RegisterVersion: 1.0
Date of publication: 22 September 2026
Last update: 22 September 2026
Organisation: DirectDemocracyS
European Commission PIC: 881951064
Registered international office: str. Muzicii nr. 22, postal code 410514, Oradea, Bihor County, Romania, European Union
Privacy contact: privacy_support@directdemocracys.org
Data Protection Officer (DPO): Franco-Romeo Zaccherini
DirectDemocracyS considers the protection of personal data, privacy, anonymity, confidentiality, security and individual freedom to be fundamental principles of its entire system.
This Privacy Policy explains, in detail, how DirectDemocracyS collects, receives, generates, processes, verifies, protects, stores, separates, transfers, archives and, where appropriate, deletes personal data.
This Policy applies to the DirectDemocracyS system, its websites, platforms, online services, internal areas, social areas, registration systems, verification systems, communication systems, administrative systems, security systems and authorised internal groups, insofar as they process personal data.
DirectDemocracyS does not consider privacy to be merely a legal obligation. Privacy is also an architectural, organisational and democratic principle.
The system is therefore designed around several fundamental concepts:
data minimisation;
purpose limitation;
confidentiality;
security;
privacy by design;
privacy by default;
separation of personal identity from operational identity;
anonymity wherever anonymity is compatible with the user's chosen or required user type;
controlled visibility;
need-to-know access;
separation of verification phases;
use of unique codes;
restricted access to highly sensitive information;
limited retention on network-accessible systems;
long-term storage only where necessary and preferably in protected environments;
accountability;
transparency;
user control over voluntarily disclosed information.
DirectDemocracyS recognises that different users have different requirements.
A person who participates only as a Free user does not necessarily need to reveal their legal identity.
A person who wishes to exercise rights that require a verified identity, participate in shared leadership, become an official member or perform official or political representation may need to undergo additional verification.
The amount of personal information processed therefore depends on the user's relationship with the system, the user type selected or obtained, the activities performed and the legal or security requirements applicable to those activities.
For the purposes of this Privacy Policy, the relevant DirectDemocracyS entity is identified as follows:
DirectDemocracyS
European Commission PIC: 881951064
Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union
Privacy contact:
privacy_support@directdemocracys.org
Data Protection Officer (DPO):
Franco-Romeo Zaccherini
Requests concerning personal data, privacy, identity verification records, access to personal information, correction, restriction, deletion, objection, portability or other applicable data protection rights may be directed to the privacy contact above.
Where a specific request requires additional verification that the requester is the person entitled to receive or modify the information, DirectDemocracyS may request only the minimum additional information necessary to verify that right.
DirectDemocracyS will not request unnecessary identity information merely because a user wishes to exercise a privacy right.
This Privacy Policy applies, as applicable, to:
visitors to public DirectDemocracyS websites;
Public users;
Test users;
Free users;
Guest users;
Access users;
Partially Registered users;
Verified users;
Members;
Politicians;
Representatives;
Owners;
Managers;
Responsible users;
Administrators;
SuperAdministrators;
Guarantors;
official representatives;
political representatives;
employees and collaborators, where their data are processed;
persons participating in identity verification;
persons participating in compatibility or skills verification;
persons communicating with DirectDemocracyS;
persons whose data are processed for security, legal, administrative, accounting or organisational purposes.
The terminology of user types is governed by the applicable DirectDemocracyS rules.
Not every user type has the same data requirements.
In particular, the fact that DirectDemocracyS may be able to verify a person's identity does not mean that the person's real identity is automatically visible to ordinary users.
DirectDemocracyS follows a simple fundamental principle:
A person's identity should be known only when there is a legitimate reason to know it.
The system therefore separates, as far as technically and organisationally possible, the following concepts:
the person's real-world identity;
the person's DirectDemocracyS username;
the person's email address;
the person's telephone number;
the person's verification codes;
the person's compatibility information;
the person's skills information;
the person's identity-verification information;
the person's public profile;
the person's internal activities;
the person's representative profile;
security and administrative records.
These categories are not automatically interchangeable.
A person may therefore be known inside the operational system by a username without that username publicly revealing their real name.
DirectDemocracyS recognises, wherever permitted by the user's user type and the applicable rules, a fundamental right to operate under an anonymous or non-identifying username.
For ordinary users, the username does not have to correspond to:
the person's first name;
the person's surname;
their legal name;
their address;
their city;
their telephone number;
their email address;
their date of birth;
their employer;
their professional identity;
their social-media identity;
or any other real-world identifying information.
A user may therefore participate using a username that has no obvious connection with their real identity.
The username is the person's operational identity within DirectDemocracyS.
A user may choose an anonymous username according to the applicable username rules.
Examples of privacy-preserving formats include:
For example:
BlueMountain
provided that the nickname does not reveal information that the user does not wish to disclose and is not misleading or reserved for another role.
For example:
RO7F4K29
or another structure based on an ISO country code followed by a random combination of letters and numbers.
The country code itself does not have to identify the person's precise location.
For example:
X7Q9-M4P2-Z8
or another permitted random alphanumeric or special-character combination.
A user may use any username permitted by the applicable DirectDemocracyS username rules, provided that it does not falsely represent another person, a protected role, an official position, an administrative function or another identity.
A user who wishes to maintain strong anonymity should avoid usernames containing:
their real name;
their surname;
their date of birth;
their telephone number;
their email address;
their exact address;
an identifiable social-media username;
an employer-specific identifier;
a unique professional identifier;
a combination of information that could easily identify them.
Anonymity also depends on what the user voluntarily publishes.
A perfectly anonymous username can lose much of its protective value if the user publicly publishes enough information to identify themselves.
For this reason, anonymity is a combination of:
the architecture of DirectDemocracyS;
the username selected by the user;
the information voluntarily disclosed by the user;
the security of the user's own devices and accounts;
compliance with the DirectDemocracyS rules.
DirectDemocracyS seeks to provide strong external invisibility for users who are entitled to anonymous participation.
For an anonymous user, ordinary visitors, external users and ordinary members should see the user's operational username rather than their real identity.
The objective is that a person viewing the public or ordinary internal profile should not be able to derive the user's:
legal name;
surname;
home address;
telephone number;
personal email address;
identity-document information;
verification information;
private identity-verification material.
The user's public or ordinary operational identity is therefore separated from their protected identity information.
This is particularly important for people who participate in political, social, professional, scientific, cultural or other activities and who may have legitimate reasons to protect their personal identity.
DirectDemocracyS also applies the principle of internal invisibility.
Internal invisibility means that even within DirectDemocracyS, a person's real identity is not automatically available to every administrator, member, specialist, verifier, manager or other user.
Access to personal identity information is restricted according to:
role;
purpose;
necessity;
authorisation;
security requirements;
legal requirements;
the particular verification activity being performed.
A person performing a compatibility test does not normally need to know the applicant's legal name.
A person performing a skills assessment does not normally need to know the applicant's legal name.
A person performing an identity verification activity receives only the information and codes necessary to perform that activity.
This separation is one of the principal mechanisms through which DirectDemocracyS seeks to protect anonymity.
DirectDemocracyS uses strong technical and organisational separation between usernames and real identity.
However, the legal concept of anonymisation must be distinguished from pseudonymisation.
Where DirectDemocracyS retains protected information that could, under exceptional authorised circumstances, be used to establish a connection between a username and a real identity, that information remains personal data under applicable data protection law.
Therefore, this Privacy Policy uses the expression “anonymity and invisibility” to describe the protection experienced by ordinary users and unauthorised persons, while recognising that exceptional legally authorised access may exist.
This does not give ordinary users, ordinary administrators or unauthorised third parties a right to access the protected identity information.
DirectDemocracyS follows another fundamental principle:
Users decide what information they voluntarily make visible, to whom, when and in what manner, except where information must be processed privately for legal, security, technical or organisational reasons.
Where the platform provides a visibility option, users may determine, according to the applicable rules and technical possibilities:
whether information is public;
whether information is visible only internally;
whether information is visible to a specific group;
whether information is visible to specific authorised persons;
whether information remains private;
when information becomes visible;
when information stops being visible;
whether information is disclosed voluntarily during a specific activity.
The system does not interpret voluntary publication of one item of information as consent to publish all other information about the same person.
For example, publication of a user's username does not mean that the person's real name, telephone number, address or identity document may also be published.
Some information is processed for technical, legal or security reasons even when it is not publicly visible.
Examples may include:
registration email address;
verified telephone number;
authentication information;
security logs;
identity-verification records;
identity documents;
identity-verification videos;
verification codes;
administrative records;
payment or accounting information;
employment records;
security information;
incident records.
Such information is not made public merely because it exists within the DirectDemocracyS system.
Depending on the user's relationship with DirectDemocracyS, the system may process different categories of information.
This may include:
username;
password credentials in appropriately protected form;
personal email address;
telephone number;
country/operator telephone information;
account status;
user type;
registration date;
account activation information;
account security information.
A secure, non-temporary personal email address and a unique telephone number are part of the applicable registration and verification procedures.
A user's profile may contain information voluntarily provided by the user.
Depending on the user's settings and user type, this may include:
username;
profile description;
interests;
areas of activity;
voluntary biography;
languages;
voluntary professional information;
voluntary geographical information;
voluntary photographs;
voluntary contributions;
participation information;
public comments;
other content intentionally published by the user.
The existence of an account does not automatically mean that all of these categories must be publicly displayed.
For users requesting higher-level participation or identity verification, DirectDemocracyS may process information necessary to determine compatibility with the system.
This may include:
compatibility-test results;
answers to compatibility questions;
evaluation results;
decisions of the authorised verification group;
unique phase codes;
procedural communications;
information necessary to repeat or review a compatibility assessment.
The compatibility process is separate from the identity verification process.
The objective is to evaluate compatibility without unnecessarily exposing the applicant's real identity.
Where a user requests a user type or activity requiring demonstrated skills, DirectDemocracyS may process:
declared skills;
qualifications;
professional experience;
educational information;
evidence supplied by the user;
documents voluntarily or necessarily provided;
specialist assessments;
verification results;
skills-verification codes;
decisions of authorised specialist or verification groups.
A person does not have to possess prestigious qualifications merely to participate in DirectDemocracyS.
However, where a person claims specific professional or specialist competence for an activity requiring verification, DirectDemocracyS may request evidence appropriate to that activity.
Identity verification is a special and highly protected category of processing within the DirectDemocracyS architecture.
Depending on the procedure and applicable user type, identity verification may involve:
real first and last name;
date of birth where relevant;
nationality where relevant;
identity-document information;
passport information;
identity-card information;
another accepted photographic identity document;
photograph;
selfie;
live video;
verification video recording;
verification codes;
verification results;
information necessary to confirm authenticity;
information necessary to document the outcome of the verification.
DirectDemocracyS applies the principle of data minimisation.
The system should not retain information that is not necessary for the specific purpose.
The current DirectDemocracyS identity verification rules establish a structured process.
The process is divided into:
Phase 0 — request and initial information;
Phase 1 — compatibility;
Phase 2 — skills;
Phase 3 — identity verification.
Identity verification is therefore not automatically the first question asked of every participant.
This is an important privacy principle.
A user can participate at lower user levels without mandatory identity verification where the applicable rules permit this.
When a user requests identity verification, the system requires the information necessary to initiate the process.
The current rules require:
a unique username;
a unique personal email address;
a unique telephone number.
The username remains the user's operational identity.
The fact that the system has a personal email address or telephone number does not mean that these data become visible to ordinary users.
In Phase 1, DirectDemocracyS verifies compatibility with the system.
A unique code is generated.
A corresponding code is provided to an authorised and randomly selected member of an appropriate verification group.
The codes are designed to separate the phases and reduce the possibility of linking information between them without special authorisation.
The compatibility verifier does not ordinarily need to know the applicant's legal identity.
The applicant is operationally identified by their username and the relevant verification code.
The result may be:
approval;
rejection;
postponement;
reassignment to another authorised group.
The user receives the result through the appropriate communication channel.
Phase 2 concerns the skills declared by the applicant.
A new unique code is generated for the phase.
An authorised verification group and/or appropriate specialists assess the information and evidence supplied.
The information may include qualifications, documents or other evidence relevant to the claimed competence.
Again, the system uses separation between phases.
The skills verifier does not automatically receive the applicant's complete real identity information merely because the person is undergoing skills verification.
The objective is to verify competence while limiting unnecessary disclosure of personal information.
Only after the preceding requirements have been completed does the applicant proceed to identity verification.
The system generates another unique identity-verification code.
The applicant receives the code.
