Privacy Notice

This Privacy Notice describes how non-profit association Eurasian Coalition on Male Health (registry code 80358856, Tartu mnt 63, 10115 Tallinn, Republic of Estonia; hereinafter we, our or ECOM) processes personal data. ECOM is the controller and the person responsible for the data processing activities described below.

We recognize the importance of privacy and we are committed to protecting the privacy of all the individuals whose personal data we process. This Privacy Notice explains how we collect, use and share your personal data, and what are your rights in respect of your personal data.

We may process your personal data in the course of performing different activities, depending on your relationship with us. We have prepared this Privacy Notice in such a way that each person who interacts with us, can find under section 1 a specific description of the conditions applicable to the processing activity that is applicable to that person.

Therefore, in order to obtain an accurate overview of the personal data processing activities and principles that concern you, please find the part(s) below that applies to your connection with ECOM (see subsections 1.1 – 1.11 below). The general principles that are applicable to all of our data processing activities are outlined at the end of the Privacy Notice (see sections 2 to 8 of the Privacy Notice).

The terms used in the Privacy Notice shall be construed as in the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter GDPR).

General principles

Categories of personal data, purposes of and legal bases for processing, and the retention of personal data

I am a visitor to ecom.ngo

Visitors to our webpage are generally in control of the personal data they share with us (e.g. by signing up for our newsletter – see subsection 1.2 – or registering an account on our website – see subsection 1.3). We may collect some personal data automatically via cookies on our website. For more information about which cookies we use and how we use the data gathered via cookies, see our Cookie Policy[.

I am a recipient of the newsletter

In the meaning of this Privacy Notice, ‘recipient of the newsletter’ is someone who regularly receives our e-mails that give an overview of our activities, our events and other topics that we consider important. 

We only send you our newsletter, if you yourself have provided us with your email addressfor the purpose of receiving the newsletter. Your email address is the only piece of personal information we collect in order to send you the newsletter. The legal basisfor such processing is your respective consentthat you give when you register your email address on our website ecom.ngo for receiving the newsletter.

Please note that you can unsubscribe from our newsletters any time by clicking the ‘unsubscribe’ button in the bottom of any of the newsletters. In such a case, we will delete your email address from the newsletter list immediately and you will not receive any of our future newsletters. 

I am a person who has registered an account on ecom.ngo (registered user)

We process the following personal datarelated to the registered users, which we have received from yourself:

  • personal details (name, surname,nickname);
  • contact details (email);
  • other information that you have decided to communicate to us.
  • preferred language
  • website
  • google+
  • twitter
  • facebook

We process your personal data for the following purposes:

  • enabling you the use of the functions available to ecom.ngo registered users;
  • enabling you to download information and apply requests and forms;
  • enabling you to send reports;
  • leave comments and rate the materials.

The legal basis for such processing is your respective consent that you give by registering to our website ecom.ngo.

We retain your personal data until it is necessary depending on the purposes for which we collected the data. We may retain your personal data longer, if it is necessary for the protection of our interests or the fulfilment of our obligations deriving from the law. We usually retain the personal data of registered users for analysis of statistics of visits and user interests. We delete all the personal data of a registered user immediately after they have deleted their account on our website.

I am a member of an initiative group or an organization that applies for funding from ECOM or receives funding from ECOM (sub-recipient)

In the meaning of this Privacy Notice ‘sub-recipient’ includes the people who are members of initiative group or of an organization that applies for funding from ECOM or receives funding from ECOM.

We process the following personal datarelated to the sub-recipients, which we have received from yourself or from the initiative group or organization that you are a member of, you work for or with which you participate in the funding process:

  • personal details (name, position, job responsibilities);
  • contact details (address, email, telephone number);
  • data related to qualification (e.g. information about the acquired education and/or professional qualifications);
  • data about employment history (e.g. previous employers, previous positions, the number of years of previous professional experience);
  • other data which you have decided to communicate to us;
  • grants story or other programs’ implementation information.

We process your personal data for the following purposes:

  • contact the sub-recipient;
  • to assess the competence and the eligibility of the sub-recipient in order to decide to whom we should give funding to;
  • to conclude a contract with the sub-recipient;
  • to exercise the rights and fulfil obligations arising from the contract with the sub-recipient.

The legal basis for processing your data for the above mentioned purposes is our legitimate interest to administer the relationship with the sub-recipient. We believe that as you are a sub-recipient, in such circumstances our business interest overrides your interests and fundamental rights and freedoms. If you are a natural person that applies for funding in your own name, the legal basis for such processing is your consent that you give by submitting the funding applicationand if you are a natural person that receives funding, the legal basis for processing your personal data is the funding contractconcluded between us.

