Thank you for your interest in our company and services. Data Privacy is an important topic for us. When you enter a relationship of any kind with us, you trust us with your information. The information set out in this document (from now on referred to as 'the Privacy Policy' or 'the document') is important. We recommend that you read this Privacy Policy carefully. We recommend that you read this document together with our Terms of Service. In the event of a conflict or inconsistency between the terms of this Privacy Policy and any other clauses from our Terms of Service, the terms of this document shall prevail. For more information about the use of cookies or similar technologies, please refer to our Cookie Usage Policy.
The purpose of this Privacy Policy is to explain, among other things, what personal data we process (e.g., collect, use, share), why we process it, how we process it, your rights under the GDPR, and how you can exercise these rights. Because we process this kind of information (i.e., personal data), we act as a controller according to Data Protection Laws. Consequently, we are legally bound to inform you about how we process your personal data.
Being fully aware that your personal information belongs to you, we do our utmost to store it safely and process it carefully. We do not provide information to third parties without informing you in accordance with Data Protection Laws. We do not make decisions based solely on automated processing, including profiling, decisions that produce legal effects concerning you or similarly affect you.
By visiting the website, using our services, or interacting with us through any means or any communication channel (e.g., e-mail, phone, social media), you agree to this Privacy Policy. If you do not agree to the provisions described in this Privacy Policy, please do not use the services provided by JoinMyMoment.
JoinMyMoment is a data controller under the GDPR for the processing of personal data of Customers. Each Customer using our services is a data controller for the end-user of the services. This Privacy Policy only covers data processing for which JoinMyMoment is a controller. If you have any questions regarding the processing of your personal data by our Customers when using our services, please contact them for this reason.
2.1. 'GDPR' means REGULATION (EU) 2016/679 of The European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
2.2. 'Controller' or 'JoinMyMoment' or 'we' means ASQUARED SRL, a Romanian company with registered office in Brasov, str Harmanului nr 15, bl 30BIS, ap 10, camera 1, registered with the Trade Register in Bucharest under no. J2024032303003, with fiscal registration code 50719801.
2.3. 'Customer' means any company or individual person other than JoinMyMoment who accesses or uses the JoinMyMoment's services.
2.4. 'Customer solution' means any Software solution (including application) used to integrate JoinMyMoment's services.
2.5. 'Data subject' means any identified or identifiable natural person whose data is processed by us as a controller, such as clients, potential clients, or website visitors.
2.6. 'Terms of Service' means the consensual distance agreement between Customers or potential Customers and JoinMyMoment, without their simultaneous physical presence, regarding the purchase and use of the Services, subject to the legal provisions and contractual clauses for the online provision of JoinMyMoment's services.
2.7. 'Services' means the services provided by JoinMyMoment to Customers as described on the website and regulated by the Terms of Service of JoinMyMoment.
2.8. 'Platform' means the set of servers and software through which the services presented and offered by JoinMyMoment are provided under the Terms of Service of JoinMyMoment.
2.9. 'Site' or 'Website' means JoinMyMoment's website with the domain https://joinmymoment.com/ and subdomains https://app.joinmymoment.com/ and https://b2b.joinmymoment.com/ and where JoinMyMoment presents the Services offered for performance and Customers may choose to purchase the services and to pay for them using one of the payment methods accepted by JoinMyMoment.
2.10. 'Data Protection Laws' means all data protection regulations applicable to a party's processing of Customer Data, including, where applicable, EU Data Protection Laws and non-EU Data Protection Laws.
2.11. 'EU Data Protection Laws' means all data protection laws and regulations applicable to Europe, Including (i) Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation) ('GDPR'); (ii) Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector; (iii) data protection laws of EU member states.
2.12. 'Processing' means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
2.13. 'Consent' of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
2.14. 'Personal Data' means any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Other terms used in this document have the meaning given by the GDPR and other applicable legal provisions.
This Privacy Policy does not cover other third-party applications or websites that you can reach by accessing links on our website because these applications or websites are not under our control. We encourage you to read the Privacy Policy on any website and application before providing your personal data.
