01
WHO IS RESPONSIBLE FOR YOUR DATA
The World Roma Israel Mandate is the controller of your personal data. If you have any question about this policy or about how we handle your data, write to us at info@worldromaisrael.org and we will answer you.
WORLD ROMA ISRAEL MANDATE
Last updated: 21 September 2026
How we collect, use, protect and keep your personal data — in full transparency, under the General Data Protection Regulation (GDPR).
01
The World Roma Israel Mandate is the controller of your personal data. If you have any question about this policy or about how we handle your data, write to us at info@worldromaisrael.org and we will answer you.
02
We collect only what the movement needs to function, and nothing more:
03
We process your data only where we have a lawful basis under the GDPR:
04
The Register is never public. Nobody can browse members, and there is no public member directory. Your identity selections, your description and your community note are visible only to you and to the administrators who safeguard the Register. The single, deliberate exception is the public supporters wall — and only for people who tick the opt-in box in step 03 of the registration, and only ever as a first name, a surname initial and a country.
05
Account data is kept while your account exists. Register data is kept while your registration is active; if you withdraw, the registration is marked withdrawn and its details are no longer shown, while a minimal record of the withdrawal is retained so your choice is respected. Contact messages are kept until your request is handled. Consent and audit records are kept so that we can always demonstrate what you agreed to and when.
06
Under the GDPR you have the right to:
07
Most things you can do yourself in the member area: update your profile, update your registration, or withdraw from the Register. For anything else — including full account deletion — write to info@worldromaisrael.org. If you believe your rights have been violated, you may lodge a complaint with your national data-protection authority; in the Czech Republic that is the Office for Personal Data Protection (ÚOOÚ).
08
Your data is stored in a secure hosted database protected by row-level security, which means every record is locked to your account, and administrators can reach member data only through strictly controlled, role-based access. Passwords are stored only as cryptographic hashes. Data is transmitted exclusively over encrypted connections. Access by administrators is limited to what is necessary to operate the Register, and every sensitive action is recorded in the audit log.
09
Only you, and the small circle of administrators who operate the Register. We do not sell your data, we do not share it with advertisers, and we do not pass it to third parties for their own marketing. Our hosting and e-mail providers process data only on our instructions, under contract, to keep the service running.
10
We use only the cookies and local storage that are strictly necessary: keeping you signed in, remembering your chosen language, and basic security protection. We use no advertising cookies and no third-party tracking.
11
The movement is intended for adults. We do not knowingly collect data from children under 16. If you believe a child has given us data, contact us and we will remove it.
12
If this policy changes, we will record a new version and, where the change affects your rights, ask for your consent again where required. Your consent records always show which version you accepted and when.
Joining the Register is voluntary, and every part of it — including whether your name appears publicly — is your choice.
JOIN THE REGISTER