PRIVACY POLICY — EU Money Monitor / NGO Risk Dashboard
Last updated: 29.03.2026
Controller: NGO Risk Dashboard – NEXT COMMUNITY SRL (the “Controller”, “we”, “us”, “our”)
Contact (privacy): watch@brussels-leaks.eu
Registered address: TOPOS MERODE – Rue Abbe Cuypers 3, 1040 Brussels, BELGIUM
Supervisory authority: Belgian Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Bruxelles — contact: https://www.autoriteprotectiondonnees.be/
1. Scope and who we are
This Privacy Policy explains how we process personal data when you visit brussels-leaks.eu and its sub-pages, use the NGO Transparency Dashboard subscription service, purchase the Belgium NGO Funding Intelligence Pack, subscribe to our newsletter, or correspond with us.
We operate from Belgium and are subject to the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), the Belgian Act of 30 July 2018 on the protection of natural persons with regard to the processing of personal data, and applicable sectoral transparency rules governing NGO governance disclosure.
We are the data controller for all processing described in this Policy.
2. What we publish and why
We build organisation-level profiles using only official public sources, currently they are:
- Belgian Official Gazette / Moniteur Belge (governance filings, mandate records)
- National Bank of Belgium (NBB) annual accounts
- Belgian Crossroads Bank for Enterprises (CBE)
- National Social Security Office (ONSS) employer registry
- EU Financial Transparency System (EU FTS)
- EC Transparency Register and equivalent public sources
From those records we extract minimal personal data relating to NGO office-holders and governance — typically name, role, and mandate dates. We do not publish contact details, financial information about individuals, or special-category data.
We also compile organisation-level analytical indicators — transparency scores, HR cost splits, parallel grant loads — derived from official accounts and grant data. These indicators do not profile natural persons and do not allege wrongdoing.
3. Legal bases for publishing public-source governance data
We process and publish the personal data of NGO governance office-holders on the following legal bases:
Legitimate interests (GDPR Art. 6(1)(f)): pursuing transparency, public accountability, and oversight of organisations receiving public funds. Office-holders of publicly funded organisations reasonably expect that information the law already requires to be public will be compiled and analysed for public-interest purposes. We have conducted and maintain an internal Legitimate Interests Assessment documenting necessity, proportionality, and safeguards.
Freedom of expression and information / journalistic and research purposes (GDPR Art. 85 and Belgian Act of 30 July 2018): our compilation, analysis, and commentary constitute public-interest journalism and research enabling oversight, scrutiny, and informed public debate. Where applicable, Article 85 derogations from certain GDPR obligations apply insofar as necessary to protect journalistic and research freedom.
Compatibility with original publication purposes: the governance data exists because Belgian associations law and EU public-fund transparency rules require it to be publicly filed. Our reuse is compatible with those purposes under GDPR Art. 6(4).
4. Personal data we collect from you
4.1 Dashboard subscribers (MemberPress)
When you register for a Dashboard subscription, we process: name, email address, hashed password, organisation or employer, professional role, billing address, country, chosen subscription plan, subscription status, and invoice records. Legal basis: contract performance (GDPR Art. 6(1)(b)) and legal obligation for accounting records (Art. 6(1)(c)).
4.2 Intelligence Pack purchasers (Stan Store)
When you purchase the Intelligence Pack through Stan Store, we receive confirmation of purchase, your name, email address, and any optional information you provide at checkout such as your organisation and intended use. We use this information to confirm delivery, manage the licence, and understand our user base. Legal basis: contract performance (Art. 6(1)(b)).
Payment card data is processed exclusively by Stan Store and STRIPE. We do not receive or store full card numbers, CVC codes, or equivalent payment credentials.
4.3 Newsletter subscribers (Kit)
When you subscribe to the Brussels on paper newsletter, we process your email address and, where provided, your first name. Legal basis: consent (GDPR Art. 6(1)(a)). You may unsubscribe at any time.
4.4 Correspondence
When you contact us by email, we process the content of your message and your contact details to respond and maintain records of corrections, editorial decisions, and rights requests. Legal basis: legitimate interests (Art. 6(1)(f)).
