Introduction
Asociația Energy Policy Group (“EPG”, “we”, “us”, or “our”) is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you interact with our website
www.epg-thinktank.org (the “Website”) and our services.
EPG is an association registered in Romania. We act as the data controller for the personal data we collect through our Website and activities. This means we determine how and why your data is processed.
This Privacy Policy applies to all individuals whose personal data we process, including:
- Website visitors
- Newsletter subscribers
- Event participants and registrants
- Job applicants
- Contact form users
- Partners and collaborators
By using our Website or providing your personal data to us, you acknowledge that you have read and understood this Privacy Policy.
Data Protection Officer
We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection practices and ensuring compliance with applicable data protection laws.
- Email: dpo@epg-thinktank.org
- Address: Icoanei, 93, 020454, București, România
If you have any questions about how we handle your personal data or wish to exercise your rights, please contact our DPO.
Legal basis and principles
We process your personal data in accordance with the EU General Data Protection Regulation (GDPR) 2016/679 and applicable Romanian data protection legislation.
Our data processing is based on the following principles:
- Lawfulness, fairness, and transparency – We process data lawfully and openly
- Purpose limitation – We collect data for specific, explicit purposes
- Data minimisation – We only collect data that is necessary
- Accuracy – We keep data accurate and up to date
- Storage limitation – We retain data only as long as necessary
- Integrity and confidentiality – We protect data with appropriate security measures
What personal data we collect
The personal data we collect depends on how you interact with us. We may collect the following categories of information:
Contact and identification data
- Name and surname
- Email address
- Telephone number
- Organisation/employer name
- Job title or professional role
- Country and city
Professional and research data
- Areas of expertise or interest
- Educational background (for research collaborations or applications)
- Professional experience (for job applications)
- Research contributions or publications
Communication data
- Email address
- Content of enquiries or messages you send us
- Records of events you register for or attend
- Preferences regarding our communications
- Responses to surveys or feedback requests
- Topics of interest
- Subscription source and date
Technical data (collected automatically)
- IP address
- Browser type and version
- Device information
- Pages visited and time spent on pages
- Referring website
- Operating system
We do not intentionally collect sensitive personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sexual orientation) through our Website. If you voluntarily provide such information (for example, in a job application CV), you may request that we delete it.
How we use your personal data
We process your personal data for the following purposes, based on specific legal grounds:
Performance of a contract or pre-contractual measures
When you register for an event, request our services, or apply for a position, we process your data to:
- Process and manage your registration or application
- Communicate with you about the event or service
- Provide the services or information you requested
- Evaluate job applications and conduct recruitment processes
Compliance with legal obligations
We process your data when required by law, including:
- Responding to lawful requests from authorities
Legitimate interests
We process your data based on our legitimate interests to:
- Respond to enquiries and provide information about our work
- Analyse Website usage to improve user experience and content
- Conduct research and policy analysis
- Ensure security of our Website and IT systems
- Prevent fraud or misuse of our services
- Maintain and improve our services
We have carefully balanced our legitimate interests against your rights and freedoms and will not process your data if your interests override ours.
Consent
For certain activities, we process your data based on your explicit consent:
- Newsletter subscriptions: sending you publications, reports, analyses, and updates about EPG’s work
- Event invitations: inviting you to workshops, seminars, or conferences organised by EPG
You can withdraw your consent at any time by:
- Clicking the “unsubscribe” link in any email
- Contacting us at dpo@epg-thinktank.org
Withdrawing consent does not affect the lawfulness of processing before withdrawal.
How we collect your personal data
We collect personal data through:
- Direct interactions – When you fill in forms, subscribe to newsletters, register for events, send enquiries, or apply for positions
- Automated technologies – Through cookies and similar technologies when you use our Website (see our Cookie Policy for details)
- Third parties – From publicly available sources, professional networks, or referrals (for recruitment or research collaborations)
- Events and conferences – When you attend our events or register through third-party platforms
Who we share your data with
We may share your personal data with the following categories of recipients, only when necessary and in accordance with data protection laws:
Service providers (data processors)
We engage trusted third-party service providers who process data on our behalf, including:
- Email service providers (MailerLite for newsletter distribution)
- Website hosting and IT infrastructure providers
- Event management platforms
- Analytics and statistics providers
All processors are bound by contractual agreements requiring them to protect your data and process it only according to our instructions.
