PRIVACY AND PERSONAL DATA PROTECTION POLICY
Last updated: 21 August 2026
Arms Wide Open Association (“Arms Wide Open”, “we”, “us” or “the Association”) respects your privacy and is committed to protecting the personal data of individuals who visit our website, contact us, participate in our programmes, projects, initiatives and events, apply for participation or support, donate to us, work with us or partner with our organisation.
This Privacy Policy explains how we collect, use, store and protect personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), applicable Bulgarian legislation and the principles of lawfulness, fairness and transparency.
1. Data Controller
The controller of your personal data is:
Arms Wide Open Association / Сдружение „Отворени обятия“
Sofia, Bulgaria
Website: www.armswideopen.eu
E-mail: info@armswideopen.bg
Telephone: +359 88 993 2233
For questions concerning personal data or the exercise of your GDPR rights, please contact us using the details above.
2. Who does this Policy apply to?
This Policy may apply to:
- website visitors;
- people contacting us by e-mail, telephone, social media or website forms;
- applicants and participants in our projects, programmes, training activities, events and initiatives;
- children and young people participating in our activities and their parents or legal guardians;
- volunteers, interns, experts and team members;
- representatives of partner organisations and institutions;
- donors and supporters;
- suppliers and contractors;
- job and volunteer applicants;
- subscribers to communications where such services are offered;
- other individuals interacting with Arms Wide Open.
3. What personal data may we process?
3.1 Identification and contact information
We may process:
- first and last name;
- e-mail address;
- telephone number;
- address where necessary;
- organisation and position;
- other information voluntarily provided to us.
3.2 Programme and project participation data
When you apply for or participate in our activities, we may process:
- age or date of birth;
- nationality or country of origin where relevant;
- language skills;
- educational background;
- professional or volunteering experience;
- motivation for participation;
- information required for project administration and reporting;
- attendance and participation records;
- information concerning support requirements where necessary and lawful.
Additional privacy information may be provided for particular projects or programmes.
3.3 Children’s and young people’s data
A significant part of Arms Wide Open’s activities involves children and young people.
Where necessary, we may process:
- name;
- age or date of birth;
- parent or guardian contact information;
- information necessary for participation;
- information relevant to participant safety and specific support needs;
- photographs, video or audio materials where an appropriate legal basis exists.
We apply a higher level of protection to children’s personal data, limit collection to what is necessary and obtain parental or legal guardian consent or authorisation where required by law.
3.4 Photographs, video and audio
Photographs, video and audio materials may be created during our events, training activities, campaigns and projects.
They may be used for:
- documenting activities;
- reporting to funding organisations;
- presenting project results;
- communicating our activities;
- publication on the website and official Arms Wide Open communication channels.
Where consent is legally required, such materials are used after appropriate consent has been obtained. Additional safeguards apply to children.
3.5 Donations and payments
When you make a donation or other permitted payment through our website, we may receive information necessary to administer and account for the transaction, including:
- name;
- contact information;
- amount and date of donation;
- transaction information;
- information required for accounting and legal purposes.
Where an external payment provider is used, payment details are processed directly by that provider under its own terms.
3.6 Technical data
When you use our website, certain technical information may be processed automatically, including:
- IP address;
- browser type and version;
- device type;
- operating system;
- date and time of access;
- pages visited;
- technical logs;
- cookie and other online identifiers;
- information concerning interaction with certain website functions and content.
4. Why do we process personal data?
We may process personal data to:
- respond to enquiries;
- communicate with you;
- receive and assess applications;
- organise training, events, projects and programmes;
- provide social, educational, cultural or other support;
- manage relationships with participants, volunteers, partners, suppliers and donors;
- perform contractual obligations;
- comply with funding requirements;
- document and report projects;
- comply with accounting, tax and other legal obligations;
- ensure participant safety;
- prevent fraud, spam, automated attacks and other misuse;
- protect our website and information systems;
- improve website functionality and content;
- communicate and promote our public-benefit activities where lawful.
