Data protection

What the platform does, not what it intends.

What the platform holds, what it publishes, and what a person can revoke.

Data protection & privacy

What the platform does, not what it intends.

GACF handles sensitive personal data — the identities, locations and legal status of scholars at risk. The list below is not a statement of principle: each item is a rule enforced in the database, and each one holds even if a page, a server action or an administrator gets something wrong.

A living person is never published

Publication scope and the living/at-risk axis are separate columns, and the database refuses to move a living person's record to public reach. It is not a policy the interface enforces; it is a constraint the record cannot violate.

Publication requires consent that is checked when it is read

A memorial profile reaches the public projection only with a satisfied consent covering exactly the fields shown. Consent is re-checked live rather than trusted from a flag, so an expired grant stops working without a job having to run.

Withdrawal never meets a second factor

A subject declining, withdrawing or revoking is never asked for a password, a code or an approval. Narrowing your own reach is always immediate; widening it is what requires authority. The public row is deleted in the same transaction as the revocation, not by a queue afterwards.

The public surface physically cannot read private data

Public pages run as a database role with no grant on any private schema. A bug on a public page cannot disclose a private field, because the query fails at the database before it reaches one.

A host organisation sees an alias, not a name

In the relocation pathway an institution offering to host sees a per-host alias, a discipline and an urgency — no name, no photo, no institution, no location. An identity reveal is a separate, time-boxed act against the scholar's own consent, and every read of it is written to the audit chain.

Notifications carry no identity

Alert delivery has no column that could carry a person's name. What travels out of band is the fact that something is waiting, never what it says.

No third-party requests

No public page loads a script, font, map tile or tracker from another host. A reader inside a conflict zone does not announce their visit to anyone else.

No data is shared with another platform

GACF links to the Civilians of Iran project and adopts its documentation method. No data moves between the two. Any integration would need its own agreement and its own consent purpose, and neither exists.

What we hold

Three categories, kept apart

Public record — published incident records, memorial profiles and statements, readable by anyone. Member data — organisational details and the contact information of verified member representatives, encrypted at rest. Scholar data — profiles in the scholars-at-risk directory, visible to verified members only and only for the fields the scholar has shared.

Not yet published

The formal instruments

The Privacy Policy, the Terms, and the GACF Data Charter — the agreement member institutions sign — are founder and counsel documents. They are not drafted here and are not published as placeholders. A route exists for each and goes live with the approved text. Until then, treat this page as a description of the software’s behaviour, not as a legal notice.

This deployment is a synthetic preview. Every person, organisation and record in it is fictional. No real sensitive data is admitted until the outstanding security, governance and legal gates close. How records are documented →

The panes marked Plannedin the rail — the Board of Trustees, the funding breakdown, annual reports, how to give, and work-with-us — are not published here. Each states facts about real people, real funders or real money that this build cannot verify, and the content ledger’s rule is that an unverified claim is absent rather than approximated. They appear when the secretariat supplies the copy. See the member directory for what the record does hold.