Last updated: August 23, 2026
Controller: HOLA25 SRL
Registered office: Str. Dealului nr. 8, Fărcășești, Gorj County, 217235, Romania
Tax ID (CIF): 54114659
Trade Registry No.: J2026013417000
Contact email: contact@hola25.com
Website: https://hola25.com
This Privacy Policy explains how HOLA25 SRL ("Controller", "we") collects, uses, and protects personal data of Hola25 users, in accordance with EU General Data Protection Regulation (GDPR) and Romanian Law No. 190/2018.
The data controller is HOLA25 SRL, registered office: Str. Dealului nr. 8, Fărcășești, Gorj County, 217235, Romania. Contact: contact@hola25.com
For all data-protection inquiries, the contact point is: contact@hola25.com
Account data: email, authentication identifiers (e.g., Google), account settings.
Restricted deleted-account ledger: normalised email, original account identifier, display name, deletion date and count, and block status, used for deletion history and moderation controls.
Email-marketing preference: the current account setting and communication language. An unticked or omitted choice is not treated as consent.
Profile data: display name, username, bio, nationality, sex, profile image, languages/skills and self-assessed levels, date of birth (public/private), phone number (private).
Usage data: call minutes (host/guest), minutes per skill (where applicable), interactions (requests, private message requests, reports).
Payment data: product, teacher or creator and the applicable schedule or access, price, currency, discounts, authorization/capture/refund/dispute status, and applicable Stripe identifiers.
Tax and billing data: legal name, address and country where needed for a fiscal document.
Contract evidence: product-agreement confirmation, confirmations made separately at payment, selected declarations, language, channel, early-performance requests, withdrawals, cancellations, refunds and confirmations sent.
Online withdrawal-function data: name, contract identifier, the email address selected for the acknowledgment, exact statement, receipt number, date and time, acknowledgment status and, where available, scope-separated HMAC pseudonyms for the IP, Firebase app ID and account. For abuse control, we temporarily retain separate HMAC pseudonyms of the acknowledgment address and contract identifier. These values are pseudonymised, not anonymous, data.
Live-lesson recording data: audio, video, content shared in the room, participant identities, technical meeting/recording identifiers, proof of separate acceptance, the playback entitlement's link to the participants authorised for the segment, access events, provider-reported actual state, start/processing incidents, and deletion state. Only audio, video, and screen streams enabled by the participant are captured; the camera may remain off where the room permits. Segment creation, synchronisation, and processing may be delayed, contain gaps, or fail, and timestamps in the file do not necessarily match attendance evidence to the second. We do not guarantee a recording's availability, continuity, or completeness. A technical failure may mean that no usable file is produced even though provider state and separate attendance and incident evidence are retained. Report any issue to contact@hola25.com as soon as possible after the lesson. We do not currently intentionally extend retention of the video file beyond the 90-day maximum and do not apply a legal-hold mechanism to it. If technical deletion is not confirmed, the file remains blocked and inaccessible while deletion is retried and escalated. Hola25 may later introduce a separate restricted hold for litigation, an investigation, a legal duty, or the defence of rights, only after technical activation and an update to the applicable notice and terms and, where legally required, acceptance. Such a hold would not extend ordinary teacher or participant access; access would be limited on a need-to-know basis to authorised staff, advisers, involved providers, or competent authorities.
Optional external-promotion data: selected public profile or listing content, creative image, Hola25 link, campaign identifiers and status, plus general audience criteria and budget. Those criteria are not an exact list or segment and may be adjusted by the external platform. Publishing the profile does not by itself authorise this use; the teacher must make a separate affirmative choice.
Insula Iubirii and Living data: eligibility and date of birth, enrolment, predictions and choices, points, rank, accuracy, and results; email address, phone number, and technical identifiers used for abuse prevention; identifiers and content of the diploma or sharing image; and, in Living, display name, photo, messages, images, technical presence, limits, restrictions, reports, and the preference to receive notifications.
Private messaging data: text messages, files uploaded directly to the lesson conversation, message request status, thread metadata, and block/unblock records needed to prevent unwanted contact.
Technical data: IP (where applicable), device/browser info, security logs, error logs.
Webinar data: webinar registrations, live presence, webinar chat messages, replay recordings, and playback/security metadata.
Moderation data: reports, reasons, outcomes of enforcement actions.
| Purpose | Data Processed | Legal Basis (GDPR) |
|---|---|---|
| Account creation and management | Email, name, authentication identifiers, and account settings | Art. 6(1)(b) - Contract performance |
| Account-deletion history and abusive re-registration control | Normalised email, original identifier, display name, deletion date/count, and block status | Art. 6(1)(f) - legitimate interests in safety, moderation, and abuse prevention; establishment, exercise, or defence of claims where necessary |
| Public profile | Name, username, bio, photo, languages, skills | Art. 6(1)(b) - Contract performance |
| Waitlist and video calls | User preferences, minutes used | Art. 6(1)(b) - Contract performance |
| Private messaging | Text messages, files uploaded directly to the lesson conversation, message request status, temporary thread metadata | Art. 6(1)(b) - Contract performance |
| Teacher announcements | Profile data, optional contact, service description | Art. 6(1)(b) - Contract performance |
| Optional external promotion of a profile or listing | Selected public content, creative image, link, campaign identifiers, status, and parameters | Art. 6(1)(a) - consent through a separate affirmative choice; absence or withdrawal blocks local creation and resumption |
| Participation in Insula Iubirii and use of Living | Eligibility and date of birth, enrolment, predictions, points, rank and results, diploma or sharing data, anti-abuse identifiers, Living content, technical presence, restrictions, reports, and notification preference | Art. 6(1)(b) - contract performance for participation and requested functions; Art. 6(1)(f) - contest integrity, security, abuse prevention, and moderation; Art. 6(1)(a) where a choice is required for notifications |
| Bookings, digital access, payments and refunds | Product, email, price, currency, status, and Stripe identifiers, schedule | Art. 6(1)(b) - Contract performance |
| Contract proof, withdrawals, complaints and disputes | Product-agreement confirmation, payment confirmations, declarations, communications, and request outcomes | Art. 6(1)(b) - Contract performance; Art. 6(1)(c) - Legal obligation; Art. 6(1)(f) - legal claims |
| Online withdrawal intake and acknowledgment | Name, contract identifier, acknowledgment address, statement, temporal evidence and operational state | Art. 6(1)(b) - pre-contractual steps and contract duties; Art. 6(1)(c) - legal duty concerning the withdrawal function and acknowledgment; Art. 6(1)(f) - security and legal claims |
| Live-lesson recording and playback | Audio-video, shared content, participants, Live Lesson Service identifiers, separate-acceptance evidence, and access events | Art. 6(1)(b) – contract performance for the live product whose mandatory characteristic is recording and access by recipients authorised for the applicable segment; Art. 6(1)(f) – safety and defence of rights in refunds or disputes. Separate acceptance proves notice of the characteristic and is not the processing ground by itself and does not authorise advertising, public use, or model-training use. Any public or advertising use of image, voice, or contributions requires separate, purpose-specific express permission from every identifiable person and, where needed, the authorised adult for a child. |
| Analytics and service improvement | Pseudonymous identifiers, technical metadata, and usage data | Art. 6(1)(a) - Consent |
| Email marketing | Email address, language, and marketing preference | Art. 6(1)(a) - Consent |
| Security and fraud prevention | IP, device info, access logs | Art. 6(1)(f) - Legitimate interests |
| Moderation and reports | Reported content, decisions, block/unblock records | Art. 6(1)(f) - Legitimate interests |
| Live webinars and replays | Live participation data, webinar chat, webinar recordings, and playback technical metadata | Art. 6(1)(b) - Contract performance; Art. 6(1)(f) - Legitimate interests (security and abuse prevention) |
| Legal compliance | Data requested by authorities | Art. 6(1)(c) - Legal obligation |
| Public date of birth | Date of birth | Art. 6(1)(a) - Explicit consent |
A public profile has a display name and username; if you do not provide them, the platform may create neutral values. The public profile record is accessible without authentication; a field written to that record may be read even when the main page does not display it. Bio, image, nationality, gender, date of birth, languages, and skills may form part of the public profile. Do not add those data to the public profile if you want them to remain private; the phone number remains in the private profile.
