Purpose and scope
This Notice covers Website visits and general contact, research, data, privacy, complaint, error-report, and digital-service interactions. It does not replace a study-specific privacy notice given to a research participant.
Responsible organization
| Item | Value |
|---|---|
| Organization | Palestine Polling Center |
| Privacy email | [Privacy email] |
| General email | [General email] |
| Address | [To be added after legal address approval] |
Information provided by users
- Name, email, and telephone.
- Organization, role, country, and language.
- Request subject and message.
- Study or project name, deadline, and approximate budget.
- Attachments and preferences.
- Complaint, privacy, or data-request information.
Information collected automatically
- Network address, device, browser, and operating system.
- Language, pages, date, time, and referral source.
- Session duration, errors, and login attempts.
- Session identifiers and cookie preferences.
- Automated-abuse protection indicators.
Other sources
Information may come from an organization represented by the user, a commissioner, partner, technology provider, registration platform, verification service, referring organization, or public source where lawful and necessary.
Sensitive information
General forms do not ordinarily request sensitive information, but some complaints or requests may concern politics, health, safeguarding, disability, children, beliefs, finance, family, or employment. Such information is restricted and used only as necessary.
Information not to send through general forms
- Participant lists or named datasets.
- Identification numbers, bulk telephone lists, or precise addresses.
- Health records or detailed children’s data.
- Passwords or banking information.
- Identifiable safeguarding disclosures.
- Nonanonymized research files.
- Highly confidential commercial documents.
Purposes
- Respond and route messages.
- Assess research requests and prepare proposals.
- Process data, privacy, and complaint requests.
- Correct published material.
- Manage accounts, events, or subscriptions.
- Protect the Website and prevent abuse.
- Improve performance and accessibility.
- Maintain professional and contractual records.
- Meet obligations and protect rights.
Basis for processing
The basis depends on the interaction and applicable law and may include consent, precontractual steps, agreement performance, legal duty, vital interests, public interest, or legitimate institutional interests. Wording should be reviewed after jurisdiction is established.
Consent
Where relied upon, consent is clear, specific, voluntary, and withdrawable. Withdrawal does not invalidate earlier use and may not require deletion where another contract, legal, complaint, or safeguarding basis applies.
General inquiries and research requests
Contact details and message content are used to understand, answer, route, and record inquiries. Research-request information supports feasibility, expertise identification, proposals, and negotiation and may be shared with a potential specialist only as necessary and confidential.
Data-access requests
Information may be used to verify requester identity, organization, purpose, variables, users, protection, and deletion and to decide access and administer the agreement.
Complaints
Complaint information supports registration, priority assessment, protection, review, communication, action, recordkeeping, and retaliation prevention. Complainant identity is restricted where consistent with review and fairness.
Privacy requests
Identity may need verification and relevant records located to prevent unauthorized disclosure and document the outcome. A full identity document should not be sent unless securely and proportionately requested.
Newsletters and updates
Optional messages are sent only under an appropriate choice or basis and may be unsubscribed. Necessary account, contract, or request messages may continue. General contact does not create automatic subscription.
Accounts and restricted services
- Name, email, and organization.
- Hashed or encrypted credential information.
- Logins, permissions, and downloads.
- Terms acceptance, failed logins, and changes.
Events and meetings
Information may manage registration, access links or location, changes, attendance, materials, and feedback. Recording or photography requires notice.
Comments and contributions
Future public features should explain what becomes public, what remains internal, moderation, deletion, and rights. Sensitive information should not be entered into public fields.
Analytics and cookies
Aggregate or limited technical information may measure visits, pages, devices, errors, and performance. Necessary technologies may manage sessions, language, and protection; optional technologies operate only under applicable choices.
Automated-abuse tools and server logs
Protection services may collect device, connection, and interaction information. Hosting logs may support security, diagnostics, and attack prevention. Collection and retention are limited to need.
Recipients
- Authorized personnel and relevant researchers or consultants.
- Partners and contractors within purpose.
- Hosting, email, form, storage, meeting, and security providers.
- Legal or professional advisers.
- Commissioners or partners where necessary and lawful.
- Competent authorities for obligation or protection.
Service providers
Arrangements should define purpose, data, duration, confidentiality, security, deletion, subprocessors, and incident notice. Providers do not independently use information without an appropriate basis and notice.
