Accessibility Tools

Privacy

Privacy Policy — DirectDemocracyS

Version: 1.0
Date of publication: 22 September 2026
Last update: 22 September 2026
Organisation: DirectDemocracyS
European Commission PIC: 881951064
Registered international office: str. Muzicii nr. 22, postal code 410514, Oradea, Bihor County, Romania, European Union
Privacy contact: This email address is being protected from spambots. You need JavaScript enabled to view it.
Data Protection Officer (DPO): Franco-Romeo Zaccherini


1. Introduction

DirectDemocracyS considers the protection of personal data, privacy, anonymity, confidentiality, security and individual freedom to be fundamental principles of its entire system.

This Privacy Policy explains, in detail, how DirectDemocracyS collects, receives, generates, processes, verifies, protects, stores, separates, transfers, archives and, where appropriate, deletes personal data.

This Policy applies to the DirectDemocracyS system, its websites, platforms, online services, internal areas, social areas, registration systems, verification systems, communication systems, administrative systems, security systems and authorised internal groups, insofar as they process personal data.

DirectDemocracyS does not consider privacy to be merely a legal obligation. Privacy is also an architectural, organisational and democratic principle.

The system is therefore designed around several fundamental concepts:

DirectDemocracyS recognises that different users have different requirements.

A person who participates only as a Free user does not necessarily need to reveal their legal identity.

A person who wishes to exercise rights that require a verified identity, participate in shared leadership, become an official member or perform official or political representation may need to undergo additional verification.

The amount of personal information processed therefore depends on the user's relationship with the system, the user type selected or obtained, the activities performed and the legal or security requirements applicable to those activities.


2. Legal Entity and Data Protection Contact

For the purposes of this Privacy Policy, the relevant DirectDemocracyS entity is identified as follows:

DirectDemocracyS

European Commission PIC: 881951064

Registered international office:

str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union

Privacy contact:

This email address is being protected from spambots. You need JavaScript enabled to view it.

Data Protection Officer (DPO):

Franco-Romeo Zaccherini

Requests concerning personal data, privacy, identity verification records, access to personal information, correction, restriction, deletion, objection, portability or other applicable data protection rights may be directed to the privacy contact above.

Where a specific request requires additional verification that the requester is the person entitled to receive or modify the information, DirectDemocracyS may request only the minimum additional information necessary to verify that right.

DirectDemocracyS will not request unnecessary identity information merely because a user wishes to exercise a privacy right.


3. Scope of this Privacy Policy

This Privacy Policy applies, as applicable, to:

  1. visitors to public DirectDemocracyS websites;

  2. Public users;

  3. Test users;

  4. Free users;

  5. Guest users;

  6. Access users;

  7. Partially Registered users;

  8. Verified users;

  9. Members;

  10. Politicians;

  11. Representatives;

  12. Owners;

  13. Managers;

  14. Responsible users;

  15. Administrators;

  16. SuperAdministrators;

  17. Guarantors;

  18. official representatives;

  19. political representatives;

  20. employees and collaborators, where their data are processed;

  21. persons participating in identity verification;

  22. persons participating in compatibility or skills verification;

  23. persons communicating with DirectDemocracyS;

  24. persons whose data are processed for security, legal, administrative, accounting or organisational purposes.

The terminology of user types is governed by the applicable DirectDemocracyS rules.

Not every user type has the same data requirements.

In particular, the fact that DirectDemocracyS may be able to verify a person's identity does not mean that the person's real identity is automatically visible to ordinary users.


4. Fundamental Privacy Principle of DirectDemocracyS

DirectDemocracyS follows a simple fundamental principle:

A person's identity should be known only when there is a legitimate reason to know it.

The system therefore separates, as far as technically and organisationally possible, the following concepts:

These categories are not automatically interchangeable.

A person may therefore be known inside the operational system by a username without that username publicly revealing their real name.


5. Right to Anonymity

5.1 General principle

DirectDemocracyS recognises, wherever permitted by the user's user type and the applicable rules, a fundamental right to operate under an anonymous or non-identifying username.

For ordinary users, the username does not have to correspond to:

A user may therefore participate using a username that has no obvious connection with their real identity.

The username is the person's operational identity within DirectDemocracyS.


6. How an Anonymous Username Can Be Chosen

A user may choose an anonymous username according to the applicable username rules.

Examples of privacy-preserving formats include:

6.1 A nickname

For example:

BlueMountain

provided that the nickname does not reveal information that the user does not wish to disclose and is not misleading or reserved for another role.

6.2 A country code combined with a random identifier

For example:

RO7F4K29

or another structure based on an ISO country code followed by a random combination of letters and numbers.

The country code itself does not have to identify the person's precise location.

6.3 A completely random identifier

For example:

X7Q9-M4P2-Z8

or another permitted random alphanumeric or special-character combination.

6.4 Other permitted anonymous formats

A user may use any username permitted by the applicable DirectDemocracyS username rules, provided that it does not falsely represent another person, a protected role, an official position, an administrative function or another identity.


7. What Users Should Avoid When Anonymity Is Important

A user who wishes to maintain strong anonymity should avoid usernames containing:

Anonymity also depends on what the user voluntarily publishes.