A public teacher profile may include the occupation title, bio, county and locations, work and education, selected languages and skills, ratings, statistics, published articles, and active listing details including description, price, duration, location, and demonstration-lesson availability. Name, image, title, bio, county, and languages may also appear in structured search-engine data; a noindex marker does not make the page private. Demonstration videos and thumbnails are processed through the video provider identified in the recipient register.
During video calls, the platform can capture a single photo at the 25th second as a memory of your connection. You have full control over this feature through the following preferences:
Enable call photos: Controls whether photos are captured during your calls. Enabled by default.
Allow others to have my photo: Controls whether other users can save combined photos that include you. Disabled by default to protect your privacy.
Prefer self-only in call history: Controls whether to display only your own photo (instead of combined photos with others) in your call history. Enabled by default.
These preferences are stored in your private profile data and can be changed at any time in your profile settings. Call photos are stored securely. An account-deletion request includes a request to remove them from storage, but account completion does not confirm deletion of every object; if a photo remains available, email contact@hola25.com.
External promotion is an optional feature separate from ordinary profile or listing publication. The teacher does not buy or pay for this service. Hola25 may decide whether and when to create a campaign, select its content, general audience criteria, channel, and budget, and finance the promotion directly or through partners. A teacher's affirmative choice permits only evaluation and use for this purpose; it does not start a campaign by itself, guarantee promotion or results, or authorise other marketing purposes.
The current implementation covers teacher listings only. A future extension to Trial Lessons or Paid Lessons will not automatically rely on the existing choice: before that processing, we will provide the applicable notice and request distinct affirmative choices scoped by product and, where relevant, by offer and subject. The absence of such a choice does not affect ordinary publication or delivery of the product outside the external promotion feature.
Withdrawing the choice, disabling the teacher profile, or deleting the account locally blocks creation and resumption and creates a stop request for affected campaigns. Confirmation by the external platform may be asynchronous; until it is received, local state is not proof that the provider has stopped the campaign. Contact contact@hola25.com to ask for the current recorded status of a specific stop; that status does not replace confirmation from the external platform.
The current provider, applicable role, and transfer limits are identified in the recipient register below. We do not treat public profile visibility as authority for external promotion. Audience criteria are general campaign directions, do not describe an exact list or segment of people, and may be adjusted by the external provider.
For participation in Insula Iubirii, we may verify eligibility and age using the date of birth, record enrolment, predictions, and choices, and calculate points, rank, accuracy, and results. Email address, phone number, and technical identifiers may be used for security, participation limits, and abuse prevention.
A diploma or sharing image may be public and accessible through a URL containing the user's technical identifier (UID). It may display the public name, couple predictions, total and activity points, rank, accuracy, the early-choice result, and other game results, and may be temporarily cached by browsers, delivery networks, or services through which it is shared. Later withdrawal or changes in Hola25 do not guarantee immediate removal of copies already saved or redistributed by third parties.
Living is a space for authenticated users. Display name and photo may be visible to other participants together with posted messages and images. We also process technical presence data, usage limits, restrictions or bans, reports, and notification interest or choice for operation, safety, and moderation. Do not post sensitive data or information about another person without an appropriate basis.
These categories do not all have the same retention period. We retain them as needed for the requested function, contest results, security, abuse prevention, moderation, defence of rights, and applicable legal duties. Retention necessity is assessed by category; depending on purpose, law, and technical feasibility, the outcome may be erasure, restriction, anonymisation, or continued retention of a record. Account deletion does not necessarily mean immediate removal of every record, a final result, or a public copy already shared. You may exercise the rights described in Section 10 by contacting contact@hola25.com; the request is assessed for each category and applicable legal exceptions.
