Privacy Policy
Last updated: February 19, 2026
1. Introduction
This Privacy Policy describes how The Iris Project gGmbH ("we", "us", or "our") collects, uses, and protects your personal data when you use the Engagement Platform ("Platform").
We are committed to protecting your privacy and ensuring the security of your information in compliance with the General Data Protection Regulation (GDPR).
2. Data Controller
The data controller for your personal information is:
The Iris Project gGmbH
Email: dy@araminta-advisers.eu
3. What Data We Collect
We collect different types of data depending on how you use the Platform. The Platform supports three privacy modes:
Full Public
- Your submission is published in the public catalog.
- Any contact information you provide in the text may be visible.
Identified to the Bank Only
- Your contact details are shared only with the bank's review team.
- Your identity is not made public.
Anonymous
- No identity or contact information is stored.
- You cannot be re-identified or contacted.
Technical Data
- We do NOT log IP addresses.
- We do NOT use Google Analytics or any third-party tracking.
4. How We Use Your Data
We use your data solely for the following purposes:
- To facilitate public consultations on development-bank projects.
- To enable secure communication between community members and bank staff.
- To improve the security and functionality of the Platform.
Your data belongs to the non-profit operator and is never sold or shared for marketing purposes.
5. Anonymous Reporting
If you choose the Anonymous privacy mode:
- We do not collect your name or email.
- We do not track your IP address.
- We cannot re-identify you.
6. Data Security
We implement strict security measures to protect your data:
- Encryption: Submission content is encrypted server-side using AES-256-GCM. Encryption keys are never stored in the browser.
- Hosting: The Platform is self-hosted in Switzerland.
- Access Control: The identity vault and any re-identification data are inaccessible without a formal legal process.
- Audits: We undergo independent Data & Security, Process, and Methodology audits.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of your data.
- Right to Rectification: You can ask us to correct inaccurate data.
- Right to Erasure: You can ask us to delete your data.
- Right to Restrict Processing: You can limit how we use your data.
- Right to Object: You can object to our processing of your data.
- Right to Data Portability: You can request your data in a structured format.
To exercise these rights, please contact us at dy@araminta-advisers.eu.
9. Data Retention
We retain your data only as long as necessary for the consultation process and accountability reporting. Anonymous submissions retain no identity data to delete.
10. Third Parties
We share data only with minimal, essential service providers:
- Hosting: Secure infrastructure hosted in Switzerland.
- Email Delivery: For sending system notifications.
We do NOT share data with advertising or analytics third parties.
11. Changes to This Policy
We may update this Privacy Policy as needed. Significant updates will be communicated through the Platform or via email for registered users.
12. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Draft — requires legal sign-off (Jennifer Gaspar / counsel).