A perfectly anonymous username can lose much of its protective value if the user publicly publishes enough information to identify themselves.

For this reason, anonymity is a combination of:

  1. the architecture of DirectDemocracyS;

  2. the username selected by the user;

  3. the information voluntarily disclosed by the user;

  4. the security of the user's own devices and accounts;

  5. compliance with the DirectDemocracyS rules.


8. External Invisibility

DirectDemocracyS seeks to provide strong external invisibility for users who are entitled to anonymous participation.

For an anonymous user, ordinary visitors, external users and ordinary members should see the user's operational username rather than their real identity.

The objective is that a person viewing the public or ordinary internal profile should not be able to derive the user's:

The user's public or ordinary operational identity is therefore separated from their protected identity information.

This is particularly important for people who participate in political, social, professional, scientific, cultural or other activities and who may have legitimate reasons to protect their personal identity.


9. Internal Invisibility

DirectDemocracyS also applies the principle of internal invisibility.

Internal invisibility means that even within DirectDemocracyS, a person's real identity is not automatically available to every administrator, member, specialist, verifier, manager or other user.

Access to personal identity information is restricted according to:

A person performing a compatibility test does not normally need to know the applicant's legal name.

A person performing a skills assessment does not normally need to know the applicant's legal name.

A person performing an identity verification activity receives only the information and codes necessary to perform that activity.

This separation is one of the principal mechanisms through which DirectDemocracyS seeks to protect anonymity.


10. Important Distinction Between Anonymity, Pseudonymity and Legal Identity

DirectDemocracyS uses strong technical and organisational separation between usernames and real identity.

However, the legal concept of anonymisation must be distinguished from pseudonymisation.

Where DirectDemocracyS retains protected information that could, under exceptional authorised circumstances, be used to establish a connection between a username and a real identity, that information remains personal data under applicable data protection law.

Therefore, this Privacy Policy uses the expression “anonymity and invisibility” to describe the protection experienced by ordinary users and unauthorised persons, while recognising that exceptional legally authorised access may exist.

This does not give ordinary users, ordinary administrators or unauthorised third parties a right to access the protected identity information.


11. User Control Over Visibility

DirectDemocracyS follows another fundamental principle:

Users decide what information they voluntarily make visible, to whom, when and in what manner, except where information must be processed privately for legal, security, technical or organisational reasons.

Where the platform provides a visibility option, users may determine, according to the applicable rules and technical possibilities:

The system does not interpret voluntary publication of one item of information as consent to publish all other information about the same person.

For example, publication of a user's username does not mean that the person's real name, telephone number, address or identity document may also be published.


12. Information That Must Remain Private

Some information is processed for technical, legal or security reasons even when it is not publicly visible.

Examples may include:

Such information is not made public merely because it exists within the DirectDemocracyS system.


13. Categories of Personal Data Processed

Depending on the user's relationship with DirectDemocracyS, the system may process different categories of information.

13.1 Account and registration information

This may include:

A secure, non-temporary personal email address and a unique telephone number are part of the applicable registration and verification procedures.


14. Public Profile Information

A user's profile may contain information voluntarily provided by the user.

Depending on the user's settings and user type, this may include:

The existence of an account does not automatically mean that all of these categories must be publicly displayed.


15. Compatibility Data

For users requesting higher-level participation or identity verification, DirectDemocracyS may process information necessary to determine compatibility with the system.

This may include:

The compatibility process is separate from the identity verification process.

The objective is to evaluate compatibility without unnecessarily exposing the applicant's real identity.


16. Skills and Competence Data

Where a user requests a user type or activity requiring demonstrated skills, DirectDemocracyS may process:

A person does not have to possess prestigious qualifications merely to participate in DirectDemocracyS.

However, where a person claims specific professional or specialist competence for an activity requiring verification, DirectDemocracyS may request evidence appropriate to that activity.


17. Identity Verification Data

Identity verification is a special and highly protected category of processing within the DirectDemocracyS architecture.

Depending on the procedure and applicable user type, identity verification may involve:

DirectDemocracyS applies the principle of data minimisation.

The system should not retain information that is not necessary for the specific purpose.


18. DirectDemocracyS Identity Verification — Three Main Phases

The current DirectDemocracyS identity verification rules establish a structured process.

The process is divided into:

  1. Phase 0 — request and initial information;

  2. Phase 1 — compatibility;

  3. Phase 2 — skills;

  4. Phase 3 — identity verification.

Identity verification is therefore not automatically the first question asked of every participant.

This is an important privacy principle.

A user can participate at lower user levels without mandatory identity verification where the applicable rules permit this.


19. Phase 0 — Request for Identity Verification

When a user requests identity verification, the system requires the information necessary to initiate the process.

The current rules require:

The username remains the user's operational identity.

The fact that the system has a personal email address or telephone number does not mean that these data become visible to ordinary users.


20. Phase 1 — Compatibility Verification

In Phase 1, DirectDemocracyS verifies compatibility with the system.

A unique code is generated.

A corresponding code is provided to an authorised and randomly selected member of an appropriate verification group.

The codes are designed to separate the phases and reduce the possibility of linking information between them without special authorisation.

The compatibility verifier does not ordinarily need to know the applicant's legal identity.

The applicant is operationally identified by their username and the relevant verification code.