5. Legal bases for processing
Depending on the circumstances, processing may be based on:
Consent – Article 6(1)(a) GDPR
For example, certain communications, photographs, videos, optional cookies and third-party content.
Performance of a contract or pre-contractual steps – Article 6(1)(b) GDPR
Where processing is necessary in connection with a contract or requested participation or service.
Compliance with a legal obligation – Article 6(1)(c) GDPR
Including accounting, financial, tax and other statutory obligations.
Legitimate interests – Article 6(1)(f) GDPR
Including organisational and information security, prevention of misuse and management of professional relationships, provided that these interests are not overridden by your rights and freedoms.
Where special categories of personal data are processed, an appropriate condition under Article 9 GDPR is also applied.
6. Special categories of personal data
Because of the nature of our public-benefit activities, it may occasionally be necessary to process information falling within the special categories of personal data under the GDPR.
Such data is not collected by default.
It is processed only where:
- necessary for a specific activity;
- an appropriate legal basis exists;
- processing is proportionate to the purpose;
- appropriate technical and organisational safeguards are applied.
7. Children and vulnerable individuals
Arms Wide Open works with children, young people and diverse communities, some members of which may be in vulnerable situations.
We apply principles including:
- data minimisation;
- confidentiality;
- restricted access;
- protection of dignity;
- particular care when publishing images and personal stories;
- prevention of unnecessary disclosure of sensitive information.
Participation in an Arms Wide Open programme does not in itself constitute consent to public disclosure of an individual’s personal story, image or sensitive information.
8. Where do we obtain personal data?
We generally obtain personal data directly from you.
In certain circumstances, information may be received from:
- a parent or legal guardian;
- a partner organisation;
- an institution;
- a service provider;
- a funding organisation;
- a publicly available source,
where necessary and lawful.
9. Website technologies and third-party services
To operate and provide functionality through www.armswideopen.eu, we use our own technologies and services provided by third parties.
WordPress and Elementor
Our website uses WordPress as its content management system and Elementor for creating and displaying website pages and content.
Technical data, local storage or cookies may be processed in connection with normal website operation.
Complianz
We use Complianz to manage and record website visitors’ choices concerning cookies and similar technologies.
Complianz may store information concerning your consent preferences, such as whether you accepted or rejected particular categories of cookies.
WooCommerce
Our website uses components of WooCommerce. Depending on the functionality used, WooCommerce may use technical or local storage necessary to provide that functionality.
Google reCAPTCHA
We use Google reCAPTCHA to protect our website, forms and functionality from spam, automated requests, bots and other forms of misuse.
Google may process information such as:
- IP address;
- browser and device information;
- technical identifiers;
- information concerning interaction with the website,
in accordance with Google’s applicable terms and policies.
Google Maps
Our website may use Google Maps to display location and related geographical information.
When Google Maps is loaded, certain technical information, including the user’s IP address, may be transmitted to Google.
Where applicable law requires consent for the relevant service or technologies, they are activated following the choices you make through our consent management system.
YouTube
Our website may publish or embed video content using YouTube, a Google service.
When embedded YouTube content is loaded or played, YouTube/Google may receive certain information, including:
- IP address;
- browser and device information;
- information concerning interaction with the video;
- cookie or other online identifiers.
Where appropriate and available, we may use privacy-enhanced settings or mechanisms that prevent third-party content from loading before the required choice is made.
Where consent is required under applicable law, the relevant YouTube content or optional technologies are loaded after consent has been obtained.
Wistia
Our website may contain multimedia content provided through Wistia.
When interacting with such content, Wistia may use local storage or similar technologies and receive technical information concerning interaction with the content.
Where consent is required for these technologies, they are activated after consent has been obtained.
PayPal
Our website uses PayPal functionality in connection with donations and payments.
When you use PayPal, the provider may process:
- transaction information;
- IP address and technical information;
- payment identifiers;
- information required for security;
- information required for fraud prevention.
Arms Wide Open does not receive your PayPal login credentials and generally does not receive your full payment card details.
