GDPR — Your Rights Under European Data Protection Law
This page describes how NESEN — New England Science and Entrepreneurship Network ("NESEN," "we," "us," or "our") handles the personal data of individuals located in the European Economic Area (EEA) and the United Kingdom (UK) in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR as retained in UK law. It supplements our Privacy Policy and Cookie Policy, which describe our data practices in full.
If you are located in the EEA or UK and use our Services, this page applies to you. If you are located elsewhere, please refer to our Privacy Policy for information about your rights.
1. Who Is the Data Controller
For the purposes of the GDPR and UK GDPR, the data controller responsible for your personal data is:
As a US-based nonprofit organization processing personal data of EEA and UK residents, NESEN is subject to GDPR requirements when it offers services to individuals in those regions or monitors their behavior. We take this responsibility seriously and have implemented the measures described in this document to ensure compliance.
EU Representative
As required by Article 27 of the GDPR, organizations established outside the EEA that process EEA residents' personal data must designate a representative within the EU. Where legally required, NESEN appoints an EU representative. Contact details for the EU representative are available upon request at privacy@nesen.org.
UK Representative
Similarly, under the UK GDPR, we appoint a UK representative where required. Contact details are available upon request.
Data Protection Officer
At our current stage of operations, NESEN is not legally required to appoint a Data Protection Officer (DPO) under Article 37 of the GDPR. However, we have designated a privacy contact responsible for overseeing our data protection compliance. You can reach this contact at privacy@nesen.org.
2. Personal Data We Collect
We collect personal data that you provide to us directly, data generated by your use of our Services, and data received from third parties. The categories of personal data we process are described in full in our Privacy Policy (Section 1). In summary, for EEA and UK residents, these categories include:
- Identity data: Name, professional title, company, and profile photograph
- Contact data: Email address and, where provided, professional contact details
- Professional data: Industry classification, career background, pitch materials, and LinkedIn profile URL
- Usage data: Meeting attendance records, referral activity, page views, and interaction logs
- Technical data: IP address, browser type, device identifiers, and cookie data
- Communications data: Messages sent to us through support channels and feedback forms
We do not intentionally collect special categories of personal data (also called "sensitive data") as defined by Article 9 of the GDPR — including data revealing racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or sexual orientation. Please do not submit such information through our Services.
3. Legal Bases for Processing
We process your personal data only when we have a lawful basis for doing so under Article 6 of the GDPR. The table below sets out the activities for which we process personal data and the legal basis that applies to each.
| Processing activity | Legal basis | Explanation |
|---|---|---|
| Creating and managing your member profile | Contract | Necessary to perform the contract established when you join NESEN |
| Processing membership applications and referrals | Contract | Necessary to deliver the Services you have requested |
| Displaying your profile to other Members | Contract | Core functionality of the referral network you have joined |
| Sending transactional emails (confirmations, meeting reminders) | Contract | Necessary to provide the Services, including weekly meeting access information |
| Sending marketing and newsletter communications | We send marketing emails only where you have opted in. You may withdraw consent at any time. | |
| Non-essential cookies and analytics | Set only after you provide consent through our cookie preference center | |
| Platform analytics and community improvement | Legitimate interests | We have a legitimate interest in understanding how Members engage with the network to improve it |
| Fraud detection and security | Legitimate interests | We have a legitimate interest in protecting the network and our Members from abuse |
| Publishing meeting content and highlights | Legitimate interests | We have a legitimate interest in promoting the community. You are informed of recording at the time of participation. |
| Responding to support and legal requests | Legitimate interests | Necessary to respond to your requests and maintain our relationship with you |
| Compliance with legal obligations | Legal obligation | Where we are required by law to process or retain data |
Legitimate interests assessment
Where we rely on legitimate interests as our legal basis, we have conducted a balancing test to confirm that our interests are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests — see Section 5 below.
4. International Data Transfers
NESEN is based in the United States, which is a third country under the GDPR. When we transfer your personal data from the EEA or UK to the United States or other third countries, we ensure that appropriate safeguards are in place as required by Chapter V of the GDPR.
Transfer mechanisms we rely on
- Standard Contractual Clauses (SCCs): For transfers from the EEA to the US and other third countries, we rely on the European Commission's Standard Contractual Clauses incorporated into our data processing agreements with service providers. For UK transfers, we use the UK Addendum to the EU SCCs.
- Data Privacy Framework: Where our US-based service providers are certified under the EU-US Data Privacy Framework (DPF) or the UK Extension to the DPF, we may rely on that certification as a transfer mechanism.