The authorised identity-verification member receives the corresponding information necessary to perform the verification.
The verifier does not ordinarily receive the applicant's username or other unnecessary information.
The purpose is to verify the identity document and the person without unnecessarily connecting the person's operational identity to their real-world identity.
The current DirectDemocracyS procedure uses a live video call for identity verification.
The applicant may be required to:
demonstrate that they are physically present;
perform simple live movements;
show their face;
present a valid photographic identity document;
show the identity document separately;
follow other security instructions necessary to establish that the person present corresponds to the document.
The call is recorded, encrypted and stored in a protected environment.
The video-verification material is not intended for ordinary public access.
One of the central privacy principles of DirectDemocracyS is that the person performing identity verification does not normally need to know the applicant's operational username.
This means that the verifier can perform the verification activity without automatically learning:
the applicant's public username;
their internal activities;
their political or social participation;
their previous activity history;
their ordinary DirectDemocracyS relationships.
The purpose is to reduce the possibility of unnecessary linking.
After successful verification, the system may mark the operational username as verified or guaranteed without making the real identity publicly visible.
When an identity document or identification file is uploaded or presented:
it is protected;
it is encrypted;
it is processed only for the verification purpose;
access is restricted;
it is not made publicly visible;
access is limited to highly authorised circumstances;
it may be analysed by authorised technical systems and AI systems where this is part of the implemented verification process;
human access is restricted according to the applicable security rules.
Identity documents are among the most sensitive forms of personal information processed by DirectDemocracyS.
They therefore receive a higher level of protection than ordinary profile information.
Where DirectDemocracyS uses its Artificial Intelligence systems to support identity verification, the AI system is used as part of the security and verification architecture.
AI-assisted processing may include:
document analysis;
consistency checking;
video analysis;
comparison of relevant information;
detection of anomalies;
verification assistance;
security analysis.
AI processing does not transform protected identity information into public information.
Where applicable, the system must also respect the legal rights relating to automated decision-making.
A user must not be subjected to an unlawful decision producing legal or similarly significant effects solely because an automated system has produced a particular result.
Where human review, reassessment or an additional verification is required by the applicable process, the appropriate human procedure must be followed.
DirectDemocracyS applies an extremely restrictive approach to access to identity-verification data.
Identity documents, identity-verification files and recorded verification videos are stored in protected environments.
Access may be technically and organisationally restricted to a very small number of highly authorised persons.
Such access must have:
a legitimate purpose;
a serious reason;
appropriate authorisation;
traceability;
documentation;
accountability.
Curiosity is not a legitimate reason for accessing identity data.
A person's administrative position does not automatically give that person unrestricted access to identity information.
The privacy model is different for official representatives and political representatives because their activities require a higher degree of public or local identifiability.
For official and political representatives, additional identity verification may be required.
This can include direct, in-person verification.
The in-person process uses unique codes and mutual verification for security.
The persons participating in the specific verification activity may necessarily know each other's identity for that activity.
This is an exceptional and purpose-specific disclosure.
It does not mean that every administrator or ordinary user receives access to the person's complete identity-verification records.
Political representatives must be identifiable for the political activities they perform.
For political representative profiles, the applicable DirectDemocracyS rules require the username to contain the person's full name and surname, written according to the applicable linguistic rules.
This is an intentional exception to the ordinary anonymity principle.
The reason is functional and organisational: political representation requires identifiable representatives.
The person's protected verification records remain subject to the security and access restrictions described in this Privacy Policy.
Official representatives may use an anonymous operational username in accordance with the applicable rules.
However, official representatives must be identifiable by the people with whom they conduct their official activities.
This creates a distinction between:
ordinary public anonymity;
operational identity;
local or activity-specific identification;
protected legal identity.
The identity disclosed for an official activity may not be reused for unrelated purposes.
For user types for which anonymity is guaranteed by the applicable DirectDemocracyS rules, the system seeks to maintain continuous anonymity.
Ordinary users should therefore be represented operationally by their username.
The system is designed so that ordinary users, ordinary members and unauthorised internal personnel cannot simply connect the username with the person's protected identity information.
This is a central privacy feature of DirectDemocracyS.
DirectDemocracyS has introduced a system under which a new user is connected or matched with an authorised official member.
The purpose includes:
assistance;
orientation;
integration;
safety;
reduction of mistakes;
support during the initial stages;
human contact with the system.
The authorised member receives only the information necessary for the relevant activity.
The existence of this human connection does not automatically grant the authorised member access to the new user's protected identity information.
The matching system does not cancel the user's right to anonymity.
DirectDemocracyS may process information generated when users communicate through:
internal messages;
email;
support requests;
video calls;
group discussions;
administrative communications;
verification communications;
security communications.
The content and metadata of such communications are processed only for legitimate purposes, including:
providing the requested service;
security;
moderation;
verification;
preventing abuse;
resolving disputes;
complying with legal obligations;
maintaining the integrity of the system.
Access to private communications is restricted according to role and purpose.
Users may voluntarily create:
articles;
comments;
posts;
messages;
proposals;
documents;
votes or voting-related records;
specialist contributions;
multimedia content;
other material.
Before publishing personal information, users should consider whether the information is genuinely necessary.
A user who voluntarily publishes personal information may make themselves identifiable even when their username is anonymous.
DirectDemocracyS cannot guarantee anonymity against information that a user deliberately publishes about themselves or that they voluntarily provide to third parties.
For security and operation, DirectDemocracyS may process technical information such as:
IP address;
connection information;
browser information;
device information;
operating-system information;
login information;
authentication events;
failed authentication attempts;
security events;
system logs;
timestamps;
error logs;
fraud-prevention information;
abuse-prevention information.
These records are not intended to become public profile information.
They are primarily used to operate, secure and protect the system.
DirectDemocracyS may use cookies and similar technical mechanisms where necessary for:
authentication;
security;
session management;
functionality;
preferences;
technical operation;
statistics;
other purposes specifically disclosed to users.
The detailed rules governing cookies are contained in the DirectDemocracyS Cookie Policy.
Where consent is legally required, the appropriate consent mechanism must be used.
Depending on the specific processing operation, DirectDemocracyS may rely on one or more legal bases recognised under applicable data protection law.
These may include:
Where processing is necessary to provide the service requested by the user or to manage the user's relationship with DirectDemocracyS.
Where DirectDemocracyS must retain or process information because applicable law requires it.
This is particularly relevant to:
accounting;
taxation;
employment;
legally required records;
security obligations;
legally required disclosures.
Where processing is necessary for legitimate organisational, security, technical or administrative purposes and those interests are not overridden by the rights and freedoms of the person concerned.
Security, prevention of fraud, prevention of abuse and protection of system integrity may constitute legitimate interests where the applicable legal requirements are satisfied.
Where consent is legally required or is the appropriate legal basis, DirectDemocracyS will request it in an appropriate manner.
Consent may be withdrawn where applicable.
Withdrawal of consent does not invalidate processing lawfully carried out before withdrawal.
Personal data collected for one purpose should not automatically be reused for an unrelated purpose.
For example:
identity-verification data are not ordinary marketing data;
security logs are not public profile data;
a telephone number used for verification is not automatically a public contact number;
an identity document is not a profile photograph;
employee records are not community-profile information.
Any new use must have an appropriate legal basis and be compatible with applicable data protection requirements.
DirectDemocracyS seeks to collect and process only the information necessary for each purpose.
Where a purpose can be achieved without identifying a person, anonymous or less identifying information should be preferred.
Where pseudonymisation can reduce the risk, it should be used where appropriate.
Where encryption can reduce the risk, it should be used.
Where access can be limited, it should be limited.
Where information no longer needs to remain on an accessible system, it should be removed from that accessible environment according to the applicable retention procedure.
DirectDemocracyS uses a distinction between:
systems accessible through the network and used for ordinary operation;
protected private storage environments that are inaccessible from the public network and from the Internet.
As a general operational rule, data are retained on the network-accessible platforms for approximately 7 working days, after which information that must be retained is transferred or archived according to the applicable retention category and security procedure.
This does not mean that every category of information is automatically destroyed after seven working days.
Different categories have different legal and operational retention requirements.
The seven-working-day period is therefore primarily the standard operational-access retention period on the network-accessible platforms, while legally or organisationally necessary records may subsequently be maintained in protected private storage.
Where information must be retained after its normal operational period, DirectDemocracyS may store it on a private server or protected storage environment that is:
inaccessible from the public Internet;
inaccessible through ordinary external network access;
separated from ordinary operational systems;
protected through access restrictions;
accessible only to authorised personnel where necessary.
The purpose of this architecture is to reduce the attack surface and to prevent sensitive historical information from remaining continuously exposed through ordinary network-accessible systems.
DirectDemocracyS applies different retention periods according to the category and purpose of the data.
The principal periods currently applicable are:
| Category | Operational / network-accessible period | Protected retention |
|---|---|---|
| General operational data | Approximately 7 working days | According to purpose and applicable necessity |
| Accounting and tax records | Approximately 7 working days on ordinary platforms | Approximately 10 years where legally required |
| Employee data | Approximately 7 working days on ordinary platforms | According to the specific legal and employment retention period |
| Video-surveillance images | Generally 24–72 hours on the network-accessible server | Up to 365 days in protected private storage where required by the applicable security/organisational policy |
| Marketing data | Approximately 7 working days on ordinary platforms | 24 months from the last administrative contact, or longer where required by applicable law |
| Identity-verification records | Limited operational exposure | According to verification, security, legal and organisational necessity |
| Verification videos | Limited operational exposure | According to the applicable security and verification retention schedule |
| Security records | Limited operational exposure | According to security, legal and incident-management requirements |
| Backups | According to backup cycle | According to backup and disaster-recovery requirements |
The exact retention period must always be interpreted together with the applicable law.
Where a law requires a longer period, the legally required period prevails.
Where no legal requirement exists, DirectDemocracyS should retain the information only for as long as reasonably necessary for the stated purpose.
Accounting records and documents required by tax legislation are retained for approximately 10 years, where required by the applicable fiscal obligations.
The purpose is to comply with legal, accounting and tax requirements.
The longer retention of these records does not mean that they are publicly accessible.
They remain protected and subject to access restrictions.
Employee information is subject to specific retention periods determined by:
labour legislation;
tax legislation;
social-security requirements;
contractual requirements;
employment-related legal obligations;
applicable national or local requirements.
Employee records therefore do not have a single universal retention period.
DirectDemocracyS maintains specific retention schedules for employee information according to the applicable legal requirements.
Where DirectDemocracyS uses video surveillance, images recorded by the surveillance system are generally removed from the network-accessible server after approximately 24–72 hours, subject to the applicable legal and operational requirements.
Where a longer retention is necessary for security, investigation, legal or organisational purposes, relevant material may be retained for up to 365 days on a private server that is inaccessible from outside and from the Internet.
Access to retained surveillance material is restricted.
Video surveillance is not intended to create a permanent public record of people's movements.
Where DirectDemocracyS lawfully processes marketing-related information, the standard retention period is approximately 24 months from the last administrative contact, unless a longer period is required by applicable law in the relevant country or local jurisdiction.
Marketing information is not automatically retained indefinitely.
Where applicable, users may exercise the right to object to direct marketing and may withdraw consent where consent is the applicable legal basis.
DirectDemocracyS applies technical and organisational measures intended to protect personal data against:
unauthorised access;
unauthorised disclosure;
alteration;
destruction;
accidental loss;
misuse;
unauthorised linking;
unlawful processing.
Depending on the system and purpose, security measures may include:
encryption;
encrypted communications;
encrypted identity documents;
encrypted video recordings;
protected servers;
private storage;
network segregation;
access control;
role-based permissions;
unique verification codes;
separation of verification phases;
restricted administrator access;
audit records;
authentication controls;
backup protection;
incident-management procedures;
least-privilege principles;
need-to-know access.
A person within DirectDemocracyS should have access only to information necessary for the activity they are authorised to perform.
For example:
A compatibility verifier does not need the user's identity document.
A skills verifier does not need unrestricted access to the user's identity document.
A technical administrator does not automatically need to know a user's real name.
A member helping a new user does not automatically receive access to identity-verification records.
A user does not receive access to another user's private personal information simply because both are members.
This principle applies regardless of organisational rank, subject to exceptional and documented security or legal requirements.
Administrators, SuperAdministrators, Guarantors and other privileged users may have access to systems containing more sensitive information.
However, higher organisational authority does not mean unlimited privacy access.
Privileged access should remain:
purpose-limited;
logged;
authorised;
justified;
reviewable;
limited to what is necessary.
