Transparency Policy
Evidence over assertion.
This is a Transparency Policy, not a privacy policy. It follows the Internet Transparency Code of Practice, so the site models the standard TCIEG helps develop.
Most sites publish a privacy policy that asserts transparency. This one follows the Internet Transparency Code of Practice (ITCoP), the operational layer of Convention 108+. The Code's first principle is evidence over assertion, so this page is built to be inspectable, not just read. As the Code's records mature, this page will link the Controller Identification Record, the notice receipt, and the Notice Event Log as inspectable evidence, not claims. This policy is TCIEG's transparency_policy_point.
1. Who is accountable, before you identify yourself
The Code requires that accountability be inspectable before anyone is asked to identify themselves. So, up front:
You do not need an account, a login, or to identify yourself to read any of the above.
2. What we process, and why
This is a static site that processes the minimum needed to serve pages and let you contact us. Each purpose, its lawful basis, and the processor acting for us:
| What | Why | Lawful basis | Processor |
|---|---|---|---|
| Network metadata (IP, timestamp, request) | Serve and secure the site | Legitimate interest | Cloudflare (global edge) |
| Fonts | Page rendering | Not applicable | None: the Inter font is self-hosted, no third-party font call |
| Email you send us | Answer your message | Your request | Proton (Canada / Switzerland) |
| Newsletter, if you subscribe | Send the update you asked for | Consent (opt in, withdraw anytime) | Ghost / Proton |
We do not run advertising trackers, behavioural analytics, or profiling on this site.
3. Your rights, and how to use them
For legitimate-interest processing (site delivery and security) you may object and request access, correction, or deletion of any personal data we hold about you. For consent-based processing (the newsletter) you may withdraw consent at any time, and every email carries an unsubscribe link.
How: contact info@tcieg.org. We answer rights requests without requiring you to create an account. Derogations: none apply to the rights described here.
4. Cross-border movement and lifecycle
The Code requires cross-border conditions to be knowable before transfer, and notice changes to be logged over time.
- Hosting: served from Cloudflare's global edge on a Canadian-jurisdiction setup; contact email handled by Proton (Canada / Switzerland).
- Transfers: because delivery uses a global CDN, request metadata may be processed at edge locations outside Canada. Recipient type: infrastructure processor. Safeguard: contractual processor terms.
- Retention: infrastructure logs are short-lived (processor default); email and subscriptions are kept only while active, then deleted on request.
- Changes: material changes to this policy are dated and, as the Code's tooling lands, recorded in a Notice Event Log so a change cannot be made silently.
5. Conformance, stated honestly
- Target now: Anonymous Disclosure (1FN) for the site. Accountability and disclosure are inspectable without you identifying yourself.
- Where consent is the basis (the newsletter): TCIEG is working toward Demonstrable Consent (2FN), issuing a notice and consent receipt you hold, via the reference demo in development.
6. No over-claim
TCIEG contributes to international standards with the mission to support and facilitate the Council of Europe Transparency Code of Practice. Supporting contributions to SC44 Privacy by Default, and ISO/IEC JTC 1 SC 27 WG 5 Privacy and Identity Management. Promoting and implementing the Kantara ANCR ISO/IEC TS 27560:2023 Notice Receipt Exchange Extension for international safety, security and digital privacy infrastructure. TCIEG does not claim ISO or CoE endorsement of this site, and does not claim the ANCR / TS 27560 extension as an adopted ISO/IEC standard; it is a proposal in progress.
Last updated on publication. Questions: info@tcieg.org.