Home|Privacy Policy
Last updated on 05.05.2025
Please read this Privacy Policy (hereinafter referred to as the “Policy”) carefully as it contains important information regarding how, when, and why North Star Support Group SRL collects, uses, and stores your personal data, with whom it may share it, as well as to inform you about your rights as a data subject and the measures taken to protect your personal data, in connection with North Star Support Group SRL’s processing over its website, and services.
Accessing and/or using North Star Support Group SRL website, and services by any person imposes the obligation to comply with the provisions set forth in the Terms and Conditions.
The website https://nssg.global/gdpr/ (hereinafter referred to as the “Website”) is owned and managed by North Star Support Group SRL, a company incorporated by Romanian laws, headquartered at 26, Grigore Alexandrescu Street, Bucharest, Romania.
This Policy regarding the processing of personal data only applies to the processing activities performed by North Star Support Group SRL and shall be complemented with the Terms and Conditions and the Cookie Policy.
The Website may contain information about or links to other websites that are outside North Star Support Group SRL custody and/or control. Carefully read and review the privacy policies of each of those websites when you browse on them to get an understanding of how your personal data is being used and shared by those third-party websites.
The terms used within this Policy have the same meanings as those mentioned in Terms and Conditions, unless otherwise mentioned in this Policy.
In general, the personal data we process is collected directly from you, as a data subject. However, there may be situations where your personal data is collected indirectly from social media, from the website of the company you represent, from your employer as a contact person, from a third party who recommended you or from various public platforms (for example ad platforms).
When we, as the Controller, do not receive the personal data directly from you, we will inform you within the legal term about our processing of your personal data.
If you provide us with personal data belonging to other individuals (for example, colleagues), you have the responsibility to make sure you have obtained prior approval from those persons for sharing their data with us.
Our Website and Services are not directed at children. We do not knowingly or intentionally collect personal data from children who have not reached the level of maturity in their country and who are not able to assume obligations in accordance with the applicable legislation.
If you are the holder of parental responsibility of a child who has not reached the level of maturity in the country of residence and you believe your child has provided us with personal data, please contact us to request the erasure of their personal data and we will act upon your request in accordance with the legal requirements.
Depending on the acquired service, we may also collect special categories of personal data (personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, data concerning health, or personal data relating to criminal convictions and offences or related security measures) but only if this is strictly necessary to protect your vital interests where you are physically or legally incapable of giving consent, or for the provision of health care or treatment, or based on your consent.
We do not collect nor is our intention to collect personal data revealing trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning a natural person’s sex life or sexual orientation, excepting the situations expressly regulated by the law.
Below you will find information about the purposes for which we process your personal data, the categories of personal data we collect for those purposes, the legal grounds on which we carry out the processing activities and the periods of time we store the personal data in relation to the purposes of the processing.
We will inform you and, where the lawful basis is your consent, we will ask for your freely given consent. If we intend to process your personal data for a new purpose that is materially different from that for which the personal data was initially collected, we will comply with all legal requirements regarding the lawfulness of processing, including obtaining your consent, if applicable.
Where the lawful basis for the processing is your consent, you may withdraw it at any time without constraint and without affecting the lawfulness of the processing prior to its withdrawal.
You may refuse to provide part or all of your personal data. Certain personal data are essential to fulfill the purposes below and your refusal to provide necessary information may result in our impossibility to deliver the Services requested.
Depending on the nature of our relationship or interaction, we will process your personal data for the following purposes.
Personal data categories: first name, last name, e-mail address, company name, job title.
Legal basis: processing of personal data is performed based on your consent or considering our legitimate interests when we have a business or commercial reason to contact you.
Retention period: personal data will be processed until you withdraw your consent or object to the processing, after which personal data will be deleted where there is no other legal ground for the processing. You can withdraw your consent or object to the processing at any time, by clicking Unsubscribe/Opt-out at the bottom of any of our emails, without affecting the legality of the processing based on the consent or our legitimate interests before withdrawal or objection.
Personal data categories: first name, last name, e-mail address, company name, job title, phone number, and any other personal data that you choose to include in your request.
Legal basis: processing of personal data is performed based on our legitimate interest to communicate with you and provide our support in solving your requests that arise from using/accessing our services, and to maintain and promote your satisfaction in relation to our services.
