Policies and legal information

Website Privacy Notice

How we handle information provided by visitors and users of Website forms and digital services.

Purpose and scope

This Notice covers Website visits and general contact, research, data, privacy, complaint, error-report, and digital-service interactions. It does not replace a study-specific privacy notice given to a research participant.

Responsible organization

ItemValue
OrganizationPalestine Polling Center
Privacy email[Privacy email]
General email[General email]
Address[To be added after legal address approval]

Information provided by users

  • Name, email, and telephone.
  • Organization, role, country, and language.
  • Request subject and message.
  • Study or project name, deadline, and approximate budget.
  • Attachments and preferences.
  • Complaint, privacy, or data-request information.

Information collected automatically

  • Network address, device, browser, and operating system.
  • Language, pages, date, time, and referral source.
  • Session duration, errors, and login attempts.
  • Session identifiers and cookie preferences.
  • Automated-abuse protection indicators.

Other sources

Information may come from an organization represented by the user, a commissioner, partner, technology provider, registration platform, verification service, referring organization, or public source where lawful and necessary.

Sensitive information

General forms do not ordinarily request sensitive information, but some complaints or requests may concern politics, health, safeguarding, disability, children, beliefs, finance, family, or employment. Such information is restricted and used only as necessary.

Information not to send through general forms

  • Participant lists or named datasets.
  • Identification numbers, bulk telephone lists, or precise addresses.
  • Health records or detailed children’s data.
  • Passwords or banking information.
  • Identifiable safeguarding disclosures.
  • Nonanonymized research files.
  • Highly confidential commercial documents.

Purposes

  • Respond and route messages.
  • Assess research requests and prepare proposals.
  • Process data, privacy, and complaint requests.
  • Correct published material.
  • Manage accounts, events, or subscriptions.
  • Protect the Website and prevent abuse.
  • Improve performance and accessibility.
  • Maintain professional and contractual records.
  • Meet obligations and protect rights.

Basis for processing

The basis depends on the interaction and applicable law and may include consent, precontractual steps, agreement performance, legal duty, vital interests, public interest, or legitimate institutional interests. Wording should be reviewed after jurisdiction is established.

Consent

Where relied upon, consent is clear, specific, voluntary, and withdrawable. Withdrawal does not invalidate earlier use and may not require deletion where another contract, legal, complaint, or safeguarding basis applies.

General inquiries and research requests

Contact details and message content are used to understand, answer, route, and record inquiries. Research-request information supports feasibility, expertise identification, proposals, and negotiation and may be shared with a potential specialist only as necessary and confidential.

Data-access requests

Information may be used to verify requester identity, organization, purpose, variables, users, protection, and deletion and to decide access and administer the agreement.

Complaints

Complaint information supports registration, priority assessment, protection, review, communication, action, recordkeeping, and retaliation prevention. Complainant identity is restricted where consistent with review and fairness.

Privacy requests

Identity may need verification and relevant records located to prevent unauthorized disclosure and document the outcome. A full identity document should not be sent unless securely and proportionately requested.

Newsletters and updates

Optional messages are sent only under an appropriate choice or basis and may be unsubscribed. Necessary account, contract, or request messages may continue. General contact does not create automatic subscription.

Accounts and restricted services

  • Name, email, and organization.
  • Hashed or encrypted credential information.
  • Logins, permissions, and downloads.
  • Terms acceptance, failed logins, and changes.

Events and meetings

Information may manage registration, access links or location, changes, attendance, materials, and feedback. Recording or photography requires notice.

Comments and contributions

Future public features should explain what becomes public, what remains internal, moderation, deletion, and rights. Sensitive information should not be entered into public fields.

Analytics and cookies

Aggregate or limited technical information may measure visits, pages, devices, errors, and performance. Necessary technologies may manage sessions, language, and protection; optional technologies operate only under applicable choices.

Automated-abuse tools and server logs

Protection services may collect device, connection, and interaction information. Hosting logs may support security, diagnostics, and attack prevention. Collection and retention are limited to need.

Recipients

  • Authorized personnel and relevant researchers or consultants.
  • Partners and contractors within purpose.
  • Hosting, email, form, storage, meeting, and security providers.
  • Legal or professional advisers.
  • Commissioners or partners where necessary and lawful.
  • Competent authorities for obligation or protection.

