Privacy Policy
Last updated · 2026-10-01
This policy describes what data Ambasada collects about you, why, who processes it, how long we keep it, and what you can do about it. The data controller is Asociația AMBSD (CIF 55564279),Constanța, Romania; reach us at [email protected]. Privacy requests: Cătălin Cenac, [email protected].
What we collect
- Member account. When you sign in to the member area we create an account with the email you used, your name and profile picture if your sign-in provider (Google, Apple, LinkedIn) shares them, and the profile you fill in yourself. Sign-in itself is handled by Clerk; we never see your password. From your sign-in provider we keep only your name, email and picture; what we add from your public LinkedIn profile is described below.
- Membership card. We issue an Apple Wallet or Google Wallet card with your name, a QR code that identifies your card, and the number of events you joined. To keep the card updated we store the identifiers Apple and Google need to push changes to your phone.
- Public LinkedIn profile. If you gave us a LinkedIn address (on Luma or in your profile), we read your public profile page, through Apify, to fill in what is missing on your member card: photo, headline, role and company. We do it when you join and may refresh it later. We never overwrite what you typed yourself, and you can change or remove any of it on your profile.
- Showing your card.When partner staff scan your card to hand out a perk, they see your name, profile photo, company, LinkedIn link, how long you have been a member and how many events you joined, plus whether you used that perk before. We log each decision and any note they add. The QR on your card is also your digital business card: whoever you show it to and lets scan it sees your name, photo, role, company, email, phone and links, and can save them to their contacts. If they are a member, you are saved in each other's Contacts. A visitor without an account can let you know they saved your card: they tick a box agreeing to share their name and email with you and to let us look up their public work profile, then create the reminder, and their calendar sends the reminder's invitation to our address. From that invitation we create a guest record with their name, email and the date and version of their consent, and fill in role, company, headline, LinkedIn link and photo from Apollo.io (by email) and Gravatar. We then email them once to say what we stored and how to have it deleted. The record becomes their account when they sign in; no card is issued before that. Without the box ticked, the reminder cannot be created and nothing is shared.
- Event registrations. When you register for one of our events on Luma, we receive your name, email and the LinkedIn address you gave in the registration. We keep them as a guest record so we can count the events you joined, have your account ready when you first sign in, and send you at most one short personal note before the next event. A guest record becomes your member account when you sign in. For the count we also keep a hashed (scrambled, but not anonymous) copy of each registrant email and the events it joined.
- Unconference topics. If an event runs an unconference, the topics you pick and propose on the Luma form (and later in the hub) are imported. Proposals are checked by an AI model so offensive or duplicate ones are filtered; topic titles are shown on Luma and on our site, without your name. Votes are stored against the hashed email.
- Personal emails from the host. If Cătălin writes to you to ask you to present, lead a topic or meet someone, we keep a copy of that email and, if you reply, your answer and the outcome, so we know who was asked what.
- Suggested intros.Before an event we may suggest that you meet another member, based on your profile (role, company, what you do) and the events you joined; an AI model running on our own servers in Europe may help us propose pairs. The other person sees your name and your LinkedIn link. Only when both of you accept are you added to each other's contacts.
- The chat. Your conversations with the AI assistant at chat.ambasada.pro and in the apps are stored on our server so you can come back to them. To answer, each message, and any file or photo you attach, is sent to an AI model provider: currently DeepSeek models that we run on our own servers in Europe (llmok.app). Do not share anything you would not want processed this way. We do not use your conversations to train models; the team opens them only to fix a problem you report or to stop abuse.
- Apps and notifications.If you use the iOS or Android app, we store the push token your phone gives us so we can send the notifications you allowed, plus the list of notifications we sent you and whether you opened them. Dictation in the chat uses your phone's own speech recognition (Apple's or Google's, under their terms), on the device where the phone supports it; we never receive the audio, only the text you send.
- For you. Which posts (offers, perks, forms, announcements) were shown to you and which you opened. If a post is addressed to you personally, the code or link meant for you.
- Forms. The message form at /contact and the partner form at /card: what you type there, plus a hashed IP address to stop abuse.
- Newsletter. Your email address, when you sign up for it.
- Partner staff. If you scan cards for a partner venue, the venue name and contact, the perks it handles, each activation (member, perk, quantity, amount typed) and a cookie that keeps the scanner open on the phone for a shift.
- Technical logs. Our hosting providers keep standard request logs for security. We run no analytics, no advertising and no cross-site tracking.
