Legal
Privacy Policy
How we collect, use, and protect TIMUN 2026 participants' data
Asociația de Reprezentare și Proiecte Diplomatice (ARPD) · Version 1.0 · Last updated: July 2026
This document is part of the TIMUN 2026 document set, alongside the Terms and Conditions, the Participation Agreement (Adults) and the Parental Agreement (Minors), and should be read together with them.
1. Data Controller
The controller of your personal data is the Association for Representation and Diplomatic Projects (ARPD), a non-profit association registered in Romania, organizer of Timișoara International Model United Nations 2026 (TIMUN 2026).
| Field | Details |
|---|---|
| Registered office | Calea Circumvalațiunii nr. 14/C, et. 10, ap. 41, Timișoara, Timiș County, Romania |
| Fiscal code (CIF) | 52708418 |
| Registration | No. 160/2025, Register of Associations and Foundations (Timișoara Court) |
| Email (data requests) | secretariat@arpd.ro |
We have not appointed a Data Protection Officer (DPO), as we are not legally required to; data-protection questions can be sent to the address above.
2. Data We Collect
2.1 Identity data
First name, last name, date of birth, nationality, national ID number (where required for identification or official documents).
2.2 Identity-document copy
A copy/photo of your ID card (front and back), used to verify identity and minimum age. It is visible only to the Secretariat, is kept as administrative data in your participant file, and is deleted at the end of the retention period (section 9).
2.3 Parent/guardian data (for participants under 18)
The legal representative's name, contact details, and consent, collected via the Parental Agreement.
2.4 Contact data
Email address, phone number, city, country.
2.5 Educational data
School/university, level of study, graduation year.
2.6 Application data
Committee and country preferences, motivation answers, prior MUN experience.
2.7 Operational data
Attendance, committee assignment, participation records.
2.8 Financial data
Payment confirmations and transaction references, required to process the seat-confirmation fee (section 4.6 of the TIMUN 2026 Terms and Conditions).
2.9 Medical / dietary data (if provided)
Allergies, dietary restrictions, emergency contact details.
2.10 Media data
Photos, video, and audio recordings made during official Conference activities (section 6 of this Policy).
2.11 Social-media handle (optional)
Your Instagram username, if you choose to provide it. This field is optional; if you opt in, it may be displayed on your shareable digital ID/badge (section 4).
3. Legal Basis for Processing
3.1 Performance of a contract
Processing applications, allocating roles, and running the Conference, based on acceptance of the TIMUN 2026 Terms and Conditions at application.
3.2 Legal obligation
Accounting, tax, and lawful reporting obligations.
3.3 Legitimate interest
Event security, organizational quality assurance, administrative management, and promoting the Conference (including through photo/video material, per section 6 of this Policy).
3.4 Consent
Optional communications and, for minor participants, the legal representative's consent expressed via the Parental Agreement.
4. Purposes of Processing
Data is processed for: organizing and running the Conference; communicating with participants; issuing certificates of participation; promoting the event; fulfilling legal obligations; handling incidents or damage claims (section 7.3 of the TIMUN 2026 Terms and Conditions); improving future editions.
Each confirmed participant receives a digital ID / badge, accessible via a personal link (of the form /id/?u=…), which displays their name, photo, school, city/region, MUN experience, and role. This link is shareable and public to anyone who has it. Additional contact fields (phone, email, and Instagram username) appear on the badge only if the participant opts in to display them.
5. Consent and Participant Declarations
By submitting the application form and attending TIMUN 2026, participants confirm that the data provided is accurate and up to date, and that they have read and accepted the TIMUN 2026 Terms and Conditions and, as applicable, the Participation Agreement (Adults) or the Parental Agreement (Minors). For participants under 18, the written consent of a parent or legal guardian is mandatory, per section 3.6 of the TIMUN 2026 Terms and Conditions. Consent for optional communications may be withdrawn at any time, without affecting the lawfulness of processing before withdrawal.
6. Photos, Videos, and Image Rights
Official sessions and social activities of the Conference may be photographed or recorded. Per section 9 of the TIMUN 2026 Terms and Conditions, participation in TIMUN 2026 implies acceptance that the participant will be photographed and filmed, and ARPD will use this material for promotional purposes, including publishing it on the website, social media, reports, and other promotional materials. This provision is a condition of participation; no option to decline photographing/filming during the Conference is available.
For participants under 18, image use is authorized by the parent or legal guardian via the Parental Agreement.
