Privacy Policy

Last Updated: 01 Oct, 2025

Stichting Global Buds Foundation (“SGBF”, “we”, “us”, “our”) is committed to protecting your privacy and ensuring that your personal information is handled securely and transparently. This Privacy Policy explains how we collect, use, disclose and store your personal data when you access our website, use our services or make a donation.

1. Data Controller

SGBF is the data controller within the meaning of the EU General Data Protection Regulation (GDPR) and relevant Dutch legislation.
Registered address: Prinses Irenestraat 13, 6941DS Didam, Netherlands
Email: info@sgbf.nl

2. What Data We Collect

We may collect the following personal data:

  • Identity data: full name, title, date of birth (if provided)

  • Contact data: email address, telephone number, mailing address (if provided)

  • Transaction & donation data: donation amount, donation date, payment method, donation frequency, program selected

  • Technical & usage data: IP address, browser type, device information, cookies, page views, time spent on site

  • Optional data: any motivation text or message you submit, feedback or questionnaire responses

3. Purpose and Legal Basis for Processing

We process your data for the following purposes:

  • To process and record your donations, issue receipts and thank you messages (legal basis: contract / legitimate interest)

  • To communicate with you regarding your donation, our mission, updates, newsletters (legal basis: consent)

  • To improve our website, services, user experience and security (legitimate interest)

  • To comply with our legal, tax and auditing obligations under Dutch law (legal basis: legal obligation)

4. Data Sharing & Recipients

We do not sell your personal data. We may share your data with:

  • Our payment service provider for processing donations (only the data necessary for the transaction)

  • Auditors, tax advisors or legal authorities when required by law

  • Third-party service providers (e.g., email platform, analytics provider) under contract and with appropriate safeguards

5. International Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure adequate protections (e.g., standard contractual clauses) are in place.

 

6. Data Retention

We retain your personal data only as long as necessary for the purposes described (e.g., accounting, auditing obligations) and in accordance with Dutch retention laws. Thereafter, we securely delete or anonymise your data.

7. Your Rights

Under the GDPR and Dutch law, you have the right to:

  • Access your personal data and receive a copy

  • Rectify inaccurate or incomplete data

  • Delete (“erasure”) your personal data in certain circumstances

  • Restrict further processing

  • Object to certain processing (e.g., direct marketing)

  • Data portability, where applicable

  • Withdraw consent at any time (where processed on consent)

To exercise these rights — or for privacy questions — please contact: [Insert email]. We will respond within one month, unless extended under law.

8. Security Measures

We implement appropriate technical and organisational security measures (encryption, access controls, regular audits) to protect your data from unauthorised access, alteration, loss or disclosure.

9. Cookies and Tracking

We use cookies and similar technologies to enhance your experience, analyze usage and provide personalised content. Please refer to our Cookie Policy for details, and you may disable cookies via your browser settings (note this may affect functionality).

 

10. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last Updated” date will reflect that. We encourage you to review it regularly.