4.5 Security and usage data
We process server logs, IP addresses, timestamps, and device and browser information to secure the platform, prevent abuse, and diagnose technical issues. Legal basis: legitimate interests (Art. 6(1)(f)).
4.6 Cookies
Strictly necessary cookies are used for login sessions, member access control, and security. No consent is required for strictly necessary cookies. Analytics or preference cookies are used only with your explicit consent via our cookie banner. We do not use cookies for targeted advertising.
5. Public-source governance data — Art. 14 GDPR notice
For NGO governance records published in our profiles, we process: name, function, mandate start and end dates, and a reference to the official source document. The source and extraction date are displayed on each profile.
Because contacting every office-holder individually would involve disproportionate effort and would undermine the journalistic and transparency purpose of the platform, we provide this notice publicly in accordance with GDPR Art. 14(5)(b) and Art. 85. Individuals may exercise their rights as described in Section 8.
6. How we use personal data
We use personal data to:
- Compile and publish NGO profiles from official public records including governance names and mandate metadata.
- Provide Dashboard member features including authentication, access control, account management, invoicing, and transactional email.
- Deliver purchased Intelligence Pack products and confirm licence terms.
- Send the Brussels on paper newsletter to confirmed subscribers.
- Maintain platform security, prevent fraud, and keep reliable access and security logs.
- Handle correction requests, right of reply submissions, and data subject rights requests.
- Produce anonymised and aggregate usage statistics to improve our services.
- Comply with legal obligations including tax, accounting, and retention requirements.
- Respond to lawful requests from competent authorities.
We do not use personal data for automated decision-making producing legal or similarly significant effects on individuals. We do not sell personal data. We do not use personal data for targeted advertising.
7. Data minimisation and accuracy
We publish the minimum personal data necessary for governance transparency purposes. Where official records are updated, we update our profiles in good faith when we become aware of the change. Individuals and organisations may request corrections at any time by providing a link or copy of the relevant official record at watch@brussels-leaks.eu.
8. Your rights
Under GDPR, you have the following rights:
Access (Art. 15): the right to obtain confirmation of whether we process your personal data and, if so, a copy.
Rectification (Art. 16): the right to correct inaccurate personal data. For public-source governance data, we verify corrections against the named official record before updating.
Erasure (Art. 17): the right to request deletion. For public-source governance data, we assess erasure requests against our journalistic and transparency mandate and the fact that the data remains in official public registers. In most cases rectification or annotation is more appropriate than erasure. We will explain our reasoning.
Restriction (Art. 18): the right to request restriction of processing in certain circumstances.
Portability (Art. 20): the right to receive personal data you provided to us in a structured, machine-readable format where processing is based on contract or consent and carried out by automated means. This applies primarily to your member account data.
Objection (Art. 21): the right to object to processing based on legitimate interests, including the publication of public-source governance names. We will assess your objection and either cease processing, explain compelling grounds that override your interests, or limit processing as appropriate.
Withdraw consent: where we rely on consent — for analytics cookies or newsletter subscriptions — you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any right, contact watch@brussels-leaks.eu. We will respond within one month, extendable by two months for complex requests with notice to you. You also have the right to lodge a complaint with the APD/GBA at any time.
9. Retention periods
Public-source NGO profiles: retained as a public-interest archive and updated when official records change. We do not routinely delete profiles because the underlying official records remain public.
Member account data: retained while your account is active. Following account closure, core accounting and invoice records are retained for ten years to meet Belgian legal obligations. Other account data is deleted or anonymised within twelve months of closure.
Intelligence Pack purchaser data: name, email, purchase record, and delivery confirmation retained for ten years for accounting and licence management purposes.
Newsletter subscriber data: retained until you unsubscribe. Following unsubscription, data is deleted within thirty days.
Server logs and security events: up to six months unless required for an ongoing security incident or legal matter.
Correspondence: normally retained for twenty-four months following closure of the matter.
Cookie consent records: twelve months or as required by applicable law.
10. Recipients and processors
We share personal data only as necessary and under contracts meeting GDPR Art. 28 requirements. Recipients include:
MemberPress: subscription management and access control for the Dashboard.
