PartnerStandard Council – Privacy Policy

Effective Date: 1 September 2025

This Privacy Policy explains how PartnerStandard Council (“we”, “us”, “our”) collects, uses, discloses, and protects personal data when you use our invitation-only platform for collaborative standards development (the “Council” or “Services”), or otherwise interact with us.

1. Who We Are

2. Scope of this Policy

This Policy covers personal data processed through:

3. Categories of Personal Data We Collect

CategoryTypical ExamplesSource
Profile DataName, email, company, title, expertise areas, bioProvided at registration or profile completion
Contribution DataDefinitions, votes, comments, collaborative articlesCreated by members during participation
Activity DataLogin times, contributions count, badges earned, statisticsAutomatically tracked during platform use
Invitation DataInviter details, invitation date, invitation statusGenerated when invitations are sent/received
Technical DataIP address, browser type, device informationAutomatic server logs

4. Purposes and Legal Bases

PurposeLegal Basis (GDPR)
Manage membership and accessArt. 6(1)(b) – Contract
Facilitate collaboration and votingArt. 6(1)(b) – Contract
Publish standards with attributionArt. 6(1)(f) – Legitimate interest
Track achievements and statisticsArt. 6(1)(f) – Legitimate interest
Platform security and integrityArt. 6(1)(f) – Legitimate interest
Service announcementsArt. 6(1)(b)/(f)

5. Data Sharing and Visibility

Within the Council:

Public Attribution:

Third Parties:

6. Cookies and Analytics

We use:

7. Service Providers

ProviderPurposeLocation
Vercel Inc.Platform hostingEU & US
Supabase Inc.Database & authenticationEU & US
Notion Labs Inc.Standards publishingUS
Resend (Twilio)Email notificationsEU & US

All providers are bound by data processing agreements and appropriate safeguards (SCCs or EU-US Data Privacy Framework).

8. International Transfers

When data is transferred outside the EEA, we ensure appropriate safeguards through:

9. Data Retention

Active Members: Data retained while account is active

Contributions: Permanently retained as part of historical record

Inactive Accounts: Deleted after 3 years of inactivity (except contributions)

Published Standards: Attribution data retained indefinitely

10. Security Measures

We implement industry-standard security measures including:

11. Your Rights (GDPR)

You have the right to:

12. Children's Privacy

The Council is not intended for users under 18. We do not knowingly collect data from children. If we become aware of such collection, we will delete the data immediately.

13. Data Breach Notification

In the event of a data breach likely to result in risk to your rights and freedoms, we will notify you within 72 hours as required by GDPR.

14. Exercising Your Rights

To exercise your rights or ask questions:

You may also lodge a complaint with the Spanish Data Protection Authority (AEPD) at aepd.es.

15. Automated Decision-Making

We do not use automated decision-making that produces legal or similarly significant effects. Voting results and statistics are transparent and based on actual member input.

16. Changes to This Policy

We may update this Policy periodically. Material changes will be announced to members at least 30 days in advance. The Effective Date indicates the latest revision.

17. Contact Information

For privacy-related questions or requests:

18. Data Protection Officer

Given our size and operations, we have not appointed a formal DPO. Privacy inquiries should be directed to the contact information above.