the exhibitor area and, if accepted, preparing the contract. Legal basis: steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).

3.3 Volunteer application form

Data: name, age, contact details, availability, relevant experience. [TO BE CONFIRMED] Purpose: selecting and organising the volunteer team. Legal basis: steps taken at your request prior to entering into a volunteering agreement (Art. 6(1)(b) GDPR).

If you are under 18, volunteering requires the consent of a parent or legal guardian.

3.4 Photography and filming at the festival

Data: your image as it appears in materials produced at the venue. Purpose: documenting the festival, promoting future editions, archiving, press materials. Legal basis: our legitimate interest in documenting and promoting the event (Art. 6(1)(f) GDPR).

We mainly photograph general shots, crowds and stage moments. You have the right to object — see section 8. For individual portraits taken on request, or materials in which you appear prominently and identifiably, we rely on your consent (Art. 6(1)(a) GDPR).

3.5 Technical data collected automatically

Data: IP address, browser type and version, operating system, pages visited, date and time of access. Purpose: operating and securing the website, preventing abuse, diagnosing errors. Legal basis: our legitimate interest in maintaining a functional and secure website (Art. 6(1)(f) GDPR).

This data is recorded in our hosting provider’s server logs and in the site’s caching mechanism.

We do not use traffic analytics, profiling or behavioural advertising tools. There is no Google Analytics, Meta Pixel or equivalent on this site.

4. What we do not do

  • We do not sell or rent your data to anyone.
  • We do not make automated decisions with legal effects concerning you, and we do not profile you.
  • We do not send you marketing communications you have not asked for.
  • We do not collect special categories of data (health, religious beliefs, political views, etc.), except where you volunteer them in a message — in which case we delete them if they are not necessary.

5. Who else has access to your data

We share data only where necessary, with:

  • our web hosting provider — [TO BE COMPLETED: name, country], which stores the website and access logs, acting as a processor;
  • our e-mail service provider — [TO BE COMPLETED], for correspondence with you;
  • collaborators and contractors involved in running the festival (photographers, production crew), bound by confidentiality obligations;
  • public authorities, where required by law.

Tickets: a separate controller

Tickets are sold online through an external ticketing partner and on site at the event box office.

For online purchases, the ticketing partner acts as an independent controller of your data — we neither receive nor process your payment data. We recommend reading their privacy policy before purchasing.

6. Transfers outside the European Economic Area

The social media icons shown on artist pages are loaded from a third-party content delivery service (cdn.simpleicons.org). When an icon loads, your IP address and basic browser information become visible to that provider, which may operate servers outside the EEA.

Otherwise, we do not transfer personal data outside the EEA.

7. How long we keep data

CategoryRetention
Messages received via the contact form1 year from the last communication
Unsuccessful exhibitor applications[TO BE COMPLETED — suggested: 1 year]
Unsuccessful volunteer applications[TO BE COMPLETED — suggested: 1 year]
Data of accepted exhibitors and volunteersfor the duration of the collaboration, plus statutory archiving periods (10 years for accounting records)
Photographs and video recordingsindefinitely, in the festival archive, except materials for which deletion is requested
Server technical logsmaximum 12 months

Once these periods expire, data is deleted or anonymised.

8. Your rights

Under the GDPR you have the right:

  • of access — to find out what data we hold about you and receive a copy;
  • to rectification — to correct inaccurate or incomplete data;
  • to erasure (“right to be forgotten”), under Article 17;
  • to restriction of processing, under Article 18;
  • to data portability — to receive your data in a structured format, where processing is based on consent or contract;
  • to object — to processing based on our legitimate interest, including appearing in photo and video materials;
  • to withdraw your consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of prior processing.

Write to us at [TO BE COMPLETED]. We respond within 30 days. For complex requests this may be extended by two months, in which case we will let you know.

We may ask for additional information to verify your identity, so that we do not disclose your data to someone else.

9. Right to lodge a complaint

If you believe we have infringed your rights, you may contact:

The National Supervisory Authority for Personal Data Processing (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania E-mail: anspdcp@dataprotection.ro Web: dataprotection.ro

You also have the right to go to court. We would appreciate hearing from us first, though — most issues can be resolved directly.

10. Cookies

The website uses cookies that are strictly necessary for its operation — remembering your selected language and the caching mechanism. Full details in our Cookie Policy [TO BE COMPLETED — link].

11. Data security

We apply reasonable technical and organisational measures to protect data: encrypted HTTPS connection, restricted access to the admin panel, separate passwords and regular platform updates.

No system is entirely secure, however. If a personal data breach occurs that is likely to result in a high risk to your rights, we will notify you without undue delay, in accordance with Article 34 GDPR.

12. Children

The website is not specifically directed at children. We do not knowingly collect data from persons under 16 without the consent of a parent or legal guardian. If you are a parent and believe we have received such data, write to us and we will delete it.

13. Changes to this policy

We may update this document. The version in force is always the one published on this page, with the last-updated date shown at the top. If we make substantial changes, we will flag them visibly on the site.