DATA PROTECTION
Privacy Policy
This Policy explains how EDACCO processes personal data through its website, forms, network activities, events, projects and connected digital services.
1. CONTROLLER
Who is responsible for personal data
The controller is Ecological Development and Collaborative Chain Organization (EDACCO), ASBL/VZW, enterprise number BE 0774.312.101, Zwaluwenlaan 21, 1950 Kraainem, Belgium.
Privacy contact: support@edacco.org | DPO legal@edacco.org
2. SCOPE
What this Policy covers
This Policy covers edacco.org/, edacco.eu/, EDACCO forms, network/expert applications, project enquiries, event activity, protected resources and integrations initiated through the website. Separate platforms may publish their own notices.
3. DATA
Categories of personal data
Depending on the interaction, EDACCO may process identity/contact information, organisation and role data, professional profiles, collaboration interests, correspondence, submitted files, event/meeting data, account information, consent records, security logs, IP/device information and website usage data.
4. PURPOSES
Purposes and legal bases
Processing may include responding to enquiries, reviewing applications, administering projects/events/accounts, providing requested secretariat or technical assistance, maintaining security, meeting legal obligations and—where appropriately configured—sending newsletters or using optional analytics.
| Purpose | Typical GDPR basis |
|---|---|
| Requested enquiries / pre-contractual steps | Article 6(1)(b) where applicable, or legitimate interests |
| Project, event or relationship administration | Contract, legitimate interests and/or legal obligation depending on context |
| Optional newsletters / non-essential cookies | Consent where required |
| Security and service integrity | Legitimate interests and/or legal obligation |
5. GLOBELINE
Secretariat and technical-assistance workflows
Where requests are routed through or supported by Globeline, the privacy role must reflect the actual arrangement. If Globeline acts only on EDACCO’s documented instructions, an Article 28 processor agreement should govern the processing. If Globeline determines separate purposes or means, its own controller responsibilities should be transparent.
6. myEPA & EXTERNAL SYSTEMS
Connected platforms
Where users choose to access myEPA or another external platform, personal data may be processed under that platform’s own terms and privacy notice. EDACCO should not combine external-platform data for unrelated purposes without an appropriate legal basis and transparency.
7. RECIPIENTS
Access to data
Data may be accessed by authorised EDACCO personnel, approved project/expert participants where necessary, and vetted providers supporting hosting, email, security, forms, CRM, events, membership, collaboration or technical assistance.
8. TRANSFERS
Transfers outside the EEA
Where data are transferred outside the EEA, EDACCO should document the applicable adequacy decision or safeguards, including Standard Contractual Clauses where relevant, together with necessary supplementary measures.
9. RETENTION
How long data are kept
EDACCO should maintain a retention schedule for enquiries, applications, active relationships, project records, events, financial/legal documentation, access logs, consent evidence and mailing lists. Data should be deleted or anonymised when no longer needed.
10. RIGHTS
Individual rights
Subject to the GDPR and the circumstances, individuals may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and safeguards in relation to certain automated decisions.
11. SUPERVISION
Complaints
Individuals may contact EDACCO and may lodge a complaint with the competent supervisory authority. For EDACCO’s Belgian establishment, the relevant authority is the Belgian Data Protection Authority / Autorité de protection des données / Gegevensbeschermingsautoriteit.
12. SECURITY
Security and incidents
EDACCO should apply proportionate technical and organisational measures including access controls, authentication, maintenance, backups, confidentiality, vendor controls and incident response. Personal data breaches should be assessed and notified where required.
13. AUTOMATION
AI and profiling
Where automated systems classify profiles, recommend funding opportunities or assist decisions, EDACCO should document purpose, human oversight and limitations. Where Article 22 GDPR applies, the required safeguards should be provided.

