Privacy Policy
How we collect, use, store and protect your personal data
1. About This Policy
This Privacy Policy explains how The Civic Chapter (“we”, “us”, “our”) collects, uses, stores, shares and protects personal data when you use the Civic Chapter Volunteer Portal (the “Platform”), accessible at volunteer.thecivicchapter.org.
We are committed to protecting your privacy and to processing your personal data in full compliance with the Data Protection Act, 2024 of Botswana (the “Act”). By using the Platform, and by providing your explicit consent at registration, you acknowledge this Policy.
Please read this Policy carefully. If you do not agree with any part of it, or if you do not consent to your data being processed in the manner described, you may not be able to use the Platform. You will be asked to provide explicit consent during registration and during your first login after this Policy takes effect.
2. Who Controls Your Data
The data controller responsible for personal data processed through the Platform is:
| Name | The Civic Chapter |
| Country of registration | Botswana |
| thecivicchapter@gmail.com | |
| Platform URL | volunteer.thecivicchapter.org |
| Data Protection Officer | Kagiso David , kagiso@thecivicchapter.org |
For any data protection enquiries, rights requests, or complaints, please contact us at the email address above, clearly stating “DATA PROTECTION” in the subject line. We will respond within 30 days.
Under section 12(1)(c) of the Act, we are required to notify the Information and Data Protection Commission before carrying out automated processing operations. The Civic Chapter has submitted the required notification to the Commission in respect of the processing activities described in this Policy.
3. What We Collect and Why
3.1 Volunteer Accounts
When you register as a volunteer and use the Platform, we collect:
- Identity data: full name, email address, phone number.
- Profile data: biography, city/location, skills, causes of interest, availability.
- Account data: role, account creation and update timestamps, notification preferences.
- Activity data: activities you sign up for, attendance records, hours volunteered, badges earned.
- Communication data: support tickets you submit, notifications you receive.
- Technical data: authentication metadata (email, encrypted password hash, session tokens), browser storage flags (session management).
3.2 Organisation Accounts
When you register an organisation, we collect:
- Organisation profile data: organisation name, description/bio, category, city, website, contact email, phone number, logo.
- Verification (KYC) data: certificate of registration/incorporation, representative identity document (national ID card or passport), proof of address (utility bill or bank statement). These documents are classified as sensitive personal data under the Act.
- Activity data: activities created, published, and managed through the Platform.
- Account data: KYC status, verification status, rejection reasons (if any), audit log entries.
- Communication data: support tickets, admin correspondence.
3.3 Data We Do Not Collect
We do not collect racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual life information, genetic data, or biometric data for recognition purposes beyond what is contained in submitted KYC identity documents, which are used solely for identity verification.
3.4 Automatically Collected Data
When you use the Platform, our infrastructure providers (Vercel, Supabase, and Cloudflare) automatically collect certain technical data including IP addresses, request logs, browser/device type, and usage patterns. This data is used for security, performance, and error monitoring. Vercel Analytics may collect anonymised page view and performance data. Cloudflare processes connection metadata (IP address, browser fingerprint, and behavioural signals) to provide bot and spam protection via its Turnstile service.
We do not use advertising trackers, third-party marketing pixels, or social media tracking technologies on the Platform.
4. Our Legal Bases for Processing
Under the Act (section 26), personal data may be processed where one or more of the following criteria are met. We rely on the following bases:
| Processing Activity | Legal Basis (section 26) |
|---|---|
| Account registration and management | s26(a) Consent + s26(b) Contract performance |
| Matching volunteers with activities | s26(b) Contract performance |
| KYC/verification of organisations | s26(a) Consent (explicit, for sensitive personal data) |
| Participation records, hours, badges | s26(b) Contract performance + s26(a) Consent |
| Notifications and communications | s26(b) Contract performance + s26(a) Consent |
| Support tickets | s26(b) Contract performance |
| Platform analytics and security | s26(f) Legitimate interest (platform integrity and safety) |
| International transfer of data to foreign hosting | s26(a) Consent + s26(b) Contract performance (s78 DPA 2024 derogations) |
6. International Data Transfers
The Platform is operated using cloud infrastructure located outside Botswana. Under the DPA 2024, international transfers of personal data are governed by Part XIV (sections 74 to 78). Transfers are freely permitted to countries that Botswana's Minister has designated as offering adequate protection. All other transfers require either prior authorisation from the Commission or a statutory derogation.