We avoid using images in a way that is excessive, misleading, or harmful to participants. Requests regarding a published photo or recording: participants (or, for minors, the parent/legal guardian) may contact the Secretariat at secretariat@arpd.ro; the Organizer will review each specific request, without guaranteeing removal of the material, since the use of participants' image for promotional purposes is a condition of participation, per section 9.2 of the TIMUN 2026 Terms and Conditions.
Group photos from public Conference moments may remain in archived documentation, based on the Organizer's legitimate interest.
7. Data Sharing and International Transfers
We do not sell personal data and do not share it for the marketing purposes of unaffiliated third parties. Data may be shared with: service providers necessary for organizing the Conference (registration platform, payment processor, website hosting, and email delivery services), competent authorities, only when required by law, and official Conference partners, with participant notice where required.
Some of these providers may be located outside the European Economic Area (EEA). In such cases, transfers rely on appropriate safeguards, such as the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. The current list of these providers is set out below.
The processors and sub-processors that receive personal data are:
| Processor | Purpose |
|---|---|
| Appwrite (Appwrite Cloud, EU/Frankfurt region) | Application database, file storage, and authentication. |
| Cloudflare (Cloudflare Pages) | Website hosting and serverless functions. |
| Banca Transilvania (iPay / e-Commerce) | Card payment processing (3-D Secure); card data is entered on the bank's hosted page and is never stored by us. |
| Google (Google Workspace) | Outgoing transactional email (Gmail) and secure storage of participant documents (ID-card copies, portrait, signed agreements) in Google Drive for the organizing team. |
| Resend | Fallback provider for outgoing transactional email. |
8. Cookies and Website Analytics
The processing of information stored on the user's terminal equipment (cookies and similar technologies) complies with Romanian Law no. 506/2004 on the processing of personal data and privacy protection in the electronic communications sector, which transposes Directive 2002/58/EC (ePrivacy), alongside the GDPR.
8.1 Strictly Necessary Cookies
The site may set cookies or equivalent technologies that are strictly necessary for the registration platform to function and for security (for example, session cookies, attack protection, or traffic load balancing). These do not require consent, under the exemption provided by Law no. 506/2004, but are listed here for transparency; the exact technical list will be published once the TIMUN 2026 registration platform launches.
8.2 Analytics Cookies
We use analytics tools (such as Google Analytics 4) solely to understand, in aggregate and anonymized form, how the website is used (pages viewed, approximate region, device and browser type), in order to improve it. We do not use this data for advertising or profiling, and advertising identifiers are redacted. The analytics provider may process data outside the EEA under applicable GDPR safeguards (Standard Contractual Clauses). You may withdraw consent for analytics cookies at any time, by changing your preference in the cookie banner/settings or by clearing this website's data from your browser — withdrawal does not affect the lawfulness of processing before it. Change cookie preference
9. Data Retention and Security
Administrative data (registration, payments, contact, identity-document copy) is retained for a maximum of 3 years after the Conference ends, except where tax/accounting law or an ongoing dispute requires a longer period, per section 5.6 of the TIMUN 2026 Terms and Conditions. Photo/video material may be retained in ARPD's archive indefinitely, for promotional and archival purposes.
We implement technical and organizational security measures, including controlled access, role-based permissions, and secure storage practices. In the event of a data security incident, we follow GDPR notification and remediation requirements.
10. Participant Rights Under GDPR
You may request at any time: information, access to your personal data, rectification of inaccurate data, erasure of data (within legal limits), restriction of processing, data portability (where applicable), objection, and withdrawal of consent for consent-based processing, without affecting the lawfulness of processing before withdrawal.
11. Exercising Your Rights
Send your request to secretariat@arpd.ro, with enough detail to identify your record. We aim to respond within one month, in accordance with GDPR.
12. Complaints to the Supervisory Authority
If you believe your data has not been processed correctly, you may lodge a complaint with Romania's National Supervisory Authority for Personal Data Processing (ANSPDCP), Bd. G-ral Gheorghe Magheru nr. 28–30, Bucharest, www.dataprotection.ro.
13. Changes to This Policy
The Organizer may update this Privacy Policy; the updated version will be published on this page, with a revised last-updated date. Major changes will be communicated per section 15.1 of the TIMUN 2026 Terms and Conditions.
14. Contact
For any question regarding this Privacy Policy: secretariat@arpd.ro.
Last updated: July 2026 · Version 1.0