Privacy Policy
Version 1.2 — 18 September 2026
1.1 In short (plain-language summary)
Mens Apta Institute (MAI) respects your privacy. This is what you need to know in one paragraph: we collect your personal data only when you contact us, subscribe to our newsletter, invite us to a consortium, apply for our activities, or take part in our research. We use it only for the purposes you gave it to us for. We do not sell it. We do not share it with anyone who does not need it to help us deliver what you asked for. You have the right to see it, correct it, delete it, and complain about how we use it. The rest of this document explains all of that in detail.
1.2 Who we are (the controller)
The controller of your personal data is:
Udruga Mens Apta Institut (international name: Mens Apta Institute, short: MAI)
Seat: Zagreb, Republic of Croatia
Registered address: Ulica Josipa Roglića 5, 10 000 Zagreb, Republic of Croatia
OIB: 09275190812
Registry number (RNO): will be published upon registration.
Registered under the Croatian Law on Associations (Zakon o udrugama) with the Register of Associations of the Republic of Croatia.
Represented by: the President of the Association.
Contact for all data-protection questions and requests:
Email: privacy@mensapta.org
Postal: Udruga Mens Apta Institut, Ulica Josipa Roglića 5, 10 000 Zagreb, Republika Hrvatska
Please write “Privacy request” (or “Zahtjev — zaštita podataka”) in the subject line.
If MAI appoints a Data Protection Officer, their contact details will be published here.
1.3 What this Policy covers
This Policy explains how MAI processes personal data of:
Visitors to our website mensapta.org.
People who write to us or fill in our contact form.
People who fill in our partnership / consortium enquiry form.
Subscribers to our newsletter.
Participants in our events, workshops, training, supervision, mentorship and other activities.
Participants in our research and evaluation projects (subject to the specific information notice provided at the point of data collection for each study).
Members of the Association, in accordance with our Statute.
Contractors, suppliers, and partner-organisation representatives with whom we correspond.
Applicants for open positions, calls and expressions of interest.
Where a specific processing activity (in particular research) requires additional or different information, we provide a dedicated information notice to the data subjects concerned. That notice takes precedence over this Policy for the processing it describes.
1.4 What personal data we process, why, and on what legal basis
We only process personal data we actually need. The table below lists each category of processing, the data involved, the purpose, the legal basis under Article 6 GDPR (and Article 9 where applicable), and how long we keep it.
A. Website visits (server logs and cookieless analytics)
Data — server logs: IP address (truncated), browser type, device type, operating system, referring URL, pages viewed, timestamps.
Data — analytics (Independent Analytics, self-hosted): a temporary daily visitor hash computed from IP, user-agent, site domain and a daily-rotating salt (the components are discarded and the hash cannot be reversed to identify you), page URL, referrer, browser, operating system, device type, and country/region derived from IP. No cookies are set, no persistent identifiers are stored, no cross-site tracking takes place. Aggregated statistics are retained for one year.
Purpose: to operate and secure the website; to understand aggregate usage and improve content.
Legal basis: Article 6(1)(f) GDPR — legitimate interest in operating a secure and functional website and in understanding aggregate usage of publicly available information (server logs and cookieless analytics). Because our analytics provider does not use cookies or persistent identifiers, and does not process personal data that can be attributed to an identified or identifiable natural person once the daily hash is discarded, the prior-consent requirement of Article 100 of the Croatian Act on Electronic Communications does not apply to this processing.
Retention: server logs up to 12 months; aggregate analytics data retained for the lifetime of the website in aggregated, non-identifying form.
B. Contact form and direct emails
Data: name, email address, organisation (optional), country, subject, message content, any attachments you choose to send.
Purpose: to respond to your enquiry and manage the correspondence that follows.
Legal basis: Article 6(1)(b) GDPR — steps at your request prior to entering a contract, where applicable; Article 6(1)(f) GDPR — legitimate interest in handling correspondence directed to us.
Retention: for as long as needed to handle the enquiry and any resulting relationship, and then for up to 12 months after closure of the enquiry, unless a longer statutory retention applies (contract, funded-project record-keeping, or legal hold).
C. Partnership / consortium enquiry form
Data: your name and role, coordinating organisation, country, programme, call identifier, deadline, envisaged role for MAI, description of the proposal, current consortium composition, optional attachments, contact email.