Our primary database is hosted in Germany (EU), which appears on Botswana's approved-countries list and therefore requires no further authorisation. Our application host (Vercel, Inc.) and bot-protection provider (Cloudflare, Inc.) are based in the United States, which is not on the approved list. We rely on the derogation in section 78(a) of the Act: you have given explicit, informed consent to this transfer at registration. We also rely on section 78(b): the transfer is necessary for the performance of the contract between you and The Civic Chapter. Without these US-based services the Platform cannot operate.
Countries Involved
| Country | Provider | Data Types Transferred |
|---|---|---|
| Germany (EU) | Supabase, Inc. (AWS eu-central-1, Frankfurt) | All personal data: profiles, activity records, KYC documents, notifications, support tickets, authentication data, uploaded files. Storage and backups in Germany. |
| United States of America | Vercel, Inc. | Personal data processed during server-side rendering and API calls; request logs, analytics. Data passes through US servers but is stored in Germany. |
| Global (via CDN) | Vercel Edge Network | Page content may be cached and served via globally distributed edge nodes for performance. No personal data is persistently stored at edge nodes. |
| United States of America (global network) | Cloudflare, Inc. | DNS resolution and Turnstile bot-protection signals (IP address, browser fingerprint, behavioural metadata). No personal data is persistently stored by Cloudflare on our behalf beyond the processing required to resolve DNS queries and evaluate bot-protection challenges. |
You have the right to withdraw your consent to international transfer at any time by contacting us. If you withdraw consent and it is not possible to maintain your account on infrastructure located exclusively within Botswana, we will be unable to continue providing the service and your account will be scheduled for deletion, with a 30-day notice period.
8. Retention and Deletion
| Data Category | Retention Period |
|---|---|
| Active user profile data | For the duration of the account, plus 2 years after account deletion |
| Activity participation records and attendance logs | For the duration of the account, plus 3 years after account deletion (required for civic record-keeping) |
| KYC documents (sensitive), identity documents, proof of address, registration certificates | Deleted within 24 hours of successful verification. If verification is declined or the submission is withdrawn, documents are deleted within 24 hours of that outcome. Documents are never retained beyond the point at which the verification decision has been made. |
| Support tickets | 2 years from ticket creation |
| Admin audit logs | 5 years (regulatory compliance) |
| Consent records | 7 years from the date of consent (legal record) |
| Authentication logs (IP addresses, session records) | 90 days |
| Accounts of non-consenting users | Scheduled for deletion 7 days after consent is refused or revoked |
After the applicable retention period, personal data is securely deleted from active databases and storage. Backups containing personal data are subject to the same deletion schedule on a rolling basis.
You may request deletion of your account and associated personal data at any time via the Settings page or by emailing us. We will process deletion requests within 30 days.
9. Security
We implement appropriate technical and organisational security measures in accordance with section 62 of the Act, including:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using HTTPS/TLS 1.2+.
- Encryption at rest: Database storage and file storage are encrypted at rest by Supabase (AWS-level AES-256 encryption).
- Row-Level Security (RLS): Database access is controlled at the row level, users can only access their own data; organisations can only access data relating to their activities.
- Authenticated API routes: All sensitive operations require a valid authenticated session. Server-side API routes verify user identity and ownership before processing any data.
- Access controls: Admin access is role-gated. Only designated administrators may access the admin panel and user management functions.
- File access controls: KYC documents and uploaded files are stored in access-controlled storage buckets, not publicly accessible URLs.
- Password security: Passwords are never stored in plaintext. Supabase uses bcrypt hashing for password storage.
- Session management: Sessions expire automatically. The “Remember me” feature extends sessions up to 7 days only when explicitly selected.
Despite our measures, no internet-based service can guarantee absolute security. In the event of a personal data breach, we will notify the Information and Data Protection Commission within 72 hours of becoming aware (section 63 of the Act) and communicate to affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (section 64 of the Act).
10. Automated Decision-Making
The Platform uses automated processing for the following purposes:
- Badge awards: Badges are automatically awarded based on participation thresholds (e.g., number of activities completed, hours volunteered). This does not constitute a decision that significantly affects your legal rights or produces legal effects.
- Cron-based reminders: Automated notifications are sent for KYC deadline enforcement and activity reminders. These are administrative in nature.
- Spot availability management: Activity spot counts are automatically maintained. If an activity is full, you are automatically placed on a waitlist.
No fully automated decisions that produce legal effects or significantly affect individuals are made without human review. KYC approval/rejection decisions are made by human administrators, not automated systems.
