Terms of service

Last Updated: June, 2026

1.  Data Controller

The entity responsible for processing personal data through the RBE Hub is:

REN21 Secretariat
158 ter rue du Temple, 75003 Paris, France
Email: secretariat@ren21.net
Website: www.ren21.net
Siret: 799 234 075 00015

REN21 processes personal data in compliance with the EU General Data Protection Regulation (GDPR) and applicable French data protection law. REN21 does not have a formal Data Protection Officer (DPO) but has designated a Data Protection Lead within the Secretariat as the primary point of contact for all privacy matters.

 

2.  What Personal Data We Collect

Depending on how you interact with the RBE Hub, we may collect the following categories of personal data:

  • Professional contact data: Contact information
    • Name, job title, organisation, email address, country.
    • Collected when you contact us, subscribe to communications, or participate in REN21 activities.
  • Submitted content:
    • Information you provide through forms, surveys, peer review processes, or consultation contributions.
  • Platform usage data:
    • Anonymised or pseudonymised data about how you navigate and use the RBE Hub (pages visited, session duration, referral source, device type, browser type, geographic region at country level).
    • Collected automatically via analytics tools. No individual user profiles are created.
  • Communication engagement data:
    • If you subscribe to REN21 newsletters, we may record whether emails are opened and which links are clicked.
    • This data is used only to improve our communications and is not used for commercial profiling.
  • Technical and security data:
    • IP addresses, server access logs, HTTP metadata. Collected automatically for security and fraud prevention purposes only. Retained for a maximum of 90 days.

We only collect personal data that is relevant and necessary for the purposes described in this Privacy Notice.

 

3. Legal Basis for Processing

Under GDPR Article 6, REN21 must have a legal basis for each data processing activity. The table below sets out the legal basis applicable to each purpose:

Purpose Description Legal Basis (Art. 6 GDPR) Notes
Newsletter subscription Sending REN21 updates, publications and event invitations to subscribers. Art. 6(1)(a) — Consent You may withdraw consent at any time by unsubscribing.
Responding to enquiries Handling messages, requests and correspondence submitted via the platform or email. Art. 6(1)(f) — Legitimate interests REN21’s interest in managing stakeholder communications.
Web analytics Understanding how users navigate the RBE Hub to improve content and usability. Art. 6(1)(f) — Legitimate interests IP anonymisation applied. Opt-out available via cookie consent banner.
Email engagement analytics Tracking open rates and link clicks in newsletters sent to opted-in subscribers. Art. 6(1)(f) — Legitimate interests Only applies within existing consent relationship. Opt-out via unsubscribe.
Stakeholder & member CRM Managing professional relationships with REN21 members, experts, partners and institutional stakeholders in Microsoft Dynamics 365. Art. 6(1)(f) — Legitimate interests Professional contact data only. Deletion available on request.
Peer review & consultations Processing contributions and contact data of participants in REN21 knowledge processes. Art. 6(1)(b) — Contract / Art. 6(1)(f) — Legitimate interests Depends on nature of participation agreement.
Security logging Detecting and preventing unauthorised access, DDoS attacks and security incidents. Art. 6(1)(f) — Legitimate interests Explicitly recognised in GDPR Recital 49. Logs deleted after 90 days.
Legal compliance Meeting legal obligations, including responding to lawful requests from authorities. Art. 6(1)(c) — Legal obligation

Legitimate interests: Where REN21 relies on legitimate interests as its legal basis, a Legitimate Interests Assessment (LIA) has been conducted and is maintained internally. It is available to data subjects upon request by emailing secretariat@ren21.net.

4.  Cookies and Similar Technologies

The RBE Hub uses cookies and similar technologies. Cookies are small text files stored on your device when you visit a website. We use two categories of cookies:

4.1  Strictly Necessary Cookies

These cookies are essential for the RBE Hub to function correctly. They cannot be switched off. They do not require your consent. They include:

  • Session management and security cookies (preventing cross-site request forgery).
  • Load-balancing and technical delivery cookies set by our hosting provider (Webflow).
  • Cookie consent preference storage (to remember your choices).

4.2  Analytics and Performance Cookies (Optional)

These cookies are not essential. They require your consent before being activated. They help us understand how visitors use the RBE Hub, which pages are most visited, and where users encounter difficulties.

