FNDRecord of Processing Activities

Documents · Data

Record of Processing Activities

Art. 30(2) GDPR: what FND processes on behalf of the organizations it serves.

Version
v1.0
In force since
24 July 2026
Last updated
24 July 2026
Contents
5 · 4 min read

In short

The register a processor must keep, published instead of sent on request.

Six activities, each with its purpose, categories, recipients, transfers and retention.

Your own Art. 30(1) record can copy from this one.

  1. 1.Scope

    This is FND's record as a processor, kept under Art. 30(2) GDPR on behalf of every partner organization. The organization keeps its own record as controller under Art. 30(1); the rows below are written so they can be copied into it.

  2. 2.The register

    ActivityPurposeCategories of dataRetention
    Account and membershipGive a verified participant access to their own organization's worldName, username, optional avatar and interests, organization, verification status, roleUntil revoked or deleted, then full cascade
    Activities and meetsShow what is happening now and let people joinActivity title, time, place, participants, photosWith the meet, then with the organization's term
    Messaging inside a meetCoordinate an activity between the people attending itMessage text, author, timestampWith the meet
    PresenceShow who is at a zone, and revoke access when someone leavesZone check-in events (place, time)30 days
    Safety and moderationReview reports, restrict repeat offenders, reconstruct an incidentReports, moderation actions, incident log, audit trail30 days rolling
    Billing and supportSell a pass, issue a receipt, answer the buyerDirector's name, organization, email, payment metadata7 years for invoices, 24 months for enquiries

    Recipients: the sub-processors at /subprocessors, and nobody else. No profiling, no automated decision-making with legal effect, no special-category data under Art. 9 is requested by the service.

  3. 3.Security measures

    The general description required by Art. 30(2)(d) is published in full at /security: row-level isolation per organization, TLS and encryption at rest, multi-factor access to production, tested daily backups, and data minimisation as the primary control.

  4. 4.Transfers

    Participant data stays in the European Union. Payment and transactional email involve providers with United States operations under Standard Contractual Clauses, and neither receives participant data. The assessment behind that is at /transfers.

  5. 5.Contact

    Questions about this record go to privacy@findndo.app and are answered within two business days. FND is not required to appoint a data protection officer under Art. 37; the operator answers directly.

Change log

  1. v1.024 July 2026

    • First published version.

Issued by

FND (Find 'n Do)

Belgium

Supervisory authority

Gegevensbeschermingsautoriteit / Autorité de protection des données

www.gegevensbeschermingsautoriteit.be

Need a countersigned copy, a filled-in vendor questionnaire, or a clause explained? One email, one business day.

Write to us