Purpose: to evaluate the partnership opportunity, to prepare and send a written response, to prepare a letter of intent or scope proposal, and to manage any resulting collaboration or proposal.
Legal basis: Article 6(1)(b) GDPR — steps at your request prior to entering a contract (partnership agreement); Article 6(1)(f) GDPR — legitimate interest in developing partnerships and responding to consortium invitations.
Retention: for the duration of the proposal cycle and any resulting project, and then for the retention period required by the funder (typically five years after final payment for EU-funded projects), or otherwise for up to 36 months after the last contact.
D. Newsletter subscriptions
Data: email address; optionally name and organisation.
Purpose: to send our newsletter (publications, open calls, event announcements).
Legal basis: Article 6(1)(a) GDPR — your explicit consent, given via double opt-in.
Retention: until you unsubscribe or withdraw consent. Unsubscribing takes effect immediately; a technical suppression record (email address only) is retained to ensure we do not accidentally contact you again.
E. Events, workshops, training, supervision and mentorship
Data: name, professional affiliation and role, email address, information relevant to the activity (e.g. area of professional practice), attendance records, and — only where you have provided them — dietary requirements and accessibility needs.
Purpose: registration, delivery, follow-up communication (materials, certificates), quality evaluation and reporting.
Legal basis: Article 6(1)(b) GDPR — performance of the participation contract; Article 6(1)(c) GDPR — compliance with legal obligations (accounting, reporting to funders); Article 6(1)(f) GDPR — legitimate interest in evaluating and reporting on our activities. Special-category data (e.g. health-related dietary or accessibility information) is processed on the basis of Article 9(2)(a) GDPR — your explicit consent.
Retention: as required by the funder or by Croatian accounting law (typically 11 years for accounting records under the Croatian Accounting Act), and otherwise up to 24 months after the activity.
F. Research and evaluation projects
Data: as described in the study-specific information notice provided to each participant. This may include, depending on the study, contact information, professional information, and — where the design requires it — special-category data such as health information.
Purpose: to conduct the specific research or evaluation study.
Legal basis: Article 6(1)(a) GDPR — your explicit consent (default); or, where applicable and specified in the study-specific notice, Article 6(1)(e) GDPR — task carried out in the public interest, in conjunction with Article 89 GDPR safeguards for research. For special-category data: Article 9(2)(a) GDPR — explicit consent; or, where applicable, Article 9(2)(j) GDPR — scientific research subject to appropriate safeguards.
Retention: as specified in the study-specific information notice. Wherever the design permits, data is anonymised at the earliest possible stage.
G. Members of the Association
Data: as required by the Croatian Law on Associations and our Statute — full name, personal identification number (OIB) where required, address, contact details, date of accession, membership category (regular, associated, honorary), and — where the member is a legal person — the equivalent identifying details of the legal person and its representative.
Purpose: to maintain the mandatory register of members and to carry out the internal governance of the Association.
Legal basis: Article 6(1)(c) GDPR — compliance with the legal obligation to maintain a register of members under Article 12 of the Croatian Law on Associations.
Retention: for the duration of membership and for the additional period required by the Law on Associations and by our internal rules.
H. Contractors, suppliers and partner-organisation representatives
Data: name, role, organisation, professional contact details, contract-related correspondence.
Purpose: to negotiate, conclude and perform contracts.
Legal basis: Article 6(1)(b) GDPR — contract performance; Article 6(1)(c) GDPR — compliance with legal obligations (accounting, tax); Article 6(1)(f) GDPR — legitimate interest in managing professional relationships.
Retention: for the duration of the contract and thereafter for the periods required by Croatian accounting and tax law (typically 11 years).
I. Job and expression-of-interest applications
Data: as submitted by you — typically CV, cover letter, references, portfolio.
Purpose: to consider your application for the specific opportunity for which you applied.
Legal basis: Article 6(1)(b) GDPR — steps at your request prior to entering a contract; Article 6(1)(a) GDPR — your consent, where we ask to retain your application for consideration for future opportunities.
Retention: for the duration of the selection process and up to 12 months thereafter for unsuccessful applicants, unless you have consented to a longer retention.
1.5 We do not use your data for automated decision-making
We do not carry out automated individual decision-making, including profiling, within the meaning of Article 22 GDPR.