The result may be:

The user receives the result through the appropriate communication channel.


21. Phase 2 — Skills Verification

Phase 2 concerns the skills declared by the applicant.

A new unique code is generated for the phase.

An authorised verification group and/or appropriate specialists assess the information and evidence supplied.

The information may include qualifications, documents or other evidence relevant to the claimed competence.

Again, the system uses separation between phases.

The skills verifier does not automatically receive the applicant's complete real identity information merely because the person is undergoing skills verification.

The objective is to verify competence while limiting unnecessary disclosure of personal information.


22. Phase 3 — Identity Verification

Only after the preceding requirements have been completed does the applicant proceed to identity verification.

The system generates another unique identity-verification code.

The applicant receives the code.

The authorised identity-verification member receives the corresponding information necessary to perform the verification.

The verifier does not ordinarily receive the applicant's username or other unnecessary information.

The purpose is to verify the identity document and the person without unnecessarily connecting the person's operational identity to their real-world identity.


23. Identity Verification Video Call

The current DirectDemocracyS procedure uses a live video call for identity verification.

The applicant may be required to:

The call is recorded, encrypted and stored in a protected environment.

The video-verification material is not intended for ordinary public access.


24. Separation Between Username and Real Identity During Verification

One of the central privacy principles of DirectDemocracyS is that the person performing identity verification does not normally need to know the applicant's operational username.

This means that the verifier can perform the verification activity without automatically learning:

The purpose is to reduce the possibility of unnecessary linking.

After successful verification, the system may mark the operational username as verified or guaranteed without making the real identity publicly visible.


25. Identity Documents and Selfies

When an identity document or identification file is uploaded or presented:

  1. it is protected;

  2. it is encrypted;

  3. it is processed only for the verification purpose;

  4. access is restricted;

  5. it is not made publicly visible;

  6. access is limited to highly authorised circumstances;

  7. it may be analysed by authorised technical systems and AI systems where this is part of the implemented verification process;

  8. human access is restricted according to the applicable security rules.

Identity documents are among the most sensitive forms of personal information processed by DirectDemocracyS.

They therefore receive a higher level of protection than ordinary profile information.


26. AI-Assisted Identity Verification

Where DirectDemocracyS uses its Artificial Intelligence systems to support identity verification, the AI system is used as part of the security and verification architecture.

AI-assisted processing may include:

AI processing does not transform protected identity information into public information.

Where applicable, the system must also respect the legal rights relating to automated decision-making.

A user must not be subjected to an unlawful decision producing legal or similarly significant effects solely because an automated system has produced a particular result.

Where human review, reassessment or an additional verification is required by the applicable process, the appropriate human procedure must be followed.


27. Exceptional Access to Identity Information

DirectDemocracyS applies an extremely restrictive approach to access to identity-verification data.

Identity documents, identity-verification files and recorded verification videos are stored in protected environments.

Access may be technically and organisationally restricted to a very small number of highly authorised persons.

Such access must have:

Curiosity is not a legitimate reason for accessing identity data.

A person's administrative position does not automatically give that person unrestricted access to identity information.


28. Official Representatives and Political Representatives

The privacy model is different for official representatives and political representatives because their activities require a higher degree of public or local identifiability.

For official and political representatives, additional identity verification may be required.

This can include direct, in-person verification.

The in-person process uses unique codes and mutual verification for security.

The persons participating in the specific verification activity may necessarily know each other's identity for that activity.

This is an exceptional and purpose-specific disclosure.

It does not mean that every administrator or ordinary user receives access to the person's complete identity-verification records.


29. Political Representative Profiles

Political representatives must be identifiable for the political activities they perform.

For political representative profiles, the applicable DirectDemocracyS rules require the username to contain the person's full name and surname, written according to the applicable linguistic rules.

This is an intentional exception to the ordinary anonymity principle.

The reason is functional and organisational: political representation requires identifiable representatives.

The person's protected verification records remain subject to the security and access restrictions described in this Privacy Policy.


30. Official Representative Profiles

Official representatives may use an anonymous operational username in accordance with the applicable rules.

However, official representatives must be identifiable by the people with whom they conduct their official activities.

This creates a distinction between:

The identity disclosed for an official activity may not be reused for unrelated purposes.


31. Anonymity of Other Users

For user types for which anonymity is guaranteed by the applicable DirectDemocracyS rules, the system seeks to maintain continuous anonymity.

Ordinary users should therefore be represented operationally by their username.

The system is designed so that ordinary users, ordinary members and unauthorised internal personnel cannot simply connect the username with the person's protected identity information.

This is a central privacy feature of DirectDemocracyS.


32. New-User Matching and Human Bridges

DirectDemocracyS has introduced a system under which a new user is connected or matched with an authorised official member.

The purpose includes:

The authorised member receives only the information necessary for the relevant activity.

The existence of this human connection does not automatically grant the authorised member access to the new user's protected identity information.

The matching system does not cancel the user's right to anonymity.


33. Data Generated by Communications

DirectDemocracyS may process information generated when users communicate through:

The content and metadata of such communications are processed only for legitimate purposes, including:

Access to private communications is restricted according to role and purpose.


34. User-Generated Content

Users may voluntarily create:

Before publishing personal information, users should consider whether the information is genuinely necessary.

