Privacy and Data Protection Policy

Women Who Won the War is committed to protecting individuals’ privacy and ensuring that personal data is handled according to the highest standards of security, transparency, and accountability, in accordance with international data protection principles.

This policy explains how the organization collects, uses, stores, and protects personal data, as well as the rights of individuals in relation to their data.

Definition of Personal Data: Personal data means any information that can directly or indirectly identify a natural person.

1. Scope of Application

This policy applies to all individuals who interact with the organization, including:

  • Website visitors 
  • Participants in programs 
  • Trainees 
  • Partners and collaborators 
  • Anyone who communicates with the organization through digital means 

2. Data We Collect

The organization may collect the following types of data:

  • Basic personal data: Name, email address, and telephone number, where necessary 
  • Program or activity registration data 
  • Correspondence and inquiry content 
  • Technical data: IP address, browser type, and cookies 

3. Legal Basis for Data Processing

Personal data is processed on the basis of one or more of the following:

  • Explicit consent from the data subject 
  • The necessity of providing a program or service offered by the organization 
  • Compliance with legal or regulatory requirements 
  • Legitimate interests related to improving services and ensuring operational continuity 

4. Use of Data

Data is used only for the following purposes:

  • Managing communication with individuals 
  • Implementing programs and activities 
  • Improving services and content 
  • Meeting administrative or legal requirements 

Personal data is not used for unauthorized commercial or marketing purposes. The organization is committed to collecting only the minimum amount of data necessary to fulfill specified purposes and will not collect or retain unnecessary data.

5. Sensitive Data

The organization treats sensitive data—including information relating to gender, political background, conflict-related circumstances, or personal safety—with an additional level of protection and restricted access procedures.

Data relating to minors and particularly vulnerable individuals is also handled with additional care and in accordance with appropriate safeguarding principles.

6. Data Security

The organization is committed to implementing appropriate technical and organizational measures to protect personal data, including:

  • Storing data in secure systems 
  • Restricting access to individuals whose professional responsibilities require access to the data 
  • Using digital security measures to prevent unauthorized access, breaches, or data leaks 
  • Providing staff with training on data protection practices 

7. Data Sharing

Personal data is not shared with third parties except in the following circumstances:

  • Where the data subject has provided explicit consent 
  • Where required by law 
  • Where operationally necessary for the direct implementation of programs 

In all cases, appropriate data protection standards are applied.

8. International Data Transfers

  • Data may be stored or processed using digital tools or platforms located outside the country in which the organization is based. 
  • The organization is committed to ensuring that all service providers apply appropriate and equivalent data protection standards. 

9. Data Retention

Data is retained for as long as necessary to fulfill operational, legal, or contractual purposes. Once it is no longer required, data is securely deleted, destroyed, or archived in a manner that prevents unauthorized access or subsequent recovery.

10. Individual Rights

Individuals have the right to:

  • Request access to their personal data 
  • Request correction or updating of their data 
  • Request deletion of their data, where permitted by law 
  • Withdraw consent to the use of their data 
  • Object to the processing of their data in certain circumstances 

Requests may be submitted through the organization’s official email address.

11. Data Breach Notification

In the event of a security breach that may affect personal data:

  • The organization will take immediate steps to mitigate potential harm. 
  • The risks associated with the incident will be assessed. 
  • Affected individuals and relevant authorities will be notified where necessary. 

12. Do No Harm

The organization is committed to using data in ways that do not expose individuals to risks, social stigma, or discrimination, particularly in sensitive contexts involving gender or conflict.

The organization places particular importance on protecting the data of journalistic sources and individuals at heightened risk.

13. Governance and Responsibility

  • The organization’s management has overall responsibility for implementing this policy and ensuring compliance with it. 
  • An internal person will be designated to oversee data protection and address related inquiries or complaints. 
  • The organization is committed to regularly raising staff awareness of privacy and data protection principles. 

14. Documentation and Auditability

The organization maintains internal records documenting the collection, use, and sharing of data to ensure transparency and enable review and auditing.

15. Cookies

  • The organization’s website uses cookies to improve the user experience. 
  • By using the website, users are considered to consent to the use of cookies in accordance with their browser settings. 

16. Amendments to This Policy

This policy may be updated from time to time. Any updated version will be published on the organization’s website together with the date of the update to ensure transparency.

Also read..