PRIVACY POLICY (GDPR)
Last updated: August 2026
- Operator:
- FIREFLY CONCEPT SRL | Romania
- Contact:
- contact@fireflyapp.ro
This Privacy Policy explains how fireflyapp.ro collects, uses, and protects the personal data of regular users and business partners (venues, event organizers) who use our party promotion platform.
1. Who We Are
The fireflyapp.ro platform is operated by FIREFLY CONCEPT SRL. As a data controller, we ensure that your data is processed in full compliance with the General Data Protection Regulation (GDPR - Regulation EU 2016/679).
The controller of your data is FIREFLY CONCEPT S.R.L., with its registered office in Pitești Municipality, Argeș County, 11 Constructorilor Street, Block C, Entrance B, Ground Floor, Ap. 3, registered under no. J2026039957007, Tax ID (CUI) 54945577. For any questions regarding your data, you can contact us at: contact@fireflyapp.ro.
2. What Data We Collect and Why
A. Data provided directly by you:
For user accounts (people looking for parties): First name, last name, email address, and password (stored securely using encryption/hashing).
For business accounts (venues / event organizers): Company/venue name, identification details of the representative – necessary for account administration and the contractual relationship with the business, contact email address, phone number, CUI, registered office, and materials uploaded for event promotion (titles, descriptions, photos, location).
Transaction data: For payments made through the platform, we may collect information such as the amount, currency, transaction date, transaction identifier, payment status, and billing information. Card payments are processed through our payment service provider, Stripe, and Firefly does not store the full card number or CVC.
For newsletters and marketing (optional): Email address – collected only if you explicitly check the box indicating that you wish to receive news and recommendations about parties.
For the contact form: Name, email address, and your message – used exclusively to respond to your inquiry.
B. Data collected automatically (technical):
Security logs (server logs): IP address, browser type, pages accessed, and date/time of access – temporarily stored for the cybersecurity protection of the platform.
3. Why and On What Grounds We Process Your Data
We process your personal data for the following purposes:
Providing our services: Creating and managing your account, secure login, and displaying relevant content (Legal basis: Performance of a contract / Terms and Conditions – Article 6(1)(b) GDPR).
Processing and managing payments: Processing payments for subscriptions, promotion, and other services offered through the platform, as well as preventing and detecting fraud and managing potential transaction disputes (Legal basis: Performance of a contract – Article 6(1)(b) GDPR and, where applicable, legitimate interests – Article 6(1)(f) GDPR).
Functional communications: Sending transactional emails (account confirmation, password reset, party-related notifications) (Legal basis: Performance of a contract).
Security and fraud prevention: Monitoring traffic to prevent cyberattacks and fake accounts (Legal basis: Legitimate interests – Article 6(1)(f) GDPR).
Newsletter / Marketing communications: Sending recommendations about events in Bucharest (Legal basis: Your explicit consent – provided through a separate checkbox).
4. How Long We Retain Data
We retain personal data only for as long as necessary to fulfill the stated purposes:
Data associated with User and Business accounts is retained for as long as the account remains active. If you decide to delete your account, your data will be deleted or anonymized, except for data that we are legally required to retain.
Transaction data and financial/accounting documents are retained for the period required by applicable tax and accounting legislation, even after account deletion, where there is a legal obligation to retain them.
Newsletter data is retained until you withdraw your consent or unsubscribe from marketing communications.
Technical logs (server logs): Automatically deleted after 30 days.
5. Who We Share Data With
We do not sell or rent your personal data to third parties. Your data is accessed only by service providers strictly necessary for the platform's operation:
- Web hosting providers, media storage providers, and IT service providers.
- Email marketing service providers.
Payment service providers: We use Stripe to process online payments. When you make a payment through the platform, certain data necessary to process the transaction (such as your name, email address, transaction data, and information required for payment) may be transmitted to Stripe. Card details are entered and processed through Stripe's infrastructure and are not stored by Firefly in full. See Stripe's Privacy Policy.
- Government authorities, where required by law.
International data transfers: Some of our service providers may process personal data outside the European Economic Area (EEA). In such cases, we ensure that transfers are carried out in accordance with the GDPR and that appropriate legal mechanisms are used, such as an adequacy decision by the European Commission, Standard Contractual Clauses (SCCs), or other mechanisms recognized under applicable law.
6. Your Rights (GDPR)
As a user, you have the following guaranteed rights:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may request correction of inaccurate personal data.
- Right to erasure (“right to be forgotten”): You may request deletion of your account and personal data.
- Right to withdraw consent: You may unsubscribe from marketing communications at any time.
- Right to restriction of processing.
- Right to data portability, where the applicable legal conditions are met.
- Right to object, particularly to processing based on legitimate interests and to direct marketing.
- Right not to be subject to a decision based solely on automated processing, including profiling, where provided for under the GDPR.
We will respond to your request without undue delay and, in principle, within one month of receiving it. In cases permitted by the GDPR, this period may be extended by up to two additional months, and you will be informed accordingly.
You also have the right to lodge a complaint with the national supervisory authority in Romania: ANSPDCP ANSPDCP (www.dataprotection.ro).
7. Data Security
We apply modern technical measures to safeguard your information: encrypted HTTPS/TLS connections, secure password storage (bcrypt hashing), brute-force protection, and login attempt limits.
8. Cookies
We use strictly necessary technical cookies to maintain your authentication session and platform security. For full details, please consult our Cookie Policy.
9. Protection of Minors
The Firefly platform is intended for persons aged 18 and over. We do not allow persons under the age of 18 to create accounts and do not knowingly collect personal data from minors. If we become aware that we have collected such data, we will take the necessary steps to delete it.
10. Policy Changes
We reserve the right to update this policy. In the event of material changes, we will notify you by email or via an alert on the website before the changes take effect.