Privacy
Hoe we omgaan met je gegevens
At Join for Joy, protecting the privacy of donors, educators, children, partners, and staff is our top priority. As a recognized ANBI charitable organization, we adhere to high standards of transparency and maintain compliance with the GDPR across all our operations, both in the Netherlands and internationally.
1. ANBI Recognition
We hold ANBI status, which reflects our commitment to serving the public interest and conducting ourselves with transparency. This includes open and accurate financial reporting and responsible data handling to strengthen donor trust and accountability.
2. Anonymity of Donors
Donors who wish to remain anonymous are registered under a code name in our system, so they cannot be directly identified.
These preferences are clearly marked in our internal systems and are respected in reporting and communications.
3. Security of Data and Devices
Passwords: all staff must update their Join for Joy email and laptop passwords at the start of each year. Automatic reminders are issued via JAMF.
Company laptops and phones: staff sign an agreement when receiving devices. Devices are managed via JAMF, including updates to serial numbers when exchanged or returned.
Google Drive access: access is restricted to Join for Joy email accounts and only to folders relevant to each role.
Document ownership: before removing a user from Google Workspace, all files must be transferred to the correct owner to avoid data loss. Google Vault provides backups if needed.
4. Use of Photos and Videos
Schools sign an MOU at the start of the program that covers the use of photos and videos of teachers and children for reporting and fundraising.
Schools are responsible for informing parents and ensuring that children whose parents object are not photographed or filmed.
5. Data Retention and Archiving
Financial data: kept for 7 years, as required by law.
Employee data: kept for a maximum of 3 years after leaving the organization.
Other data: deleted after 5 years, unless there is a legal or operational reason to keep it longer.
Annual clean-up: our Google Drive is cleaned once a year to reduce the risk of data breaches.
Physical financial data: credit card and bank details must always be securely stored and never left unattended.
6. Privacy in Country Offices
All Join for Joy country offices apply the same privacy rules.
Local teams are responsible for staying up to date with national privacy laws in addition to GDPR.
7. Key GDPR Principles
When handling personal data, we always apply the following principles: lawfulness, fairness and transparency; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability.
8. Sensitive Data
Certain categories of personal data require extra care. Join for Joy only processes these when absolutely necessary and under strict conditions: medical information, religious beliefs, union membership, sexual orientation, biometric data such as fingerprints and facial recognition, political opinions, sexual behavior or life, and genetic data.
9. Do No Harm Principle
Join for Joy integrates the Do No Harm principle into all our privacy and safeguarding protocols. This means we always aim to protect the privacy, dignity, and safety of children, teachers, donors, and partners, and we avoid any actions that could put individuals at risk through the processing or sharing of their data.
Conclusion
By following these policies, Join for Joy protects the privacy of everyone we work with, strengthens our GDPR compliance, and minimizes the risk of data breaches. Privacy and data security remain a shared responsibility within our team and are supported by training, clear protocols, and annual reviews.