Personal Data Protection Policy

version 1.0 (9 May 2025)

1. Preamble

Because the use of our services brings us into contact with your personal data within the meaning of EU Regulation 679/2016 (GDPR), we have chosen to draw up this Privacy Policy, which is intended to inform you about the type of data collected, the purpose and manner of its processing, and the rights and obligations you have as a data subject.

PADEL EXPERIENCE S.R.L. (hereinafter: PADELXP) appreciates your visit to our website and your interest in our products and our company. The privacy and protection of your personal data are important to us and we take this into account in all our processes.

We therefore process your personal data in compliance with the applicable data protection regulations, in particular the requirements of the EU General Data Protection Regulation (GDPR).

Below we would like to provide you with information about data processing in cases where PADELXP carries out processing operations.


2. The party responsible for the commitments made in this Privacy Policy

The “Controller”, as defined in Article 4 no. 7 of the GDPR, is PADEL EXPERIENCE S.R.L., a Romanian legal entity with its registered office in Câmpina, Prahova County, registered with the Trade Register under no. J2025026671005, tax identification number (CUI) 51624190.

These rules apply equally to all entities operating under the PADELXP name (hereinafter “PADELXP”), including both the parent company and its direct partners – franchisees or other distributors.

If you have any questions about how we process your personal data or about data protection in general, please contact us at contact@padelxp.ro.


3. Principles governing the processing of personal data

In accordance with the provisions of EU Regulation 679/2016, personal data is processed in compliance with the following principles:

Lawfulness, fairness and transparency

Lawfulness is an essential principle that characterises all conduct of individuals in society; under the GDPR, the principle of lawfulness requires data to be processed on the basis of legal provisions forming part of the EU acquis, linked to the stated purpose of the processing and to the legal grounds permitted by the GDPR.

Fairness involves moral and ethical values; fair processing is processing carried out on the basis of the same objective and honest criteria, without discrimination.

Transparency means that all information and communications relating to the processing of personal data are easily accessible and easy to understand, and that clear and plain language is used when this information/communication is provided.

Purpose limitation

Personal data must be collected for specified, explicit and legitimate purposes, and further processing in a manner incompatible with those purposes is prohibited, except where further processing is carried out for archiving purposes in the public interest, for scientific/historical research purposes or for statistical purposes.

Setting purposes that are specified, explicit and legitimate contributes to transparency and provides predictability, protecting the data subject by setting limits on how controllers can use their personal data and reinforcing the fairness of personal data processing.

Data minimisation – adequate, limited and relevant

Under this principle, controllers are advised that any collection of personal data must be carefully analysed before the data is actually obtained; the data must be the most relevant and strictly limited to what is absolutely necessary for the purposes for which it is processed.

Accuracy of data and keeping it up to date

Controllers must take every measure to ensure the validity of the data, and data found to be inaccurate must be quickly updated or deleted. To this end, the data subject has the right to request the correction or deletion of inaccurate data.

Storage limitation

Data must be kept only for as long as it is needed for the intended processing. Longer storage periods are exceptions and usually result from the law (for example, the obligation to keep archives for a certain number of years, or keeping data for research or statistical purposes).

Integrity and confidentiality — data security

Personal data must be processed under the most appropriate security conditions, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, by taking appropriate technical or organisational measures.


4. Applying the principles

We have described the principles above as set out in the Regulation so that the conditions under which personal data may be processed can be understood.

On the basis of these principles, we have implemented both procedures for our employees and partners and technical and organisational measures capable of ensuring compliance with all these principles.

If you consider that anything in this Policy does not comply with the principles set out above, please let us know what you think should be changed/removed.


5. Definition of personal data

Personal data is defined as any information relating to an identified or identifiable natural person. This includes, for example, your name, your contact details, your phone number or email address and your relationship with a company, as well as your interactions/activities with us.

When you use our website, personal data may be processed in the form of information about your use of the website. This information is usually collected through log files and cookies.

In the case of requests or messages sent, personal data may include your name, contact details (business and private), address and any other personal information you provide when you write a text message or fill in a form on the PADELXP website.