The more sensitive the data, the more restricted access should be.
There may be exceptional situations in which protected information must be accessed.
Examples may include:
a serious security incident;
suspected identity fraud;
serious abuse;
legal proceedings;
a binding legal obligation;
a serious threat to the integrity of the system;
investigation of a serious violation of the rules;
a legitimate request by a competent authority;
technical recovery of critical data.
Exceptional access must not become ordinary access.
Where technically possible, exceptional access should be:
documented;
authorised;
attributable to a specific person;
limited in scope;
limited in time;
auditable.
DirectDemocracyS may disclose personal data to competent public authorities where this is:
legally required;
necessary to comply with a binding legal obligation;
authorised under applicable law;
necessary for a lawful investigation;
necessary to protect fundamental rights or serious security interests.
DirectDemocracyS does not interpret a general request from an authority as an automatic right to unrestricted access to all information.
The request must be handled according to applicable law and the principle of minimisation.
The effective DirectDemocracyS processing structure is intentionally limited.
The current operational environment consists primarily of:
the DirectDemocracyS system;
DirectDemocracyS platforms;
DirectDemocracyS websites;
authorised DirectDemocracyS groups and organisational units.
Authorised internal groups operate under DirectDemocracyS rules and access controls and do not automatically constitute independent external data controllers or processors merely because they are separate operational groups.
Where an external service provider or legally separate entity is actually engaged to process personal data on behalf of DirectDemocracyS, that relationship must be governed by the applicable data protection requirements and documented appropriately.
The list of actual external processors should therefore always reflect the providers actually used at the time this Policy is applied.
DirectDemocracyS does not sell or rent users' personal data.
DirectDemocracyS does not sell personal data.
It does not rent personal information to third parties for commercial exploitation.
Personal data are not treated as a commodity.
The existence of a DirectDemocracyS account does not constitute permission for unrelated organisations to commercially exploit the user's identity.
Where personal data are transferred outside the European Economic Area, DirectDemocracyS applies the safeguards required by applicable data protection law.
Depending on the circumstances, these may include:
an adequacy decision;
appropriate contractual safeguards;
Standard Contractual Clauses;
additional technical measures;
other legally recognised transfer mechanisms.
The specific transfer mechanism depends on the actual location of the receiving system and the applicable law.
DirectDemocracyS should maintain an up-to-date record of actual international transfers.
DirectDemocracyS seeks to maintain accurate information.
Users may be asked to correct information that is:
inaccurate;
incomplete;
obsolete;
inconsistent with the purpose for which it is used.
Where the user controls the information directly through their account, they should use the available profile-management tools.
Where the information cannot be changed directly, the user may contact the privacy team.
A person may have the right to request confirmation as to whether DirectDemocracyS processes their personal data and, where applicable, to obtain access to those data.
Access may include:
categories of data;
purposes;
applicable retention information;
recipients;
relevant processing information;
copies of personal data, subject to applicable legal limitations.
DirectDemocracyS may need to verify that the requester is entitled to receive the information.
This verification should be proportionate and should not unnecessarily undermine the user's anonymity.
Users may request correction of inaccurate personal data.
Where appropriate, DirectDemocracyS may also update information internally when an error is discovered.
Identity-verification information may be subject to specific verification procedures because changing such information can affect the integrity of the verification process.
Where applicable, a person may request deletion of their personal data.
However, the right to erasure is not absolute.
DirectDemocracyS may retain certain information where retention is necessary or legally required, including:
tax records;
accounting records;
employment records;
legally required documents;
security records;
evidence necessary for legal proceedings;
information necessary to prevent serious fraud or abuse;
records whose retention is required to protect the integrity of the system.
Where complete deletion is not legally possible, DirectDemocracyS should restrict processing and, where appropriate, anonymise or isolate the information.
Where applicable, a person may request restriction of processing, for example where:
accuracy is disputed;
processing is allegedly unlawful;
the person needs the information for legal claims;
the person has objected and the relevant assessment is pending.
Restricted data should not be used beyond the purposes permitted by applicable law.
Where the applicable legal basis permits objection, a person may object to certain processing.
This may be particularly relevant to:
direct marketing;
certain processing based on legitimate interests;
other processing for which the law provides a right to object.
DirectDemocracyS will assess the objection according to the applicable legal requirements.
Where the legal conditions for portability are satisfied, a person may request their personal data in a structured, commonly used and machine-readable format.
Portability generally applies only to the categories and legal circumstances defined by applicable data protection law.
DirectDemocracyS may use automated systems and AI to support certain processes.
Examples may include:
technical security analysis;
document analysis;
anomaly detection;
verification assistance;
classification;
system administration.
Automated processing must not unlawfully remove the rights of the person concerned.
Where applicable law grants a right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, DirectDemocracyS must respect that right and provide the safeguards required by law.
DirectDemocracyS recognises a particular difficulty created by strong anonymity.
If a person uses an entirely random username and DirectDemocracyS does not publicly connect that username to their real identity, the system may not be able to determine whether a person making a request is genuinely the account holder.
In such cases, DirectDemocracyS may request reasonable proof of control over the relevant account or another proportionate verification mechanism.
The purpose is not to destroy anonymity.
The purpose is to prevent one person from obtaining another person's private information.
DirectDemocracyS should therefore seek to verify entitlement without collecting unnecessary additional personal data.
DirectDemocracyS maintains procedures for identifying, containing, investigating and responding to security incidents.
Where a personal-data breach occurs, DirectDemocracyS will assess:
what happened;
what information was affected;
which users may be affected;
the level of risk;
what containment measures are required;
whether notification to a supervisory authority is legally required;
whether affected persons must be informed.
The applicable notification deadlines and procedures are determined by law.
Privacy is incorporated into the DirectDemocracyS architecture from the beginning rather than added only after a system has been developed.
Examples include:
anonymous usernames;
separation of username and identity;
unique verification codes;
separate verification phases;
random selection of verifiers;
restricted access to identity documents;
encrypted verification videos;
private storage;
limited network exposure;
role-based access;
need-to-know access;
limited retention;
separate representative profiles;
controlled visibility.
The objective is to reduce the amount of personal information that any individual person can access.
Where a user has not actively chosen to make information public, the system should apply the most privacy-protective setting reasonably available.
This means that private information should not become public merely because a user has created an account.
The default should be:
minimum necessary visibility, unless greater visibility is deliberately chosen or required for the user's activity.
DirectDemocracyS recognises that security and privacy must work together.
Security procedures may require processing personal information.
However, security is not a general justification for unlimited access.
The appropriate approach is:
collect only what is necessary;
use it only for a legitimate purpose;
protect it;
restrict access;
record exceptional access;
retain it only as long as necessary;
remove or archive it appropriately.
DirectDemocracyS distinguishes between:
the right to participate;
the right to anonymity;
the right to verified identity;
the right to shared leadership;
the right to collective ownership;
the responsibilities of official representation;
the requirements of political representation.
These rights and responsibilities are not identical.
A person does not lose their general right to privacy merely because another person chooses to become an official or political representative.
At the same time, a person who voluntarily requests a role requiring verified identity must accept the additional verification requirements applicable to that role.
Collective ownership is one of the reasons for the identity-verification requirements applicable to official members.
Where the rules require a verified and guaranteed identity for official membership, the identity verification exists to establish eligibility for that specific legal and organisational function.
It does not mean that the person's identity becomes publicly available to every other member.
Verification of eligibility and public disclosure of identity are two different concepts.
Similarly, binding participation in shared leadership may require a verified identity.
The verification exists to ensure that the person exercising the corresponding rights is a real, eligible and uniquely identified participant.
The underlying identity remains protected from ordinary users unless the applicable role requires public identification.
DirectDemocracyS uses different user types because not every activity requires the same level of verification.
The general principle is:
Higher responsibility may require higher verification, but higher verification does not automatically mean unrestricted public disclosure.
A Free user may remain anonymous where the rules permit.
A Verified user may have a verified identity while still operating publicly through a username.
An official member may have additional rights and responsibilities while their real identity remains protected from ordinary users.
A political representative must be identifiable because political representation requires it.
Age-related processing is governed by the applicable DirectDemocracyS participation rules and by the law applicable to the relevant user.
Where age verification is required for a specific service or legal obligation, DirectDemocracyS processes only the information necessary for that purpose.
No unnecessary age-related information should be made public.
DirectDemocracyS may contain links to external websites or services.
When a user leaves a DirectDemocracyS platform and accesses an external service, that service may have its own:
Privacy Policy;
Cookie Policy;
Terms of Service;
data-processing practices.
DirectDemocracyS is not responsible for processing performed independently by an external website outside the DirectDemocracyS system.
Users should therefore review the privacy information of external services before providing them with personal data.
DirectDemocracyS provides strong privacy architecture, but no system can protect a user from every form of voluntary disclosure.
A user may unintentionally identify themselves through:
photographs;
documents;
writing style;
personal stories;
location information;
employment information;
social-media links;
external websites;
unique personal events;
communication with people who already know their identity.
Users who require strong anonymity should therefore avoid voluntarily publishing combinations of information that make identification easy.
The username is the primary operational identifier within DirectDemocracyS.
For an anonymous user, the username should not reveal the person's legal identity.
Protected information such as:
name;
surname;
identity-document information;
telephone number;
personal email;
verification records;
must not automatically be inferred from the username.
Where the technical architecture permits, identity information and operational information should be maintained in separate logical and technical environments.
Identity-verification data and other particularly sensitive information may be stored on servers inaccessible from the public network.
This architecture is intended to provide an additional security layer.
The fact that information exists on a private server does not eliminate the obligation to protect it.
Private storage must therefore also be subject to:
access controls;
authentication;
encryption where appropriate;
monitoring;
authorisation;
backup security;
retention rules;
deletion procedures.
Backups may contain personal data because they are necessary to restore system availability and integrity.
Backups should be protected with security measures appropriate to the data they contain.
Backup copies should not be treated as an excuse for indefinite retention.
Where data are deleted according to the applicable retention schedule, the deletion process should also consider backup cycles and technical limitations.
Where DirectDemocracyS investigates serious violations, fraud, identity misuse, abuse or security incidents, it may temporarily process additional information.
Such information may include:
account activity;
technical logs;
communications;
verification records;
reports;
evidence;
incident records.
Access is restricted to authorised persons.
The information must not be used for unrelated purposes without an appropriate legal basis.
Where the DirectDemocracyS rules provide for sanctions, a disciplinary or security process may require processing information necessary to:
identify the relevant account;
establish the facts;
protect other users;
document the decision;
provide appropriate procedural safeguards;
respond to appeals;
comply with legal requirements.
Disciplinary records remain subject to confidentiality and retention rules.
DirectDemocracyS operates through specialist, security, administrative, legal, verification and other internal groups.
Membership in an internal group does not grant unlimited access to all personal data.
Each group should receive only the information necessary for its authorised activity.
Information received for one activity must not be redistributed to another group unless there is a legitimate reason and appropriate authorisation.
Persons authorised to access protected personal information must respect confidentiality.
They must not:
disclose identity information without authorisation;
copy protected documents for unrelated purposes;
publish private information;
connect anonymous usernames with real identities for personal reasons;
use protected information for harassment;
use protected information for commercial purposes;
use verification information to obtain personal advantages.
Violations may result in the sanctions provided by DirectDemocracyS rules and, where applicable, legal consequences.
DirectDemocracyS may use human bridges between users and authorised members, and between humans and Artificial Intelligence systems.
The existence of a human bridge does not automatically authorise disclosure of the user's protected personal information.
The bridge should receive only what is necessary to perform its specific role.
Where an AI system is involved, personal data must also be protected according to the applicable privacy and security requirements.
DirectDemocracyS may use Artificial Intelligence systems as part of its technological architecture.
This may include ddsAI, allddsAI or other authorised AI systems where applicable.
AI may assist with:
verification;
analysis;
classification;
security;
translation;
moderation;
information organisation;
technical operations;
detection of anomalies;
other authorised activities.
AI systems do not automatically receive unrestricted access to personal data.
The same principles apply to AI processing as to human processing:
necessity;
purpose limitation;
minimisation;
confidentiality;
access control;
security;
retention limitation;
accountability.
Where AI processing is not necessary, personal data should not be provided merely because the technology is available.
The existence of an AI system inside the DirectDemocracyS ecosystem does not create a general right for that AI system to access all identity information.
Highly sensitive identity data remain protected.
Access should be technically restricted to the specific AI function for which processing is authorised.
