1. Who is responsible for your data

MARCO POLO C.E.E. S.R.L. is the controller of the personal data described in this policy. Our identification and contact details are set out in the block above.

We are committed to protecting the personal data of the people we work with. This policy describes what we collect, why, on what legal basis, who we share it with, how long we keep it, and what rights you have.

For any question about this policy or about how we handle your data, write to office@marcopolocee.com.

2. What data we collect and where it comes from

Marco Polo CEE provides commercial and management consultancy, training and coaching services. For those purposes we collect and process personal data received either directly from you — when you fill in a form, write to us, subscribe to the newsletter, or take part in a programme — or indirectly from our corporate clients, who ask us to deliver services to their employees under a commercial contract.

Where data reaches us through a corporate client, that client is required by written agreement to ensure an adequate level of protection and to have a lawful basis for passing the data to us.

The categories we typically process are: name and surname, contact details (email, phone), employer, role and seniority, professional interests, and — where a programme includes them — assessment responses, individual profile results, manager evaluations and attendance records. We collect only what is necessary and relevant for delivering the service.

We do not seek to collect special categories of data (health, political opinions, religious beliefs, trade union membership and similar). Please do not include such information in free-text fields.

3. Why we process it, and on what legal basis

We process personal data only for the purposes set out below, and only on the legal bases indicated.

4. Who we share data with

We do not sell personal data, and we do not disclose it to third parties for their own marketing purposes.

We may share data with:

  • Our consultants and trainers, to the extent needed to deliver the programme you take part in;
  • The corporate client that commissioned a programme — normally in aggregated form. Individual assessment results are shared with an employer only where the participant has been informed and, where required, has consented;
  • Service providers acting as processors on our written instructions — including our learning platform provider (PROMOTE), assessment instrument providers (TTI Success Insights for DISC, the PCM licensor), hosting, email and IT support providers;
  • Partner organizations in the Marco Polo Performance network, where a programme is delivered jointly, under written agreements imposing equivalent protection;
  • Public authorities, where we are required to do so by law.

5. Transfers outside the European Economic Area

We deliver in the European Union, the United States, the Middle East, Central Asia and Africa, and some of our service providers operate outside the European Economic Area.

Where personal data is transferred outside the EEA, we do so only on the basis of an adequacy decision of the European Commission, or under Standard Contractual Clauses adopted by the Commission together with any supplementary measures required. You can request a copy of the safeguards in place by writing to us.

6. How long we keep it

We keep personal data only for as long as necessary for the purpose for which it was collected, and then for any period required by law.

  • Enquiries that do not lead to a contract — up to 24 months from the last contact.
  • Programme participation and assessment records — for the duration of the contract with the client and up to 3 years after it ends, unless the contract provides otherwise.
  • Newsletter subscriptions — until you unsubscribe, and then for a short period to record the withdrawal of consent.
  • Accounting and invoicing documents — for the periods required by Romanian fiscal and accounting legislation.

We review our data protection impact assessment periodically, at intervals of no more than three years.

7. How we protect it

Personal data is collected, processed and stored in a controlled manner, through technical and organisational measures implemented by Marco Polo CEE — including access control on a need-to-know basis, encryption in transit, confidentiality undertakings from all consultants and staff, and written processing agreements with our providers.

No system is completely secure. If a personal data breach occurs that is likely to result in a high risk to your rights and freedoms, we will inform you and the supervisory authority in accordance with the GDPR.

8. Automated decision-making

We do not take decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.

Assessment instruments such as DISC or PCM generate an individual profile, but that profile is always interpreted and debriefed by a certified consultant and is never used on its own as the basis of a decision about a person.

9. Your rights

Under the GDPR you have the following rights in relation to your personal data.

  • Right of access — to obtain confirmation of whether we process your data and a copy of it.
  • Right to rectification — to have inaccurate or incomplete data corrected.
  • Right to erasure — to have your data deleted in the circumstances set out in the GDPR.
  • Right to restriction of processing — to limit how we use your data in certain situations.
  • Right to data portability — to receive the data you provided in a structured, machine-readable format, or to have it transmitted to another controller.
  • Right to object — to processing based on legitimate interest, and at any time and without justification to processing for direct marketing.
  • Right to withdraw consent — at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before it.
  • Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you.

To exercise any of them, write to office@marcopolocee.com, or send a dated and signed written request to MARCO POLO C.E.E. S.R.L., Strada Piața Amzei nr. 5, et. 1, ap. 14, Sector 1, București, Romania. We will respond within one month; if the request is complex we may extend that period by two further months and will tell you if we do.

If we refuse a request — for example on the basis of an exception provided by law — we will explain why, and you may challenge that decision.

10. Complaints

If you believe we have not handled your personal data correctly, we would prefer you to tell us first so that we can put it right.

You also have the right to lodge a complaint with the Romanian supervisory authority:

Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28–30, Sector 1, 010336 București, Romania
www.dataprotection.ro · anspdcp@dataprotection.ro

If you are resident in another EU member state, you may also complain to the supervisory authority of that state.

11. Changes to this policy

We may update this policy to reflect changes in our processing activities or in applicable law. Where a change is material, we will inform you before it takes effect. The date of the last update is shown at the top of this page.