Retention period: personal data is stored for as long as we have an existing contractual relationship in place with you or with your company and subsequently for a period of 3 (three) years after its termination. If we don’t have a contractual relationship yet, but you choose to contact us, we will store your personal data for a period of 6 (six) months after which it will be deleted.
Personal data categories: first name, e-mail address, company name, job title
Legal basis: processing of personal data is necessary for the performance of the contract (represented by the Terms and Conditions) concluded with you.
Retention period: personal data is stored for a duration of 6 months from the date of the NSSG Talk/Podcast.
Personal data categories: first name, last name, e-mail address, telephone number, country of residence, job title, information on professional experience, information on studies, diplomas, certifications, profile on a professional social network (e.g., LinkedIn), and any other data included in the CV.
Legal basis: processing of personal data is performed based on our legitimate interest to ensure that only qualified and reliable people are selected to provide the services.
Retention period: personal data is stored during the execution of the contract. At the end of the storage period, personal data will be deleted.
Personal data categories: first name, last name, powers of representation, and any other personal data included in the documents certifying the role of legal representative of the company.
Legal basis: processing of personal data is performed based on our legitimate interest to conclude the contract for the provision of services, as well as to ensure that the person signing the contract has full authority to represent the company, and to avoid contractual fraud.
Retention period: personal data is stored during the execution of the contract. At the end of the storage period, the personal data will be deleted.
If, following the checks carried out, we decide not to conclude the service contract with the company you represent, we will proceed to delete your personal data.
Personal data categories: first name, last name, e-mail address, job title, telephone number, signature, image (if the case).
Legal basis: processing of personal data is necessary for the performance of the service contract to which you are party when you are contracting as an individual, or based our legitimate interest to conclude the service contract with the company that you represent.
Retention period: personal data is stored during the execution of the service contract and subsequently for a period of 3 (three) years. At the end of the storage period, personal data will be deleted.
Personal data categories: first name, last name, bank account, bank where the account is opened.
Legal basis: processing of personal data is necessary for the performance of the service contract to which you are party.
Retention period: personal data is stored for a duration of 10 years according to the accounting legislation.
Personal data categories: first name, last name, e-mail address, company, job title, telephone number.
Legal basis: processing of personal data is performed based on our legitimate interest to communicate with you and to offer you support in resolving requests arising from the execution of the service contract.
Retention period: personal data is stored during the execution of the service contract, as well as subsequently for a period of 3 (three) years from the termination of the service contract. At the end of the storage period, the data will be deleted.
Personal data categories: first name, last name, e-mail address, telephone number, date of reporting, object of reporting, signature (if applicable), voice (recorded) (if applicable), manner of resolution, as well as any other data subject to reporting.
Legal basis: processing of personal data is performed for the fulfillment of our legal obligations under the legislation on the protection of whistleblowers in the public interest to ensure and maintain internal reporting channels on breaches of law, corroborated with our legitimate interest to ensure that violations of applicable laws or regulations, including violations of our Code of Conduct, are dealt with properly and in a timely manner in order to protect the Controller, employees, customers etc. from the effect of the illicit facts, corroborated with the consent of the data subject for recording the conversation (if the report is made using a telephone line or other voice messaging system) and disclosure of the identity of the data subject and of any other information that would allow his direct or indirect identification.
Retention period: personal data is stored for a period of 5 (five) years from the reporting date, according to the legislation on the protection of whistleblowers in the public interest. At the end of the storage period, personal data will be deleted.
5.10 Purpose: monitor and ensure compliance with the contractual obligations, internal regulations, procedures, and policies of the Controller.
Personal data categories: first name, last name, e-mail address, telephone number, brand, access logs, user name, used data (related costs), traffic data (data processed for the purpose of transmitting a communication over an electronic communications network, such as telephone number, IP address, terminal equipment identifier, call duration data, data traffic volume, date and time of the call), IMEI mobile terminal, internal ID number, location data (such as WiFi access points), first name, last name, signature, information on the conflicts of interest, etc.
Legal basis: processing of personal data is performed based on our legitimate interest to conduct and protect our activity, to prevent potential violations and to ensure that our partners comply with the obligations regulated by the contract service, our internal regulations, procedures, and policies.
