Privacy policy

We respect your right to privacy. Here, in plain language, is what data we collect, why, and how you control it.

Effective from: 10 September 2026 · Version: 1.2

1. Who we are

The controller of your personal data is MTÜ LumiKids, a non-profit association registered in Estonia, registry code 80674528 (the “Foundation”, “we”). For anything related to privacy, write to info@lumiki.org.

We are established in Estonia, in the European Union — the GDPR (Regulation (EU) 2016/679) therefore applies directly to how we handle your data.

2. What data we collect

  • Donations: email (for the receipt and reports), amount, frequency; your name if you choose to give it; whether you asked to stay anonymous.
  • “Circle of Light” subscription: email and the parameters of the recurring payment.
  • Forms (volunteering, partnership, contact): name, email, phone if you give it, the text of your message, company name.
  • Newsletter: email.
  • Technical data: cookies and aggregated visit analytics — only with your consent.

We do not store your card details. They are processed by the payment provider under the PCI DSS standard and never reach our servers.

3. Why we process it, and on what legal basis

  • To process your donation and send you a receipt and report — performance of a contract (Art. 6(1)(b) GDPR).
  • To send the newsletter — your consent (Art. 6(1)(a)), confirmed by double opt-in; you can withdraw it at any time.
  • To handle a volunteer or partnership enquiry — steps taken at your request and our legitimate interest (Art. 6(1)(b), (f)).
  • To improve the site through analytics — your consent (Art. 6(1)(a)), managed by the cookie banner.
  • To meet accounting and charity-reporting obligations — legal obligation (Art. 6(1)(c)).

4. Who we share data with

Only with processors that help us operate, and only to the extent needed:

  • payment providers — to take payments and manage recurring donations;
  • an email delivery service — for thank-you letters and the monthly digest;
  • analytics services — in aggregated form, subject to your consent;
  • our hosting and database provider, which stores the site's data.
  • Meta Platforms Ireland Limited — the Meta Pixel, which shows how our campaigns on Facebook and Instagram perform; it runs only if you allow analytics cookies.

We do not sell your data and we do not pass it on for third-party marketing.

5. International transfers

Your data is processed within the European Economic Area. It leaves the EEA in only two cases. First, where a service provider we use is located in a third country — for such transfers we rely on the European Commission's Standard Contractual Clauses together with supplementary organisational and technical measures. Second, where information about a specific fundraiser has to be shared with our partner charitable foundation in Ukraine so that the help reaches the child — limited to what delivering that help requires. On request we will tell you which safeguard applies to a specific transfer.

6. Cookies and analytics

Essential cookies make the site work — they include remembering your cookie choice and your language. Analytics cookies are switched on only after you agree in the banner. You can change your choice at any time by clearing cookies in your browser.

For advertising analytics we use the Meta Pixel (Meta Platforms Ireland Limited). It lets us see how many people reach the site from our Facebook and Instagram campaigns and go on to donate. The pixel is loaded only after you press “Accept all” in the banner; if you choose “Essential only”, it is never loaded and sends nothing. For the data it receives, Meta acts as its own controller under its own privacy policy. To withdraw consent, clear this site’s cookies in your browser — the banner will appear again.

7. How long we keep data

For as long as needed for the purpose the data was collected for, or for as long as the law requires. In particular, accounting documents relating to donations are kept for 7 years, as Estonian accounting law requires. After that, data is deleted or anonymised. Newsletter data is kept until you unsubscribe.

8. Your rights under the GDPR

  • access your data and receive a copy of it;
  • have inaccurate data corrected;
  • have your data erased (“the right to be forgotten”), where no legal ground requires us to keep it;
  • restrict or object to processing, including processing based on legitimate interest;
  • receive your data in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing carried out before withdrawal;
  • lodge a complaint with a data protection authority — in Estonia this is the Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee); you may also complain to the authority in your own country of residence.

To exercise any of these rights, write to info@lumiki.org. We reply within one month, as the GDPR requires.

9. Data security

The site runs over a secure connection (SSL/HSTS). Only authorised team members have access to donor data, protected by two-factor authentication. We apply organisational and technical security measures appropriate to the risk.

10. Children's data

Protecting children is our priority. Photographs and stories of children are published only with the written consent of their parents or guardians, and in line with the Foundation's code of ethics. We change or shorten names and never give precise locations. We do not knowingly collect personal data from children through this site.

11. Automated decision-making

We do not use your data for automated decision-making or profiling that produces legal effects for you.

12. Changes to this policy

We may update this policy. The current version is always on this page, with its effective date. If a change is significant, we will tell subscribers by email.

13. Contact

MTÜ LumiKids, Estonia · registry code 80674528 · Tallinn, Kristiine linnaosa, Pärnu mnt 186, 11314 · +380 67 528 90 71 · +372 5335 6149 · info@lumiki.org