We share data with the following providers only as necessary. Their GDPR role may be processor, independent controller, or recipient depending on the service and data involved:
| Provider | Purpose | Location | Role and transfers |
|---|---|---|---|
| Google/Firebase (Google entity applicable to the service) | Authentication; Firestore and Realtime Database; Firebase Storage; hosting and cloud functions; Cloud Messaging for notification tokens and delivery; App Check and, where applicable, reCAPTCHA for integrity signals and abuse prevention. This may involve account data and content, uploaded files, real-time presence state, notification tokens, and technical app, device, or browser metadata. For the lesson conversation, messages and file metadata are kept in Firestore, while files uploaded directly are kept in Firebase Storage (Google Cloud Storage); this history is not deleted automatically based on age, and access to a file is granted only to an authorised lesson participant through a signed URL valid for 60 seconds. | Under the applicable configuration and contract | The role and mechanism are determined for the applicable service, configuration, and destination; retention follows the data category, technical settings, and applicable contract |
| Google Workspace / Gmail (Google LLC) | Transactional email and withdrawal acknowledgment delivery, including the name, contract identifier, destination address and statement included in the message | USA / EU | The role and mechanism are determined for the applicable service and destination |
| Twilio Verify (Twilio entity applicable to the service) | Sending and verifying SMS codes for the phone number, including the number, verification status, and delivery, security, and fraud-prevention metadata required by the service | Under the applicable configuration and contract | The entity, role, retention, subprocessors, and transfer mechanism are those established by the applicable contract and configuration |
| Stripe (entity applicable to the transaction) | Web payment processing, Stripe Connect, fraud prevention, refunds and payment evidence | USA | The applicable entity, role, and mechanism are those identified for the transaction |
| Meta Platforms Ireland Limited / applicable Meta entity | External Advertising Platform used for optional delivery of selected content on Facebook and Instagram | EEA / global infrastructure | The entity, role, and transfer mechanism are determined for the applicable campaign, configuration, and destination |
| Oblio Software S.R.L. | Fiscal-document issue/correction and RO e-Factura transmission when the fiscal document is issued through this service | Romania / EU | The role and terms applicable to the fiscal service used |
| Google Analytics | Traffic analysis (with consent) | USA | The role and mechanism are determined for the applicable configuration and destination |
| Cloudflare, Inc. — Stream | Live webinar ingest and streaming, recording processing, replay delivery, access control, and associated technical or security metadata | Under the applicable configuration and contract | The role, retention, and transfer mechanism are determined for the applicable service, configuration, and destination |
| Cloudflare, Inc. — RealtimeKit (the "Live Lesson Service") and R2 (the "Private Recording Storage") | The Live Lesson Service, including technical and attendance metadata; files and images sent in the Live Lesson Service chat within the video room are stored in the provider's private storage and are reachable by participants through temporary addresses valid for at most 7 days; for lessons where the recording policy is active, recording of enabled audio/video/screen streams, storage and delivery to recipients authorised for the applicable segment | USA / Global | The role and mechanism are determined for the applicable service, configuration, and destination |
| Agora Interactive Whiteboard / Netless Fastboard (Agora Lab, Inc. and/or the applicable contracting entity) | The collaborative lesson whiteboard: room and user identifiers, IP address and device/browser metadata, whiteboard operations and drawings, and files uploaded for conversion or display. Pages produced by document conversion are stored by Hola25 in Google Cloud Storage (EU region), are reachable via unpublished web addresses, and are deleted automatically after 90 days | Under the applicable region, configuration, and contract | The contracting entity, role, subprocessors, retention, and transfer mechanism are those established by the order, contract, and DPA applicable to the service used by Hola25 |
| BunnyWay d.o.o. (Bunny Stream) | Demonstration lesson video upload, encoding, thumbnail generation, and playback delivery | EU / Global CDN | The role and mechanism are determined for the applicable service and destination |
| YouTube/Google: the player API from youtube.com and playback through youtube-nocookie.com where embedded video content is displayed | Embedded-video delivery; when loaded or played, the provider may receive the IP address, device and browser data, referring page, and player interaction, while local storage or cookies depend on configuration and user choices | Under the applicable service and contract | The role, retention, and transfer mechanism are determined for the applicable configuration and destination |
| jsDelivr CDN | Script delivery (image compression) | Global | If the browser contacts the CDN, it may receive request metadata including the IP address; the role and mechanism depend on the actual delivery path |
We may disclose strictly necessary data to ANAF/SPV, ANSPDCP, ANPC, courts, law-enforcement bodies or other authorities where a legal obligation or valid request applies. Teachers and creators receive only what is needed to perform the product and never the buyer's full card details.