Retention period: personal data is stored for the duration of the service contract. At the end of the storage period, personal data will be deleted.
5.11 Purpose: record and investigate security incidents/breaches and prepare reports for fraudulent, criminal or corporate policy violations.
Personal data categories: first name, last name, e-mail address, telephone number, internal ID number, access logs, user name, used data (related costs), traffic data (data processed for the purpose of transmitting a communication over an electronic communications network, such as telephone number, IP address, terminal equipment identifier, call duration data, data traffic volume, date and time of the call), IMEI mobile terminal (location data (such as WiFi access points), video images, arrival time and departure time, date, car registration no. (if applicable).
Legal basis: processing of personal data is performed based on our legitimate interests to maintain the security of our systems and the integrity and confidentiality of information, to protect our commercial activity, including intellectual property rights and trade secrets, as well as to ensure that our partners comply with the applicable legislation and internal regulations, policies and procedures, corroborated with our legal obligation to investigate and report incidents.
Retention period: personal data is stored for the duration of the service contract. At the end of the storage period, personal data will be deleted.
5.12 Purpose: present you as a part of our team on our presentation website so that you can be known and contacted by website visitors.
Personal data categories: first name, last name, image, professional training, email address, LinkedIn profile.
Legal basis: processing of personal data is performed based on your freely expressed consent.
Retention period: personal data is stored for the duration of the service contract or until you withdraw your consent. At the end of the storage period, the data will be deleted. However, we may proceed to delete the personal data when we decide that it is no longer relevant to achieve the purpose.
5.13 Purpose: ensure the necessary conditions to fulfill contractual obligations (e.g. providing work equipment and access cards; creating and managing accounts in the Controller’s software applications; managing critical situations; ensuring the maintenance of confidentiality, integrity, and availability of data when using computer networks and / or Controller’s systems).
Personal data categories: e-mail address, telephone number, brand, access logs, user name, consumption data (voice, data, sms), traffic data (data processed for the purpose of transmitting a communication over an electronic communications network, such as telephone number, IP address, terminal equipment identifier, call duration data, data traffic volume, date and time of the call, IMEI mobile terminal), location data (such as WiFi access points).
Legal basis: processing of personal data is performed for the performance of the service contract, or considering our legitimate interest to ensure the necessary conditions to fulfill contractual obligations.
Retention period: personal data is stored for the duration of the service contract. At the end of the storage period, the data will be deleted.
5.14 Purpose: ensure business continuity after termination of the contractual relationship.
Personal data categories: Email address, first name, last name.
Legal basis: Our legitimate interest to ensure the continuity of our activity.
Retention period: Personal data are stored for the duration of the service contract, as well as subsequently for a period of 6 (six) months from the termination of the contractual relationship. At the end of the storage period, the data will be deleted.
5.15 Purpose: solving the requests received from you, including those regarding the protection of personal data.
Personal data categories: First name, last name, e-mail address, telephone number, as well as any other personal data contained in the received request.
Legal basis: Our legitimate interest to solve the requests received from the data subjects, corroborated with our legal obligation under the legislation on the protection of personal data.
Retention period: Personal data is stored for a period of 3 (three) years from the date of solving the request. At the end of the storage period, the data will be deleted.
5.16 Purpose: verify your role of representative of the company to ensure that you have the full power and authority to conclude the service contract.
Personal data categories: First name, last name, powers of representation, as well as any other personal data included in the documents attesting your role as representative.
Legal basis: processing of personal data is performed based on our legitimate interest to conclude the service contract with the company you represent, as well as to ensure that the signatory of the service contract has the full power and authority to represent the company, and to avoid contractual fraud.
Retention period: Personal data is stored for the duration of the service contract. At the end of the storage period, personal data will be deleted.
If, following the checks carried out, we decide not to conclude the service contract with the company you represent, we will proceed to delete your personal data.
5.17 Purpose: conclude and execute the services agreement, as well as to manage the contractual relationship.
Personal data categories: first name, last name, e-mail address, image (if the case) company, position/role, phone number, signature, representation powers.
Legal basis: processing of personal data is necessary for the performance of the services agreement concluded with you when you are contracting as an individual, or based on our legitimate interest to conclude and execute the services agreement with the company that you represent, depending on the case.