6. Data protection notice for the PADELXP website

Below, PADELXP, the operator of the website https://padelxp.ro, would like to give you an overview of how we protect your personal data on our website, the type of personal data we process, for what purposes and to what extent.


7. Data processing

When you visit our website, general information is collected automatically. This information (server log files) includes the type of web browser, the operating system used, the domain name of your internet service provider and similar details. In addition, your IP address is transmitted in order to use the service you requested. This information is essential when using the internet and is technically necessary to ensure the website’s constant availability.

As a rule, this log file data is anonymised or deleted by us after a period of a few weeks, unless we describe extended data processing below.

If you send us a request by email or through your user account, we collect the data you provide in order to process your request and to fulfil your requests, where applicable.

If you use any services offered on our website, other personal data may also be collected from you. We process this data to the extent necessary to provide the services you have requested.

In addition, you may voluntarily create other personal data. We describe the legal basis in the individually presented functions and offers below.

If you send us a request by email, we collect the data you provide in order to process your request and to fulfil your requests, where applicable.

The legal basis for the above cases is Article 6(1)(1)(f) of the GDPR.

Further processing of your data by us or by other group companies or service providers for purposes beyond those above takes place as set out below, in accordance with the use you have selected or where you have given your consent.


8. General enquiries and correspondence

In addition to contacting us by phone and email, you can also use the contact forms on the website, where available, to send us general questions about us or our products and services. We process the data you have entered in the form. The form includes mandatory information that we need in order to process and respond to your request, as well as largely voluntary information that you enter voluntarily in the free text fields.

The data is as follows:

  • Email address (mandatory information)
  • Subject of your request (optional)
  • Content of your message (optional)
  • Surname, first name (optional)
  • Company name (optional)
  • Phone number (optional)
  • Mobile phone number (optional)
  • Attachments you upload through the form (optional)

We process and store the data to the extent and for the duration necessary to process and respond to your request and/or to comply with the retention obligations laid down by law.

The legal basis for requesting and processing the information requested is Art. 6(1)(f) GDPR.

We need this information, such as your email address, so that we can automatically forward your request to the relevant internal department and process and respond to your request. In this respect, the collection and processing of this information is in your interest.

The legal basis for processing the information you enter voluntarily in the free text fields is Art. 6(1)(f) of the GDPR. By voluntarily entering this information in the online form, you agree that the processing of this information is in your interest and that you knowingly wish it to be processed.

The legal basis is Art. 6(1)(b) GDPR if your data and the correspondence between you and us are necessary so that you, as an employee of our customers, suppliers or other third parties, can perform your work duties and contact us as an employee, for example to order products and services or to report a support case if you are already a customer.


9. Security information and external links

We take technical and organisational security measures on the PADELXP website to protect the personal data we store against access by third parties, loss or misuse, and to allow the secure transfer of data.

The PADELXP website may contain links to other websites from other providers. Please note that PADELXP is not responsible for the data protection policies or the content of these other websites.


10. Advertising by post and email

If you have given your consent or if we have received your contact details as part of concluding a contract, we may send you information about our products and services by email.

We may continue to send you information about events, competitions, products and services by post if we have obtained your address and you have agreed to receive this information. Further information on how your data is used for advertising purposes where there is a business relationship can be found in the sections below.

Of course, you can withdraw your consent to receive advertising mail at any time or object to the use of your data for advertising purposes. The easiest way to revoke your consent is to unsubscribe from the advertising newsletter or to send us an email at the address given in the introductory part of this document.


11. Scope of data processing and designated uses

Performance of the contract

PADELXP processes the data it receives from you in the context of requests or existing contractual relationships, in particular emails, orders, your wishes regarding our products, and payment details.

We process the following information that we receive from you and about you on the website:

  • Surname, first name, form of address
  • Email address
  • Phone number
  • Your consent to marketing activities
  • An overview of orders received and existing orders
  • Your position / your role in the company
  • “Representation” within the company

We process this information in order to provide customer services and to improve efficiency in allocating and processing orders. Our employees need this data to contact you and to conduct the business relationship between the parties properly.