A user who voluntarily publishes personal information may make themselves identifiable even when their username is anonymous.

DirectDemocracyS cannot guarantee anonymity against information that a user deliberately publishes about themselves or that they voluntarily provide to third parties.


35. Technical and Security Data

For security and operation, DirectDemocracyS may process technical information such as:

These records are not intended to become public profile information.

They are primarily used to operate, secure and protect the system.


36. Cookies and Similar Technologies

DirectDemocracyS may use cookies and similar technical mechanisms where necessary for:

The detailed rules governing cookies are contained in the DirectDemocracyS Cookie Policy.

Where consent is legally required, the appropriate consent mechanism must be used.


37. Legal Bases for Processing

Depending on the specific processing operation, DirectDemocracyS may rely on one or more legal bases recognised under applicable data protection law.

These may include:

37.1 Performance of a contract or requested service

Where processing is necessary to provide the service requested by the user or to manage the user's relationship with DirectDemocracyS.

37.2 Legal obligation

Where DirectDemocracyS must retain or process information because applicable law requires it.

This is particularly relevant to:

37.3 Legitimate interests

Where processing is necessary for legitimate organisational, security, technical or administrative purposes and those interests are not overridden by the rights and freedoms of the person concerned.

Security, prevention of fraud, prevention of abuse and protection of system integrity may constitute legitimate interests where the applicable legal requirements are satisfied.

37.4 Consent

Where consent is legally required or is the appropriate legal basis, DirectDemocracyS will request it in an appropriate manner.

Consent may be withdrawn where applicable.

Withdrawal of consent does not invalidate processing lawfully carried out before withdrawal.


38. Purpose Limitation

Personal data collected for one purpose should not automatically be reused for an unrelated purpose.

For example:

Any new use must have an appropriate legal basis and be compatible with applicable data protection requirements.


39. Data Minimisation

DirectDemocracyS seeks to collect and process only the information necessary for each purpose.

Where a purpose can be achieved without identifying a person, anonymous or less identifying information should be preferred.

Where pseudonymisation can reduce the risk, it should be used where appropriate.

Where encryption can reduce the risk, it should be used.

Where access can be limited, it should be limited.

Where information no longer needs to remain on an accessible system, it should be removed from that accessible environment according to the applicable retention procedure.


40. Data Storage Architecture

DirectDemocracyS uses a distinction between:

  1. systems accessible through the network and used for ordinary operation;

  2. protected private storage environments that are inaccessible from the public network and from the Internet.

As a general operational rule, data are retained on the network-accessible platforms for approximately 7 working days, after which information that must be retained is transferred or archived according to the applicable retention category and security procedure.

This does not mean that every category of information is automatically destroyed after seven working days.

Different categories have different legal and operational retention requirements.

The seven-working-day period is therefore primarily the standard operational-access retention period on the network-accessible platforms, while legally or organisationally necessary records may subsequently be maintained in protected private storage.


41. Private Server Storage

Where information must be retained after its normal operational period, DirectDemocracyS may store it on a private server or protected storage environment that is:

The purpose of this architecture is to reduce the attack surface and to prevent sensitive historical information from remaining continuously exposed through ordinary network-accessible systems.


42. Retention Periods

DirectDemocracyS applies different retention periods according to the category and purpose of the data.

The principal periods currently applicable are:

Category Operational / network-accessible period Protected retention
General operational data Approximately 7 working days According to purpose and applicable necessity
Accounting and tax records Approximately 7 working days on ordinary platforms Approximately 10 years where legally required
Employee data Approximately 7 working days on ordinary platforms According to the specific legal and employment retention period
Video-surveillance images Generally 24–72 hours on the network-accessible server Up to 365 days in protected private storage where required by the applicable security/organisational policy
Marketing data Approximately 7 working days on ordinary platforms 24 months from the last administrative contact, or longer where required by applicable law
Identity-verification records Limited operational exposure According to verification, security, legal and organisational necessity
Verification videos Limited operational exposure According to the applicable security and verification retention schedule
Security records Limited operational exposure According to security, legal and incident-management requirements
Backups According to backup cycle According to backup and disaster-recovery requirements

The exact retention period must always be interpreted together with the applicable law.

Where a law requires a longer period, the legally required period prevails.

Where no legal requirement exists, DirectDemocracyS should retain the information only for as long as reasonably necessary for the stated purpose.


43. Accounting and Tax Records

Accounting records and documents required by tax legislation are retained for approximately 10 years, where required by the applicable fiscal obligations.

The purpose is to comply with legal, accounting and tax requirements.

The longer retention of these records does not mean that they are publicly accessible.

They remain protected and subject to access restrictions.


44. Employee Data

Employee information is subject to specific retention periods determined by:

Employee records therefore do not have a single universal retention period.

DirectDemocracyS maintains specific retention schedules for employee information according to the applicable legal requirements.


45. Video-Surveillance Data

Where DirectDemocracyS uses video surveillance, images recorded by the surveillance system are generally removed from the network-accessible server after approximately 24–72 hours, subject to the applicable legal and operational requirements.

Where a longer retention is necessary for security, investigation, legal or organisational purposes, relevant material may be retained for up to 365 days on a private server that is inaccessible from outside and from the Internet.