Retention period: personal data is stored for as long as we have an existing contractual relationship in place, and subsequently for a period of 3 (three) years after its termination (or until you withdraw your consent for processing your image, whichever comes first). At the end of the storage period, personal data will be deleted.
5.18 Purpose: providing assistance and support for resolving requests regarding the execution of the service contract to ensure customer satisfaction.
Personal data categories: First name, last name, email address, company, position, phone number.
Legal basis: processing of personal data is performed based on our legitimate interest to communicate with you and provide you with support in resolving requests arising from the use of our services.
Retention period: Personal data is stored for the duration of the service contract, as well as for a period of 3 (three) years after the termination of the service contract. At the end of the storage period, the data will be deleted.
5.19 Purpose: collect your feedback through satisfaction surveys in order to help us improve our services and where the case post your review on the website.
Personal data categories: First name, last name, image, company name, position/role within the company, and any other personal data provided by you and contained in the review message.
Legal basis: We rely on your freely expressed consent when you voluntary fill out our review form. You can withdraw your consent at any time, without affecting the legality of the processing based on consent before its withdrawal.
Retention period: Personal data will be stored for as long as we have your consent until withdrawal, in which case data will be deleted. However, we can proceed to the deletion of personal data when we decide that it is no longer relevant for achieving the purpose.
5.20 Purpose: defending a person against attacks that endanger their life, bodily integrity, health or property.
Personal data categories: First name, last name, image, address, phone number, company, role, health data.
In addition, depending on the chosen service, we will process the following personal data:
Legal basis: processing of personal data is performed based on our legitimate interest to provide the services subject to the services contract. Regarding the processing of health data, the legal basis for processing is the protection of the vital interests of the data subject, when the data subject is physically or legally incapable of giving consent or providing medical care or medical treatment, as the case may be.
Retention period: Personal data is stored for the duration of the service contract, as well as for a period of 3 (three) years after the termination of the service contract. At the end of the storage period, the data will be deleted.
5.21 Purpose: prevent and detect information on breaches of law, as well as to investigate and deal with misconduct, including with regard to alleged fraud, and to maintain records of reports.
Personal data categories: first name, last name, e-mail address, phone number, date of reporting, object of reporting, signature (if applicable), voice (recorded) (if applicable), manner of resolution, as well as any other personal data included in the reporting.
Legal basis: processing of personal data is performed based on our legal obligation under the legislation on the protection of whistleblowers in the public interest to ensure and maintain internal reporting channels on breaches of law, corroborated with our legitimate interest to ensure that violations of applicable laws or regulations, including violations of our Code of Conduct are dealt with properly and in a timely manner in order to protect the company, employees, customers etc. from the effect of the illicit facts, corroborated with your consent for recording the conversation (if the report is made using a telephone line or other voice messaging system) and disclosure of your identity and of any other information that would allow the direct or indirect identification.
Retention period: personal data is stored for a period of 5 (five) years from the reporting date. At the end of the storage period, personal data will be deleted.
5.22 Purpose: ensure the protection and security of persons and our assets through video surveillance equipment installed on our premises.
Personal data categories: Your image captured by the video cameras when you access our offices.
Legal basis: processing of personal data is performed based on our legitimate interest in ensuring the safety and security of employees and property, as well as protecting the life and integrity of natural persons, through real-time monitoring and access to images in case there are suspicions of committing an offence.
Retention period: personal data is stored for a period of 30 (thirty) days. At the end of the storage period, personal data will be deleted.
5.23 Purpose: ensure the protection and security to our premises by maintaining a register regarding the access of individuals to our premises.
Personal data categories: first name, last name, identity document series and number, destination, time of arrival and departure, date.
Legal basis: processing of personal data is performed based on our legal obligation under the legislation on the security of objectives, goods, values, and protection of persons.
Retention period: personal data is stored for a period of 2 (two) years from the end of the calendar year during which the register of access of persons to our premises was completed. At the end of the storage period, personal data will be deleted.
5.24 Purpose: recruitment and selection for vacancies within our company.
Personal data categories: first name, last name, e-mail address, phone number, information on the candidate’s professional/work experience (former employers, current employer, seniority in the current position), information regarding studies, diplomas, certifications, profile on a professional social network (e.g. LinkedIn) and any other personal data included in the application documents.
