Logo

PRIVACY NOTICE

Privacy Policy

Comprehensive disclosure of our data practices and your privacy rights.

Compliance Framework
GDPRCCPAPIPEDALGPD
Effective Date
January 28, 2024
Version
Version 2.3

Data Processing Overview

Identity Data

Retention: Active account + 24 months
Examples
NameEmailOrganizationContact Details
Legal Basis
Contract, Legitimate Interest

Professional Data

Retention: Active account + 36 months
Examples
Grant HistoryFunding GoalsAreas of Interest
Legal Basis
Consent, Legitimate Interest

Technical Data

Retention: 12 months
Examples
IP AddressDevice InfoBrowser Data
Legal Basis
Legitimate Interest

Usage Data

Retention: 24 months
Examples
Search HistoryFeature UsageSession Data
Legal Basis
Consent, Legitimate Interest
Data Protection Officer
Sarah Chen, Data Protection Officer

Your Privacy Rights

Right to Access

Response: 30 days

Know what data we have about you

Right to Correct

Response: 30 days

Fix inaccurate information

Right to Delete

Response: 45 days

Request data deletion

Right to Port

Response: 30 days

Get your data in usable format

Right to Object

Response: Immediate

Opt-out of processing

Right to Withdraw

Response: Immediate

Withdraw consent at any time

1. Scope & Purpose

Important
This Privacy Policy ("Policy") describes how GrantPlatform Inc. ("we," "us," or "our") collects, uses, processes, stores, and protects personal information in connection with our grant information platform ("Services"). This Policy applies to all users of our Services, including website visitors, registered users, and subscribers.

We are committed to transparency about our data practices and compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other data protection regulations.

2. Key Definitions

2.1 "Personal Data" means any information relating to an identified or identifiable individual.
2.2 "Processing" includes collection, storage, use, and disclosure of Personal Data.
2.3 "Data Controller" refers to GrantPlatform Inc. as the entity determining purposes of processing.
2.4 "Data Subject" means the individual to whom Personal Data relates.
2.5 "Consent" means freely given, specific, informed, and unambiguous indication of agreement.
2.6 "Legitimate Interest" refers to our business needs that do not override data subject rights.

3. Data We Collect

Important
3.1 Information You Provide:
• Account Information: Name, email, organization details, contact information
• Professional Data: Grant history, areas of interest, funding goals, organizational mission
• Payment Information: Billing address, payment method details (processed by secure third parties)
• Communications: Support inquiries, feedback, survey responses

3.2 Automatically Collected Information:
• Usage Data: Pages visited, search queries, feature usage, session duration
• Technical Data: IP address, browser type, device information, operating system
• Location Data: General location based on IP address or provided preferences
• Cookies & Tracking: As described in Section 7

3.3 Information from Third Parties:
• Social media platforms (if you connect accounts)
• Analytics providers
• Payment processors
• Public grant databases

5. How We Use Your Data

Important
We use your Personal Data for the following purposes:

5.1 Service Delivery:
• Providing access to grant database and tools
• Personalizing grant recommendations
• Processing payments and subscriptions
• Account management and authentication

5.2 Service Improvement:
• Analyzing usage patterns to improve Services
• Developing new features and functionality
• Conducting research and analysis

5.3 Communication:
• Sending service-related notifications
• Providing grant alerts and updates
• Responding to support requests
• Sending promotional communications (with consent)

5.4 Legal & Security:
• Complying with legal obligations
• Protecting against fraud and security threats
• Enforcing our Terms of Service
• Protecting rights and property

6. Data Sharing & Transfers

Important
6.1 Service Providers: We share data with trusted vendors who assist in:
• Payment processing (Stripe, PayPal)
• Cloud hosting (AWS, Google Cloud)
• Email delivery (SendGrid)
• Analytics (Google Analytics)
• Customer support (Zendesk)

6.2 Legal Requirements: We may disclose data when required by law, regulation, or legal process.

6.3 Business Transfers: In connection with mergers, acquisitions, or asset sales.

6.4 International Transfers: Data may be transferred to countries with different privacy laws. We ensure adequate protection through:
• Standard Contractual Clauses (EU)
• Adequacy Decisions
• Privacy Shield (where applicable)

We do NOT sell Personal Data to third parties.

