Privacy Policy
Last updated: 2026
The Connect, a platform operated by CEFA ("we", "us"), is the controller of personal data processed through this website and application. This policy explains what we collect, why, the legal bases we rely on, and the rights you have. It is written to align with the EU and UK GDPR, the ePrivacy Directive, the California Consumer Privacy Act as amended by the CPRA, and comparable data-protection laws. Contact: privacy@thecefa.org.
Data we collect: account details (name, email, organisation, role); subscription and billing data (processed by Stripe — we do not store full card numbers); usage data (searches, saved notices, alerts, log and device data); and cookies / local storage as described in our Cookie Policy.
Why we process it, and our legal bases (GDPR Art. 6): to provide the service and your subscription — performance of a contract; to secure the platform, prevent abuse, and improve features — our legitimate interests; for preference and analytics cookies and any marketing — your consent; and to meet tax, accounting, and legal obligations — legal obligation. Where we rely on legitimate interests we have balanced them against your rights, and you may object at any time.
We do not sell your personal data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under the CPRA. We use no advertising cookies.
Who we share it with: service providers ("sub-processors") who process data on our instructions under a data-processing agreement — currently Vercel (hosting), Supabase (database and authentication), and Stripe (billing). See our Sub-processors page. We may also disclose data where required by law or to protect our rights.
International transfers: where personal data is transferred outside the EEA, UK, or your home jurisdiction, we rely on an adequacy decision where available, or on Standard Contractual Clauses (and the UK Addendum / IDTA) with supplementary safeguards.
Retention: account data is kept while your subscription is active and for a limited period afterwards to meet legal, tax, and audit obligations; usage logs are kept for a shorter operational period. We delete or anonymise data when it is no longer needed.
Security: encryption in transit and at rest, role-based access control, single active session per account, tamper-evident audit logging, and least-privilege service operations.
Your rights: depending on where you live you have rights of access, correction, deletion, portability, restriction, and objection, the right to withdraw consent, and the right to opt out of any sale or sharing — see our Data Rights page for the full list and how to exercise them. EU/UK users may also lodge a complaint with their supervisory authority.
Children: the platform is intended for institutional and professional use and is not directed to anyone under 18.
Changes: we will post any material change here and, where required, ask for renewed consent. Questions: privacy@thecefa.org.