Privacy Policy & Terms of Service

Rotaract Club Luxembourg ASBL

Rotaract Club Luxembourg ASBL ("we," "us," or "our") is committed to protecting the privacy and security of personal data collected from members, donors, volunteers, and visitors to our website rotaract.lu. This Privacy Policy outlines how we collect, use, store, and protect your information in compliance with the EU General Data Protection Regulation (GDPR), Luxembourg's Law of 1 August 2018 on Data Protection, and other applicable legislation.

1. Data Controller and Legal Basis

Identity of the Controller

Rotaract Club Luxembourg ASBL
Registered Office: [Address to be updated]
Email: Contact us Page

Legal Basis for Processing

We process personal data under the following GDPR Article 6 legal bases:

  • Consent: When you voluntarily provide data for membership applications, event registrations, or newsletter subscriptions
  • Contractual Necessity: To fulfill obligations related to membership benefits, event participation, or donation processing
  • Legitimate Interests: For internal administrative purposes, fraud prevention, and network security
  • Legal Obligations: To comply with financial reporting requirements under Luxembourg nonprofit regulations

2. Types of Personal Data Collected

Directly Provided Data

  • Identifiers: Full name, date of birth, and contact details (email, phone, address) for membership management and event coordination
  • Financial Information: Bank account details for donation processing and transaction records for audit compliance
  • Professional Background: Employment status and skills submitted through volunteer application forms
  • Preferences: Communication language (English/French) and opt-in choices for marketing materials

Automatically Collected Data

  • Technical Information: IP address, browser type, and device identifiers for security monitoring and analytics
  • Usage Patterns: Pages visited and interaction times via cookies

3. Purposes of Data Processing

Core Organizational Activities

  1. Membership Management
    • Verifying eligibility for membership
    • Coordinating club elections and leadership roles
  2. Event Operations
    • Sending event confirmations and logistical updates
    • Handling dietary requirements and accessibility needs for in-person gatherings
  3. Donation Processing
    • Issuing tax receipts under Luxembourg's nonprofit fiscal laws
    • Fraud detection through transaction monitoring

Communications and Outreach

  • Newsletters: Sharing updates about club projects and Rotary International initiatives
  • Fundraising Campaigns: Targeted outreach based on past donation history

4. Data Sharing and Third-Party Transfers

Categories of Recipients

  • Service Providers:
    • Payment processors (e.g., PayPal, Stripe) for secure donation handling
    • Email platforms (e.g., Mailchimp) for newsletter distribution
  • Rotary Affiliates:
    • Rotaract Europe and Rotary International for cross-border collaboration
  • Legal Authorities:
    • Luxembourg tax authorities (Administration des Contributions Directes) for audit requests

International Transfers

Data transferred outside the EU/EEA (e.g., to Rotary International's U.S. headquarters) is protected through:

  • Standard Contractual Clauses with Rotary entities
  • Adequacy Decisions for countries with equivalent data protection standards

5. Data Security Measures

Technical Safeguards

  • Encryption: AES-256 for data at rest and TLS 1.3 for data in transit
  • Access Controls: Role-based permissions and multi-factor authentication for administrative systems

Organizational Practices

  • Staff Training: Annual GDPR compliance workshops for board members and volunteers
  • Incident Response Plan: 72-hour breach notification protocol to the CNPD

6. Your Data Subject Rights

Access and Portability

Request a copy of your data in a structured, machine-readable format via our dedicated webform or by contacting us on the Contact us Page.

Rectification and Erasure

Update inaccurate details or request deletion (except where retention is legally required) by contacting us on the Contact us Page.

Complaint Lodgment

Submit grievances to Luxembourg's National Data Protection Commission:

Commission Nationale pour la Protection des Données
15, Boulevard du Jazz, L-4370 Belvaux
Email: [email protected]

7. Data Retention Periods

Data Type Retention Period Legal Basis
Membership records 5 years post-membership Nonprofit association laws
Financial transactions 10 years Luxembourg fiscal code
Website analytics 26 months CNPD guidance
Marketing communications 3 years or until consent withdrawal Legitimate interests

8. Cookies and Tracking Technologies

Essential Cookies

Session cookies enable login functionality and form persistence for donation and membership applications.

Analytical Cookies

Third-party analytics measure traffic patterns and user engagement to improve our website experience. You can opt-out through your browser settings or our cookie preference center.

9. Children's Privacy

We do not knowingly collect data from individuals under 16 without parental consent. If you believe we have inadvertently collected such information, please contact us immediately.

10. Policy Updates

Changes will be posted on this page with revised effective dates. Material modifications trigger direct email notifications to active members.

Effective Date: February 16, 2025
Last Updated: May 26, 2025