1.6 We do not sell your data
We do not sell, rent or trade personal data. We do not use your data for advertising to you.
1.7 Recipients and processors
We share personal data only with the following categories of recipients, and only to the extent necessary:
Processors we engage to run our operations, under written data-processing agreements as required by Article 28 GDPR. As of the date of this Policy, this includes:
Website hosting and CDN: [hosting provider name, EU/EEA region].
Email and productivity tools: [provider name].
Newsletter platform: [provider name].
Website analytics: Independent Analytics (self-hosted on the mensapta.org WordPress installation). Independent Analytics is a privacy-friendly, cookieless first-party analytics plugin configured with a daily-rotating IP salt and one-year retention. It does not set cookies, does not store raw IP addresses, does not generate persistent identifiers, and does not track visitors across sites. No personal data is transferred to a third-party analytics provider.
Form processing (if separate from hosting): [provider name].
Accounting and bookkeeping: [provider name].
Public authorities and regulators, where we are required by Croatian or EU law to disclose data (for example, to the tax authority, to the Register of Associations, or to a court order).
Consortium partners and funders, only where you have entered into or applied for a contractual relationship in which the sharing is necessary (for example, for reporting on an EU-funded project). Where this applies, the specific project agreement governs the sharing.
Professional advisers (lawyers, auditors) under duties of confidentiality, where necessary to defend our rights or comply with our obligations.
We do not share personal data with any other third parties without your consent.
1.8 International transfers
Wherever possible, we use processors that store and process data within the European Economic Area (EEA). Where a processor transfers data outside the EEA, we ensure that an appropriate safeguard under Chapter V GDPR is in place — typically an adequacy decision issued by the European Commission or Standard Contractual Clauses. You can request a copy of the safeguard used for a specific transfer by writing to privacy@mensapta.org.
1.9 Security
We apply technical and organisational measures appropriate to the risk, including access controls, encryption in transit (HTTPS), encryption at rest where supported by the processor, restricted access on a need-to-know basis, staff confidentiality obligations, and regular review of our processors’ security posture.
If a personal data breach occurs and is likely to result in a risk to your rights and freedoms, we will notify the Croatian Personal Data Protection Agency (AZOP) within 72 hours in accordance with Article 33 GDPR, and we will inform you directly where required by Article 34 GDPR.
1.10 Your rights
Under the GDPR, you have the following rights in relation to your personal data:
Right of access (Article 15) — to obtain confirmation of whether we process your data and, if so, a copy and information about the processing.
Right to rectification (Article 16) — to have inaccurate data corrected and incomplete data completed.
Right to erasure (Article 17) — to have your data deleted where one of the grounds in Article 17 applies.
Right to restriction of processing (Article 18) — to require us to stop processing your data in certain circumstances while keeping a copy.
Right to data portability (Article 20) — where the processing is based on your consent or on a contract and is carried out by automated means, to receive your data in a structured, commonly used, machine-readable format, or to have it transmitted directly to another controller.
Right to object (Article 21) — to object to processing based on our legitimate interest, including profiling; where you object, we will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
Right to withdraw consent (Article 7(3)) — at any time, where processing is based on your consent, without affecting the lawfulness of processing carried out before withdrawal.
Right not to be subject to automated decision-making (Article 22) — not applicable to us, as we do not carry out such processing.
Right to lodge a complaint with a supervisory authority (Article 77) — in Croatia, with:
Agencija za zaštitu osobnih podataka (AZOP)
Selska cesta 136, 10000 Zagreb, Republika Hrvatska
Email: azop@azop.hr · Website: azop.hr
To exercise any of these rights, please write to privacy@mensapta.org. We will respond within one month of receipt of your request (extendable by two further months for complex requests, in which case we will inform you within the first month). We do not charge for handling requests unless they are manifestly unfounded or excessive.
1.11 Children
Our website and services are directed at adult professionals and institutional audiences. We do not knowingly collect personal data from persons under the age of 16. In line with our Statute, a minor who has reached 14 years of age may become a member of the Association only with the written consent of their legal representative and without voting rights in the bodies of the Association until reaching 18.
1.12 Changes to this Policy
We may update this Policy from time to time to reflect changes in law, in our processing activities or in our processors. The date at the top of this Policy is the version date. Material changes will be announced on the website and, where appropriate, communicated to subscribers.
