Privacy Policy
Last Updated: March 14, 2026
1. Introduction & Controller Identity
This Privacy Policy explains how Civic Atlas (âweâ, âusâ, or âourâ) collects, uses, and protects personal data when you visit this website and interact with our pages, forms, and cookie preferences. The website presents an informational and community participation resource focused on communities across Canada (for example, community learning resources, event information, and participation guidance). Civic Atlas operates from the Netherlands.
Data Controller: Civic Atlas B.V.
Address: Joop Geesinkweg 209, 1114 AB Amsterdam-Duivendrecht, Netherlands
Email: [email protected]
Phone: +31 20 723 0846
We do not appoint a dedicated Data Protection Officer (DPO) for this website at this time. If you have questions about this policy or want to exercise your rights, contact us using the details above.
2. Personal Data We Collect
The exact data we collect depends on how you use the site. We aim to keep data collection proportionate and practical. The categories below describe what may be collected.
- Identity and contact data: name (if provided), email address, and phone number (if provided).
- Form content: messages you submit, project or participation details you include, topic selections, and any accessibility notes you provide.
- Technical data: IP address, browser type and version, device type, operating system, language settings, and approximate location derived from IP (city/region level).
- Usage data: pages viewed, time spent on pages, referral source, click paths, and interactions with key elements (for example, clicks on email or phone links).
- Cookies and identifiers: essential cookies for site continuity and consent storage, and optional analytics/marketing identifiers if you choose those categories.
- Conversion events: whether a form submission was completed and basic metadata needed to measure and reduce technical failures.
We do not intentionally collect special-category personal data (such as health information, religious beliefs, political opinions), financial account details, or government identification numbers through this website. Please do not include sensitive details in free-text fields unless it is strictly necessary for your request.
3. Why We Process Personal Data & Legal Basis (GDPR Art. 6)
We process personal data only when we have a legal basis under the EU General Data Protection Regulation (GDPR) and applicable Dutch data protection law. Typical purposes and legal bases include:
- Responding to contact requests: when you submit a form or email us, we use your details and message to respond, clarify next steps, and keep a short record of the conversation. Legal basis: Art. 6(1)(b) (steps prior to entering a contract) and Art. 6(1)(a) (consent) where you explicitly provide consent.
- Optional analytics: to understand how the site is used and improve content structure (for example, which resource pages are most helpful). Legal basis: Art. 6(1)(a) (consent).
- Optional marketing and remarketing: to measure advertising performance and show relevant ads to people who have visited the site. Legal basis: Art. 6(1)(a) (consent).
- Security and fraud prevention: to protect the site, prevent abuse, investigate suspicious traffic, and maintain availability. Legal basis: Art. 6(1)(f) (legitimate interests), balanced against your rights and freedoms.
- Legal obligations: where required to comply with applicable law (for example, responding to lawful requests). Legal basis: Art. 6(1)(c) (legal obligation).
Automated decision-making (Art. 22): We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
4. Cookies & Tracking
Cookies are small text files stored on your device. We use a consent-based approach: essential cookies are needed to run the site, while analytics and marketing cookies activate only after you choose them. Some tracking may also use pixel tags and server-side signals (for example, when an advertising platform records a conversion). You can read more in our Cookie Policy.
Essential (always active)
Essential cookies support core functionality and remember your cookie preference selection. Examples include _site_session and cookie_consent. Retention ranges from session-only to up to 12 months depending on the cookie.
Analytics (optional, consent required)
Analytics cookies help us understand usage patterns (for example, which pages are read most and how people navigate). When enabled, we may use Google Analytics 4 (GA4) with IP anonymization and a typical data retention of 14 months. Cookie examples: _ga and _ga_XXXXXXXXXX.
Marketing (optional, consent required)
Marketing cookies support advertising attribution and remarketing. When enabled, cookies may include _gcl_au (Google Ads) and _fbp/_fbc (Meta). These identifiers help measure whether ads lead to visits and form submissions, and can be used to build audiences for future ads.
Beyond cookies, tracking can include pixel tags (such as gtag.js or Meta Pixel) and may be supported by server-side measurement (for example, via tag management systems or conversion APIs). Where this is used, it is governed by the same consent choices you make in our cookie panel.
5. Consent (EEA/UK)
Users in the EEA and the UK receive a consent notice under GDPR/UK GDPR. Analytics and marketing cookies activate only after explicit, informed, freely given consent (Art. 6(1)(a)). Your consent choice is recorded in the cookie_consent browser cookie (typically 12 months).
You may withdraw consent at any time by using âManage cookie preferencesâ in the footer or by clearing cookies in your browser. Withdrawal does not affect the lawfulness of processing carried out before you withdraw.
6. Sharing With Advertising & Service Partners
We use service providers to operate and improve the site. Depending on your cookie choices and how you interact with us, we may share limited data with:
- Google LLC (Google Analytics 4, Google Ads, Tag Manager, remarketing): cookie identifiers, usage data, and conversion events. Reference: policies.google.com/privacy.
- Meta Platforms (Meta Pixel, Custom/Lookalike Audiences, Conversion API where enabled): page views, conversions, audience membership, and potentially hashed identifiers (if implemented later). Reference: facebook.com/privacy/policy.
