Privacy policy
How the Digital Governance & Compliance Alliance collects, uses and protects personal data.
Template: requires legal review before launch. This text is a starting point and is not legal advice.
Who we are
The Digital Governance & Compliance Alliance ("DGCA", "we") is the controller of the personal data described in this policy. Contact details are on our Contact page.
What we collect and why
- Account and membership data (name, email, organisation, job title, membership status): to provide your account and membership (contract).
- Event registrations: to run the event and send you joining details (contract / legitimate interests).
- Contact enquiries: to answer you (legitimate interests).
- Newsletter: only with your consent, confirmed by email (consent). You can unsubscribe at any time.
- Technical data (server logs, security checks): to keep the site secure (legitimate interests).
How long we keep it
- Contact enquiries: deleted automatically after 24 months.
- Unconfirmed newsletter sign-ups: deleted after 30 days.
- Member accounts: until you delete your account (you can do this from your account page).
Who we share it with
Service providers who host the website, store files and send email on our behalf, under contracts that require them to protect it. We do not sell personal data.
International transfers
Where data is transferred outside your country, we use appropriate safeguards such as standard contractual clauses.
Your rights
Depending on where you live (for example under the GDPR or Singapore’s PDPA) you can ask to access, correct, export or delete your data, object to or restrict processing, and withdraw consent. Members can export or delete their data from their account page; anyone can use the Contact page and choose "Privacy / data request". You may also complain to your data protection authority.
Cookies
See our cookie policy.