Access to retained surveillance material is restricted.

Video surveillance is not intended to create a permanent public record of people's movements.


46. Marketing Data

Where DirectDemocracyS lawfully processes marketing-related information, the standard retention period is approximately 24 months from the last administrative contact, unless a longer period is required by applicable law in the relevant country or local jurisdiction.

Marketing information is not automatically retained indefinitely.

Where applicable, users may exercise the right to object to direct marketing and may withdraw consent where consent is the applicable legal basis.


47. Data Security

DirectDemocracyS applies technical and organisational measures intended to protect personal data against:

Depending on the system and purpose, security measures may include:


48. Need-to-Know Principle

A person within DirectDemocracyS should have access only to information necessary for the activity they are authorised to perform.

For example:

A compatibility verifier does not need the user's identity document.

A skills verifier does not need unrestricted access to the user's identity document.

A technical administrator does not automatically need to know a user's real name.

A member helping a new user does not automatically receive access to identity-verification records.

A user does not receive access to another user's private personal information simply because both are members.

This principle applies regardless of organisational rank, subject to exceptional and documented security or legal requirements.


49. Special Protection for Privileged Users

Administrators, SuperAdministrators, Guarantors and other privileged users may have access to systems containing more sensitive information.

However, higher organisational authority does not mean unlimited privacy access.

Privileged access should remain:

The more sensitive the data, the more restricted access should be.


50. Exceptional Access

There may be exceptional situations in which protected information must be accessed.

Examples may include:

Exceptional access must not become ordinary access.

Where technically possible, exceptional access should be:


51. Disclosure to Public Authorities

DirectDemocracyS may disclose personal data to competent public authorities where this is:

DirectDemocracyS does not interpret a general request from an authority as an automatic right to unrestricted access to all information.

The request must be handled according to applicable law and the principle of minimisation.


52. Processors and Internal Authorised Units

The effective DirectDemocracyS processing structure is intentionally limited.

The current operational environment consists primarily of:

Authorised internal groups operate under DirectDemocracyS rules and access controls and do not automatically constitute independent external data controllers or processors merely because they are separate operational groups.

Where an external service provider or legally separate entity is actually engaged to process personal data on behalf of DirectDemocracyS, that relationship must be governed by the applicable data protection requirements and documented appropriately.

The list of actual external processors should therefore always reflect the providers actually used at the time this Policy is applied.

DirectDemocracyS does not sell or rent users' personal data.


53. No Sale of Personal Data

DirectDemocracyS does not sell personal data.

It does not rent personal information to third parties for commercial exploitation.

Personal data are not treated as a commodity.

The existence of a DirectDemocracyS account does not constitute permission for unrelated organisations to commercially exploit the user's identity.


54. International Data Transfers

Where personal data are transferred outside the European Economic Area, DirectDemocracyS applies the safeguards required by applicable data protection law.

Depending on the circumstances, these may include:

The specific transfer mechanism depends on the actual location of the receiving system and the applicable law.

DirectDemocracyS should maintain an up-to-date record of actual international transfers.


55. Data Accuracy

DirectDemocracyS seeks to maintain accurate information.

Users may be asked to correct information that is:

Where the user controls the information directly through their account, they should use the available profile-management tools.

Where the information cannot be changed directly, the user may contact the privacy team.


56. Right of Access

A person may have the right to request confirmation as to whether DirectDemocracyS processes their personal data and, where applicable, to obtain access to those data.

Access may include:

DirectDemocracyS may need to verify that the requester is entitled to receive the information.

This verification should be proportionate and should not unnecessarily undermine the user's anonymity.


57. Right to Rectification

Users may request correction of inaccurate personal data.

Where appropriate, DirectDemocracyS may also update information internally when an error is discovered.

Identity-verification information may be subject to specific verification procedures because changing such information can affect the integrity of the verification process.


58. Right to Erasure

Where applicable, a person may request deletion of their personal data.

However, the right to erasure is not absolute.

DirectDemocracyS may retain certain information where retention is necessary or legally required, including:

Where complete deletion is not legally possible, DirectDemocracyS should restrict processing and, where appropriate, anonymise or isolate the information.


59. Right to Restriction of Processing

Where applicable, a person may request restriction of processing, for example where:

Restricted data should not be used beyond the purposes permitted by applicable law.


60. Right to Object

Where the applicable legal basis permits objection, a person may object to certain processing.

This may be particularly relevant to:

DirectDemocracyS will assess the objection according to the applicable legal requirements.


61. Right to Data Portability

Where the legal conditions for portability are satisfied, a person may request their personal data in a structured, commonly used and machine-readable format.

Portability generally applies only to the categories and legal circumstances defined by applicable data protection law.


62. Automated Decision-Making

DirectDemocracyS may use automated systems and AI to support certain processes.

Examples may include:

Automated processing must not unlawfully remove the rights of the person concerned.

Where applicable law grants a right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, DirectDemocracyS must respect that right and provide the safeguards required by law.


63. Exercising Privacy Rights While Remaining Anonymous

DirectDemocracyS recognises a particular difficulty created by strong anonymity.

If a person uses an entirely random username and DirectDemocracyS does not publicly connect that username to their real identity, the system may not be able to determine whether a person making a request is genuinely the account holder.

