Privacy & Your Data
Your privacy is fundamental to how we build denizen. We operate under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Last updated: 9 March 2026
Our Privacy Principles
Privacy by Design
Privacy is built into every feature from day one — not bolted on as an afterthought. We collect only what we need and nothing more.
Transparency
We tell you exactly what data we collect, why we collect it, how we use it, and who can see it. No dark patterns. No tricks.
Your Data, Your Control
You can access, export, correct, or delete your data at any time. You're always in control. We never sell your data.
What Data We Collect
Account & Identity
- •Name (first name only, or full name if you provide it)
- •Email address
- •Whether you identify as a local leader/elected official
Legal basis: Legitimate interest (Art. 6(1)(f)) — providing the service
Location Data
- •Country, county/region, and town/neighbourhood
- •We use Nominatim (OpenStreetMap) for geocoding — IP-based geolocation is used only for initial country detection
Legal basis: Consent (Art. 6(1)(a)) — you choose your location during onboarding
Wellbeing Data
- •Self-assessed wellbeing scores across 14 life dimensions (1-10 scale)
- •Priority ratings for each dimension
- •Year-on-year comparison selections
- •Optional personal notes (you choose whether to add these)
Legal basis: Explicit consent (Art. 9(2)(a)) — this may include health-related data
Civic Engagement
- •Selected civic issues and sentiment responses
- •Votes and polling responses
- •Issue flags and local relevance markers
- •Actions taken or willing to take
Legal basis: Legitimate interest (Art. 6(1)(f)) — facilitating civic participation
Technical Data
- •Anonymous session ID (stored in localStorage — not a tracking cookie)
- •Browser timezone (for country detection only)
- •No IP addresses are stored. No third-party analytics. No advertising trackers.
Legal basis: Legitimate interest (Art. 6(1)(f)) — maintaining service functionality
How We Use Your Data
Personalisation
Your name and location personalise your experience. Wellbeing scores shape the tools and resources we recommend.
Aggregate Community Intelligence
Wellbeing scores and civic sentiment are aggregated (anonymised) to show community-level trends. Individual data is never publicly displayed.
Leader Dashboards
If you opt into leader tools, constituent data is shown only in aggregate form — leaders never see individual records.
Email Communications
If you subscribe, we send monthly wellbeing check-in reminders and platform updates via Resend (our email provider). You can unsubscribe at any time.
What We Never Do
We never sell your data. We never share individual records with third parties. We never use your data for advertising. We never profile you for commercial purposes.
Data Storage & Security
Infrastructure: Your data is stored on Supabase (built on PostgreSQL), hosted in the EU. Supabase provides encryption at rest and in transit (TLS 1.2+).
Data Residency: All data resides within the European Union, compliant with GDPR data residency requirements.
Access Control: Admin access requires authentication. Public endpoints use API gateway authorisation. All server communication uses HTTPS.
Session Identifiers: We use a randomly-generated session ID stored in your browser's localStorage. This is not a cookie and is not shared with any third party. It persists only so we can link your onboarding progress and allow you to return to your data.
Email Service: We use Resend to send transactional emails. Resend processes your email address solely for delivery purposes under a data processing agreement.
No Third-Party Analytics: We do not use Google Analytics, Facebook Pixel, or any third-party tracking service. We do not use advertising cookies.
Your Rights Under GDPR
As an EU/EEA data subject, you have the following rights:
Right of Access (Art. 15)
You can request a copy of all personal data we hold about you. We will respond within 30 days.
Right to Rectification (Art. 16)
You can ask us to correct any inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
You can request deletion of your personal data ("Right to be Forgotten").
Right to Restrict Processing (Art. 18)
You can ask us to limit how we process your data while a concern is being resolved.
Right to Data Portability (Art. 20)
You can receive your data in a structured, machine-readable format (JSON).
Right to Object (Art. 21)
You can object to processing based on legitimate interest at any time.
Submit a Data Request
Email privacy@denizen.one naming the request type below, and we'll acknowledge your request by email and process it within 30 days as required by GDPR.
Get a copy of all personal data we hold about you (Art. 15 GDPR)
Request erasure of your personal data (Art. 17 — "Right to be Forgotten")
Receive your data in a portable, machine-readable format (Art. 20)
Request rectification of inaccurate personal data (Art. 16)
Request restriction of processing while a concern is addressed (Art. 18)
Object to processing of your personal data (Art. 21)
We will acknowledge your request by email and process it within 30 days.
Privacy FAQ
Questions?
If you have any questions about this privacy policy or how we handle your data, please don't hesitate to get in touch.
Data Controller: denizen.one
Email: privacy@denizen.one
Supervisory Authority: Data Protection Commission, Ireland