PRIVACY POLICY


1. Who are we?

Stichting GildeLab is a sustainable and social studio in Amsterdam. We support women with a distance to work in developing professional skills, work experience, and self-confidence. In addition, we work together with small sustainable fashion and lifestyle brands and with partners, funds, donors, and volunteers.

Data controller: Stichting GildeLab, Ferdinand Huyckstraat 60, 1061 HW Amsterdam. Chamber of Commerce (KvK): 60317884. RSIN/ANBI: 853856102. Email: info@hetgildelab.nl. Phone: 020 737 2512.

For privacy questions you can contact via info@hetgildelab.nl. Mention in the subject preferably “Privacy”.


2. For whom does this privacy statement apply?

This privacy statement applies to everyone whose personal data we process, including website visitors, persons who contact us, participants/trainees, volunteers, interns, applicants, donors, fund providers, subsidy providers, customers, suppliers, cooperation partners, and visitors of workshops, open days or other activities.

For participants/trainees, volunteers, employees and interns, in addition to this general privacy statement, an additional internal privacy text or agreement may apply, because in those relationships we process more or other data.

3. Which personal data do we process?

We process only personal data that is necessary for our foundation, activities, administration, communication, fundraising, guidance and legal obligations. Depending on your relationship with us it can concern the following data:


Relationship with GildeLab

Examples of personal data

Website visitors

IP address insofar as technically visible, browser and device data, visited pages, cookie preferences, analytical data if used.

Contact persons

Name, email address, telephone number, organization, content of your message and further correspondence.

Participants/trainees/volunteers

Name, contact details, motivation, availability, relevant education/experience, participation data, attendance, progress, guidance, evaluations, communication, possible emergency contact data and – only if necessary – additional data for guidance or safety.

Interns/applicants/employees

Name, contact details, CV/motivation, education, work experience, availability, interview notes, employment contract or volunteer contract, administrative data and data that is legally required.

Donors, friends and fund providers

Name, contact details, donation data, bank account/IBAN insofar as visible in payment traffic, communication preferences, relationship history and administrative/tax data.

Customers, sustainable brands, suppliers and partners

Name, function, organization, business contact details, project information, agreements, offers, invoice data, payment data and correspondence.

Event/workshop visitors

Name, contact details, registration, attendance, possible preferences or necessary information to organize participation well.

Image material

Photos, video, audio recordings or quotes on which someone can be recognizable, only for the purposes for which consent or another legal basis exists.


4. Why do we process personal data and on which legal basis?

We process personal data for the purposes below. We use one or more legal bases from the GDPR: execution of an agreement, legal obligation, legitimate interest, consent, or – in specific cases – another legal basis.


Purpose

Examples

Legal basis

Contact and communication

Answering questions, scheduling appointments, maintaining relationships.

Legitimate interest, agreement or consent.

Execution of activities

Training, guidance, workshops, volunteer work, assignments and project execution.

Agreement, legitimate interest or consent.

Participant guidance and development

Intake, progress, coaching, placement towards work/education, evaluation.

Agreement, legitimate interest and where necessary consent.

Administration and finances

Invoices, payments, donations, subsidies, bookkeeping, tax administration.

Legal obligation, agreement and legitimate interest.

Fundraising and donor relationship

Informing donors/friends, relationship management, thank-you messages, reporting to funds.

Legitimate interest, consent or agreement.

ANBI/CBF accountability

Publication of mandatory ANBI data, annual reporting, accountability to supervisors/funds.

Legal obligation and legitimate interest.

Newsletters and updates

Sending news, invitations and updates about GildeLab.

Consent or existing relationship/legitimate interest, with unsubscribe option.

Image material and publicity

Website, social media, reporting, fundraising, annual report, press.

Consent, unless another clear basis exists. For participants we use consent as starting point.

Website management and security

Proper functioning of the website, analysis of use, protection against misuse.

Legitimate interest and/or consent for non-essential cookies.

Compliance with laws and regulations

Retention obligation, controls, rights of data subjects, data breach notifications.

Legal obligation and legitimate interest.


5. Special personal data and sensitive information

We process special personal data, such as data about health, origin, religion, biometrics or political opinions, only when this is necessary and a valid legal basis exists.

Because GildeLab works with participants in a learning and development context, certain information can be sensitive, for example information about guidance, personal development, barriers towards work or necessary support.

We ask participants, volunteers and employees not to share sensitive information with us that is not necessary for participation, guidance, safety or legal obligations. When sensitive information is nevertheless necessary, we explain why we need that information, who can access it and how long we store it.

