Data processing policy
Records of processing, processors, retention periods, transfers outside the EEA and security measures at New European Strategies.
Last updated: 2026-09-14
Principles that bind every activity
- Lawfulness, fairness and transparency - every activity has a named purpose and legal basis before it starts.
- Purpose limitation - data collected to let you into an event does not feed a marketing list without separate consent.
- Minimisation - we do not collect fields just in case. A field we cannot tie to a purpose is removed from the form, not hidden.
- Accuracy - you correct profile data yourself, and we do not overwrite it from external sources without your knowledge.
- Storage limitation - every category has a deadline; after it the data is deleted or irreversibly anonymised.
- Integrity and confidentiality - role-based access, encryption in transit and at rest, isolation of data between platform tenants.
- Accountability - we can demonstrate the above, not merely assert it.
Processing activities - summary of the record
- Running accounts and professional profiles - performance of a contract (Article 6(1)(b) GDPR).
- Subscriptions, orders and settlements - performance of a contract and legal obligation (Article 6(1)(b) and (c) GDPR).
- Newsletter and marketing communications - consent (Article 6(1)(a) GDPR) combined with electronic communications law.
- Community: comments, threads, messages, professional network - performance of a contract and legitimate interest in moderation (Article 6(1)(b) and (f) GDPR).
- Discussion clubs: membership applications, rosters, contributions - performance of a contract and legitimate interest in maintaining a confidential format.
- Events: registration, tickets, access control, badges - performance of a contract; passing a contact to a partner only on the basis of separate consent.
- Security and abuse prevention: logs, rate limiting, abuse detection - legitimate interest (Article 6(1)(f) GDPR).
- Product analytics and audience measurement - consent for non-essential cookies, legitimate interest for aggregate measurement.
- Handling GDPR requests, complaints and content reports - legal obligation and legitimate interest in defending claims.
Categories of data and special care
We do not maintain collections of special categories of data (Article 9 GDPR) or data on criminal convictions and offences (Article 10 GDPR). We do not ask about political opinions, beliefs, health or origin.
A caution about what you publish yourself: describing your professional background or speaking in a discussion may reveal sensitive information. We process such data only because you manifestly made it public yourself (Article 9(2)(e) GDPR) - and you can remove it at any time.
We neither see nor store card details: full payment data is taken directly by the payment provider.
Processors - categories and roles
With every processor we conclude a data processing agreement meeting the requirements of Article 28(3) GDPR. A sub-processor enters the chain only with our authorisation and on the same terms.
- Cloud infrastructure and database - application hosting, data storage, backups.
- Content delivery network and attack protection - traffic handling, abuse filtering, TLS termination.
- Payment provider (Stripe) - taking payments, tax settlement, handling disputes and chargebacks.
- Transactional email and newsletter provider - message delivery and delivery statuses.
- Analytics and audience measurement tools - strictly within the scope of your consent.
- Providers of editorial and support tooling - to the extent necessary to perform the task.
- External advisers (legal, accounting, audit) - as separate controllers or as processors, depending on the nature of the service.
Transfers outside the European Economic Area
We aim to process data inside the European Union. Some providers nevertheless process data outside the EEA - most often in the United States.
- A European Commission adequacy decision - where the provider is covered by a data protection framework recognised as adequate, including the EU-US Data Privacy Framework.
- Standard contractual clauses adopted by Commission Implementing Decision 2021/914 - the default mechanism for other transfers.
- A transfer impact assessment with supplementary measures (encryption, scope minimisation, access control) where the legal mechanism alone is not sufficient.
- On request we identify the mechanism applied to a specific transfer and provide information about the safeguards.
Retention periods
- Account and profile data - for as long as the account exists; after deletion we erase or anonymise it, subject to the exceptions below.
- Accounting and settlement records - for the period required by tax law, counted from the end of the calendar year in which the payment deadline fell.
- Data needed to establish, exercise or defend claims - until the limitation periods under the Civil Code expire.
- Newsletter data - until consent is withdrawn; after unsubscribing we keep only the record of the unsubscribe itself, so that the opt-out is reliably remembered.
- Security logs and abuse detection records - as a rule up to 12 months, unless a specific record is evidence in an ongoing matter.
- Consent records and their history - for the duration of the consent and the limitation period after withdrawal; this is the evidence of accountability.
- Event attendee data - for as long as needed to settle the event and handle complaints; access control records are deleted once settlement closes.
- Public content (comments, threads) - until removed by the author or a moderator; after account deletion it may remain in anonymised form.
Technical and organisational measures
- Encryption in transit, encryption at rest on the infrastructure provider's side, and password storage as hashes only.
- Authorisation enforced at the database level (row-level security), not only in the interface - a bug in a view does not open somebody else's data.
- Strict isolation of data between platform tenants - queries are scoped to the tenant server-side, never by a parameter from the request.
- Staff access on a need-to-know basis, two-factor authentication for administrative accounts, and an audit log of administrative operations.
- Credentials for peripheral devices (event scanners) are narrowly scoped, bound to a single event, expiring and revocable.
- Backups together with restore testing; separation of production and test environments, with no copying of production data into tests.
- Automated quality gates on every code change - covering data access rules, the scope of the personal data export and redaction of data in telemetry.
- A data protection impact assessment (Article 35 GDPR) before launching processing likely to result in a high risk.
Breach procedure
- An internal report reaches the person responsible for data protection immediately on detection; the risk assessment is documented regardless of its outcome.
- Notification of the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33 GDPR).
- Notification of data subjects where the breach is likely to result in a high risk to their rights and freedoms (Article 34 GDPR).
- We keep an internal register of all breaches - including those that are not notifiable, together with the reasoning behind that decision.
Contact and verifying our statements
Questions about a specific processing activity, processor or retention period: office@neweuropeanstrategies.com. If you represent a partner or an institutional client and need a data processing agreement or a security questionnaire, write to us - we have a ready set of documents.
This document describes the state of our processes on the date of last update. We maintain the full record of processing activities (Article 30 GDPR) internally and make it available to the supervisory authority on request; data subjects receive Article 15 information on request.