How we collect, use, and protect your personal data.
The Loki Foundation is committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, store, and share information about you when you visit our website or contact us, and sets out your rights under applicable data protection law.
This policy applies to residents of Ireland, the United Kingdom, and the European Union. It is written in compliance with the EU General Data Protection Regulation (EU GDPR 2016/679), the UK General Data Protection Regulation (UK GDPR), and the Data Protection Act 2018.
The data controller responsible for your personal data is:
If you have any questions about this policy or how we handle your data, please contact us at the email address above.
We may collect and process the following categories of personal data:
When you use our contact or get-involved form, we collect:
When you visit our website, certain technical data may be collected automatically by our hosting provider (Microsoft Azure), including:
We do not use tracking cookies or third-party analytics services on this website. No advertising or profiling takes place.
| Purpose | Data used | Lawful basis (GDPR Art. 6) |
|---|---|---|
| Responding to your enquiry or get-involved request | Name, email, phone, message content | Legitimate interests (Art. 6(1)(f)) - responding to direct contact from you |
| Keeping you informed about Loki Foundation developments (where you have opted in) | Name, email | Consent (Art. 6(1)(a)) |
| Maintaining records of partnership and research enquiries | Name, organisation, email | Legitimate interests (Art. 6(1)(f)) - managing our relationships and activities |
| Ensuring the security and performance of our website | Technical/access data | Legitimate interests (Art. 6(1)(f)) - operating a secure website |
| Complying with legal obligations | Any relevant data | Legal obligation (Art. 6(1)(c)) |
We will never use your data for automated decision-making or profiling.
We retain personal data only for as long as necessary for the purpose it was collected:
After the applicable retention period, personal data is securely deleted or anonymised.
We do not sell, rent, or trade your personal data. We may share data with the following categories of third parties, only to the extent necessary:
We require all third parties to respect the security of your data and to treat it in accordance with applicable law.
Your data is primarily stored and processed within the European Economic Area (EEA) or the United Kingdom. Where data is transferred outside these areas (for example, via Microsoft's global infrastructure), appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission and equivalent UK mechanisms.
Our website does not use cookies for tracking, analytics, or advertising purposes. We do not set any non-essential cookies. The only data stored in your browser relates to the technical operation of the site (such as security tokens managed by Azure).
If this changes in future, we will update this policy and request your consent where required by law.
Under EU GDPR and UK GDPR, you have the following rights in relation to your personal data:
To exercise any of these rights, please contact us at info@loki-foundation.com. We will respond within one month. We will not charge a fee for reasonable requests.
We may need to verify your identity before fulfilling a request.
If you believe we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the relevant supervisory authority:
We would, however, appreciate the opportunity to address your concern directly before you approach a supervisory authority. Please contact us first at info@loki-foundation.com.
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. Our website is served over HTTPS and hosted on Microsoft Azure, which maintains ISO 27001 and SOC 2 certifications.
No method of transmission over the internet is entirely secure. While we take all reasonable steps to protect your data, we cannot guarantee absolute security.
Our website may contain links to external websites. We are not responsible for the privacy practices or content of those sites and encourage you to read their privacy policies.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The date at the top of this page shows when it was last revised. We encourage you to review this policy periodically.
For any questions, requests, or concerns relating to this Privacy Policy or the way we handle your personal data, please contact: