Privacy policy
Last updated: [Insert date]
This page is a drafting starting point and has not yet been reviewed by a lawyer. Bracketed values must be completed before publication — several of them change the legal meaning of the clause.
This policy explains what personal data CIBET International Council collects, why, how long it is kept, and what rights you have over it.
Who is responsible for your data
The data controller is [Insert registered legal name], [Insert registered office address]. Data protection enquiries go to [Insert data protection contact email].
What we collect and why
| Data | Why we hold it | How long |
|---|---|---|
| Membership application details | To assess your application against the published criteria | [Insert retention period] after a decision |
| Supporting documents you upload | To verify eligibility | [Insert retention period] after a decision |
| Member profile and directory entry | To operate the member directory and route introductions | For the duration of membership, then [Insert period] |
| Event registration details | To administer attendance and issue confirmations | [Insert retention period] |
| Enquiry and contact messages | To respond to you | [Insert retention period] |
| Newsletter subscription | To send the briefing you asked for | Until you unsubscribe |
Lawful basis
- Contract, where processing is necessary to provide membership you have applied for.
- Consent, for marketing email and for publishing any contact detail in the directory. Consent can be withdrawn at any time.
- Legitimate interests, for administering the Council and protecting the site from abuse, balanced against your rights.
- Legal obligation, where retention is required by law.
The member directory
Directory entries are published only where a member has consented. Consent is recorded per field: appearing in the directory, publishing an email address and publishing a telephone number are three separate permissions. Contact details are never published without the specific consent for that detail. Introduction requests are routed by the Secretariat so that your details are not disclosed by that route either.
Sharing
Personal data is not sold. It is shared only with service providers acting on the Council's instructions under a written agreement — [Insert list of processors: hosting, email delivery, payment processing] — and where required by law.
International transfers
CIBET operates internationally, so data may be transferred outside your country. Where that happens, transfers are made under [Insert transfer mechanism, e.g. standard contractual clauses or an adequacy decision].
Security
Data is transmitted over HTTPS. Uploaded documents are stored outside the public web directory with generated filenames. Passwords, where accounts exist, are stored only as one-way hashes. Access is limited to Secretariat staff who need it.
Your rights
- Access a copy of the data held about you.
- Correct data that is inaccurate.
- Request erasure, subject to any legal retention obligation.
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting processing already carried out.
- Complain to [Insert supervisory authority].
Requests go to [Insert data protection contact email]. We will respond within [Insert number] days.
Changes
Material changes will be published here and, where they affect members, notified by email.
Questions about this page
Write to [email protected] or use the contact form.