We retain your personal data until it is necessary depending on the purposes for which we collected the data. We may retain your personal data longer, if it is necessary for the protection of our interests or the fulfilment of our obligations deriving from the law. For instance, we store personal data necessary for the fulfilment of our accounting obligations for at least 7 years from the end of the relevant financial year, and the data necessary for filing claims or defending ourselves against claims for 1o years after the end of the contract.

I provide funding to ECOM or represent a legal person who provides funding to ECOM (donors and representatives of donors)

In the meaning of this Privacy Notice ‘donor’ means a physical or legal person who provides funding to ECOM. ‘Representatives of donors’ includes the people who are the legal representatives of the donors and people who are the contact persons of the donors.

We process the following personal data of the donors, the representatives of donors and other natural persons associated with donors, which we have received from yourself or from the donor:

  • personal details (name, date of birth);
  • contact details (email, telephone number);
  • the relationship with the donor and position (if relevant).

We process your personal data for the following purposes:

  • to contact you or the donor you are associated with;
  • to conclude a contract with you or the donor you are associated with;
  • to exercise the rights and fulfil obligation arising from the contract concluded with you or the donor you are associated with.

If you are a donor that is a natural person, the legal basis for processing your personal data is the necessity to take steps prior to entering into a contract and performing the contract.

If you are associated with a donor (e.g. representative of a donor), the legal basis for processing your personal data is our legitimate interest to receive funding from the donor and administer the relationship with the donor. We believe that, as you are the representative of the donor, our business interests override your interests and fundamental rights and freedoms.

We retain your personal data until it is necessary depending on the purposes for which we collected the data. We may retain your personal data longer, if it is necessary for the protection of our interests or the fulfilment of our obligations deriving from the law. For instance, we store personal data necessary for the fulfilment of our accounting obligations for at least 7 yearsfrom the end of the relevant financial year, and the data necessary for filing claims or defending ourselves against claims for 1oyearsafter the end of the contract.

I am a participant of a survey conducted by ECOM

In the meaning of this Privacy Notice, ‘participant of a survey’ includes all people who have decided to participate in any survey conducted by ECOM.

We process the following personal data related to survey participants, which we have received from yourself (the categories of personal data may vary in different surveys):

  • age;
  • place of residence (town and/or country);
  • medical information;
  • sexual orientation;
  • gender;
  • IP-address (if the survey is conducted online);
  • Facebook profile (optional);
  • Email address (optional).

We process your personal data for the following purposes:

  • to acquire practical knowledge and use it in developing new programs, projects and coordinating our activities directed at achieving the goals and purposes set forth in our articles of association;
  • to create reports of the results of the surveys to publish them on our website and to raise awareness.

We process your data for these purposes only if you have given your explicit consent for that.

We may also collect your namenickname, information about your Facebook profile and/or your email address, if you have decided to communicate such data to us. Please note, that providing such data is optional and it is not considered as a prerequisite for participating in the survey. We process such data only with the purpose to send you similar surveys in the future, only if you have consented to such processing and have provided your contact details for that purpose.

Please note that the results of the survey will be published in a generalized form only, without the possibility to identify any of our participants. Overall, we do not identify any of our survey participants even if you decide to provide us your name, nickname, information about your Facebook profile and/or your email address.

Where we process your personal data based on your consent, you have the right to withdraw your consent at any time by contacting us at contact@ecom.ngo. The withdrawal of the consent does not affect the lawfulness of the processing based on consent before its withdrawal.

We retain your personal data (your name, nickname, information about your Facebook profile and/or your email address) until publication of the final survey report. Since we collect the answers to our surveys in unidentifiable form, we are able to retain this data for an indefinite period.

I am a participant of an event organized by ECOM or our sub-recipient (event participants)

In the meaning of this Privacy Notice, ‘event participants’ includes all persons who participate in any of the events (including seminars, webinars, meetings and conferences) organized by ECOM or its sub-recipients.

We process the following personal data related to event participants, which we have received from yourself, our sub-recipients (to whom you have given your personal data yourself or who have collected data themselves during the events), your representative(s) or which we have collected at the events (e.g. photos):

  • personal details (name, date of birth, passport number or personal ID code);
  • contact details (address, email, telephone number);
  • copy of a passport;
  • medical information (e.g. data about food allergies, disability);
  • photos taken at the events.

