Skip to main content
Home

Public document YTC-03

Privacy and Data Protection Policy

English translation for review

This translation is published for accessibility while legal review is pending. If the texts differ, the Arabic source controls.

Published for review

This is a public founding draft, version 0.3. It is not effective until its approval and effective date are formally recorded.

Version
0.3
Source date
Classification
Public
Status
Founding draft pending approval

What we collect, why we collect it, how we use and protect it, and members’ rights

Document scope

This policy applies to the YTC website and platform, membership and event forms, surveys, and official channels. It sets a high operational standard without suggesting that every international law automatically applies.

Who we are

Yemen Tech Collective is an independent technology community with a non-profit purpose and is in the process of formalising its legal structure. Until a legal entity is established, the interim leadership team is responsible for determining the purposes of data processing. This section will be updated when registration is complete.

Our principles

  • Clarity and fairness: we explain how we use data in understandable language and do not use it in surprising or misleading ways.
  • Purpose limitation and data minimisation: we collect only what is needed for membership, events, and the services we describe.
  • Control: members decide what appears on their public profiles, especially phone numbers, email addresses, and social links.
  • Security and limited retention: we restrict access and delete data when there is no longer a legitimate need for it.
  • Accountability: we document service providers, permissions, incidents, and material changes.

Data we may collect

  • Account and identity data: name, email, optional phone number, city or country, and profile image.
  • Professional data: discipline, skills, experience, optional employer, CV, and professional links.
  • Event data: application, registration time, preferences, admission decision, attendance, feedback, and accessibility needs.
  • Usage and security data: IP address, device and browser, sign-in logs, fraud attempts, and audit records.
  • Correspondence and reports: support messages, rights requests, and conduct reports with evidence when provided.
  • Images and recordings: where notice and consent, or another clear basis, are in place, with a practical way for people to object to appearing.

Purposes of use

  • Create accounts and professional profiles and operate the search and contact features chosen by members.
  • Manage events, fair selection, attendance, waiting lists, and feedback.
  • Run mentoring, opportunity-sharing, and volunteer programmes, and improve the community experience.
  • Protect against fraud, abuse, and unauthorised access and enforce the Code of Conduct.
  • Send operational communications, and send news or promotional opportunities only where a person has made a choice they can withdraw.
  • Prepare aggregated statistics and impact reports that do not identify people.

Public profiles

When a public profile is enabled, the information selected by the member becomes available to any visitor and may be indexed by search engines or copied by others. Sensitive contact details are hidden by default, and a phone number appears only after an explicit, reversible choice. Disabling a public profile does not delete the account or necessary operational records.

Sharing with others

We do not sell or rent personal data or provide member lists to sponsors or recruiters. We may share the minimum necessary with hosting, email, support, and security providers under confidentiality and protection obligations; with a programme partner after the member’s express consent; or to comply with a valid legal obligation or protect safety. Sponsors normally receive aggregated figures only.

International transfers and hosting

Service providers may operate from different countries. Before approving a provider, YTC assesses the processing location, security controls, contractual terms, and deletion and export capabilities. Where the law requires particular safeguards for international transfers, the collective seeks to put the appropriate safeguards in place before transferring data.

Retention periods

Category Initial period
Account and profile For the life of the active account, followed by deletion or de-identification within 30 days of a deletion request. Protected backups may remain for up to 90 days.
Unsuccessful event applications Up to 6 months to measure fairness and handle objections, unless the applicant agrees to be considered for later opportunities.
Attendance and feedback Up to 24 months for reporting and improvement, after which identity is removed or the data is aggregated.
Security logs Usually up to 12 months, extended where an incident is being investigated.
Conduct reports Up to 3 years after closure, or longer where an ongoing risk or legal obligation requires it, with strictly restricted access.
Contracts and funding For the period needed for accounting and legal obligations, to be defined when the legal status is completed.

Security

We apply proportionate controls, including least-privilege access, strong authentication for administrative accounts, encryption in transit, backups, audit logs, security updates, and reviews of volunteer and provider access. No service is completely secure, so we document an incident-response plan and notify affected people when required.

Your rights and choices

  • Request a copy of your data or information about how it is used.
  • Correct and update your data and control public fields.
  • Request account deletion or restriction of specific processing, subject to necessary exceptions that will be explained.
  • Withdraw consent at any time from future messages, photography, or sharing with a programme partner.
  • Object to unexpected use or request review of a significant automated decision if one is used in the future.

Cookies and analytics

We use necessary first-party cookies for sessions, form security, secure sign-in, and your cookie choice. We save theme and menu preferences only after you allow Preferences. We do not use analytics or marketing cookies, pixels, tag managers, or third-party tracking. The current Cookies Policy lists every cookie and browser-storage name, purpose, and duration.

Minors, changes, and contact

The general platform is intended for people aged 18 or over. We do not knowingly collect a minor’s data before adopting a safeguarding policy and obtaining appropriate consent. Material changes are published and members receive reasonable notice before they take effect. For privacy requests, contact privacy@yementc.org. We may request proportionate verification to protect the account before fulfilling a request.