Privacy Policy
How Mohanji Connect handles your personal data (GDPR)
Last updated: August 2026
1. Who We Are
Mohanji Connect is the global member platform of the Mohanji Foundation. This policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).
Data controller: Mohanji Hrvatska, Komparija 5, Goričan, Croatia, OIB 91033534456. For any privacy request, contact us at connect@mohanji.hr.
2. What Data We Collect
- Profile data: name, date of birth, address, phone number, e-mail, T-shirt size, language preferences, dietary restrictions and special requirements.
- Event data: registrations, attendance history, payment records and invoices.
- Donation data: the amount, date, payment method and — if you supply it — the postal address that appears on your donation receipt, plus any message you send with a donation. You can donate without an account; in that case we hold only what you enter on the donation form. Monthly donations additionally record that a standing order exists and when each payment was taken.
- Volunteer data: team memberships, roles, skills, tasks, availability and engagement history.
- Technical data: login timestamps and session information needed to keep your account secure.
3. Why We Process Your Data
- To manage your membership account and event registrations (performance of contract).
- To process payments and issue invoices (legal obligation).
- To process donations and issue donation receipts, and to keep the accounting records the receiving entity is required to keep (legal obligation). Donor names are never published: campaign pages show only the total raised and the number of donations.
- To organize volunteer work and programmes (legitimate interest / consent).
- To send you information about events you registered for (performance of contract).
4. Who Can See Your Data
Access inside the platform is role- and scope-based:
- You see and manage your own profile.
- Team leaders and coordinators see contact details (including address and phone number) of volunteers within their own team, country or region only.
- Finance roles see payment records and donations for their own country or region only.
- Global management has administrative access to the full database.
Restricted documents (e.g. SOPs) are visible only to members holding the required role and level.
5. Data Processors
We use the following processors. Each is bound by a data processing agreement that forms part of the terms we accepted with them:
- Stripe — card payments and monthly donations (we never store full card numbers; a monthly donation is held as a standing order at Stripe).
- Payrexx — card payments in some countries (Switzerland; we never store full card numbers).
- Google — sign-in (OAuth) and maps.
- Resend — e-mail delivery.
- Neon — database hosting (EU, Frankfurt).
- Render — application hosting (EU, Frankfurt).
- Sentry — error monitoring (EU region, Frankfurt). When something breaks, a technical report of the failure is sent so we can fix it. We have disabled session recording and we strip e-mail addresses from these reports; they identify you only by your internal account ID.
PayPal is different. When you pay through PayPal, PayPal is not acting as our processor but as an independent controller of your payment data: it also processes that data for its own purposes, under its own privacy policy. What you share with PayPal during a payment is therefore governed by PayPal's terms, not only by this policy.
6. Transfers Outside the EEA
Our database and the application itself run in the EU (Frankfurt). The companies behind the services above are based in the United States, however, so your data may be accessed or transferred there. Each transfer relies on a safeguard recognised under GDPR Chapter V:
- Stripe — EU Standard Contractual Clauses, through its Data Transfers Addendum. Accounts in the EEA contract with Stripe Payments Europe Ltd. in Ireland.
- Google — EU Standard Contractual Clauses in the Cloud Data Processing Addendum; Google LLC is additionally certified under the EU-US Data Privacy Framework.
- Resend — certified under the EU-US Data Privacy Framework.
- Neon — EU-US Data Privacy Framework.
- Render — EU Standard Contractual Clauses, incorporated into its Data Processing Addendum.
- Sentry — EU Standard Contractual Clauses, incorporated into its Data Processing Addendum. Our data is stored in Sentry's EU region.
- Payrexx — based in Switzerland, which the European Commission recognises as providing an adequate level of data protection, so no additional safeguard is required for this transfer.
- PayPal — as an independent controller, PayPal transfers data under its own safeguards, described in its privacy policy.
7. How Long We Keep Data
- Profile data — while your account is active.
- Payment and invoice records — 11 years, as required by the Croatian Accounting Act. The period starts at the end of the business year the records belong to.
- Donation records and receipts — the same 11 years, and for the same reason: a donation receipt is an accounting document of the receiving entity. This applies whether or not you have an account with us.
- Volunteer records — while you are an active member, unless you request erasure.
Links we e-mail you for a donation or a guest event registration are signed and expire after 90 days. They exist so that someone without an account can reach their own receipt, payment details or monthly donation; after they expire, please contact us instead.
Deleting your account
You can delete your account yourself from your Profile, or by writing to us. Deletion starts a 7-day waiting period: until it passes you can cancel simply by signing in again. After that the deletion is carried out automatically and cannot be undone.
What is removed, and what is deliberately kept:
- Removed: your name, e-mail, date of birth, address, phone number, profile photo, password, dietary restrictions, special requirements, languages, T-shirt size, availability and privacy settings.
- Deleted outright: your role, team and vertical assignments, volunteer profile and notifications. These are removed entirely rather than just marked inactive.
- Kept: your country and the dates the account was created and deleted, because scope and statistics rely on them. These do not identify you on their own.
- Messages you posted in community channels remain, shown to other members as “Deleted user”, so that conversations others took part in stay readable. Global management can still see the name behind them, so that a report about harassment can still be investigated after the account is gone.
- Paid and refunded registrations, and the invoices belonging to them, keep the details printed on them, because accounting law requires it (GDPR Art. 17(3)(b)). Registrations that were never paid are cleared along with the rest.
- If your account was suspended, the record of that suspension and its reason is kept. It documents a decision the organisation made, and is retained on the basis of establishing or defending legal claims (GDPR Art. 17(3)(e)).
Because your name is kept for the two purposes above, the result is pseudonymisation rather than full anonymisation. We say so plainly rather than claim the data is gone entirely.
The retained name, and any record of a suspension, are erased five years after the account is deleted. Five years is the general limitation period for claims under Croatian law, and defending such a claim is the only reason these records still exist.
8. Children
Under Croatian law a person under 16 cannot consent on their own to a service like this one. A child may have an account here, but it must be opened by a parent or guardian, who consents on the child's behalf and stays responsible for it. If you believe an account was created for a child without that consent, write to us and we will remove it.
9. Your Rights
Under GDPR you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate data (you can edit most data in your Profile).
- Erasure — request deletion of your account and data.
- Restriction & objection — limit or object to certain processing.
- Portability — receive your data in a machine-readable format.
- Complaint — lodge a complaint with your local supervisory authority. In Croatia this is the Personal Data Protection Agency (AZOP).
To exercise any of these rights, write to connect@mohanji.hr. We respond within 30 days.