Skip to main content
Download Privacy Policy

Privacy Policy – Join for Joy 

At Join for Joy, protecting the privacy of donors, educators, children, partners, and staff is our top priority. As a recognized ANBI charitable organization (per the Dutch Tax Authorities), we adhere to high standards of transparency and maintain compliance with the GDPR across all our operations, both in the Netherlands and internationally.

1. ANBI Recognition

We hold ANBI status, which reflects our commitment to serving the public interest and conducting ourselves with transparency. This includes open and accurate financial reporting and responsible data handling to strengthen donor trust and accountability.

2. Anonymity of Donors

  • Donors who wish to remain anonymous are registered under a code name in our system, so they cannot be directly identified. 
  • These preferences are clearly marked in our internal systems and are respected in reporting and communications.

3. Security of Data and Devices

  • Passwords: All staff must update their Join for Joy email and laptop passwords at the start of each year. Automatic reminders are issued via JAMF. 
  • Company laptops and phones: Staff sign an agreement when receiving devices. Devices are managed via JAMF, including updates to serial numbers when exchanged or returned. 
  • Google Drive access: Access is restricted to Join for Joy email accounts and only to folders relevant to each role. 
  • Document ownership: Before removing a user from Google Workspace, all files must be transferred to the correct owner to avoid data loss. Google Vault provides backups if needed. 

4. Use of Photos and Videos

  • Schools sign an MOU at the start of the program that covers the use of photos and videos of teachers and children for reporting and fundraising. 
  • Schools are responsible for informing parents and ensuring that children whose parents object are not photographed or filmed.

5. Data Retention and Archiving

  • Financial data: kept for 7 years (as required by law). 
  • Employee data: kept for a maximum of 3 years after leaving the organization. 
  • Other data: deleted after 5 years, unless there is a legal or operational reason to keep it longer. 
  • Annual clean-up: Our Google Drive is cleaned once a year to reduce the risk of data breaches. 
  • Physical financial data: Credit card and bank details must always be securely stored and never left unattended.

6. Privacy in Country Offices

  • All Join for Joy country offices apply the same privacy rules. 
  • Local teams are responsible for staying up to date with national privacy laws in addition to GDPR.

7. Key GDPR Principles

When handling personal data, we always apply the following principles:

  • Lawfulness, fairness & transparency 
  • Data minimization 
  • Accuracy 
  • Storage limitation 
  • Integrity and confidentiality 
  • Accountability

8. Sensitive Data

Certain categories of personal data require extra care. Join for Joy only processes these when absolutely necessary and under strict conditions:

  • Medical information 
  • Religious beliefs 
  • Union membership 
  • Sexual orientation 
  • Biometric data (e.g., fingerprints, facial recognition) 
  • Political opinions 
  • Sexual behavior or life 
  • Genetic data

9. Do No Harm Principle

Join for Joy integrates the Do No Harm principle into all our privacy and safeguarding protocols. This means we always aim to protect the privacy, dignity, and safety of children, teachers, donors, and partners, and we avoid any actions that could put individuals at risk through the processing or sharing of their data.

Conclusion

By following these policies, Join for Joy protects the privacy of everyone we work with, strengthens our GDPR compliance, and minimizes the risk of data breaches. Privacy and data security remain a shared responsibility within our team and are supported by training, clear protocols, and annual reviews.