Privacy Policy

Home / Privacy Policy

 

 

 

Education in Crisis (EiC)

For Learning Everywhere

PRIVACY POLICY

A Policy of Education in Crisis (EiC)

 

EiC-GLB-FCR-POL-002 | Version 1.0 | October 2026

Classification: Public | www.eduincrisis.org 

 

Document Metadata

Document Code

EiC-GLB-FCR-POL-002

Version

1.0

Document Type

Privacy Policy

Classification

Public

Primary Owner

Finance, Compliance & Risk (FCR)

Technical Custodian

Partnerships, Resource Mobilization & External Relations (PRER)

Compliance Support

People, Culture & Safeguarding (PCS)

Effective Date

Upon Board Approval

Applies To

All users accessing www.eduincrisis.org and individuals whose data EiC processes

Review Cycle

Every two years, or upon significant legal change

Geographic Scope

Global — all EiC offices and digital presence

Governing Law

United Republic of Tanzania

Related Instruments

EiC Data Protection Policy; EiC Child Protection & Safeguarding Policy; EiC PSEA Policy; EiC Website Terms of Use

Departments

FCR, PRER, PCS, OPS

Core Principle

EiC handles all personal data with transparency, integrity, and respect for the dignity and rights of every individual.

Institutional Tagline

For Learning Everywhere

Notice: This Privacy Policy describes how Education in Crisis (EiC) collects, uses, stores, and protects personal data in connection with our website at www.eduincrisis.org and our programmes. By using the EiC website or engaging with EiC’s services, you acknowledge that you have read and understood this Policy.

1. Introduction and Commitment

Education in Crisis (EiC) — For Learning Everywhere — is committed to protecting the privacy, dignity, and rights of every individual whose personal data we collect or process. This Privacy Policy sets out how EiC collects, uses, stores, shares, and protects personal information in connection with our website, programmes, partnerships, fundraising activities, and organisational operations.

EiC operates in complex humanitarian contexts, including conflict-affected and fragile environments. We recognise that mishandling of personal data — particularly data relating to vulnerable individuals such as programme participants, children, displaced populations, or field informants — can have serious consequences. This Policy reflects our commitment to handling all personal data with the highest standards of care, transparency, and accountability.

EiC is registered in the United Republic of Tanzania (Coordination Headquarters, Arusha, 2023) and the Republic of Sudan (National NGO, South Kordofan, 2020). Our data practices comply with applicable Tanzanian data protection law, including the Electronic and Postal Communications Act (Tanzania), and with the General Data Protection Regulation (GDPR) where processing involves data subjects in the European Union or United Kingdom.

 

2.  Who We Are — Data Controller

For the purposes of this Privacy Policy, Education in Crisis (EiC) acts as the Data Controller in respect of personal data collected through our website at www.eduincrisis.org and through our organisational activities.

Our registered coordination address is:

 

Data Controller: Education in Crisis (EiC) | P.O. Box 11993, Mlimani, Sinoni, Arusha, United Republic of Tanzania | info@eduincrisis.org | +255 742 342 921

Where EiC acts as a data processor on behalf of a donor, UN agency, or implementing partner, the terms of the applicable data processing agreement govern the processing of that personal data in addition to this Policy.

 

3. Scope of This Policy

This Privacy Policy applies to:

  • All visitors to the EiC website at www.eduincrisis.org;
  • Individuals who subscribe to EiC communications, newsletters, or mailing lists;
  • Individuals who contact EiC through our website, by email, or through social media channels;
  • Donors, supporters, volunteers, and prospective partners who engage with EiC;
  • Applicants for employment, volunteer positions, or consultancy roles with EiC;
  • Programme participants, community members, and individuals whose data is collected as part of EiC’s humanitarian and education programmes.

This Policy does not apply to third-party websites, applications, or services that may be linked from the EiC website. EiC is not responsible for the privacy practices of third parties.

