Privacy Policy

Last updated: 11/16/2025

Data Retention Commitment

🗓️ Your personal data will be automatically deleted:

  • Inactive organizer accounts: 1 year after last login
  • Completed events: 6 months after end date
  • Volunteer registrations: 2 months after event end
  • Sessions and tokens: 30 days maximum

💡 You can request immediate deletion of your data at any time via our contact form.

1. Data Collected

For Organizers:

  • Full name and email address (required)
  • Organization name (optional)
  • Encrypted password
  • Creation and last login dates

For Volunteers:

  • Full name and email address (required)
  • Phone number (optional)
  • Time slot preferences
  • Event registration date

2. Data Usage

Legitimate Purposes

  • Organization and coordination of volunteer events
  • Communication between organizers and volunteers
  • Management of registrations and time slots
  • Anonymized usage statistics

We NEVER

  • Sell or share data with third parties
  • Use for commercial purposes
  • Send unsolicited advertisements
  • Profile or behavioral analysis

3. Your GDPR Rights

Right of Access

View all data we have about you

Right to Erasure

Immediate deletion of your data

Right to Rectification

Correction of inaccurate data

Right to Portability

Export your data in a standard format

4. Data Security

  • 🔒 Encryption: All data is encrypted in transit (HTTPS) and at rest
  • 🛡️ Authentication: Secure access via password and JWT sessions
  • 🏠 Hosting: Data stored in Europe (GDPR compliant)
  • 🔍 Monitoring: Continuous monitoring of access and intrusion attempts
  • 💾 Backups: Encrypted backups with limited retention

5. Automatic Deletion

Automated Process

Our system automatically executes cleanup tasks to honor our retention commitments:

  • Daily verification of retention periods
  • Automatic deletion of expired data
  • Anonymization of statistics before deletion
  • Audit logs of deletions performed