Privacy Policy

PRIVACY POLICY
EVENT: KAPITAL FESTIVAL
ORGANIZER: NEVERSEA PRODUCTION S.R.L
1. Introduction
1.1 The confidentiality of personal data is one of the main concerns within the Organizing companies. As such, we want to ensure the highest standards of confidentiality and transparency regarding the personal data we process in our day-to-day business.
1.2 Since it is necessary to process a series of personal data in the course of our activity, especially in relation to the specifics of our object of activity, we want to provide assurances that the processing will take place in compliance with the principles underlying the processing of personal data. This privacy policy is intended to help you understand what data we collect, why we collect it, and what we do with it.
2. Information about the Personal Data Controller
2.1 The organizing company of the Kapital event is Neversea Production S.R.L., with headquarters in Cluj-Napoca, 122A G-ral Eremia Grigorescu Street, Cluj-Napoca county. Cluj, registered in the Trade Register with no. J2023005035127, CUI: 49168377 (hereinafter referred to as "the Operator" or "we"). NEVERSEA PRODUCTION SRL acts as the controller of the personal data collected through the www.kapitalfestival.com website ("Site"), the Kapital application, the on-site check-in system, the means of video monitoring and the capture of photo and video images within the Festival by authorized persons.
2.2 The Controller is obliged to manage the data securely and only for the specified purposes.
3. What data do we process, the purpose of the processing and the retention period on each data category?
3.1.1. For the purpose of creating and accessing an account on www.kapitalfestival.com website, in the Kapital app and/or on external platforms such as Extasy.
- What data do we process? The phone number and cryptographic hash set (generated by applying the PBKDF2 encryption algorithm) related to the password set by the user so that they can log in to their account.
- Retention Duration: We will store this data for as long as you have an account on the Kapital website/app. We specify that to the extent that there is no request for anonymization of this data on the dpo@kapitalfestival.com, they will be anonymized in no more than 5 years from the last use of the account.
- Legal basis for processing: Art. 6 (1) lit. b - the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract.
3.1.2. For the purpose of purchasing a Kapital product or service.
- What data do we process? Name, surname, e-mail, telephone, country, city, address.
- Retention period: Until the general limitation period of 3 years from the end of the edition in which the ticket was purchased or the edition about which the problem was reported.
- Legal basis for processing: Art. 6 (1) lit. b - the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract.
3.1.3. For the purpose of purchasing products or services in installments or for saving the card for the purpose of carrying out future transactions.
- What data do we process? A secure card identifier (not the entire number), the card's expiration date, and the cardholder's name. Our payment processing service is responsible for encrypting and securing your card data.
- Retention Duration: For installment purchases, card data cannot be deleted from the system for as long as there are active payment installments associated with that card. After completing the last installment, the user can request the deletion of the card data. For the purpose of saving the card for the purpose of future purchases, the data is stored for the duration that the user keeps the card saved in his account. The user can request their deletion at any time, unless there are outstanding financial obligations associated with the card. However, this data will not be kept for a period longer than 3 years, which is the general limitation period applicable to the resolution of applications and possible investigations.
- Legal basis for processing: Art. 6 (1) lit. b - the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract.
3.1.4. For the purpose of returning the purchased products or solving a problem addressed to us.
- What data do we process? Name, surname, email, phone number, IBAN, and account holder name, as well as other information provided via email or other platforms to describe the issue.
- Retention period: Until the general limitation period of 3 years from the end of the edition in which the ticket was purchased or the edition about which the problem was reported.
- Legal basis for processing: Art. 6 (1) lit. b - the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract.
3.1.5. In the CHECK-IN process:
3.1.5.1 In order to ensure access to the festival perimeter and to provide the services to which the participant is entitled based on the ticket, to provide information on the aspects related to the organization and conduct of the event or any other offers and announcements in relation to the purchased product, to prevent fraud, misuse and to verify the validity of the ticket or subscription.
- What data do we process? Name, surname, e-mail, phone number, profile picture (except for minors under 18 years of age for whom a generic and impersonal image will be automatically set in the system) and the number of the ticket/bracelet for access to the festival.
- Retention Duration: Your profile picture will be deleted within 20 days of the end of the Festival. The other data will be anonymized within 3 years from the last edition in which the data subject participated in the Festival, if this has not been previously requested.