DirectDemocracyS recognises that retaining personal information creates risk.
For this reason, the system follows a two-level approach:
Data remain on ordinary network-accessible systems for approximately seven working days as a general operational period.
Information that must be retained for legal, security, accounting, employment, verification, historical, administrative or other legitimate reasons may be transferred to protected private storage.
This separation reduces the continuous exposure of historical information.
Retention periods should be reviewed periodically.
If information is no longer required, it should be:
deleted;
securely destroyed;
anonymised where appropriate;
or isolated where legal retention still applies but operational access is no longer necessary.
The fact that storage is inexpensive does not constitute a justification for indefinite retention.
DirectDemocracyS operates from Romania and within the European Union while potentially interacting with users and activities in multiple jurisdictions.
Different legal systems may impose different retention, employment, accounting, tax, security, marketing or other requirements.
Where applicable law requires a different period from the general DirectDemocracyS retention period, the legally required period applies to the relevant processing activity.
The system therefore maintains category-specific retention requirements rather than treating all data identically.
Marketing communications are subject to applicable law.
Where consent is required, communications will be sent only where valid consent exists.
Where another legal basis is applicable, DirectDemocracyS will comply with the requirements governing that basis.
Users may unsubscribe or exercise applicable objection rights.
Marketing information is normally retained for approximately 24 months from the last administrative contact, unless a longer legally required period applies.
Administrative communications are different from marketing.
They may be necessary for:
account security;
registration;
verification;
password recovery;
important rule changes;
legal notices;
system maintenance;
security incidents;
user-requested services.
Because these communications may be necessary to operate the relationship with the user, they may not always be subject to the same opt-out rules as marketing.
DirectDemocracyS may update this Privacy Policy when:
the system changes;
technology changes;
legal requirements change;
new user types are introduced;
verification procedures change;
retention rules change;
new services are introduced;
security requirements change.
The version and date of the Policy will be updated.
Where legally required, users will receive appropriate notice of material changes.
A modification to this Privacy Policy does not automatically authorise DirectDemocracyS to process personal data for an unrelated new purpose.
Where a new processing activity requires:
a new legal basis;
additional information;
consent;
a contractual change;
another legal safeguard;
the applicable requirement must be satisfied.
DirectDemocracyS considers transparency and accountability fundamental to its privacy model.
The organisation should be able to demonstrate:
what data it processes;
why it processes them;
who can access them;
how long they are retained;
how they are protected;
which legal basis applies;
how users can exercise their rights.
Privacy is therefore not only a statement of intention.
It is an organisational responsibility.
The DirectDemocracyS privacy model can be summarised through the following principles:
You may use an anonymous username where the applicable user type permits it.
Even identity verification does not automatically mean public disclosure.
A person may be verified while remaining operationally anonymous.
Compatibility, skills and identity verification are separated.
Different phases use different verification codes.
They are not ordinary profile information.
They are recorded, encrypted and stored in protected environments according to the applicable rules.
A person does not receive access merely because they are a member or administrator.
The general operational period is approximately seven working days.
Where retention is necessary, information may be transferred to private storage inaccessible from the public network.
This is required by applicable tax and accounting obligations.
Where required, protected retention may extend to 365 days.
Applicable local or national legal requirements may require a different period.
This is a specific exception required by the nature of political representation.
Their real identity is not normally disclosed to other users.
They choose what they reveal, to whom, when and how, within the limits required by the system and applicable law.
It is not merely a document added after the system has been built.
| Data category | Main purpose | Ordinary visibility | Typical operational retention | Longer protected retention |
|---|---|---|---|---|
| Username | Operational identification | According to profile/user type | Approximately 7 working days on operational systems as applicable | While account/records require it |
| Email address | Registration, communication, security | Private | Approximately 7 working days operationally | According to account/legal necessity |
| Telephone number | Verification and security | Private | Approximately 7 working days operationally | According to account/security necessity |
| Password/authentication data | Account security | Never public | According to security requirements | According to security requirements |
| Profile information | User participation | User-controlled where available | According to account/activity requirements | According to purpose |
| Public posts/comments | User participation and publication | Public if deliberately published | According to publication/system rules | According to applicable content-retention rules |
| Compatibility information | Compatibility assessment | Restricted | Limited | According to verification/security requirements |
| Skills information | Skills assessment | Restricted | Limited | According to verification/security requirements |
| Identity documents | Identity verification | Never public | Extremely limited | Protected retention according to verification/legal necessity |
| Selfie/photo-ID verification | Identity verification | Never public | Extremely limited | Protected retention according to verification/legal necessity |
| Verification videos | Identity verification/security | Never public | Limited | Protected storage according to applicable rules |
| Verification codes | Secure process control | Restricted | Limited | Only as necessary |
| Security logs | Security and abuse prevention | Never public | Limited | According to security/legal requirements |
| Accounting information | Tax/accounting obligations | Restricted | Limited operational exposure | Approximately 10 years where required |
| Employee information | Employment obligations | Restricted | Limited operational exposure | According to applicable legal schedule |
| Video-surveillance images | Security | Never public | Generally 24–72 hours on accessible server | Up to 365 days in protected storage where applicable |
| Marketing information | Lawful marketing | Restricted | Limited | Approximately 24 months from last administrative contact or legal period |
| Support communications | Assistance and administration | Restricted | Limited | According to purpose/legal necessity |
| Incident records | Security/legal protection | Highly restricted | Limited | According to legal/security necessity |
A user wishing to exercise a privacy right should contact:
privacy_support@directdemocracys.org
The request should indicate, as appropriate:
the username;
the nature of the request;
the relevant account or activity;
the specific information concerned;
any information necessary to identify the relevant record.
Users should not send unnecessary copies of identity documents unless specifically requested through an authorised and secure procedure.
DirectDemocracyS will attempt to use the least intrusive method necessary to establish the applicant's entitlement.
The Data Protection Officer designated for DirectDemocracyS is:
Franco-Romeo Zaccherini
The DPO may be contacted through:
privacy_support@directdemocracys.org
The DPO's role includes supporting the organisation's compliance with applicable data protection requirements and serving as a contact point for privacy-related matters.
Where a person believes that their personal data have been processed unlawfully, they may have the right to lodge a complaint with the competent data protection supervisory authority.
For persons subject to European data protection law, the competent authority depends on the circumstances, including residence, workplace and the location of the relevant processing.
DirectDemocracyS encourages users to contact the organisation first where appropriate so that privacy issues can be investigated and resolved internally, without prejudice to the person's statutory right to contact a supervisory authority.
This Privacy Policy must be read together with the applicable DirectDemocracyS rules, particularly:
the Join Us Definitive Rules;
the Identity Verification Implementing Rules;
username rules;
security rules;
rules governing user types;
rules governing official representatives;
rules governing political representatives;
rules governing internal groups;
the Cookie Policy;
applicable Terms and Conditions;
other implementing rules concerning personal data and security.
Where a specific operational procedure provides additional privacy safeguards, those safeguards remain applicable.
DirectDemocracyS considers privacy to be closely connected with freedom.
A person should be able to:
participate without unnecessarily exposing their identity;
express ideas without automatically exposing their private life;
contribute without being forced to disclose information unrelated to the activity;
obtain verification where necessary without losing all anonymity;
choose what personal information to reveal;
control voluntary disclosure;
know why information is collected;
know who can access it;
know how long it is retained;
request correction or deletion where legally possible.
Privacy therefore protects not only data.
It protects the person's freedom to participate.
DirectDemocracyS is committed to protecting personal data through a combination of:
legal compliance;
privacy by design;
privacy by default;
anonymity;
operational invisibility;
identity separation;
encryption;
access control;
limited retention;
private storage;
controlled verification;
unique codes;
restricted privileged access;
transparency;
accountability.
The central principle is simple:
The fact that DirectDemocracyS may be able to know something about a person does not mean that everyone else has the right to know it.
The system distinguishes between what must be known, what may be known, what may be voluntarily disclosed and what must remain protected.
For ordinary users, the person's username is their operational identity.
For users requiring verified identity, verification establishes eligibility without automatically creating public disclosure.
For official and political representatives, additional identification requirements apply because of their responsibilities.
In all cases, personal information should be processed only for legitimate, necessary and proportionate purposes, protected against unauthorised access and retained only for as long as required.
DirectDemocracyS
European Commission PIC: 881951064
Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union
Privacy and data protection:
privacy_support@directdemocracys.org
Data Protection Officer:
Franco-Romeo Zaccherini
Privacy Policy version: 1.0
Publication date: 22 September 2026
This Privacy Policy is the general DirectDemocracyS privacy framework.
It is intended to govern the processing of personal data across the DirectDemocracyS system, its platforms, websites and authorised organisational structures.
Specific processing activities may be governed by additional notices, implementing rules, consent mechanisms, contractual provisions or legally required information.
Where a specific activity requires more detailed information than this general Policy provides, the relevant specific privacy notice must be provided to the person concerned.
DirectDemocracyS will periodically review this document to ensure that it remains consistent with:
the actual technical architecture;
the actual data-processing activities;
applicable European Union law;
Romanian law;
applicable local and national legislation;
the DirectDemocracyS rules;
security requirements;
technological developments;
changes to the organisation's platforms and services.
End of Privacy Policy
DirectDemocracyS — 22 September 2026
Version: 1.0
Date of publication: 22 September 2026
Last update: 22 September 2026
Organisation: DirectDemocracyS
European Commission PIC: 881951064
Registered international office: str. Muzicii nr. 22, postal code 410514, Oradea, Bihor County, Romania, European Union
Privacy contact: privacy_support@directdemocracys.org
Data Protection Officer (DPO): Franco-Romeo Zaccherini
DirectDemocracyS considers the protection of personal data, privacy, anonymity, confidentiality, security and individual freedom to be fundamental principles of its entire system.
This Privacy Policy explains, in detail, how DirectDemocracyS collects, receives, generates, processes, verifies, protects, stores, separates, transfers, archives and, where appropriate, deletes personal data.
This Policy applies to the DirectDemocracyS system, its websites, platforms, online services, internal areas, social areas, registration systems, verification systems, communication systems, administrative systems, security systems and authorised internal groups, insofar as they process personal data.
DirectDemocracyS does not consider privacy to be merely a legal obligation. Privacy is also an architectural, organisational and democratic principle.
The system is therefore designed around several fundamental concepts:
data minimisation;
purpose limitation;
confidentiality;
security;
privacy by design;
privacy by default;
separation of personal identity from operational identity;
anonymity wherever anonymity is compatible with the user's chosen or required user type;
controlled visibility;
need-to-know access;
separation of verification phases;
use of unique codes;
restricted access to highly sensitive information;
limited retention on network-accessible systems;
long-term storage only where necessary and preferably in protected environments;
accountability;
transparency;
user control over voluntarily disclosed information.
DirectDemocracyS recognises that different users have different requirements.
A person who participates only as a Free user does not necessarily need to reveal their legal identity.
A person who wishes to exercise rights that require a verified identity, participate in shared leadership, become an official member or perform official or political representation may need to undergo additional verification.
The amount of personal information processed therefore depends on the user's relationship with the system, the user type selected or obtained, the activities performed and the legal or security requirements applicable to those activities.
For the purposes of this Privacy Policy, the relevant DirectDemocracyS entity is identified as follows:
DirectDemocracyS
European Commission PIC: 881951064
Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union
Privacy contact:
privacy_support@directdemocracys.org
Data Protection Officer (DPO):
Franco-Romeo Zaccherini
Requests concerning personal data, privacy, identity verification records, access to personal information, correction, restriction, deletion, objection, portability or other applicable data protection rights may be directed to the privacy contact above.
Where a specific request requires additional verification that the requester is the person entitled to receive or modify the information, DirectDemocracyS may request only the minimum additional information necessary to verify that right.
DirectDemocracyS will not request unnecessary identity information merely because a user wishes to exercise a privacy right.
This Privacy Policy applies, as applicable, to:
visitors to public DirectDemocracyS websites;
Public users;
Test users;
Free users;
Guest users;
Access users;
Partially Registered users;
Verified users;
Members;
Politicians;
Representatives;
Owners;
Managers;
Responsible users;
Administrators;
SuperAdministrators;
Guarantors;
official representatives;
political representatives;
employees and collaborators, where their data are processed;
persons participating in identity verification;
persons participating in compatibility or skills verification;
persons communicating with DirectDemocracyS;
persons whose data are processed for security, legal, administrative, accounting or organisational purposes.
The terminology of user types is governed by the applicable DirectDemocracyS rules.
Not every user type has the same data requirements.