The legal basis for data processing is Art. 6(1)(b) and (f) of the General Data Protection Regulation (GDPR). The purposes mentioned above represent our legitimate interest in processing the data.

Lawyers, tax advisers and external auditors may have access to the information and documents they need to provide professional advisory and audit services related to our business relationship.

To protect data subjects and our IT systems from cyber attacks and hackers, we do not publish the names of external system providers directly; instead, on request, we will provide you with the (company) names of the external recipients.

The data centres of PADELXP and of the external cloud providers are located in the EU.

Access to user account data is also granted to people in the sales and customer support departments for the purpose of processing business transactions, and to people who maintain our IT and cloud systems and provide support services.

PADELXP processes and stores the data collected to the extent and for as long as this is necessary for establishing, performing and ending the business relationship, and to the extent and for as long as necessary under Art. 17(3)(e) GDPR for establishing, exercising or defending legal claims (for example, for delivery, payment, warranty or damages), or to the extent and for as long as tax, accounting and record-keeping periods and obligations require.

The legal basis for storing the data is Art. 6(1)(b), Art. 17(3)(e) GDPR and Art. 6(1)(c) GDPR.

Promotional use of data by PADELXP

PADELXP and the service providers it engages use your name and address as a contact person in ongoing business relationships, or those of interested persons, for further measures aimed at establishing a business relationship with our company.

This includes sending/presenting advertising material about PADELXP products and services, so that potential customers and business partners can learn about products that may be of interest and form a long-term business relationship.

Last but not least, we would like to keep in touch with you on special occasions and send you holiday greetings, for example.

PADELXP uses your phone number for promotional purposes only if you have given your consent or if consent can reasonably be assumed – for example, in an existing business relationship or following previous contact.

PADELXP also uses your email address, obtained from contact persons when contracts are concluded, to advertise similar products and services.

In all other cases, we use your email address for advertising purposes only with your separate consent.

Of course, you have the right to refuse these promotional contacts. We inform you of your right to object to advertising in each individual case.

In addition, PADELXP processes data collected in the course of the business relationship (contact information, product purchases, services ordered) and obtained when using services on the PADELXP website, at trade fairs or during other advertising campaigns (use of data when accessing the website or taking part in advertising campaigns, as well as information you voluntarily disclose when using the website) in order to offer you offers tailored to your interests.

Through the above, we use the data collected during the business relationship and data obtained while you use our products/services to inform you about offers, information and current developments relating to our products and services that may be of interest.

Through this data processing, we can present products and services that we think may interest you through personalised offers (advertising on the website, by email or by post).

We may also send you – as an existing customer or if we have received your contact details in another way – information about special promotions or events.

In this case, you will receive a message from us with information about the specific campaign, how you can take part and what information you need to provide.

In this case, we will often register your participation through a website linked to the event and process your data for the purposes indicated, for example to offer you products or to send you information.

We may use the information received as part of the processing described here.

When information is first selected and sent, your data is processed on the basis of an analysis of our interests, Article 6(1)(1)(f) GDPR; when you take part in a campaign and register, your data is processed for the performance of the contract, in accordance with Article 6(1)(1)(b) GDPR.

As a rule, your data is stored in the EU for advertising purposes. We may therefore use service providers that we have carefully inspected and audited. If, in individual cases, data is transferred to and processed on servers in third countries outside the EU/EEA, in particular in the USA and, where applicable, in the United Kingdom (UK), we use service providers that we engage and monitor, that guarantee us a reasonable level of data protection and with which the European Commission’s standard data protection clauses have in principle been agreed. In individual cases, permission for the data transfer may also arise under Article 49 of the GDPR, for example to perform a contract with an international centre or if you have given your consent.

To achieve the objectives associated with this promotional use, we process your data for the entire lifetime of our products and for as long as you remain a customer.

Exceptions are made if you agree to a longer period of use and/or if the data is subject to legal retention obligations. In the latter case, the data is deleted after the retention period expires. The processing period may be shorter if you exercise your right to object.

The legal basis for this promotional use is Article 6(1)(1)(f) of the GDPR or, if you have given your consent, Article 6(1)(1)(a) of the GDPR. We inform you below of your rights regarding the use of your data for advertising purposes, in particular your right to object.