Some recipients may process data outside the EEA or allow access from a third country. Before an applicable transfer, we assess the recipient, destination, role, and legal instrument. Depending on the case, this may be an adequacy decision, Standard Contractual Clauses with the appropriate module and supplementary measures, or another mechanism permitted by GDPR Articles 44-49. You may request information about the mechanism applicable to your data using the contact address.
Mobile advertising is disabled in the current release. The iPhone app does not include the Google Mobile Ads or UMP SDKs, does not include the ATT permission, and does not request the advertising identifier and therefore makes no ad request through those components.
| Data Category | Retention Period | Justification |
|---|---|---|
| Account and profile data | For the account lifetime; after an erasure request, according to the category and applicable legal limitations | Contract performance and handling the erasure request |
| Restricted deleted-account ledger | The current implementation has no automatic expiry; every field and its continued retention are subject to periodic necessity review, data-subject requests, and any applicable duty or claim | Deletion history, safety, moderation, and prevention of abusive re-registration |
| External-promotion choice, campaigns, and stop requests | The current choice is kept until it changes or the account is deleted. Campaign and stop-request data are kept until external confirmation and then only as needed to evidence the choice, withdrawal, and the establishment, exercise, or defence of claims. | Applying the choice, ending the use, and demonstrating compliance with withdrawal |
| Insula Iubirii and Living data | No single period applies to every category. Data is retained for the time needed for the function or season and afterwards as needed for contest results, security, abuse prevention, moderation, defence of rights, and applicable legal duties. Erasure or restriction requests are assessed by category. | Function delivery, integrity of results, safety, moderation, and compliance with applicable duties |
| In-call messages | Deleted automatically at call end | Data minimization |
| Lesson-conversation history: text messages and files uploaded directly | Remains available to authorized lesson participants; it is not deleted automatically based on age. Erasure or anonymisation in connection with account deletion follows the separate Account Deletion Policy. | Conversation continuity and participant access to lesson history |
| Message request and block metadata | Duration of account or until unblock/deletion | Safety, abuse prevention, user control |
| Call photos | Duration of account | User preference; account deletion requests removal from storage, with object confirmation separate from the final account state |
| Usage minutes (statistics) | Duration of account | Platform functionality |
| Security logs | 90 days | Security and incident investigation |
| Pseudonymised withdrawal-function counters | 48 hours for HMAC counters; 31 days for evidence of a rate-limit breach | Availability, abuse prevention and incident investigation; deleted through the Firestore TTL policy |
| Reports and moderation | 1 year from resolution | Recidivism prevention, evidence |
| Webinar chat messages | 180 days | Content moderation, report investigation, and operational safety |
| Webinar recordings (replay) | 90 days from webinar end | Published replay delivery + storage limitation (GDPR Art. 5(1)(e)) |
| Recordings of lessons where the recording policy is active | Access for up to 90 days after the lesson ends; then removal of access | Temporary access for the teacher and participants authorised for the applicable segment; authorised Hola25 personnel have restricted access only for safety, refunds, or disputes. Segmentation and timestamps may be delayed, contain gaps, or fail and do not certify a person's attendance interval to the second. At expiry the file becomes unavailable to participants and personnel, and the technical process attempts deletion. If deletion is not confirmed, the file remains blocked and inaccessible while the operation is retried and escalated. In the current configuration, a dispute or legal duty does not extend retention of the file and no legal-hold mechanism exists for it. Separate acceptance, attendance, and dispute-resolution evidence may be retained longer under the rows applicable to those records, without the audio-video file. Availability, continuity, and completeness of the file are not guaranteed; issues must be reported to contact@hola25.com as soon as possible after the lesson. |
| Trial lesson reviews | For the lifetime of the teacher's account or until deletion/moderation | Teacher's public reputation and informing other students |