ASQUARED SRL, a Romanian company with a registered office in Brasov, str Harmanului nr 15, bl 30BIS, ap 10, camera 1, registered with the Trade Register in Bucharest under no. J2024032303003, with fiscal registration code 50719801, e-mail contact@joinmymoment.com, is responsible for processing your personal data that we collect directly from you or from other sources.
According to the law, our company is a data controller. Therefore, for your personal data to be processed safely, we have implemented reasonable and appropriate technical and organizational measures to protect your personal data.
Under Data Protections Laws, you, the natural person who is the beneficiary of our services, the representative or contact person of a company that is our customer or potential customer, the website visitor or the person in any relationship with JoinMyMoment whose personal data are being processed, are a 'data subject' (i.e., an identified or identifiable natural person). In order to be completely transparent about data processing and to allow you to exercise your rights easily at any time, we have implemented measures to facilitate the exercise of rights. For more information, please refer to the sections 14 and 15 of this document.
Protecting your personal information is important to us. That is why we are committed to respecting European and national legislation on the protection of personal data, in particular GDPR and the following principles:
Lawfulness, fairness, and transparency
We process your data legally and correctly. We are always transparent about the information we use, and you are informed accordingly.
You are in control
According to the Data Protection Laws, we offer you the opportunity to review, modify, delete personal data you have shared with us and exercise your other legal rights. For more information about exercising your rights, please refer to sections 14 and 15 of this document.
Data integrity and purpose limitation
We use the data only for the purposes described at the time of collection or for new purposes compatible with the original ones. In all cases, our purposes are consistent with the law. In addition, we take reasonable steps to ensure that personal data is accurate, complete and up-to-date.
Security
We have implemented reasonable security measures for the processing of personal data in order to best protect your personal information. For more information, please refer to section 12 and Annex A of this document. However, please note that no website, application or internet connection is completely secure.
We may change this Privacy Policy at any time. All updates, information, and changes to this Privacy Policy are effective or at a later date specified in the updated Privacy Policy. The new Privacy Policy will be displayed on our website.
When you browse our website, send us an email request or contact us in any other way and on any other communication channel, when you sign up, sign in or request a password change and when you purchase one of our paid Services or pay for our Services in any way, we might process the following personal data, which we receive directly from you or from other sources, as explained in the table below.
| Categories | Purpose(s) | Legal basis(es) |
|---|---|---|
| Account Data (name, e-mail, sign up ip & user agent, sign in sessions, ip & user agent, Google ID when using Sign In With Google, etc.) |
|
|
| Data Required for Billing (name, e-mail, country, address, payment method, last 4 digits of credit card, etc.) |
|
|
| Data Used for E-mail Marketing (name, e-mail) |
|
|
| Customer Support Data (name, e-mail, country, IP, social accounts, etc.) |
|
|
| HTTP Access & Error Logs (IP, user agent, visits, etc.) |
|
|
| Third-Party Integration Data (Google Photos) (Google account email address, OAuth access tokens, OAuth refresh tokens, token expiry dates, album metadata for albums created through our Service) |
|
|
*Although we have made every possible effort to identify all personal data processed and purposes, please note that the above table is not exhaustive.
Most of the information is collected directly from you (for example, by filling in a form on the Website). Generally, we process data as described above, but there may be situations where we collect data from third parties (i.e. partners, platforms).
In addition to the information indicated above, we may collect the following information, depending on the circumstances:
If you make purchases through our partners, in certain situations, certain payment information (e.g., card data) will be processed. Generally, this information is processed by our partners. Therefore, we cannot read or access that kind of data, except some categories of personal data (i.e., the payment method, last four digits of your credit card number, country and e-mail).
In addition to the purposes listed in the table in the previous section, we process personal data for the following purposes:
(A) Registration as a user. If you decide to register as a user on our website, we must process your data to identify you as a user of this website and to give you access to its various functionalities or services available to you as a registered user. You can also log in through a Google account to register as a new user or log in. In this case, your login data and your name and your e-mail address (if you accept this) will be imported from your Google account. In any case, we recommend that you check your privacy settings and read Google's Privacy Policy.