In particular, the fact that DirectDemocracyS may be able to verify a person's identity does not mean that the person's real identity is automatically visible to ordinary users.
DirectDemocracyS follows a simple fundamental principle:
A person's identity should be known only when there is a legitimate reason to know it.
The system therefore separates, as far as technically and organisationally possible, the following concepts:
the person's real-world identity;
the person's DirectDemocracyS username;
the person's email address;
the person's telephone number;
the person's verification codes;
the person's compatibility information;
the person's skills information;
the person's identity-verification information;
the person's public profile;
the person's internal activities;
the person's representative profile;
security and administrative records.
These categories are not automatically interchangeable.
A person may therefore be known inside the operational system by a username without that username publicly revealing their real name.
DirectDemocracyS recognises, wherever permitted by the user's user type and the applicable rules, a fundamental right to operate under an anonymous or non-identifying username.
For ordinary users, the username does not have to correspond to:
the person's first name;
the person's surname;
their legal name;
their address;
their city;
their telephone number;
their email address;
their date of birth;
their employer;
their professional identity;
their social-media identity;
or any other real-world identifying information.
A user may therefore participate using a username that has no obvious connection with their real identity.
The username is the person's operational identity within DirectDemocracyS.
A user may choose an anonymous username according to the applicable username rules.
Examples of privacy-preserving formats include:
For example:
BlueMountain
provided that the nickname does not reveal information that the user does not wish to disclose and is not misleading or reserved for another role.
For example:
RO7F4K29
or another structure based on an ISO country code followed by a random combination of letters and numbers.
The country code itself does not have to identify the person's precise location.
For example:
X7Q9-M4P2-Z8
or another permitted random alphanumeric or special-character combination.
A user may use any username permitted by the applicable DirectDemocracyS username rules, provided that it does not falsely represent another person, a protected role, an official position, an administrative function or another identity.
A user who wishes to maintain strong anonymity should avoid usernames containing:
their real name;
their surname;
their date of birth;
their telephone number;
their email address;
their exact address;
an identifiable social-media username;
an employer-specific identifier;
a unique professional identifier;
a combination of information that could easily identify them.
Anonymity also depends on what the user voluntarily publishes.
A perfectly anonymous username can lose much of its protective value if the user publicly publishes enough information to identify themselves.
For this reason, anonymity is a combination of:
the architecture of DirectDemocracyS;
the username selected by the user;
the information voluntarily disclosed by the user;
the security of the user's own devices and accounts;
compliance with the DirectDemocracyS rules.
DirectDemocracyS seeks to provide strong external invisibility for users who are entitled to anonymous participation.
For an anonymous user, ordinary visitors, external users and ordinary members should see the user's operational username rather than their real identity.
The objective is that a person viewing the public or ordinary internal profile should not be able to derive the user's:
legal name;
surname;
home address;
telephone number;
personal email address;
identity-document information;
verification information;
private identity-verification material.
The user's public or ordinary operational identity is therefore separated from their protected identity information.
This is particularly important for people who participate in political, social, professional, scientific, cultural or other activities and who may have legitimate reasons to protect their personal identity.
DirectDemocracyS also applies the principle of internal invisibility.
Internal invisibility means that even within DirectDemocracyS, a person's real identity is not automatically available to every administrator, member, specialist, verifier, manager or other user.
Access to personal identity information is restricted according to:
role;
purpose;
necessity;
authorisation;
security requirements;
legal requirements;
the particular verification activity being performed.
A person performing a compatibility test does not normally need to know the applicant's legal name.
A person performing a skills assessment does not normally need to know the applicant's legal name.
A person performing an identity verification activity receives only the information and codes necessary to perform that activity.
This separation is one of the principal mechanisms through which DirectDemocracyS seeks to protect anonymity.
DirectDemocracyS uses strong technical and organisational separation between usernames and real identity.
However, the legal concept of anonymisation must be distinguished from pseudonymisation.
Where DirectDemocracyS retains protected information that could, under exceptional authorised circumstances, be used to establish a connection between a username and a real identity, that information remains personal data under applicable data protection law.
Therefore, this Privacy Policy uses the expression “anonymity and invisibility” to describe the protection experienced by ordinary users and unauthorised persons, while recognising that exceptional legally authorised access may exist.
This does not give ordinary users, ordinary administrators or unauthorised third parties a right to access the protected identity information.
DirectDemocracyS follows another fundamental principle:
Users decide what information they voluntarily make visible, to whom, when and in what manner, except where information must be processed privately for legal, security, technical or organisational reasons.
Where the platform provides a visibility option, users may determine, according to the applicable rules and technical possibilities:
whether information is public;
whether information is visible only internally;
whether information is visible to a specific group;
whether information is visible to specific authorised persons;
whether information remains private;
when information becomes visible;
when information stops being visible;
whether information is disclosed voluntarily during a specific activity.
The system does not interpret voluntary publication of one item of information as consent to publish all other information about the same person.
For example, publication of a user's username does not mean that the person's real name, telephone number, address or identity document may also be published.
Some information is processed for technical, legal or security reasons even when it is not publicly visible.
Examples may include:
registration email address;
verified telephone number;
authentication information;
security logs;
identity-verification records;
identity documents;
identity-verification videos;
verification codes;
administrative records;
payment or accounting information;
employment records;
security information;
incident records.
Such information is not made public merely because it exists within the DirectDemocracyS system.
Depending on the user's relationship with DirectDemocracyS, the system may process different categories of information.
This may include:
username;
password credentials in appropriately protected form;
personal email address;
telephone number;
country/operator telephone information;
account status;
user type;
registration date;
account activation information;
account security information.
A secure, non-temporary personal email address and a unique telephone number are part of the applicable registration and verification procedures.
A user's profile may contain information voluntarily provided by the user.
Depending on the user's settings and user type, this may include:
username;
profile description;
interests;
areas of activity;
voluntary biography;
languages;
voluntary professional information;
voluntary geographical information;
voluntary photographs;
voluntary contributions;
participation information;
public comments;
other content intentionally published by the user.
The existence of an account does not automatically mean that all of these categories must be publicly displayed.
For users requesting higher-level participation or identity verification, DirectDemocracyS may process information necessary to determine compatibility with the system.
This may include:
compatibility-test results;
answers to compatibility questions;
evaluation results;
decisions of the authorised verification group;
unique phase codes;
procedural communications;
information necessary to repeat or review a compatibility assessment.
The compatibility process is separate from the identity verification process.
The objective is to evaluate compatibility without unnecessarily exposing the applicant's real identity.
Where a user requests a user type or activity requiring demonstrated skills, DirectDemocracyS may process:
declared skills;
qualifications;
professional experience;
educational information;
evidence supplied by the user;
documents voluntarily or necessarily provided;
specialist assessments;
verification results;
skills-verification codes;
decisions of authorised specialist or verification groups.
A person does not have to possess prestigious qualifications merely to participate in DirectDemocracyS.
However, where a person claims specific professional or specialist competence for an activity requiring verification, DirectDemocracyS may request evidence appropriate to that activity.
Identity verification is a special and highly protected category of processing within the DirectDemocracyS architecture.
Depending on the procedure and applicable user type, identity verification may involve:
real first and last name;
date of birth where relevant;
nationality where relevant;
identity-document information;
passport information;
identity-card information;
another accepted photographic identity document;
photograph;
selfie;
live video;
verification video recording;
verification codes;
verification results;
information necessary to confirm authenticity;
information necessary to document the outcome of the verification.
DirectDemocracyS applies the principle of data minimisation.
The system should not retain information that is not necessary for the specific purpose.
The current DirectDemocracyS identity verification rules establish a structured process.
The process is divided into:
Phase 0 — request and initial information;
Phase 1 — compatibility;
Phase 2 — skills;
Phase 3 — identity verification.
Identity verification is therefore not automatically the first question asked of every participant.
This is an important privacy principle.
A user can participate at lower user levels without mandatory identity verification where the applicable rules permit this.
When a user requests identity verification, the system requires the information necessary to initiate the process.
The current rules require:
a unique username;
a unique personal email address;
a unique telephone number.
The username remains the user's operational identity.
The fact that the system has a personal email address or telephone number does not mean that these data become visible to ordinary users.
In Phase 1, DirectDemocracyS verifies compatibility with the system.
A unique code is generated.
A corresponding code is provided to an authorised and randomly selected member of an appropriate verification group.
The codes are designed to separate the phases and reduce the possibility of linking information between them without special authorisation.
The compatibility verifier does not ordinarily need to know the applicant's legal identity.
The applicant is operationally identified by their username and the relevant verification code.
The result may be:
approval;
rejection;
postponement;
reassignment to another authorised group.
The user receives the result through the appropriate communication channel.
Phase 2 concerns the skills declared by the applicant.
A new unique code is generated for the phase.
An authorised verification group and/or appropriate specialists assess the information and evidence supplied.
The information may include qualifications, documents or other evidence relevant to the claimed competence.
Again, the system uses separation between phases.
The skills verifier does not automatically receive the applicant's complete real identity information merely because the person is undergoing skills verification.
The objective is to verify competence while limiting unnecessary disclosure of personal information.
Only after the preceding requirements have been completed does the applicant proceed to identity verification.
The system generates another unique identity-verification code.
The applicant receives the code.
The authorised identity-verification member receives the corresponding information necessary to perform the verification.
The verifier does not ordinarily receive the applicant's username or other unnecessary information.
The purpose is to verify the identity document and the person without unnecessarily connecting the person's operational identity to their real-world identity.
The current DirectDemocracyS procedure uses a live video call for identity verification.
The applicant may be required to:
demonstrate that they are physically present;
perform simple live movements;
show their face;
present a valid photographic identity document;
show the identity document separately;
follow other security instructions necessary to establish that the person present corresponds to the document.
The call is recorded, encrypted and stored in a protected environment.
The video-verification material is not intended for ordinary public access.
One of the central privacy principles of DirectDemocracyS is that the person performing identity verification does not normally need to know the applicant's operational username.
This means that the verifier can perform the verification activity without automatically learning:
the applicant's public username;
their internal activities;
their political or social participation;
their previous activity history;
their ordinary DirectDemocracyS relationships.
The purpose is to reduce the possibility of unnecessary linking.
After successful verification, the system may mark the operational username as verified or guaranteed without making the real identity publicly visible.
When an identity document or identification file is uploaded or presented:
it is protected;
it is encrypted;
it is processed only for the verification purpose;
access is restricted;
it is not made publicly visible;
access is limited to highly authorised circumstances;
it may be analysed by authorised technical systems and AI systems where this is part of the implemented verification process;
human access is restricted according to the applicable security rules.
Identity documents are among the most sensitive forms of personal information processed by DirectDemocracyS.
They therefore receive a higher level of protection than ordinary profile information.
Where DirectDemocracyS uses its Artificial Intelligence systems to support identity verification, the AI system is used as part of the security and verification architecture.
AI-assisted processing may include:
document analysis;
consistency checking;
video analysis;
comparison of relevant information;
detection of anomalies;
verification assistance;
security analysis.
AI processing does not transform protected identity information into public information.
Where applicable, the system must also respect the legal rights relating to automated decision-making.
A user must not be subjected to an unlawful decision producing legal or similarly significant effects solely because an automated system has produced a particular result.
Where human review, reassessment or an additional verification is required by the applicable process, the appropriate human procedure must be followed.
DirectDemocracyS applies an extremely restrictive approach to access to identity-verification data.
Identity documents, identity-verification files and recorded verification videos are stored in protected environments.
Access may be technically and organisationally restricted to a very small number of highly authorised persons.
Such access must have:
a legitimate purpose;
a serious reason;
appropriate authorisation;
traceability;
documentation;
accountability.
Curiosity is not a legitimate reason for accessing identity data.
A person's administrative position does not automatically give that person unrestricted access to identity information.
The privacy model is different for official representatives and political representatives because their activities require a higher degree of public or local identifiability.
For official and political representatives, additional identity verification may be required.
This can include direct, in-person verification.
The in-person process uses unique codes and mutual verification for security.
The persons participating in the specific verification activity may necessarily know each other's identity for that activity.
This is an exceptional and purpose-specific disclosure.
It does not mean that every administrator or ordinary user receives access to the person's complete identity-verification records.
Political representatives must be identifiable for the political activities they perform.
For political representative profiles, the applicable DirectDemocracyS rules require the username to contain the person's full name and surname, written according to the applicable linguistic rules.
This is an intentional exception to the ordinary anonymity principle.
The reason is functional and organisational: political representation requires identifiable representatives.
