Privacy Policy
Last Updated: March 12, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Community Connect Canada (âweâ, âusâ, âourâ) collects, uses, and protects personal data when you visit our website or interact with our services. Community Connect Canada is a community platform for learning resources, event information, and participation opportunities intended primarily for communities across Canada. The platform is operated by FN Beheer B.V., a Netherlands-registered organization.
For the purposes of the General Data Protection Regulation (âGDPRâ) and applicable Dutch privacy laws, the data controller is:
- Legal entity: FN Beheer B.V.
- Registered office: Regentenland 10, 3994 TZ Houten, Netherlands
- Contact email: [email protected]
- Telephone: +31 30 639 0500
We do not appoint a Data Protection Officer as a matter of course. If your request is complex or relates to a broader privacy concern, we will ensure it is handled by the appropriate person within FN Beheer B.V. and respond within the timelines set out below.
This policy is effective from the âLast Updatedâ date above. We may update it from time to time; we explain how changes are communicated in Section 17.
2. Personal Data We Collect
We collect personal data in a few predictable ways: when you submit forms, when you communicate with us, and when your browser accesses our pages. We aim for data minimization, which means we ask for what we need to run the platform, coordinate participation, and respond to messages.
- Identity and contact data: name, email address, and phone number if you provide it.
- Form content: the message you type, topic/subject selections, community or event details you include, and any logistics notes you send (for example, preferred format such as online or local).
- Technical data: IP address, browser type and version, device type, operating system, and language settings.
- Usage data: pages viewed, time spent on pages, referrer information, and interaction data such as click paths that help us understand what content is useful.
- Cookies and identifiers: cookie values and similar identifiers described in Section 4 and our Cookie Policy.
- Conversion and submission events: whether a form was submitted successfully, which helps us measure reliability and coordinate follow-up.
We do not intentionally collect special-category data (such as health information, religious beliefs, political opinions), financial account details, or government identification numbers through our standard forms. Please avoid sharing sensitive personal data in free-text fields. If you include sensitive details anyway, we will handle them with care and may redact or delete portions where appropriate to reduce risk.
3. Why We Process Personal Data & Legal Bases (GDPR Art. 6)
We process personal data only where we have a lawful basis. The basis depends on the context of your interaction with the platform.
- Contact and membership inquiries: we use your data to reply and coordinate next steps. Legal basis: Art. 6(1)(b) (steps at your request prior to entering into a relationship) and Art. 6(1)(a) (consent where you explicitly provide it via required consent tick boxes).
- Event coordination: we use registration details to confirm attendance, provide logistics (time zones, format), and manage operational notices. Legal basis: Art. 6(1)(b) and, where relevant, Art. 6(1)(a).
- Analytics: we use analytics data to understand what sections are used and to improve readability and navigation. Legal basis: Art. 6(1)(a) (consent).
- Marketing and remarketing: we may use marketing cookies to measure advertising performance and show relevant ads. Legal basis: Art. 6(1)(a) (consent).
- Security and fraud prevention: we use technical data (including IP and logs) to secure the site, prevent abuse, and maintain service reliability. Legal basis: Art. 6(1)(f) (legitimate interests).
- Legal obligations: if we must keep records to comply with law (for example, responding to lawful requests or maintaining audit trails), we process data accordingly. Legal basis: Art. 6(1)(c) (legal obligation).
Automated decision-making (Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you. If we use analytics or advertising tools, they may create aggregated segments for measurement, but we do not use them to make decisions that materially affect your rights.
4. Cookies & Tracking
Cookies are small text files stored on your device. They help websites function, remember preferences, and (where permitted) measure usage or advertising performance. In addition to cookies, some tracking may occur through pixel tags or similar technologies embedded on pages. Any analytics or marketing tracking is activated only after consent, unless it is strictly necessary for the site to function.
Your cookie preferences can be changed at any time using âManage cookie preferencesâ in the footer. Essential cookies remain active because they are required for basic site operation.