Legal basis: processing of personal data is performed in order to take steps at your request prior to entering into a contract.
Retention period: personal data is stored for the duration of the recruitment and selection process and subsequently for a period of 6 (six) months to manage possible complaints. At the end of the storage period, personal data will be deleted.
Additional information related to the processing of personal data in the context of recruitment and selection and be found in the Privacy Notice for Recruitment and Selection Process.
In addition to the purposes mentioned above, we may process your personal data for the purpose of fulfilling our legal obligations under the laws governing our activity, including those regarding equal opportunities and non-discrimination, ensuring physical and IT security and protecting whistleblowers in the public interest. In these situations, the categories of data processed, and the data storage periods are determined according to the applicable legal provisions.
Your data may also be processed, based on the legitimate interest of the Controller, for the purpose of exercising or defending a right or legitimate interest in a judicial, administrative or similar procedure, in which the Controller is involved or to respond to requests from public authorities, courts and tribunals or criminal investigation and prosecution bodies, based on and within the legal obligations the Controller is subject to. The categories of data processed and the storage periods are determined on a case-by-case basis, depending on the applicable legal procedures and provisions.
At the end of the retention periods specified above, personal data will be deleted or anonymized, as applicable to the specific situation.
Our website uses cookies, plug-ins and other online identifiers (collectively referred to as “cookies”) in order to ensure functional browsing or to provide a better browsing experience, to perform statistical analysis regarding accessed information, or to provide you with custom content and advertising appropriate to your preferences and interests.
Detailed information regarding the cookies we use may be found in our Cookie Policy.
We do not make decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
We may transfer your personal data, to the extent that this is necessary to the following categories of recipients: companies from the same group, service partners, subcontractors, payment providers, courier service providers, archiving companies, IT service providers, software or hardware vendors, market research companies, marketing companies, public authorities, court or arbitral tribunals, as well as competent authorities to investigate criminal offenses.
Personal data may be disclosed or transferred to the categories of recipients mentioned above in order to provide our Services at the highest quality level, ensure the intervention of specialists by outsourcing parts of our business or to provide access to services and benefits according to our business partnerships, or to ensure compliance with the specific legal obligations to which we are subject according to the activity carried out.
In the event that personal data is transferred to third countries we will apply the technical and organizational measures required by law and we will inform you about the transfer in accordance with the legal requirements.
The security of your personal data is important to us. Therefore, we maintain a variety of appropriate technical and organizational measures to protect your personal data from loss, misuse, and unauthorized access or disclosure. We limit access to personal data to employees or contractors who we believe reasonably need to retrieve that information to provide our Services. Considering the current state of technology, we have implemented reasonable physical, technical and procedural safeguards designed to protect your personal data, such as limiting access, encrypting, anonymizing, or storing it on secure media.
It is very important that you, as a data subject, know the risks and take the measures to protect your personal data, for example by checking the sources of information, avoiding access to suspicious or unknown links, regularly changing passwords and using appropriate anti-virus and anti-malware solutions.
The law grants data subjects enforceable and effective rights concerning their personal data which can be exercised under particular conditions.
You have the following rights regarding your personal data:
Except for the right to contact the Supervisory Authority, which you can exercise using the contact details indicated above, you can exercise your legal rights by contacting our Data Protection Officer by e-mail at dataprotection@nssg.global.
We will respond to your requests without undue delay and in any case within one month of receiving the request. This period may be extended by two months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receiving your request, stating the reasons for the delay.
In the event that we do not take action on your request, we will inform you, without undue delay and no later than one month after the receipt of your request, of the reasons for not taking action. In such a case, you have the possibility to lodge a complaint with the competent Supervisory Authority or to take a legal action.
This Policy is subject to periodic reviews and updates to ensure that it always corresponds to reality, and it is in line with the applicable legal requirements. For this reason, please regularly consult this Policy to keep up to date with any changes. Any major changes to this Policy will be notified accordingly.
If you have any questions or concerns regarding the processing of your personal data, this Policy or how it applies, or you wish to exercise any of your rights, you can contact our Data Protection Officer by email at dataprotection@nssg.global.