- Legal basis for processing: Art. 6 (1) lit. b - the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract.
3.1.5.2. For exclusively internal purposes for the preparation of reports and surveys, the organization of access areas, the creation of dedicated campaigns and activities, in order to respond to a request from the public authorities, for complaints or complaints.
- What data do we process? Gender, country, city, county, date of birth.
- Retention period: This data is kept in the Organizer's archive without being associated with a natural person following the irreversible anonymization of personal data.
- Legal basis for processing: Art. 6 (a) lit. f the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
3.1.6. For marketing purposes:
3.1.6.1. For commercial purposes of promoting Kapital's products and services.
- What data do we process? Name, surname, email address, phone number.
- Retention period: The data will be anonymized upon withdrawal of consent or at most within 4 years if the data subject no longer reacts to any commercial message.
- Legal basis for processing: Art. 6 (a) lit. f the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
3.1.6.2. For the purpose of subscribing to the Kapital Newsletter with the consent of the data subject.
- What data do we process? Email address.
- Retention Duration: Until you unsubscribe or withdraw your consent.
- Legal basis for processing: Art. 6 (1) (a) the data subject has given his/her consent to the processing of his/her personal data for one or more specific purposes.
3.1.5.3. For the purpose of conducting surveys to improve the quality of the services we offer, telephone calls may be recorded with the consent of the data subject.
- What data do we process? The voice of the data subject.
- Retention Duration: Recorded calls will be deleted within 30 days from the time of recording.
- Legal basis for processing: Art. 6 (1) (a) the data subject has given his/her consent to the processing of his/her personal data for one or more specific purposes.
3.1.7. In the REGISTER CAMPAIGN:
3.1.7.1. For the purpose of enrolling in the Register Campaign where the data subjects register in a community where they receive recurring information regarding the latest promotions, campaigns, announcements, ticket sales at promotional prices at the editions of the Kapital Festival.
- What data do we process? Name, surname, email address, phone number.
- Retention period: The data will be anonymized upon withdrawal of consent or at most within 4 years from the last edition in which the person registered for the campaign. If the data subjects have purchased a Ticket in this campaign, their personal data will be processed from this step forward in order to be able to ensure the purchased services and access to the Festival.
- Legal basis for processing: Art. 6 (1) lit. b - the processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject before concluding a contract.
3.1.7.2. For exclusively internal purposes for the preparation of reports and surveys, the organization of artistic moments, the creation of the concept of annual event, the creation of dedicated campaigns and activities.
- What data do we process? Gender, country, county, date of birth.
- Retention period: This data is kept in the Organizer's archive without being associated with a natural person following the irreversible anonymization of personal data.
- Legal basis for processing: Art. 6 (a) lit. f the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
3.1.8. In order to ensure the security of goods, spaces and people, video monitoring means are used in the perimeter of the festival.
- What data do we process? The image of the visitors at the event.
- Retention period: 20 days. Some data may be retained for a longer period if the retention is necessary for the investigation of fraud, for the defense of the legal rights of either Party or in situations where it is necessary to comply with requests made by the competent authorities.
- Legal basis for processing: Art. 6 (a) lit. f the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
3.1.9. For the taking of photographs and videos during the event, subsequently used for journalistic, informational, commercial, marketing and promotional purposes of the event, Kapital products and services or adjacent products and services, on its own behalf by Kapital or by any partner or sponsor of the Kapital Festival, as well as for the purpose of making NFTs (Non-fungible tokens) and selling them on the relevant market.
- What data do we process? The image of the visitors at the event.
- Retention period: Until the time of the deletion request from the data subject or at most 15 years from the moment of completion of the edition in which they were made.
- Legal basis for processing: Art. 6 (a) lit. f the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
3.1.10. For the purpose of organizing promotional campaigns and contests, as well as to ensure the sending of prizes.
- What data do we process? Name, surname, email, social media profile (if applicable), information included in comments within campaigns organized by the Organizer or in partnership with other partners.
- Retention period: Until the general limitation period of 3 years from the end of the campaign or contest has expired.
- Legal basis for processing: Art. 6 (a) lit. f the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
3.2 In addition to the aforementioned purposes, the Controller processes the personal data collected with the following purpose in mind:
- For the fulfillment of the legal obligations incumbent on us, as a result of the services provided (e.g. accounting, tax, audit obligations, etc.) these are always compatible with the main purposes, for which the data were collected.