Partners and commissioners
Where another organization helps determine purpose or receives information, a specific notice explains roles and rights. A commissioner does not automatically receive all information simply because it funded or requested the work.
Legal or protective disclosure
Only necessary information may be disclosed to comply with lawful orders, protect a person from serious harm, investigate fraud, protect rights, defend claims, or cooperate with competent authorities.
No sale or undisclosed targeting
The Center does not sell personal information to advertisers or brokers and does not use it for undisclosed political or commercial targeting. Future advertising tools would require prior notice and controls.
International processing
Hosting, email, cloud, support, or partners may process information in another country. Sensitivity, location, contract, encryption, rights, necessity, and safeguards are assessed.
Storage
Information may be stored in institutional systems, devices, email, hosting, cloud, project-management, complaint, or secure-data environments. Sensitive information should not remain in unapproved personal accounts.
Retention
Information is not retained longer than necessary. Duration depends on request type, contract, project, audit, complaints, law, sensitivity, and deletion or anonymization feasibility.
| Record type | Provisional approach |
|---|---|
| General inquiry | Until follow-up ends, then delete or retain minimally. |
| Research request | During proposal and negotiation and a defined professional period. |
| Contract correspondence | During contract and required post-contract period. |
| Data or privacy request | During review, completion, and outcome documentation. |
| Complaint | According to sensitivity, accountability, and retaliation prevention. |
| Account | While active and for a limited security period after closure. |
| Security logs | In proportion to investigation and protection. |
| Subscription | Until unsubscribe or service closure. |
Deletion and anonymization
When no longer needed, information may be deleted, removed from active systems, restricted in archives, anonymized, aggregated, or reduced to a compliance record. Backup copies may persist temporarily until routine replacement.
Security
- Encrypted connections and institutional accounts.
- Multifactor authentication and restricted access.
- Backups, updates, and access monitoring.
- Sensitive-data separation, training, and confidentiality.
- Vendor review and incident response.
User security
- Send only necessary information.
- Protect accounts and passwords.
- Verify the official domain.
- Avoid suspicious links.
- Report compromise or impersonation.
- Use care on shared devices.
Data incidents
Incidents may include misaddressed email, lost devices, compromise, public file links, dashboard exposure, or unauthorized access. Response considers data type, people, harm, containment, notification, and prevention.
User rights
- Know whether information is held.
- Obtain a copy where applicable.
- Correct inaccuracies.
- Request deletion, restriction, or objection.
- Withdraw consent.
- Request portability where applicable.
- Seek review of consequential automated decisions.
- Complain.
Rights limitations
Other people’s rights, trade secrets, legal privilege, danger, legitimate investigations, contracts, or legal duties may limit fulfillment. Access does not automatically include third-party data.
Submitting a request
Submit to [Privacy email] or the privacy form with name, contact, request type, service, period, record-locating information, and response method.
Verification and representatives
Proportionate verification or authority evidence may be required from a parent, guardian, or representative. Requests may be delayed or refused where reasonable verification is impossible.
Response and fees
The process covers confirmation, clarification, search, assessment, completion or explanation, and documentation. Applicable law determines final timing. Ordinary requests should not normally incur a fee, subject to lawful treatment of excessive, repetitive, or abusive requests.
Review and complaints
Users may request internal review, clarify scope, complain to a competent authority after jurisdiction is identified, or use available legal remedies.
Children
The general Website does not target children’s information. If a child submits information, retention is minimized and a responsible adult may be involved where appropriate and safe. Research involving children uses separate notices and safeguards.
External links and social media
External services and social platforms process information under their own policies. Sensitive complaints and data should not be sent through direct messages unless a designated secure channel exists.
Organizational change
If the Center restructures, merges, or transfers an activity, relevant information may transfer to a successor subject to purpose, protection, notice, contractual limits, and consent.
