Policies and legal information

Website Privacy Notice

How we handle information provided by visitors and users of Website forms and digital services.

Purpose and scope

This Notice covers Website visits and general contact, research, data, privacy, complaint, error-report, and digital-service interactions. It does not replace a study-specific privacy notice given to a research participant.

Responsible organization

ItemValue
OrganizationPalestine Polling Center
Privacy email[Privacy email]
General email[General email]
Address[To be added after legal address approval]

Information provided by users

  • Name, email, and telephone.
  • Organization, role, country, and language.
  • Request subject and message.
  • Study or project name, deadline, and approximate budget.
  • Attachments and preferences.
  • Complaint, privacy, or data-request information.

Information collected automatically

  • Network address, device, browser, and operating system.
  • Language, pages, date, time, and referral source.
  • Session duration, errors, and login attempts.
  • Session identifiers and cookie preferences.
  • Automated-abuse protection indicators.

Other sources

Information may come from an organization represented by the user, a commissioner, partner, technology provider, registration platform, verification service, referring organization, or public source where lawful and necessary.

Sensitive information

General forms do not ordinarily request sensitive information, but some complaints or requests may concern politics, health, safeguarding, disability, children, beliefs, finance, family, or employment. Such information is restricted and used only as necessary.

Information not to send through general forms

  • Participant lists or named datasets.
  • Identification numbers, bulk telephone lists, or precise addresses.
  • Health records or detailed children’s data.
  • Passwords or banking information.
  • Identifiable safeguarding disclosures.
  • Nonanonymized research files.
  • Highly confidential commercial documents.

Purposes

  • Respond and route messages.
  • Assess research requests and prepare proposals.
  • Process data, privacy, and complaint requests.
  • Correct published material.
  • Manage accounts, events, or subscriptions.
  • Protect the Website and prevent abuse.
  • Improve performance and accessibility.
  • Maintain professional and contractual records.
  • Meet obligations and protect rights.

Basis for processing

The basis depends on the interaction and applicable law and may include consent, precontractual steps, agreement performance, legal duty, vital interests, public interest, or legitimate institutional interests. Wording should be reviewed after jurisdiction is established.

Consent

Where relied upon, consent is clear, specific, voluntary, and withdrawable. Withdrawal does not invalidate earlier use and may not require deletion where another contract, legal, complaint, or safeguarding basis applies.

General inquiries and research requests

Contact details and message content are used to understand, answer, route, and record inquiries. Research-request information supports feasibility, expertise identification, proposals, and negotiation and may be shared with a potential specialist only as necessary and confidential.

Data-access requests

Information may be used to verify requester identity, organization, purpose, variables, users, protection, and deletion and to decide access and administer the agreement.

Complaints

Complaint information supports registration, priority assessment, protection, review, communication, action, recordkeeping, and retaliation prevention. Complainant identity is restricted where consistent with review and fairness.

Privacy requests

Identity may need verification and relevant records located to prevent unauthorized disclosure and document the outcome. A full identity document should not be sent unless securely and proportionately requested.

Newsletters and updates

Optional messages are sent only under an appropriate choice or basis and may be unsubscribed. Necessary account, contract, or request messages may continue. General contact does not create automatic subscription.

Accounts and restricted services

  • Name, email, and organization.
  • Hashed or encrypted credential information.
  • Logins, permissions, and downloads.
  • Terms acceptance, failed logins, and changes.

Events and meetings

Information may manage registration, access links or location, changes, attendance, materials, and feedback. Recording or photography requires notice.

Comments and contributions

Future public features should explain what becomes public, what remains internal, moderation, deletion, and rights. Sensitive information should not be entered into public fields.

Analytics and cookies

Aggregate or limited technical information may measure visits, pages, devices, errors, and performance. Necessary technologies may manage sessions, language, and protection; optional technologies operate only under applicable choices.

Automated-abuse tools and server logs

Protection services may collect device, connection, and interaction information. Hosting logs may support security, diagnostics, and attack prevention. Collection and retention are limited to need.

Recipients

  • Authorized personnel and relevant researchers or consultants.
  • Partners and contractors within purpose.
  • Hosting, email, form, storage, meeting, and security providers.
  • Legal or professional advisers.
  • Commissioners or partners where necessary and lawful.
  • Competent authorities for obligation or protection.

