Information
Last updated: March 2024
Privacy Policy - Pravovsim Service (March 2024)
The Pravovsim platform, owned by the Danish Refugee Council in Ukraine (hereinafter referred to as "DRC"), pays special attention to protecting your privacy. Our main goal is to ensure your rights and protect your personal data. We collect and process your data for the sole purpose of providing and facilitating access to legal aid.
This Privacy Policy describes in detail the processes of collecting, using and disclosing personal information that you provide when using Pravovsim and its services. It also provides comprehensive information on your legal protections and options related to the processing of personal data by our platform.
This document contains key information about your rights and we recommend that you read it carefully before using the Pravovsim digital platform.
Who we are
The Danish Refugee Council is an international humanitarian organization that works to protect the rights of displaced and vulnerable people in times of crisis. One of the key values that guides DRC's work is transparency. Therefore, DRC is committed to ensuring transparency with all relevant stakeholders, including the displaced people it assists.
The Information, Counseling and Legal Assistance Program is part of the legal aid initiative implemented by the Danish Refugee Council. The main goal is to create opportunities for people who have been displaced to claim and enforce their rights and find durable solutions. Through the activities of the digital platform Pravovsim, people are empowered to claim and realize their rights through assistance, counseling, legal support, dispute resolution, capacity building and advocacy.
DRC is committed to processing your personal data in accordance with Загального регламенту Європейського Союзу щодо захисту даних 2016/679-GDPR (далі – GDPR) and local data protection regulations in force in the country where personal information is processed. Thus, DRC acts as a data controller.
Whenever this Policy refers to "DRC", "Pravovsim", "we", "us" or "our", it refers to:
Danish Refugee Council
Information about Pravovsim
Pravovsim, developed by the DRC, is designed to provide you with access to information, guidance and content related to the rights of refugees, internally displaced persons and other persons in need. This platform is designed to provide general guidance and information and consultations on legal issues, as well as a case management system that allows you to easily manage your case within DRC.
In order to work, Pravovsim may request users to provide personal information. Without this information, Pravovsim may not be able to provide you with the services and assistance it is intended to provide. DRC is fully aware of the risks associated with data collection. That is why DRC is committed to protecting the privacy and security of your personal data on the Pravovsim platform.
Personal information we collect and how we use it
We collect "personal information" from two sources:
· information that we automatically collect on the Pravovsim platform; and
· information you choose to provide to DRC.
We collect, process, store and transfer different types of personal information depending on whether you register on the platform or not. Three different types of users should be distinguished:
· unregistered users;
· online users;
1. Unregistered users
You can use Pravovsim services anonymously, without disclosing your name or any other identifying information, and without creating an account on the platform. Anonymous interaction may include reading the FAQ content, navigating through frequently asked questions, etc.
If you are not registered on the Pravovsim platform and have rejected cookies when logging in, we will not collect any personal information.
If you are not registered on the Pravovsim platform and have accepted cookies when logging in to the platform, we collect personal information in the form of identification data, such as your age, gender or country, location data, usage data, and data and devices. DRC may collect, use, store and process this information to:
· analyzing the audience, coverage and effectiveness of Pravovsim; and
· improving the performance of the software and platform hosting.
If you decide to use the feedback form or the "Contact Us" form on the Pravovsim platform, you can send your message anonymously without providing us with any personal information. If you use the above forms you choose to provide us with identification and contact information, namely your name, email address and phone number, you consent to the collection and processing of this personal information. DRC may collect, use, store and process this information to:
· analyzing the audience, coverage and effectiveness of the Pravovsim service;
· improving the performance of the software and platform hosting; and
· communicating with you through one-way status updates or two-way communication.
The legal basis for processing such personal data is:
· User consent;
· The processing is necessary for our legitimate interests, namely communication with users;
· The processing is necessary for our legitimate interests, namely the enforcement of our policies;
· The processing is necessary for our legitimate interests, namely to ensure the safety of users.
2. Online users
To get access to additional Pravovsim services, such as making an appointment for a consultation with an Authorized Lawyer or sending a request via online chat on the platform, you need to create an account on Pravovsim.
When registering on the platform, you will be required to provide some personal information. The categories of personal information we may collect include:
• Contact information such as your name, phone number and email address. In addition, additional information such as your citizenship, marital status, or IDP status may be required to provide legal assistance.
