Policies

Privacy & Data Protection Policy

Compliant with Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the General Data Protection Regulation.

01Data controller

The data controller is Hrvatska Udruga Umirovljenika Europskih Integracija, OIB 33098033965, Svilno 25, Most Svilno, 51000 Rijeka, Croatia. Questions about this policy should be addressed to the Secretary General at dickerson-theodoreg@gmx.com.

02What we collect

Membership and volunteer records: name, age group, postal address, telephone number and email address. Programme records: courses attended and consent status for photography. Correspondence: the content of messages you send us. We do not collect health data except where a member voluntarily discloses a condition relevant to safe participation in an exercise session, which is recorded only with written consent.

03Legal basis

We process membership data on the basis of the contractual relationship of membership (Art. 6(1)(b) GDPR), legal obligations relating to association records and accounting (Art. 6(1)(c)), and consent for photography, newsletters and any voluntarily disclosed health information (Art. 6(1)(a)).

04Retention

Membership records are retained for the duration of membership and for five years thereafter, in line with accounting and grant-audit obligations. Correspondence is retained for two years. Photographs are retained until consent is withdrawn.

05Sharing

We do not sell or rent personal data. Data is shared only with municipal or county partners where necessary to deliver a specific programme, with grant funders in anonymised aggregate form, and with public authorities where legally required. No data is transferred outside the European Economic Area.

06Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting prior lawful processing. Requests are answered within thirty days at no cost. You may lodge a complaint with the Croatian Personal Data Protection Agency (AZOP).

07Security

Membership records are held in access-controlled files; digital records are password protected and accessible only to the Secretary General, Treasurer and President. Volunteers receive written data-handling instructions and sign a confidentiality undertaking.

08Website and cookies

This website uses only technically necessary storage required to remember your language preference. We do not use advertising cookies or third-party behavioural tracking.