- To the extent that the data subject has given consent to the processing of his or her personal data for one or more specific purposes.
- For any other purpose ancillary to the above, or for any other purpose for which the personal data has been provided to us, in compliance with the relevant legislation.
d. To protect us legitimate interests. taking precedence of the interests or fundamental rights and freedoms of the data subject, taking into account their reasonable expectations based on their relationship with the controller:
- To conduct market research and analysis that helps improve and personalize our products and services.
- For direct marketing purposes, to send communications of general interest or messages asking you to evaluate the quality of our services/products
- For the management of the company's activity, the preparation of internal reports that are used in the organization of the access areas and collection of bracelets of future editions, in order to organize dedicated campaigns and activities
- To prevent or detect misuse of our intellectual property, fraud, or other crimes.
- To ensure security at the event, to resolve complaints related to fraud, criminal or contravention complaints, complaints related to the sale of tickets, cases in which the Organizer needs to identify a person with the ticket number, to identify if that person entered the festival perimeter and at what time, or to defend the company's rights in court.
3.3 In situations where we use your personal data, we will for purposes other than those mentioned in this Policy, we undertake to obtain your consent, unless we have a legal obligation or have another legal basis for processing the data.
3.4 The Operator does not make individual profiles of the participants in the Kapital Festival.
4. How we collect your personal data personally?
4.1 We collect your personal data, either directly from you, for example, when you create an account on our website/app, send us an e-mail to ask@kapitalfestival.com address, through which you request an offer/information from us, give your consent to the communication of commercial messages, when you purchase a product, etc., or indirectly, For example, when you transmit this information on the platforms of other collaborators of our company, in the process of purchasing the ticket/subscription.
4.2 We collect your personal data and automatically, when you use our services on the Kapital website or app, we collect information through cookies and by logging your activity. For more information on the use of cookies, please refer to Art. 6 of this Policy.
4.3. If you choose to provide us with the personal data of other persons, such as when you purchase tickets on behalf of others, you assume responsibility for how you obtained this data and that you have a legal basis for processing it, and we cannot be held liable for the violation of the rights of those individuals.
5. How do we store personal data?
5.1 For the storage of personal data that you provide to us as a user of our website/application, a cloud service offered by Amazon Web Services EMEA S.A.R.L. is used.
5.2 At the same time, the data collected in the context of on-site check-in is stored by our partner Festipay Zrt. on its servers in the European Union.
6. USE OF COOKIES
6.1 The Website contains cookies (very small files sent to the computers of the users of the Website or other access devices).
6.2 There are two types:
6.2.1. Cookies according to their lifespan:
a) Session cookies
They are temporarily stored in the cookie folder of the web browser so as to keep them until the user leaves the respective website or closes the browser window (for example, when logging in/out of an email account or social media).
b) Persistent cookie-uri
They are stored on the hard drive of a computer or device (and generally depend on the default cookie lifespan). Persistent cookies also include those placed by a website different from the one the user is currently visiting – known as "third-party cookies" – which can be used anonymously to store a user's interests so that the most relevant advertising to users can be displayed.
6.2.2. Cookies according to their role
a) Strictly necessary cookies
These types of cookies are necessary for web pages to function properly. Strictly necessary cookies allow you to navigate the site and benefit from its functions. Without these cookies, we will not be able to provide certain functionalities, such as automatically forwarding to the server with the least congestion or remembering your list. of desires.
b) Functional cookies
Functional cookies record information about the choices users make and allow website operators to customize the website according to the user's requirements. For example, cookies can be used to save preferences regarding categories/segments.
c) Performance and analytics cookies
These types of cookies allow website operators to monitor visits and traffic sources, how users interact with the website or certain sections of the website.
The information provided by analytics cookies helps operators understand how visitors use websites and then use this information to improve how content provided to users is presented.
d) Advertising cookies
These cookies may provide the ability to monitor users' online activities and create profiles of them, which can then be used for marketing purposes. For example, cookies can be used to identify products and services approved by a user, and this information is then used to send appropriate advertising messages to that user.
6.3 Accessing the website implies the consent of users to place these types of cookies on their device and to access them on their next visit to the website.