• Pravovsim account information, including username and password. - Location data, platform usage and log information, and device information.
• Copies of documents containing personal data that you have decided to save on Pravovsim for further use.
Your privacy and security is our priority, and we are committed to maintaining and protecting your data in accordance with the law.
In exceptional cases, DRC may collect special categories of personal data, such as health information, to provide better assistance to users with disabilities. We will only process this data if there are compelling reasons and in compliance with the GDPR.
As an online user, DRC may collect, use, store and process your personal information in order to:
• communicating with you through one-way status updates or two-way communication;
• finding relevant content and recommendations for you;
• referring you to other service providers with your consent;
• making appointments when you register for free consultation slots;
• storage of documents that you upload to the platform;
• analyzing the audience, coverage and effectiveness of Pravovsim;
• improving the performance of the software and platform hosting; and
• collecting complaints and feedback (e.g., blog comments, feedback on lawyers, etc.).
The legal basis for processing such personal data includes:
1. User consent - when a user expresses their consent to the processing of their personal data for a specific purpose or action.
2. Processing necessary for our legitimate interests, such as communicating with users, which includes providing requested services and resolving issues.
3. Processing necessary for our legitimate interests, such as enforcing our policies, which will make the platform more efficient and correct.
4. Processing necessary for our legitimate interests, in particular to ensure the security of users, including protection against fraud and abuse.
This legal framework ensures that the processing of personal data is carried out in accordance with the requirements of the law and with due regard for the rights and interests of the platform users.
In cases where it is genuinely necessary to provide better assistance to users with disabilities, DRC may collect special categories of personal data, such as health information. However, we treat this data with care and only process it when we have an important reason to do so and when it is in compliance with the European Union's General Data Protection Regulation (GDPR). Your privacy and confidentiality is our priority, and we guarantee you that your personal data will be protected and secure in all circumstances.
The law allows us to transfer or disclose your personal information in various cases to fulfill various obligations and protect your rights:
• We may disclose your data to comply with our legal obligations, respond to requests from relevant authorities, prevent potential harm, and protect your rights.
• If necessary, we may refer you to other service providers who may provide you with additional assistance or services.
• We honor our commitments to our donors and may share information to fulfill those commitments.
• In order to optimize our services, we may use software services that provide for third-party integration and use of your personal information within these services.
1. In accordance with the law and our legal obligations, DRC may disclose your information, including personal data, to various authorities and authorized third parties in the following situations:
• Fulfill our legal obligations to the courts, law enforcement agencies, government agencies and tax authorities as required by law.
• Responding to reasonable legal inquiries or responding to claims related to DRC's activities.
• To comply with lawful requests related to criminal investigations or the prevention of illegal activities that may violate the law.
• Ensuring compliance with the Terms of Service and other agreements with users.
• Protecting the rights, property, and safety of DRC, its employees, users, and other stakeholders.
This disclosure may be necessary to comply with our legal obligations, to protect your or another person's vital interests, or for the purposes of our legitimate interests or the legitimate interests of a third party to ensure the security of the DRC program, prevent harm or crime, or to exercise or defend legal rights.
2. Referrals to other service providers
In some cases, when you contact us with a problem that exceeds our capabilities, we may refer you to another service provider who may be able to provide you with additional support. In such situations, we may share a limited amount of your personal information to ensure that you have access to the services you need.
Before transferring your personal information, we will ask for your consent and notify you of which aspects of your information will be transferred to ensure that your request is properly fulfilled.
3. Compliance with donor commitments
As a non-profit organization, DRC relies on donations from both public and private entities to fund its mission. In order to meet donor requirements and ensure transparency in the use of financial resources, DRC may share limited personal information with donors, such as the names of Pravovsim users. This approach helps to ensure trust and support from donor agencies, including the confidentiality of users' personal data.
4. Third-party service providers
To expand the range of services, Pravovsim uses third-party integration. This means that Pravovsim establishes a connection with external programs, such as web analytics services, contractors or IT service providers. When you consent to the transfer of personal information to Pravovsim, you automatically agree to the transfer of this information to third parties involved in third-party integration. This approach allows us to expand the capabilities and improve the quality of services provided to Pravovsim users.