We do not use sensitive information for commercial purposes and we do not publish it without explicit consent.

6. Photos, videos, quotes and social media

We publish recognizable photos, videos, audio recordings or personal quotes only when there is a suitable legal basis for that. For recognizable image material of participants, volunteers and other involved persons, we use prior consent as starting point.

We request consent for image material as concretely as possible: for example separately for website, social media, newsletter, annual report, fundraising, press or internal use. You may refuse consent or withdraw it later. Withdrawal has no retroactive effect on publications already lawfully made, but we will reasonably do what is possible to stop further publication.

Note: when we post messages on platforms such as Instagram, Facebook, LinkedIn or Pinterest, those platforms also process personal data themselves. Their privacy terms also apply.

7. Cookies and similar techniques

Our website may use cookies and similar techniques.

Functional cookies are necessary for the website to function properly. Limited analytical cookies may be used to get anonymized insight into website use. For tracking cookies, marketing cookies, non-anonymized analytics and embedded social media cookies we ask prior consent via a cookie banner.

The current website must be technically checked for actually placed cookies. The final cookie statement must then precisely state which cookies are used, by whom, for which purpose and how long they are stored.

You can change or withdraw cookie preferences via the cookie banner or via your browser settings. Non-essential cookies are not placed without valid consent.

8. Sharing personal data with third parties

We only share personal data when necessary for our activities, administration, legal obligations or services. We do not sell personal data.

Examples of recipients are: hosting party, website manager, email provider, cloud storage, accountant, bank/payment service provider, CRM or newsletter system, subsidy providers/funds when reporting is necessary, insurer, legal advisor, IT administrator, cooperation partners in learning/work trajectories and competent government authorities when we are obliged to do so.

With parties that process personal data on our behalf, we conclude, where necessary, a processor agreement. With independent controllers we make appropriate agreements about purpose, security and confidentiality.

9. Transfer outside the European Economic Area

We try to process personal data as much as possible within the European Economic Area. When we use services where personal data may be processed outside the EEA, we only do this when there is a valid transfer basis, for example an adequacy decision or appropriate safeguards such as standard contractual clauses.

Examples where this may be relevant: cloud storage, email, newsletter software, analytics, social media and online collaboration platforms. This must be checked in practice during final implementation.

10. How long do we store personal data?

We do not store personal data longer than necessary for the purpose for which we process the data, unless we are legally obliged to store data longer or the data is needed for an ongoing procedure, audit or accountability.

As a starting point we use:
  • Contact questions and general correspondence: up to max. 2 years after last contact, unless longer needed
  • Participant/trainee data: during participation and in principle up to max. 2 years after completion, unless longer retention is needed for subsidy, reporting or legal obligations
  • Volunteer and intern data: during the relationship and in principle up to max. 2 years after end of relationship; administrative data longer if legally required
  • Application data: 4 weeks after completion of the application procedure, or max. 1 year with consent
  • Financial administration, invoices, donations and bookkeeping: 7 years
  • Newsletter data: until you unsubscribe or object
  • Image material with consent: as long as relevant or until consent is withdrawn
  • Cookie and analytics data: according to cookie statement and tool settings

11. Security

We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration or disclosure. Examples are access limitation, password policy, two-factor authentication where possible, secure storage, careful authorization, confidentiality, backups, periodic checks and agreements with processors.

When a possible data breach occurs, we assess this according to our internal data breach procedure. If necessary, we report a data breach to the Dutch Data Protection Authority and/or to those involved.

12. Your privacy rights

You have, according to the GDPR, different rights. You can request access to your personal data, correction of incorrect data, deletion of data, restriction of processing, data portability or objection to certain processing. When processing is based on consent, you can withdraw that consent.

Send your request to info@hetgildelab.nl with subject “Privacy request”. We respond in principle within one month. If your request is complex or if there are many requests, we may extend this period by a maximum of two months. In that case we inform you.

We do not standardly ask for a copy of your identity document. Only if we have reasonable doubt about your identity, we may request additional information to verify your identity. In that case do not send unnecessary data and black out BSN, photo and machine-readable zone.

13. Complaints

We take privacy questions and complaints seriously. Please first contact us via info@hetgildelab.nl so that we can assess and solve your question or complaint.

You also have the right to file a complaint with the Dutch Data Protection Authority via www.autoriteitpersoonsgegevens.nl.

14. Changes

We may adjust this privacy statement when our activities, systems, legal obligations or internal working methods change. The most current version is on our website. In case of substantial changes we inform involved parties where appropriate or required.