Data Processing Information
Last Updated: December 2025
1. Data Controller
Leaders of Tomorrow (LOT) is the data controller responsible for processing your personal data.
Contact Information:
Email: lot@lotep.org
Location: Baghdad, Iraq
2. Legal Basis for Processing (GDPR Article 6)
We process your personal data based on the following legal grounds under GDPR Article 6:
Special Category Data: We do not intentionally collect special category data (sensitive personal data) as defined in GDPR Article 9, unless explicitly provided by you with consent.
3. Categories of Personal Data
We process the following categories of personal data:
- Identity data (name, age, date of birth)
- Contact data (email, phone, address)
- Application data (essays, interview responses, qualifications)
- Program participation data (attendance, activities, projects)
- Technical data (IP address, device information, cookies)
- Analytics data (website usage, behavior patterns, geographic location)
- Google account data (when signed into Google and ads personalization is enabled: search history, YouTube history, location, data from Google partner sites)
4. Purposes of Processing
We process your personal data for the following purposes:
- Application evaluation and selection
- Program administration and delivery
- Communication with participants
- Attendance tracking and certification
- Alumni network management
- Program improvement and analytics
- Website analytics and user behavior analysis (via Google Analytics)
- Audience segmentation and remarketing
- Ads personalization and targeted advertising
- Cross-device tracking and measurement (via Google Signals)
- Legal compliance and dispute resolution
5. Data Recipients
We may share your data with:
- Program facilitators and coordinators
- Other participants in your Virtual Host Family
- Service providers (platform providers, email services, cloud storage)
- Google LLC: We share website usage data with Google through Google Analytics for analytics, measurement, and ads personalization purposes
- Google Ads Accounts: When ads personalization is enabled, we export audience lists and key events to linked Google Ads accounts
- Advertising Partners: Data may be shared with advertising networks for remarketing and targeted advertising when you have consented
- Legal authorities when required by law
5.1 Third-Party Platform Providers
We use the following third-party platforms to deliver our program, and your data will be processed by these services:
- Google LLC (United States):
- Microsoft Corporation (United States):
- Zoom Video Communications (United States):
- Zoom - Video conferencing and virtual meetings
- Privacy Policy: zoom.us/privacy
- Discord Inc. (United States):
- Telegram Messenger LLP (United Kingdom/UAE):
Each of these platforms acts as an independent data controller for the data they collect and process. We recommend reviewing their respective privacy policies to understand how they handle your information.
6. International Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place, including standard contractual clauses and adequacy decisions.
Most of our third-party platform providers are based in the United States (Google, Microsoft, Zoom, Discord) or have international operations. These companies implement appropriate safeguards for international data transfers, including:
- Standard Contractual Clauses (SCCs) approved by relevant data protection authorities
- Compliance with GDPR, CCPA, and other applicable data protection regulations
- Technical and organizational security measures
- Data Processing Agreements where required
For specific information about how each platform handles international transfers, please refer to their privacy policies linked in Section 5.1.
7. Data Retention
We retain your personal data for:
- Application data: Until the end of the application cycle, or longer if you are accepted
- Program participation data: For the duration of the program and 3 years after completion
- Alumni data: Indefinitely, unless you request deletion
- Legal/regulatory requirements: As required by applicable law
8. Your Rights (GDPR Chapter III)
Under GDPR and other data protection laws, you have the following rights:
- Right of Access (Article 15): Request a copy of your personal data and information about how we process it.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17): Request deletion of your data under certain circumstances ("right to be forgotten").
- Right to Restrict Processing (Article 18): Request that we limit how we use your data in certain situations.
- Right to Data Portability (Article 20): Request a copy of your data in a structured, machine-readable format.
- Right to Object (Article 21): Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, you can withdraw it at any time without affecting prior processing.
- Right to Lodge a Complaint (Article 77): File a complaint with your local data protection supervisory authority.
- Right Not to be Subject to Automated Decision-Making (Article 22): We do not engage in automated decision-making that produces legal or similarly significant effects.
8.1 How to Exercise Your Rights
To exercise any of these rights, contact us at lot@lotep.org with the subject line "Data Subject Rights Request". We will:
- Respond within 30 days (or 1 month as per GDPR)
- Verify your identity before processing the request
- Provide information free of charge (unless requests are manifestly unfounded or excessive)
- Extend the response period by 2 months if necessary, with explanation
8.2 Supervisory Authority
If you believe your data protection rights have been violated, you can lodge a complaint with:
- Your local data protection supervisory authority (EEA List)
- The Information Commissioner's Office (ICO) if you are in the UK
9. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal effects or significantly affects you.
10. Google Analytics and Advertising Features
Google Signals: We have activated Google Signals, which allows Google Analytics to collect and associate data from users signed into Google accounts who have consented to ads personalization. This includes:
- Cross-device tracking and reporting
- Remarketing with Google Analytics audiences
- Advertising reporting features
- Demographics and interests reports
User-ID and User-Provided Data: We may collect user-provided data in a privacy-safe way to improve measurement and conversion tracking. This data supplements our Google Analytics data and may be shared with linked Google Ads accounts.
Granular Location and Device Data: We collect city-level location metadata and granular device details for location and device-based analytics capabilities.
Ads Personalization: When ads personalization is allowed, we may export Google Analytics audiences and key events to linked advertising accounts for delivering personalized experiences. You can disable ads personalization through your Google Ads Settings.
We adhere to the Google Advertising Features Policy and do not collect data related to sensitive categories as defined by Google.
11. Consent Management & Withdrawal
Where we process your data based on consent, you have the right to:
- Provide Informed Consent: We provide clear information about what you're consenting to before collecting your data
- Withdraw Consent: You can withdraw consent at any time through:
- Our cookie consent banner (for cookies and analytics)
- Contacting us at lot@lotep.org (for program-related data)
- Unsubscribing from emails (for marketing communications)
- Granular Consent: You can provide or withdraw consent for specific processing activities (e.g., analytics vs. necessary cookies)
Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
12. User Data Collection Acknowledgement
By using our website and services, you acknowledge that:
- We have provided you with clear, transparent information about data collection and processing
- You have the right to consent or refuse consent for non-essential data processing
- You consent to the association of your data with Google's information when using our website while signed into Google (only if you have accepted analytics cookies)
- Data may be used for analytics, measurement, and ads personalization (subject to your consent choices)
- You can manage your data and privacy settings through your Google account
- You can access and delete your data via Google My Activity
- You can exercise all data subject rights outlined in Section 8
13. Contact & Data Protection Officer
For questions about data processing, to exercise your rights, or to contact our data protection contact:
Email: lot@lotep.org
Subject Line: "Data Protection Inquiry" or "Data Subject Rights Request"
Location: Baghdad, Iraq
Response Time: We will respond to all data protection inquiries within 30 days (1 month) as required by GDPR.
Complaints: If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.