← Governance framework
Data & Privacy

Data Protection and Privacy Policy

How ImpactMiles collects, uses, shares and protects personal data across all jurisdictions in which it operates.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Data Protection Officer
Approver
Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
b05c319953f50d5a0ee0800d8e3df92359b2ea77dbcaddfeea0411c08cdf1597
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:b05c319953f50d5a

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All personal data processed by ImpactMiles
  • All staff and processors

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • Row Level Security on every public schema table
  • Consent captured at signup and onboarding
  • Privacy request intake at /privacy
  • DPIA required before any new processing of special-category data

1. Lawful Bases

  • Consent - marketing communications, optional analytics cookies.
  • Contract - account provisioning, participation in donations, sponsorships and events.
  • Legal obligation - tax reporting, AML/CTF record keeping.
  • Legitimate interests - platform security, fraud prevention, service improvement (with balancing test recorded).

2. Data Minimisation

Only the fields necessary for the stated purpose are collected. Public artefacts such as ACDCs never contain personal data; they reference organisational identifiers only.

3. Cross-Border Transfers

  • Transfers into and out of the EEA and UK rely on Standard Contractual Clauses plus a Transfer Impact Assessment.
  • APAC transfers rely on the recipient country's adequacy status or contractual safeguards recognised by the source regulator.
  • Hong Kong personal data is processed in accordance with PDPO s.33 principles.

4. Data Subject Rights

Access, rectification, erasure, restriction, portability and objection are honoured within statutory timescales (30 days GDPR, 40 days PDPO, 30 days PDPA). Requests are lodged at /privacy and tracked in the privacy_requests register.

5. Special-Category and Biometric Data

Not collected by default. Any proposal to introduce such processing triggers a mandatory DPIA and Board approval.

6. Vendors and Sub-processors

Maintained in a public sub-processor register with purpose, location and safeguards. See the Vendor & Sub-processor Management Policy.

Questions or concerns about this policy? Contact the DPO.

Related policies