Processing of personal data as a result of legal obligations

PADELXP, like any other company in Romania and Europe, must comply with various legal obligations to verify the data of customers and business partners.

In such cases, we process your personal data only to the extent required by law.

To fulfil these legal obligations, it may be necessary for us to process some of your data automatically in order to assess personal aspects.

The legal basis for this processing is Article 6(1)(c) of the GDPR, in conjunction with the applicable legal provisions.

These legal provisions relate in particular to:

  • The prevention of fraud and money laundering
  • Audit and tax reporting requirements
  • Risk assessment and management within the Group
  • Sanctions lists
  • Export controls and customs regulations
  • Audits, in particular by tax advisers and auditors

12. Sharing of data within the PADELXP group

PADELXP may pass on your basic data (surname, first name, company name, contact persons, address and contact details such as phone number and email address) to other companies in the PADELXP group and may update it to ensure that all PADELXP companies involved with you in a transaction (for example, the performance of a contract) have the same data.

This is intended to simplify our processes and may help you avoid having to provide your basic data again when you contact another company in the group.

The legal basis for this type of data processing is Article 6(1)(b) or (f) of the GDPR. Your rights are protected by internal contractual policies that ensure a high standard of data protection.

In addition to basic data, data relating to a specific order (order data) or data for preparing such an order may also be passed on where your request can be forwarded to other PADELXP companies, if this is necessary given the specific nature of your order. For example, different PADELXP products are sold in different parts of the country by distributors or franchisees, so data may need to be transferred to simplify order processing and delivery.

In such cases, you will be informed of this transfer when the contract is concluded. The legal basis for this processing is Article 6(1)(b) of the GDPR.


13. Surveys using online tools

In some cases, we carry out surveys/questionnaires with customers, suppliers, trade fair visitors and stakeholders to find out as much as possible about their requirements for our products and services. We may therefore ask you to take part in a survey, which is always voluntary. We carry out surveys in different places, for different reasons and for different purposes, using different technical tools and different people. If we interview you in person at an event or trade fair, we may carry out and document the survey and documentation using an electronic device such as a tablet.

We use your surname, first name and email address to invite you to complete a survey. If we have invited you by email to complete a survey and you do so online, a cookie will be placed on your device to prevent multiple participation and falsification of the results. This information is kept separately from the information and details provided in the survey and is not linked to other data.

We carry out both anonymous and personal surveys.

When you take part in an anonymous survey, the answers of all respondents are combined statistically and evaluated collectively. It is therefore not possible to match answers to individual participants. In addition, we word the questions in such a way that we cannot identify the person answering.

When you take part in a personal, non-anonymous survey, we generally collect your surname, first name, contact details, the name and sector of your company, your role in the company, etc., and then evaluate this information.

Sometimes we link participation in the survey to a competition or other rewards; in such cases we always make sure that answers and rewards are kept separate, so that we cannot identify an individual’s answers. We may also display individualised design elements, such as images, videos, questions or pages.

The legal basis for processing your data when you take part in an anonymous survey is Art. 6(1)(1) of the GDPR. Our legitimate interest is to receive voluntary feedback from you about the company and our products. If you take part in a personal survey, we will obtain your consent in advance. The legal basis is Art. 6(1)(1) of the GDPR.

If you withdraw your consent, the data will be deleted within one month, unless there are laws, obligations or overriding interests that prevent immediate deletion. In all other respects, the information will be deleted to the extent and as soon as processing of this information is no longer necessary to fulfil specific purposes, to meet record-keeping requirements or for the protection or exercise of legal rights.


14. Data protection information for job applicants at PADELXP

If you apply to PADELXP for a job, the data processing principles described below apply. Once we hire you, we will inform you separately about data processing in the context of concluding the contract.

Internal processing of data when reviewing your application

We process the data you have provided in connection with your application in order to assess your application and your suitability for the advertised position. We store your data in our database in Romania if you contact us through one of our service providers or through a social media platform. To review your application, we may use specialised service providers that we monitor (recruitment platforms). Applications suitable for a position are forwarded by the human resources department to the relevant department for further assessment. To assess your application comprehensively, we always need your CV as well as relevant certificates or proof. Further information and a photo are optional.