Service providers

Arrangements should define purpose, data, duration, confidentiality, security, deletion, subprocessors, and incident notice. Providers do not independently use information without an appropriate basis and notice.

Partners and commissioners

Where another organization helps determine purpose or receives information, a specific notice explains roles and rights. A commissioner does not automatically receive all information simply because it funded or requested the work.

Legal or protective disclosure

Only necessary information may be disclosed to comply with lawful orders, protect a person from serious harm, investigate fraud, protect rights, defend claims, or cooperate with competent authorities.

No sale or undisclosed targeting

The Center does not sell personal information to advertisers or brokers and does not use it for undisclosed political or commercial targeting. Future advertising tools would require prior notice and controls.

International processing

Hosting, email, cloud, support, or partners may process information in another country. Sensitivity, location, contract, encryption, rights, necessity, and safeguards are assessed.

Storage

Information may be stored in institutional systems, devices, email, hosting, cloud, project-management, complaint, or secure-data environments. Sensitive information should not remain in unapproved personal accounts.

Retention

Information is not retained longer than necessary. Duration depends on request type, contract, project, audit, complaints, law, sensitivity, and deletion or anonymization feasibility.

Record typeProvisional approach
General inquiryUntil follow-up ends, then delete or retain minimally.
Research requestDuring proposal and negotiation and a defined professional period.
Contract correspondenceDuring contract and required post-contract period.
Data or privacy requestDuring review, completion, and outcome documentation.
ComplaintAccording to sensitivity, accountability, and retaliation prevention.
AccountWhile active and for a limited security period after closure.
Security logsIn proportion to investigation and protection.
SubscriptionUntil unsubscribe or service closure.

Deletion and anonymization

When no longer needed, information may be deleted, removed from active systems, restricted in archives, anonymized, aggregated, or reduced to a compliance record. Backup copies may persist temporarily until routine replacement.

Security

  • Encrypted connections and institutional accounts.
  • Multifactor authentication and restricted access.
  • Backups, updates, and access monitoring.
  • Sensitive-data separation, training, and confidentiality.
  • Vendor review and incident response.

User security

  • Send only necessary information.
  • Protect accounts and passwords.
  • Verify the official domain.
  • Avoid suspicious links.
  • Report compromise or impersonation.
  • Use care on shared devices.

Data incidents

Incidents may include misaddressed email, lost devices, compromise, public file links, dashboard exposure, or unauthorized access. Response considers data type, people, harm, containment, notification, and prevention.

User rights

  • Know whether information is held.
  • Obtain a copy where applicable.
  • Correct inaccuracies.
  • Request deletion, restriction, or objection.
  • Withdraw consent.
  • Request portability where applicable.
  • Seek review of consequential automated decisions.
  • Complain.

Rights limitations

Other people’s rights, trade secrets, legal privilege, danger, legitimate investigations, contracts, or legal duties may limit fulfillment. Access does not automatically include third-party data.

Submitting a request

Submit to [Privacy email] or the privacy form with name, contact, request type, service, period, record-locating information, and response method.

Submit a Privacy Request

Verification and representatives

Proportionate verification or authority evidence may be required from a parent, guardian, or representative. Requests may be delayed or refused where reasonable verification is impossible.

Response and fees

The process covers confirmation, clarification, search, assessment, completion or explanation, and documentation. Applicable law determines final timing. Ordinary requests should not normally incur a fee, subject to lawful treatment of excessive, repetitive, or abusive requests.

Review and complaints

Users may request internal review, clarify scope, complain to a competent authority after jurisdiction is identified, or use available legal remedies.

Children

The general Website does not target children’s information. If a child submits information, retention is minimized and a responsible adult may be involved where appropriate and safe. Research involving children uses separate notices and safeguards.

External links and social media

External services and social platforms process information under their own policies. Sensitive complaints and data should not be sent through direct messages unless a designated secure channel exists.

Organizational change

If the Center restructures, merges, or transfers an activity, relevant information may transfer to a successor subject to purpose, protection, notice, contractual limits, and consent.

Changes, language, and dates

The Notice may change with services, providers, accounts, portals, analytics, law, or incidents. Arabic and English are available; the controlling or equally authoritative version is determined after review.

ItemValue
Effective date[To be added after approval]
Latest update[To be added when revised]
Version1.0 – launch draft