1. Scope
This GDPR Data Protection Notice supplements the Privacy Policy for individuals whose personal data is protected by the EU General Data Protection Regulation (“GDPR”) or substantially similar European data protection law.
2. Controller
For processing described in this notice where EO New Jersey determines the purposes and means of processing, the controller is New Jersey Young Entrepreneur’s Organization, Inc., d/b/a EO New Jersey. Privacy requests may be submitted through the EO New Jersey Contact Chapter page.
EO Global and WhatsApp/Meta may separately process personal data under their own privacy notices and agreements.
3. Personal Data and Sources
We may process your WhatsApp mobile number and messages, EO membership information used for access verification, event and attendee information available through EO Global, registration requests and confirmations, and limited security or diagnostic data. Data is obtained from you, WhatsApp/Meta, and EO Global systems.
4. Purposes and Lawful Bases
We process personal data only when a lawful basis applies, including:
- Membership/service performance: to authenticate you, answer event requests, and process registrations you request;
- Legitimate interests: to provide a secure and efficient member service, prevent unauthorized access, maintain event operations, and protect EO confidential information, provided those interests are not overridden by your rights;
- Legal obligations: when processing is required to comply with applicable law; and
- Consent: where we expressly ask for consent for a specific optional use.
5. Recipients
Personal data may be disclosed as necessary to EO Global, WhatsApp/Meta, authorized EO New Jersey administrators or volunteers, technical service providers, and authorities where disclosure is legally required.
6. International Transfers
Personal data may be processed outside the European Economic Area, including in the United States. Where GDPR requires a transfer safeguard, EO New Jersey will rely on an applicable lawful transfer mechanism, which may include an adequacy decision, Standard Contractual Clauses, or another mechanism permitted by law.
7. Retention
We keep personal data only as long as necessary for the purposes described above, including service operation, security, registration records, legal compliance, dispute resolution, and enforcement of EO rules. Data held in EO Global systems is subject to EO Global’s retention practices.
8. Your GDPR Rights
Subject to the conditions and exceptions in applicable law, you may have the right to:
- access your personal data;
- correct inaccurate or incomplete personal data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data where the right applies; and
- withdraw consent at any time where processing is based on consent.
You also have the right to lodge a complaint with the data protection supervisory authority in the country where you live, work, or believe a violation occurred.
9. Automated Access Decision
The Service automatically compares the WhatsApp mobile number used to contact the Service with EO Global records to determine whether access should be granted. This access-control function is not intended to make decisions producing legal or similarly significant effects. If you believe the result is incorrect, contact EO New Jersey for review.
10. Data Minimization and Security
We limit processing to information reasonably necessary for the Service and use appropriate technical and organizational measures to protect it against unauthorized access, disclosure, alteration, or loss.
11. Contact
To exercise a GDPR right or ask a data protection question, use the EO New Jersey Contact Chapter page and identify the request as a privacy or GDPR request.