Legal basis for collecting personal information
All data collected and processed by DRC is done in a completely honest and transparent manner. The processing of personal data is carried out in accordance with the reasonable expectations of users and does not have any unlawful consequences for their rights.
Data collection and processing will be lawfully based on one of the following criteria:
· authorization or requirement of national law;
· necessity under the terms of the contract;
· legitimate interest;
· user consent;
· protection of vital interests of a person.
1. Authorization or requirement of national law
DRC may process user information in accordance with national law.
2. Contractual necessity
DRC may process personal information when necessary to prepare or enter into a contract with you.
3. Legitimate interest
DRC may process personal information to fulfill legitimate interests, such as (but not limited to) managing user accounts, mailing lists, security incidents, and communicating with partners, donors, suppliers, and vendors.
4. Consent
In the absence of legal justification, contractual relationship or legitimate interest, DRC will request your consent when processing personal information. Consent must be given freely and knowingly.
5. Protection of vital interests of a person
DRC may process your personal information when it is necessary to ensure your safety if you are unable to consent due to physical or legal incapacity. In such a case, a DRC representative must document the reasons for processing under this basis.
How long your personal information is stored
We will retain your personal information for as long as is necessary to fulfill the purpose for which it was collected or to comply with donor or governmental requirements. The following elements will be considered to determine whether the data no longer needs to be retained and whether it can be deleted or anonymized:
· whether the specific purpose for which the personal information was collected was achieved;
· if that specific purpose is not achieved, whether all of the personal information collected is still necessary to achieve the specific purpose for which the information was collected;
· if a specific goal is unlikely to be achieved, whether it is necessary to retain personal information;
· whether the retention of personal information is necessary for legitimate statistical purposes and whether the benefits of retaining the data are proportionate to the risks of retention; and
· whether DRC has any legal or contractual obligations to store personal information.
Monitoring and transmission of aggregated data
We may review, scan, or analyze your communications on DRC for fraud prevention, abuse prevention and investigation, risk assessment, regulatory compliance, product development, research, analytics, and customer support purposes. We use automated methods whenever reasonably possible. However, at times we may need to manually review some communications, for example, to investigate possible fraud, report misconduct, and provide customer support. At times, we may manually review messages to evaluate and improve the functionality of these automated tools.
These actions are based on DRC's legitimate interest in enforcing all applicable laws and our Terms of Service, preventing fraud, enhancing security, and improving and ensuring the adequate operation of our services.
We may also share aggregated information (information about our users that we combine so that it no longer identifies or refers to an individual user) and other anonymous information to comply with regulatory requirements, research, performance monitoring, demographic profiling, marketing and advertising of our content, or donor requirements.
Pravovsim transfers data to processors outside the European Union (the "EU") or the European Economic Area (the "EEA"), including to servers located in the regions where we operate. When DRC transfers personal information to processors outside of the EU or EEA, DRC ensures that appropriate safeguards are in place to protect your personal information and your rights as a data subject, and that you have access to effective remedies.
In addition, Pravovsim uses Google Analytics to track its performance and collect information about visitors. This helps DRC to improve the Pravovsim platform by tracking the source of user traffic, measuring the success of different content, evaluating interaction with different pages, and obtaining demographic information about Pravovsim users.
By using our platform, you agree to the transfer of cookies, which may contain personal information, to Google Analytics.
If you wish to opt-out of Google Analytics, you can do so by clicking here: https://tools.google.com/dlpage/gaoptout.
Your rights regarding personal information
As a data subject on our platform, you have the right to:
· Manage your information;
· The right to request changes to personal information;
· The right to access the personal information we have collected;
· The right to request deletion;
· The right to object to the processing of your data;
· Notification of data security breaches;
· Complaints.
1. Managing your information
You have the right to manage and update some of your information through your profile settings. It is your responsibility to keep your personal information up to date and to ensure that the information you provide is accurate.
2. The right to request changes to personal information
You have the right to request that we amend inaccurate or incomplete personal information about you, that you cannot change yourself using the application. You should send these requests to the contact information provided in the "Contact Us" section below, stating (1) your name, (2) the incorrect data, and (3) the changes you want to make to your personal information.