(B) Improving services. If you use our services, we inform you that we will process your navigation data for analytical and statistical purposes, in order to understand how users interact with our Site, and therefore we can improve it.
When we ask you to give your personal data in order to provide you access to certain website features or services, we will mark some fields as mandatory because this is the information we need to be able to provide you with that service or to give you access to that functionality.
Please note that if you decide not to give us the mandatory information, you may not be able to complete your registration as a user or benefit from these services or functionalities.
(A) Legitimate interest. If we use the legitimate interest, we carry out a legitimate interest analysis (i.e., balancing test) in order to balance our interest and your interests. If our interests prevail, we will use the legitimate interest. If your interests prevail, we will not use the legitimate interest, and if we fail to identify another correct legal basis, we will not carry out that processing activity. We currently use the legitimate interest for the data categories listed in the table in Section 8.
(b) Consent. Please note that consent is not mandatory, and we will only obtain your consent in situations where we have failed to use another legal basis. We currently use consent for e-mail marketing purposes only.
(c) Vital interest. In the unlikely event of a medical emergency or other exceptional circumstances, processing may be necessary to protect your vital or other individual's interests.
JoinMyMoment offers an optional integration with Google Photos that allows you to upload photos and videos from your Moments directly to your Google Photos account. This section explains how we handle data when you use this integration.
(A) What data we access and collect:
(B) How we use this data:
(C) What we do NOT do with your Google data:
(D) Data security for Google Photos integration:
(E) Disconnecting the integration:
You can disconnect your Google Photos account at any time from your JoinMyMoment account settings. When you disconnect:
(F) Google API Services User Data Policy Compliance:
JoinMyMoment's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use data obtained through Google APIs for the purposes described in this Privacy Policy and as explicitly authorized by you.
If you are an end-user of our services, this information is important to you.
(A) Qualification under the GDPR. Under the GDPR, we are the processor, and we process the end-user's personal data only under the instructions issued by the controller.
(B) Information. As we are a processor, it is not our responsibility to inform but the controller's, so we recommend that you read the privacy policy of the controller processing your data (our customer).
(C) Consent. As we are a processor, it is not our responsibility to get consent but the controller's, so we recommend that you address the data controller if you have any such requests.
(D) The exercise of rights under the GDPR. As we are a processor, it is not our responsibility to facilitate the exercise of your rights (but we will assist the controller in so far as we are bound by law or agreements), but this is the controller's responsibility. Therefore, we recommend that you address the controller who is processing your data if you have a request to exercise a right under the GDPR.
We only keep your personal data for as long as it is necessary to fulfill the purposes, but no longer than five years after the end of the contract (for customers) or after the last interaction with us (for other categories of data subjects).
After the end of the period, personal data will be destroyed or erased from computer systems or transformed into anonymous data for scientific, historical, or statistical research purposes.
Please note that we store the data for the period required by law in certain cases.
The following table explains the storage period for different categories of records.
| Personal data categories | Storage period |
|---|---|
| Account Data (name, e-mail, sign up ip & user agent, sign in ip & user agent, Google ID when using Sign In With Google, etc.) | Up to 5 years |
| Data Required for Billing (name, e-mail, country, address, payment method, last 4 digits of credit card, etc.) | 10 years according to the legislation |
| Data Used for E-mail Marketing (name, e-mail, etc.) | Until deleted by the user or a request to delete the information is received from the user. |
| Customer Support Data (name, e-mail, country, ip, social accounts, etc.) | Up to 5 years |
| HTTP Access & Error Logs (ip, user agent, referrer, etc.) | Up to 6 months |
| Third-Party Integration Data (Google Photos) (Google account email, OAuth tokens, album metadata) | Until the user disconnects the integration or deletes their account. OAuth tokens are deleted immediately upon disconnection. |
In compliance with applicable law, we may disclose your data to business partners or other third parties. We are constantly making reasonable efforts to ensure that these third parties have in place adequate protection and security measures. In addition, we have contractual terms with these third parties in order to protect your data. In these situations, we will ensure that any transfer is legitimate under the law.
