Privacy policy
Protecting your personal data sits at the heart of our transparency commitments. This privacy policy describes how Med Romania collects, processes and protects the information you entrust to us, in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and French Law No. 78-17 of 6 January 1978 as amended (the “Data Protection Act”).
1. Who is the data controller?
| Field | Value |
|---|---|
| Data controller | Med Romania |
| Address | [To be completed] |
| Contact email | privacy@med-romania.com |
2. What data do we collect?
2.1 Data you give us directly
When you use our forms (contact, eligibility quiz, guide download, order), we collect the following data:
- Contact form: first name, surname, email address, phone number (optional), country of residence, message content.
- Eligibility quiz: country of origin, type of school-leaving qualification or equivalent, subject stream, year obtained, language(s) spoken, intended budget, target university or universities and programme(s).
- Guide download: email address, first name.
- Service order: first name, surname, email address, postal address, phone number, academic documents (transcripts, diplomas, ID document), payment information.
2.2 Data collected automatically
As you browse the Site, we automatically collect:
- Browsing data: IP address (anonymised), browser type, pages visited, time spent, traffic source (referrer).
- Strictly necessary cookies: session cookie, language preference cookie, cookie consent cookie.
This data is collected through Google Analytics 4 (with IP address anonymisation enabled) and through our host’s technical logs.
2.3 Data we do NOT collect
- We collect no special category data within the meaning of the GDPR (health data, political opinions, religious beliefs, etc.) beyond the academic documents strictly necessary for your admission file.
- We neither request nor store bank card details. Payments are handled by a PCI-DSS certified provider (Stripe). We never have access to your full card number.
3. Why do we collect your data? (Legal basis and purposes)
| Purpose | Data concerned | Legal basis |
|---|---|---|
| Answering your contact enquiries | Name, email, message | Legitimate interest (responding to an enquiry) |
| Sending you the free PDF guide | Email, first name | Consent (tick box) |
| Delivering a personalised eligibility assessment | Quiz data | Consent (tick box) |
| Sending you the newsletter and nurturing emails | Consent (separate tick box) | |
| Processing your order and performing the service contract | Order data, academic documents | Performance of a contract (terms of sale) |
| Following up your admission file | Academic documents, correspondence | Performance of a contract (terms of sale) |
| Measuring Site audience | Anonymised browsing data | Legitimate interest (improving the service) |
| Keeping the Site secure | IP address, technical logs | Legitimate interest (security) |
Important: the tick box for the newsletter and nurturing emails is separate from the box for the service you requested. You can receive the guide or your quiz result without subscribing to the newsletter.
4. How long do we keep your data?
| Type of data | Retention period |
|---|---|
| Contact data (form) | 3 years from the last exchange |
| Eligibility quiz data | 3 years from quiz submission |
| Account and order data | 5 years from the end of the contractual relationship (legal obligation) |
| Academic documents | 3 years after the end of the contractual relationship, then deleted |
| Browsing data (anonymised) | 14 months maximum (Google Analytics 4) |
| Technical logs | 12 months |
At the end of these periods, data is deleted or irreversibly anonymised.
5. Who do we share your data with?
Med Romania undertakes never to sell, rent or trade your personal data. Your data is shared only in the following strictly necessary cases:
| Recipient | Data shared | Why |
|---|---|---|
| Partner sworn translator (Romania) | Academic documents | Official translation for the admission file |
| Romanian legal partner (where mandated) | Identity documents | Legalisation, filing of the application |
| Stripe (payment provider) | Amount, transaction ID | Payment processing (PCI-DSS) |
| Google (Analytics) | Anonymised IP address, browsing | Audience measurement |
| Cloudflare (host) | IP address, logs | Hosting and Site security |
| Romanian universities (UMF) | The applicant’s complete file | Filing the application (with your explicit consent) |
All our processors are bound by a GDPR-compliant data processing agreement. For transfers outside the EU (United States: Google, Cloudflare, Stripe), we ensure the processor adheres to the Data Privacy Framework (successor to the Privacy Shield) or uses standard contractual clauses approved by the European Commission.
6. How do we protect your data?
We implement appropriate technical and organisational measures:
- TLS/SSL encryption (HTTPS) across the whole Site.
- Restricted access to personal data: only authorised people (team members with a need to know) can access it.
- Strong authentication on all internal tools.
- Anonymisation of IP addresses in Google Analytics.
- Regular encrypted backups.
- A breach notification procedure: in the event of a breach presenting a risk to your rights and freedoms, we will inform you within 72 hours, in accordance with Article 34 of the GDPR.
7. What are your rights?
Under the GDPR, you have the following rights:
| Right | What it means |
|---|---|
| Right of access | Obtain confirmation that your data is being processed and receive a copy of it. |
| Right to rectification | Correct inaccurate or incomplete data. |
| Right to erasure (“right to be forgotten”) | Ask for your data to be deleted, within legal limits. |
| Right to restriction | Temporarily freeze the use of your data. |
| Right to portability | Receive your data in a structured format and pass it to a third party. |
| Right to object | Refuse the processing of your data on legitimate grounds, in particular for marketing. |
| Right to withdraw consent | At any time, for processing based on consent (newsletter, quiz). Withdrawal does not affect the lawfulness of earlier processing. |
| Right to give post-mortem instructions | Determine what happens to your data after your death. |
How to exercise your rights
Write to privacy@med-romania.com, stating the right you wish to exercise and enclosing a copy of an identity document (we may ask you to prove your identity to prevent impersonation).
We undertake to reply within one month of receiving your request. That period may be extended by two months for complex requests, in which case we will tell you.
If, after contacting us, you consider your rights are not being respected, you can lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), the French data protection authority — 3 Place de Fontenoy, 75007 Paris — www.cnil.fr. You may also lodge a complaint with the supervisory authority in your own country of residence.
8. Cookies and similar technologies
See our Cookie policy for details of the cookies used and how to manage them.
In summary:
- Strictly necessary cookies (session, language, consent): exempt from consent.
- Audience measurement cookies (Google Analytics, anonymised IP): subject to consent, via the cookie banner.
- Marketing cookies: we use none at launch. If that changes, you will be informed and your consent will be required.
9. Changes to this privacy policy
We may amend this policy, in particular where the law, regulations or technology change. The update date will be changed accordingly. We encourage you to check this page regularly.
In the event of a substantial change (a new purpose, a new recipient, and so on), we will actively inform you by email if you are in our contact database.
Last updated: 30 July 2026.