Why, and on what basis
- To run your membership: account, card, events count, and the For you feed. Basis: the membership agreement you enter by signing in (Article 6(1)(b) GDPR).
- To notify you on your card, in the app or by email when something changes or a new post is for you. Basis: the same agreement; push notifications only with the permission you give on your phone, and each kind can be switched off in your profile at any time.
- To answer you in the chat and to suggest intros. Basis: the membership agreement.
- To keep a guest record for people who registered for our events and send them one short personal note before the next one. Basis: our legitimate interest in welcoming people back to a community they chose to visit. Reply to any note to stop them, or write to us to have the record deleted.
- To answer applications and messages. Basis: your request.
- To send the newsletter. Basis: your consent; every mail has an unsubscribe link.
- To keep the site secure. Basis: our legitimate interest in running a working, safe site.
- To fill in profiles from public sources, suggest intros, run the unconference and keep a record of the host's personal asks. Basis: our legitimate interest in connecting the people of the community; you can object at any time by writing to us.
Who processes it
Data is held in the EU where the provider offers it. Our processors:
- Clerk: sign-in and account security.
- Supabase: database and file storage (EU, Ireland).
- Vercel: website hosting.
- Cloudflare: runs our wallet card service, which builds the card and relays updates to Apple and Google.
- Apple and Google: deliver the card and its updates to your phone under their own terms when you add it to your wallet.
- Luma: event registration. Luma holds your registration under its own policy; we read from it.
- Resend: email delivery (EU sending region).
- Hetzner: hosts the chat, its conversations and our notification service (Germany).
- llmok.app: our own AI servers in Europe, running DeepSeek models, for the chat, intro suggestions, topic moderation and drafting short personal notes.
- Apify: reads public LinkedIn profiles for us, as described above.
- Apollo.io (US) and Gravatar (Automattic, US): look up the public work profile and photo of a visitor who agreed to share their email with a member, as described above.
- Apple and Google push services: deliver notifications to the apps.
Some of these providers (Clerk, Vercel, Resend, Cloudflare, Apple, Google, Luma, Apollo.io, Gravatar) are based in the United States or may process data there. Clerk and Resend are certified under the EU-US Data Privacy Framework; for the others we rely on their standard data protection terms.
Only the Ambasada team can access the data directly. Partner staff who scan cards see only what is described under “Showing your card”.
How long we keep it
- Member account and card: until you delete your account or ask us to.
- For you history, perk redemptions, contacts and intros: with your account.
- Guest records (from Luma or a card you saved): until you ask us to delete them, or delete the account after signing in.
- Applications and contact messages: twelve months, then deleted automatically. An application linked to a live account stays as part of that account.
- Hashed Luma registrations: refreshed every few hours from Luma; entries disappear when they are no longer on Luma.
- Unconference votes and proposals, the host's personal emails and replies, and newsletter delivery logs: until you ask us or delete your account.
- Chat conversations: until you delete them in the chat, or with your account.
- Notification history: with your account.
- Newsletter: until you unsubscribe.
We review these periods regularly; the next review is due in October 2027.
Your rights, and where to use them
- Access and export: Profile, then Download my data. You get a JSON file with your account and profile, the events you joined, your For you history, points, check-ins, perk redemptions, the people you met and your newsletter status. For anything else above (intros, the host's emails, unconference votes, notifications), write to us and we send it.
- Correction: edit your profile; your name updates on the card.
- Erasure: Profile, then Delete my account, on the web or in the apps; or, if you never signed in, write to us. We delete your account or guest record and everything linked to it: contacts, intros, points, perks, unconference votes and proposals (topics others voted on stay, without your name), the host's emails to you, newsletter subscription and logs, form messages, card photos, chat conversations and files, notifications and device tokens. The card is closed and your name and email are removed from it. We keep only a hashed copy of your email and the date, so our Luma sync does not create you again from your registrations; if you sign in again later, that is removed too. The copy of the card already on your phone is yours to remove; your Luma registrations remain with Luma.
- Object or restrict: switch wallet notifications off in your profile, unsubscribe from the newsletter, or write to us.
- Complain: to the Romanian supervisory authority, ANSPDCP, or the authority where you live.
For anything else, email [email protected]with the subject “privacy”. We answer within 30 days, usually much faster.
Cookies
One keeps members signed in (set by Clerk), one keeps admins signed in, and one remembers on your phone the member cards you opened while not signed in (for 30 days, nothing is sent to us), so that when you sign in we can offer to add them to your contacts. No marketing or analytics cookies.
Age
The member area is for people aged 16 and over.
Changes
When this policy changes we update the date above.