  • We use Google Analytics (with IP anonymisation enabled).
  • Data generated by these cookies is aggregated and does not identify you personally.
  • You may accept, decline or change your preferences at any time via the cookie consent banner displayed on your first visit.
  • You may also use the Google Analytics opt-out browser add-on (available at tools.google.com/dlpage/gaoptout).

Your consent for optional cookies is obtained before any analytics cookies are activated. Declining analytics cookies does not affect your access to any content or features of the RBE Hub.

5.  How We Collect Personal Data

We collect personal data through the following means:

  • Directly, when you subscribe to newsletters, contact REN21, register for events, or participate in surveys, peer reviews or consultations.
  • Automatically, when you browse the RBE Hub: technical and usage data is collected via cookies and server logs (subject to your cookie preferences).
  • Through contributions, when you submit data, insights or expert input to the RBE Hub.
  • Through communication, when you interact with REN21 emails (open and click events, where analytics cookies are accepted or within the scope of legitimate interests for opted-in subscribers).

 

6.  How We Use Personal Data

Personal data collected through the RBE Hub is used to:

  • Provide access to REN21 knowledge resources and platform services.
  • Respond to enquiries, requests and correspondence.
  • Manage newsletter subscriptions and send communications to opted-in subscribers.
  • Improve the RBE Hub platform, content and user experience through analytics.
  • Manage professional relationships with REN21 members, partners, experts and institutional stakeholders.
  • Conduct peer reviews, surveys and collaborative research activities.
  • Produce aggregated and fully anonymised statistics for reporting purposes.
  • Protect the security and integrity of the RBE Hub and its users.
  • Comply with legal obligations.

 REN21 does not use personal data for automated decision-making or profiling. No individual is subject to decisions based solely on automated processing that produce legal or similarly significant effects (GDPR Article 22).

7.  Service Providers and Data Processors

REN21 works with trusted third-party service providers who process personal data on its behalf. All processors are bound by Data Processing Agreements (DPAs) in accordance with GDPR Article 28.

Provider Purpose Safeguards
Webflow Inc. Website hosting and delivery DPA in place. US data transfers under Standard Contractual Clauses (SCCs).
Google LLC (Analytics) Website analytics and usage measurement DPA in place. IP anonymisation enabled. US data transfers under SCCs. Activated only with consent.
Microsoft Corporation (Dynamics 365) Stakeholder relationship and communications management (CRM) DPA in place. US data transfers under SCCs. Professional contact data only.

 Personal data may also be disclosed where required by applicable law or to protect REN21’s legal rights. REN21 does not sell, rent or trade personal data.

8.  International Data Transfers

Some of REN21’s service providers operate outside the European Economic Area (EEA), including in the United States. Where personal data is transferred internationally, REN21 applies appropriate safeguards as required by GDPR Chapter V, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, currently in place with Webflow, Google, and Microsoft.
  • Data minimisation measures, ensuring only necessary data is transferred to processors.
  • IP anonymisation for analytics data before any international transfer occurs.

You may request information about the specific safeguards applicable to international transfers by contacting secretariat@ren21.net.

 

9.  Data Retention

REN21 retains personal data only for as long as necessary to fulfil the purposes for which it was collected, subject to applicable legal and operational requirements. The following retention periods apply:

Data category Retention period Deletion trigger
Newsletter subscriber data Duration of subscription + 12 months Unsubscribe request or 12 months of inactivity.
Email engagement data (open/click rates) 24 months Rolling deletion; also deleted within 30 days of unsubscribe.
Professional contact / CRM records Duration of relationship + 3 years Annual review; inactive contacts deleted or re-confirmed after 3 years.
Web analytics data (session-level) 14 months Automatic deletion configured in analytics platform.
Web analytics data (aggregated) Indefinite Aggregated data carries no individual identifiers.
Security / server logs 90 days Automatic deletion; extended only in the event of an active security incident.
Survey and peer review contributions Duration of relevant project + 5 years Aligned with REN21’s standard project record-keeping policy.
Correspondence and enquiry records 3 years from last interaction Assessed at annual data review.

When data is no longer required, it is securely deleted or irreversibly anonymised.