 

4. Personal Data We Collect

EiC collects personal data in the following categories, depending on how you interact with us:

 

4.1 Data You Provide Directly

  • Identity data: full name, date of birth, gender, nationality;
  • Contact data: email address, telephone number, postal address;
  • Communication data: messages, feedback, and correspondence you send to us;
  • Financial data: payment or donation information (processed through secure third-party providers; EiC does not store card details);
  • Volunteer and employment data: CV/resume, qualifications, professional history, references;
  • Programme data: information provided as part of registration for EiC programmes, trainings, or events.

4.2 Data We Collect Automatically

  • Technical data: IP address, browser type and version, time zone, browser plug-in types and versions, operating system and platform;
  • Usage data: information about how you use our website, including pages visited, time spent, links clicked, and referring URLs;
  • Cookie data: see Section 6 (Cookies and Tracking Technologies) below.

4.3 Data We Receive from Third Parties

  • Referral data: where you have been referred to EiC by a partner organisation, we may receive limited contact data from that partner;
  • Public information: information that is publicly available, such as professional profiles used for partnership due diligence;
  • Programme partner data: data shared by implementing partners, UN agencies, or government counterparts as part of jointly delivered programmes.

4.4 Sensitive Personal Data

EiC may collect special categories of sensitive personal data in specific programme contexts, including health data, data relating to ethnic or racial origin, and data about displacement or conflict-affected status. Such data is collected only where strictly necessary for programme delivery, with explicit informed consent, and is handled with enhanced safeguards in accordance with our Data Protection Policy.

 

5. How We Use Your Personal Data

EiC uses personal data only for lawful, specified, and legitimate purposes. The following table summarises our main processing activities:

 

Purpose

Examples

Lawful Basis

Programme delivery

Registration, attendance tracking, learning assessments

Legitimate interests / Consent

Communication

Responding to enquiries, sending updates and newsletters

Consent / Legitimate interests

Fundraising

Processing donations, acknowledging supporters

Contract / Legitimate interests

Recruitment

Processing job and volunteer applications

Pre-contract / Legitimate interests

Research & evidence

Programme evaluations, needs assessments, learning studies

Legitimate interests / Consent

Legal compliance

Meeting statutory obligations, responding to legal requests

Legal obligation

Safety & security

Preventing harm, protecting staff and programme participants

Vital interests / Legal obligation

Website improvement

Analysing usage patterns, fixing technical issues

Legitimate interests

EiC does not use personal data for automated decision-making that produces significant legal or similarly serious effects on individuals without appropriate human oversight and consent.

 

6. Cookies and Tracking Technologies

EiC’s website uses cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and understand how visitors interact with our content. Cookies are small text files placed on your device when you visit a website.

 

6.1 Types of Cookies We Use

  • Essential cookies: necessary for the website to function correctly. These cannot be switched off.
  • Analytics cookies: help us understand how visitors interact with our website (e.g. pages visited, time spent). We use this data in aggregate, anonymised form only.
  • Functional cookies: remember your preferences and choices to improve your experience.
  • Third-party cookies: where our website includes embedded content or sharing features from third parties (e.g. social media), those parties may set their own cookies.

You can control or disable cookies through your browser settings. Disabling cookies may affect the functionality of parts of our website. By continuing to use our website without adjusting your browser settings, you consent to our use of cookies as described in this Policy.

 

7. Data Sharing and Disclosure

EiC does not sell, rent, or trade personal data to any third party for commercial purposes. We may share personal data in the following limited circumstances:

 

7.1 Service Providers and Data Processors

EiC engages trusted third-party service providers to support our operations, including IT systems, website hosting, email services, payment processing, and data analytics. These providers act as data processors under contract with EiC and are required to handle data only in accordance with our instructions and applicable data protection law.

 

7.2 Donor and Partner Reporting

Where required by grant agreements or partnership contracts, EiC may share aggregated or anonymised programme data with donors, UN agencies, or implementing partners. EiC does not share identifying personal data of programme participants with donors without explicit consent, and applies the principle of data minimisation to all external reporting.

 

7.3 Legal Requirements

EiC may disclose personal data where required by law, court order, regulatory authority, or governmental request, or where necessary to protect the rights, property, or safety of EiC, its staff, or others.

 

7.4 Organisational Transfers

In the event of a merger, acquisition, restructuring, or transfer of EiC’s operations to another humanitarian organisation, personal data may be transferred as part of that process, subject to appropriate data protection safeguards.