| Accounting supporting documents and transaction data | 5 years calculated from 1 July of the year following the financial year, unless a specific rule requires longer | Accounting and tax duties; extended where an audit, dispute or another applicable duty requires it |
| Financial statements and mandatory ledgers | 10 years | Legal obligation (Romanian Accounting Law 82/1991) |
| Contract evidence, withdrawals, refunds and disputes | For the contract or resolution and afterwards only as needed for an applicable legal duty, limitation period, audit, or dispute | Evidence of contract information/performance, consumer rights compliance and legal claims |
| Online-withdrawal case and durable acknowledgment | Until resolution and afterwards only as needed for an applicable legal duty, limitation period, audit, or dispute | Evidence of receipt, acknowledgment and resolution; administrative logs are retained only under the configuration actually applied to their category |
| Current email-marketing preference | For the account lifetime or until the setting changes or the account is erased, subject to a legal duty | Applying the current choice and honouring withdrawal |
| Data after account deletion | Erased, anonymised, or retained under restriction according to the category and applicable ground; there is no single period for every category | Minimisation, legal duties, security, and legal claims |
Under GDPR, you have the following rights:
Access (Art. 15): Obtain a copy of your personal data being processed;
Rectification (Art. 16): Correct inaccurate or incomplete data;
Erasure (Art. 17): Request deletion of your data ("right to be forgotten");
Restriction (Art. 18): Limit processing in certain conditions;
Portability (Art. 20): Receive your data in structured format (JSON);
Objection (Art. 21): Object to processing based on legitimate interests;
Automated decisions (Art. 22): Not be subject to decisions based solely on automated processing.
To exercise your rights, email contact@hola25.com. We respond without undue delay and no later than one month. For a complex or numerous request, the period may be extended by up to two further months; we explain the extension and its reasons within the first month. If we do not act, we communicate the reasons, complaint right, and available judicial remedy within one month. We may request only additional information necessary and proportionate to verify identity.
Eligibility rules, security or fraud signals, moderation tools, search, ordering, and recommendations may involve automated processing and, where applicable, profiling. The waitlist displays available users, while the choice of whom to contact remains manual. We do not use an automated result as a final decision with legal or similarly significant effects without the applicable safeguards and rights; you may request an explanation and human intervention for a decision controlled by Hola25.
We implement technical and organisational measures appropriate to the assessed risk, including:
Encryption in transit (HTTPS/TLS);
authentication and role-based access controls;
access rules for databases and storage;
restricted access to payment services and transaction data;
logging, monitoring, and, where applicable, continuity and recovery measures.
No transmission or storage method is 100% secure. Users should protect their credentials and immediately report any suspicious activity.
In case of a data breach posing risk to the rights and freedoms of data subjects, we will notify ANSPDCP within 72 hours (Art. 33 GDPR) and, if necessary, inform affected users without undue delay (Art. 34 GDPR).
You may lodge a complaint with ANSPDCP or the supervisory authority in the Member State of your habitual residence, place of work, or the alleged infringement, without losing your right to a judicial remedy:
National Supervisory Authority for Personal Data Processing (ANSPDCP)
B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania
Website: www.dataprotection.ro
Email: anspdcp@dataprotection.ro
Phone: +40 318 059 211
This policy may be updated periodically. Material changes are communicated through an appropriate channel before they take effect where required by law or contract. The last update date is displayed at the top of this page.
For any questions about data protection:
HOLA25 SRL
Str. Dealului nr. 8, Fărcășești, Gorj County, 217235, Romania
Email: contact@hola25.com
Initial response period: no later than one month; an extension of up to two further months is available only under the conditions in section 9
We use cookies to improve your experience on Hola25. Essential cookies are necessary for the platform to work. You can customize settings for analytics and marketing cookies.
Cookie Policy | Privacy Policy