11. Your Rights
Under the Botswana Data Protection Act, 2024, you have the following rights as a data subject:
| Right | Description | How to Exercise |
|---|---|---|
| Right of Access (s42) | Obtain confirmation of whether we hold personal data about you, and receive a copy of that data | Email us, we will respond within 30 days |
| Right to Rectification (s43) | Have inaccurate or incomplete personal data corrected | Update your profile in Settings, or contact us |
| Right to Erasure (s44) | Request erasure of your personal data (subject to legal retention obligations) | Account Settings, Delete Account, or contact us |
| Right to Restriction (s45) | Request restriction of processing of your personal data in certain circumstances | Contact us with specific grounds |
| Right to Data Portability (s47) | Receive your personal data in a structured, commonly used, machine-readable format | Contact us to request a data export |
| Right to Object (s48) | Object to processing of your data on grounds relating to your particular situation | Contact us with specific grounds |
| Right to Withdraw Consent (s28) | Withdraw consent at any time; this may affect your ability to use the Platform | Account Settings or contact us |
| Right to Complain (s80) | Submit a complaint to the Information and Data Protection Commission | Contact the Commission directly |
All rights requests are free of charge and will be answered within 30 days of receipt. We may request verification of your identity before processing a request.
If you are unsatisfied with our response, you have the right to submit a complaint to the Information and Data Protection Commission of Botswana.
12. Minors
The Platform is not intended for use by persons under the age of 18 without verified parental or guardian consent. Age restrictions on specific activities are set by the organising organisations and are displayed on each activity listing. We do not knowingly collect personal data from minors without appropriate safeguards.
Please note that under the Act, data of minors is classified as sensitive personal data and is subject to enhanced protection requirements.
13. Electronic Communications (ECTA)
Electronic marketing communications are separately governed by the Electronic Communications and Transactions Act (ECTA), Act No. 14 of 2014, in addition to the DPA 2024.
We send the following categories of email to registered users:
| Type | Purpose | Basis |
|---|---|---|
| Transactional | Account registration, password reset, KYC status, activity confirmations, support ticket updates, donation references | Necessary for contract performance; not subject to ECTA opt-out |
| Security | Failed login alerts, incident escalation notices, breach notifications | Necessary for security and legal compliance; not subject to ECTA opt-out |
| Platform notifications | Activity reminders, volunteer matching suggestions, KYC deadline reminders, new messages | Consent-based (DPA 2024 s26(a)); you may opt out via Notification Preferences in Settings |
Under ECTA, every platform notification email includes an unsubscribe or “Manage Preferences” link. You may withdraw consent to platform notifications at any time by clicking that link or by visiting Settings › Notification Preferences in your account. Withdrawing consent to notifications will not affect your ability to use the Platform, but you may miss time-sensitive activity updates.
Transactional and security emails cannot be opted out of while your account is active, as they are necessary for the safe operation of the service.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our platform, or our data practices. Material changes (including changes to data categories, processing purposes, or international transfer arrangements) will be communicated to you via email and/or an in-platform notification, and you will be asked to review and re-consent where required by law.
Minor, non-material changes may be published with an updated “Last Reviewed” date without individual notification. The current version of this Policy is always accessible at volunteer.thecivicchapter.org/legal/privacy-policy.
Continued use of the Platform after a material change takes effect constitutes acceptance of the revised Policy, subject to any re-consent requirements.
15. Contact Us
For all data protection enquiries, rights requests, or complaints, please contact:
Data Protection OfficerKagiso David
Email: kagiso@thecivicchapter.org
Subject line: “DATA PROTECTION , [your enquiry type]”
Response time: within 30 days
You may also reach us at our general inbox: thecivicchapter@gmail.com
You also have the right to lodge a complaint directly with the Information and Data Protection Commission of Botswana if you believe your rights under the Data Protection Act, 2024 have been violated.
16. Version History
| Version | Date | Summary of Changes |
|---|---|---|
| 1.3 | 28 August 2026 | Full DPA 2024 compliance review: corrected all section citations against Act No. 18 of 2024 (in force 29 October 2024); added Commission notification disclosure (§2); clarified USA transfer derogation basis (section 78(a)(b)) and Botswana approved-countries list (§6); added ECTA electronic communications section (§13); updated rights table with section numbers; corrected breach notification to sections 63 and 64; expanded Your Rights to include restriction, portability, and complaint rights. Governing law header updated. |
| 1.2 | 23 May 2026 | Appointed Data Protection Officer (Kagiso David, kagiso@thecivicchapter.org). Added DPO details to §2 (Who Controls Your Data) and §14 (Contact Us). |
| 1.1 | 23 May 2026 | Added Cloudflare, Inc. as a data processor. Updated §3.4 (automatically collected data), §5.2 (data processors table), §6 (international transfers table), and §7 (cookies and local storage table) to disclose Cloudflare DNS and Turnstile bot-protection services. |
| 1.0 | 22 May 2026 | Initial publication. |