 

Security Protocol: In line with EiC’s field security protocols and child protection commitments, names, locations, and identifying information of programme participants, particularly those in conflict-affected contexts, are never shared in externally published documents or donor-facing materials without informed consent and specific authorisation from EiC’s safeguarding function.

8. International Data Transfers

EiC operates across multiple jurisdictions, including Tanzania and Sudan. As part of our operations, personal data may be transferred between EiC’s offices or to service providers located in other countries.

Where personal data is transferred internationally, EiC ensures that adequate protections are in place, including:

  • Transfers to countries with an adequate level of data protection as recognised by applicable law;
  • Standard contractual clauses or equivalent safeguards where required under GDPR for transfers involving EU/UK data subjects;
  • Intra-organisational data transfer protocols between EiC’s Tanzania and Sudan offices;
  • Strict access controls limiting who may access field-level data involving individuals in conflict-affected contexts.

9. Data Retention

EiC retains personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law, grant conditions, or donor reporting requirements. Our standard retention periods are:

 

Data Category

Retention Period

Basis

Programme participant data (conflict-affected / child protection contexts)

Indefinite (with access controls)

Safeguarding obligations

Donor and financial records

7 years after end of grant

Legal / grant compliance

Employee and volunteer records

6 years after end of engagement

Legal obligation

General correspondence and enquiries

2 years

Legitimate interests

Website analytics data (anonymised)

13 months (rolling)

Legitimate interests

Job applicant data (unsuccessful)

12 months

Legitimate interests

Donation records

7 years

Financial/legal compliance

At the end of the applicable retention period, personal data is securely deleted or anonymised. Physical records are disposed of by shredding or equivalent secure destruction methods.

 

10. Your Data Protection Rights

Subject to applicable law and certain limited exceptions, individuals whose personal data EiC holds have the following rights. To exercise any of these rights, please contact EiC using the details in Section 18.

 

  1. Right of Access: You may request a copy of the personal data EiC holds about you (commonly known as a Subject Access Request).
  2. Right to Rectification: You may request that EiC corrects inaccurate or incomplete personal data about you without undue delay.
  3. Right to Erasure: You may request that EiC deletes your personal data where it is no longer necessary for the purpose it was collected, where you withdraw consent, or where there is no other lawful basis for processing.
  4. Right to Restriction of Processing: You may request that EiC restricts the processing of your personal data in certain circumstances.
  5. Right to Data Portability: Where processing is based on consent or contract and carried out by automated means, you may request that EiC provides your personal data in a structured, commonly used, machine-readable format.
  6. Right to Object: You may object at any time to the processing of your personal data where it is based on EiC’s legitimate interests. You may also object to the use of your data for direct marketing purposes.
  7. Right to Withdraw Consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
  8. Right to Lodge a Complaint: You may lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. In Tanzania, the relevant authority is the Tanzania Communications Regulatory Authority (TCRA). EU/UK data subjects may also contact their national data protection authority.

EiC will respond to all rights requests within one month of receipt. This period may be extended by a further two months where the request is complex or numerous, in which case EiC will notify you within the first month.

 

11. Children’s Privacy and Digital Safeguarding

Core Commitment: EiC is a UNICEF Full Capacity Partner (August 2025) and a member of the Alliance for Child Protection in Humanitarian Action (ACPHA). The safety, dignity, and rights of every child are non-negotiable in all EiC operations, including our digital presence.

The EiC website is not directed at children under the age of 13. EiC does not knowingly collect personal data from children under 13 without verifiable parental or guardian consent. If EiC becomes aware that personal data has been collected from a child under 13 without appropriate consent, EiC will take prompt steps to delete such data.

Where EiC collects data about children as part of programme activities (including as programme participants, scholarship recipients, or learning assessment subjects), such data is:

  • Collected with the informed consent of the child’s parent or guardian;
  • Handled with enhanced security and access controls;
  • Never shared externally in an identifiable form without specific authorisation;
  • Subject to EiC’s Child Protection and Safeguarding Policy and Do No Harm protocols.