For example, we could provide your data to other companies, such as IT services providers (cloud, hosting, development, tech support platforms) or scheduling, telecommunications, accounting, legal services, subscription management, billing, invoicing, analytics, tech support, marketing and other third parties with which we have a contractual relationship. These third parties are selected with particular care so that your data is processed only for the purposes we indicate and according to security standards.
We may share the data with other parties with your consent or under your instructions, such as when you exercise your right to data portability.
We may transfer your personal information to the prosecution, police, courts and other competent state bodies within the limits of legal provisions and following specific requests.
If we need to transfer your data to the above institutions or bodies, we will send you a new information note in advance regarding this transfer to the extent permitted by law.
We use the following categories of sub-processors to help us provide and improve our Services. Each sub-processor is bound by data processing agreements that ensure your data is processed in accordance with GDPR and other applicable data protection laws:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (Google LLC) | Cloud hosting, storage, and infrastructure services | EU/EEA data centers |
| Firebase (Google LLC) | Authentication, database, and analytics services | EU/EEA data centers |
| Hetzner Online GmbH | API hosting and server infrastructure | Germany (EU) |
| Scaleway (Iliad Group) | Primary object storage for photos and videos | France (EU) |
| Amazon Web Services EMEA SARL | Secondary/backup object storage | EU data centers (Frankfurt, Paris) |
| Stripe Payments Europe, Ltd. | Payment processing and billing | Ireland (EU) |
| Google Photos API (Google LLC) | Optional integration for photo/video uploads (only when user enables this feature) | User's Google account location |
| Email Service Providers | Transactional emails (account confirmations, password resets, invoices) | EU/EEA |
A complete and up-to-date list of our sub-processors is available upon request by contacting contact@joinmymoment.com. We will notify customers of any intended changes concerning the addition or replacement of sub-processors, giving customers the opportunity to object to such changes.
The transfer of personal data to a third state can only occur if the state to which the transfer is intended ensures an adequate level of protection.
The transfer of data to a state whose legislation does not provide for a level of protection at least equal to that provided by the General Data Protection Regulation is only possible if there are sufficient safeguards with regard to the protection of the fundamental rights of data subjects. We will establish these safeguards through contracts with service providers to which your personal data will be transferred.
Some of our service providers are located outside the European Economic Area (EEA), so their processing of your personal data will involve a transfer of data outside the EEA.
Every time we transfer your personal data outside the EEA, we will make sure that there is a similar level of protection through one of the following safeguard mechanisms:
We understand how important is the security of personal data, and we take the necessary measures to protect our customers and other natural persons whose data we process from unauthorized access to personal data, as well as from unauthorized modification, disclosure or destruction of the data we process in our day-to-day business.
We have implemented the following technical and organizational measures for the security of personal data:
a) Dedicated policies. We constantly adapt and review internal practices and policies for processing personal data (including physical and electronic security measures) to protect our systems from possible unauthorized access or other possible threats to their security. In addition, these policies are subject to constant checks to ensure that we comply with legal requirements and that the systems function correctly.
b) Data minimization. We ensure that your personal data we process is limited to only those necessary, appropriate and relevant for the purposes stated in this Policy.
c) Restricting access to data. We are trying to restrict as much as possible the access to the personal data we process to the minimum necessary: employees, collaborators and other individuals who need to access this data in order to process it and perform a service. Our partners and collaborators are subject to strict confidentiality obligations (either by contract or by law).
d) Specific technical measures. We use technologies that ensure the security of our customers' data, always trying to implement the best data protection solutions. We also make regular data back-ups to be able to recover them in the event of a possible incident, and we have regular audit procedures in place regarding the security of the equipment used. However, no website, application or internet connection is completely secure and untouchable.
e) Ensuring your data is accurate. Sometimes we may ask you to confirm the accuracy or timeliness of your data in order to be sure that they reflect reality.
f) Staff training. We constantly train and test our employees and collaborators regarding the legislation and best practices for protecting personal data.
g) Anonymization of data. Whenever possible, we try as far as possible to anonymize/pseudonymize the personal data we process so that we can no longer identify the persons to which they refer.
However, while we are constantly working to ensure the security of the data you entrust us with, we may also have less happy events where security incidents/breaches occur. In these cases, we will strictly follow the procedure for reporting and notifying security incidents and take all necessary steps to restore the situation to normal as soon as possible.