We process the personal data for the following purposes:

  • to enable you to participate in our event;
  • to organize the event;
  • to promote our events and activities;
  • to fulfil our reporting obligation to our donors.

If you have participated in one of the events organised by our sub-recipient, we may receive following personal data about you from our sub-recipient (to whom you have given your personal data yourself or who have collected data themselves during the events):

  • personal details (name, date of birth, passport number or personal ID code);
  • contact details (address, email, telephone number);
  • photos taken at events.

We process the personal data received from our sub-recipients for the following purposes:

  • to have control over the use of funding we have given to our sub-recipients;
  • to fulfil our reporting obligation to our donors.

The legal basis for such processing is either your consent that you give when you sign up to an event or performance of contract between us or between you and our sub-recipient. Since we have reporting obligation in front of our donors, we may share your data with our donors on the basis of our legitimate interest. Additionally, we may receive your personal data from our sub-recipients who we provide funding to organize events. In such a case, we may process your data on the basis of our legitimate interest.

We also take photos of the events and publish these to share information about our organisation and our events. In such cases, the legal basis for processing depends on the objectives and characteristics of the specific event, but is either your consentor our legitimate interest. Before deciding, whether our legitimate interest would be a proper legal basis for processing your image, we conduct proper analysis of your and our interests. If we believe that our legitimate interest can be considered as a proper legal basis for processing your image, we always inform you of the fact that the event is being photographed. If you do not want be photographed, you shall always have the right to object to that. In addition, if the legal basis for processing is our legitimate interest, you shall always have the right to object to the processing of your image.

Where we process your personal data based on your consent, you have the right to withdraw your consent at any time by contacting us at contact@ecom.ngo. The withdrawal of the consent does not affect the lawfulness of the processing based on consent before its withdrawal.

We retain your personal data for no more than 10 years.

I am a contractor that offers or provides services to ECOM or a representative of a contractor that offers or provides services to ECOM (service providers and representatives of service providers)

In the meaning of this Privacy Notice, ‘service providers’ refers to physical or legal persons who have made an offer to provide services to ECOM and/or provide services to ECOM. ‘Representatives of service providers’ are the legal representatives, the contact persons and employees of the service provider, who are involved in the provision of the services or are otherwise related to the service agreement.

We process the following personal data related to service providers and representatives of service providers, which we have received from yourself or from the service provider:

  • personal details (name, date of birth or personal ID code or passport number);
  • copy of a passport or other ID;
  • contact details (address, email, telephone number);
  • data related to qualifications (e.g. information about the acquired education and/or professional qualifications);
  • data about employment history (e.g. previous employers, previous positions, the number of years of previous professional experience);
  • payment details (e.g. bank account number, tax details);
  • other data which you have decided to communicate to us in your CV, recommendation letter or otherwise.

We process your personal data for the following purposes:

  • to verify you and the personal data you have submitted to us (on the basis of your passport or other ID);
  • to contact the service provider;
  • to assess the competence of the service provider in order to decide with whom we should conclude service agreements with;
  • to conclude contracts;
  • to exercise the rights and fulfil obligations arising from the contract with the service provider.

The legal basis for such processing is the necessity to takes steps prior to entering into a contract and/or to perform the contract. If you are a representative of a service provider, the legal basis for processing your personal data is our legitimate interest to receive services from the service provider and to administer the relationship. We believe that as you are professionally connected to the service provider, in such circumstances our business interest overrides your interests and fundamental rights and freedoms.

We retain your personal data until it is necessary depending on the purposes for which we collected the data. We may retain your personal data longer, if it is necessary for the protection of our interests or the fulfilment of our obligations deriving from the law. For instance, we store personal data necessary for the fulfilment of our accounting obligations for at least 7 years from the end of the relevant financial year, and the data necessary for filing claims or defending ourselves against claims for 1o years after the end of the contract.

I am a job applicant

In the meaning of this Privacy Notice, ‘job applicants’ include all people who have expressed their wish to be employed by ECOM and made their personal data available for ECOM to assess their suitability for working for ECOM.

We process the following personal data related to job applicants, which we have received from yourself:

  • personal details (name, date of birth, nationality/citizenship);
  • contact details (address, email address, telephone number);
  • data related to qualifications (e.g. information about the acquired education and/or professional qualifications);
  • data about employment history (e.g. previous employers, previous positions, the number of years of previous professional experience);
  • data collected through qualification and knowledge tests;
  • other data which you have decided to communicate to us in your CV, motivation letter, at the interview or otherwise.