Changes, language, and dates
The Notice may change with services, providers, accounts, portals, analytics, law, or incidents. Arabic and English are available; the controlling or equally authoritative version is determined after review.
| Item | Value |
|---|---|
| Effective date | [To be added after approval] |
| Latest update | [To be added when revised] |
| Version | 1.0 – launch draft |
Data by interaction channel
| Channel | Illustrative information |
|---|---|
| General contact | Name, email, organization, subject, message, and attachments. |
| Research request | Scope, questions, timing, budget, and documents. |
| Data request | Identity, organization, purpose, variables, and protection plan. |
| Complaint | Event, persons, project, evidence, and requested outcome. |
| Account | Registration, permissions, login, and download records. |
| Event or newsletter | Registration, preferences, and consent record. |
Data minimization
Forms should collect only what the purpose requires. Unused fields should be removed, optional fields clearly marked, duplication across systems avoided, and a complete identity document not requested where a less intrusive verification method is sufficient.
General messages do not create a subscription
An inquiry, research request, complaint, or download does not automatically subscribe the user to a newsletter or marketing. Optional communication requires a clear choice and may be stopped while necessary messages about a request, contract, or account continue.
Website analytics detail
If analytics are enabled, identifiers and retention should be minimized and advertising and unnecessary sharing disabled. The current package has no analytics or advertising enabled, and this Notice and the cookie register must be updated before a provider is added.
Automated decisions
The Website is not intended to make consequential individual decisions solely through automated processing. A future service doing so would explain the decision, information, general logic, effect, human-review right, and appeal.
Illustrative detailed retention
| Record type | Proposed approach before final periods are approved |
|---|---|
| General inquiry | Until follow-up is complete, then delete or retain a limited archive. |
| Proposal request | During assessment and negotiation and for a defined professional period. |
| Contract correspondence | During performance and the required legal or audit period. |
| Data request | During assessment, access, follow-up, and compliance documentation. |
| Complaint | According to sensitivity, accountability, recurrence prevention, and claims. |
| Privacy request | Long enough to document verification and response. |
| Security log | In proportion to investigation and protection needs. |
| Mailing subscription | Until unsubscribe or service closure, with a suppression record where needed. |
Access right
A request may cover data categories, purposes, recipients, retention, source, international safeguards, and a copy. It does not automatically include other people’s data, trade secrets, legally privileged material, or information that would expose someone to harm.
Correction right
A user may request correction of name, email, organization, contact method, or an inaccurate record. Proportionate evidence may be requested where the change is material or affects another person’s rights or restricted access.
Deletion request
Deletion may apply where information is no longer needed, consent is withdrawn without another basis, or use was unlawful. Retention may remain necessary for a contract, legal duty, complaint, claim, safeguarding, fraud prevention, or protected research.
Objection and restriction
A user may request a defined use to stop, access to be restricted, optional messages to cease, or processing to pause while accuracy is reviewed. The request is balanced against purpose, basis, other rights, and obligations.
Withdrawal of consent
Consent may be withdrawn for newsletters, optional cookies, recording or photography, or defined voluntary sharing. Withdrawal does not invalidate prior lawful use and does not stop processing based on a contract, duty, or separate basis.
Portability
Certain information provided by a user may be available in a structured format where applicable law covers automated processing based on consent or contract. The Center is not required to create new information or disclose other people’s rights.
Requests through representatives
A parent, guardian, legal representative, or authorized person may submit a request with evidence proportionate to sensitivity. Information is not disclosed to a person merely claiming representation without reasonable verification.
Fees and excessive requests
An ordinary request is not normally charged. Applicable law may permit a reasonable fee or refusal for manifestly excessive or abusive repetition, but fees are not used to prevent a legitimate right.
Supervisory authority
Details of the competent supervisory authority will be added after the Center’s legal jurisdiction is determined. Until then, an internal review may be requested and available legal rights used in the relevant location.
Data-incident notification
Need for notification is assessed according to information type, likelihood of harm, safeguards, law, and agreement. A notice should explain what happened, affected information, measures, and steps the person may take.
Social-media communication
Messages and comments are also governed by platform rules. Sensitive complaints or datasets should not be sent by direct message; the Center may move the discussion to a safer channel and remove or restrict unnecessary copies.
Contact and dates
| Item | Status |
|---|---|
| Privacy email | [privacy@palestinepollingcenter.org or another approved address] |
| General email | [General email] |
| Address | [To be added after legal address approval] |
| Supervisory authority | [To be added after jurisdiction is determined] |
| Effective date | [To be added after approval] |
| Latest update | [To be added when revised] |
| Version | 1.0 on first approval |