Service providers

Arrangements should define purpose, data, duration, confidentiality, security, deletion, subprocessors, and incident notice. Providers do not independently use information without an appropriate basis and notice.

Partners and commissioners

Where another organization helps determine purpose or receives information, a specific notice explains roles and rights. A commissioner does not automatically receive all information simply because it funded or requested the work.

Legal or protective disclosure

Only necessary information may be disclosed to comply with lawful orders, protect a person from serious harm, investigate fraud, protect rights, defend claims, or cooperate with competent authorities.

No sale or undisclosed targeting

The Center does not sell personal information to advertisers or brokers and does not use it for undisclosed political or commercial targeting. Future advertising tools would require prior notice and controls.

International processing

Hosting, email, cloud, support, or partners may process information in another country. Sensitivity, location, contract, encryption, rights, necessity, and safeguards are assessed.

Storage

Information may be stored in institutional systems, devices, email, hosting, cloud, project-management, complaint, or secure-data environments. Sensitive information should not remain in unapproved personal accounts.

Retention

Information is not retained longer than necessary. Duration depends on request type, contract, project, audit, complaints, law, sensitivity, and deletion or anonymization feasibility.

Record typeProvisional approach
General inquiryUntil follow-up ends, then delete or retain minimally.
Research requestDuring proposal and negotiation and a defined professional period.
Contract correspondenceDuring contract and required post-contract period.
Data or privacy requestDuring review, completion, and outcome documentation.
ComplaintAccording to sensitivity, accountability, and retaliation prevention.
AccountWhile active and for a limited security period after closure.
Security logsIn proportion to investigation and protection.
SubscriptionUntil unsubscribe or service closure.

Deletion and anonymization

When no longer needed, information may be deleted, removed from active systems, restricted in archives, anonymized, aggregated, or reduced to a compliance record. Backup copies may persist temporarily until routine replacement.

Security

  • Encrypted connections and institutional accounts.
  • Multifactor authentication and restricted access.
  • Backups, updates, and access monitoring.
  • Sensitive-data separation, training, and confidentiality.
  • Vendor review and incident response.

User security

  • Send only necessary information.
  • Protect accounts and passwords.
  • Verify the official domain.
  • Avoid suspicious links.
  • Report compromise or impersonation.
  • Use care on shared devices.

Data incidents

Incidents may include misaddressed email, lost devices, compromise, public file links, dashboard exposure, or unauthorized access. Response considers data type, people, harm, containment, notification, and prevention.

User rights

  • Know whether information is held.
  • Obtain a copy where applicable.
  • Correct inaccuracies.
  • Request deletion, restriction, or objection.
  • Withdraw consent.
  • Request portability where applicable.
  • Seek review of consequential automated decisions.
  • Complain.

Rights limitations

Other people’s rights, trade secrets, legal privilege, danger, legitimate investigations, contracts, or legal duties may limit fulfillment. Access does not automatically include third-party data.

Submitting a request

Submit to [Privacy email] or the privacy form with name, contact, request type, service, period, record-locating information, and response method.

Submit a Privacy Request

Verification and representatives

Proportionate verification or authority evidence may be required from a parent, guardian, or representative. Requests may be delayed or refused where reasonable verification is impossible.

Response and fees

The process covers confirmation, clarification, search, assessment, completion or explanation, and documentation. Applicable law determines final timing. Ordinary requests should not normally incur a fee, subject to lawful treatment of excessive, repetitive, or abusive requests.

Review and complaints

Users may request internal review, clarify scope, complain to a competent authority after jurisdiction is identified, or use available legal remedies.

Children

The general Website does not target children’s information. If a child submits information, retention is minimized and a responsible adult may be involved where appropriate and safe. Research involving children uses separate notices and safeguards.

External links and social media

External services and social platforms process information under their own policies. Sensitive complaints and data should not be sent through direct messages unless a designated secure channel exists.

Organizational change

If the Center restructures, merges, or transfers an activity, relevant information may transfer to a successor subject to purpose, protection, notice, contractual limits, and consent.

Changes, language, and dates

The Notice may change with services, providers, accounts, portals, analytics, law, or incidents. Arabic and English are available; the controlling or equally authoritative version is determined after review.