In such cases, DirectDemocracyS may request reasonable proof of control over the relevant account or another proportionate verification mechanism.

The purpose is not to destroy anonymity.

The purpose is to prevent one person from obtaining another person's private information.

DirectDemocracyS should therefore seek to verify entitlement without collecting unnecessary additional personal data.


64. Data Breaches and Security Incidents

DirectDemocracyS maintains procedures for identifying, containing, investigating and responding to security incidents.

Where a personal-data breach occurs, DirectDemocracyS will assess:

The applicable notification deadlines and procedures are determined by law.


65. Privacy by Design

Privacy is incorporated into the DirectDemocracyS architecture from the beginning rather than added only after a system has been developed.

Examples include:

The objective is to reduce the amount of personal information that any individual person can access.


66. Privacy by Default

Where a user has not actively chosen to make information public, the system should apply the most privacy-protective setting reasonably available.

This means that private information should not become public merely because a user has created an account.

The default should be:

minimum necessary visibility, unless greater visibility is deliberately chosen or required for the user's activity.


67. Security Does Not Cancel Privacy

DirectDemocracyS recognises that security and privacy must work together.

Security procedures may require processing personal information.

However, security is not a general justification for unlimited access.

The appropriate approach is:


68. Privacy and Democratic Participation

DirectDemocracyS distinguishes between:

  1. the right to participate;

  2. the right to anonymity;

  3. the right to verified identity;

  4. the right to shared leadership;

  5. the right to collective ownership;

  6. the responsibilities of official representation;

  7. the requirements of political representation.

These rights and responsibilities are not identical.

A person does not lose their general right to privacy merely because another person chooses to become an official or political representative.

At the same time, a person who voluntarily requests a role requiring verified identity must accept the additional verification requirements applicable to that role.


69. Privacy and Collective Ownership

Collective ownership is one of the reasons for the identity-verification requirements applicable to official members.

Where the rules require a verified and guaranteed identity for official membership, the identity verification exists to establish eligibility for that specific legal and organisational function.

It does not mean that the person's identity becomes publicly available to every other member.

Verification of eligibility and public disclosure of identity are two different concepts.


70. Privacy and Shared Leadership

Similarly, binding participation in shared leadership may require a verified identity.

The verification exists to ensure that the person exercising the corresponding rights is a real, eligible and uniquely identified participant.

The underlying identity remains protected from ordinary users unless the applicable role requires public identification.


71. Privacy and the Different User Types

DirectDemocracyS uses different user types because not every activity requires the same level of verification.

The general principle is:

Higher responsibility may require higher verification, but higher verification does not automatically mean unrestricted public disclosure.

A Free user may remain anonymous where the rules permit.

A Verified user may have a verified identity while still operating publicly through a username.

An official member may have additional rights and responsibilities while their real identity remains protected from ordinary users.

A political representative must be identifiable because political representation requires it.


72. Children and Age-Related Processing

Age-related processing is governed by the applicable DirectDemocracyS participation rules and by the law applicable to the relevant user.

Where age verification is required for a specific service or legal obligation, DirectDemocracyS processes only the information necessary for that purpose.

No unnecessary age-related information should be made public.


73. Third-Party Websites and External Services

DirectDemocracyS may contain links to external websites or services.

When a user leaves a DirectDemocracyS platform and accesses an external service, that service may have its own:

DirectDemocracyS is not responsible for processing performed independently by an external website outside the DirectDemocracyS system.

Users should therefore review the privacy information of external services before providing them with personal data.


74. User Responsibility for Personal Disclosure

DirectDemocracyS provides strong privacy architecture, but no system can protect a user from every form of voluntary disclosure.

A user may unintentionally identify themselves through:

Users who require strong anonymity should therefore avoid voluntarily publishing combinations of information that make identification easy.


75. Relationship Between the Username and the Personal Data

The username is the primary operational identifier within DirectDemocracyS.

For an anonymous user, the username should not reveal the person's legal identity.

Protected information such as:

must not automatically be inferred from the username.

Where the technical architecture permits, identity information and operational information should be maintained in separate logical and technical environments.


76. Special Protection of Identity-Verification Servers

Identity-verification data and other particularly sensitive information may be stored on servers inaccessible from the public network.

This architecture is intended to provide an additional security layer.

The fact that information exists on a private server does not eliminate the obligation to protect it.

Private storage must therefore also be subject to:


77. Backup Copies

Backups may contain personal data because they are necessary to restore system availability and integrity.

Backups should be protected with security measures appropriate to the data they contain.

Backup copies should not be treated as an excuse for indefinite retention.

Where data are deleted according to the applicable retention schedule, the deletion process should also consider backup cycles and technical limitations.


78. Data Concerning Security Investigations

Where DirectDemocracyS investigates serious violations, fraud, identity misuse, abuse or security incidents, it may temporarily process additional information.

Such information may include:

Access is restricted to authorised persons.

The information must not be used for unrelated purposes without an appropriate legal basis.


79. Data Concerning Disciplinary Procedures

Where the DirectDemocracyS rules provide for sanctions, a disciplinary or security process may require processing information necessary to:

Disciplinary records remain subject to confidentiality and retention rules.


