Legal · GDPR
Privacy Policy
In accordance with Regulation (EU) 2016/679 (GDPR)
Last updated: 19 July 2026
1. Data controller
WERRO is the controller of the personal data collected on this platform, in accordance with Regulation (EU) 2016/679 (GDPR) and Romanian Law no. 190/2018.
2. The data we collect
At registration:
- Full name, email address, phone number
- City and county of residence
- Role on the platform (client or artist)
- For artists: stage name, artistic category, location, price, biography, photo gallery
When booking:
- Event details: date, location, event type, number of guests, special requirements
- Details of the payment method agreed between the client and the artist
- When a booking is confirmed, contact details (name and phone number) are shared between client and artist so they can coordinate the event directly — see section 4
Collected automatically:
- IP address, browser type, operating system (for security and debugging)
- Session cookies strictly necessary for authentication
- Activity logs (technical logs)
3. How we use the data and the legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Account authentication and security | Art. 6(1)(b) — performance of the contract |
| Processing bookings | Art. 6(1)(b) — performance of the contract |
| Transactional notifications | Art. 6(1)(b) — performance of the contract |
| Sharing contact details (phone number) between client and artist for a confirmed booking, in order to coordinate the event | Art. 6(1)(b) — performance of the contract |
| Generating digital contracts | Art. 6(1)(c) — legal obligation (Law 455/2001) |
| Invoicing and accounting records | Art. 6(1)(c) — legal obligation |
| Marketing and newsletter | Art. 6(1)(a) — consent (explicit opt-in) |
| Improving the platform | Art. 6(1)(f) — legitimate interest |
4. Who we share data with
Between client and artist (the parties to a booking)
When a booking is confirmed, WERRO shares the strictly necessary contact details between the two parties involved — name and phone number — so that the client and the artist can coordinate directly regarding the event (confirmations, schedule changes, unforeseen situations on the day). These details appear in the transactional confirmation and event reminder emails.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract between client and artist.
What is shared: name and phone number. The email address, password and other account data are not shared.
When: only after the booking is confirmed. For unconfirmed requests, contact details are not disclosed to the other party.
Purpose: coordinating the event only. Using these details for any other purpose (e.g. the other party's own marketing) is not permitted.
From the moment they receive it, each party becomes an independent controller for the other party's contact data and is responsible for using it in accordance with the GDPR. You may object to this sharing by writing to gdpr@werro.ro, but note that without contact details it is not possible to coordinate the event directly.
With contracted processors
We also share data with authorised contracted processors, under standard GDPR contractual clauses:
Supabase — Frankfurt, Germany (EU)
Database hosting and authentication
Resend — USA (with SCCs)
Sending transactional emails
Vercel — USA (with SCCs)
Web platform hosting
We do not sell data to third parties. We do not use data for advertising or tracking.
5. Your rights under the GDPR
Under Regulation (EU) 2016/679 you have the following rights, which you can exercise free of charge:
Right of access (Art. 15)
You can request a copy of all the data we hold about you, in JSON format.
Right to rectification (Art. 16)
You can correct inaccurate data in your account at any time.
Right to erasure / "right to be forgotten" (Art. 17)
You can request the deletion of your account. Data is deleted within 30 days, except for data kept under a legal obligation (invoices: 5 years).
Right to restriction of processing (Art. 18)
You can request that the processing of your data be temporarily suspended.
Right to data portability (Art. 20)
You can receive your data in a structured, machine-readable format (JSON/CSV).
Right to object (Art. 21)
You can object to processing based on legitimate interest, including marketing.
Withdrawal of consent
Where processing is based on consent, you can withdraw it at any time without any consequences.
Send your requests to gdpr@werro.ro. We reply within 30 days at the latest.
You also have the right to lodge a complaint with ANSPDCP (the Romanian data protection authority) — www.dataprotection.ro.
7. Security
We apply appropriate technical and organisational measures to protect the data:
- HTTPS across the whole platform (TLS 1.3)
- Passwords hashed with bcrypt
- Row Level Security (RLS) on the database
- Data access restricted through strict authorisation policies
8. Data retention
| Data category | Retention period |
|---|---|
| Active account data | For as long as the account exists |
| Data after account deletion | 30 days (grace period) |
| Invoicing data | 5 years (legal tax obligation) |
| Digital contracts | 5 years (Law 455/2001) |
| Technical logs | 12 months |
| Marketing data (with consent) | Until consent is withdrawn |
9. International data transfers
Some processors (Vercel, Resend) are located in the USA. Transfers are made with appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfer impact assessments (TIAs) carried out
- Minimisation of the data transferred outside the EU
10. Contact and DPO
Data Protection Officer (DPO): gdpr@werro.ro
General support: contact@werro.ro
ANSPDCP: www.dataprotection.ro
See also: Terms and Conditions →