DATA PROTECTION POLICY – ideas.org.es

Version: 1.1 (all contents and clauses of this document are subjected to be updated from time to time)
Date: August 24, 2026
Responsible: Shehnoor Azhar (Data Controller)

  1. Purpose and Scope

This policy outlines how ideas.org.es (the consultancy) collects, uses, stores, and protects personal data during its activities. It applies to all data processing operations, including but not limited to:

  • The equitable thermometer online petition (data capture of signatories).
  • Donations received in support of the podcast and/or petition campaign.
  • Website visitor analytics and contact forms.
  • Podcast subscriber and newsletter mailing lists.
  • Client and business partner information.

All personal data is processed in compliance with the EU General Data Protection Regulation (GDPR) and the Spanish LOPDGDD (Organic Law 3/2018).

  1. Data Collection – Principles

We adhere to the following principles:

Principle

Our Approach

Lawfulness, fairness, transparency

We process data only on a lawful basis (e.g., consent, legitimate interest) and inform individuals clearly.

Purpose limitation

Data is collected for specified, explicit, and legitimate purposes (e.g., petition signatures, publications like newsletter subscriptions, donations) and not further processed in a way incompatible with those purposes.

Data minimization

We collect only the data strictly necessary for the stated purpose. For the petition, we typically collect: Name, Email address, and optionally, Postal code/Country of residence – sufficient to verify and count signatures. For donations, we collect Name, Email address, Donation amount, and Payment method. We do not collect sensitive data (e.g., political opinions) unless explicitly required and justified.

Accuracy

We take reasonable steps to ensure data is accurate and kept up to date.

Storage limitation

Data is kept only as long as necessary. Petition signature data is retained for the duration of the campaign and for a reasonable period thereafter (e.g., 24 months) for audit and reporting purposes, unless a longer retention is required by law. Donation records are retained for tax and accounting purposes as required by Spanish law (typically 5 years).

Integrity and confidentiality

Data is processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.

  1. Lawful Basis for Processing

For the petition, our lawful basis is consent (Article 6(1)(a) GDPR). By signing, individuals actively and freely give their consent for us to process their data for the purpose of the petition. For newsletter subscriptions and donations, the basis is also consent.

For other consultancy activities, we may rely on legitimate interest (Article 6(1)(f) GDPR) or contractual necessity where applicable.

Consent must be:

  • Freely given, specific, informed, and unambiguous.
  • Obtained through a clear affirmative action (e.g., ticking an unchecked box with legible statement(s) available in English & Spanish.
  • Withdrawable at any time. An easy opt-out or unsubscribe mechanism must be provided in all communications.

 

  1. Data Capture and Use

Activity

Data Collected

Purpose

Lawful Basis

Petition Signature

Name, Email address, (Optional: Location)

To record and verify signatures for the campaign; to demonstrate public support; to send occasional updates about the campaign (with consent).

Consent

Donation

Name, Email address, Donation amount, Payment method (e.g., PayPal, bank transfer)

To process the donation, acknowledge the donor, and include them in campaign communications (with consent).

Consent (for data processing) and Legitimate Interest (for financial reconciliation)

Newsletter / Podcast Subscription

Name, Email address

To send the monthly newsletter and podcast updates.

Consent

Website Contact Forms

Name, Email address, Message

To respond to inquiries.

Legitimate Interest / Contractual

We do not sell, rent, or share personal data with third parties for their own marketing purposes.

  1. Data Storage, Security, and Access

5.1 Storage

Personal data is stored in secured, GDPR-compliant servers located within the European Economic Area (EEA). Where third-party services (e.g., email marketing platforms, form builders, payment processors) are used, we ensure they are GDPR-compliant and have appropriate data processing agreements in place.

Payment transactions are processed through trusted, secure third-party payment gateways (e.g., PayPal, Stripe). We do not store full credit card details on our own servers.

5.2 Security Measures

We implement appropriate technical and organizational measures to protect data, including:

  • Access controls: Only the consultant (Shehnoor Azhar) and the authorized website manager/administrator have access to the data. Access is granted on a need-to-know basis.
  • Authentication: Strong passwords are used for all systems and accounts. Two-factor authentication (2FA) is used where available.
  • Encryption: Data transmission is encrypted using HTTPS.
  • Data minimisation & Pseudonymisation: Where feasible, data is stored in a way that does not directly identify individuals (e.g., using unique identifiers instead of names).
  • All collected information will be primarily stored on the servers designated by the hosting platform.
  • We do not currently use cookies, tracking or analytics tools, a cookie consent banner is not required at this time. We will review and update our cookie policy if any tracking or analytics tools are introduced in the future.
  • A period of one month applies to respond to any legitimate and lawful query while 2 months for the query of complex nature unless explicitly clarified otherwise.
  • The Controller and/or Web Manager will not be responsible for anonymity or falsification of information provided while accessing the website in general or its contents (proprietary or free-to-use).

