Privacy Policy
Your privacy is important to us.
Introduction
M & M, ASBL/VZW ("we," "our," or "us") is committed to protecting the privacy and personal data of our members, donors, volunteers, website visitors, and all individuals who interact with our organisation. This Privacy Policy explains how we collect, use, store, share, and protect your personal data in full compliance with the European Union General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, and the Belgian Data Protection Act of 30 July 2018.
We believe that transparency is fundamental to building trust. This policy is designed to inform you about your rights and our practices regarding the processing of personal data. By visiting our website, contacting us, becoming a member, or making a donation, you acknowledge that you have read and understood this Privacy Policy.
We reserve the right to update this policy at any time. Material changes will be communicated through our website and, where appropriate, by direct notification to affected individuals. We encourage you to review this page periodically to stay informed about how we safeguard your data.
Data Controller
The data controller responsible for the processing of personal data under this Privacy Policy is:
M & M, ASBL/VZW
Herentalsesteenweg 66 B
2220 Heist-op-den-Berg, Belgium
Enterprise number: BE0843318493
Email: organibe@gmail.com
If you have any questions about this Privacy Policy or our data processing practices, please contact us using the details provided above. Our data protection contact point will respond to your enquiry within a reasonable timeframe, and in any case within one month of receipt as required by the GDPR.
Personal Data We Collect
We collect personal data only when it is necessary and for specified, explicit, and legitimate purposes. The categories of personal data we may collect include:
- Contact form data: When you reach out to us through our website contact form, we collect your name, email address, phone number (optional), and the content of your message. This information is necessary for us to respond to your inquiry.
- Membership data: When you register as a member of M & M, we collect your full name, date of birth, address, contact details (phone number and email), emergency contact information, medical or health information relevant to participation in our activities (with explicit consent), bank account details for membership fee processing, and a photograph for membership identification purposes.
- Donation records: When you make a donation, we collect your name, contact information, donation amount, date of the transaction, payment method details (processed securely through our payment processor), and whether you wish to receive a tax certificate. We do not store full credit or debit card numbers on our systems.
- Website analytics: Our website may collect certain technical data automatically when you visit, including your IP address (anonymised where possible), browser type and version, operating system, referring URL, pages visited, time and date of your visit, and time spent on pages. This data is collected through cookies and similar technologies. For full details, please refer to our Cookie Policy.
- Communication records: If you correspond with us by email, phone, or through other channels, we may retain records of those communications to ensure continuity of service and to document our interactions.
Legal Basis for Processing
Under the GDPR, we must have a lawful basis for processing your personal data. We rely on the following legal bases:
- Consent (Article 6(1)(a) GDPR): Where you have given us clear, affirmative consent to process your personal data for a specific purpose. For example, when you subscribe to our newsletter, consent to receive marketing communications, or agree to the processing of health-related information for participation in activities. You may withdraw your consent at any time without affecting the lawfulness of processing carried out before withdrawal.
- Contractual necessity (Article 6(1)(b) GDPR): Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request prior to entering into a contract. For example, processing your membership application and managing your membership, or processing a donation you have chosen to make.
- Legitimate interest (Article 6(1)(f) GDPR): Where processing is necessary for the purposes of the legitimate interests pursued by our organisation or by a third party, except where such interests are overridden by your fundamental rights and freedoms. Examples include improving our website and services, ensuring network and information security, and preventing fraud.
- Legal obligation (Article 6(1)(c) GDPR): Where processing is necessary for compliance with a legal obligation to which we are subject. For example, maintaining financial records required under Belgian tax and accounting legislation, or responding to lawful requests from public authorities.
How We Use Your Data
We use the personal data we collect for the following purposes:
- To respond to your inquiries, requests, and communications in a timely and accurate manner.
- To administer and manage your membership, including processing membership fees, maintaining membership registers, and communicating important organisational updates.
- To process and acknowledge donations, issue tax certificates where applicable under Belgian law, and maintain accurate financial records.
- To send newsletters, event invitations, and organisational updates by email or post, but only where you have given your explicit consent to receive such communications. You may unsubscribe at any time by contacting us or using the unsubscribe link provided in our communications.
- To organise, deliver, and improve our sports programs, events, and community activities.
- To ensure the safety and well-being of our members and participants during activities.
- To improve our website, services, and overall member experience through analysis of anonymised usage data.
- To comply with our legal and regulatory obligations, including financial reporting and tax compliance.
- To protect the rights, property, and safety of M & M, our members, and the public.
We will not use your personal data for purposes that are incompatible with the purposes for which it was collected, unless we have a lawful basis to do so and have informed you accordingly.
Data Sharing
We value your trust and want to be clear about how your data is shared:
- We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes.
- Payment processors: When you make a donation or pay membership fees, we share necessary transaction details with our trusted, PCI-DSS-compliant payment processing provider solely for the purpose of completing the transaction. These processors are bound by data processing agreements and are required to protect your information.