7. Cookies & Tracking Technologies

7.1 Types of Cookies Used:
• Essential Cookies: Required for basic functionality
• Performance Cookies: Collect anonymous usage statistics
• Functionality Cookies: Remember preferences and settings
• Targeting Cookies: Used for personalized advertising (with consent)

7.2 Cookie Management:
You can manage cookie preferences through:
• Browser settings (all major browsers)
• Our cookie consent banner
• Third-party opt-out tools (NAI, DAA)

7.3 Do Not Track: We respect "Do Not Track" browser signals.

7.4 Analytics: We use Google Analytics with IP anonymization enabled.

8. Data Security Measures

Important
We implement comprehensive security measures including:

8.1 Technical Controls:
• Encryption in transit (TLS 1.3) and at rest (AES-256)
• Regular security audits and penetration testing
• Intrusion detection and prevention systems
• Secure development practices

8.2 Administrative Controls:
• Employee security training
• Access controls and least privilege principle
• Incident response plan
• Regular risk assessments

8.3 Physical Controls:
• Secure data center facilities
• Environmental protections
• Access logging and monitoring

While we implement industry-standard security measures, no system is 100% secure. We will notify affected users of data breaches as required by law.

9. Data Retention Periods

We retain Personal Data only as long as necessary for the purposes outlined in this Policy:

9.1 Active Accounts: Data retained while account is active
9.2 Inactive Accounts: Deleted after 24 months of inactivity
9.3 Legal Requirements: Retained as required by law (e.g., tax records: 7 years)
9.4 Legitimate Business: Retained for legitimate business purposes
9.5 Backup Data: Retained in secure backups for up to 30 days

Specific retention periods for each data category are documented in our Data Retention Policy.

10. Your Privacy Rights

Important
Depending on your jurisdiction, you may have the following rights:

10.1 Access Rights: Right to know what Personal Data we hold about you.
10.2 Correction Rights: Right to correct inaccurate or incomplete data.
10.3 Deletion Rights: Right to request deletion of your data ("right to be forgotten").
10.4 Portability Rights: Right to receive your data in a structured, commonly used format.
10.5 Objection Rights: Right to object to certain processing activities.
10.6 Restriction Rights: Right to restrict processing in certain circumstances.
10.7 Consent Withdrawal: Right to withdraw consent at any time.
10.8 Non-Discrimination: Right not to receive discriminatory treatment for exercising rights.

To exercise these rights, contact our Data Protection Officer. We will respond within 30 days.

11. Children's Privacy

Our Services are not intended for individuals under 16 years of age. We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without parental consent, we will take steps to delete such information.

Parents or guardians who believe their child has provided us with Personal Data should contact us immediately. We will promptly investigate and take appropriate action.

12. International Compliance

Important
12.1 GDPR Compliance: We comply with the EU General Data Protection Regulation, including:
• Appointment of Data Protection Officer
• Data Protection Impact Assessments
• Records of Processing Activities
• Data Processing Agreements with vendors

12.2 CCPA Compliance: We comply with the California Consumer Privacy Act, including:
• "Do Not Sell" compliance
• Verifiable consumer requests
• Non-discrimination provisions

12.3 Other Jurisdictions: We comply with applicable laws in jurisdictions where we operate, including:
• PIPEDA (Canada)
• LGPD (Brazil)
• Privacy Act (Australia)

13. Policy Updates

We may update this Privacy Policy periodically to reflect:
• Changes in our data practices
• New legal requirements
• Service enhancements
• User feedback

Material changes will be communicated through:
• Email notification to registered users
• Platform announcement
• Updated "Last Updated" date

We encourage you to review this Policy regularly. Continued use of our Services after changes constitutes acceptance of the updated Policy.

Exercise Your Rights

Contact our Data Protection Officer to exercise your privacy rights or for any privacy-related inquiries.

Email
privacy@grantplatform.com
DPO
Sarah Chen, Data Protection Officer
Phone
+1 (555) 123-4567
privacy@grantplatform.com
Currently Viewing
1. Scope & Purpose