Last updated: 8 August 2026

This Privacy Notice explains how Generation Europe ("Generation Europe", "we", "us") processes personal data when you visit our website (generationeurope.eu), contact us, or submit one of our forms.

This website is operated by Generation Europe, an unincorporated association under Articles 36 et seq. of the Italian Civil Code, based in Savona, Italy.

1) Data Controller (who is responsible)

Generation Europe
Unincorporated association under Articles 36 et seq. of the Italian Civil Code
Address: Corso Italia 15/6 — 17100 Savona (SV), Italy
Italian tax code (codice fiscale): 92123240092
Contact email: info@generationeurope.eu

For any question regarding your personal data you may write to the email address above: we will reply within the time limits set by the GDPR.

2) What personal data we process

A. Data you provide via website forms

Our website hosts two forms — the Join Us form and the Contact form. When you submit a form, we process the personal data you provide:

  • Join Us form: full name, email address, country, city, area of contribution (selected from a list), and any optional message you choose to include.
  • Contact form: name, email address, subject, and message content.
  • Privacy consent: the timestamp at which you marked the privacy consent checkbox, kept as evidence of valid consent.

B. Data you provide via direct email

If you contact us directly at info@generationeurope.eu (rather than through a form), we process the personal data you provide, such as your email address, your name (if included), the content of your message and any attachments, and any other personal data you choose to share.

C. Data you provide when you book a video call with us

Our Book a Call page embeds a scheduling widget provided by Cal.com. If you book a call, we process your name, email address, the time slot and time zone you select, and any note you add to the booking. The booking creates an entry in our calendar and a Google Meet link for the call itself.

After the call we may keep a short internal note on what was discussed and on your possible role within the movement. These notes are visible only to the people who coordinate the association, are not published, and are not shared with anyone outside it.

D. Data relating to the emails we send you

If you have submitted one of our forms, we send you emails through Brevo (confirmation of your submission, the link to book a call, occasional updates on the association). Brevo records whether an email was delivered, opened, and whether you clicked a link, so that we can tell whether our messages are arriving at all and follow up with people who have not received them. We do not use this data to build behavioural profiles or for advertising.

E. Data processed automatically when you visit the website (technical data)

Our website is hosted on Netlify. When you access the site, Netlify's infrastructure processes technical data ("server logs"), such as:

  • IP address;
  • date and time of access;
  • pages requested and request details;
  • browser/device information (user agent);
  • referrer URL (where available);
  • error logs and security-related events.

This information is necessary to operate, secure, and maintain the website.

F. Links to third-party platforms (social media)

Our website contains links to third-party platforms (Instagram, Telegram, WhatsApp). When you click a link, you leave our website and the third party processes your personal data under its own privacy policy. We recommend reviewing those policies. We do not embed any tracking pixels or social widgets on our pages — only outbound links.

3) Why we process personal data (purposes)

We process personal data for the following purposes:

  1. Form submissions and enquiry handling. To read, route, and respond to messages submitted through our forms or sent to our email address; to coordinate your participation in the movement (digital teams, local chapters, working groups) if you have signed up.
  2. Organising introductory video calls. To schedule, hold, and keep track of the introductory calls we offer to people who wish to take part in the movement.
  3. Emails to people who have signed up. To confirm we have received your submission, send you the link to book a call, and keep you informed about the association and how to join it.
  4. Managing membership. To assess applications, admit members, and keep the register of members required of an association.
  5. Website operation and security. To deliver the website, ensure stability, prevent abuse, and troubleshoot technical issues.
  6. Protection of rights and handling disputes. To prevent fraud or misuse, manage security incidents, and establish, exercise, or defend legal claims where necessary.

4) Legal bases (GDPR)

We process personal data under the following legal bases:

  • Consent (Article 6(1)(a) GDPR) when you submit one of our forms and tick the privacy consent checkbox, or when you voluntarily send us personal data via email. You may withdraw consent at any time (see Section 10).
  • Legitimate interests (Article 6(1)(f) GDPR) for operating and securing the website, preventing abuse, and ensuring IT stability.
  • Compliance with a legal obligation (Article 6(1)(c) GDPR) where applicable (e.g., if we must retain certain records to respond to lawful requests).

Where we rely on legitimate interests, we balance those interests against your rights and reasonable expectations.

