PRIVACY NOTICE
Privacy Policy
Comprehensive disclosure of our data practices and your privacy rights.
Compliance Framework
GDPRCCPAPIPEDALGPD
Effective Date
January 28, 2024
Version
Version 2.3
Data Processing Overview
Identity Data
Retention: Active account + 24 months
Examples
NameEmailOrganizationContact Details
Legal Basis
Contract, Legitimate Interest
Professional Data
Retention: Active account + 36 months
Examples
Grant HistoryFunding GoalsAreas of Interest
Legal Basis
Consent, Legitimate Interest
Technical Data
Retention: 12 months
Examples
IP AddressDevice InfoBrowser Data
Legal Basis
Legitimate Interest
Usage Data
Retention: 24 months
Examples
Search HistoryFeature UsageSession Data
Legal Basis
Consent, Legitimate Interest
Your Privacy Rights
Right to Access
Response: 30 days
Know what data we have about you
Right to Correct
Response: 30 days
Fix inaccurate information
Right to Delete
Response: 45 days
Request data deletion
Right to Port
Response: 30 days
Get your data in usable format
Right to Object
Response: Immediate
Opt-out of processing
Right to Withdraw
Response: Immediate
Withdraw consent at any time
1. Scope & Purpose
ImportantThis Privacy Policy ("Policy") describes how GrantPlatform Inc. ("we," "us," or "our") collects, uses, processes, stores, and protects personal information in connection with our grant information platform ("Services"). This Policy applies to all users of our Services, including website visitors, registered users, and subscribers.
We are committed to transparency about our data practices and compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other data protection regulations.
We are committed to transparency about our data practices and compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other data protection regulations.
2. Key Definitions
2.1 "Personal Data" means any information relating to an identified or identifiable individual.
2.2 "Processing" includes collection, storage, use, and disclosure of Personal Data.
2.3 "Data Controller" refers to GrantPlatform Inc. as the entity determining purposes of processing.
2.4 "Data Subject" means the individual to whom Personal Data relates.
2.5 "Consent" means freely given, specific, informed, and unambiguous indication of agreement.
2.6 "Legitimate Interest" refers to our business needs that do not override data subject rights.
2.2 "Processing" includes collection, storage, use, and disclosure of Personal Data.
2.3 "Data Controller" refers to GrantPlatform Inc. as the entity determining purposes of processing.
2.4 "Data Subject" means the individual to whom Personal Data relates.
2.5 "Consent" means freely given, specific, informed, and unambiguous indication of agreement.
2.6 "Legitimate Interest" refers to our business needs that do not override data subject rights.
3. Data We Collect
Important3.1 Information You Provide:
• Account Information: Name, email, organization details, contact information
• Professional Data: Grant history, areas of interest, funding goals, organizational mission
• Payment Information: Billing address, payment method details (processed by secure third parties)
• Communications: Support inquiries, feedback, survey responses
3.2 Automatically Collected Information:
• Usage Data: Pages visited, search queries, feature usage, session duration
• Technical Data: IP address, browser type, device information, operating system
• Location Data: General location based on IP address or provided preferences
• Cookies & Tracking: As described in Section 7
3.3 Information from Third Parties:
• Social media platforms (if you connect accounts)
• Analytics providers
• Payment processors
• Public grant databases
• Account Information: Name, email, organization details, contact information
• Professional Data: Grant history, areas of interest, funding goals, organizational mission
• Payment Information: Billing address, payment method details (processed by secure third parties)
• Communications: Support inquiries, feedback, survey responses
3.2 Automatically Collected Information:
• Usage Data: Pages visited, search queries, feature usage, session duration
• Technical Data: IP address, browser type, device information, operating system
• Location Data: General location based on IP address or provided preferences
• Cookies & Tracking: As described in Section 7
3.3 Information from Third Parties:
• Social media platforms (if you connect accounts)
• Analytics providers
• Payment processors
• Public grant databases
4. Legal Basis for Processing
ImportantWe process Personal Data based on the following legal grounds:
4.1 Contractual Necessity: Processing necessary to fulfill our service agreement with you.
4.2 Legitimate Interests: Processing for our legitimate business interests, balanced against your rights.
4.3 Legal Obligation: Processing required to comply with legal requirements.
4.4 Consent: Processing based on your explicit consent, which may be withdrawn at any time.
Specific legal bases for each processing activity are documented in our Data Processing Records.