6.4. In general, data on internet browsing activity is collected and analyzed anonymously. If this analysis reveals a specific interest, a cookie (small text file used by most sites to store certain useful information to improve the browsing experience) - is placed on the user's computer and this cookie determines what type of advertising the user will receive, which is called interest-based advertising.
6.5. You can see all the cookies used by our website in the Cookie Notice at the bottom of the page. You can withdraw your consent to the use of cookies at any time by changing the options in the appropriate cookie settings available. Blocking necessary cookies in your browser It may also not work properly. Disabling other types of cookies (other than those necessary) may also affect your operation or experience. in the use of the site.
6.6. The Website may use or implement third-party social media modules. Overall, your interaction with with such a module allows the third party to collect certain information about you, including your IP address, page header information, and browser information. The site has implemented the following social media buttons:
-> Facebook https://www.facebook.com/privacy
-> Instagram https://help.instagram.com/519522125107875
-> WhatsApp https://www.whatsapp.com/security
6.7. The Website uses Google Analytics, a web analytics service provided by Google Inc., with its registered office at 1600 Amphitheater Parkway, Mountain View, CA 94043, United States of America ("Google"). Based on your consent, Google will analyze on our behalf how you use our website. For this purpose, we use, among other things, the cookies detailed in the table above. The information that Google collects about how you use the website (e.g. the URL you provide, our web pages you visit, your browser type, language settings, operating system, screen resolution) will be sent to a Google server in the States.
7. To whom do we disclose personal data?
7.1 In order to fulfill the processing purposes, the Controllers may disclose your personal data to partners, to third parties or entities that support the Operators in carrying out the activity, or to central/local public authorities, in the following illustrative cases listed:
1. To our service providers and contractual partners, for example: providers of marketing (including surveys) and advertising services; our partner in charge of ensuring access to the Kapital Festival venue; IT service provider; courier services, payment services, banking services, payment services, ticket sales, etc. This data will be provided to the extent necessary and only on the basis of a confidentiality commitment on the part of the contractual partners, by which they guarantee that these data are kept secure and that their processing is carried out in accordance with the legislation in force;
2. To the accountants, auditors, lawyers, insurers or other such external advisors of the Operator. This data will be provided to the extent necessary and only on the basis of a confidentiality commitment on the part of the contractual partners, by which they guarantee that these data are kept secure and that their processing is carried out in accordance with the legislation in force;
3. Public authorities, institutions and bodies, where there is a lawful request from them or to the extent that there is a legal obligation on our part;
4. The Controller may disclose this data whenever required by law, or in the event that this is necessary to allow the exercise of the rights provided by law and/or to be able to take legal action against any illegal activity;
5. Your personal data may be transferred to third countries, based on the contractual relationships we have with our partners (both affiliates and other entities in the European Union) in order to produce statistics and other types of reports. To the extent that data is processed outside the European Union, we will ensure by contractual or other measures that such data enjoys an adequate level of protection there, comparable to that which it would enjoy in the European Union, in accordance with European regulations.
8. How long do we keep personal data?
8.1 As a matter of principle, we will only process your personal data for as long as necessary to achieve the processing purposes mentioned above. For more details about our Data Retention Policy for certain specific processing, please review the information in Art.3.
9. Your rights in relation to the processing of personal data:
9.1. Where the processing is based on consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal. Thus, you can change or withdraw consent at any time, and we will act immediately accordingly, unless there is a legal reason or legitimate interest not to do so.
9.2. If we process your data on the basis of our legitimate interest or that of third parties, you can object to that processing on grounds relating to your particular situation. In some cases, our legitimate interest or that of third parties may be above yours and we will not be able to accommodate your request to object to processing.
9.3. As a data subject, you benefit from a series of specific rights guaranteed by the General Data Protection Regulation no. 679/2016 (GDPR) and the legislation in force in Romania on the protection of personal data:
9.3.1. Right to information
Data subjects whose personal data is processed in the context of our specific activities have the right to receive information from us about the processing operations carried out in our capacity as data controller.
9.3.2. Right of access
You have the right to obtain confirmation from us as to whether or not we are processing personal data concerning you.
If we confirm that we hold your personal data, you have the right to access it and obtain a number of additional relevant information.
9.3.3. Right to rectification
You have the possibility to obtain from the data controller the rectification of inaccurate data concerning you or the completion of personal data that is incompletely recorded in our internal records.
