Using this site

Privacy policy

We are committed to letting you know what data we collect, why we collect it, and what we do with it. If you have any questions about how we use your personal information or comply with data protection legislation, please email us. This privacy policy forms part of the Terms and Conditions.

1.0 Our principles regarding user privacy and data protection

  • We believe user privacy and data protection are human rights
     
  • We take protecting your privacy seriously, and we recognise we have a duty of care to the people whose data we hold
     
  • We will only collect and process data when it is absolutely necessary, and when we do, we will make it clear why we are doing so and how it will be used
     
  • We will not send you regular email newsletters that you have not subscribed to – we hate spam as much as you do! We will always give you the choice to unsubscribe
     
  • We will not share your personal information with anyone else without your permission

2.0 Personal information collected (and why we collect it)

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data). IIED will process all personal data lawfully, fairly and in a transparent manner. The General Data Protection Regulations (GDPR) sets out six lawful grounds for processing personal data, five of which IIED relies on for processing personal data and special category personal data. This website collects and uses personal information in the following ways, for the reasons specified:

2.1 Cookies and tracking site visitors

Like most websites this site makes use of cookies, which are small amounts of textual data that are stored on the device (computer, mobile phone, tablet etc.) that you use to access our website. This data is used to enhance your experience of this site.

Cookies may be set and accessed by third-party data processors, including Google Analytics (GA, see Section 5 below). We use this data to monitor how many people are using our site and to better understand how they use the site, in order to improve the experience we provide. Although GA records information such as your geographical location, device, internet browser and operating system, none of this data personally identifies you to us.

Disabling cookies on your internet browser will stop this site from tracking any part of your visit to this website. Further information on how to enable and disable cookies is available from aboutcookies.org.uk, www.aboutcookies.org or www.allaboutcookies.org.

You can set your browser not to accept cookies and the above websites tell you how to do this. However, some of our website features may not function correctly as a result.

Clicking any link on our website is taken as implied consent to our placing cookies on your device, unless you have disabled them in your browser as described above.

2.2 Uses made of information

We use personal information held about you:

  • As part of our efforts to keep our website safe and secure
  • To administer our website and for internal operations, including troubleshooting, data analysis, testing, research, statistical and research purposes
  • To personalise and optimise your experiences as part of our provision of the service
  • To provide you with our service and to communicate with you in respect of your use of the service.
  • To allow you to participate in interactive features of our service, when you choose to do so, such as responding to surveys or registering to receive email updates from us.
  • To ensure that content from our website is presented in the most effective manner for you and for your computer. This involves conducting data and system analytics to develop and improve our service. In such circumstances we shall use anonymised data to the extent possible.

2.3 The IIED blog

We require users to register with third-party service provider 'Disqus' in order to comment on our blog posts. Disqus stores your name, your email address, your computer’s IP address, and the time and date that you submitted the comment. You can read its privacy policy in Section 5.0.

Only your name is displayed publicly on our site (or you can decide to comment anonymously), and we do not collect any information from your use of Disqus. Your comment will remain on the site until we remove the blog or you use Disqus to remove your comment, which you can do at any time.

You are wholly responsible for all content posted by you on the website, and when submitting comments you should avoid entering personally identifiable information.

Any reference to an identifiable individual in our content has been obtained via their consent and all our research data is strictly collected in this way.

2.4 Contact forms and email links

Should you complete a form on our site, none of the data that you supply will be stored by this website or passed to/be processed by any of the third-party data processors defined in Section 5.0.

2.5 Email newsletter

We use third-party data processor MailChimp to provide us with email marketing services, so if you subscribe to any of our email newsletters, the email address and associated information that you submit to us will be forwarded to MailChimp. You can read MailChimp’s privacy policy in Section 5.0.

The information that you submit will only be securely stored in our Microsoft Dynamics contact management relationship system, along with your preferences.

Your details will remain within MailChimp’s database for as long as we continue to use MailChimp’s services for email marketing or until you specifically request removal from the list. You can do this by using the unsubscribe links contained in any email newsletters that we send you.