4.1 Contractual Necessity: Processing necessary to fulfill our service agreement with you.
4.2 Legitimate Interests: Processing for our legitimate business interests, balanced against your rights.
4.3 Legal Obligation: Processing required to comply with legal requirements.
4.4 Consent: Processing based on your explicit consent, which may be withdrawn at any time.
Specific legal bases for each processing activity are documented in our Data Processing Records.
5. How We Use Your Data
ImportantWe use your Personal Data for the following purposes:
5.1 Service Delivery:
• Providing access to grant database and tools
• Personalizing grant recommendations
• Processing payments and subscriptions
• Account management and authentication
5.2 Service Improvement:
• Analyzing usage patterns to improve Services
• Developing new features and functionality
• Conducting research and analysis
5.3 Communication:
• Sending service-related notifications
• Providing grant alerts and updates
• Responding to support requests
• Sending promotional communications (with consent)
5.4 Legal & Security:
• Complying with legal obligations
• Protecting against fraud and security threats
• Enforcing our Terms of Service
• Protecting rights and property
5.1 Service Delivery:
• Providing access to grant database and tools
• Personalizing grant recommendations
• Processing payments and subscriptions
• Account management and authentication
5.2 Service Improvement:
• Analyzing usage patterns to improve Services
• Developing new features and functionality
• Conducting research and analysis
5.3 Communication:
• Sending service-related notifications
• Providing grant alerts and updates
• Responding to support requests
• Sending promotional communications (with consent)
5.4 Legal & Security:
• Complying with legal obligations
• Protecting against fraud and security threats
• Enforcing our Terms of Service
• Protecting rights and property
6. Data Sharing & Transfers
Important6.1 Service Providers: We share data with trusted vendors who assist in:
• Payment processing (Stripe, PayPal)
• Cloud hosting (AWS, Google Cloud)
• Email delivery (SendGrid)
• Analytics (Google Analytics)
• Customer support (Zendesk)
6.2 Legal Requirements: We may disclose data when required by law, regulation, or legal process.
6.3 Business Transfers: In connection with mergers, acquisitions, or asset sales.
6.4 International Transfers: Data may be transferred to countries with different privacy laws. We ensure adequate protection through:
• Standard Contractual Clauses (EU)
• Adequacy Decisions
• Privacy Shield (where applicable)
We do NOT sell Personal Data to third parties.
• Payment processing (Stripe, PayPal)
• Cloud hosting (AWS, Google Cloud)
• Email delivery (SendGrid)
• Analytics (Google Analytics)
• Customer support (Zendesk)
6.2 Legal Requirements: We may disclose data when required by law, regulation, or legal process.
6.3 Business Transfers: In connection with mergers, acquisitions, or asset sales.
6.4 International Transfers: Data may be transferred to countries with different privacy laws. We ensure adequate protection through:
• Standard Contractual Clauses (EU)
• Adequacy Decisions
• Privacy Shield (where applicable)
We do NOT sell Personal Data to third parties.
8. Data Security Measures
ImportantWe implement comprehensive security measures including:
8.1 Technical Controls:
• Encryption in transit (TLS 1.3) and at rest (AES-256)
• Regular security audits and penetration testing
• Intrusion detection and prevention systems
• Secure development practices
8.2 Administrative Controls:
• Employee security training
• Access controls and least privilege principle
• Incident response plan
• Regular risk assessments
8.3 Physical Controls:
• Secure data center facilities
• Environmental protections
• Access logging and monitoring
While we implement industry-standard security measures, no system is 100% secure. We will notify affected users of data breaches as required by law.
8.1 Technical Controls:
• Encryption in transit (TLS 1.3) and at rest (AES-256)
• Regular security audits and penetration testing
• Intrusion detection and prevention systems
• Secure development practices
8.2 Administrative Controls:
• Employee security training
• Access controls and least privilege principle
• Incident response plan
• Regular risk assessments
8.3 Physical Controls:
• Secure data center facilities
• Environmental protections
• Access logging and monitoring
While we implement industry-standard security measures, no system is 100% secure. We will notify affected users of data breaches as required by law.