9.3.4. Right to erasure of data ("right to be forgotten")
You have the right to request the erasure of the personal data we process about you. We must comply with this request if:
a) the personal data are no longer necessary for the fulfillment of the purposes for which they were collected;
b) you object to the processing on grounds relating to your particular situation;
c) the personal data have been unlawfully processed;
d) the personal data must be deleted in order to comply with a legal obligation incumbent on us, unless the data are necessary:
- for exercising the right to free expression and information;
- to comply with a legal obligation we have;
- for archiving purposes in the public interest, scientifically or for historical studies or for statistical purposes;
- for establishing, exercising or defending a right in court.
9.3.5. Right to restriction of processing
You can ask us to restrict the processing of your personal data when:
- contest the accuracy of the personal data we process, while we verify the accuracy of the data;
- the data processing is illegal, but instead of requesting the deletion of personal data you want to restrict their processing;
- personal data are no longer necessary for us to achieve the purpose for which they were processed, but you request those data from us for the establishment, exercise or defense of a legal claim;
- You have objected to the processing and request a restriction while we are verifying whether our legitimate interest in the processing prevails.
9.3.6. Right to data portability
You have the right to obtain your data from us in a structured, commonly used and machine-readable format.
9.3.7. Right to object
At any time, the data subject has the right to object, on grounds relating to his or her particular situation, to the processing. The controller no longer processes personal data, unless the controller demonstrates that it has compelling legitimate grounds justifying the processing and which override the interests, rights and freedoms of the data subject, or that the purpose is to establish, exercise or defend a claim in court.
You can object at any time to the processing of your personal data for direct marketing purposes, whatever your reason.
9.3.8. Right not to be subject to a decision based solely on automated processing, including profiling
This right is applicable where automated individual decision-making produces legal effects that concern or affect you to a significant extent.
9.3.9. Right to lodge a complaint
If you have a complaint about the way we process your personal data, please contact us so that we can resolve your issue using the following contact details:
- E-mail: dpo@kapitalfestival.com
- Address: str. G-ral Eremia Grigorescu, nr. 122 A, Cluj-Napoca, Cluj County.
You can also contact the National Supervisory Authority for Personal Data Processing through their website www.dataprotection.ro.
Please note the following aspects of interest, related to the method of analysis and response to the request for the exercise of rights:
We will make every effort to respond to your request within 30 days. This period may be extended due to reasons related to the specific legal right invoked or the complexity of your request by a maximum additional period of two months. In any case, if the legal deadline for response is extended, then we will inform you of the new deadline and the reasons that led to this extension.
10. Information Security
10.1 We work hard to protect our website, app and users, as well as all personal data collected under this Policy, from unauthorized access to or alteration, unauthorized disclosure or destruction of information held by us.
10.2. The Controller guarantees that it has implemented technical and organisational measures appropriate to the processing activities it carries out, in order to protect the personal data, against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access thereto, transmission, storage or processing in any other unlawful manner.
10.3. In this regard:
- The Controller certifies that it meets the minimum requirements for the security of personal data, the data being processed in a way that ensures protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, by taking appropriate technical or organizational measures;
- For the data collected through the website and the application, in order to ensure access to the festival, the Operator uses a cloud service offered by Amazon Web Services EMEA SARL. Thus, the security settings offered by Amazon are used. Data access is made in a white-list of security groups, which means that data can only be accessed from certain pre-defined IP addresses. Access is based on username and password, and at the level of the co-organizing companies, access to the database is allowed to a limited number of people.
- The data storage systems used have back-up mechanisms in place to ensure the redundancy of the stored data.
- We regularly review information collection, storage, and processing practices, including physical information, as well as security measures, to prevent unauthorized access to systems.
- We restrict our employees and contractors' access to your information. and contractual relations with these persons are subject to strict rules regarding contractual confidentiality obligations, including under penalty of termination of contracts.
11. When does this Privacy Policy apply?
11.1 Our Privacy Policy applies to all services offered by our company and excludes services that have separate privacy policies and do not contain the provisions of this Privacy Policy.
12. Changes
12.1 We will post any changes to the privacy policy on our website, which will take effect within one day and, if the changes are material, we will provide a more prominent notice (including, for certain services, email notification of changes to the privacy policy).
12.2. We will also retain previous versions of this Privacy Policy in the archive so that it can be reviewed by you at any time.
The most recent update of this Policy was made on 18.11.2025.