Stan Store: sales, payment processing, and digital delivery for the Intelligence Pack. Stan operates as both processor and independent controller for payment data under its own privacy policy.
Kit (formerly ConvertKit): newsletter and subscriber management for the Brussels on paper newsletter. Processes subscriber email addresses and engagement data under a data processing agreement.
Hosting and infrastructure providers: website hosting, databases, backups, and security services located primarily within the EEA.
Email delivery providers: for transactional emails relating to subscriptions, password resets, and invoices.
Professional advisers: legal and accounting advisers under confidentiality obligations.
Competent authorities: where required by law.
We do not permit processors to use your personal data for their own purposes beyond the service they provide to us.
11. International transfers
Our primary hosting infrastructure is located within the EEA. Where service providers are located outside the EEA, we rely on a valid transfer mechanism under GDPR Chapter V, including European Commission adequacy decisions or Standard Contractual Clauses with supplementary safeguards where required.
12. Cookies
Strictly necessary cookies are used for authentication, session management, member access control, and security. No consent is required.
Analytics and preference cookies are used only where you have provided explicit consent through our cookie banner. You may withdraw consent at any time through the banner or your browser settings.
We do not use cookies for behavioural advertising or cross-site tracking. Where we embed third-party content that may place its own cookies, we block such embeds until you have provided consent where required.
13. Security
We apply appropriate technical and organisational measures under GDPR Art. 32, including TLS encryption in transit, access controls and role-based permissions, hashed password storage, regular patching and backups, activity logging and abuse monitoring, and vendor due diligence with data processing agreements. In the event of a personal data breach, we will notify the APD/GBA and, where required, affected individuals within the legally required timeframes.
14. Children
Our services are intended for adults and professionals. We do not knowingly collect personal data from persons under 16 years of age and require users to be 18 or older to enter into contracts. If you believe a minor has created an account, contact us immediately at watch@brussels-leaks.eu.
15. Links to third-party sites
Our profiles link to official registries and third-party platforms. We are not responsible for their content, availability, or privacy practices. Please review their policies before providing personal data to those sites.
16. Changes to this Policy
We may update this Policy to reflect legal, technical, or business developments. We will publish the updated version with a new effective date. For material changes affecting paid subscribers or the processing of personal data, we will notify affected users by email with reasonable advance notice.
17. Contact
For all privacy, data protection, and rights requests: watch@brussels-leaks.eu NGO Risk Dashboard – NEXT COMMUNITY SRL TOPOS MERODE – Rue Abbé Cuypers 3, 1040 Brussels, Belgium
For complaints: Belgian Data Protection Authority (APD/GBA), Rue de la Presse 35, 1000 Brussels — https://www.autoriteprotectiondonnees.be/
Annex A — Summary of legal bases
| Purpose | Data categories | Legal basis |
|---|---|---|
| Publish NGO governance data from official public registers | Name, role, mandate dates | Legitimate interests (Art. 6(1)(f)); freedom of expression and journalistic purposes (Art. 85) |
| Compute organisation-level transparency indicators | Organisation-level financial and grant data only | Not applicable to individuals |
| Dashboard subscription management | Account details, plan, invoices | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Intelligence Pack purchase and licence | Name, email, purchase record | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Payment processing | Payment identifiers (card data held by Stan) | Contract; legal obligation; legitimate interests |
| Platform security | IP addresses, timestamps, device data | Legitimate interests (Art. 6(1)(f)) |
| Correspondence and rights requests | Contact details, message content | Legitimate interests (Art. 6(1)(f)) |
| Newsletter (Kit) | Email address, first name | Consent (Art. 6(1)(a)) |
| Analytics cookies | Pseudonymous usage data | Consent (Art. 6(1)(a)) |
Annex B — How to exercise your rights
Email watch@brussels-leaks.eu and state clearly which right you wish to exercise. For governance data corrections, attach or link the relevant official record. We may ask for limited identity verification. We respond within one month, extendable to three months for complex requests. If we decline a request — for example because Art. 85 journalistic exemptions apply or because the data remains lawfully public in official registries — we will explain our reasoning and your right to complain to the APD/GBA.