Unless you wish to be saved in our list of candidates, we will delete your application data 6 months after the end of the application process, i.e. after the position has been filled. This data processing takes place on the basis of Article 6(1)(b) of the GDPR and Law no. 53/2003 on the Labour Code.

Matching open job offers within PADELXP

If you gave your consent during the application by ticking the relevant box, we will check during the application process whether you are suitable for positions other than those you mentioned that match your qualifications.

If you do not want such access to take place in future, you can tell us at any time. If you raise an objection, this will not affect the outcome of your current application.

This data processing takes place on the basis of Article 6(1)(b) of the GDPR and Law no. 53/2003 on the Labour Code.

Your data is also deleted in the manner described above if we are unable to find a suitable position for you. Your rights are protected by internal contractual policies that ensure a high standard of data protection.

Saving your application in our talent database

If we were unable to consider your application for a specific position, we would still like to save your application in our talent database.

For this purpose, you only need to give your consent. This allows us to notify you when a suitable position becomes available. We will only save your application if you have given us the appropriate explicit consent.

If you give your consent, we will store your data for a maximum of 5 years; after this period we will delete your data, unless you request that it be stored again.

Please note that if you object to the processing of your data, we may not be able to consider you for future positions that might suit you.

The legal basis in this respect is Article 6(1)(a) of the GDPR.

Applications through social media platforms

You can also apply to us using social media platforms (for example, Facebook or Linkedin). We then receive your CV and any other documents you have provided through the platforms. In this case, the platforms make available to us the data that has been stored on them. We have no further details about how these platforms process data. The legal basis is Article 6(1)(b) of the GDPR.

Applications from apprentices, work placement students and interns who are still studying

Under certain conditions we accept applications from apprentices, work placement students and interns who are still studying. If your application is not accepted, we will delete the application documents at the end of the quarter following the end of the application process. The legal basis is Article 6(1)(b) of the GDPR.

If you would like to apply again at a later date, we look forward to hearing from you.

Applications from holiday workers

Under certain conditions we accept applications from holiday workers. If your application is not accepted, we will delete the documents relating to your application 6 months after the end of the application process. The legal basis is Article 6(1)(b) of the GDPR.

If you would like to apply again at a later date, we look forward to hearing from you.


15. Data protection information for visitors to PADELXP

We are pleased when you visit us on site – whether as a contact person for a company (such as a customer or supplier) or as a potential customer, applicant or employee at PADELXP locations. So that we can quickly identify the location concerned in the event of an accident in our production facilities or on the company’s premises and business headquarters, and so that we can trace your visit, for example in connection with claims for compensation, and protect our business and trade secrets (purpose of processing), we record the following information about you in digital form in an internal IT visitor system:

  • Surname, first name
  • The name of your organisation or company and its location
  • Your contact person at PADELXP
  • The date and time of your arrival and departure

The legal basis is Article 6(1)(f) of the GDPR.

The processing purposes above constitute our “legitimate interests”.

We store the information about you recorded in our internal visitor system for a period of three years.


16. Data protection information on the processing of personal data in connection with trade fairs and other events

If you visit us at a trade fair or another networking event, we may exchange information about our products or about existing or future collaboration, or for the purpose of contacting each other for future cooperation, i.e. to initiate, conduct or conclude business relationships.

We will process the following information about you, depending on the individual situation/case or the information you give us:

  • Surname, first name.
  • Address.
  • Position.
  • Phone number (business).
  • Email address (business).
  • The content of your email/messenger messages in connection with our correspondence before, during or after a trade fair or business event.
  • The name and address of your company.
  • The department you work in.
  • Your role in the company.
  • Your industry.
  • The information on the business cards we exchange or that you give us.
  • Information taken from your (public) website or your (public) social media profile.
  • Your image/appearance in photographs, audio or video recordings, if we make and publish recordings as part of the event. If you are the focus of the photograph/recording, i.e. you are specifically seen or heard, we will obtain your consent in advance.
  • Information that is recorded and documented in the conversation note. In addition to your name and contact details, this includes, but is not limited to, information about your industry, project planning, visitor category (customer, potential customer, supplier, press, student, applicant, other service providers), the main topics of the conversation, notes from the conversation, extracts from your statements (original audio) in the conversation, the requested contact method (phone, post, email, message), interest in advertising and planned orders.
  • Other information from our correspondence before, during and after the event.
  • Documentation/a comment in the conversation note stating that you have objected to the processing and storage of your data in our IT systems and files.

