Data Protection
GDPR Privacy Policy
This Privacy Policy explains how REDI collects, uses, protects, and retains personal data in full compliance with the General Data Protection Regulation (GDPR) (EU 2016/679).
EU GDPR Compliance (Regulation 2016/679)
Updated July 20261. Data Controller Identification
The data controller responsible for the processing of personal data is REDI NGO (Roma Entrepreneurship Development Initiative).
Official Email Contact: office@redi-ngo.eu
2. Categories of Personal Data Collected
We collect and process personal data exclusively provided voluntarily through contact, newsletter, or inquiry forms:
- Full Name
- Email Address
- Phone Number
- Business / Organization Entity Details (optional)
3. Purpose and Legal Basis for Processing
Personal data is processed solely to send occasional updates, program announcements, and technical assistance details to individuals who have expressed interest in REDI’s activities.
The legal basis for processing is the legitimate interest pursued by REDI (Art. 6(1)(f) GDPR) to inform beneficiaries and partners about economic empowerment opportunities.
4. Data Security and Technical Protection
REDI implements strict technical and organizational safeguards to prevent unauthorized access, loss, or alteration of personal data:
- End-to-end HTTPS encryption
- Multi-factor authentication (MFA)
- Strict role-based access controls (RBAC) limiting data access to designated personnel
5. Retention Period
Personal data is retained for a maximum of 6 months from collection, unless a longer retention period is explicitly requested by the data subject or required by applicable legal obligations.
6. Rights of Data Subjects
Under GDPR, you hold the following enforceable rights:
- Right to Access: Request a copy of personal data held about you.
- Right to Rectification: Correct inaccurate or incomplete information.
- Right to Erasure ('Right to be Forgotten'): Request full deletion of your personal data by emailing office@redi-ngo.eu. Erasure requests are processed within 10 working days.
- Right to Object & Restrict Processing: Object to data usage or request processing restrictions.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
7. Third-Party Sharing & Transfers
REDI does not sell, rent, or transfer personal data to third parties, commercial entities, or international recipients outside the European Economic Area (EEA).
8. Cookies & Tracking Technologies
REDI’s website operates without intrusive tracking cookies, third-party analytics scripts, or behavioral profiling mechanisms.
Need to exercise your data rights?
Contact our data controller at office@redi-ngo.eu for prompt assistance within 10 working days.
