Legal
Privacy Policy
This policy explains what personal data The ID Project collects, why we collect it, who we share it with, how long we keep it and what rights you have over it.
- Document
- IDP-LEG-02
- Revision
- 1.0
- Effective
- 12 Aug 2026
- Controller
- [Legal entity name]
01Who we are
The ID Project is operated by [Legal entity name], registered at [Street address, City, State, ZIP, Country]. We act as the data controller for personal data collected through theidproject.org. For any question about this policy, write to privacy@theidproject.org.
02Data we collect
- Details you give us. Name, business email, phone number, company, job title, country and the content of your enquiry or research brief.
- Order data. Billing address, tax registration numbers, purchase order references, licence type and order history. Card details are captured and stored by our payment processor, not by us.
- Usage data. IP address, approximate location derived from IP, browser and device type, referring URL, pages viewed, search terms used on site and time spent.
- Communication data. Emails, call notes and support tickets exchanged with our team.
03Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Answering enquiries and sending report samples | Steps taken at your request before a contract |
| Processing orders, delivery and invoicing | Performance of a contract |
| Fraud screening, tax and accounting records | Legal obligation |
| Site analytics and service improvement | Legitimate interests, or consent where required |
| Marketing emails about relevant research | Consent, or soft opt in for existing customers |
04Who we share data with
We share only what is necessary, and never sell personal data. Recipients fall into these groups: publishers whose reports you purchase, so they can register your licence and issue updates; payment processors and banks; hosting, email, CRM and analytics providers acting on our instructions; professional advisers; and authorities where the law requires it. Every processor is bound by a written agreement covering confidentiality and security.
05International transfers
Our publishers and service providers operate across several countries. Where personal data leaves your region, we rely on adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum or equivalent safeguards. You can request a copy of the mechanism used for a specific transfer.
06How long we keep it
- Enquiries that do not become orders: 24 months from last contact.
- Customer and licence records: 7 years, or longer where tax law requires.
- Marketing consent records: for the life of the consent plus 3 years.
- Analytics data: up to 14 months in identifiable form.
07Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent at any time, and opt out of the sale or sharing of personal information. Residents of India may also nominate another person to exercise rights on their behalf under the DPDP Act. To exercise any right, email privacy@theidproject.org. We respond within 30 days and may ask for proof of identity.
If you are not satisfied with our response you can complain to your supervisory authority, such as the ICO in the United Kingdom, your national data protection authority in the EEA, or the Data Protection Board of India.
08Security, children and changes
We protect data with encryption in transit, access controls, least privilege permissions and regular reviews of our providers. No system is perfectly secure, so we also maintain a breach response process. Our services are sold to businesses and are not directed at anyone under 18. We may update this policy; material changes will be announced on this page with a new revision number and effective date. Cookies are covered separately in our cookie policy.
Questions about your data?
Our privacy team answers access, correction and deletion requests directly. No ticket queues.
