Legal & trust

ICF Gateway Privacy Policy — Account Services

This approved notice explains how ICF Gateway, implemented by ECITD, handles personal data for public accounts, funding intelligence, membership administration and moderated network services.

ICF Gateway Management · Mediterranean & Europe
01

1. Scope and responsible organisation

This notice covers the ICF Gateway website, public Site accounts, saved opportunities, funding preferences, membership administration, member profiles, consultation entitlements and partnership requests. ICF Gateway is implemented by ECITD. ECITD determines why and how personal data is used for these services, subject to the final owner and legal review of this notice.

02

2. Authentication providers

Public account authentication is provided through Supabase Auth. For the initial release, Google is the only enabled identity provider. Supabase and Google process authentication data under their respective terms and privacy notices. ICF Gateway requests only OpenID, email and profile identity scopes and does not request access to Gmail, Google Drive, Google Calendar, Google Contacts, YouTube or other Google services.

03

3. Verified identity information

After authentication, ICF Gateway receives a stable Supabase user identifier, verified email address and, where available, the name supplied by the identity provider. During initial setup, the user supplies or confirms their full name, organisation, professional title or role and account purpose. The verified email is read-only in the setup form and is not replaced using browser-submitted identity data.

04

4. Account and service records

ICF Gateway may store account status, registration intention, accepted legal versions, acceptance timestamps, last sign-in time, saved opportunities, funding preferences, membership-application links, approved member-profile links, consultation entitlements and usage, partnership requests, consent records and necessary service history. A free Site account is maintained separately from membership status.

05

5. Purposes of processing

Personal data is used to create and secure accounts; provide authorised access to funding and network information; personalise saved records and preferences; administer membership applications, offline-payment status and member publication; manage consultation entitlements; moderate partnership requests; respond to enquiries; send essential service communications; investigate abuse; maintain audit history; and comply with applicable legal, contractual and security obligations.

06

6. Cookies, sessions and security

The account service uses essential Secure, HttpOnly and SameSite-protected cookies to maintain an authenticated session. Provider tokens are encrypted inside the server-managed session cookie and are not stored in D1, localStorage or browser-visible JavaScript. D1 stores only an opaque session identifier and revocation status. Security and abuse-prevention records may include event timestamps, account identifiers, rate-limit events and non-sensitive audit reasons.

07

7. Saved opportunities and funding preferences

Authenticated users may save funding opportunities and record funding interests such as sectors, themes, applicant roles, project maturity, preferred instruments, partnership interests and alert preferences. These records support dashboard personalisation. Automated matching or email alerts must not be represented as active unless the relevant workflow and delivery provider have been implemented and tested.

08

8. Membership applications and member profiles

Membership applications, payment evidence, review notes, compliance information and private contact details remain restricted to authorised administrators. Creating a free account does not approve membership. A member profile becomes public only after the existing approval, confirmed or waived payment, public-profile consent, active-profile and publication requirements are satisfied. Only approved public fields are returned through public member interfaces.

09

9. Consultation and partnership information

For active members, ICF Gateway may record consultation allocations, adjustments and completed usage. Partnership requests may contain project needs, thematic interests, geography, timing, confidentiality choices and consent to share selected information. Requests are reviewed by authorised administrators before matching or introduction. Another member’s private contact information is not disclosed automatically.

10

10. Communications and consent

Essential account, security, membership and service communications are separate from optional marketing. Marketing consent is optional, unchecked by default and may be withdrawn. Withdrawal does not prevent communications needed to operate or secure the account, administer a requested service or meet applicable obligations.

11

11. Service providers and international processing

Relevant service providers may include Supabase for authentication, Google as the optional identity provider, Cloudflare for hosting and abuse protection, ChatGPT Sites for Site hosting, and separately approved email or operational providers. Processing may occur outside the user’s country. ECITD must maintain appropriate provider agreements, access controls and legally required transfer safeguards before public launch.

12

12. Retention and deletion requests

Account and service records are retained only for as long as needed for the stated purposes and applicable legal, contractual, audit, fraud-prevention or security requirements. A user may request account deletion. Deletion may first place the account in a review state because membership, payment, consent, audit or dispute records may need to be retained or de-identified. Authentication sessions are revoked when an account is deleted or suspended.

13

13. User rights

Subject to applicable law, users may request access to relevant personal data, correction of inaccurate information, deletion, restriction, objection, portability where applicable, and withdrawal of consent. Users may also raise a concern about how their information is handled. Identity verification may be required before fulfilling a request, and lawful retention exceptions may apply.

14

14. Privacy contact

Privacy questions and rights requests should be sent to info@icf-gateway.org. Requests should not include passwords, authentication codes, payment-card details or unnecessary sensitive information. The final notice must confirm ECITD’s formal privacy contact details and any regulator or complaint route required by applicable law.

15

15. Changes to this notice

Material changes will be issued as a new version. Where required, account holders will be asked to review and accept the new version before continuing to use affected services. The accepted version and timestamp are recorded for accountability.