Privacy Policy — FNT Mobile

Last updated: 30 April 2026 Effective date: 30 April 2026

This Privacy Policy explains how Fundația Națională pentru Tineret ("FNT", "we", "us", "the Foundation") collects, uses, and protects personal data when you use the FNT Mobile application ("the App").

We are the data controller for the personal data described below, in the sense of Regulation (EU) 2016/679 (GDPR).


1. Who we are

  • Data controller: Fundația Națională pentru Tineret
  • Registered address: Strada Căderea Bastiliei nr. 11, 010611, Sector 1, București, România
  • Tax ID (CUI): 21047677
  • Registration in the Register of Associations and Foundations (RAF): [TO CONFIRM]
  • Contact email for privacy matters: [email protected]
  • Data Protection Officer (if appointed): [NAME, contact — or remove this line if none]

2. What data we collect

We collect only what is necessary to provide the App's services. Specifically:

2.1 Account data (you provide)

  • Phone number
  • Email address
  • First name and last name
  • Password (only when registering with email/password — stored hashed on our server, never in plain text)
  • Date of birth (optional)
  • County / județ (optional)

2.2 Activity data (generated as you use the App)

  • Authentication tokens (so you stay signed in)
  • Submissions to forms made available by the Foundation (e.g. surveys, registrations) — including your answers and the time of submission
  • A unique account identifier we assign you (UUID)

2.3 Data we do not collect

  • We do not use analytics, advertising, or tracking SDKs.
  • We do not collect device identifiers (IDFA / AAID), location, camera, microphone, contacts, or photos.
  • We do not sell or rent your personal data to anyone, ever.

3. Why we use it (legal basis under GDPR)

PurposeLegal basis (GDPR Art. 6)
Create and manage your account; authenticate youPerformance of a contract — Art. 6(1)(b)
Send SMS one-time passwords (OTP) for loginPerformance of a contract — Art. 6(1)(b)
Allow you to submit forms / register for activitiesPerformance of a contract — Art. 6(1)(b)
Comply with legal obligations (e.g. retain certain records)Legal obligation — Art. 6(1)(c)
Improve security and prevent abuseLegitimate interest — Art. 6(1)(f)

We rely on consent — Art. 6(1)(a) — only where required (for example, optional profile fields you choose to fill in).


4. Where your data is stored and processed

Your data is processed on servers controlled by the Foundation and on infrastructure provided by the following processors:

ProcessorRoleLocation
Render, Inc.Hosting our backend APIUnited States, with EU edge options
Twilio Ireland Limited (and Twilio Inc., US)Delivering SMS one-time passwordsEU + US (transfer governed by Standard Contractual Clauses)

For any transfer outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses as the safeguard required by Articles 44–46 GDPR.

We do not transfer your data to any other third party except as described above or where required by law.


5. How long we keep it

DataRetention
Account data (name, phone, email, etc.)While your account exists, plus up to 90 days after deletion for backups
Authentication tokensUntil you log out or the token expires (typically days)
Form submissionsWhile your account exists, unless retention is required by law (e.g. for grant or activity reporting)
Server logsUp to 30 days

When you delete your account from the App (Settings → Delete account), we permanently remove your personal data on the timelines above.


6. Your rights (GDPR)

If you are a resident of the European Economic Area (including Romania), you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict or object to certain processing
  • Portability — receive your data in a structured, machine-readable format
  • Withdraw consent at any time, where processing is based on consent
  • Lodge a complaint with the Romanian supervisory authority: ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal Bd. G-ral Gheorghe Magheru 28-30, Sector 1, București https://www.dataprotection.ro

To exercise any of these rights, write to [email protected]. We respond within 30 days.


7. Children's data

The App is intended for users aged 16 and over. The Foundation's activities address young people — but we do not knowingly collect personal data from anyone under 16 without verifiable parental or guardian consent. If you believe a minor has provided us with personal data without consent, please contact us so we can delete it.


8. Security

We protect your data using industry standards:

  • Authentication tokens are stored on your device in the operating system's encrypted credential store (iOS Keychain / Android Keystore).
  • Passwords are hashed and never stored in clear text.
  • All traffic between the App and our servers uses HTTPS (TLS 1.2 or higher).
  • Access to backend systems is restricted to authorized personnel of the Foundation.

No system is perfectly secure. If a personal data breach occurs and is likely to result in a high risk to your rights, we will notify you and the supervisory authority within the timelines required by law (Articles 33–34 GDPR).


9. Changes to this policy

We may update this policy from time to time. The latest version is always available at https://rotineret.ro/privacy with the date noted at the top. Material changes will be communicated through the App.


10. Contact

Questions, complaints, or requests to exercise your rights:

Fundația Națională pentru Tineret Strada Căderea Bastiliei nr. 11, 010611, Sector 1, București, România Email: [email protected]


This policy is published in English. A Romanian translation is available at https://rotineret.ro/politica-de-confidentialitate — in case of any conflict, the Romanian version prevails for users in Romania.