24TH SANTA VENERA GIRL GUIDES

Policies & Compliance

This page outlines how we run the Santa Venera Girl Guides web properties in line with Malta Girl Guides guidance and EU regulations.

Overview

Single reference for all policies

The Santa Venera Girl Guides unit (“SVGG”, “we”, “us”) operates the public site, member portal, and leader/admin dashboard described on this domain. We follow the policies below to meet EU and Maltese requirements, including GDPR, ePrivacy Directive, safeguarding expectations from Malta Girl Guides (MGG), and Cloudflare’s acceptable use standards.

Last updated: 17 November 2025. Future revisions will be logged here and signposted via the portal announcements feed.

Terms of Use

Conditions for accessing our digital services

By using our public site, portal, or admin dashboard you agree to:

Leaders may suspend or revoke access if the terms are breached. Severe cases will be escalated to the Malta Girl Guides Association and, where appropriate, regulators.

Privacy Notice

How we collect and use personal data

For the purposes of the EU General Data Protection Regulation (GDPR), the Santa Venera Girl Guides unit (“SVGG”, “we”, “us”) is the data controller for personal data collected through this website, the member portal, and related digital forms.

The website, portal and leader/admin dashboard are hosted and technically operated by secure.mt, a Maltese cybersecurity and digital services provider, which acts as our data processor. secure.mt processes personal data only on our documented instructions, in order to provide hosting, security, and technical support.

This includes parent/guardian contact details, member registration data, activity preferences, medical/allergy notes shared with consent, newsletter subscriptions, and leader credentials.

Lawful bases for processing

Hosting, storage and access

All portal and site data is stored within secure.mt’s Cloudflare Pages environment, including Cloudflare D1/SQLite databases. Cloudflare primarily processes data within the European Union. Where data is routed outside the EU due to Cloudflare’s global network, such transfers are protected using EU Standard Contractual Clauses (SCCs) and additional technical safeguards.

Access to personal data is limited to:

Data sharing and processors

We do not sell personal data or publish membership lists. We share data only where necessary for guiding activities and in line with GDPR:

All processors are bound by written data processing agreements and must implement appropriate technical and organisational measures to protect personal data in line with EU GDPR.

Retention

Most membership records are retained for up to three guiding years after a member leaves, unless a longer period is required for safeguarding or legal obligations. Newsletter subscriber data is removed within 30 days of an unsubscribe request. Technical logs and backups retained by secure.mt are kept only for as long as necessary for security and operational purposes.

Cookies & Tracking

Minimal cookies for access and security

Our public site uses only essential cookies (Cloudflare security cookies). The portal and admin dashboard set signed session cookies to verify passcodes or Cloudflare Access tokens. We do not run advertising pixels or analytics that profile individuals.

You can block cookies at the browser level, but the portal/admin features will not function without the session cookies noted above.

Your Rights

EU GDPR data subject rights

Members, guardians, and leaders can exercise the following rights:

We aim to respond to verified requests within 30 days. Complex requests may take an additional 30 days; we will notify you if more time is required.

Safeguarding & Conduct

Protecting minors and leaders online

Offline safeguarding and behaviour policies continue to apply at meetings, camps, and events. This digital policy extends those expectations to all online interactions managed by SVGG.

Contact & Requests

How to reach us about these policies

Please email santavenera@maltagirlguides.com for any privacy, policy, or safeguarding query. Include:

You may also escalate unresolved privacy issues to the Office of the Information and Data Protection Commissioner (IDPC) in Malta or to the Data Protection Authority where you reside.