Last updated 9 September 2026

Privacy policy

This page explains what personal data reaches us through this site, why we use it, how long we keep it, and what you can ask us to do with it.

It is written to be read, not to be ticked off. If anything stays unclear, write to us and we will answer in plain words.

1. Who is responsible for your data

The controller for data collected through this site is the team operating OpenCall.

Email
contact@opencall.ro
Website
opencall.ro

2. What we collect

Through the "Request an instance" form you send us: the name of your organisation, a contact person, an email address, a phone number (optional), the subdomain you want, the platform name and colour (optional), the package you are interested in, the size of your organisation, the estimated number of calls and applications per year, and whatever you write in the message field.

If you email us directly, we keep the message and the address it came from, so that we can reply and so that we remember what was discussed.

The server that serves this site records, in its technical logs, your IP address and the type of browser. We use these for security and troubleshooting, never for profiling. The logs rotate automatically, by size — we keep no historical archive of them.

3. Why we use it, and on what basis

  • To answer your request and prepare a possible working relationship — steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
  • To keep the site running and to defend it against abuse — our legitimate interest (Art. 6(1)(f) GDPR).
  • To meet accounting and tax obligations, if we end up working together — legal obligation (Art. 6(1)(c) GDPR).

4. The email we send

Every message we send goes out because a specific person did something: requested an instance, confirmed their address, submitted an application, received a request for clarifications, was invited to a jury. We send no unsolicited campaigns.

Addresses are never bought, rented, imported from third-party lists or scraped from other sites. Every address belongs to a person who registered themselves, or who was invited by name, inside the platform, by the organisation running the call. An account does not work until its address has been confirmed through a link sent to it.

Every message that is not about account security carries the "List-Unsubscribe" header (one-click unsubscribe, straight from the mail client) and a visible unsubscribe link. Unsubscribing is recorded on the account and checked in a single place in the code that every send passes through — an unsubscribed address cannot be reached by accident from some forgotten routine.

There is one exception: address confirmation and password reset. Someone who unsubscribed and then cannot reset their password is locked out of their own account.

Addresses that hard-bounce, and addresses that report a message as unwanted, are removed from further sends automatically.

5. Who else sees the data

We sell data to nobody and use it for no advertising. It reaches only the suppliers we need in order to operate, each under contract and bound to process it solely on our instructions:

WhoWhat forWhere
Hetzner Online GmbHServer hosting and file storageEuropean Union
Mailgun (Sinch)Sending emailEuropean Union / USA
Amazon Web Services (Amazon SES)Sending emailEuropean Union (Stockholm)

6. How long we keep it

  • Instance requests that do not turn into a working relationship: 12 months from the last exchange.
  • Data of organisations we work with: for the duration of the contract, plus the periods required by accounting and tax law.
  • Email correspondence: 24 months.
  • Technical server logs: until they rotate automatically.

7. Cookies and browser storage

This site has no analytics, no tracking pixels, no advertising cookies, and connects you to no social network.

The only thing it writes into your browser is your theme preference — light or dark — and only if you press the switch. That setting stays on your own computer; it never reaches us. This is why you will find no cookie banner here: there is nothing to ask you about.

8. Data inside our customers’ platforms

This page covers the presentation site. Every organisation using OpenCall has its own instance, with its own domain, database and storage, separate from all others.

For the data inside — applicants, dossiers, evaluations, contracts — the controller is the organisation running the call, and we are the processor: we handle it only on their instructions. If you applied somewhere and want to exercise your rights, write to that organisation. If you do not know which one, write to us and we will point you.

9. What you can ask for

You have the right to know what data we hold about you and to receive a copy, to correct it, to have it erased, to ask us to restrict its use, to receive it in a portable format, and to object to processing based on our legitimate interest.

Write to the address below and we will answer within one month. It costs nothing.

If our answer does not satisfy you, you may complain to the Romanian supervisory authority (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro, or to the authority in your own country.

10. How we keep it safe

  • All traffic is encrypted, over HTTPS.
  • Each instance has its own database and its own storage, separate from every other customer.
  • Server access is limited to the people who need it to do their work.
  • Backups are automatic and encrypted.
  • Files uploaded by applicants are not public: they are reachable only through the platform, after signing in.

11. Changes

When we change something here, we change the date at the top of the page as well. If the change concerns you directly — a different basis, a different supplier, a different retention period — we write to you rather than leaving you to find out.