Images and case studies featuring children are published on the EiC website only where documented consent has been obtained in accordance with EiC’s Safeguarding and Photography/Media Protocol. EiC applies a strict Do No Harm approach: images that could identify children in conflict-affected contexts, or that could expose them to risk, are never published.

 

12. Data Security

EiC implements appropriate technical, organisational, and procedural measures to protect personal data against unauthorised access, loss, alteration, disclosure, or destruction. These measures include:

  • Secure storage systems with access controls and role-based permissions;
  • Encrypted transmission of personal data over networks (HTTPS/TLS);
  • Regular security reviews and updates to IT systems and software;
  • Staff training on data protection, information security, and safe data handling;
  • Physical security measures at EiC office premises;
  • Secure disposal of physical records and decommissioned devices.

Where EiC engages third-party service providers to process personal data, those providers are required by contract to implement equivalent or higher security standards.

EiC acknowledges that no method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect personal data, we cannot guarantee absolute security. In the event of a data breach that poses a risk to the rights and freedoms of individuals, EiC will notify the relevant supervisory authority and affected individuals in accordance with applicable legal requirements.

 

13. Donor and Supporter Privacy

EiC values the trust placed in us by our donors and supporters. Personal data provided in connection with a donation — including name, contact details, and payment information — is used solely to process the donation, issue receipts and acknowledgements, and communicate with the donor about EiC’s work where consent has been given.

EiC does not share donor personal data with third parties for their own marketing or commercial purposes. Donor data may be shared with EiC’s financial auditors or regulatory authorities as required by law.

Where EiC publishes donor recognition (such as an Annual Report acknowledgements page), EiC will seek explicit consent before listing any individual donor by name. Donors who prefer to remain anonymous will have that preference respected.

 

14. Programme Participants and Field Data

EiC works with some of the world’s most vulnerable populations, including children and communities in conflict-affected areas of Sudan. The protection of programme participant data is therefore a matter of operational security and humanitarian ethics, not only legal compliance.

EiC applies the following principles to field-level data:

  • Necessity: only data strictly necessary for programme delivery and accountability is collected;
  • Informed consent: data is collected with the informed consent of participants or their guardians, using appropriate language and methods for the local context;
  • Minimum retention: field data is retained only as long as required by the programme and relevant grant conditions;
  • Conflict sensitivity: data that could expose individuals to harm — including names, locations, affiliations, or identifying characteristics — is handled with heightened care in conflict-affected contexts;
  • MEAL standards: data collected as part of EiC’s monitoring, evaluation, accountability, and learning (MEAL) activities follows the EiC MEAL framework and applicable inter-agency data protection standards for humanitarian action.

15. Third-Party Links and External Platforms

The EiC website may contain links to third-party websites, social media platforms, and partner organisation sites. These sites are operated independently of EiC and have their own privacy policies and terms. EiC does not control and is not responsible for the content, privacy practices, or data handling of any third-party site.

EiC encourages users to read the privacy policies of any third-party site they visit through links on the EiC website. The presence of a link on the EiC website does not constitute an endorsement of the linked site or its privacy practices.

 

16. Governing Law and Jurisdiction

This Privacy Policy is governed by and construed in accordance with the laws of the United Republic of Tanzania. Any disputes arising out of or in connection with this Policy shall be subject to the non-exclusive jurisdiction of the courts of the United Republic of Tanzania.

Where EiC’s processing activities involve individuals in the Republic of Sudan, applicable provisions of Sudanese law apply in addition to Tanzanian law. In cases of conflict between the two jurisdictions, Tanzanian law shall prevail.

For individuals based in the European Union or United Kingdom, the General Data Protection Regulation (EU GDPR) and UK GDPR apply to the extent that EiC processes personal data of such individuals in connection with the offering of services or monitoring of behaviour. In such cases, EiC’s compliance with GDPR obligations is subject to the oversight of the relevant national data protection authority.

 

17. Updates to This Privacy Policy

EiC reviews this Privacy Policy at least every two years, and following any significant change in our data processing activities, applicable law, or organisational structure. When material changes are made, EiC will:

  • Post the updated policy on our website at www.eduincrisis.org/privacy-policy/ with a revised effective date;
  • Where reasonably practicable, notify individuals whose data we hold of material changes by email or prominent notice on the website;
  • Seek fresh consent where the change affects processing that was previously carried out on the basis of consent.

