Mohanji Connect

Privacy Policy

How Mohanji Connect handles your personal data (GDPR)

Last updated: August 2026

1. Who We Are

Mohanji Connect is the global member platform of the Mohanji Foundation. This policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).

Data controller: Mohanji Hrvatska, Komparija 5, Goričan, Croatia, OIB 91033534456. For any privacy request, contact us at connect@mohanji.hr.

2. What Data We Collect

3. Why We Process Your Data

4. Who Can See Your Data

Access inside the platform is role- and scope-based:

Restricted documents (e.g. SOPs) are visible only to members holding the required role and level.

5. Data Processors

We use the following processors. Each is bound by a data processing agreement that forms part of the terms we accepted with them:

PayPal is different. When you pay through PayPal, PayPal is not acting as our processor but as an independent controller of your payment data: it also processes that data for its own purposes, under its own privacy policy. What you share with PayPal during a payment is therefore governed by PayPal's terms, not only by this policy.

6. Transfers Outside the EEA

Our database and the application itself run in the EU (Frankfurt). The companies behind the services above are based in the United States, however, so your data may be accessed or transferred there. Each transfer relies on a safeguard recognised under GDPR Chapter V:

7. How Long We Keep Data

Links we e-mail you for a donation or a guest event registration are signed and expire after 90 days. They exist so that someone without an account can reach their own receipt, payment details or monthly donation; after they expire, please contact us instead.

Deleting your account

You can delete your account yourself from your Profile, or by writing to us. Deletion starts a 7-day waiting period: until it passes you can cancel simply by signing in again. After that the deletion is carried out automatically and cannot be undone.

What is removed, and what is deliberately kept:

Because your name is kept for the two purposes above, the result is pseudonymisation rather than full anonymisation. We say so plainly rather than claim the data is gone entirely.

The retained name, and any record of a suspension, are erased five years after the account is deleted. Five years is the general limitation period for claims under Croatian law, and defending such a claim is the only reason these records still exist.

8. Children

Under Croatian law a person under 16 cannot consent on their own to a service like this one. A child may have an account here, but it must be opened by a parent or guardian, who consents on the child's behalf and stays responsible for it. If you believe an account was created for a child without that consent, write to us and we will remove it.

9. Your Rights

Under GDPR you have the right to:

To exercise any of these rights, write to connect@mohanji.hr. We respond within 30 days.