About this policy
The Global Grant Community (“GGC”) is a collaborative initiative involving grantor and grantee organizations from all over the world.
At the core of the Global Grant Community is a new international standard called Good Financial Grant Practice (the GFGP standard).
The development of the GFGP standard was funded by Wellcome and the Medical Research Council (UK) and is hosted at the African Academy of Sciences (AAS) in Nairobi, Kenya.
The AAS is also the Owner of the Certification Scheme for GFGP and responsible for licensing competent Certification Bodies for GFGP.
The development of the GGC portal (“the site”) was funded by the UK’s National Institute for Health Research and Medical Research Council, and the European and Developing Countries Clinical Partnership (EDCTP). The portal is supported by the AAS and hosted on Amazon Web Services in Ireland.
The AAS is currently the host for the site, and each grantor, grantee or other organisations using the site has responsibility for the personal data they provide to the site.
This Policy (together with the Terms & Conditions and any other documents referred to in it) sets out the basis on which any personal data collected from you, or provided by you, will be processed by the AAS. Please read the following carefully to understand our practices regarding your personal data and how it will be treated. By continuing to use www.globalgrantcommunity.org you are accepting and consenting to the practices described in this Policy.
www.globalgrantcommunity.org and any subdomains therein (“The site”) are operated by the AAS. We are committed to protecting the privacy and security of your personal information (‘personal data’).
This policy (together with our Terms & Conditions https://www.globalgrantcommunity.org/termsandconditions/) , together with any other documents referred to in it) describes how we collect and use your personal data during your use of our site, in accordance with the General Data Protection Regulation (GDPR) and associated data protection legislation.
Who is using your personal data?
The AAS is the “data controller" for the information that you provide to us when visiting this website. This means that we decide how to use it and are responsible for looking after it in accordance with the GDPR.
Access to your personal data within the AAS will be provided to those staff who need to view it as part of their work in connection with the operation of this website. It will also be shared with the third parties described in Section 10 below.
Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.
Updating of the policy
We reserve the right to update this policy at any time... Use of the site includes accessing, browsing or registering to use the site.
Where we refer in this policy to your ‘personal data’, we mean any recorded information that is about you and from which you can be identified. It does not include data where your identity has been removed (anonymous data).
Where we refer to the ‘processing’ of your personal data, we mean anything that we do with that information, including collection, use, storage, disclosure or retention.
Types of data we collect about you
We will collect, store, and use the following categories of data when you use our site:
Data you give us. You may give us data about you including:
- Your name
- Your email address
- Your organizational name
- Job title
- Telephone contact details
Data we collect about you, unless you prevent or delete cookie. Refer to our Cookie Statement.
- If you visit our site, we will automatically collect certain technical information, for example, the type of device (and its unique device identifier) you use to access our site, the Internet protocol (IP) address used to connect your device to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, operating system, mobile network information and platform.
- We will automatically collect information about your visit to our site including the full Uniform Resource Locators (URL), clickstream to, through and from the Website (including date and time), pages you viewed, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
When we collect your data
We will collect the vast majority of data about you when you register to use our site, e-mail or otherwise, subscribe to our service, participate in discussion boards or other social media functions on our site, complete a self assessment to the requirements of GFGP, enter a survey, or when you report a problem with our site.
When you visit our site, we may also automatically collect technical information about your visit from your computer.
How we use your data
We process your data for one or more of the following reasons:
To provide you with the services, products and/or information you have requested e.g. issues with registration, logins, activities on the site and queries on discussion forums.
This processing is necessary to meet our contractual obligations to you or to take steps requested by you prior to entering into a contract. Information processed for this purpose includes, but is not limited to email address, name, location, job role, telephone number.
Process the compliance assessments your organization may have completed in the portal. This processing is to provide the AAS with an overview of compliance assessments performed by multiple organization to determine if there are common areas of compliance non conformity.
To send you site update notifications by email e.g. further changes to our terms and conditions, service disruption or site maintenance and new content, member sites and website functionality. We do this only where you have specifically indicated that you consent to receive such communications, for example, when you register to the site e.g. by ticking the consent box. You can withdraw your consent at any time by contacting us at firstname.lastname@example.org In this event, we will stop any processing as soon as we can. However, this will not affect the lawfulness of any processing carried out before your withdrawal of consent and you may no longer be able to use the site in the same way you did before.
