Data Protection and Privacy Policy
How ImpactMiles collects, uses, shares and protects personal data across all jurisdictions in which it operates.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Data Protection Officer
- Approver
- Board of Trustees
b05c319953f50d5a0ee0800d8e3df92359b2ea77dbcaddfeea0411c08cdf1597EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEaudit:governance:b05c319953f50d5aThis receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- All personal data processed by ImpactMiles
- All staff and processors
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- Row Level Security on every public schema table
- Consent captured at signup and onboarding
- Privacy request intake at /privacy
- DPIA required before any new processing of special-category data
1. Lawful Bases
- Consent - marketing communications, optional analytics cookies.
- Contract - account provisioning, participation in donations, sponsorships and events.
- Legal obligation - tax reporting, AML/CTF record keeping.
- Legitimate interests - platform security, fraud prevention, service improvement (with balancing test recorded).
2. Data Minimisation
Only the fields necessary for the stated purpose are collected. Public artefacts such as ACDCs never contain personal data; they reference organisational identifiers only.
3. Cross-Border Transfers
- Transfers into and out of the EEA and UK rely on Standard Contractual Clauses plus a Transfer Impact Assessment.
- APAC transfers rely on the recipient country's adequacy status or contractual safeguards recognised by the source regulator.
- Hong Kong personal data is processed in accordance with PDPO s.33 principles.
4. Data Subject Rights
Access, rectification, erasure, restriction, portability and objection are honoured within statutory timescales (30 days GDPR, 40 days PDPO, 30 days PDPA). Requests are lodged at /privacy and tracked in the privacy_requests register.
5. Special-Category and Biometric Data
Not collected by default. Any proposal to introduce such processing triggers a mandatory DPIA and Board approval.
6. Vendors and Sub-processors
Maintained in a public sub-processor register with purpose, location and safeguards. See the Vendor & Sub-processor Management Policy.