Essential (always active)
Essential cookies are required for core functionality such as session continuity, security, and saving your consent choice. These cookies do not require consent under EU rules when they are strictly necessary.
- _site_session: helps maintain session continuity. Retention: session to a short persistent period depending on implementation.
- cookie_consent: stores your consent choice. Retention: 12 months.
Analytics (requires consent)
If you consent, we may use Google Analytics 4 (GA4) to understand usage patterns, such as which pages are most useful and whether navigation paths are clear. Where available, IP anonymization is used. Retention for analytics data is typically 14 months.
- _ga (GA4 user identifier). Retention: 2 years.
- _ga_XXXXXXXXXX (GA4 session state; example ID). Retention: 2 years.
Marketing (requires consent)
If you consent, marketing cookies may be used to measure advertising performance, limit repeated ads, and build audiences for remarketing or lookalike modelling. These tools rely on cookie identifiers and event data such as page views or form submissions.
- _gcl_au (Google Ads conversion linker). Retention: 90 days.
- _fbp (Meta Pixel browser identifier). Retention: 90 days.
- _fbc (Meta click identifier). Retention: 90 days when click ID is set.
Beyond cookies, some providers support server-side event sharing (for example, Meta Conversion API or server-side tagging). Where used, identifiers may be hashed before transfer. If these tools are used, they will still respect the consent choices stored in your cookie_consent cookie.
5. Consent (EEA/UK)
Users in the EEA and the UK receive a consent notice consistent with GDPR and UK GDPR expectations. Analytics and marketing cookies activate only after explicit, informed, freely given consent (Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent cookie and stored for up to 12 months unless you change it.
You may withdraw consent at any time using âManage cookie preferencesâ in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing based on consent before it was withdrawn.
6. Sharing With Advertising & Service Partners
We share personal data only where needed to operate the site, provide services, and (where you have consented) measure marketing performance. We do not sell personal data. Depending on your consent choices and the tools enabled on the site, the following partners may receive data:
- Google LLC (Google Analytics 4, Google Ads, Google Tag Manager, remarketing): cookie identifiers, usage data, and conversion events used for measurement and audience creation. Policy: https://policies.google.com/privacy
- Meta Platforms (Meta Pixel, Custom/Lookalike Audiences, Conversion API): page view events, conversion events, and audience signals; identifiers may be hashed where supported. Policy: https://www.facebook.com/privacy/policy
- Cloudflare (CDN and security): IP-based threat detection and performance routing. Policy: https://www.cloudflare.com/privacypolicy/
We do not permit these providers to use site data for their own independent commercial purposes beyond providing services to us, but some providers may process data as independent controllers for their own compliance and security needs. You should review their policies for more detail.
7. International Transfers
FN Beheer B.V. is based in the Netherlands, but some service providers we use may process data outside the EEA/UK, including in the United States. When personal data is transferred internationally, we use appropriate safeguards.
- EUâUS Data Privacy Framework (where applicable, since July 2023).
- UK Extension to the EUâUS Data Privacy Framework (where applicable).
- SwissâUS Data Privacy Framework (where applicable).
- Standard Contractual Clauses (EU 2021/914) as a fallback mechanism.
- UK IDTA as a fallback mechanism for UK-related transfers.
We also apply practical measures such as data minimization, limited retention, and access controls to reduce risk.
8. Retention
We retain personal data only as long as needed for the purposes described in this policy. Retention periods can vary based on the context of your request and legal requirements.
- Contact submissions: typically up to 2 years from the last interaction, to maintain continuity and handle follow-up.
- Email correspondence: for the duration of the relationship and up to 1 year afterward, unless a longer retention is needed for dispute handling.
- Server logs: typically up to 90 days for security monitoring and troubleshooting.
- Analytics data: typically 14 months (where enabled by consent).
- Marketing cookies: per cookie lifetime (for example 90 days), where enabled by consent.