Your continued use of the EiC website after any changes are posted constitutes your acceptance of the updated Privacy Policy. If you do not agree with the updated Policy, you should cease using the EiC website and may contact us to exercise your rights in respect of data we hold about you.

 

18. Contact, Complaints, and Data Requests

If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or wish to raise a concern about EiC’s handling of your personal data, please contact us using the following details:

 

Contact Type

Details

General Privacy Enquiries

info@eduincrisis.org | +255 742 342 921

Subject Access Requests

info@eduincrisis.org (Subject: SAR — Data Request)

Data Protection Concerns

info@eduincrisis.org (Subject: Data Protection Concern)

Postal Address

Education in Crisis (EiC), P.O. Box 11993, Mlimani, Sinoni, Arusha, United Republic of Tanzania

Safeguarding Reports

info@eduincrisis.org (Subject: Safeguarding) — EiC responds to all safeguarding-related data concerns within 48 hours

EiC is committed to resolving all privacy concerns fairly and promptly. If you are not satisfied with EiC’s response, you have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction.

 

ANNEX A — Definitions

Term

Definition

Consent

Freely given, specific, informed, and unambiguous indication by an individual of their agreement to the processing of their personal data, demonstrated by a clear affirmative act.

Controller

The natural or legal person, public authority, agency, or other body that determines the purposes and means of the processing of personal data.

Cookie

A small text file placed on a user’s device by a website, used to store preferences, session information, or analytics data.

Data Subject

An identified or identifiable natural person whose personal data is processed by EiC.

GDPR

The General Data Protection Regulation (EU) 2016/679 and, as applicable, its UK equivalent retained in UK law following Brexit.

Lawful Basis

A legal ground under applicable data protection law that justifies the processing of personal data.

Legitimate Interests

A lawful basis for processing where EiC has a genuine, proportionate interest in processing personal data that is not overridden by the interests or rights of the data subject.

Personal Data

Any information relating to an identified or identifiable natural person, including name, email address, location data, IP address, or any other identifier.

Processing

Any operation performed on personal data, including collection, recording, organisation, storage, use, disclosure, erasure, or destruction.

Processor

A natural or legal person that processes personal data on behalf of the controller.

Sensitive Personal Data

Special categories of personal data that reveal racial or ethnic origin, political opinions, religious beliefs, trade union membership, health data, biometric or genetic data, sexual orientation, or data relating to criminal convictions.

Subject Access Request (SAR)

A request by an individual to receive a copy of the personal data an organisation holds about them.

 

ANNEX B — Related EiC Policies and Instruments

This Privacy Policy forms part of EiC’s broader data governance and safeguarding framework. It should be read alongside the following related policies and instruments:

 

Policy / Instrument

Document Code

Custodian Department

EiC Data Protection Policy

EiC-GLB-FCR-POL-001

Finance, Compliance & Risk (FCR)

EiC Child Protection & Safeguarding Policy

EiC-GLB-PCS-POL-001

People, Culture & Safeguarding (PCS)

EiC PSEA Policy

EiC-GLB-PCS-POL-002

People, Culture & Safeguarding (PCS)

EiC Website Terms of Use

EiC-GLB-PRER-POL-001

Partnerships, Resource Mobilization & External Relations (PRER)

EiC Information & Cyber Security Policy

EiC-GLB-OPS-POL-001

Operations & Supply Chain (OPS)

EiC Communications & Media Policy

EiC-GLB-PRER-POL-002

Partnerships, Resource Mobilization & External Relations (PRER)

 

Adoption Statement: This Privacy Policy was approved by the Governing Body of Education in Crisis (EiC) and is effective from the date of adoption. It supersedes any prior privacy notice or statement published by EiC. Compliance with this Policy is mandatory for all EiC staff, volunteers, consultants, and partners who process personal data on EiC’s behalf.

 

Education in Crisis (EiC) — For Learning Everywhere

www.eduincrisis.org | info@eduincrisis.org | +255 742 342 921

Arusha, United Republic of Tanzania