MOJ: 211.171.1242074

Policies

Privacy & Data Protection Policy

The people we work with often share information at a difficult moment in their lives. This policy sets out, without euphemism, what we record, who may see it, how long it survives, and how to make us delete it.

Version: 3.1

Last reviewed: 12 February 2026

1. Scope and legal basis

This policy governs every category of personal data processed by Innovative and Equal, whether collected in a village training room, submitted through this website, gathered during household research, or received from a partner institution. It applies to staff, volunteers, board members, contractors, interpreters and evaluators acting on our behalf.

Processing is carried out in accordance with the Law of the Republic of Armenia on the Protection of Personal Data, the Law on Public Organisations, and — where a donor requires it — the standards of the EU General Data Protection Regulation. Where two frameworks differ, we apply whichever offers the data subject stronger protection.

2. What we collect and why

For programme participants we record name, community, contact details, age band, household composition where it determines eligibility, attendance, and the outcomes a participant chooses to report. For volunteers and job applicants we hold applications, references and, for roles working with children, the results of a safeguarding check. For donors we hold the details required by accounting and anti-money-laundering rules.

Every field exists because a specific decision depends on it — eligibility, safety, or a reporting obligation to the Ministry of Justice or a donor. We do not collect data speculatively, and enumerators are trained to refuse information that a respondent volunteers but that we have no lawful use for.

Website visitors are counted using privacy-preserving aggregate statistics. We do not run advertising trackers, we do not sell or rent any personal data under any circumstances, and we do not build behavioural profiles of visitors.

4. Sharing with third parties

Personal data leaves the organisation in only four situations: an anonymised dataset supplied to a research or evaluation partner under a written data-sharing agreement; aggregate figures reported to donors and the Ministry of Justice; information disclosed to the police or a child-protection body where there is an imminent risk to life or safety; and information a court lawfully compels us to produce.

Donors receive numbers and anonymised narratives, never participant registers. Any partner receiving data is bound by contract to our retention and security standards, and we audit at least one data-sharing agreement per year.

5. Storage, security and retention

Electronic records are held in encrypted storage with access limited by role; paper records are kept in a locked cabinet at the Yerevan office. Access rights are reviewed quarterly and revoked on the last working day of any departing staff member or volunteer.

Programme records are retained for five years after a participant's last activity, financial records for the period required by Armenian tax and accounting law, safeguarding records for the period required by child-protection rules, and unsuccessful job applications for six months. At the end of a retention period records are deleted or irreversibly anonymised, and the deletion is logged.

6. Your rights and how to use them

You may ask what data we hold about you, receive a copy of it, correct anything inaccurate, ask for deletion where no legal obligation requires us to keep it, object to a particular use, or withdraw consent. Requests can be made by email, by telephone, or in person at the office, and we do not require a written form or a lawyer.

We answer within thirty calendar days and never charge a fee. Identity is verified proportionately — usually a single piece of information only the data subject would know. If you are not satisfied with our response, you may complain to the Personal Data Protection Agency of the Ministry of Justice of the Republic of Armenia, and we will supply the contact details and support the complaint process rather than obstruct it.

7. Breaches and changes to this policy

Any suspected breach must be reported internally within twenty-four hours. The Executive Director assesses the risk, notifies the supervisory authority where the law requires it, and informs affected individuals directly and in plain Armenian where there is a risk to their rights — even when notification is not strictly mandatory.

This policy is reviewed annually by the Board and whenever the law or a major programme design changes. The version number and review date at the top of this page always reflect the text in force; superseded versions are archived and available on request.

Contact regarding this policy

Innovative and Equal / Նորարար ու ՀավասարMOJ: 211.171.1242074

14 Petros Adamyan St, Yerevan 0010, Armenia

Phone: +374 10 56 02 12 · Email: horvathtamas6554@gmail.com