Documents · Data
Record of Processing Activities
Art. 30(2) GDPR: what FND processes on behalf of the organizations it serves.
In short
The register a processor must keep, published instead of sent on request.
Six activities, each with its purpose, categories, recipients, transfers and retention.
Your own Art. 30(1) record can copy from this one.
1.Scope
This is FND's record as a processor, kept under Art. 30(2) GDPR on behalf of every partner organization. The organization keeps its own record as controller under Art. 30(1); the rows below are written so they can be copied into it.
2.The register
Activity Purpose Categories of data Retention Account and membership Give a verified participant access to their own organization's world Name, username, optional avatar and interests, organization, verification status, role Until revoked or deleted, then full cascade Activities and meets Show what is happening now and let people join Activity title, time, place, participants, photos With the meet, then with the organization's term Messaging inside a meet Coordinate an activity between the people attending it Message text, author, timestamp With the meet Presence Show who is at a zone, and revoke access when someone leaves Zone check-in events (place, time) 30 days Safety and moderation Review reports, restrict repeat offenders, reconstruct an incident Reports, moderation actions, incident log, audit trail 30 days rolling Billing and support Sell a pass, issue a receipt, answer the buyer Director's name, organization, email, payment metadata 7 years for invoices, 24 months for enquiries Recipients: the sub-processors at /subprocessors, and nobody else. No profiling, no automated decision-making with legal effect, no special-category data under Art. 9 is requested by the service.
3.Security measures
The general description required by Art. 30(2)(d) is published in full at /security: row-level isolation per organization, TLS and encryption at rest, multi-factor access to production, tested daily backups, and data minimisation as the primary control.
4.Transfers
Participant data stays in the European Union. Payment and transactional email involve providers with United States operations under Standard Contractual Clauses, and neither receives participant data. The assessment behind that is at /transfers.
5.Contact
Questions about this record go to privacy@findndo.app and are answered within two business days. FND is not required to appoint a data protection officer under Art. 37; the operator answers directly.
Change log
v1.024 July 2026
- First published version.
Issued by
FND (Find 'n Do)
Belgium
Supervisory authority
Gegevensbeschermingsautoriteit / Autorité de protection des données
Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.
Write to us