3. Your rights to access
You have the right at any time to request access to the personal information that DRC collects and processes about you and to receive personal information provided to you in a structured, commonly used and machine-readable format. DRC aims to respond to all legitimate requests within one month. If it takes longer to process your request, you will be notified in writing.
4. Storing and deleting data
You may request the complete deletion of all of your personal information by contacting DRC using the contact information located in the "Contact Us" section below. Please note that if you request deletion of your personal information:
· We may retain some of your personal information if it is necessary to detect and prevent fraud and to improve security;
· we may store and use your personal information to the extent necessary to fulfill our legal obligations. For example, Pravovsim may retain some of your information for legal reporting, auditing, and fulfillment of donor requirements;
· we keep a copy of the data collected through Pravovsim to protect against accidental or malicious loss and destruction, and therefore copies of your personal information cannot be deleted from our backup systems for a limited period of time;
· we will regularly delete inactive user accounts and all related personal information for which we no longer have a legitimate interest in retaining the data.
5. Prohibition of processing
You have the right to prohibit the processing of your personal information for certain purposes. If you object to the processing, DRC will stop using your personal information unless we can provide compelling legitimate grounds to continue to process it.
For any processing based on consent, you may withdraw your consent at any time without affecting the lawfulness of the processing that took place prior to the withdrawal.
6. Notification of a data breach
Pravovsim takes all reasonable measures to minimize the risk of personal information leakage during its processing.
In the event of a personal data leak, Pravovsim is obliged to, without undue delay and, if possible, notify the supervisory authority of the personal data leak no later than 72 hours after becoming aware of it, за винятком випадків, when the leakage of personal data is unlikely to result in a risk to the rights and freedoms of the data subject.
The risk assessment to be carried out by Pravovsim will determine whether the risk to the rights and freedoms of the affected subjects is considered high enough to justify notifying them.
In addition, in the event of a personal data breach that may result in a high risk to the rights and freedoms of data subjects, Pravovsim is obliged to notify the relevant data subject whose personal data has been breached without undue delay.
Pravovsim document all personal data breaches, including the facts relating to the personal data breach, its consequences and the remedial measures taken. This documentation should allow the data protection authority to verify compliance with the GDPR.
The respective processor shall, without undue delay, notify Pravovsim of a personal data breach when processing such personal data in accordance with Pravovsim's instructions.
7. Complaints
You have the right to lodge a complaint about our data processing activities by filling out a complaint form and sending it to our Data Protection Officer using the contact details located in the "Contact Us" section below.
Security
We continuously implement and update administrative, technical and physical security measures to protect your personal information from unauthorized access, loss, destruction or alteration. Some of the safeguards we use to protect your personal information are firewalls and data encryption, as well as access control to information. If you know or have reason to believe that your Pravovsim account information has been lost, stolen, misappropriated or otherwise compromised, or in the event of any actual or suspected unauthorized use of your Pravovsim account, please contact us using the details provided in the "Contact Us" section below.
Policy on children
The Pravovsim platform is not intended for persons under the age of 18, and we do not knowingly collect any personal information from minors. If you are a parent or guardian and you become aware that your child has provided us with personal data without your consent, please contact us using the details provided in the 'Contact Us' section below.
Changes to this Privacy Policy
DRC reserves the right to make changes to this Privacy Policy at any time in accordance with this provision. If we make changes to this Privacy Policy, we will post the revised Privacy Policy on the Pravovsim websites and update the "Last Updated" date at the top of this Privacy Policy. We will also send you a notice of the changes by email at least thirty (30) days prior to their effective date.
If you do not agree to the revised Privacy Policy, you may delete your account. If you do not delete your account prior to the effective date of the revised Privacy Policy, your continued access to or use of the DRC Program will be subject to the revised Privacy Policy.
Contact us
If you have any questions about how we process your personal information or would like to exercise your rights, please contact the DRC Data Protection Officer at any time using the contact details below:
For users in Ukraine: [email protected]
Please note that we can only respond to you after we have safely received your email, so our response may be slower if you choose to contact us by mail.
Personal information collected by DRC
Identification and contact information, such as your name, email address, phone number or IP address
Account information, such as passwords
Location data, usage data, and logs and device information
Copies of documents, for example, documents containing personal data that you have decided to save in the Pravovsim service for future use.