Version of September 11, 2026 · badge code scanning
Privacy policy
Emisar APP (emisar.ro) is the catalog and networking platform for conferences. This text describes the data we use to run the service — it is not a complete legal instrument.
Who we are
The data controller for Emisar APP accounts is PR & ARTS COMMUNICATIONS SRL (tax ID 45376502), registered office Str. Baicului 2, Bl. 1A, Sc. 1, Et. 9, Ap. 33, Sectorul 2, București. For attendee lists the controller is the event organizer and PR & ARTS COMMUNICATIONS SRL acts as processor. Data questions: salut@emisar.ro.
What we process
Organizer or attendee account: email and display name. Event profile: what you offer, what you’re looking for, goal, and contact channels you choose to share. Usage data needed to run the product (session, check-in, meetings, badge code scans). Your email and name are required for the account; the rest of the profile is optional, except the fields the organizer asks for at registration. We do not sell contact lists.
Our legal basis
Organizer accounts and service emails (sign-in link, code, confirmations): performance of the contract (Art. 6(1)(b) GDPR). Security of the service and technical logs: our legitimate interest in keeping the service safe and working (Art. 6(1)(f)). The newsletter for organizers: your consent (Art. 6(1)(a)), which you can withdraw at any time. The log of badge code scans: our legitimate interest in keeping the event safe and investigating abuse and complaints (Art. 6(1)(f)). We process event attendees’ data on behalf of the organizer, who is the controller and sets the legal basis.
Where the data lives and who it passes through
The server, with the database and its backups, is at Contabo GmbH in Germany. Cloudflare sits in front of it: it serves the pages and runs DNS, so requests to the site, with your IP address, pass through its network. Emails leave from our own mail server straight to the recipient’s inbox; if an organizer connects their own SMTP server, their invitations go through it. Push notifications pass, encrypted, through your browser’s push service (Google, Apple or Mozilla). We use no external analytics, error-monitoring or bulk-email services. If an organizer connects their ticketing platform (Eventbrite, Oveit, iaBilet, Biletin) or puts a YouTube or Vimeo video on the event page, that data also passes through those services.
Transfers outside the European Union
Cloudflare, Inc. (USA) serves the pages and runs DNS, so requests to the site pass through its network. The transfer relies on the EU–US Data Privacy Framework. All providers are listed on the “Subprocessors and cookies” page.
How long we keep data
Organizer account: while it is active; we delete it on request. Event data (attendees, profiles, meetings, contacts): at most 24 months after the event, then we anonymize it. The organizer can ask for earlier deletion. The scan log: 12 months after the event ends, then we anonymize it (only the numbers remain). Database backups: 14 days. Server technical logs: at most 30 days. Unused sign-in links and codes: deleted one day after they expire.
Automatically calculated recommendations
Meeting recommendations are calculated automatically from what you filled in your profile (what you offer, what you look for, your industry). They have no legal effect and do not stop you from finding anyone in the list.
Scanning the code on your badge
The code on your badge identifies you at the event. It does not open your account: you sign in only with the link or code sent by email. Whoever scans your code (a booth or another attendee) receives the contact details you show in your profile. If your profile is hidden, they only get a request, without your details. You can ask to approve every scan, at registration or from your profile; the organizer can require approval for everyone. You can withdraw shared details at any time; what a booth has already exported stays with them. The scan log keeps who scanned whom or what, when, how and the result, without the IP address. Purpose: event security and investigating abuse and complaints. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). The organizer sees the log. We open it only for an investigation, and every access stays in our admin log. Twelve months after the event we anonymize it: only the numbers remain. You can object to this processing by writing to the address below.
Cookies
We use essential cookies for session, language, and theme. We do not run third-party ads or track visitors for advertising.
Your rights
You have the right to access your data, to have it corrected or erased, to restrict its processing, to data portability and to object to processing based on legitimate interest. If you gave consent, you can withdraw it at any time; this does not affect what was done before. For event data, the request goes to the organizer, and we help them respond. We reply within one month. You have the right to lodge a complaint with the Romanian data protection authority, ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, www.dataprotection.ro.
Contact
For privacy requests: salut@emisar.ro. We reply manually, by email.
PR & ARTS COMMUNICATIONS SRL · CUI 45376502 · J40/22168/2021 · Str. Baicului 2, Bl. 1A, Sc. 1, Et. 9, Ap. 33, Sectorul 2, București
salut@emisar.ro