The person's protected verification records remain subject to the security and access restrictions described in this Privacy Policy.
Official representatives may use an anonymous operational username in accordance with the applicable rules.
However, official representatives must be identifiable by the people with whom they conduct their official activities.
This creates a distinction between:
ordinary public anonymity;
operational identity;
local or activity-specific identification;
protected legal identity.
The identity disclosed for an official activity may not be reused for unrelated purposes.
For user types for which anonymity is guaranteed by the applicable DirectDemocracyS rules, the system seeks to maintain continuous anonymity.
Ordinary users should therefore be represented operationally by their username.
The system is designed so that ordinary users, ordinary members and unauthorised internal personnel cannot simply connect the username with the person's protected identity information.
This is a central privacy feature of DirectDemocracyS.
DirectDemocracyS has introduced a system under which a new user is connected or matched with an authorised official member.
The purpose includes:
assistance;
orientation;
integration;
safety;
reduction of mistakes;
support during the initial stages;
human contact with the system.
The authorised member receives only the information necessary for the relevant activity.
The existence of this human connection does not automatically grant the authorised member access to the new user's protected identity information.
The matching system does not cancel the user's right to anonymity.
DirectDemocracyS may process information generated when users communicate through:
internal messages;
email;
support requests;
video calls;
group discussions;
administrative communications;
verification communications;
security communications.
The content and metadata of such communications are processed only for legitimate purposes, including:
providing the requested service;
security;
moderation;
verification;
preventing abuse;
resolving disputes;
complying with legal obligations;
maintaining the integrity of the system.
Access to private communications is restricted according to role and purpose.
Users may voluntarily create:
articles;
comments;
posts;
messages;
proposals;
documents;
votes or voting-related records;
specialist contributions;
multimedia content;
other material.
Before publishing personal information, users should consider whether the information is genuinely necessary.
A user who voluntarily publishes personal information may make themselves identifiable even when their username is anonymous.
DirectDemocracyS cannot guarantee anonymity against information that a user deliberately publishes about themselves or that they voluntarily provide to third parties.
For security and operation, DirectDemocracyS may process technical information such as:
IP address;
connection information;
browser information;
device information;
operating-system information;
login information;
authentication events;
failed authentication attempts;
security events;
system logs;
timestamps;
error logs;
fraud-prevention information;
abuse-prevention information.
These records are not intended to become public profile information.
They are primarily used to operate, secure and protect the system.
DirectDemocracyS may use cookies and similar technical mechanisms where necessary for:
authentication;
security;
session management;
functionality;
preferences;
technical operation;
statistics;
other purposes specifically disclosed to users.
The detailed rules governing cookies are contained in the DirectDemocracyS Cookie Policy.
Where consent is legally required, the appropriate consent mechanism must be used.
Depending on the specific processing operation, DirectDemocracyS may rely on one or more legal bases recognised under applicable data protection law.
These may include:
Where processing is necessary to provide the service requested by the user or to manage the user's relationship with DirectDemocracyS.
Where DirectDemocracyS must retain or process information because applicable law requires it.
This is particularly relevant to:
accounting;
taxation;
employment;
legally required records;
security obligations;
legally required disclosures.
Where processing is necessary for legitimate organisational, security, technical or administrative purposes and those interests are not overridden by the rights and freedoms of the person concerned.
Security, prevention of fraud, prevention of abuse and protection of system integrity may constitute legitimate interests where the applicable legal requirements are satisfied.
Where consent is legally required or is the appropriate legal basis, DirectDemocracyS will request it in an appropriate manner.
Consent may be withdrawn where applicable.
Withdrawal of consent does not invalidate processing lawfully carried out before withdrawal.
Personal data collected for one purpose should not automatically be reused for an unrelated purpose.
For example:
identity-verification data are not ordinary marketing data;
security logs are not public profile data;
a telephone number used for verification is not automatically a public contact number;
an identity document is not a profile photograph;
employee records are not community-profile information.
Any new use must have an appropriate legal basis and be compatible with applicable data protection requirements.
DirectDemocracyS seeks to collect and process only the information necessary for each purpose.
Where a purpose can be achieved without identifying a person, anonymous or less identifying information should be preferred.
Where pseudonymisation can reduce the risk, it should be used where appropriate.
Where encryption can reduce the risk, it should be used.
Where access can be limited, it should be limited.
Where information no longer needs to remain on an accessible system, it should be removed from that accessible environment according to the applicable retention procedure.
DirectDemocracyS uses a distinction between:
systems accessible through the network and used for ordinary operation;
protected private storage environments that are inaccessible from the public network and from the Internet.
As a general operational rule, data are retained on the network-accessible platforms for approximately 7 working days, after which information that must be retained is transferred or archived according to the applicable retention category and security procedure.
This does not mean that every category of information is automatically destroyed after seven working days.
Different categories have different legal and operational retention requirements.
The seven-working-day period is therefore primarily the standard operational-access retention period on the network-accessible platforms, while legally or organisationally necessary records may subsequently be maintained in protected private storage.
Where information must be retained after its normal operational period, DirectDemocracyS may store it on a private server or protected storage environment that is:
inaccessible from the public Internet;
inaccessible through ordinary external network access;
separated from ordinary operational systems;
protected through access restrictions;
accessible only to authorised personnel where necessary.
The purpose of this architecture is to reduce the attack surface and to prevent sensitive historical information from remaining continuously exposed through ordinary network-accessible systems.
DirectDemocracyS applies different retention periods according to the category and purpose of the data.
The principal periods currently applicable are:
| Category | Operational / network-accessible period | Protected retention |
|---|---|---|
| General operational data | Approximately 7 working days | According to purpose and applicable necessity |
| Accounting and tax records | Approximately 7 working days on ordinary platforms | Approximately 10 years where legally required |
| Employee data | Approximately 7 working days on ordinary platforms | According to the specific legal and employment retention period |
| Video-surveillance images | Generally 24–72 hours on the network-accessible server | Up to 365 days in protected private storage where required by the applicable security/organisational policy |
| Marketing data | Approximately 7 working days on ordinary platforms | 24 months from the last administrative contact, or longer where required by applicable law |
| Identity-verification records | Limited operational exposure | According to verification, security, legal and organisational necessity |
| Verification videos | Limited operational exposure | According to the applicable security and verification retention schedule |
| Security records | Limited operational exposure | According to security, legal and incident-management requirements |
| Backups | According to backup cycle | According to backup and disaster-recovery requirements |
The exact retention period must always be interpreted together with the applicable law.
Where a law requires a longer period, the legally required period prevails.
Where no legal requirement exists, DirectDemocracyS should retain the information only for as long as reasonably necessary for the stated purpose.
Accounting records and documents required by tax legislation are retained for approximately 10 years, where required by the applicable fiscal obligations.
The purpose is to comply with legal, accounting and tax requirements.
The longer retention of these records does not mean that they are publicly accessible.
They remain protected and subject to access restrictions.
Employee information is subject to specific retention periods determined by:
labour legislation;
tax legislation;
social-security requirements;
contractual requirements;
employment-related legal obligations;
applicable national or local requirements.
Employee records therefore do not have a single universal retention period.
DirectDemocracyS maintains specific retention schedules for employee information according to the applicable legal requirements.
Where DirectDemocracyS uses video surveillance, images recorded by the surveillance system are generally removed from the network-accessible server after approximately 24–72 hours, subject to the applicable legal and operational requirements.
Where a longer retention is necessary for security, investigation, legal or organisational purposes, relevant material may be retained for up to 365 days on a private server that is inaccessible from outside and from the Internet.
Access to retained surveillance material is restricted.
Video surveillance is not intended to create a permanent public record of people's movements.
Where DirectDemocracyS lawfully processes marketing-related information, the standard retention period is approximately 24 months from the last administrative contact, unless a longer period is required by applicable law in the relevant country or local jurisdiction.
Marketing information is not automatically retained indefinitely.
Where applicable, users may exercise the right to object to direct marketing and may withdraw consent where consent is the applicable legal basis.
DirectDemocracyS applies technical and organisational measures intended to protect personal data against:
unauthorised access;
unauthorised disclosure;
alteration;
destruction;
accidental loss;
misuse;
unauthorised linking;
unlawful processing.
Depending on the system and purpose, security measures may include:
encryption;
encrypted communications;
encrypted identity documents;
encrypted video recordings;
protected servers;
private storage;
network segregation;
access control;
role-based permissions;
unique verification codes;
separation of verification phases;
restricted administrator access;
audit records;
authentication controls;
backup protection;
incident-management procedures;
least-privilege principles;
need-to-know access.
A person within DirectDemocracyS should have access only to information necessary for the activity they are authorised to perform.
For example:
A compatibility verifier does not need the user's identity document.
A skills verifier does not need unrestricted access to the user's identity document.
A technical administrator does not automatically need to know a user's real name.
A member helping a new user does not automatically receive access to identity-verification records.
A user does not receive access to another user's private personal information simply because both are members.
This principle applies regardless of organisational rank, subject to exceptional and documented security or legal requirements.
Administrators, SuperAdministrators, Guarantors and other privileged users may have access to systems containing more sensitive information.
However, higher organisational authority does not mean unlimited privacy access.
Privileged access should remain:
purpose-limited;
logged;
authorised;
justified;
reviewable;
limited to what is necessary.
The more sensitive the data, the more restricted access should be.
There may be exceptional situations in which protected information must be accessed.
Examples may include:
a serious security incident;
suspected identity fraud;
serious abuse;
legal proceedings;
a binding legal obligation;
a serious threat to the integrity of the system;
investigation of a serious violation of the rules;
a legitimate request by a competent authority;
technical recovery of critical data.
Exceptional access must not become ordinary access.
Where technically possible, exceptional access should be:
documented;
authorised;
attributable to a specific person;
limited in scope;
limited in time;
auditable.
DirectDemocracyS may disclose personal data to competent public authorities where this is:
legally required;
necessary to comply with a binding legal obligation;
authorised under applicable law;
necessary for a lawful investigation;
necessary to protect fundamental rights or serious security interests.
DirectDemocracyS does not interpret a general request from an authority as an automatic right to unrestricted access to all information.
The request must be handled according to applicable law and the principle of minimisation.
The effective DirectDemocracyS processing structure is intentionally limited.
The current operational environment consists primarily of:
the DirectDemocracyS system;
DirectDemocracyS platforms;
DirectDemocracyS websites;
authorised DirectDemocracyS groups and organisational units.
Authorised internal groups operate under DirectDemocracyS rules and access controls and do not automatically constitute independent external data controllers or processors merely because they are separate operational groups.
Where an external service provider or legally separate entity is actually engaged to process personal data on behalf of DirectDemocracyS, that relationship must be governed by the applicable data protection requirements and documented appropriately.
The list of actual external processors should therefore always reflect the providers actually used at the time this Policy is applied.
DirectDemocracyS does not sell or rent users' personal data.
DirectDemocracyS does not sell personal data.
It does not rent personal information to third parties for commercial exploitation.
Personal data are not treated as a commodity.
The existence of a DirectDemocracyS account does not constitute permission for unrelated organisations to commercially exploit the user's identity.
Where personal data are transferred outside the European Economic Area, DirectDemocracyS applies the safeguards required by applicable data protection law.
Depending on the circumstances, these may include:
an adequacy decision;
appropriate contractual safeguards;
Standard Contractual Clauses;
additional technical measures;
other legally recognised transfer mechanisms.
The specific transfer mechanism depends on the actual location of the receiving system and the applicable law.
DirectDemocracyS should maintain an up-to-date record of actual international transfers.
DirectDemocracyS seeks to maintain accurate information.
Users may be asked to correct information that is:
inaccurate;
incomplete;
obsolete;
inconsistent with the purpose for which it is used.
Where the user controls the information directly through their account, they should use the available profile-management tools.
Where the information cannot be changed directly, the user may contact the privacy team.
A person may have the right to request confirmation as to whether DirectDemocracyS processes their personal data and, where applicable, to obtain access to those data.
Access may include:
categories of data;
purposes;
applicable retention information;
recipients;
relevant processing information;
copies of personal data, subject to applicable legal limitations.
DirectDemocracyS may need to verify that the requester is entitled to receive the information.
This verification should be proportionate and should not unnecessarily undermine the user's anonymity.
Users may request correction of inaccurate personal data.
Where appropriate, DirectDemocracyS may also update information internally when an error is discovered.
Identity-verification information may be subject to specific verification procedures because changing such information can affect the integrity of the verification process.
Where applicable, a person may request deletion of their personal data.
However, the right to erasure is not absolute.
