Privacy policy
What personal data Visit Neamț processes, why, who receives it (including Cloudflare), how long we keep it and what rights you have.
Last updated:
This policy explains in plain language what happens to your data when you use Visit Neamț. In short: we use no tracking cookies, run no analytics with personal identifiers, sell no data and show no ads. The only personal data we collect is what ticket orders need.
1. Who is the controller
The controller of the Visit Neamț website (the county tourism portal) is Consiliul Județean Neamț (Neamț County Council), Str. Alexandru cel Bun nr. 27, Piatra Neamț, Neamț County, Romania. Phone: +40 233 21 28 90. Email: cons.judetean@cjneamt.ro. Full identification details are on the Legal notice page.
The Council's data protection officer (DPO) is published on the institution's page: Personal data protection (in Romanian). [TODO-CJ: confirm the DPO responsible for this platform and a dedicated email for GDPR requests]
Museum tickets are sold for the museum whose page you buy from. [TODO-CJ: confirm whether, for ticket orders, the controller is the County Council, the museum, or both as joint controllers (Art. 26 GDPR), and state each role here]
2. What data we process, why and on what legal basis
Browsing the site. Our servers receive, like any website, your IP address, browser type, the page requested and the time. We use them only to deliver the page, protect it from abuse and fix errors. Legal basis: a task carried out in the public interest, promoting tourism and the county's heritage (Art. 6(1)(e) GDPR). We do not link this data to a person and do not use it for profiling.
Ticket orders and the pass. For an order we keep: your name, email address, phone number (only if you enter one), language, the tickets chosen (museum, date, time, fare), the amount, the order code and its status. At the door, scanning a ticket records the museum, the time and the result (valid, used, expired), with no other data about you. Legal basis: performance of the ticket sale contract (Art. 6(1)(b)) and accounting and tax obligations (Art. 6(1)(c)).
Payment. In the current edition card payment is simulated: your card is not charged and we collect no card data. When real payment is switched on, the payment processor will be named on this page before it goes live. [TODO-CJ: the chosen payment processor and its role]
The map. The map loads straight from your browser from the OpenFreeMap service (tiles.openfreemap.org). It sees your IP address and the map area requested, like any map server. We send it no other data.
Device location. The "near me" button asks your browser for permission. The position is used only in the browser, to sort or centre results. We do not send it to our servers. You can refuse without losing any other feature.
Google Maps links. "Directions" buttons open Google Maps on a separate page, only after you press them. From that moment Google's policy applies.
Events: registration and tickets. Event pages show the place, entry, tickets and registration, but registration and tickets for events are handled on the organiser's own site or contact. The data you give there is processed by the organiser, not by us; we do not collect event registrations.
Messages to us. If you write to us, we use the data in your message only to reply.
Editor accounts. People who manage content have accounts with a name, email and passkey. These are not visible to the public.
Claiming a page. The "Claim this page" form is being prepared. When it exists we will publish here what data it asks for, why, and how long we keep it.
3. Who receives the data
- Cloudflare, Inc. (processor): hosts the website and the app, delivers pages through its network, protects against attacks and stores the database (D1), media files (R2) and sessions. The database and files are created in Cloudflare's EU region. Cloudflare keeps technical request logs for a short period.
- OpenFreeMap: the map service described above (it receives the IP address when the map loads; it is not our processor).
- The museum you buy tickets for: receives the order data so it can admit you.
- Public authorities, only where the law requires it.
We do not sell or rent data. We use no ad networks, tracking pixels or traffic analytics services.
4. Transfers outside the European Economic Area
Cloudflare, Inc. is a US company. Transfers to it rely on its data processing agreement (DPA) with standard contractual clauses and on its participation in the EU–US Data Privacy Framework. We transfer no data to other recipients outside the EEA. [TODO-CJ: confirm the DPA with Cloudflare is signed in the institution's account]
5. How long we keep data
- Technical server logs: a short period set in the Cloudflare account. [TODO-CJ: confirm the duration]
- Ticket orders and tickets: as long as accounting and tax obligations require. [TODO-CJ: set the period with the DPO and accounting; supporting documents are usually kept 5 years]
- Ticket scans: [TODO-CJ: set the period, proposal 12 months]
- Messages to us: as long as needed to reply and at most 12 months.
6. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection (Arts. 15–21 GDPR). To exercise them, write to cons.judetean@cjneamt.ro and we reply within 30 days. For orders, give the order code and the email address used. We may ask for proof of identity so that we do not hand your data to someone else.
If you are unhappy with the answer, you can complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP).
7. Security
The connection is encrypted (HTTPS), pages use strict security headers (CSP, HSTS), tickets carry signed codes, and the admin panel is accessed with passkeys, not passwords. No system is perfect: if you suspect a security problem, write to us.
8. Cookies and children
Details on cookies and local storage are on the Cookies page. The site is not aimed at children under 16 and does not knowingly collect data about them; tickets for children are bought by an adult.
9. Changes
If we change what data we process, we update this page and the date below. Current version: 8 October 2026.