GDPR Compliance Policy

AF-MEDIA SERVICES SRL
ID: 44745059 | EUID: ROONRCJ12/3872/2021
RO93BTRLRONCRT0618644001 | RO43BTRLEURCRT0618644001 | RO18TREZ2165069XXX044884
Address: Str. A Little No. 2, Ap. 14, Cluj-Napoca
Phone: +4 0364 630165 | Email: help@aftech.ro
Website: https://aftech.ro


Introduction

This GDPR (General Data Protection Regulation) Compliance Policy defines the company's commitments and practices AF-MEDIA SERVICES SRL to ensure the protection of personal data of customers, employees and partners, in accordance with Regulation (EU) 2016/679.


Policy objectives

  1. To protect the rights and freedoms of natural persons with regard to the processing of personal data.
  2. Ensure compliance with GDPR requirements and other applicable regulations.
  3. To establish clear procedures for the management of personal data.
  4. To prevent, detect and remedy any data protection incidents.

Field of Application

This policy applies:

  • Personal data collected, stored, processed or transmitted by the company.
  • To employees, collaborators, customers and partners.
  • The systems and processes used to manage personal data.

Important Definitions

  1. Personal data: Any information that can identify a natural person (for example: name, CNP, email, IP address).
  2. Operator: AF-MEDIA SERVICES SRL, which determines the purposes and means of data processing.
  3. Data subject: The individual whose data is processed.
  4. Processing: Any operation performed on personal data (collection, storage, modification, deletion, etc.).

GDPR Principles Respected

  1. Legality, Fairness and Transparency: Data is processed in a legal, fair and transparent manner.
  2. Purpose Limitation: Data is collected and used only for specified, explicit and legitimate purposes.
  3. Data Minimization: Only strictly necessary data is collected.
  4. Accuracy: Data is kept accurate and up to date.
  5. Storage Limitation: The data is kept for a limited time, according to the stated purpose.
  6. Integrity and Confidentiality: Technical and organizational measures are implemented to protect data.

Rights of Data Subjects

AF-MEDIA SERVICES SRL guarantees the exercise of the following rights:

  1. The right to information: Data subjects are informed about how their data is processed.
  2. Right of access: Individuals can request access to their personal data.
  3. The right to rectification: Correction of inaccurate or incomplete data.
  4. Right to erasure (“Right to be forgotten”): Deletion of data on request, under certain conditions.
  5. The right to restrict processing: Limitation of data processing in certain situations.
  6. The right to data portability: Data transfer to another operator, upon request.
  7. The right to opposition: Individuals can refuse data processing for certain purposes.
  8. Rights related to automated decisions: Protection against decisions made solely on the basis of automated processing.

Obligations of the Company

  1. Assuring Consent: The explicit consent of the data subjects is obtained for data processing.
  2. Privacy: Employees are required to maintain the confidentiality of personal data.
  3. Process Documentation: The record of processing activities is updated periodically.
  4. Data Security: Implementation of appropriate technical and organizational measures for data protection.
  5. Incident Notification: Any security breach is reported to the relevant authorities within 72 hours.

Data Protection And Security

The company implements security measures, including:

  • Encryption of sensitive data.
  • Limiting access to data to authorized persons only.
  • Periodic creation of safety copies.
  • System monitoring to identify unauthorized access.

Incident Management

  1. Rapid identification of incidents related to personal data.
  2. Notification of the National Supervisory Authority for the Processing of Personal Data (ANSPDCP) in case of breaches.
  3. Informing affected persons, if applicable.
  4. Implementation of corrective measures to prevent similar incidents.

Employee Education and Awareness

AF-MEDIA SERVICES SRL organizes training sessions for employees, to ensure:

  • Awareness of data protection responsibilities.
  • Compliance with security practices.
  • Prompt reporting of incidents.

Audit and Review

  • The GDPR policy is reviewed annually or whenever legislative changes occur.
  • Internal and external audits ensure ongoing compliance.

Contact for Data Protection

For any question or request related to the processing of personal data, data subjects can contact the Data Protection Officer (DPO):

Email: dpo@aftech.ro
Telephone: +4 0364 630165
Address: Str. A Little No. 2, Ap. 14, Cluj-Napoca


This policy has been approved by the company's management and is effective on the date of signature.