Privacy & Your Data

Your privacy is fundamental to how we build denizen. We operate under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.

Last updated: 9 March 2026

Our Privacy Principles

Privacy by Design

Privacy is built into every feature from day one — not bolted on as an afterthought. We collect only what we need and nothing more.

Transparency

We tell you exactly what data we collect, why we collect it, how we use it, and who can see it. No dark patterns. No tricks.

Your Data, Your Control

You can access, export, correct, or delete your data at any time. You're always in control. We never sell your data.

What Data We Collect

Account & Identity

  • Name (first name only, or full name if you provide it)
  • Email address
  • Whether you identify as a local leader/elected official

Legal basis: Legitimate interest (Art. 6(1)(f)) — providing the service

Location Data

  • Country, county/region, and town/neighbourhood
  • We use Nominatim (OpenStreetMap) for geocoding — IP-based geolocation is used only for initial country detection

Legal basis: Consent (Art. 6(1)(a)) — you choose your location during onboarding

Wellbeing Data

  • Self-assessed wellbeing scores across 14 life dimensions (1-10 scale)
  • Priority ratings for each dimension
  • Year-on-year comparison selections
  • Optional personal notes (you choose whether to add these)

Legal basis: Explicit consent (Art. 9(2)(a)) — this may include health-related data

Civic Engagement

  • Selected civic issues and sentiment responses
  • Votes and polling responses
  • Issue flags and local relevance markers
  • Actions taken or willing to take

Legal basis: Legitimate interest (Art. 6(1)(f)) — facilitating civic participation

Technical Data

  • Anonymous session ID (stored in localStorage — not a tracking cookie)
  • Browser timezone (for country detection only)
  • No IP addresses are stored. No third-party analytics. No advertising trackers.

Legal basis: Legitimate interest (Art. 6(1)(f)) — maintaining service functionality

How We Use Your Data

Personalisation

Your name and location personalise your experience. Wellbeing scores shape the tools and resources we recommend.

Aggregate Community Intelligence

Wellbeing scores and civic sentiment are aggregated (anonymised) to show community-level trends. Individual data is never publicly displayed.

Leader Dashboards

If you opt into leader tools, constituent data is shown only in aggregate form — leaders never see individual records.

Email Communications

If you subscribe, we send monthly wellbeing check-in reminders and platform updates via Resend (our email provider). You can unsubscribe at any time.

What We Never Do

We never sell your data. We never share individual records with third parties. We never use your data for advertising. We never profile you for commercial purposes.

Data Storage & Security

Infrastructure: Your data is stored on Supabase (built on PostgreSQL), hosted in the EU. Supabase provides encryption at rest and in transit (TLS 1.2+).

Data Residency: All data resides within the European Union, compliant with GDPR data residency requirements.

Access Control: Admin access requires authentication. Public endpoints use API gateway authorisation. All server communication uses HTTPS.

Session Identifiers: We use a randomly-generated session ID stored in your browser's localStorage. This is not a cookie and is not shared with any third party. It persists only so we can link your onboarding progress and allow you to return to your data.

Email Service: We use Resend to send transactional emails. Resend processes your email address solely for delivery purposes under a data processing agreement.

No Third-Party Analytics: We do not use Google Analytics, Facebook Pixel, or any third-party tracking service. We do not use advertising cookies.

Your Rights Under GDPR

As an EU/EEA data subject, you have the following rights:

Right of Access (Art. 15)

You can request a copy of all personal data we hold about you. We will respond within 30 days.

Right to Rectification (Art. 16)

You can ask us to correct any inaccurate or incomplete personal data.

Right to Erasure (Art. 17)

You can request deletion of your personal data ("Right to be Forgotten").

Right to Restrict Processing (Art. 18)

You can ask us to limit how we process your data while a concern is being resolved.

Right to Data Portability (Art. 20)

You can receive your data in a structured, machine-readable format (JSON).

Right to Object (Art. 21)

You can object to processing based on legitimate interest at any time.

Submit a Data Request

Email privacy@denizen.one naming the request type below, and we'll acknowledge your request by email and process it within 30 days as required by GDPR.

Access My Data

Get a copy of all personal data we hold about you (Art. 15 GDPR)

Delete My Data

Request erasure of your personal data (Art. 17 — "Right to be Forgotten")

Export My Data

Receive your data in a portable, machine-readable format (Art. 20)

Correct My Data

Request rectification of inaccurate personal data (Art. 16)

Restrict Processing

Request restriction of processing while a concern is addressed (Art. 18)

Object to Processing

Object to processing of your personal data (Art. 21)

Email a Data Request

We will acknowledge your request by email and process it within 30 days.

Privacy FAQ

Questions?

If you have any questions about this privacy policy or how we handle your data, please don't hesitate to get in touch.

Data Controller: denizen.one

Email: privacy@denizen.one

Supervisory Authority: Data Protection Commission, Ireland