Privacy Policy

The Open Churches Foundation (Fondation Églises Ouvertes / Stichting Open Kerken) (“Open Churches”, “we”) attaches great importance to the protection of your privacy and your personal data. This policy explains what data we process, for what purposes, on what legal bases, with whom it is shared, and what rights you can exercise, in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian law.

1. Data controller

The data controller is the Open Churches Foundation (Fondation Églises Ouvertes / Stichting Open Kerken), whose registered office is at Chaussée de Tirlemont 508A, 1370 Jodoigne (Belgium). For any question regarding this policy or your data, you can contact us by e-mail at info@openchurches.eu or via the site’s contact form.

2. Data we process

We only collect the data necessary for the purposes described below:

  • Data you provide when you use the contact form, create an account, register a building, propose an event or subscribe to our newsletter: in particular your first and last name, your e-mail address, your contact details, and the information relating to the building or event concerned.
  • Account data: login credentials and preferences (language, country, favourites) if you create an account.
  • Technical and browsing data: IP address, browser type, pages viewed and approximate location (country), collected in particular by means of cookies (see our cookie policy).

3. Purposes of processing

  • respond to and follow up on your requests;
  • manage your account and your participation in the network;
  • publish the buildings and events you submit to us;
  • send you our newsletter, if you have consented to it;
  • adapt the content to your country and language;
  • ensure the proper operation, security and improvement of the site.

4. Legal bases

Depending on the purpose, the processing is based on your consent (newsletter, non-essential cookies), on the performance of measures taken at your request or of a service you have requested (account, submission of a building or event), on our legitimate interest in keeping the network alive and securing the site, or on compliance with a legal obligation.

5. Recipients and processors

Your data is neither sold nor rented. It is only shared with the providers strictly necessary for the operation of the service, contractually bound to confidentiality and acting as processors:

  • our hosting provider and technical service providers;
  • our provider for sending e-mails and the newsletter (Brevo);
  • our content delivery network (CDN) provider, for displaying images;
  • the third-party services embedded in certain pages (Google Maps maps, YouTube videos), which may process data when displayed (see our cookie policy).

6. Transfers outside the European Economic Area

Our providers are, as far as possible, established within the European Union. Where a third-party service (for example Google) processes data outside the EEA, that transfer is governed by appropriate safeguards (standard contractual clauses, an adequacy decision or the applicable data protection framework).

7. Retention period

We keep your data only for as long as necessary for the purposes pursued: messages sent via the contact form are kept for up to one year; account data for the entire lifetime of your account, and are deleted when it is closed or at your request; newsletter subscription data until you unsubscribe. Beyond that, your data is deleted or anonymised, subject to legal retention obligations.

8. Your rights

In accordance with the GDPR, you have at all times the rights of access, rectification, erasure, restriction, objection and portability of your data, as well as the right to withdraw your consent at any time, without affecting the lawfulness of earlier processing. To exercise these rights, contact us via the contact form or at info@openchurches.eu.

You also have the right to lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels — www.dataprotectionauthority.be.

9. Security

We implement appropriate technical and organisational measures to protect your data against loss, unauthorised access or misuse: secure connection (HTTPS), access management and password encryption.

10. Cookies

This site uses cookies. To find out their nature and how to manage them, see our cookie policy.

11. Minors

This site is intended for a general audience and is not specifically aimed at children. If you are a minor, we invite you to obtain the consent of your legal representative before sending us personal data.

12. Changes

This policy may be amended to reflect changes to the site or the applicable regulations. We invite you to consult it regularly. Last updated: July 2026.