UYA GDPR Compliance Policy

Introduction
At Universal Youth Alliance (UYA), we are committed to protecting the privacy and personal data of all individuals, including event participants, partners, employees, and stakeholders. This GDPR Compliance Policy outlines how UYA processes, stores, and protects personal data in accordance with the General Data Protection Regulation (GDPR) (UK) 2018 c. 12.

Scope

This policy applies to:

  • Participants registering for events or conferences organized by UYA.
  • Employees, contractors, and volunteers involved in event management and operations.
  • Partners, sponsors, and vendors supporting UYA events.
  • Visitors and users interacting with UYA through our website or digital platforms.

This policy applies to all personal data collected, processed, or stored by UYA, regardless of location or source.

What Data We Collect

UYA collects and processes the following categories of personal data:

  • Personal Identification Data: Name, address, email, phone number, and passport details.
  • Event-Related Information: Registration details, ticket purchases, session preferences, and event participation data.
  • Financial Data: Payment information for event registrations and ticket sales.
  • Media and Marketing Data: Photographs, videos, and testimonials for promotional purposes.
  • Technical Data: IP addresses, cookies, and browsing activity on UYA’s website.

How We Use Personal Data

UYA processes personal data for the following purposes:

  1. Event Registration and Management: To facilitate event participation, ticket sales, and communication with attendees.
  2. Communication and Marketing: To send event updates, newsletters, and promotional offers with explicit consent.
  3. Payment Processing: To securely process ticket purchases and manage refunds where applicable.
  4. Compliance with Legal Obligations: To comply with applicable laws, including tax regulations and government reporting.
  5. Media Usage: Photographs and videos captured during events may be used for promotional purposes across UYA’s platforms.

Legal Basis for Processing

UYA processes personal data under the following legal bases:

  • Consent: Data subjects explicitly provide consent for specific purposes, such as receiving newsletters or marketing communications.
  • Contractual Necessity: Processing is required to fulfill our contractual obligations (e.g., event registration and participation).
  • Legal Obligation: Compliance with applicable laws and regulations.
  • Legitimate Interest: Data processing necessary for legitimate interests, such as improving event operations and participant engagement.

How We Protect Personal Data

UYA takes appropriate technical and organizational measures to protect personal data from unauthorized access, loss, alteration, or misuse, including:

  • Encryption: Sensitive data is encrypted both in transit and at rest.
  • Access Control: Personal data is accessible only to authorized personnel.
  • Regular Audits: We conduct regular data protection audits and assessments to ensure compliance.
  • Data Retention Policy: Personal data is retained only as long as necessary for the purposes outlined in this policy or as required by law.

Data Subject Rights

Under the GDPR, data subjects have the following rights:

  1. Right to Access: Request access to your personal data held by us.
  2. Right to Rectification: Request corrections to inaccurate or incomplete data.
  3. Right to Erasure: Request the deletion of your personal data, subject to legal requirements.
  4. Right to Restriction of Processing: Request that we restrict the processing of your data under certain circumstances.
  5. Right to Data Portability: Receive your personal data in a structured, commonly used format.
  6. Right to Object: Object to the processing of your data based on legitimate interests or direct marketing.
  7. Right to Withdraw Consent: Withdraw your consent to data processing at any time.

To exercise these rights, please contact us at privacy@universalyouthalliance.org.

Third-Party Sharing and Transfers

UYA may share personal data with third parties under the following circumstances:

  • Event Partners and Vendors: Data may be shared with event venues, sponsors, and vendors to facilitate event operations.
  • Payment Processors: Payment information is securely shared with payment gateways such as Stripe.
  • Legal Obligations: Data may be disclosed to regulatory authorities when required by law.
  • International Transfers: If data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) or equivalent frameworks.

Cookies and Website Tracking

Our website uses cookies and tracking technologies to enhance user experience and analyze website traffic. You can manage your cookie preferences through your browser settings.

Data Breach Notification

In the event of a data breach, UYA will notify affected individuals and relevant authorities within 72 hours of becoming aware of the breach, in accordance with GDPR requirements.

Updates to this Policy

We may update this GDPR Compliance Policy from time to time to reflect changes in legal requirements or business operations. Any updates will be posted on our website, and significant changes will be communicated directly to participants or partners.

Contact Information

For any questions or concerns regarding this policy, please contact us:
Email: privacy@universalyouthalliance.org
Website: https://universalyouthalliance.org

Shopping Basket