We may also collect your personal data from your recommenders (e.g. your previous employers), if you have consented to that. By giving us the name and the contact details of your recommender, we assume that you have given your consent to contact them.

We process your personal data for the following purposes and on the following legal bases:

  • to find the most suitable candidates for us and to decide with whom to conclude employment contract with;
  • if necessary, for filing claims and for defending ourselves against claims.

The legal basis for such processing is either your consent that you give us by applying to a respective position or our legitimate interest to find the best candidate for a vacant position or to protect our rights. Where the legal basis for processing is our legitimate interest, we have concluded that our legitimate interest overrides your interests and fundamental rights and freedoms in a given situation.

If we choose someone other than you to fill the vacant job position, we retain your personal data up to 1 year from making the recruitment decision. We may retain your personal data longer, if it is necessary for the protection of our interests or the fulfilment of our legal obligations. If we conclude an employment contract with you, subsequent processing of your personal data by us will be carried out in accordance with separate processing rules that will be presented to you before signing of the contract.

I am applying to be a member of ECOM (membership applicants)

In the meaning of this Privacy Notice, ‘membership applicants’ include all natural persons who themselves have applied for membership to ECOM or are representatives of such applicants.

We process the following personal data, which we have received from yourself or from the applicant that is a legal entity:

  • personal details (name, surname, date of birth);
  • contact details (address, email address, telephone number);
  • data retrievable from the CV (e.g. information about the acquired education and/or professional qualifications, previous employers, previous positions, the number of years of previous professional experience);
  • description of previous activities relating to ECOM’s activities;
  • motivation letter;
  • copy of an ID document.

As one of the preconditions to join ECOM is to submit a recommendation letter from a current ECOM member, we also collect your personal data from your recommender(s).

We process your personal data for the following purposes and on the following legal bases:

  • to identify you or the organisation you are representing or related to;
  • assess whether you or the organisation you are related to, fulfil the requirements we have stipulated for ECOM membership.

The legal basis for such processing is either your consent that you give by applying or our legitimate interest to find members that share our goals and suit our organisation. Where the legal basis for processing is our legitimate interest, we have concluded that our legitimate interest overrides your interests and fundamental rights and freedoms in a given situation.

If we decide not to grant you the membership, we will delete your application data after three months of the decision or if immediately upon your request.  If we accept you as a member, subsequent processing of your personal data by us will be carried out in accordance with clause 1.11 of this Privacy Notice.

I am a member of ECOM

‘Members of ECOM’ are the natural persons who are themselves members or related to the legal entities that are members of our non-profit association within the meaning of our articles of association.

We process the following personal data, which we have received from yourself or from the applicant that is a legal entity:

  • all the personal data that you have submitted to us during the membership application process (see above – clause 1.10);
  • information on your activities as a member of ECOM (e.g. your candidacy and activities in our organs, participation in events etc.);
  • your participation, statements and voting during general assembly;
  • other relevant data about your membership that you yourself have submitted to us or we have gathered ourselves.

We process your personal data for the following purposes and on the following legal bases:

  • for administrative and archiving purposes;
  • to exercise our obligations under our articles of association;
  • to fulfil our legal obligations;
  • to identify you or the organisation you are related to.

The legal basis for such processing is usually performance of contract, our legitimate interest or our legal obligation. Within the meaning of GDPR we perceive our articles of association to be a contract between you and ECOM.

We retain your personal data until it is necessary depending on the purposes for which we collected the data. We will retain your data for as long as you are a member of ECOM.

If you leave our organisation or you cease to represent your organisation in ECOM, we will delete your data after three months of the decision or immediately upon your request, except the data that we need in order to fulfil our legal obligations (e.g. bookkeeping obligations) or if we have overwhelming legitimate interest to do so (e.g. for archiving purposes).

2. Transmission of personal data

We share your personal data with third parties only if we have justified need, to the justified extent and only if we have a legal basis for such transmission

Data Processors

In the meaning of this Privacy Notice, ‘data processors’ are our service providers who process your personal data in ECOM’s name. ECOM remains responsible for the processing activities carried out by our data processors.

We use in our activities the following categories of service providers who may get access to your personal data (data processors):

  • e-mail service providers;
  • management and storage providers;
  • consultants, service providers and other advisors.

We only use data processors who provide sufficient guarantees that they apply appropriate technical and organizational measures in order to ensure the protection of your personal data. We have concluded appropriate data processing agreements with the service providers and shall remain responsible for their actions in respect of the processing of your personal data.

Should you require more detailed information as regards the data processors we use (e.g. their names and location) please contact us on the contact details below.

Third parties

We may also transmit your personal data to the following third parties who act as independent controllers with regard to your personal data:

  • upon request, to our donors and their representatives, in which case the legal basis for transmission is either the performance of our contract or our legitimate interest to the extent which in our assessment overrides your interests and fundamental rights and freedoms depending on our relationship;
  • if necessary, to third parties via whom we organize transportation and accommodation to our consultants, employees, in which case the legal basis for transmission is the fulfilment of our mutual agreement;
  • to third parties who are the members of ECOM steering committee, in which case the legal basis for the transmission of personal data is our legitimate interest to the extent which in our assessment overrides your interests and fundamental rights and freedoms;
  • to third parties who protect our legal rights (e.g. our legal consultants), in which case the legal basis for the transmission of personal data is our legitimate interest to the extent which in our assessment overrides your interests and fundamental rights and freedoms;
  • to third parties who provide us with audit services to verify our accounts, in which case the legal basis for transmission is either the performance of our contract or our legitimate interest to the extent which in our assessment overrides your interests and fundamental rights and freedoms depending on our relationship;
  • to third parties to whom we are obligated to transmit personal data in accordance with law or other legal acts (e.g. supervisory authorities), in which case the legal basis for transmission is the fulfilment of our obligations arising from law.

We only share your personal data with third parties if stipulated in this Privacy Notice, if required under the applicable law (e.g. when we are obligated to share personal data with the authorities) or under your consent.

3. Transmission of personal data outside the European Economic Area

We transmit your personal data outside the European Economic Area (EEA) only if we have a legal basis to do so, including to data recipients: (i) who are located in a country where sufficient level of personal data protection is ensured in the assessment of the European Commission (including organisations certified under the Privacy Shield) or (ii) on the basis of an agreement which meets the EU requirements for the transmission of personal data to personal data processors located outside the EEA.

Should you require more detailed information as regards transferring your personal data outside the EEA (e.g. the names of the recipients and the exact legal basis for any such transfer), please contact us on the contact details below.

4. Security

We implement sufficient technical and organizational security measures to protect your personal data, taking into account: (i) the level of technology, (ii) the costs of implementation, (iii) the nature, scope, context and purposes, and (iv) the possible risks to you that may arise from data processing.

5. Your rights

With regard to your personal data, you have all the rights prescribed by legal acts, including the GDPR, on the terms and conditions and to the extent established therein:

  • the right to request access to your personal data (including to receive a copy of your personal data);
  • the right to request the rectification of personal data;
  • the right to request the deletion of personal data;
  • the right to request the restriction of the processing of personal data;
  • the right to the portability of personal data;
  • the right to withdraw your consent, if we process your personal data on the basis of your consent;
  • the right to submit objections if personal data is being processed on the basis of our legitimate interest.

If you wish to exercise the rights specified above or should you have any questions about the processing of your personal data, please contact us on the contact details provided below. We will answer to your request as soon as possible, but at least within 1 month of receipt of your request and inform you about the measures we have taken. For reasons of complexity or large scope of your request, it may take us longer to process your request (up to 3 months), in which case we will inform you of such circumstances.

If you believe that your rights have been violated or your personal data have not been processed in accordance with this Privacy Notice, we kindly recommend you to contact us on the contact details provided below. In case of a violation, you also have the right to turn to a competent data protection supervisory authority (in Estonia the Estonian Data Protection Inspectorate) or the court.

6. Amendment of the Privacy Notice

If our personal data processing practices shall change or we need to change the Privacy Notice due to changes in the applicable data protection related legal acts, other legal acts, case-law or guidelines or practices of competent authorities, we have the right to unilaterally amend the Privacy Notice. If the amendments affect you significantly, we shall notify you before the amendments enter into force by email.

7. Applicable law

Non-profit association Eurasian Coalition on Male Health is an association registered in the Republic of Estonia and the processing of your personal data is therefore subject to the laws of the Republic of Estonia.

8. Contact details

If you have any questions concerning the processing of your personal data or if you wish to exercise your rights with regard to your personal data, please contact us using the following contact details:

Eurasian Coalition on Male Health

Address: Tartu mnt 63, 10115 Tallinn, Republic of Estonia
Email: contact@ecom.ngo
Phone: +372 634 6257

Current Privacy Policy valid from 15.02.2019