- Hosting and IT providers: Our website and data systems are hosted by reputable service providers who process data on our behalf under strict data processing agreements. These providers implement robust security measures and are located within the European Economic Area (EEA) or in countries that provide adequate data protection as determined by the European Commission.
- Legal authorities: We may disclose personal data if required by law, regulation, court order, or governmental request, or when we believe disclosure is necessary to protect our rights, the safety of our members, or the public.
- Professional advisors: We may share data with our accountants, legal advisors, or auditors where necessary for compliance, financial reporting, or legal purposes. These parties are bound by professional confidentiality obligations.
Any third-party service providers we engage are contractually obligated to process personal data only on our instructions, to implement appropriate security measures, and to comply with the GDPR.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:
- Contact form data: Retained for a maximum of two (2) years from the date of your last correspondence, after which it is securely deleted or anonymised.
- Membership data: Retained for the duration of your active membership plus five (5) years after membership ends. This extended period allows us to maintain accurate records, address any outstanding matters, and comply with legal obligations.
- Donation records: Retained for seven (7) years from the date of the donation, as required by Belgian tax and accounting legislation (Belgian Accounting Act of 29 April 2019 and related Royal Decrees).
- Website analytics data: Anonymised analytics data may be retained indefinitely as it can no longer be linked to identifiable individuals. Non-anonymised data is retained for a maximum of twelve (12) months.
- Communication records: Retained for a period necessary to document and follow up on the relevant interaction, typically no longer than two (2) years unless related to an ongoing membership or legal matter.
When data is no longer required, it is securely deleted or irreversibly anonymised.
Your Rights Under GDPR
Under the General Data Protection Regulation, you have the following rights regarding your personal data:
- Right of Access (Article 15): You have the right to obtain confirmation as to whether or not we process your personal data, and if so, to request access to that data along with information about how it is processed.
- Right to Rectification (Article 16): You have the right to request the correction of inaccurate personal data or the completion of incomplete data without undue delay.
- Right to Erasure (Article 17): You have the right to request the deletion of your personal data ("right to be forgotten") where there is no compelling legal or organisational reason for continued processing.
- Right to Restriction of Processing (Article 18): You have the right to request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to its processing.
- Right to Data Portability (Article 20): You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit it to another controller where technically feasible.
- Right to Object (Article 21): You have the right to object to the processing of your personal data based on legitimate interests, including for direct marketing purposes.
- Right to Withdraw Consent (Article 7(3)): Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Belgian Data Protection Authority (Autorite de protection des donnees / Gegevensbeschermingsautoriteit) at Drukpersstraat 35, 1000 Brussels, Belgium, or via www.dataprotectionauthority.be if you believe your data protection rights have been infringed.
How to Exercise Your Rights
To exercise any of the rights described above, or if you have any questions about how we process your personal data, please contact us by email at organibe@gmail.com. To protect your privacy and security, we may need to verify your identity before processing your request.
We will respond to your request within one (1) month of receipt. In cases of complexity or a high volume of requests, this period may be extended by an additional two (2) months, in accordance with Article 12(3) of the GDPR. You will be informed of any such extension within the initial one-month period.
Please note that certain rights may be limited where we have a compelling legal ground for processing your data, or where the exercise of a right would adversely affect the rights and freedoms of others.
Data Security
M & M takes the security of your personal data seriously and implements appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. These measures include, but are not limited to:
- Use of encrypted connections (SSL/TLS) for data transmitted through our website.
- Access controls limiting who within our organisation can access personal data, based on the principle of least privilege.
- Regular review and updating of our security practices and procedures.
- Training of our staff and volunteers on data protection and information security best practices.
- Secure disposal of physical and digital records containing personal data when they are no longer needed.
- Use of reputable, GDPR-compliant third-party service providers who maintain robust security certifications.
While we strive to protect your personal data, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security but are committed to taking all reasonable steps to protect your information and to notify you promptly in the event of a data breach that poses a risk to your rights and freedoms, in accordance with Article 33 of the GDPR.
Cookies
Our website uses cookies and similar technologies to enhance your browsing experience, analyse website traffic, and understand user behaviour. Cookies are small text files placed on your device when you visit a website.
We use only essential and limited functional cookies. We do not use third-party advertising or tracking cookies. For full details about the cookies we use, how to manage them, and your choices, please see our dedicated Cookie Policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you directly or post a prominent notice on our website.
We encourage you to review this policy periodically. Your continued use of our website or services after any changes to this Privacy Policy constitutes your acceptance of the updated terms, unless a new explicit consent is required by law.
Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us at:
M & M, ASBL/VZW
Herentalsesteenweg 66 B
2220 Heist-op-den-Berg, Belgium
Enterprise number: BE0843318493
Email: organibe@gmail.com
We are committed to working with you to resolve any concerns about the processing of your personal data. If you are not satisfied with our response, you also have the right to lodge a complaint with the Belgian Data Protection Authority (see "Your Rights Under GDPR" above).