If you are a new customer, an existing customer or a potential customer, the information listed here will be entered in our customer relationship management system and processed. The information is processed on PADELXP servers and in the cloud environment of external cloud providers. To protect our IT systems from cyber attacks and hackers, we do not publish the names of external system providers directly, but on request we will provide you with the (company) names of the external recipients, system providers and/or cloud providers. The data centres of PADELXP and of the external cloud providers are located in the EU. Your data may be accessed by employees working in sales and customer support, as well as by those who maintain the IT systems and provide support services.

If you are a supplier, the information presented here will be entered and managed in our supplier management system.

If you contact us in a professional capacity, i.e. in the performance of your duties at the trade fair or event, data processing will be based on Art. 6(1)(b) GDPR, as the data processing (exchange of contact details, initiation of business/projects) is necessary for you and our employees to perform your/their tasks.

The legal basis is also Art. 6(1)(f) GDPR. Managing contacts and initiating and conducting business are in both our legitimate interest and yours.

For public relations purposes, we may take and publish still images and audio and video recordings of the event or of our stand at the trade fair. If you are the focus of the image/recording, i.e. you are specifically seen and/or heard, we will obtain your consent. We will also obtain your consent if we interview you and publish that interview or a statement (original audio) by you in the media.

The legal basis is Art. 6(1)(a) GDPR. If you are not the focus of the recording but rather a peripheral presence, for example one person among many others, our legitimate interest in making and publishing the recordings takes priority.

The legal basis is then Art. 6(1)(f) GDPR.

Please read our data protection information on the creation and publication of photographs and audio and video recordings.

If you take part in an on-site survey/questionnaire, we will obtain your consent in advance. The legal basis is then Art. 6(1)(a) GDPR.

The information is stored to the extent and for as long as necessary to fulfil the purposes mentioned above and/or to comply with legal retention obligations.

If we connect on a social network such as LinkedIn in connection with the event, that network’s privacy policy must also be observed.


17. Data protection information for the creation and publication of photo, audio and video recordings and of press and advertising texts

If you take part in one of our events or training sessions, or visit us at a trade fair / event or for other reasons and get in touch with us or with an authorised external agency, we may, for public relations or employer branding purposes, create and publish photographs and audio and video recordings of the proceedings and of the people present at our events (training sessions, trade fairs, competitions, etc.), in which you are either the focus of the photograph/recording or recognisable as a peripheral person, i.e. one person among many others and not the focus of that photograph/recording.

In individual cases, you may talk to us or we may ask you specifically about a particular event, our products or our cooperation, for example, and we may process and publish a quote or statement from you in a press release.

In addition to your external appearance (photograph and video recording), your voice and language (video and audio recording), in certain circumstances we may also collect, depending on the situation, your name, position in the company, email address and phone number, for example if we mention you in a press release, a social media post or an image caption.

Depending on how and where the images/recordings and press releases in which you are mentioned are published, they may be seen, heard, saved, evaluated or reproduced both internally within PADELXP and externally, i.e. worldwide, by anyone who has access to the medium concerned.

The means of communication are, for example, the worldwide internet, local, regional, national and global online and print media, printed advertising material such as brochures and leaflets from Padel Experience SRL and from the distributors/franchisees of Padel Experience SRL, regional, national and international trade magazines, local, regional and national radio and television stations, online magazines, social media platforms, digital press, PADELXP pages, social networks such as YouTube, Facebook, Instagram, Tik Tok, LinkedIn or others, as well as newsletters or emails from PADELXP and newsletters or emails from its affiliated companies.