3.0 Marketing emails

From time to time you will receive marketing emails inviting you to events and sharing relevant information. As IIED is an international organisation, sometimes this will be based on the information we have on your location.

You can always opt out of these emails. We store your information securely in our Microsoft Dynamics contact management relationship database.

We embed invisible gifs, also known as web beacons, in our HTML-based email newsletters through third-party data processors MailChimp and ClickDimensions (see Section 5.0). This is the industry standard for email tracking and allows us to see which emails are opened and which links are clicked by recipients. The information allows for more accurate reporting and improvement of our newsletters.

Because it relies on a hidden graphic you can block any tracking by turning off automatic image loading in your email. Alternatively you can use the update preference link at the bottom of any of our emails and choose plain-text as your preferred email format.

4.0 About this website’s server

This website is hosted by Acquia Cloud, within a data centre located in Dublin. Acquia’s security meets international standards.

5.0 Our third-party data processors

We use a number of third-party service providers who process personal data on our behalf. These third parties have been carefully chosen and all of them comply with the legislation set out in Section 9.0.

The majority of these third parties are based in the United States and are EU-U.S Privacy Shield compliant.

6.0 Other websites

Our website contains many links to and from other websites. If you follow a link to any of these websites, please note that they will have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

6.1 Community and social networks

IIED is a member of several third-party community and social networks. It manages a presence on their platforms and our website contains links to these networks. These companies also process personal data, and you should check their privacy policies before sharing personal information:

7.0 Website data breaches

In the event of an unlawful data breach of this website’s database or the database(s) of any of our third-party data processors, we will report it to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen.

8.0 Requesting your personal data

Individuals have the right to the personal data that an organisation such as IIED holds on them. You can request your personal data by making a subject access request.

There is no fee for making a subject access request. This should be done by completing a form to provide IIED with the necessary information needed to deal with your request.

The right of access extends to all information held on an individual, and includes staff files, databases, interview notes and emails referring to the individual.

However, there are a number of exemptions which effectively allow personal data to be withheld. To consider and apply an exemption will be dependent on the purpose for which the personal data is being processed, and will be considered and undertaken on a case-by-case basis. There is more detailed guidance on exemptions available from the Information Commissioner's Office.

The data controller (see section 10.0) is required to communicate to the data subject the information it holds in an intelligible form within 1 month or up to 2 months if the request is complex. This timeframe starts from the date the request is received by the data controller, or the data has been provided with sufficient information by the data subject to locate the information being requested.

9.0 Relevant legislation

This website and our business and internal computer systems are designed to comply with the following national and international legislation with regards to data protection and user privacy:

This site’s and IIED’s compliance with the above legislation, all of which are stringent in nature, means that this site and IIED is likely compliant with the data protection and user privacy legislation set out by many other countries and territories as well. If you are unsure about whether this site is compliant with your own country of residence’s specific data protection and user privacy legislation you can contact our data protection lead (details of whom can be found in section 11.0) for clarification

10.0 Data controller

The data controller of this website and the Publications Library is: International Institute for Environment and Development (IIED): an independent charity registered in England (charity number 800066) and in Scotland (OSCR number SC039864). Our registered office is 80-86 Gray's Inn Road, London, WC1X 8NH, UK. 

11.0 Data protection lead

Catherine Baker
Tel: +44 (0) 20 3463 7399
Email: data-protection@iied.org

12.0 Changes to our privacy policy

This privacy policy may change from time to time in line with legislation or industry developments. Any changes we make will be posted on this page, and specific policy changes and updates will be mentioned in the change log below.

12.1 How to contact us

Questions, comments and requests regarding how we use your personal information or comply with data protection legislation, please email data-protection@iied.org

12.2 Change log

  • Version 2.1.2 GDPR revised, updated 24 May 2018 to ensure compliance with GDPR legislation
  • Updated 24 September 2018 to include the Data Protection Act 2018 under ‘relevant legislation’.

This Privacy Policy forms part of the Terms and Conditions.