VELMORYA
Privacy Policy
(GDPR & CCPA compliant)
Last updated: [08/08/2025]
1. Who We Are
Velmorya (“we, us, our”) operates the website https://unitedpublic.wixsite.com/velmorya (“Site”) to share community information and accept crowdfunding support.
2. Information We Collect
Data you provide – name, email, postal address, donation amounts, residency-application details.
Device data – IP address, browser type, referring pages.
Cookies and similar tech – session IDs, preference files, marketing pixels.
3. How We Use Your Information
-
Process donations and issue tax receipts.
-
Send newsletters and campaign updates you opt into (unsubscribe anytime).
-
Improve Site performance through aggregated analytics.
-
Comply with legal requirements, such as anti-money-laundering rules.
4. Legal Bases for Processing (GDPR)
We rely on your consent, performance of a contract, and our legitimate interests in operating and protecting the Site.
5. Sharing and Disclosure
We never sell personal data. We share it only with:
-
Trusted service providers (payment processors, email platforms) under strict data-processing agreements.
-
Regulators or law-enforcement agencies when legally required.
-
Successor entities in the event of a merger or reorganization.
6. International Transfers
Data may be processed in the United States and other countries. Standard Contractual Clauses and comparable safeguards protect transfers from the EU/UK.
7. Data Retention
Donation and application records are kept for seven years (tax and finance) or until you request deletion where allowed.
8. Your Rights
GDPR (EU/UK) residents – access, rectification, erasure, restriction, portability, and objection.
CCPA (California) residents – right to know, delete, correct, and opt out of “sale” or “share.”
To exercise any right, email privacy@velmorya.org. We reply within 30 days and will not retaliate for exercising rights.
9. Cookies & Tracking Choices
A banner requests consent for non-essential cookies. Adjust preferences anytime via Cookie Settings in the footer.
10. Security
We use TLS encryption, ISO-27001 hosting, and least-privilege staff access, but no Internet transmission is entirely secure.
11. Children
We do not knowingly collect data from anyone under 13 (U.S.) or 16 (EU). Contact us to remove any such information.
12. Changes to This Policy
Updates appear here; material changes are also emailed to registered users.