80. Confidentiality of Internal Groups

DirectDemocracyS operates through specialist, security, administrative, legal, verification and other internal groups.

Membership in an internal group does not grant unlimited access to all personal data.

Each group should receive only the information necessary for its authorised activity.

Information received for one activity must not be redistributed to another group unless there is a legitimate reason and appropriate authorisation.


81. Confidentiality Obligations of Authorised Members

Persons authorised to access protected personal information must respect confidentiality.

They must not:

Violations may result in the sanctions provided by DirectDemocracyS rules and, where applicable, legal consequences.


82. Human Bridges and Privacy

DirectDemocracyS may use human bridges between users and authorised members, and between humans and Artificial Intelligence systems.

The existence of a human bridge does not automatically authorise disclosure of the user's protected personal information.

The bridge should receive only what is necessary to perform its specific role.

Where an AI system is involved, personal data must also be protected according to the applicable privacy and security requirements.


83. Artificial Intelligence and Personal Data

DirectDemocracyS may use Artificial Intelligence systems as part of its technological architecture.

This may include ddsAI, allddsAI or other authorised AI systems where applicable.

AI may assist with:

AI systems do not automatically receive unrestricted access to personal data.

The same principles apply to AI processing as to human processing:

Where AI processing is not necessary, personal data should not be provided merely because the technology is available.


84. No Generalised AI Access to Private Identity

The existence of an AI system inside the DirectDemocracyS ecosystem does not create a general right for that AI system to access all identity information.

Highly sensitive identity data remain protected.

Access should be technically restricted to the specific AI function for which processing is authorised.


85. Data Retention and the Right to Privacy

DirectDemocracyS recognises that retaining personal information creates risk.

For this reason, the system follows a two-level approach:

Operational storage

Data remain on ordinary network-accessible systems for approximately seven working days as a general operational period.

Protected storage

Information that must be retained for legal, security, accounting, employment, verification, historical, administrative or other legitimate reasons may be transferred to protected private storage.

This separation reduces the continuous exposure of historical information.


86. Review of Retention Periods

Retention periods should be reviewed periodically.

If information is no longer required, it should be:

The fact that storage is inexpensive does not constitute a justification for indefinite retention.


87. Local, National and European Legal Requirements

DirectDemocracyS operates from Romania and within the European Union while potentially interacting with users and activities in multiple jurisdictions.

Different legal systems may impose different retention, employment, accounting, tax, security, marketing or other requirements.

Where applicable law requires a different period from the general DirectDemocracyS retention period, the legally required period applies to the relevant processing activity.

The system therefore maintains category-specific retention requirements rather than treating all data identically.


88. Marketing and Communications

Marketing communications are subject to applicable law.

Where consent is required, communications will be sent only where valid consent exists.

Where another legal basis is applicable, DirectDemocracyS will comply with the requirements governing that basis.

Users may unsubscribe or exercise applicable objection rights.

Marketing information is normally retained for approximately 24 months from the last administrative contact, unless a longer legally required period applies.


89. Administrative Communications

Administrative communications are different from marketing.

They may be necessary for:

Because these communications may be necessary to operate the relationship with the user, they may not always be subject to the same opt-out rules as marketing.


90. Changes to This Privacy Policy

DirectDemocracyS may update this Privacy Policy when:

The version and date of the Policy will be updated.

Where legally required, users will receive appropriate notice of material changes.


91. No Reduction of Existing Privacy Rights Through a Mere Policy Change

A modification to this Privacy Policy does not automatically authorise DirectDemocracyS to process personal data for an unrelated new purpose.

Where a new processing activity requires:

the applicable requirement must be satisfied.


92. Transparency and Accountability

DirectDemocracyS considers transparency and accountability fundamental to its privacy model.

The organisation should be able to demonstrate:

Privacy is therefore not only a statement of intention.

It is an organisational responsibility.


93. Summary of the DirectDemocracyS Privacy Model

The DirectDemocracyS privacy model can be summarised through the following principles:

1. Your username is your operational identity.

You may use an anonymous username where the applicable user type permits it.

2. Your real identity is not automatically public.

Even identity verification does not automatically mean public disclosure.

3. Verification and visibility are separate concepts.

A person may be verified while remaining operationally anonymous.

4. Different activities see different information.

Compatibility, skills and identity verification are separated.

5. Unique codes reduce unnecessary linking.

Different phases use different verification codes.

6. Identity documents receive special protection.

They are not ordinary profile information.

7. Verification videos receive special protection.

They are recorded, encrypted and stored in protected environments according to the applicable rules.

8. Access is based on necessity.

A person does not receive access merely because they are a member or administrator.

9. Network-accessible retention is limited.

The general operational period is approximately seven working days.

10. Longer retention is protected.

Where retention is necessary, information may be transferred to private storage inaccessible from the public network.

11. Accounting records may be retained for approximately ten years.

This is required by applicable tax and accounting obligations.

12. Video-surveillance data are generally removed from accessible systems after approximately 24–72 hours.

Where required, protected retention may extend to 365 days.

13. Marketing data are generally retained for approximately 24 months from the last administrative contact.

Applicable local or national legal requirements may require a different period.

14. Political representatives are identifiable.

This is a specific exception required by the nature of political representation.

