Privacy Policy
Introduction
This Privacy Policy provides you (also referred to as the data subject), as a participant in our events and other activities, with an overview of how Eesti Ühinenud Rahvaste Organisatsiooni Ühing (Eesti ÜRO Ühing) (also referred to as “Eesti ÜRO Ühing”, the “Association”, “we” or “us”) processes your personal data.
We consider your right to privacy important and therefore comply in all personal data processing activities with the requirements established by Regulation (EU) 2016/679, the General Data Protection Regulation (the “GDPR”), and other applicable legislation.
We continually strive to ensure that both our data processing and the related documentation are clear. We therefore regularly update, clarify and improve this Privacy Policy. The current version is always available on our website.
Controller
The controller of your personal data is Eesti Ühinenud Rahvaste Organisatsiooni Ühing (Eesti ÜRO Ühing).
Registry code: 80583553
Address: Tähe tn 85, Tartu 50107, Republic of Estonia
Email: unaeesti@unaeesti.ee
Categories of Personal Data, Purposes of Processing, Legal Bases and Retention Periods
We process only the minimum personal data necessary for the relevant purpose.
Event Registration Data
Data processed: first and last name, date of birth and country of residence
Purpose: registering participants for events
Legal basis: consent
Retention period: 3 years after consent is given
Newsletter Communication Data
Data processed: email address
Purpose: contacting participants in connection with an event and sending related newsletters
Legal basis: consent
Retention period: deleted 2 years after the event
Future Event Notification Data
Data processed: first and last name and email address
Purpose: providing useful information
Legal basis: consent
Retention period: deleted when consent is withdrawn
Accounting Data
Data processed: first and last name and bank account number
Purpose: reimbursing participants’ travel expenses
Legal basis: legal obligation
Retention period: 7 years after the transaction
Location Data
Data processed: name of the county, city, town or settlement
Purpose: compiling event statistics; the individual provides the data voluntarily
Legal basis: consent
Retention period: deleted one week after the event
Social Media Content Data
Data processed: photographs or short videos
Purpose: promoting and covering events, including sharing participant-created content on social media to raise awareness
Legal basis: consent
Retention period: retained for as long as necessary to achieve the Association’s objectives and published on the Association’s social media channels
Payment Data
Data processed: first and last name, email address, payment amount, payment method, transaction reference and other data required to make the payment
Purpose: receiving and processing participation fees, donations or other payments
Legal basis: entering into or performing a contract and complying with a legal obligation
Retention period: payment and accounting data are retained for seven years after the transaction unless a different period is required by law
Other Personal Data Related to Events
Other personal data obtained during event registration and the event may occasionally be processed.
Security Screening Data
Data processed: personal identification code
Purpose: arranging entry to an event held at a public authority
Legal basis: consent
Retention period: deleted one week after the event
Contact Details of the Legal Representative of a Minor Participant
Data processed: first name and telephone number
Purpose: ensuring a means of contacting the minor’s representative
Legal basis: legitimate interest
Retention period: deleted one week after the event
Eesti ÜRO Ühing does not process special categories of personal data (e.g. health data, biometric data, political opinions, racial or ethnic origin). If a data subject provides such data, they do so voluntarily and the Association will delete it once the relevant purpose has been fulfilled, unless the data are necessary for the establishment, exercise or defence of legal claims. Eesti ÜRO Ühing does not require any participant to provide special categories of personal data.
Sources of Personal Data and Access Rights
We obtain personal data about you primarily directly from you as the data subject, for example when you attend or register for our events, apply to join an organising team, make a payment on our website or contact us by email.
Within the Association, access to the personal data described in this Privacy Policy is limited to persons authorised by the Management Board of Eesti ÜRO Ühing. Access is granted only to the extent necessary for the person to perform their duties.
The Association may use processors that process personal data on the Association’s instructions and only to the extent necessary to provide their services.
Payment Processing
Eesti ÜRO Ühing is the controller of personal data. To process payments, Eesti ÜRO Ühing transfers the personal data necessary for payment processing to its processor, Maksekeskus AS, registry code 12268475.
Maksekeskus AS processes personal data to provide payment services and fulfil payment-related obligations. In processing a payment, Maksekeskus AS may process, among other data, the payer’s name, contact details, bank account details, payment card details and other information required to complete the payment.
Rights of the Data Subject
In connection with the processing of your personal data by Eesti ÜRO Ühing, you have the following data protection rights under the GDPR:
- Right of access. You have the right to obtain information about whether and which personal data we process about you and the legal basis and manner of processing. You also have the right to request a copy of your personal data. The Association may refuse to provide copies of documents if doing so would adversely affect the rights and freedoms of others.
- Right to rectification and restriction of processing. You have the right to request that we correct your personal data or restrict its processing. Where processing is restricted, we may process the data only to a limited extent, for example for the establishment of legal claims or compliance with legal obligations.
- Right to withdraw consent. Where processing is based on consent, you may withdraw it at any time by contacting us at the email address above. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right to object. Where processing is based on the Association’s legitimate interests, you have the right to object to such processing.
Security Measures
We have implemented extensive technical, organisational (including staff training) and physical security measures to protect personal data. Access to personal data is strictly limited to those who need it.
Questions and Complaints
To exercise the rights described above, please contact us at the email address stated above. Please note that data protection rights are not absolute, and for each request we must assess whether and to what extent applicable data protection law permits us to grant it. We generally respond within 28 days of receiving a request.
If it is not possible to respond within one month, we may extend the response period by two months, informing you of the extension and the reasons for it within one month of receiving the request.
If you disagree with our response, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon): Tatari 39, Tallinn 10134; email info@aki.ee; telephone +372 627 4135.