5) Cookies and similar technologies

This website does not use cookies for advertising or behavioural profiling. We do not embed Google Analytics, Meta Pixel, or any third-party advertising tracker.

The only cookies that may be set are strictly necessary technical cookies served by our hosting provider (Netlify) for essential functions such as load balancing, security, and the delivery of the website itself. These cookies do not require consent under Article 5(3) of Directive 2002/58/EC (ePrivacy Directive).

On the Book a Call page only, we embed the Cal.com scheduling widget. That widget is loaded from Cal.com's own servers and may set its own technical cookies, which are necessary for the booking function you have chosen to use. The widget is present on that single page and on no other page of this website.

All fonts used on this site are served from our own servers. We do not load them from an external content delivery network, so visiting our pages does not disclose your IP address to any font provider.

5a) Visit statistics (cookieless)

To understand how many people visit the site and which content is read most, we use Umami, a privacy-friendly analytics tool that sets no cookies and stores no permanent identifiers on your device.

Umami collects only aggregated, anonymous data: number of pageviews, most visited pages, referring site, country, device type, browser and operating system, and visit duration. We do not retain your IP address, we do not build individual profiles, we do not follow you across other websites, and we do not share this data for advertising purposes.

Because no cookies or identification technologies are used, this processing does not require your consent; the legal basis is our legitimate interest (Article 6(1)(f) GDPR) in understanding, in aggregate form, how the website performs and in improving its content. You can still block collection with any ad-blocker or by enabling your browser's "Do Not Track" setting.

For a limited period we also use the aggregated statistics provided by our hosting platform (Netlify Analytics), which are processed server-side from technical logs and involve no cookies and no script on your device.

If we ever introduce non-essential cookies (e.g., marketing pixels or embedded social widgets that track users), we will update this Notice and implement an appropriate consent mechanism (cookie banner with opt-in) before activating them.

6) Who we share personal data with (recipients)

We share personal data only where strictly necessary for the purposes above, with the following categories of recipients:

  1. Netlify, Inc. (website hosting and form processing) — Netlify hosts the website and, where Netlify Forms is used, processes form submissions on our behalf. In GDPR terms, Netlify acts as a processor for visitor and form data processed on our behalf, and may also act as an independent controller for certain processing in accordance with its own policies. See Netlify's privacy notice at netlify.com/privacy.
  2. Zoho Corporation (email) — provides our @generationeurope.eu mailboxes on European infrastructure. Acts as a processor for messages and related data on our behalf, and may also process certain data as an independent controller for service administration and security according to its own policies.
  3. Sendinblue SAS – Brevo (email sending, France) — sends the emails described in Section 2D and records delivery, opens, and clicks on our behalf.
  4. Cal.com, Inc. (call scheduling, United States) — operates the booking widget and processes the booking data described in Section 2C.
  5. Google (calendar and video calls) — our calendar and the Google Meet rooms used for the calls.
  6. Supabase, Inc. (data storage, servers in Switzerland) — stores the bookings and the internal notes described in Section 2C.
  7. Vercel, Inc. (internal applications, United States) — hosts the internal tools the association uses to manage contacts and calls. These tools are not public and are protected by authentication.
  8. Umami Software, Inc. (visit statistics) — receives and processes on our behalf the aggregated, anonymous data described in Section 5a. It receives no identifying data and sets no cookies. See its privacy notice at umami.is/privacy.
  9. Service providers assisting with IT/security, only if necessary for maintenance, troubleshooting, or incident response.
  10. Public authorities, only where required by law or where necessary to protect rights, safety, and security.

We do not sell personal data. We do not share personal data with marketing partners or for advertising purposes.

7) International data transfers

Some of our providers process data outside the European Economic Area (EEA):

  • United States: Netlify, Cal.com, Vercel and Google. These transfers rely on the Standard Contractual Clauses adopted by the European Commission, incorporated into the data processing terms of each provider, together with supplementary measures where required.
  • Switzerland: Supabase stores our data in its Zurich region. Switzerland benefits from an adequacy decision of the European Commission, so no further safeguards are required.

Our email provider (Zoho), our email sending provider (Brevo, France) and our visit statistics (Umami) operate on European infrastructure.

If you would like more information about the safeguards relevant to our specific configuration, please contact us at info@generationeurope.eu.

