1. Purpose and Commitment
Global Gastronomy Tourism Organization (GGTO) is committed to processing personal data lawfully, fairly and transparently, in accordance with Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on the Protection of Personal Data and the Guarantee of Digital Rights.
This Policy sets out what data is collected through this website, the purposes for which it is processed, the legal bases relied upon, the recipients to whom it may be disclosed, the periods for which it is retained and the rights available to the data subject.
2. Data Controller
The controller of the personal data collected through this website is Global Gastronomy Tourism Organization (GGTO), holder of tax identification number G01907880, with registered address at Calle de Ayala, 45 — 28001 Madrid, Spain.
All matters relating to personal data may be addressed to info@whoiswhogt.com.
3. Scope of Application
This Policy applies to the personal data of applicants for membership, of admitted members whose profiles are published in the Directory, and of professional references named within an application. It does not extend to third-party websites accessible through links published on this site.
No personal data is obtained by observation, profiling or tracking. All data is provided directly by the data subject through the application form.
4. Categories of Data Collected
Only the data required by the membership application is collected. The categories are as follows.
- Identification data: title, given and family names, nationality, country and city of residence.
- Professional data: current position, organisation, professional sector, niches of specialty, areas of interest for networking, professional biography, publications, honours and awards, professional memberships, and motivation for joining.
- Contact data: electronic mail address, WhatsApp number, professional website, LinkedIn and other social media profiles.
- Supporting documentation: two professional photographs and, optionally, a curriculum vitae and any further material the applicant elects to attach.
- Declaration data: the four consents given, the applicant's typed name by way of signature, and the place and date of signing.
- Reference data: where a professional reference is named, the name, position, organisation and electronic mail address of that person.
- Internal data: observations submitted by the applicant and the assessment notes recorded by the review team. These are never published.
5. Purposes and Legal Bases of Processing
- Assessment of the application and the decision on admission — consent of the data subject and the steps taken at the request of the data subject prior to membership (Arts. 6.1.a and 6.1.b GDPR).
- Publication of the professional profile in the printed and digital Directory — the explicit and separate consent of the data subject (Art. 6.1.a), given by means of the publication declaration within the form.
- Inclusion of the photographs within that profile — consent of the data subject, which extends to the rights over that person's image.
- Communications concerning the application and the membership — performance of the relationship between the parties (Art. 6.1.b).
- Compliance with accounting, tax and record-keeping duties — legal obligations to which the controller is subject (Art. 6.1.c).
6. Third-Party Data Provided by the Applicant
Where a professional reference is named, the applicant provides the personal data of another person. The applicant must have informed that person, prior to submission, that the name, position, organisation and electronic mail address have been provided, and that the rights set out in section 11 may be exercised before the controller at any time.
Reference data is processed for one purpose alone: the assessment of the application. References are not added to any distribution list and are not contacted for any other reason.
7. Publication in the Directory
Where an application is accepted and the publication consent has been given, the profile published in the Directory comprises the name and title, position and organisation, country and city of residence, professional sector, niches, areas of interest, professional biography, publications, honours and professional memberships, together with the professional photographs supplied.
The electronic mail address and WhatsApp number are not published on the open web. They are disclosed solely to other members of the Directory who have signed in.
Observations, the identity of the reference, the curriculum vitae, the record of consents and the internal assessment notes are never published, in any edition.
8. Data Sharing and Processors
Personal data is neither sold nor disclosed for advertising purposes. Data is processed on behalf of the controller solely by the providers that operate this service, each under a data processing agreement:
- Supabase — database, file storage and authentication, hosted within the European Union.
- Vercel — website hosting and content delivery.
- The printer and distributor of the printed edition, in respect of the published profile alone.
9. Data Security
Data is transmitted over an encrypted connection and stored encrypted at rest. Access to applications is restricted to the review team, each member holding a personal account.
Uploaded documents are held in private storage that is never publicly addressable and is reachable only through short-lived links issued to authenticated staff. Invitation links are stored solely as a cryptographic hash and may be used once.
10. Data Retention
- Accepted and published members: for the duration of the membership and, thereafter, for the periods required to address any legal claim.
- Applications not accepted or withdrawn: twelve months from the decision, after which they are deleted together with any documents submitted with them.
- Invitations that are not used: until expiry and for twelve months thereafter.
- Record of consents: for the duration of the corresponding processing, as evidence of its lawfulness.
- An edition of the Directory already printed and distributed cannot be recalled or amended. Erasure takes effect within the systems of the controller and in every subsequent edition, digital and printed.
11. Rights of the Data Subject
The data subject may at any time request access to the data, its rectification or erasure, the restriction of its processing and its portability, and may object to the processing. Where processing rests on consent, that consent may be withdrawn at any time, without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of the publication consent removes the profile from the digital Directory and from all future printed editions.
Requests may be addressed to info@whoiswhogt.com and will be answered within one month. In order that data is not disclosed to a third party, confirmation of identity may be requested.
Where the data subject considers that a request has not been properly addressed, a complaint may be lodged with the Spanish Data Protection Agency (Agencia Española de Protección de Datos), C/ Jorge Juan 6, 28001 Madrid, www.aepd.es.
12. Modifications to this Policy
Where the manner in which personal data is processed changes, the revised Policy will be published on this page bearing a new date. Where a modification materially affects the data subject, notice will be given by electronic mail.