15. Official representatives may use anonymous profiles but must identify themselves in their official activities.

16. Ordinary users retain strong anonymity.

Their real identity is not normally disclosed to other users.

17. Users control voluntary disclosure.

They choose what they reveal, to whom, when and how, within the limits required by the system and applicable law.

18. DirectDemocracyS does not sell personal data.

19. Privacy is part of the architecture.

It is not merely a document added after the system has been built.


94. Detailed Data Protection Matrix

Data category Main purpose Ordinary visibility Typical operational retention Longer protected retention
Username Operational identification According to profile/user type Approximately 7 working days on operational systems as applicable While account/records require it
Email address Registration, communication, security Private Approximately 7 working days operationally According to account/legal necessity
Telephone number Verification and security Private Approximately 7 working days operationally According to account/security necessity
Password/authentication data Account security Never public According to security requirements According to security requirements
Profile information User participation User-controlled where available According to account/activity requirements According to purpose
Public posts/comments User participation and publication Public if deliberately published According to publication/system rules According to applicable content-retention rules
Compatibility information Compatibility assessment Restricted Limited According to verification/security requirements
Skills information Skills assessment Restricted Limited According to verification/security requirements
Identity documents Identity verification Never public Extremely limited Protected retention according to verification/legal necessity
Selfie/photo-ID verification Identity verification Never public Extremely limited Protected retention according to verification/legal necessity
Verification videos Identity verification/security Never public Limited Protected storage according to applicable rules
Verification codes Secure process control Restricted Limited Only as necessary
Security logs Security and abuse prevention Never public Limited According to security/legal requirements
Accounting information Tax/accounting obligations Restricted Limited operational exposure Approximately 10 years where required
Employee information Employment obligations Restricted Limited operational exposure According to applicable legal schedule
Video-surveillance images Security Never public Generally 24–72 hours on accessible server Up to 365 days in protected storage where applicable
Marketing information Lawful marketing Restricted Limited Approximately 24 months from last administrative contact or legal period
Support communications Assistance and administration Restricted Limited According to purpose/legal necessity
Incident records Security/legal protection Highly restricted Limited According to legal/security necessity

95. User Rights — Practical Procedure

A user wishing to exercise a privacy right should contact:

This email address is being protected from spambots. You need JavaScript enabled to view it.

The request should indicate, as appropriate:

Users should not send unnecessary copies of identity documents unless specifically requested through an authorised and secure procedure.

DirectDemocracyS will attempt to use the least intrusive method necessary to establish the applicant's entitlement.


96. Data Protection Officer

The Data Protection Officer designated for DirectDemocracyS is:

Franco-Romeo Zaccherini

The DPO may be contacted through:

This email address is being protected from spambots. You need JavaScript enabled to view it.

The DPO's role includes supporting the organisation's compliance with applicable data protection requirements and serving as a contact point for privacy-related matters.


97. Supervisory Authority

Where a person believes that their personal data have been processed unlawfully, they may have the right to lodge a complaint with the competent data protection supervisory authority.

For persons subject to European data protection law, the competent authority depends on the circumstances, including residence, workplace and the location of the relevant processing.

DirectDemocracyS encourages users to contact the organisation first where appropriate so that privacy issues can be investigated and resolved internally, without prejudice to the person's statutory right to contact a supervisory authority.


98. Relationship With Other DirectDemocracyS Rules

This Privacy Policy must be read together with the applicable DirectDemocracyS rules, particularly:

Where a specific operational procedure provides additional privacy safeguards, those safeguards remain applicable.


99. Privacy as a Fundamental Freedom

DirectDemocracyS considers privacy to be closely connected with freedom.

A person should be able to:

Privacy therefore protects not only data.

It protects the person's freedom to participate.


100. Final Commitment

DirectDemocracyS is committed to protecting personal data through a combination of:

The central principle is simple:

The fact that DirectDemocracyS may be able to know something about a person does not mean that everyone else has the right to know it.

The system distinguishes between what must be known, what may be known, what may be voluntarily disclosed and what must remain protected.

For ordinary users, the person's username is their operational identity.

For users requiring verified identity, verification establishes eligibility without automatically creating public disclosure.

For official and political representatives, additional identification requirements apply because of their responsibilities.

In all cases, personal information should be processed only for legitimate, necessary and proportionate purposes, protected against unauthorised access and retained only for as long as required.


101. Official Contact Information

DirectDemocracyS

European Commission PIC: 881951064

Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union

Privacy and data protection:
This email address is being protected from spambots. You need JavaScript enabled to view it.

Data Protection Officer:
Franco-Romeo Zaccherini

Privacy Policy version: 1.0

Publication date: 22 September 2026


102. Document Status

This Privacy Policy is the general DirectDemocracyS privacy framework.

It is intended to govern the processing of personal data across the DirectDemocracyS system, its platforms, websites and authorised organisational structures.

Specific processing activities may be governed by additional notices, implementing rules, consent mechanisms, contractual provisions or legally required information.

Where a specific activity requires more detailed information than this general Policy provides, the relevant specific privacy notice must be provided to the person concerned.

DirectDemocracyS will periodically review this document to ensure that it remains consistent with:

End of Privacy Policy

DirectDemocracyS — 22 September 2026