- Adequacy decisions: For transfers to countries that benefit from a European Commission adequacy decision, no additional safeguard is required.
You may request a copy of the transfer mechanisms we have in place by contacting us at privacy@nesen.org.
Third-party service providers
We use third-party service providers who may process your personal data outside the EEA. We have entered into data processing agreements with each of these providers that include the appropriate transfer safeguards. A list of our current sub-processors is available upon request.
5. Your Rights Under the GDPR
The GDPR grants you a comprehensive set of rights with respect to your personal data. These rights apply to EEA and UK residents and are described below.
You have the right to obtain confirmation of whether we process personal data about you and, if so, to receive a copy of that data together with information about how and why we process it (Article 15).
You have the right to have inaccurate personal data corrected and incomplete data completed without undue delay (Article 16). You can update most profile information directly in your account settings.
You have the right to request deletion of your personal data in certain circumstances, such as where the data is no longer necessary for the purpose for which it was collected (Article 17).
You have the right to request that we restrict the processing of your personal data in certain circumstances (Article 18).
Where we process your data on the basis of consent or contract by automated means, you have the right to receive your data in a structured, commonly used, machine-readable format (Article 20).
You have the right to object at any time to processing based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will stop immediately (Article 21).
Where we process your data on the basis of consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
You have the right not to be subject to decisions based solely on automated processing that produce significant legal or similarly significant effects on you (Article 22). We do not currently make such decisions.
How to exercise your rights
To exercise any of the rights above, please submit a request to privacy@nesen.org with the subject line "GDPR Rights Request." Please include your full name, the email address associated with your NESEN account, and a clear description of the right you wish to exercise.
We will acknowledge your request within 72 hours and respond substantively within one calendar month of receipt. We may extend this period by a further two months for complex requests — we will notify you of any extension within the initial one-month period.
6. Data Retention
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, to comply with legal obligations, to resolve disputes, and to enforce our agreements. The specific retention periods we apply are:
- Member profile data: Retained for the duration of your membership and deleted within 90 days of account closure, subject to the exceptions below.
- Meeting attendance and referral records: Retained for 3 years from the date of the meeting to support community continuity and dispute resolution.
- Marketing consent records: Retained for 3 years after consent is withdrawn, to demonstrate the lawfulness of prior communications.
- Security and fraud logs: Retained for 12 months from the date of the incident or log entry.
- Support communications: Retained for 2 years from the date of the last communication in the thread.
After the applicable retention period, personal data is securely deleted or anonymized so that it can no longer be linked to an identifiable individual.
7. Automated Processing and Profiling
We use automated systems to deliver certain features of the Services, including member matching suggestions and meeting recommendations based on your industry classification and participation history. These automated processes are used to improve your experience and do not produce legal or similarly significant effects on you.
We do not use your personal data to make automated decisions that have legal effects. If this changes, we will update this page and notify affected Members.
8. Security of Personal Data
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, disclosure, alteration, or destruction, in accordance with Article 32 of the GDPR. These measures include:
- Encryption of personal data in transit using TLS 1.2 or higher;
- Encryption of personal data at rest in our production databases;
- Access controls restricting data access to personnel who need it to perform their functions;
- Regular security assessments of our infrastructure; and
- Incident response procedures, including notification protocols for data breaches.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR.
9. Children's Data
Our Services are not directed at children under the age of 16 in the EEA and UK. We do not knowingly process personal data of children under 16 without verifiable parental or guardian consent, as required by Article 8 of the GDPR. If you believe that we have processed data of a child under 16 without the required consent, please contact us immediately at privacy@nesen.org.
10. Right to Lodge a Complaint
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with your local supervisory authority. We encourage you to contact us first at privacy@nesen.org so that we have an opportunity to address your concern directly.
Key supervisory authorities
- Ireland: Data Protection Commission (DPC)
- Germany: Federal Commissioner for Data Protection (BfDI)
- France: CNIL
- Netherlands: Autoriteit Persoonsgegevens (AP)
- United Kingdom: Information Commissioner's Office (ICO)
- All EEA supervisory authorities: European Data Protection Board member list
11. Changes to This Page
We may update this GDPR page from time to time to reflect changes in our processing activities, applicable law, or regulatory guidance. When we make material changes, we will update the effective date and notify affected Members by email where the changes are significant.
12. Contact and Further Information
For any questions, concerns, or requests related to your rights under the GDPR or UK GDPR, please contact us:
Related documents:
- Privacy Policy — full description of how we collect and use personal data
- Cookie Policy — how we use cookies and tracking technologies
- Terms of Service — the agreement governing use of our Services