5.3 Data Access and Internal Use

Data is accessed only for the purpose of the petition and related communications. Specifically:

  • The consultant uses it to verify signatures, respond to queries, report campaign progress, and reconcile donations.
  • The website manager/administrator (based outside Europe) has access to the backend systems for technical maintenance, troubleshooting, and website updates. All correspondence in this regard will be conducted through the designated servers held by the hosting platform. No third part emails or data transfers will be conducted. 
  • No third-party contractors have access to the data unless they are formally appointed as Data Processors and bound by a Data Processing Agreement.

5.4 International Transfers (Third-Country Transfers)

Because the website manager/administrator is based outside the European Economic Area (EEA), the following applies:

  • We have verified that the jurisdiction in question does not have an adequacy decision from the European Commission. Therefore, we rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure an adequate level of data protection.
  • The website manager/administrator has signed a Data Processing Agreement (DPA) incorporating these SCCs, committing to process data only in accordance with our instructions and to apply appropriate security measures.
  • If you have any questions about this transfer, you can contact us using mentioned elsewhere in this document.

 

  1. Data Subject Rights

Under the GDPR, individuals have the following rights. Requests can be submitted to the contact details below:

Right

Description

Right to Access

Obtain confirmation of whether we hold your data and request a copy.

Right to Rectification

Have inaccurate or incomplete data corrected.

Right to Erasure (“Right to be Forgotten”)

Request deletion of your data, subject to certain conditions (e.g., if consent is withdrawn).

Right to Restrict Processing

Request that we limit processing of your data.

Right to Data Portability

Receive your data in a structured, commonly used, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).

  1. Data Breach Response

In the event of a personal data breach (e.g., accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data), we will:

  1. Contain and assess the breach immediately.
  2. Notify the Spanish Data Protection Agency (AEPD) within 72 hours where feasible, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
  3. Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms.
  1. Disclosures and Transparency

Beyond the general privacy policy already on the website, the following specific disclosures are made for the petition and donations:

  • At the point of donation or signature: A clear and concise privacy notice (first-layer information) is provided. This includes:
    • The identity and contact details of the data controller (Shehnoor Azhar / ideas.org.es).
    • The purpose of processing (the petition and its campaign).
    • The lawful basis for processing (consent).
    • Information on the transfer of data to a third country (the website manager) and the safeguards in place (SCCs).
    • The right to withdraw consent at any time.
    • All donations are tax non-deductible.
  • On the website: A detailed privacy policy (full disclosure) is publicly available and easily accessible.

A summary of disclosures is provided in the table below:

Disclosure Requirement

Where It Is Provided

Identity & Contact Details of Controller

Privacy Policy / At point of donation or signature

Purpose & Lawful Basis of Processing

Privacy Policy / At point of donation or signature

Data Retention Period

Privacy Policy

Data Subject Rights

Privacy Policy

Third-Country Transfer & Safeguards

Privacy Policy

Right to Withdraw Consent

At point of donation or signature / In all communications

Right to Lodge a Complaint with AEPD

Privacy Policy

SPECIAL DISCLOSURE FOR DONATIONS (Tax Treatment)

Given that ideas.org.es is a sole proprietorship (autónomo) and not a registered non-profit or charitable foundation, the following must be clearly communicated to potential donors at the point of donation:

IMPORTANT NOTICE FOR DONORS:

Donations made to ideas.org.es are not tax-deductible under Spanish tax law. The consultancy is registered as a self-employed professional activity (autónomo), and donations are treated as income of the sole proprietor, Shehnoor Azhar. If you are a Spanish taxpayer, your donation does not qualify for the deductions available for donations to registered non-profits or charitable foundations under Ley 49/2002.

All donations are used to support the podcast (Population Health Weekly and El Boletín de Salud del Sur) and related public health advocacy campaigns. For transparency, we are happy to share how funds are allocated upon request.

This disclosure must be placed:

  • Immediately above or immediately below the donation button or form.
  • In bold or in a clearly visible text box to avoid being overlooked.

Why this is required:

  1. Tax Compliance: Under Spanish law, donations to autónomos are not eligible for tax deductions. Misrepresenting this could lead to penalties from the Agencia Tributaria.
  2. Donor Expectations: Donors must be fully informed to avoid disappointment or legal complaints.
  3. Transparency: Explicit disclosure builds trust and avoids any perception of misleading marketing.
  1. Data Protection Officer (DPO)

Given the size and scope of our operations, we are not required to appoint a Data Protection Officer (DPO). However, all data protection queries should be directed to:

Shehnoor Azhar
ideas.org.es
Email: info@ideas.org.es

  1. Policy Review

This policy is reviewed annually or whenever there is a significant change in data processing activities. The latest version is always available on the website.

In case you adopt this policy, please mention ideas.org.es in its credits