DirectDemocracyS may retain certain information where retention is necessary or legally required, including:
tax records;
accounting records;
employment records;
legally required documents;
security records;
evidence necessary for legal proceedings;
information necessary to prevent serious fraud or abuse;
records whose retention is required to protect the integrity of the system.
Where complete deletion is not legally possible, DirectDemocracyS should restrict processing and, where appropriate, anonymise or isolate the information.
Where applicable, a person may request restriction of processing, for example where:
accuracy is disputed;
processing is allegedly unlawful;
the person needs the information for legal claims;
the person has objected and the relevant assessment is pending.
Restricted data should not be used beyond the purposes permitted by applicable law.
Where the applicable legal basis permits objection, a person may object to certain processing.
This may be particularly relevant to:
direct marketing;
certain processing based on legitimate interests;
other processing for which the law provides a right to object.
DirectDemocracyS will assess the objection according to the applicable legal requirements.
Where the legal conditions for portability are satisfied, a person may request their personal data in a structured, commonly used and machine-readable format.
Portability generally applies only to the categories and legal circumstances defined by applicable data protection law.
DirectDemocracyS may use automated systems and AI to support certain processes.
Examples may include:
technical security analysis;
document analysis;
anomaly detection;
verification assistance;
classification;
system administration.
Automated processing must not unlawfully remove the rights of the person concerned.
Where applicable law grants a right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, DirectDemocracyS must respect that right and provide the safeguards required by law.
DirectDemocracyS recognises a particular difficulty created by strong anonymity.
If a person uses an entirely random username and DirectDemocracyS does not publicly connect that username to their real identity, the system may not be able to determine whether a person making a request is genuinely the account holder.
In such cases, DirectDemocracyS may request reasonable proof of control over the relevant account or another proportionate verification mechanism.
The purpose is not to destroy anonymity.
The purpose is to prevent one person from obtaining another person's private information.
DirectDemocracyS should therefore seek to verify entitlement without collecting unnecessary additional personal data.
DirectDemocracyS maintains procedures for identifying, containing, investigating and responding to security incidents.
Where a personal-data breach occurs, DirectDemocracyS will assess:
what happened;
what information was affected;
which users may be affected;
the level of risk;
what containment measures are required;
whether notification to a supervisory authority is legally required;
whether affected persons must be informed.
The applicable notification deadlines and procedures are determined by law.
Privacy is incorporated into the DirectDemocracyS architecture from the beginning rather than added only after a system has been developed.
Examples include:
anonymous usernames;
separation of username and identity;
unique verification codes;
separate verification phases;
random selection of verifiers;
restricted access to identity documents;
encrypted verification videos;
private storage;
limited network exposure;
role-based access;
need-to-know access;
limited retention;
separate representative profiles;
controlled visibility.
The objective is to reduce the amount of personal information that any individual person can access.
Where a user has not actively chosen to make information public, the system should apply the most privacy-protective setting reasonably available.
This means that private information should not become public merely because a user has created an account.
The default should be:
minimum necessary visibility, unless greater visibility is deliberately chosen or required for the user's activity.
DirectDemocracyS recognises that security and privacy must work together.
Security procedures may require processing personal information.
However, security is not a general justification for unlimited access.
The appropriate approach is:
collect only what is necessary;
use it only for a legitimate purpose;
protect it;
restrict access;
record exceptional access;
retain it only as long as necessary;
remove or archive it appropriately.
DirectDemocracyS distinguishes between:
the right to participate;
the right to anonymity;
the right to verified identity;
the right to shared leadership;
the right to collective ownership;
the responsibilities of official representation;
the requirements of political representation.
These rights and responsibilities are not identical.
A person does not lose their general right to privacy merely because another person chooses to become an official or political representative.
At the same time, a person who voluntarily requests a role requiring verified identity must accept the additional verification requirements applicable to that role.
Collective ownership is one of the reasons for the identity-verification requirements applicable to official members.
Where the rules require a verified and guaranteed identity for official membership, the identity verification exists to establish eligibility for that specific legal and organisational function.
It does not mean that the person's identity becomes publicly available to every other member.
Verification of eligibility and public disclosure of identity are two different concepts.
Similarly, binding participation in shared leadership may require a verified identity.
The verification exists to ensure that the person exercising the corresponding rights is a real, eligible and uniquely identified participant.
The underlying identity remains protected from ordinary users unless the applicable role requires public identification.
DirectDemocracyS uses different user types because not every activity requires the same level of verification.
The general principle is:
Higher responsibility may require higher verification, but higher verification does not automatically mean unrestricted public disclosure.
A Free user may remain anonymous where the rules permit.
A Verified user may have a verified identity while still operating publicly through a username.
An official member may have additional rights and responsibilities while their real identity remains protected from ordinary users.
A political representative must be identifiable because political representation requires it.
Age-related processing is governed by the applicable DirectDemocracyS participation rules and by the law applicable to the relevant user.
Where age verification is required for a specific service or legal obligation, DirectDemocracyS processes only the information necessary for that purpose.
No unnecessary age-related information should be made public.
DirectDemocracyS may contain links to external websites or services.
When a user leaves a DirectDemocracyS platform and accesses an external service, that service may have its own:
Privacy Policy;
Cookie Policy;
Terms of Service;
data-processing practices.
DirectDemocracyS is not responsible for processing performed independently by an external website outside the DirectDemocracyS system.
Users should therefore review the privacy information of external services before providing them with personal data.
DirectDemocracyS provides strong privacy architecture, but no system can protect a user from every form of voluntary disclosure.
A user may unintentionally identify themselves through:
photographs;
documents;
writing style;
personal stories;
location information;
employment information;
social-media links;
external websites;
unique personal events;
communication with people who already know their identity.
Users who require strong anonymity should therefore avoid voluntarily publishing combinations of information that make identification easy.
The username is the primary operational identifier within DirectDemocracyS.
For an anonymous user, the username should not reveal the person's legal identity.
Protected information such as:
name;
surname;
identity-document information;
telephone number;
personal email;
verification records;
must not automatically be inferred from the username.
Where the technical architecture permits, identity information and operational information should be maintained in separate logical and technical environments.
Identity-verification data and other particularly sensitive information may be stored on servers inaccessible from the public network.
This architecture is intended to provide an additional security layer.
The fact that information exists on a private server does not eliminate the obligation to protect it.
Private storage must therefore also be subject to:
access controls;
authentication;
encryption where appropriate;
monitoring;
authorisation;
backup security;
retention rules;
deletion procedures.
Backups may contain personal data because they are necessary to restore system availability and integrity.
Backups should be protected with security measures appropriate to the data they contain.
Backup copies should not be treated as an excuse for indefinite retention.
Where data are deleted according to the applicable retention schedule, the deletion process should also consider backup cycles and technical limitations.
Where DirectDemocracyS investigates serious violations, fraud, identity misuse, abuse or security incidents, it may temporarily process additional information.
Such information may include:
account activity;
technical logs;
communications;
verification records;
reports;
evidence;
incident records.
Access is restricted to authorised persons.
The information must not be used for unrelated purposes without an appropriate legal basis.
Where the DirectDemocracyS rules provide for sanctions, a disciplinary or security process may require processing information necessary to:
identify the relevant account;
establish the facts;
protect other users;
document the decision;
provide appropriate procedural safeguards;
respond to appeals;
comply with legal requirements.
Disciplinary records remain subject to confidentiality and retention rules.
DirectDemocracyS operates through specialist, security, administrative, legal, verification and other internal groups.
Membership in an internal group does not grant unlimited access to all personal data.
Each group should receive only the information necessary for its authorised activity.
Information received for one activity must not be redistributed to another group unless there is a legitimate reason and appropriate authorisation.
Persons authorised to access protected personal information must respect confidentiality.
They must not:
disclose identity information without authorisation;
copy protected documents for unrelated purposes;
publish private information;
connect anonymous usernames with real identities for personal reasons;
use protected information for harassment;
use protected information for commercial purposes;
use verification information to obtain personal advantages.
Violations may result in the sanctions provided by DirectDemocracyS rules and, where applicable, legal consequences.
DirectDemocracyS may use human bridges between users and authorised members, and between humans and Artificial Intelligence systems.
The existence of a human bridge does not automatically authorise disclosure of the user's protected personal information.
The bridge should receive only what is necessary to perform its specific role.
Where an AI system is involved, personal data must also be protected according to the applicable privacy and security requirements.
DirectDemocracyS may use Artificial Intelligence systems as part of its technological architecture.
This may include ddsAI, allddsAI or other authorised AI systems where applicable.
AI may assist with:
verification;
analysis;
classification;
security;
translation;
moderation;
information organisation;
technical operations;
detection of anomalies;
other authorised activities.
AI systems do not automatically receive unrestricted access to personal data.
The same principles apply to AI processing as to human processing:
necessity;
purpose limitation;
minimisation;
confidentiality;
access control;
security;
retention limitation;
accountability.
Where AI processing is not necessary, personal data should not be provided merely because the technology is available.
The existence of an AI system inside the DirectDemocracyS ecosystem does not create a general right for that AI system to access all identity information.
Highly sensitive identity data remain protected.
Access should be technically restricted to the specific AI function for which processing is authorised.
DirectDemocracyS recognises that retaining personal information creates risk.
For this reason, the system follows a two-level approach:
Data remain on ordinary network-accessible systems for approximately seven working days as a general operational period.
Information that must be retained for legal, security, accounting, employment, verification, historical, administrative or other legitimate reasons may be transferred to protected private storage.
This separation reduces the continuous exposure of historical information.
Retention periods should be reviewed periodically.
If information is no longer required, it should be:
deleted;
securely destroyed;
anonymised where appropriate;
or isolated where legal retention still applies but operational access is no longer necessary.
The fact that storage is inexpensive does not constitute a justification for indefinite retention.
DirectDemocracyS operates from Romania and within the European Union while potentially interacting with users and activities in multiple jurisdictions.
Different legal systems may impose different retention, employment, accounting, tax, security, marketing or other requirements.
Where applicable law requires a different period from the general DirectDemocracyS retention period, the legally required period applies to the relevant processing activity.
The system therefore maintains category-specific retention requirements rather than treating all data identically.
Marketing communications are subject to applicable law.
Where consent is required, communications will be sent only where valid consent exists.
Where another legal basis is applicable, DirectDemocracyS will comply with the requirements governing that basis.
Users may unsubscribe or exercise applicable objection rights.
Marketing information is normally retained for approximately 24 months from the last administrative contact, unless a longer legally required period applies.
Administrative communications are different from marketing.
They may be necessary for:
account security;
registration;
verification;
password recovery;
important rule changes;
legal notices;
system maintenance;
security incidents;
user-requested services.
Because these communications may be necessary to operate the relationship with the user, they may not always be subject to the same opt-out rules as marketing.
DirectDemocracyS may update this Privacy Policy when:
the system changes;
technology changes;
legal requirements change;
new user types are introduced;
verification procedures change;
retention rules change;
new services are introduced;
security requirements change.
The version and date of the Policy will be updated.
Where legally required, users will receive appropriate notice of material changes.
A modification to this Privacy Policy does not automatically authorise DirectDemocracyS to process personal data for an unrelated new purpose.
Where a new processing activity requires:
a new legal basis;
additional information;
consent;
a contractual change;
another legal safeguard;
the applicable requirement must be satisfied.
DirectDemocracyS considers transparency and accountability fundamental to its privacy model.
The organisation should be able to demonstrate:
what data it processes;
why it processes them;
who can access them;
how long they are retained;
how they are protected;
which legal basis applies;
how users can exercise their rights.
Privacy is therefore not only a statement of intention.
It is an organisational responsibility.
The DirectDemocracyS privacy model can be summarised through the following principles:
You may use an anonymous username where the applicable user type permits it.
Even identity verification does not automatically mean public disclosure.
A person may be verified while remaining operationally anonymous.
Compatibility, skills and identity verification are separated.
Different phases use different verification codes.
They are not ordinary profile information.
They are recorded, encrypted and stored in protected environments according to the applicable rules.
A person does not receive access merely because they are a member or administrator.
The general operational period is approximately seven working days.
Where retention is necessary, information may be transferred to private storage inaccessible from the public network.
This is required by applicable tax and accounting obligations.
Where required, protected retention may extend to 365 days.
Applicable local or national legal requirements may require a different period.
This is a specific exception required by the nature of political representation.
Their real identity is not normally disclosed to other users.
They choose what they reveal, to whom, when and how, within the limits required by the system and applicable law.