9. Data Retention Periods
We retain Personal Data only as long as necessary for the purposes outlined in this Policy:
9.1 Active Accounts: Data retained while account is active
9.2 Inactive Accounts: Deleted after 24 months of inactivity
9.3 Legal Requirements: Retained as required by law (e.g., tax records: 7 years)
9.4 Legitimate Business: Retained for legitimate business purposes
9.5 Backup Data: Retained in secure backups for up to 30 days
Specific retention periods for each data category are documented in our Data Retention Policy.
9.1 Active Accounts: Data retained while account is active
9.2 Inactive Accounts: Deleted after 24 months of inactivity
9.3 Legal Requirements: Retained as required by law (e.g., tax records: 7 years)
9.4 Legitimate Business: Retained for legitimate business purposes
9.5 Backup Data: Retained in secure backups for up to 30 days
Specific retention periods for each data category are documented in our Data Retention Policy.
10. Your Privacy Rights
ImportantDepending on your jurisdiction, you may have the following rights:
10.1 Access Rights: Right to know what Personal Data we hold about you.
10.2 Correction Rights: Right to correct inaccurate or incomplete data.
10.3 Deletion Rights: Right to request deletion of your data ("right to be forgotten").
10.4 Portability Rights: Right to receive your data in a structured, commonly used format.
10.5 Objection Rights: Right to object to certain processing activities.
10.6 Restriction Rights: Right to restrict processing in certain circumstances.
10.7 Consent Withdrawal: Right to withdraw consent at any time.
10.8 Non-Discrimination: Right not to receive discriminatory treatment for exercising rights.
To exercise these rights, contact our Data Protection Officer. We will respond within 30 days.
10.1 Access Rights: Right to know what Personal Data we hold about you.
10.2 Correction Rights: Right to correct inaccurate or incomplete data.
10.3 Deletion Rights: Right to request deletion of your data ("right to be forgotten").
10.4 Portability Rights: Right to receive your data in a structured, commonly used format.
10.5 Objection Rights: Right to object to certain processing activities.
10.6 Restriction Rights: Right to restrict processing in certain circumstances.
10.7 Consent Withdrawal: Right to withdraw consent at any time.
10.8 Non-Discrimination: Right not to receive discriminatory treatment for exercising rights.
To exercise these rights, contact our Data Protection Officer. We will respond within 30 days.
11. Children's Privacy
Our Services are not intended for individuals under 16 years of age. We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without parental consent, we will take steps to delete such information.
Parents or guardians who believe their child has provided us with Personal Data should contact us immediately. We will promptly investigate and take appropriate action.
Parents or guardians who believe their child has provided us with Personal Data should contact us immediately. We will promptly investigate and take appropriate action.
12. International Compliance
Important12.1 GDPR Compliance: We comply with the EU General Data Protection Regulation, including:
• Appointment of Data Protection Officer
• Data Protection Impact Assessments
• Records of Processing Activities
• Data Processing Agreements with vendors
12.2 CCPA Compliance: We comply with the California Consumer Privacy Act, including:
• "Do Not Sell" compliance
• Verifiable consumer requests
• Non-discrimination provisions
12.3 Other Jurisdictions: We comply with applicable laws in jurisdictions where we operate, including:
• PIPEDA (Canada)
• LGPD (Brazil)
• Privacy Act (Australia)
• Appointment of Data Protection Officer
• Data Protection Impact Assessments
• Records of Processing Activities
• Data Processing Agreements with vendors
12.2 CCPA Compliance: We comply with the California Consumer Privacy Act, including:
• "Do Not Sell" compliance
• Verifiable consumer requests
• Non-discrimination provisions
12.3 Other Jurisdictions: We comply with applicable laws in jurisdictions where we operate, including:
• PIPEDA (Canada)
• LGPD (Brazil)
• Privacy Act (Australia)
13. Policy Updates
We may update this Privacy Policy periodically to reflect:
• Changes in our data practices
• New legal requirements
• Service enhancements
• User feedback
Material changes will be communicated through:
• Email notification to registered users
• Platform announcement
• Updated "Last Updated" date
We encourage you to review this Policy regularly. Continued use of our Services after changes constitutes acceptance of the updated Policy.
• Changes in our data practices
• New legal requirements
• Service enhancements
• User feedback
Material changes will be communicated through:
• Email notification to registered users
• Platform announcement
• Updated "Last Updated" date
We encourage you to review this Policy regularly. Continued use of our Services after changes constitutes acceptance of the updated Policy.
Currently Viewing
1. Scope & Purpose