If we publish images/recordings and press releases on our Facebook, YouTube, Tik Tok, LinkedIn or Instagram channels, all users of these social media platforms can access them. If we publish recordings on radio and television, anyone who receives these channels can watch and listen to them.

If you are the focus of an image/recording and can be clearly and unambiguously recognised or heard, and/or you are named in a press release/advertising text, for example together with a quote and your position in the company, and you are published in the media mentioned, we will obtain your informed consent in advance.

The legal basis in this case is Art. 6(1)(a) and Art. 7 GDPR. In accordance with Art. 7(3) GDPR, you can withdraw your consent at any time without giving reasons.

If you have given us unlimited consent, we will publish and save the press releases/advertising texts and images/recordings for an unlimited period of time.

If you withdraw your consent within one month, we will delete the images/recordings in which only you are the focus. Passages in press releases/advertising texts in which you are specifically mentioned will be deleted within one month, provided that this is legally, technically and economically possible and reasonable for us.

If you are not the focus of the images/recordings but only a peripheral person in a recording or in a group shown, our legitimate interest (for example, public relations work and employer branding) in publishing this image/recording may also, in certain circumstances, outweigh your interest in it not being published.

The legal basis is Art. 6(1)(f) GDPR. In accordance with Art. 21(1) GDPR, you can object at any time without giving reasons. You can do this, for example, by sending an email to the contact address given above. If you have objected, we will try to make you unrecognisable and/or inaudible in texts and/or images/recordings within one month by pixelation (image, photograph, video) and/or distortion (voice, sound) and/or deletion of the text, provided that this is legally, technically and economically possible and reasonable for us.

We would also like to inform you that we cannot rule out the possibility that press/advertising texts or images/recordings published on the internet with your consent or on the basis of our overriding interest may continue to circulate on the internet even after they have been deleted or made unrecognisable (for example, by pixelation) by us and by the media/portals for which PADELXP is responsible. Nor can we rule out the possibility that they may previously have been downloaded, copied and further processed by third parties in their original “uncensored” state.


18. Data protection information for the use of Microsoft Teams as a collaboration platform

Microsoft Teams (hereinafter “MS Teams”) enables collaboration and communication through virtual teams and channels, chat messaging, the use of presence information, file sharing and storage, as well as web conferencing and the voluntary recording of images and sound – for example, for documentation, learning and training purposes. The following data may be processed:

  • surname, first name
  • display name / username
  • username, UserID / Meeting-ID
  • email address and phone number (preferably a business one), where applicable
  • the date and content of chat and video chat messages
  • documents sent and shared through the platform
  • image and external appearance (face, body, facial expressions, gestures, body movements, gait, etc.), provided that the video camera is enabled and switched on
  • profile picture, if you use one
  • spoken words, voice and language, provided that you have switched on the microphone and/or spoken during the meeting
  • audio and video recording of the meeting, provided that recording has been enabled and consent to the recording has been obtained in advance
  • pseudonymised diagnostic data (metadata): data required for the operation of MS Teams and for product improvements, such as information about the current version of MS Teams, the operating system version and system errors. This data is linked to a pseudonymised ID, which Microsoft does not use to identify users but to check, for example, whether system errors have occurred for one person (one ID) or for 100 people (100 IDs);

Where PADELXP employees or applicants carry out and complete their (professional) correspondence and tasks, for example by video conference, the processing is based on Law no. 81/2018 on the regulation of telework and Law no. 53/2003 on the Labour Code.

Where employees of PADELXP customers, suppliers, stakeholders or other third parties take part in a video conference, for example, the data is processed so that they can perform their tasks and so that we can communicate with each other to establish, conduct or conclude the transaction.

The legal basis is Art. 6(1)(b) GDPR and Art. 6(1)(f) GDPR.

Where, in a number of cases, data has to be transferred to third countries in order to perform tasks and correspondence, Art. 49(1)(b) and (c) GDPR applies.

Where the video conference is to be recorded, for example so that those who could not attend the live event can watch it later, or for learning and training purposes, PADELXP will obtain the users’ consent by recording the consent of the users/participants, given verbally or through other actions at the start of the recording. The legal basis is Article 6(1)(a) and Article 7 of the GDPR, and Article 49(1)(a) of the GDPR where data is transferred to third countries.

