
DATA PROTECTION
Any personal data we collect will be in compliance with the General Data Protection Regulation in the European Union.
-
Only Collecting What’s Needed: We’ll only gather the information that’s absolutely necessary for our work. We won’t ask for or keep extra data that isn’t relevant to the project.
-
Clear Consent and Explanation: Before we collect any personal information, we’ll ask for permission and explain exactly why we need it, how we’ll use it, and what rights people have over their information. This includes the right to see, change, or delete their data if they want.
-
Keeping Data Secure: We’ll make sure any personal data we collect is stored securely, using protections like passwords or encryption (scrambling data so it can only be read with a special code) to prevent unauthorized access.
-
Deleting Data When It’s No Longer Needed: We’ll only keep people’s personal information as long as necessary for the project. Once it’s no longer needed, or if someone requests it, we’ll delete it. This is in line with GDPR’s “right to be forgotten.”
-
Identifying Privacy Risks for Sensitive Projects: If a project involves sensitive data or has a higher chance of privacy concerns, we’ll conduct a Data Protection Impact Assessment (DPIA). This is a check we do to find any privacy risks early on, so we can address them right away and keep data safe.
-
Third-Party Partners and Data Transfers: If we need to share data with any outside partners, we’ll make sure they follow GDPR rules, too. If data has to go outside the EU, we’ll use special agreements to ensure it’s handled safely and legally, even in other countries.