- Cookie consent record: up to 3 years for audit and compliance evidence, where applicable.
- Legal and tax: where a specific Dutch or EU legal obligation applies, we retain data for the required period (commonly 6â10 years for invoice-related records, where relevant).
9. Your Rights (GDPR & UK GDPR)
If you are in the EEA or the UK, you have rights under GDPR/UK GDPR. These include the right to access your data, correct it, request deletion, restrict processing, object to processing, and request portability where applicable. You also have the right to withdraw consent (Art. 7(3)) at any time where processing is based on consent.
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Portability (Art. 20)
- Objection (Art. 21)
- Withdraw consent (Art. 7(3))
- Lodge a complaint (Art. 77)
To exercise your rights, email [email protected]. We respond within 30 days. For complex requests, this may be extended by up to 60 days, in which case we will explain why.
Supervisory authority (Netherlands): You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). Website: https://autoriteitpersoonsgegevens.nl. For general EU guidance, see the EDPB: https://edpb.europa.eu.
10. Children
This website is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, contact us and we will delete the data promptly where appropriate.
11. Do Not Track
This website does not respond to âDo Not Trackâ (DNT) browser signals. Some third-party providers may offer their own DNT-related controls; you should review their documentation for details.
12. Account & Data Deletion Requests
To request deletion of personal data, email us at [email protected] with the subject line âData Deletion Requestâ. To prevent improper deletion, we may ask for minimal verification that you control the email address used in the submission. We aim to complete valid deletion requests within 30 days.
We may retain limited information where required by law, where needed to establish, exercise, or defend legal claims, or where retention is necessary for security and fraud prevention.
13. Business Transfers
If FN Beheer B.V. is involved in a merger, acquisition, asset sale, financing, reorganization, insolvency, or receivership, personal data may be transferred as part of that transaction. If such a transfer materially changes how personal data is used, we will provide a notice on the site before the change takes effect, where feasible.
14. California (CCPA / CPRA)
While FN Beheer B.V. is established in the Netherlands, visitors from the United States may use the site. The information below is provided for transparency and may apply depending on how California law is interpreted for your interaction.
In the past 12 months, we may have disclosed the following categories of personal information for business purposes to service providers and, if you consent, advertising partners:
- Identifiers: name, email address, IP address, cookie identifiers.
- Internet or network activity: page views, interactions, and device data used for analytics and performance.
- Inferences: interest categories derived from page views for advertising measurement (where enabled by consent).
We do not sell personal information as defined by CCPA. We do share information for cross-context behavioral advertising only where marketing cookies are enabled by consent. California residents may opt out of sharing by rejecting marketing cookies via our cookie preferences panel.
California rights may include: the right to know, delete, correct, and opt out of sale/sharing, and the right to non-discrimination. To submit a request, email [email protected] with the subject âCalifornia Privacy Requestâ. We may need to verify your identity. Authorized agents may submit requests with proof of authorization.
15. Virginia (VCDPA)
Virginia residents may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject âVirginia Privacy Requestâ. If we decline a request, you may appeal by emailing with the subject âAppeal of Refusal â Privacy Requestâ. We respond to appeals within 60 days. If the appeal is denied, you may contact the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing us with the subject âNevada Do Not Sell Requestâ. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Policy
We may update this Privacy Policy to reflect changes in how the platform operates, legal requirements, or service provider practices. If changes are material, we will publish a notice on the homepage at least 14 days before the updated policy takes effect, where feasible.
The âLast Updatedâ date at the top of this page shows when the policy was most recently revised.
18. Contact
If you have questions about this Privacy Policy or want to exercise your privacy rights, contact:
- FN Beheer B.V.
- Regentenland 10, 3994 TZ Houten, Netherlands
- Email: [email protected]
- Phone: +31 30 639 0500
Privacy questions
For privacy-related inquiries, contact us at [email protected]. Please include enough detail for us to locate the relevant request (for example, the email used on a form submission).