01 / Controller
Who is responsible for the data?
Proposed controller: Academy of Economic Studies of Moldova (ASEM), 61 Mitropolit Gavriil Bănulescu-Bodoni Street, MD-2005 Chișinău, Republic of Moldova. The final notice must state the exact legal entity, registration details, data-protection contact and any joint-controller arrangement with co-organisers.
02 / Scope
Which activities are covered?
This notice is intended to cover conference enquiries, alert subscriptions, registration, payments and invoicing, abstract or manuscript submission, peer review, programme management, accessibility arrangements, invitation letters, certificates, event delivery, photography and recording, post-event communication and legal compliance. Separate notices may be required where a third-party platform acts under its own terms.
03 / Personal data categories
Collect only what the process requires.
- Identity and professional data: name, title, affiliation, role, country and public professional profile.
- Contact data: institutional or personal email, telephone only when operationally necessary, and correspondence history.
- Participation data: registration category, attendance, sessions, certificate details and networking preferences.
- Submission and review data: authorship, abstracts, manuscripts, keywords, reviewer reports, decisions, conflicts and integrity declarations.
- Financial and administrative data: billing identity, invoice information, payment status, institutional sponsorship and invitation-letter evidence. Avoid storing full payment-card data in conference systems.
- Accessibility and dietary data: only the minimum information needed to provide an accommodation, handled with enhanced confidentiality.
- Technical data: security logs, browser and device information where generated by the selected hosting or conference platforms.
04 / Purposes and legal bases
State the purpose before the field.
The final notice must map each processing purpose to an applicable legal basis. Depending on the approved institutional arrangement, these may include steps requested before entering a participation contract, performance of that contract, compliance with legal obligations, legitimate interests in running a secure academic event, public-interest or institutional tasks, and consent for optional communications or identifiable promotional media. Consent must be specific, informed, freely given and withdrawable where used.
06 / Retention
Retain by record type, not indefinitely.
07 / Individual rights
Make rights practical.
Subject to applicable law, individuals may have rights of information, access, correction, deletion, restriction, objection, portability and withdrawal of consent, as well as the right to complain to a competent supervisory authority. The final site must state how to submit a request, how identity is verified, response deadlines, limitations and the relevant authority.
08 / Photography, streaming and recording
Separate documentation from promotion.
Before the event, publish the purpose and scope of photography and recording, identify streamed or recorded sessions, provide visible notices on site, define consent or other legal basis, offer a practical no-photo signal where feasible, and obtain explicit speaker permissions for recording and reuse. Do not assume that conference registration authorises unlimited promotional use.
09 / Website technology and cookies
The prototype is intentionally lean.
This static English-only prototype does not use local browser storage. It includes no analytics, advertising trackers, third-party fonts, embedded maps, payment widgets or connected forms. The live site must inventory all cookies and similar technologies, avoid non-essential trackers by default, and implement an appropriate consent mechanism where required.
10 / Security and incidents
Design for least privilege.
Use institutional accounts, multi-factor authentication, role-based access, encrypted transmission, supported software, tested backups, audit logs and an incident-response route. Do not use personal mailboxes or uncontrolled spreadsheets as the primary participant database. Define how suspected breaches are contained, assessed, documented and notified.
11 / Privacy contact and changes
Complete before launch.
Proposed conference contact: sustainx@ase.md. A separate institutional privacy or data-protection contact must be confirmed. The notice should carry a version number, publication date, change log and archive of superseded versions. Material changes should be communicated to registered participants.