This processing is necessary to meet our contractual obligations to you, to take steps requested by you prior to entering into a contract or to meet our legitimate interests. Information processed for this purpose includes, but is not limited to website use and contact details.
For purposes arising from your use of this website, for example, to ensure that we understand who uses our site and how our site is used and to improve our site and ensure it is secure. This processing occurs because it is necessary to meet our legitimate interests in operating this website. Information processed for this purpose includes but is not limited to contact details and website/newsletter use.
We will only use your data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another related reason and that reason is compatible with the original purpose. If we need to use your data for an unrelated purpose, we will seek your consent to use it for that new purpose.
Please note that we may process your data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
We would like to send you information by email about site updates, events, services and opportunities which may be of interest to you.
We will not provide your data to other businesses so they can use it for marketing purposes.
You can unsubscribe from website update notifications via the unsubscribe link on our correspondence. We are developing further functionality in the future which will give you the opportunity to clearly set out what messages you wish to receive by ticking these boxes – we will look to develop this soon so please check back here regularly for updates.
Sharing your data with third parties
We may share your data with third parties who provide services on our behalf, such as invoicing and collecting payments for the services provided by the site.
All our third-party service providers are required to take appropriate security measures to protect your data in line with our policies. We do not allow them to use your data for their own purposes. We permit them to process your data only for specified purposes and in accordance with our instructions.
Where your data is shared with third parties, we will seek to share the minimum amount necessary.
Any data from the processing of compliance assessments which is shared with a third party will be at a high level and anonymized.
Where we store or use your data
We may store data collected by the website manually or electronically. The data are stored on Amazon Web Services servers in their premises within Ireland.
There may be occasions when we transfer your data outside the European Economic Area (EEA), for example, when we communicate with you using a cloud based service provider that operates outside the EEA such as Survey Monkey/MailChimp/Eventbrite/Wuhoo/Zoho etc. Such transfers will only take place if one of the following applies:
- the country receiving the data is considered by the EU to provide an adequate level of data protection;
- the organisation receiving the data is covered by an arrangement recognised by the EU as providing an adequate standard of data protection e.g. transfers to companies that are certified under the EU US Privacy Shield;
- the transfer is governed by approved contractual clauses;
- the transfer has your consent;
- the transfer is necessary for the performance of a contract with you or to take steps requested by you prior to entering into that contract; or
- the transfer is necessary for the performance of a contract with another person, which is in your interests.
Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of data transmitted to the website and any transmission is at your own risk.
Third party websites
In the future it is likely our site will contain links to and from various third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
Retaining your data
We will only retain your data for as long as we need it to fulfil our purposes, including any relating to legal, accounting, or reporting requirements.
Under certain circumstances, by law you have the right to:
- Request access to your data (commonly known as a "subject access request"). This enables you to receive a copy of your data and to check that we are lawfully processing it.
- Request correction of your data. This enables you to ask us to correct any incomplete or inaccurate information we hold about you.
- Request erasure of your data. This enables you to ask us to delete or remove your data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your data where you have exercised your right to object to processing (see below).
- Object to processing of your data where we are relying on our legitimate interests (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground.
- Request the restriction of processing of your data. This enables you to ask us to suspend the processing of your data, for example if you want us to establish its accuracy or the reason for processing it.
- Request the transfer of your data to another party.
Depending on the circumstances and the nature of your request it may not be possible for us to do what you have asked, for example, where there is a statutory or contractual requirement for us to process your data and it would not be possible to fulfil our legal obligations if we were to stop. However, where you have consented to the processing you can withdraw your consent at any time by emailing us at: email@example.com. In this event, we will stop the processing as soon as we can. However, this will not affect the lawfulness of any processing carried out before your withdrawal of consent and you may no longer be able to use the site in the same way as you did before.
If you want to exercise any of the rights described above or are dissatisfied with the way we have used your information, you should contact the AAS’s Data Privacy Team at firstname.lastname@example.org The same email address may be used to contact the AAS’s Data Protection Officer. We will seek to deal with your request without undue delay, and in any event in accordance with the requirements of the GDPR. Please note that we may keep a record of your communications to help us resolve any issues which you raise.
If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office at https://ico.org.uk/concerns/.
Changes to this policy