Privacy Policy – SELECT ORGANIC
The SELECT ORGANIC project website aims to provide transparent services and takes your privacy seriously. Any personal data collected through this website is processed in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Dutch Implementation Act (UAVG). By using this Service, you agree to the processing of your personal data as described in this Privacy Policy.
Personal data will only be processed for clearly defined purposes and will not be shared except as described in this document.
For purposes of this agreement, “Service” refers to all content and services provided via the SELECT ORGANIC website hosted on Squarespace. The terms “we,” “us,” and “our” refer to the SELECT ORGANIC project consortium. “You” refers to any user of the website.
Latest update: 11-05-2026
Contact details
Personal data is processed by members of the SELECT ORGANIC consortium who apply appropriate technical and organisational measures to protect personal data in accordance with Article 32 GDPR.
The main contact person on behalf of the SELECT ORGANIC consortium is: EFFAB – European Forum of Farm Animal Breeders
Visitor address: EFFAB, Brussels
Postal address: Rue de Trèves 61, B-1040 Brussels, Belgium
E-mail: cagla.kaya@effab.info
Website: https://www.effab.info
1. Consent
By accessing and using this website, you agree to this Privacy Policy and consent to the collection and processing of your personal data as described herein.
Consent is obtained where required (e.g. for marketing cookies, newsletters, and audiovisual materials), and may be withdrawn at any time without affecting the lawfulness of prior processing.
This Privacy Policy applies to all users of the website, regardless of registration.
2. Information we collect
We may collect:
Personal data (e.g. name, email address, organisation, phone number if provided)
Non-personal data (e.g. anonymised usage statistics, browser type, pages visited)
We also automatically collect technical data such as IP address, device type, operating system, and interaction data.
2.1 Squarespace data processing
This website is hosted by Squarespace, Inc. (“Squarespace”).
Squarespace may process personal data on our behalf as a data processor under a Data Processing Agreement (DPA) in accordance with Article 28 GDPR.
Squarespace may collect and store:
IP address
Browser and device information
Website usage data
Cookies and similar technologies
Squarespace may process data in the EU, the United States, and other jurisdictions. Where data is transferred outside the European Economic Area (EEA), such transfers are safeguarded through Standard Contractual Clauses (SCCs) or equivalent GDPR-approved mechanisms.
Squarespace privacy policy: https://www.squarespace.com/privacy
2.2 Cookies and tracking
This website uses cookies provided by Squarespace and third parties.
In compliance with EU ePrivacy rules (as implemented in Dutch law), non-essential cookies are only activated after explicit user consent via the cookie banner.
Cookies may include:
Essential cookies (required for website functionality)
Analytics cookies (to understand website usage)
Functional cookies (to improve user experience)
Users may withdraw consent or change preferences at any time via the cookie settings tool.
3. Purpose and legal basis of processing
3.1 Purposes
Personal data is processed for:
Website operation and security
Communication and dissemination (e.g. newsletters)
Event registration and stakeholder engagement
Analytics and performance improvement
Compliance with Horizon Europe reporting obligations
Legal and financial record keeping
3.2 Legal basis
Processing is based on:
Consent (Article 6(1)(a) GDPR)
Contract necessity (Article 6(1)(b))
Legal obligation (Article 6(1)(c))
Legitimate interest (Article 6(1)(f))
Legitimate interest is applied only after balancing against user rights and documented internally where required.
4. Automated decision-making
No automated decision-making or profiling producing legal or similarly significant effects is carried out.
5. Retention period
Personal data is retained only for as long as necessary:
Contact data: duration of project. Personal data may be retained after the end of the project for communication about related activities, including dissemination of results and information about follow-up or successor projects with similar objectives. Data subjects may be informed and given the opportunity to opt out at any time.
Financial/audit data: up to 7 years (legal requirement)
Cookies: according to retention periods defined in Squarespace settings or user browser controls
Audiovisual content: until consent is withdrawn or no longer relevant
6. Third-party services
In addition to Squarespace, the website may use third-party tools such as:
Email/newsletter services
Analytics tools (e.g. Squarespace Analytics or equivalent GDPR-compliant service)
All third-party processors operate under GDPR-compliant data processing agreements.
7. Links to external websites
The website may contain links to third-party websites. We are not responsible for the privacy practices or content of external websites.
8. Age of consent
The website is not intended for children under 16 years of age unless parental consent is provided in accordance with GDPR Article 8.
9. Data subject rights
Under GDPR, you have the right to:
Access your data
Rectify inaccurate data
Request erasure
Restrict processing
Object to processing
Data portability
Withdraw consent
Requests can be sent to the contact person listed above.
Requests will be handled within one month, extendable by up to two additional months in complex cases (Article 12(3) GDPR).
Identity verification may be required where strictly necessary and in accordance with data minimisation principles.
10. Data security
Appropriate technical and organisational measures are implemented, including:
Secure Squarespace infrastructure
HTTPS encryption
Access control restrictions
Regular security monitoring
Data Processing Agreements with all service providers
11. Data breaches
In case of a personal data breach:
The breach is reported internally without undue delay
The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is notified within 72 hours where required
Affected individuals are informed if there is a high risk to their rights and freedoms
12. Changes to this Privacy Policy
This Privacy Policy may be updated to reflect legal or operational changes.
The latest version will always be published on this website. Continued use of the Service constitutes acceptance of any updates.