Project partners and collaborators
When working on joint research projects or events, we may share relevant contact details with partner organisations, always in accordance with our legitimate interests or with your consent.
Public authorities
We may disclose your data when required by law or to comply with legal obligations.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
International data transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA).
In certain circumstances, we may transfer your data outside the EEA to service providers located in third countries. When we do so, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions confirming the third country provides adequate protection
- Other mechanisms recognised under GDPR
Specific transfers include:
Google LLC in the USA for website traffic and performance analysis (via Google Tag Manager).
If you would like more information about international transfers affecting your data, please contact our DPO.
How long we keep your data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal obligations.
| Category | Retention period | Legal basis |
| Newsletter subscribers | Until you unsubscribe and 3 years after that | Consent / legitimate interest |
| Event registrations | 3 years after the event | Legitimate interest / contract |
| Contact form enquiries | 3 years after contact | Legitimate interest / contract |
| Job applications | 12 months after recruitment process ends | Legitimate interest / contract |
| Website analytics | Up to 2 years | Legitimate interest / contract |
After the retention period expires, we securely delete or anonymise your personal data.
Data security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or damage. These measures include:
Technical measures
- Encryption of data in transit and at rest
- Secure authentication and access controls
- Regular software updates and security patches
- Antivirus and anti-malware protection
- Firewall protection
- Regular security backups stored securely
Organisational measures
- Access to personal data limited to authorised personnel based on roles
- Staff training on data protection and security practices
- Confidentiality agreements with employees and contractors
- Data protection policies and procedures
- Regular security assessments and audits
- Incident response procedures
We require all service providers processing data on our behalf to implement equivalent security measures.
While we strive to protect your personal data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but continuously work to maintain appropriate protection.
Your rights
Under GDPR, you have the following rights regarding your personal data:
Right to access
You can request confirmation of whether we process your data and obtain a copy of that data, along with information about how we process it.
Right to rectification
You can request correction of inaccurate or incomplete personal data without undue delay.
Right to erasure (“right to be forgotten”)
You can request deletion of your personal data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where processing is based on consent)
- You object to processing and there are no overriding legitimate grounds
- The data has been unlawfully processed
Deletion is required to comply with a legal obligation
- Right to restriction of processing
- You can request that we restrict processing of your data when:
- You contest the accuracy of the data (during the verification period)
- Processing is unlawful but you prefer restriction over erasure
- We no longer need the data, but you need it for legal claims
- You have objected to processing (pending verification of legitimate grounds)
Right to data portability
You can request to receive your personal data in a structured, commonly used, machine-readable format and have it transmitted to another controller where:
- Processing is based on consent or contract
- Processing is carried out by automated means
Right to object
You can object at any time to:
- Processing based on legitimate interests (unless we demonstrate compelling legitimate grounds that override your interests)
- Processing for direct marketing purposes (we will stop such processing immediately)
Right not to be subject to automated decision-making
You have the right not to be subject to decisions based solely on automated processing that produces legal effects or similarly significantly affects you. EPG does not use fully automated decision-making processes for website visitors.
How to exercise your rights
To exercise any of these rights, please contact our Data Protection Officer:
Email: dpo@epg-thinktank.org
Post: Icoanei, 93, 020454, București, România
We will respond to your request within one month. In complex cases, we may extend this by a further two months and will inform you accordingly.
You have the right to lodge a complaint with the Romanian supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
Website: www.dataprotection.ro
Email: anspdcp@dataprotection.ro
Children’s privacy
Our Website and services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately so we can delete it.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational needs. We will notify you of any material changes by:
- Posting the updated policy on this page with a new “Last updated” date
- Sending an email notification to newsletter subscribers (for significant changes)
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
Links to other websites
Our Website may contain links to third-party websites, social media platforms, or services that are not operated by us. This Privacy Policy does not apply to those third-party sites. We encourage you to review the privacy policies of any third-party sites you visit.
We are not responsible for the privacy practices or content of third-party websites.
Cookies and tracking technologies
Our Website uses cookies and similar technologies. For detailed information about the cookies we use and how to manage them, please see our Cookie Policy.
Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact our Data Protection Officer:
- Email: dpo@epg-thinktank.org
- Address: Icoanei, 93, 020454, București, România
