Last Updated: January 1, 2025 |
Effective: January 1, 2025
This policy supplements our
Privacy Policy and applies specifically to data subjects in the European Union, European Economic Area, and United Kingdom. For all data rights requests, please use our
secure contact form.
1. Our Commitment to GDPR
Peacemakers Movement is committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR. We process personal data fairly, transparently, and lawfully, and only for specified, explicit, and legitimate purposes.
2. Lawful Bases for Processing
We rely on the following lawful bases under GDPR Article 6:
- Article 6(1)(a) β Consent: Newsletter subscriptions, marketing communications, optional data fields. You may withdraw consent at any time.
- Article 6(1)(b) β Contract / Pre-contractual steps: Processing your contact form submission to provide the service you requested.
- Article 6(1)(c) β Legal obligation: Retaining records for legal compliance purposes.
- Article 6(1)(f) β Legitimate interests: Security measures, anti-spam controls, site analytics, and routing of inquiries to appropriate team members. We have balanced these interests against your privacy rights.
3. Data Subject Rights
As an EU/UK data subject, you have the following rights under GDPR. To exercise any right, use our secure legal contact form. We will respond within 30 days.
π Right of Access (Art. 15)
Request a copy of all personal data we hold about you, including how it is being used and shared.
βοΈ Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data we hold about you.
ποΈ Right to Erasure (Art. 17)
Request deletion of your personal data where there is no compelling reason for its continued processing.
βΈοΈ Right to Restriction (Art. 18)
Request that we restrict processing of your data in certain circumstances (e.g., while accuracy is contested).
π¦ Right to Portability (Art. 20)
Receive your personal data in a structured, commonly used, machine-readable format (applies to consent-based processing).
π« Right to Object (Art. 21)
Object to processing based on legitimate interests, including for direct marketing purposes.
π Right to Withdraw Consent (Art. 7)
Withdraw consent at any time where we are relying on consent as the lawful basis for processing. Withdrawal does not affect processing before the withdrawal.
βοΈ Right to Complain (Art. 77)
Lodge a complaint with your national supervisory authority if you believe your data rights have been violated.
4. How to Exercise Your Rights
All data rights requests must be submitted via our secure contact form. Select "Legal" as the inquiry type and include "GDPR Request" in the subject. We will:
- Acknowledge your request within 72 hours
- Verify your identity before processing the request
- Respond fully within 30 days (extendable by 2 months for complex requests, with notice)
- Provide responses free of charge (except for manifestly unfounded or excessive requests)
5. Cookies and Tracking
Essential Cookies (No Consent Required)
pmm-theme β Stores your light/dark mode preference. Expires: 1 year. No personal data.
pmm-cookie-consent β Records your cookie consent decision. Expires: 1 year. No personal data.
Analytics Cookies (Consent Required)
- We may use Google Analytics or a privacy-friendly alternative (e.g., Plausible, Fathom) to understand site traffic patterns.
- Analytics cookies are only activated after you accept via the cookie consent banner.
- IP addresses are anonymized before storage.
- Data is not used for advertising or cross-site tracking.
Managing Cookies
You can manage cookies by:
- Using the consent banner displayed on your first visit to accept or reject non-essential cookies
- Clearing cookies and local storage in your browser settings
- Using browser extensions to block tracking cookies
6. Data Transfers Outside the EEA
Where we transfer personal data outside the European Economic Area, we ensure adequate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers only to countries with an adequacy decision from the European Commission
- Data processing agreements with all third-party processors
7. Data Protection by Design
We implement data protection by design and default:
- We collect only the minimum data necessary for each purpose
- Optional fields are clearly marked β you are not required to provide more than necessary
- Form submissions use anti-spam and validation measures to protect against unauthorized use
- Access to personal data is restricted to authorised team members on a need-to-know basis
- We conduct regular reviews of data processing activities and retention periods
8. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority within 72 hours of becoming aware
- Notify affected individuals without undue delay where the breach is likely to result in high risk
- Document all breaches in our internal breach register
9. Supervisory Authority
If you are located in the EU or UK and are not satisfied with our response to a data rights request, you have the right to lodge a complaint with your local data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO): ico.org.uk. In the EU, contact your national DPA.
10. Updates to This Policy
We review and update this GDPR Policy regularly to reflect changes in law and our data processing activities. Material changes will be communicated via a notice on our website.