Access to this information is granted to people who, for example, take part in a video conference and/or to whom a recording of the video conference is available, and, where applicable, to employees of PADELXP and of Microsoft Corporation and Microsoft Ireland Operations Ltd., to the extent that they are responsible for providing and supporting MS Teams.

MS Teams is cloud-based. Microsoft’s data centres are located in Amsterdam (the Netherlands) or in the EU. Because the pseudonymised diagnostic data (metadata) mentioned above could be transferred through and from you to Microsoft Corporation in the USA, EU standard contractual clauses have been concluded with Microsoft Corporation. In addition, Microsoft has adopted additional technical and organisational protection measures to protect data transfers to and from the USA. Microsoft also guarantees that law enforcement authorities will not have access to the information described unless a law expressly permits or requires it.

PADELXP does not delete the content and documents in chats or the posts published in teams and channels, unless users ask PADELXP to delete this content and these documents. In addition, users can delete their own content and documents in chats, channels and teams.

If the MS Teams account is deleted, the associated account login data and the account’s content and documents (document storage, mailbox) will be permanently deleted after 60-90 days, in accordance with Microsoft standards, unless further processing is required in individual cases to meet legal retention obligations/periods. PADELXP points out that even after an individual account has been deleted, the content and documents in chats and the posts in team rooms and channels will remain available to the existing users with whom the departing person exchanged them through the platform, in their individual storage.

If users have given their consent to the creation and storage of a recording, the data will be deleted within one month of withdrawal of consent, unless PADELXP is required by law to continue processing or the rights of third parties prevent deletion of the entire recording, for example the rights of the other participants.


19. Your rights as a data subject

As a data subject, you have various rights. The relevant chapters of this data protection information describe the most appropriate way to exercise your rights.

Every data subject has the following rights:

  • The right of access (Article 15 of the GDPR)
  • The right to rectification of incorrect data (Article 16 of the GDPR)
  • The right to erasure (Article 17 of the GDPR)
  • The right to restriction of processing of personal data (Article 18 of the GDPR)
  • The right to data portability (Article 20 of the GDPR)
  • The right to lodge a complaint with a supervisory authority (Article 77 of the GDPR)

You can object at any time, without giving a reason, to the processing of personal data for promotional purposes – including the analysis of customer data – or to its disclosure to third parties for promotional purposes.

In addition, every data subject has a general right to object [see Article 21(1) of the GDPR]. # live variant (site URL in text differs local/live)

In this case, the objection to data processing must be justified. Where data is processed with your consent, you can revoke this consent at any time with immediate effect for the future. Revoking your consent does not affect the lawfulness of the data processing carried out with your consent up to the time of revocation.

Please also note that the rights listed above are not absolute. There are exceptions, which is why each request received will be analysed so that we can decide whether or not it is justified. If the request is justified, we will help you exercise your rights. If the request is unjustified, we will reject it, but we will inform you of the reasons for the refusal and of your rights to lodge a complaint with the Supervisory Authority and to go to court.


20. The right to lodge a complaint with the competent data protection authority

You have the right to lodge a complaint with the competent supervisory authority (in particular in the Member State where you live, work or where the alleged infringement took place) if you consider that any of your data is being processed in a way that infringes General Data Protection Regulation no. 679/2016.

In Romania, the supervisory authority is ANSPDCP – the National Supervisory Authority for Personal Data Processing, with its headquarters in Bucharest, Bd. General Gheorghe Magheru nr. 28-30, sector 1, tel. +4.0318.059.211, website http://www.dataprotection.ro .


21. Applicable law

This Privacy Policy is governed by and must be interpreted in accordance with Romanian law and any other mandatory legal provisions applicable in the European Union.


22. Updates to the Privacy Policy

You can find out when this Privacy Notice was last changed by checking the version and update date at the top of the document.

If you object to any changes, you can expressly state your intention to do so. Continuing to use the website after changes to this Privacy Policy have been published means that you have read, understood and accepted the changes.

You can print, download and keep a copy of the Privacy Policy (and any revised version) in any way for your records.

Scroll to Top