for parents / adults

Privacy & Cookies Policy EDESSENCE S.R.L.

Last updated: Nov. 4th 2025

1. Introduction

EDESSENCE SRL (“we”, “us”, “our”) is committed to protecting the personal data and privacy of all users of our website and services.
This Privacy & Cookies Policy explains how we collect, use, disclose, store, and protect your personal data, in accordance with Regulation (EU) 2016/679 (“General Data Protection Regulation” – GDPR) and other applicable data protection laws.

2. Identity of the Data Controller

The data controller responsible for processing your personal data is:

EDESSENCE SRL
Registered office: 49–57 Grigore Gafencu St., Entrance A, 6th Floor, Apt. A62, Sector 1, Bucharest, Romania
Trade Register No.: J2025073062001
Email: privacy@edessence.eu

3. Categories of Data Collected

We process categories of personal data including but not limited to:

  • Identification data: name, date of birth, national ID/passport number (for travel documents), nationality;
  • Contact data: postal address, e-mail, telephone numbers;
  • Education data: school, year/class, academic interests;
  • Health and special needs (sensitive): dietary requirements, allergies, medical conditions, medication, emergency contact health info, processed only where strictly necessary for safe participation;
  • Travel and logistics: passport/visa details, travel insurance details, travel reservations;
  • Financial & transactional data: payment details (card token, payment confirmations), card data handled by PCI-DSS compliant processors;
  • Communications & media: photos/videos taken during programs if consented;
  • Online identifiers & cookies: IP address, device identifiers, analytics cookies.

Sensitive categories (health, biometric where applicable) are processed only with appropriate legal basis and safeguards.

Note on children: when services are offered directly to children under the age of digital consent applicable in their Member State, we obtain verifiable parental consent before collecting personal data from children). Specific age thresholds may vary by Member State. We implement parental verification procedures accordingly.

4. Purpose and Legal Basis of Processing

We process personal data for the following purposes and on the following legal bases (non-exhaustive):

  1. To perform contract(s) with parents/participants (booking, transport, accommodation, program delivery): lawful basis: performance of a contract (GDPR Art. 6(1)(b)). 
  2. To comply with legal obligations (immigration control, safety reporting, health/safety regulations): lawful basis: compliance with legal obligations (Art. 6(1)(c)). 
  3. To protect vital interests (medical emergencies): lawful basis: vital interests (Art. 6(1)(d)); processing of health data where necessary to provide urgent care (Art. 9(2)(h)). 
  4. Parental consent for minors: where required by law (processing of a child’s data for information society services, or where explicit consent is needed for special categories), we rely on parental consent and verification procedures (GDPR Art. 8 and EDPB/Guidelines on children). 
  5. Legitimate interests (limited, balanced assessment) for operational needs, fraud prevention, communications about similar programs, where we rely on legitimate interests, we document balancing tests and provide opt-outs. (GDPR Art. 6(1)(f)). 
  6. Where we ask for explicit consent (e.g., marketing communications, optional photography, certain cookies): lawful basis: consent (Art. 6(1)(a); consent for special categories where required: Art. 9(2)(a)). We implement consent in line with EDPB guidance.

5. Data Retention Period

We retain personal data only as long as necessary for the purpose for which they were collected, considering legal obligations and legitimate business needs. Indicative retention examples (subject to final operational policy):

  • Bookings and contractual records: 10 years (for insurance/tax/accounting recordkeeping), adjust per national tax/accounting rules;
  • Medical / emergency records: duration of activity + as required for legal claims;
  • Marketing data: until consent withdrawal or objection;
  • Cookies: per cookie category (analytics 12 months typical, marketing 12–24 months depending on provider).

After this period, data will be securely deleted or anonymised.

6. Disclosure of Data

Your personal data may be shared with:

  • Service providers (transport, accommodation, insurance etc.);
  • IT and hosting providers ensuring website functionality and security;
  • Competent authorities when required by law;
  • Other travel partners within or outside the EEA, only under adequate safeguards (e.g., Standard Contractual Clauses).

We ensure that all recipients guarantee the confidentiality and protection of your data.

