Privacy policy

Protecting your personal data sits at the heart of our transparency commitments. This privacy policy describes how Med Romania collects, processes and protects the information you entrust to us, in accordance with the General Data Protection Regulation (GDPR — Regulation (EU) 2016/679) and French Law No. 78-17 of 6 January 1978 as amended (the “Data Protection Act”).


1. Who is the data controller?

FieldValue
Data controllerMed Romania
Address[To be completed]
Contact emailprivacy@med-romania.com

2. What data do we collect?

2.1 Data you give us directly

When you use our forms (contact, eligibility quiz, guide download, order), we collect the following data:

  • Contact form: first name, surname, email address, phone number (optional), country of residence, message content.
  • Eligibility quiz: country of origin, type of school-leaving qualification or equivalent, subject stream, year obtained, language(s) spoken, intended budget, target university or universities and programme(s).
  • Guide download: email address, first name.
  • Service order: first name, surname, email address, postal address, phone number, academic documents (transcripts, diplomas, ID document), payment information.

2.2 Data collected automatically

As you browse the Site, we automatically collect:

  • Browsing data: IP address (anonymised), browser type, pages visited, time spent, traffic source (referrer).
  • Strictly necessary cookies: session cookie, language preference cookie, cookie consent cookie.

This data is collected through Google Analytics 4 (with IP address anonymisation enabled) and through our host’s technical logs.

2.3 Data we do NOT collect

  • We collect no special category data within the meaning of the GDPR (health data, political opinions, religious beliefs, etc.) beyond the academic documents strictly necessary for your admission file.
  • We neither request nor store bank card details. Payments are handled by a PCI-DSS certified provider (Stripe). We never have access to your full card number.

PurposeData concernedLegal basis
Answering your contact enquiriesName, email, messageLegitimate interest (responding to an enquiry)
Sending you the free PDF guideEmail, first nameConsent (tick box)
Delivering a personalised eligibility assessmentQuiz dataConsent (tick box)
Sending you the newsletter and nurturing emailsEmailConsent (separate tick box)
Processing your order and performing the service contractOrder data, academic documentsPerformance of a contract (terms of sale)
Following up your admission fileAcademic documents, correspondencePerformance of a contract (terms of sale)
Measuring Site audienceAnonymised browsing dataLegitimate interest (improving the service)
Keeping the Site secureIP address, technical logsLegitimate interest (security)

Important: the tick box for the newsletter and nurturing emails is separate from the box for the service you requested. You can receive the guide or your quiz result without subscribing to the newsletter.


4. How long do we keep your data?

Type of dataRetention period
Contact data (form)3 years from the last exchange
Eligibility quiz data3 years from quiz submission
Account and order data5 years from the end of the contractual relationship (legal obligation)
Academic documents3 years after the end of the contractual relationship, then deleted
Browsing data (anonymised)14 months maximum (Google Analytics 4)
Technical logs12 months

At the end of these periods, data is deleted or irreversibly anonymised.


5. Who do we share your data with?

Med Romania undertakes never to sell, rent or trade your personal data. Your data is shared only in the following strictly necessary cases:

RecipientData sharedWhy
Partner sworn translator (Romania)Academic documentsOfficial translation for the admission file
Romanian legal partner (where mandated)Identity documentsLegalisation, filing of the application
Stripe (payment provider)Amount, transaction IDPayment processing (PCI-DSS)
Google (Analytics)Anonymised IP address, browsingAudience measurement
Cloudflare (host)IP address, logsHosting and Site security
Romanian universities (UMF)The applicant’s complete fileFiling the application (with your explicit consent)

All our processors are bound by a GDPR-compliant data processing agreement. For transfers outside the EU (United States: Google, Cloudflare, Stripe), we ensure the processor adheres to the Data Privacy Framework (successor to the Privacy Shield) or uses standard contractual clauses approved by the European Commission.


6. How do we protect your data?

We implement appropriate technical and organisational measures:

  • TLS/SSL encryption (HTTPS) across the whole Site.
  • Restricted access to personal data: only authorised people (team members with a need to know) can access it.
  • Strong authentication on all internal tools.
  • Anonymisation of IP addresses in Google Analytics.
  • Regular encrypted backups.
  • A breach notification procedure: in the event of a breach presenting a risk to your rights and freedoms, we will inform you within 72 hours, in accordance with Article 34 of the GDPR.

7. What are your rights?

Under the GDPR, you have the following rights:

RightWhat it means
Right of accessObtain confirmation that your data is being processed and receive a copy of it.
Right to rectificationCorrect inaccurate or incomplete data.
Right to erasure (“right to be forgotten”)Ask for your data to be deleted, within legal limits.
Right to restrictionTemporarily freeze the use of your data.
Right to portabilityReceive your data in a structured format and pass it to a third party.
Right to objectRefuse the processing of your data on legitimate grounds, in particular for marketing.
Right to withdraw consentAt any time, for processing based on consent (newsletter, quiz). Withdrawal does not affect the lawfulness of earlier processing.
Right to give post-mortem instructionsDetermine what happens to your data after your death.

How to exercise your rights

Write to privacy@med-romania.com, stating the right you wish to exercise and enclosing a copy of an identity document (we may ask you to prove your identity to prevent impersonation).

We undertake to reply within one month of receiving your request. That period may be extended by two months for complex requests, in which case we will tell you.

If, after contacting us, you consider your rights are not being respected, you can lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL), the French data protection authority — 3 Place de Fontenoy, 75007 Paris — www.cnil.fr. You may also lodge a complaint with the supervisory authority in your own country of residence.


8. Cookies and similar technologies

See our Cookie policy for details of the cookies used and how to manage them.

In summary:

  • Strictly necessary cookies (session, language, consent): exempt from consent.
  • Audience measurement cookies (Google Analytics, anonymised IP): subject to consent, via the cookie banner.
  • Marketing cookies: we use none at launch. If that changes, you will be informed and your consent will be required.

9. Changes to this privacy policy

We may amend this policy, in particular where the law, regulations or technology change. The update date will be changed accordingly. We encourage you to check this page regularly.

In the event of a substantial change (a new purpose, a new recipient, and so on), we will actively inform you by email if you are in our contact database.


Last updated: 30 July 2026.