PayPal may process certain information as an independent data controller under its own privacy terms.
10. Cookies and similar technologies
Our website uses cookies and similar technologies which may fall into categories including:
- strictly necessary/functional;
- preferences;
- statistics;
- marketing.
Cookies and technologies that are not strictly necessary are used on the basis of consent where consent is required by applicable law.
Through the “Manage consent” / “Cookie settings” tool, you can accept, reject or subsequently change your choices.
Further information is provided in our Cookie Policy.
11. Who may receive personal data?
We do not sell personal data.
Where necessary and supported by an appropriate legal basis, personal data may be disclosed to:
- Arms Wide Open employees, experts and volunteers who require access;
- project partner organisations;
- funding organisations where required by funding arrangements;
- accountants, auditors and professional advisers;
- IT, hosting, cloud and technical service providers;
- payment service providers;
- online and communications service providers;
- third-party content and technology providers when you use the relevant functionality;
- competent public authorities where required by law.
Where a provider processes personal data on our behalf, we take appropriate steps to ensure that the relationship is governed in accordance with GDPR requirements.
Certain providers may also process information as independent data controllers under their own privacy policies.
12. International data transfers
The use of certain technology and online services may involve processing of or access to personal data outside the European Economic Area (EEA).
Where personal data is transferred internationally, appropriate safeguards required by the GDPR are applied where necessary, including:
- European Commission adequacy decisions;
- Standard Contractual Clauses;
- other legally recognised transfer mechanisms.
13. How long do we retain personal data?
We do not retain personal data for longer than necessary for the purposes for which it was collected.
The applicable retention period depends on:
- the nature of the information;
- the purpose of processing;
- the duration of the relevant project or relationship;
- funder requirements;
- applicable accounting, tax and other statutory retention periods;
- the need to establish, exercise or defend legal claims.
Once the applicable period expires, information is deleted, securely destroyed or anonymised unless longer retention is required by law.
14. Data security
We apply appropriate technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unlawful use;
- accidental loss;
- alteration;
- destruction;
- unauthorised disclosure.
Access to personal data is limited to persons who reasonably require it in connection with their duties.
15. External websites and social media
Our website may contain links to external websites, social media platforms, video platforms, payment services and partner websites.
When you follow an external link, the processing of your personal data may also be governed by the relevant third party’s privacy terms.
Arms Wide Open does not control the privacy practices of independent third-party websites.
16. Your rights
Subject to the conditions provided by the GDPR, you may have the right to:
- receive information about the processing of your personal data;
- access your personal data;
- request correction of inaccurate or incomplete information;
- request erasure;
- request restriction of processing;
- object to certain processing;
- data portability where applicable;
- withdraw consent at any time;
- not be subject to a decision based solely on automated processing where the relevant GDPR conditions apply;
- lodge a complaint with the competent supervisory authority.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
17. Exercising your rights
Requests concerning your personal data may be sent to:
info@armswideopen.bg
To protect your information, we may request information reasonably necessary to verify your identity.
We will respond within the time limits prescribed by the GDPR.
18. Right to lodge a complaint
If you believe that your personal data is being processed in breach of applicable data protection legislation, you have the right to lodge a complaint with:
Commission for Personal Data Protection (CPDP)
Republic of Bulgaria
You may also contact us first at info@armswideopen.bg so that we can attempt to address your concern.
19. Automated decision-making
Arms Wide Open currently does not carry out solely automated decision-making that produces legal effects concerning individuals or similarly significantly affects them, unless expressly stated otherwise for a particular service.
20. Changes to this Policy
We may update this Policy periodically following changes to:
- applicable legislation;
- the activities of the Association;
- technologies and service providers used;
- our personal data processing practices.
The current version will be published on our website together with the date of the latest update.
21. Contact us
For questions about this Policy or our processing of personal data:
Arms Wide Open Association / Сдружение „Отворени обятия“
Sofia, Bulgaria
E-mail: info@armswideopen.bg
Telephone: +359 88 993 2233
Website: www.armswideopen.eu