7. Data Transfers Outside the EEA

There is no data transfered outside the EEA at this time, but if transfers outside the European Economic Area should occur, we ensure adequate protection through one of the following mechanisms:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses (SCCs);
  • Explicit consent from the data subject (when no other legal basis applies).

8. Data Security

We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorised access.
Such measures include data encryption, access controls, pseudonymisation, and regular security audits.

9. Data Subjects’ Rights

You have the following rights under the GDPR:

  • Right of access to obtain confirmation and access to your personal data;
  • Right to rectification to correct inaccurate or incomplete data;
  • Right to erasure (“right to be forgotten”);
  • Right to restriction of processing;
  • Right to data portability;
  • Right to object to certain types of processing (e.g., direct marketing);
  • Right to withdraw consent at any time, where processing is based on consent;
  • Right to lodge a complaint with a supervisory authority (ANSPDCP or your local EU authority).

10. Processing of Children’s Data

We take special care to protect children’s data.

We do not knowingly collect or process personal data from children under 18 without verified parental consent.

Parents or legal guardians may request deletion of their child’s data by contacting us at privacy@edessence.eu.

11. Updates to This Policy

We may update this Privacy & Cookies Policy from time to time to reflect changes in our practices or in applicable legislation.
Any update will be published on this page with a revised “last updated” date.

12. Cookie Policy

12.1 What is a Cookie?

A “cookie” is a small text file containing letters and numbers that is stored on a user’s device when visiting a website.
Cookies are sent by a web server to your browser and stored locally; they cannot run programs or deliver viruses.
They serve to make your browsing experience more efficient and personalized.

There are three main categories of cookies:

  • Session cookies: temporary, deleted when the browser is closed;
  • Persistent cookies: remain stored until they expire or are deleted manually;
  • Third-party cookies: set by domains other than the one you are visiting.

12.2 Why We Use Cookies

We use cookies to:

  • Recognize returning visitors and improve user experience;
  • Store user preferences (language, display settings);
  • Enable essential website functionality (e.g., login, shopping cart);
  • Analyse site traffic and performance;
  • Manage cookie consent preferences.

12.3 Cookies Used on This Website

Functional / Session Cookies

Cookie

Source

Duration

Purpose

_lscache_vary

LiteSpeed

2 days

Prevents cached page display; ensures up-to-date content.

cmplz_functional

local

1 year

Stores user consent for functional cookies.

cmplz_preferences

local

1 year

Stores user consent for preference cookies.

cmplz_banner-status

local

1 year

Records the cookie banner’s acceptance or rejection status.

cmplz_consented_services

local

1 year

Stores user’s consent preferences for various services.

cmplz_marketing

local

1 year

Stores user consent for marketing cookies.

cmplz_statistics

local

1 year

Stores user consent for statistical cookies.

Analytics Cookies

Cookie

Source

Duration

Purpose

_ga

Google Analytics

2 years

Collects anonymous data about site usage and interactions.

ga*

Google Analytics

2 years

Tracks anonymous session and event data for analytics.

Marketing Cookies

These cookies are used to build user profiles and deliver personalized advertising across sites.

12.4 Data Collected Through Cookies

Cookies may collect anonymous information such as:

  • Session ID, browser type, referral page, time of access, and preferences;
  • Aggregated statistics on user activity (pages visited, time on site etc.).

12.5 Importance of Cookies

Cookies are essential for the efficient functioning of websites.
They allow tailored content, relevant advertising, and analytics for performance improvement.
Disabling cookies may limit functionality or prevent certain services from operating correctly.

12.6 Cookie Security and Privacy

Cookies are plain text files and cannot execute code.
While cookies cannot harm your system, they may be used to track browsing behaviour; for this reason, most browsers include privacy settings to manage or delete cookies.

12.7 How to Manage or Disable Cookies

You can manage cookie settings directly from your browser:

  • Internet Explorer: Manage cookies
  • Mozilla Firefox: Manage cookies
  • Google Chrome: Manage cookies
  • Apple Safari: Manage cookies

For general guidance, please visit: www.allaboutcookies.org