8) Data retention

We keep personal data only as long as necessary for the purposes described above:

  • Server logs (technical data): retained for a limited period needed for security and troubleshooting, in accordance with Netlify's retention configuration.
  • Form submissions from people who do not become members: retained for 24 months from your last meaningful contact with us (a form submission, a reply to one of our emails, a call, a click on one of our links). If that period passes with no contact, we delete your data. You may ask us to delete it sooner at any time.
  • Data of members: retained for the whole duration of membership and, once membership ends, for the period required by the rules on the register of members and by tax and accounting law.
  • Booking data and notes on introductory calls: retained on the same terms as the point above that applies to you — 24 months for those who do not become members, the duration of membership for those who do.
  • Delivery, open and click records of our emails: retained for 24 months, then deleted or made anonymous.
  • Email correspondence: retained as long as necessary to respond to you and manage your participation, and thereafter only as needed for record-keeping, security, or legal purposes.
  • Records of consent (privacy checkbox timestamp): retained for as long as the underlying processing is active, plus a reasonable archival period for accountability under Article 7(1) GDPR.
  • Security incidents and legal claims: retained for as long as necessary to investigate or to establish, exercise, or defend legal claims.

You may request deletion of your data at any time (see Section 10). We may retain minimal information where strictly required for legal or security reasons.

9) Security

We implement reasonable technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include encrypted transport (HTTPS), access restrictions, and reliance on reputable infrastructure providers. No internet-based service can guarantee absolute security, but we work to maintain protections appropriate to the risks.

10) Your rights

Depending on your location and applicable law (including GDPR), you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • erase your data in the circumstances foreseen by law (right to be forgotten);
  • restrict processing in certain cases;
  • object to processing based on legitimate interests;
  • data portability (where applicable);
  • withdraw consent at any time, where processing is based on consent — without affecting the lawfulness of processing carried out before withdrawal.

To exercise your rights, contact info@generationeurope.eu. We will respond within 30 days. We may request information necessary to verify your identity.

Right to complain

You also have the right to lodge a complaint with your local data protection authority (supervisory authority) in the EEA/UK, typically in the country of your habitual residence, workplace, or where you believe an infringement occurred.

11) Children

Our website is not directed at children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.

12) Third-party services and external links

Our website contains links to third-party platforms (including social media platforms such as Instagram, Telegram, and WhatsApp). We are not responsible for the content, security, or privacy practices of those third parties. Please review their privacy policies before providing them with any personal data.

13) Changes to this Privacy Notice

We may update this Notice from time to time. The "Last updated" date at the top indicates when it was most recently revised. Where changes are material, we will make reasonable efforts to highlight them on the website.

14) Contact

For privacy-related enquiries, requests to exercise your rights, or any question about this Notice, contact us at:
info@generationeurope.eu

15) Legal Notice / Site Imprint

This section provides information about the publisher and operation of generationeurope.eu, in accordance with applicable transparency requirements (including, where relevant, § 5 of the German Telemediengesetz / Digitale-Dienste-Gesetz).

Publisher

Generation Europe — unincorporated association under Articles 36 et seq. of the Italian Civil Code.
Address: Corso Italia 15/6 — 17100 Savona (SV), Italy
Italian tax code (codice fiscale): 92123240092
Email: info@generationeurope.eu

In Italy, Generation Europe also operates through its affiliated association Generation Europe Italia (tax code 92123250091, same address), which promotes its mission and activities nationally while retaining its own organisational and administrative autonomy.

Editorial responsibility

Editorial responsibility for the content of this website lies with Generation Europe, in the person of its legal representative pro tempore. For any content-related question, write to info@generationeurope.eu.

Hosting

This website is hosted by Netlify, Inc., 44 Montgomery Street, Suite 300, San Francisco, CA 94104, United States — netlify.com.

Liability for content

The content of this website is provided in good faith, for general information and engagement purposes related to the political project of European unification. Despite our efforts, we cannot guarantee that all content is at all times complete, accurate, or up to date.

Liability for external links

Our website contains links to third-party websites whose content we do not control. Responsibility for those external pages lies exclusively with their respective operators. We have no influence over their current or future content.

Copyright

Unless otherwise indicated, the content of this website (text, graphics, layout) is the work of Generation Europe contributors and is protected under European copyright law. Reuse for non-commercial, civic, and educational purposes is generally welcomed; please contact us at info@generationeurope.eu for any other use.