In the event of a personal data breach, we will comply with our obligations under GDPR Articles 33 and 34:
We may use, according to data protection laws, direct marketing technologies using the collected information about you. We are now sending business e-mail messages (e-mail marketing) to those who have given prior consent. You may object to direct marketing and/or withdraw your consent at any time by following the opt-out instructions from each e-mail ('unsubscribe' or by submitting a request to do so on contact@joinmymoment.com.
Your rights under the GDPR Regulation are as follows:
(a) The right to be informed of the processing of your data.
(b) The right of access to data. You have the right to obtain confirmation from us that personal data concerning you are being processed or not and, if so, to receive access to such data and to the information required by Article 15(1) GDPR.
(c) The right to rectify inaccurate or incomplete data. You have the right to obtain from us, without undue delay, the rectification of inaccurate personal data concerning you.
(d) The right to erasure ('right to be forgotten'). In the circumstances referred to in Article 17 GDPR, you have the right to request and obtain the deletion of personal data. The data subject can also delete his or her data directly from the JoinMyMoment services interface.
e) The right to restriction of processing. In the cases referred to in Article 18 GDPR, you have the right to obtain from us a restriction of processing.
f) The right to transfer the data to another controller ('right to data portability') in the cases referred to in Article 20 GDPR.
g) The right to object to the processing of data. In the cases referred to in Article 21 GDPR, you have the right to object to the processing of data.
h) In cases referred to in Article 22 GDPR, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
i) The right to go to court for the defense of your rights and interests.
j) The right to lodge a complaint with a Supervisory Authority;
| Name | National Authority for the Supervision of the Processing of Personal Data |
| Address | B-dul G-ral. Gheorghe Magheru nr. 28-30, Sector 1, postal code 010336, Bucharest, Romania |
| Telephone | +40.318.059.211 or +40.318.059.212 |
| anspdcp@dataprotection.ro |
Please note that:
(1) You may withdraw your consent for direct marketing at any time by following the unsubscribe instructions in each e-mail.
(2) If you wish to exercise your rights, you may do so by sending a written request at contact@joinmymoment.com.
(3) The rights listed above are not absolute. There are exceptions, which is why each request received will be examined in order to determine if your request is justified or not. In so far as the request is justified, we will facilitate the exercise of your rights. If the request is not justified, we will reject it. If we deny your request, we will inform you of the reasons for the denial, the right to lodge a complaint with the Supervisory Authority, and the right to go to a court to defend your rights.
(4) We will try to answer the request within one month. However, the time limit may be extended in the light of different aspects, such as the complexity of the request, the large number of applications received or the impossibility to identify you within a reasonable time.
(5) If we do our best, but we cannot identify you, and you do not provide us with any additional information to help us identify you, we are not obliged to answer the request.
You can also find detailed explanations of your rights below.
| Rights | Additional information |
|---|---|
| Access to data | You can ask us to:
|
| Rectification | You may ask us to fill in/modify your personal data to be consistent with reality. |
| Right to erasure ('right to be forgotten') | You may request us to delete your personal data, but only if:
|
| Restriction of data processing | You may ask us to restrict the processing of your personal data in the following cases:
|
| Data portability | You may request us to send you the personal data related to you which you have provided to us in a structured, commonly used and machine-readable format, and you have the right to transmit this data to another controller in the following cases:
|
| The objection | You have the right to object to processing where: (a) processing is necessary for the performance of a task carried out in the public interest, (b) processing is necessary for the purposes of the legitimate interests pursued by us or a third party, including profiling based on those provisions. In such a case, we shall no longer process your personal data unless we demonstrate that we have legitimate and compelling reasons justifying the processing and which override the interests, rights and freedoms of the data subject or that the purpose is the establishment, exercise or defense of legal claims. |
| Automated decision-making and Profiling | You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This right has certain limitations, namely:
|
If you have any questions or concerns about the processing of your information or want to exercise your legal rights, or have any other privacy concerns, you can contact us at contact@joinmymoment.com.
Last update: 20th January 2026