10.  Your Rights

Under the GDPR, you have the following rights in relation to your personal data:

Right What it means How to exercise it
Access (Art. 15) Request a copy of the personal data REN21 holds about you. Email secretariat@ren21.net with subject: Data Access Request.
Rectification (Art. 16) Request correction of inaccurate or incomplete personal data. Email secretariat@ren21.net with the correction required.
Erasure (Art. 17) Request deletion of your personal data (‘right to be forgotten’), subject to legal exceptions. Email secretariat@ren21.net with subject: Erasure Request.
Restriction (Art. 18) Request that REN21 restricts processing of your data in certain circumstances. Email secretariat@ren21.net with details of your request.
Objection (Art. 21) Object to processing based on legitimate interests. REN21 must stop unless it demonstrates compelling grounds. Email secretariat@ren21.net with subject: Objection to Processing.
Portability (Art. 20) Receive your personal data in a structured, machine-readable format (applies to consent-based processing). Email secretariat@ren21.net with subject: Data Portability Request.
Withdraw consent (Art. 7(3)) Withdraw consent for newsletter subscriptions or analytics cookies at any time, without affecting past processing. Use unsubscribe link in emails, or update cookie preferences via the banner.
Complaint (Art. 77) Lodge a complaint with a data protection supervisory authority. Contact the CNIL (see below).

Response timeframe. REN21 will acknowledge all rights requests within 72 hours and provide a full response within one calendar month of receipt. In complex cases, this period may be extended by a further two months, with notice given to you within the first month (GDPR Article 12(3)).

Supervisory Authority

If you believe your data protection rights have not been respected, you have the right to lodge a complaint with the competent supervisory authority in France:

Commission Nationale de l’Informatique et des Libertés (CNIL)

3 place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07
Website: www.cnil.fr — Telephone: +33 1 53 73 22 22

11.  Newsletter Communications

REN21 sends newsletters, updates and event invitations to individuals who have actively subscribed. By subscribing, you consent to receive these communications.

  • Newsletters may include engagement analytics (open events, link clicks) to help REN21 improve the relevance and quality of its communications. This is disclosed in Section 3 (legal basis: legitimate interests within the existing consent relationship).
  • You may unsubscribe at any time using the unsubscribe link included in every email. Upon unsubscribing, your subscriber data will be deleted within 30 days.
  • Unsubscribing from newsletters does not affect any other data REN21 holds about you in its professional network (e.g. CRM records relating to your institutional membership or event participation).

 

12.  Automated Decision-Making and Profiling

REN21 does not engage in automated decision-making or profiling within the meaning of GDPR Article 22. No decisions with legal or significant effects are made about individuals based solely on automated processing of their personal data. Analytics and CRM data are used only by human members of the Secretariat to improve REN21’s programmes and communications.

13.  Security

REN21 implements technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include:

  • Encrypted data transmission (TLS/HTTPS) across the RBE Hub.
  • Access controls restricting personal data to Secretariat staff with a legitimate operational need.
  • Data Processing Agreements with all third-party processors.
  • Security log monitoring and incident response procedures.
  • Regular review of data protection practices.

While no digital system can guarantee absolute security, REN21 is committed to maintaining appropriate cybersecurity practices. In the event of a personal data breach likely to result in a risk to individuals, REN21 will notify the CNIL within 72 hours of becoming aware of the breach, and affected individuals where the risk is high (GDPR Articles 33–34).

14.  Changes to this Privacy Notice

REN21 implements technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure. These include:

Current version 1.0
Last updated May 2026
Previous version N/A — this is the initial version for the RBE Hub platform
Next scheduled review May 2027 or upon material change to processing activities

15.  Contact Us

For any questions, requests or concerns relating to this Privacy Notice or the processing of your personal data, please contact:

REN21 Data Protection Lead

REN21 Secretariat
158 ter rue du Temple, 75003 Paris, France
Email: secretariat@ren21.net

Built through crowd-sourced and crowd-owned data and insights

The RBE Hub is shaped by researchers, governments, industry associations and civil society organisations contributing data, analysis and expertise from around the world.

We use cookies on this site to enhance your user experience. By clicking the Accept button, you agree to us doing so. Terms of Service
cookie