ItemValue
Effective date[To be added after approval]
Latest update[To be added when revised]
Version1.0 – launch draft

Data by interaction channel

ChannelIllustrative information
General contactName, email, organization, subject, message, and attachments.
Research requestScope, questions, timing, budget, and documents.
Data requestIdentity, organization, purpose, variables, and protection plan.
ComplaintEvent, persons, project, evidence, and requested outcome.
AccountRegistration, permissions, login, and download records.
Event or newsletterRegistration, preferences, and consent record.

Data minimization

Forms should collect only what the purpose requires. Unused fields should be removed, optional fields clearly marked, duplication across systems avoided, and a complete identity document not requested where a less intrusive verification method is sufficient.

General messages do not create a subscription

An inquiry, research request, complaint, or download does not automatically subscribe the user to a newsletter or marketing. Optional communication requires a clear choice and may be stopped while necessary messages about a request, contract, or account continue.

Website analytics detail

If analytics are enabled, identifiers and retention should be minimized and advertising and unnecessary sharing disabled. The current package has no analytics or advertising enabled, and this Notice and the cookie register must be updated before a provider is added.

Automated decisions

The Website is not intended to make consequential individual decisions solely through automated processing. A future service doing so would explain the decision, information, general logic, effect, human-review right, and appeal.

Illustrative detailed retention

Record typeProposed approach before final periods are approved
General inquiryUntil follow-up is complete, then delete or retain a limited archive.
Proposal requestDuring assessment and negotiation and for a defined professional period.
Contract correspondenceDuring performance and the required legal or audit period.
Data requestDuring assessment, access, follow-up, and compliance documentation.
ComplaintAccording to sensitivity, accountability, recurrence prevention, and claims.
Privacy requestLong enough to document verification and response.
Security logIn proportion to investigation and protection needs.
Mailing subscriptionUntil unsubscribe or service closure, with a suppression record where needed.

Access right

A request may cover data categories, purposes, recipients, retention, source, international safeguards, and a copy. It does not automatically include other people’s data, trade secrets, legally privileged material, or information that would expose someone to harm.

Correction right

A user may request correction of name, email, organization, contact method, or an inaccurate record. Proportionate evidence may be requested where the change is material or affects another person’s rights or restricted access.

Deletion request

Deletion may apply where information is no longer needed, consent is withdrawn without another basis, or use was unlawful. Retention may remain necessary for a contract, legal duty, complaint, claim, safeguarding, fraud prevention, or protected research.

Objection and restriction

A user may request a defined use to stop, access to be restricted, optional messages to cease, or processing to pause while accuracy is reviewed. The request is balanced against purpose, basis, other rights, and obligations.

Withdrawal of consent

Consent may be withdrawn for newsletters, optional cookies, recording or photography, or defined voluntary sharing. Withdrawal does not invalidate prior lawful use and does not stop processing based on a contract, duty, or separate basis.

Portability

Certain information provided by a user may be available in a structured format where applicable law covers automated processing based on consent or contract. The Center is not required to create new information or disclose other people’s rights.

Requests through representatives

A parent, guardian, legal representative, or authorized person may submit a request with evidence proportionate to sensitivity. Information is not disclosed to a person merely claiming representation without reasonable verification.

Fees and excessive requests

An ordinary request is not normally charged. Applicable law may permit a reasonable fee or refusal for manifestly excessive or abusive repetition, but fees are not used to prevent a legitimate right.

Supervisory authority

Details of the competent supervisory authority will be added after the Center’s legal jurisdiction is determined. Until then, an internal review may be requested and available legal rights used in the relevant location.

Data-incident notification

Need for notification is assessed according to information type, likelihood of harm, safeguards, law, and agreement. A notice should explain what happened, affected information, measures, and steps the person may take.

Social-media communication

Messages and comments are also governed by platform rules. Sensitive complaints or datasets should not be sent by direct message; the Center may move the discussion to a safer channel and remove or restrict unnecessary copies.

Contact and dates

ItemStatus
Privacy email[privacy@palestinepollingcenter.org or another approved address]
General email[General email]
Address[To be added after legal address approval]
Supervisory authority[To be added after jurisdiction is determined]
Effective date[To be added after approval]
Latest update[To be added when revised]
Version1.0 on first approval