- Cloudflare (CDN and security): IP-based threat detection, request metadata, and security logs. Reference: cloudflare.com/privacypolicy.
We do not sell personal data. These providers act as processors or independent controllers depending on the context. We do not permit them to use site data for their own independent commercial purposes beyond providing their contracted services, subject to their terms and settings.
7. International Transfers
Some of our partners may process data outside the EEA (for example, in the United States). Where international transfers occur, we rely on appropriate safeguards such as:
- EUâUS Data Privacy Framework (where applicable), including the UK Extension and SwissâUS framework where relevant.
- Standard Contractual Clauses (EU 2021/914) as a fallback safeguard.
- UK IDTA (International Data Transfer Agreement) as a fallback safeguard for UK-related transfers.
We also apply practical measures where possible, such as minimizing shared fields, enforcing consent gating, and limiting retention.
8. Data Retention
We keep personal data only as long as necessary for the purposes described in this policy, unless a longer retention period is required by law. Typical retention periods are:
- Contact submissions: up to 2 years from the last interaction to maintain continuity and handle follow-up questions.
- Analytics data: typically 14 months (where enabled).
- Marketing cookies: per cookie lifetime (for example, 90 days), where enabled.
- Email correspondence: the duration of the relationship plus 1 additional year, unless deletion is requested sooner.
- Server logs: typically 90 days for security and troubleshooting.
- Cookie consent records: up to 3 years for audit and compliance documentation.
- Legal/tax obligations: as required under applicable law (for example, 6â10 years for relevant records where an invoicing relationship exists).
9. Your Rights (GDPR & UK GDPR)
If GDPR or UK GDPR applies to your data, you may have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure (Art. 17)
- Restriction (Art. 18)
- Data portability (Art. 20)
- Objection (Art. 21)
- Withdraw consent at any time (Art. 7(3))
- Lodge a complaint with a supervisory authority (Art. 77)
To exercise your rights, email [email protected]. We aim to respond within 30 days, and may extend by a further 60 days for complex requests where permitted.
If you are in the EU, you can also find information about supervisory authorities via the European Data Protection Board: edpb.europa.eu.
Netherlands supervisory authority: Autoriteit Persoonsgegevens (AP): autoriteitpersoonsgegevens.nl.
10. Children
This site is not directed at individuals under 16. We do not knowingly collect personal data from minors. If you believe a child under 16 has provided personal data without verifiable parental consent, contact us and we will delete the information promptly.
11. Do Not Track
This website does not respond to âDo Not Trackâ (DNT) browser signals. Third-party providers may have their own DNT handling and opt-out settings.
12. Account & Data Deletion Requests
To request deletion of personal data associated with your messages or inquiries, email us with the subject line âData Deletion Requestâ at [email protected]. We may request additional information to verify your identity before deleting data. We aim to complete verified requests within 30 days.
In some cases we may retain limited information where legally required (for example, for compliance or security) or where needed to establish, exercise, or defend legal claims.
13. Business Transfers
In a merger, acquisition, asset sale, financing, insolvency, or similar transaction, personal data may be transferred to a successor entity. If a transfer materially changes how personal data is used, we will provide notice on this website.
14. California (CCPA / CPRA)
If you are a California resident, you may have rights under the California Consumer Privacy Act (as amended by the CPRA). In the past 12 months, we may have collected:
- Identifiers: name, email, IP address, cookie identifiers (shared with service providers and, if you consent, advertising partners).
- Internet/network activity: browsing interactions and page views (analytics and advertising providers if enabled by consent).
- Inferences: interests and preferences inferred from site usage (advertising partners if enabled by consent).
We do not sell personal information as defined by CCPA. We may share information for cross-context behavioral advertising when marketing cookies are enabled; California residents may opt out via our cookie preferences panel.
You may request to know, delete, or correct information, and you may opt out of sale/sharing. To submit a request, email [email protected] with the subject âCalifornia Privacy Requestâ. Identity verification may be required. Authorized agents must provide proof of authorization.
15. Virginia (VCDPA)
If you are a Virginia resident, you may have rights to access, correct, delete, and obtain a copy of personal data, and to opt out of targeted advertising. We do not sell personal data or engage in profiling that produces legal or similarly significant effects.
To submit a request, email [email protected] with the subject âVirginia Privacy Requestâ. If we deny your request, you may appeal by emailing with the subject âAppeal of Refusal â Privacy Requestâ. We respond to appeals within 60 days. Unresolved issues may be directed to the Virginia Attorney General.
16. Nevada
Nevada residents may submit a verified opt-out request by emailing [email protected] with the subject âNevada Do Not Sell Requestâ. We do not currently sell personal information under Nevada Revised Statutes Chapter 603A.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If changes are material, we will post a clear notice on the homepage at least 14 days before the new policy takes effect. The âLast Updatedâ date at the top of this page reflects the most recent revision.
18. Contact
For privacy questions, requests, or concerns, contact:
Civic Atlas B.V.
Joop Geesinkweg 209
1114 AB Amsterdam-Duivendrecht, Netherlands
Email: [email protected]
Phone: +31 20 723 0846