Legal · GDPR

Privacy Policy

In accordance with Regulation (EU) 2016/679 (GDPR)

Last updated: 19 July 2026

1. Data controller

WERRO is the controller of the personal data collected on this platform, in accordance with Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018.

Name: WERRO

GDPR contact: gdpr@werro.ro

General contact: contact@werro.ro

2. The data we collect

At registration:

  • Full name, email address, phone number
  • City and county of residence
  • Role on the platform (client or artist)
  • For artists: stage name, artistic category, location, price, biography, photo gallery

When booking:

  • Event details: date, location, event type, number of guests, special requirements
  • Details of the payment method agreed between the client and the artist
  • When a booking is confirmed, contact details (name and phone number) are shared between client and artist so they can coordinate the event directly — see section 4

Collected automatically:

  • IP address, browser type, operating system (for security and debugging)
  • Session cookies strictly necessary for authentication
  • Activity logs (technical logs)

3. How we use the data and the legal basis

PurposeLegal basis (GDPR)
Account authentication and securityArt. 6(1)(b) — performance of the contract
Processing bookingsArt. 6(1)(b) — performance of the contract
Transactional notificationsArt. 6(1)(b) — performance of the contract
Sharing contact details (phone number) between client and artist for a confirmed booking, in order to coordinate the eventArt. 6(1)(b) — performance of the contract
Generating digital contractsArt. 6(1)(c) — legal obligation (Law 455/2001)
Invoicing and accounting recordsArt. 6(1)(c) — legal obligation
Marketing and newsletterArt. 6(1)(a) — consent (explicit opt-in)
Improving the platformArt. 6(1)(f) — legitimate interest

4. Who we share data with

Between client and artist (the parties to a booking)

When a booking is confirmed, WERRO shares the strictly necessary contact details between the two parties involved — name and phone number — so that the client and the artist can coordinate directly regarding the event (confirmations, schedule changes, unforeseen situations on the day). These details appear in the transactional confirmation and event reminder emails.

Legal basis: Art. 6(1)(b) GDPR — performance of the contract between client and artist.

What is shared: name and phone number. The email address, password and other account data are not shared.

When: only after the booking is confirmed. For unconfirmed requests, contact details are not disclosed to the other party.

Purpose: coordinating the event only. Using these details for any other purpose (e.g. the other party's own marketing) is not permitted.

From the moment they receive it, each party becomes an independent controller for the other party's contact data and is responsible for using it in accordance with the GDPR. You may object to this sharing by writing to gdpr@werro.ro, but note that without contact details it is not possible to coordinate the event directly.

With contracted processors

We also share data with authorised contracted processors, under standard GDPR contractual clauses:

Supabase Frankfurt, Germany (EU)

Database hosting and authentication

Resend USA (with SCCs)

Sending transactional emails

Vercel USA (with SCCs)

Web platform hosting

We do not sell data to third parties. We do not use data for advertising or tracking.

5. Your rights under the GDPR

Under Regulation (EU) 2016/679 you have the following rights, which you can exercise free of charge:

Right of access (Art. 15)

You can request a copy of all the data we hold about you, in JSON format.

Right to rectification (Art. 16)

You can correct inaccurate data in your account at any time.

Right to erasure / "right to be forgotten" (Art. 17)

You can request the deletion of your account. Data is deleted within 30 days, except for data kept under a legal obligation (invoices: 5 years).

Right to restriction of processing (Art. 18)

You can request that the processing of your data be temporarily suspended.

Right to data portability (Art. 20)

You can receive your data in a structured, machine-readable format (JSON/CSV).

Right to object (Art. 21)

You can object to processing based on legitimate interest, including marketing.

Withdrawal of consent

Where processing is based on consent, you can withdraw it at any time without any consequences.

Send your requests to gdpr@werro.ro. We reply within 30 days at the latest.

You also have the right to lodge a complaint with ANSPDCP (the Romanian data protection authority) — www.dataprotection.ro.

6. Cookies

We use only cookies that are strictly necessary for the platform to work:

CookiePurposeDuration
sb-auth-tokenSupabase authentication (user session)Session / 7 days
cookie-consentRemembering your cookie preference1 year

We do not use third-party tracking, advertising or analytics cookies.

7. Security

We apply appropriate technical and organisational measures to protect the data:

  • HTTPS across the whole platform (TLS 1.3)
  • Passwords hashed with bcrypt
  • Row Level Security (RLS) on the database
  • Data access restricted through strict authorisation policies

8. Data retention

Data categoryRetention period
Active account dataFor as long as the account exists
Data after account deletion30 days (grace period)
Invoicing data5 years (legal tax obligation)
Digital contracts5 years (Law 455/2001)
Technical logs12 months
Marketing data (with consent)Until consent is withdrawn

9. International data transfers

Some processors (Vercel, Resend) are located in the USA. Transfers are made with appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfer impact assessments (TIAs) carried out
  • Minimisation of the data transferred outside the EU

10. Contact and DPO

Data Protection Officer (DPO): gdpr@werro.ro

General support: contact@werro.ro

ANSPDCP: www.dataprotection.ro

See also: Terms and Conditions →