Privacy policy
What we collect about you, why, who else sees it, and how long we keep it. Written against the actual database, not a template.
Last revised 6 August 2026
1Who is responsible for your data
The controller is EXPERT LASH S.R.L., trade register J12/4913/2023, registered at Str. Anton Pann nr. 14-16, Corp B, parter, Cluj-Napoca, jud. Cluj. CUI 49124478. You can call us on +40 742 359 107.
For anything about your data, write to contact@expert-lash.com. We are not required to appoint a data protection officer and have not appointed one; that address reaches the people who can actually act on your request.
2What we collect
Grouped by why it exists, because that is what decides the rest.
- Your account — name, email address, password (stored only as a cryptographic hash, never in readable form), and the date you registered.
- Your profile as a participant — country, academy, Instagram handle, phone number, the level you declared for the edition, and your personal invitation code.
- Your orders — what you bought, the price at the time, and the billing details you entered: name or company name, VAT code and trade register number for companies, address, city, region, postcode, phone. These are stored as a snapshot on the order, not as a link to your profile, so an invoice from last year still shows the address you had last year.
- Your works — the photographs you upload and the nomination they belong to. See the photo policy.
- Judging — the scores given to your works. Judges never receive your identity; they work from an entry code.
- Email delivery — whether a confirmation was sent, and the error if it failed.
We do not ask for and do not want any special-category data — health, beliefs, and so on. A photograph of a model’s eye area is an image of a person, but we do not process it biometrically and we do not use it to identify anyone.
3Why we are allowed to hold it
- To perform our contract with you (Art. 6(1)(b) GDPR) — your account, your level, your entries, your works, your scores, the results. Without these there is no competition to enter.
- To meet a legal obligation (Art. 6(1)(c)) — invoices and the billing details on them. Romanian accounting law requires us to keep them, and we cannot delete them on request.
- Our legitimate interests (Art. 6(1)(f)) — keeping the platform secure, preventing fabricated invitation rewards, and answering your questions. We have weighed these against your rights and consider them proportionate; you may object at any time.
- Your consent (Art. 6(1)(a)) — marketing emails and any promotional use of your photographs beyond the competition itself. Consent is optional, separate, and you can withdraw it at any time without losing anything you paid for.
4Who else sees it
We do not sell your data and we do not share it for anyone else’s marketing. We use these processors, each for one job:
- Supabase — database, accounts and file storage. Your data sits in the EU (Ireland).
- Vercel — hosting of the application.
- Stripe — card payments. Card numbers go directly to Stripe and never reach us. Stripe is a separate controller for its own fraud prevention.
- SmartBill — fiscal invoicing. Receives the billing details for the invoice.
- Brevo — transactional and marketing email. Receives your name and email address.
- Cloudflare — DNS and email routing.
The judging panel sees works by code only. Public results show the entry code, the nomination and the score; a participant’s name appears in published results only where we announce winners, as described in the competition terms.
We will also disclose data where a law or a court obliges us to. If that happens and we are permitted to tell you, we will.
5Leaving the EU
Our database and files are stored in the European Union. Some of the services above are operated by companies established outside the EU; in those cases the transfer is covered by the European Commission’s standard contractual clauses, or by an adequacy decision where one applies. You can ask us for the details.
6How long we keep it
- Invoices and the billing details on them — ten years from the end of the financial year, as Romanian accounting law requires. This one is not negotiable, for either of us.
- Your account and profile — while your account exists. Ask us to close it and we delete it, keeping only what the line above obliges us to.
- Works and scores — kept for the edition and its published results, which are part of the competition’s record.
- Marketing consent — until you withdraw it, plus a record that you withdrew, so we do not contact you again by mistake.
7What you can ask us to do
Under the GDPR you can ask us to:
- give you a copy of the data we hold about you, in a portable format;
- correct anything wrong;
- delete your data, where no legal obligation requires us to keep it;
- restrict what we do with it while a dispute is resolved;
- stop processing based on our legitimate interests, by objecting;
- withdraw a consent you gave, at any time.
Write to contact@expert-lash.com. We answer within 30 days, free of charge. If we cannot do what you asked, we say why rather than going quiet.
If you are not satisfied, you may complain to the Romanian supervisory authority (ANSPDCP, Bucharest) or to the authority in your own country of residence.
8Cookies
We store the minimum needed to make the site work, and nothing at all for advertising or analytics:
- a session cookie that keeps you signed in, set only after you sign in;
- a cookie that remembers whether you chose English, Romanian or Italian, set only when you pick one.
One is strictly necessary and the other is a preference you asked for, so no consent banner is required. Until September 2026 there was a third cookie, which remembered the invitation link that brought you here; we removed it, and invitation codes now travel in the address instead. The detail is in the cookie policy.
9Security, and what happens if it fails
Access is enforced at the database level, row by row, not merely hidden in the interface — a judge who tried to read participant identities would be refused by the database itself. Passwords are hashed. Card details never touch our servers.
No system is perfect. If a breach occurs that is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and tell you directly.
10Changes
If we change this policy in a way that matters to you, we will email you before it takes effect. The revision date is at the top of this page.
Anything unclear, write to us and we will answer in plain language.
Back to the championship