It is not merely a document added after the system has been built.
| Data category | Main purpose | Ordinary visibility | Typical operational retention | Longer protected retention |
|---|---|---|---|---|
| Username | Operational identification | According to profile/user type | Approximately 7 working days on operational systems as applicable | While account/records require it |
| Email address | Registration, communication, security | Private | Approximately 7 working days operationally | According to account/legal necessity |
| Telephone number | Verification and security | Private | Approximately 7 working days operationally | According to account/security necessity |
| Password/authentication data | Account security | Never public | According to security requirements | According to security requirements |
| Profile information | User participation | User-controlled where available | According to account/activity requirements | According to purpose |
| Public posts/comments | User participation and publication | Public if deliberately published | According to publication/system rules | According to applicable content-retention rules |
| Compatibility information | Compatibility assessment | Restricted | Limited | According to verification/security requirements |
| Skills information | Skills assessment | Restricted | Limited | According to verification/security requirements |
| Identity documents | Identity verification | Never public | Extremely limited | Protected retention according to verification/legal necessity |
| Selfie/photo-ID verification | Identity verification | Never public | Extremely limited | Protected retention according to verification/legal necessity |
| Verification videos | Identity verification/security | Never public | Limited | Protected storage according to applicable rules |
| Verification codes | Secure process control | Restricted | Limited | Only as necessary |
| Security logs | Security and abuse prevention | Never public | Limited | According to security/legal requirements |
| Accounting information | Tax/accounting obligations | Restricted | Limited operational exposure | Approximately 10 years where required |
| Employee information | Employment obligations | Restricted | Limited operational exposure | According to applicable legal schedule |
| Video-surveillance images | Security | Never public | Generally 24–72 hours on accessible server | Up to 365 days in protected storage where applicable |
| Marketing information | Lawful marketing | Restricted | Limited | Approximately 24 months from last administrative contact or legal period |
| Support communications | Assistance and administration | Restricted | Limited | According to purpose/legal necessity |
| Incident records | Security/legal protection | Highly restricted | Limited | According to legal/security necessity |
A user wishing to exercise a privacy right should contact:
privacy_support@directdemocracys.org
The request should indicate, as appropriate:
the username;
the nature of the request;
the relevant account or activity;
the specific information concerned;
any information necessary to identify the relevant record.
Users should not send unnecessary copies of identity documents unless specifically requested through an authorised and secure procedure.
DirectDemocracyS will attempt to use the least intrusive method necessary to establish the applicant's entitlement.
The Data Protection Officer designated for DirectDemocracyS is:
Franco-Romeo Zaccherini
The DPO may be contacted through:
privacy_support@directdemocracys.org
The DPO's role includes supporting the organisation's compliance with applicable data protection requirements and serving as a contact point for privacy-related matters.
Where a person believes that their personal data have been processed unlawfully, they may have the right to lodge a complaint with the competent data protection supervisory authority.
For persons subject to European data protection law, the competent authority depends on the circumstances, including residence, workplace and the location of the relevant processing.
DirectDemocracyS encourages users to contact the organisation first where appropriate so that privacy issues can be investigated and resolved internally, without prejudice to the person's statutory right to contact a supervisory authority.
This Privacy Policy must be read together with the applicable DirectDemocracyS rules, particularly:
the Join Us Definitive Rules;
the Identity Verification Implementing Rules;
username rules;
security rules;
rules governing user types;
rules governing official representatives;
rules governing political representatives;
rules governing internal groups;
the Cookie Policy;
applicable Terms and Conditions;
other implementing rules concerning personal data and security.
Where a specific operational procedure provides additional privacy safeguards, those safeguards remain applicable.
DirectDemocracyS considers privacy to be closely connected with freedom.
A person should be able to:
participate without unnecessarily exposing their identity;
express ideas without automatically exposing their private life;
contribute without being forced to disclose information unrelated to the activity;
obtain verification where necessary without losing all anonymity;
choose what personal information to reveal;
control voluntary disclosure;
know why information is collected;
know who can access it;
know how long it is retained;
request correction or deletion where legally possible.
Privacy therefore protects not only data.
It protects the person's freedom to participate.
DirectDemocracyS is committed to protecting personal data through a combination of:
legal compliance;
privacy by design;
privacy by default;
anonymity;
operational invisibility;
identity separation;
encryption;
access control;
limited retention;
private storage;
controlled verification;
unique codes;
restricted privileged access;
transparency;
accountability.
The central principle is simple:
The fact that DirectDemocracyS may be able to know something about a person does not mean that everyone else has the right to know it.
The system distinguishes between what must be known, what may be known, what may be voluntarily disclosed and what must remain protected.
For ordinary users, the person's username is their operational identity.
For users requiring verified identity, verification establishes eligibility without automatically creating public disclosure.
For official and political representatives, additional identification requirements apply because of their responsibilities.
In all cases, personal information should be processed only for legitimate, necessary and proportionate purposes, protected against unauthorised access and retained only for as long as required.
DirectDemocracyS
European Commission PIC: 881951064
Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union
Privacy and data protection:
privacy_support@directdemocracys.org
Data Protection Officer:
Franco-Romeo Zaccherini
Privacy Policy version: 1.0
Publication date: 22 September 2026
This Privacy Policy is the general DirectDemocracyS privacy framework.
It is intended to govern the processing of personal data across the DirectDemocracyS system, its platforms, websites and authorised organisational structures.
Specific processing activities may be governed by additional notices, implementing rules, consent mechanisms, contractual provisions or legally required information.
Where a specific activity requires more detailed information than this general Policy provides, the relevant specific privacy notice must be provided to the person concerned.
DirectDemocracyS will periodically review this document to ensure that it remains consistent with:
the actual technical architecture;
the actual data-processing activities;
applicable European Union law;
Romanian law;
applicable local and national legislation;
the DirectDemocracyS rules;
security requirements;
technological developments;
changes to the organisation's platforms and services.
End of Privacy Policy
DirectDemocracyS — 22 September 2026
Version: 1.0
Date of publication: 22 September 2026
Last update: 22 September 2026
Organisation: DirectDemocracyS
European Commission PIC: 881951064
Registered international office: str. Muzicii nr. 22, postal code 410514, Oradea, Bihor County, Romania, European Union
Privacy contact: privacy_support@directdemocracys.org
Data Protection Officer (DPO): Franco-Romeo Zaccherini
DirectDemocracyS considers the protection of personal data, privacy, anonymity, confidentiality, security and individual freedom to be fundamental principles of its entire system.
This Privacy Policy explains, in detail, how DirectDemocracyS collects, receives, generates, processes, verifies, protects, stores, separates, transfers, archives and, where appropriate, deletes personal data.
This Policy applies to the DirectDemocracyS system, its websites, platforms, online services, internal areas, social areas, registration systems, verification systems, communication systems, administrative systems, security systems and authorised internal groups, insofar as they process personal data.
DirectDemocracyS does not consider privacy to be merely a legal obligation. Privacy is also an architectural, organisational and democratic principle.
The system is therefore designed around several fundamental concepts:
data minimisation;
purpose limitation;
confidentiality;
security;
privacy by design;
privacy by default;
separation of personal identity from operational identity;
anonymity wherever anonymity is compatible with the user's chosen or required user type;
controlled visibility;
need-to-know access;
separation of verification phases;
use of unique codes;
restricted access to highly sensitive information;
limited retention on network-accessible systems;
long-term storage only where necessary and preferably in protected environments;
accountability;
transparency;
user control over voluntarily disclosed information.
DirectDemocracyS recognises that different users have different requirements.
A person who participates only as a Free user does not necessarily need to reveal their legal identity.
A person who wishes to exercise rights that require a verified identity, participate in shared leadership, become an official member or perform official or political representation may need to undergo additional verification.
The amount of personal information processed therefore depends on the user's relationship with the system, the user type selected or obtained, the activities performed and the legal or security requirements applicable to those activities.
For the purposes of this Privacy Policy, the relevant DirectDemocracyS entity is identified as follows:
DirectDemocracyS
European Commission PIC: 881951064
Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union
Privacy contact:
privacy_support@directdemocracys.org
Data Protection Officer (DPO):
Franco-Romeo Zaccherini
Requests concerning personal data, privacy, identity verification records, access to personal information, correction, restriction, deletion, objection, portability or other applicable data protection rights may be directed to the privacy contact above.
Where a specific request requires additional verification that the requester is the person entitled to receive or modify the information, DirectDemocracyS may request only the minimum additional information necessary to verify that right.
DirectDemocracyS will not request unnecessary identity information merely because a user wishes to exercise a privacy right.
This Privacy Policy applies, as applicable, to:
visitors to public DirectDemocracyS websites;
Public users;
Test users;
Free users;
Guest users;
Access users;
Partially Registered users;
Verified users;
Members;
Politicians;
Representatives;
Owners;
Managers;
Responsible users;
Administrators;
SuperAdministrators;
Guarantors;
official representatives;
political representatives;
employees and collaborators, where their data are processed;
persons participating in identity verification;
persons participating in compatibility or skills verification;
persons communicating with DirectDemocracyS;
persons whose data are processed for security, legal, administrative, accounting or organisational purposes.
The terminology of user types is governed by the applicable DirectDemocracyS rules.
Not every user type has the same data requirements.
In particular, the fact that DirectDemocracyS may be able to verify a person's identity does not mean that the person's real identity is automatically visible to ordinary users.
DirectDemocracyS follows a simple fundamental principle:
A person's identity should be known only when there is a legitimate reason to know it.
The system therefore separates, as far as technically and organisationally possible, the following concepts:
the person's real-world identity;
the person's DirectDemocracyS username;
the person's email address;
the person's telephone number;
the person's verification codes;
the person's compatibility information;
the person's skills information;
the person's identity-verification information;
the person's public profile;
the person's internal activities;
the person's representative profile;
security and administrative records.
These categories are not automatically interchangeable.
A person may therefore be known inside the operational system by a username without that username publicly revealing their real name.
DirectDemocracyS recognises, wherever permitted by the user's user type and the applicable rules, a fundamental right to operate under an anonymous or non-identifying username.
For ordinary users, the username does not have to correspond to:
the person's first name;
the person's surname;
their legal name;
their address;
their city;
their telephone number;
their email address;
their date of birth;
their employer;
their professional identity;
their social-media identity;
or any other real-world identifying information.
A user may therefore participate using a username that has no obvious connection with their real identity.
The username is the person's operational identity within DirectDemocracyS.
A user may choose an anonymous username according to the applicable username rules.
Examples of privacy-preserving formats include:
For example:
BlueMountain
provided that the nickname does not reveal information that the user does not wish to disclose and is not misleading or reserved for another role.
For example:
RO7F4K29
or another structure based on an ISO country code followed by a random combination of letters and numbers.
The country code itself does not have to identify the person's precise location.
For example:
X7Q9-M4P2-Z8
or another permitted random alphanumeric or special-character combination.
A user may use any username permitted by the applicable DirectDemocracyS username rules, provided that it does not falsely represent another person, a protected role, an official position, an administrative function or another identity.
A user who wishes to maintain strong anonymity should avoid usernames containing:
their real name;
their surname;
their date of birth;
their telephone number;
their email address;
their exact address;
an identifiable social-media username;
an employer-specific identifier;
a unique professional identifier;
a combination of information that could easily identify them.
Anonymity also depends on what the user voluntarily publishes.
A perfectly anonymous username can lose much of its protective value if the user publicly publishes enough information to identify themselves.
For this reason, anonymity is a combination of:
the architecture of DirectDemocracyS;
the username selected by the user;
the information voluntarily disclosed by the user;
the security of the user's own devices and accounts;
compliance with the DirectDemocracyS rules.
DirectDemocracyS seeks to provide strong external invisibility for users who are entitled to anonymous participation.
For an anonymous user, ordinary visitors, external users and ordinary members should see the user's operational username rather than their real identity.
The objective is that a person viewing the public or ordinary internal profile should not be able to derive the user's:
legal name;
surname;
home address;
telephone number;
personal email address;
identity-document information;
verification information;
private identity-verification material.
The user's public or ordinary operational identity is therefore separated from their protected identity information.
This is particularly important for people who participate in political, social, professional, scientific, cultural or other activities and who may have legitimate reasons to protect their personal identity.
DirectDemocracyS also applies the principle of internal invisibility.
Internal invisibility means that even within DirectDemocracyS, a person's real identity is not automatically available to every administrator, member, specialist, verifier, manager or other user.
Access to personal identity information is restricted according to:
role;
purpose;
necessity;
authorisation;
security requirements;
legal requirements;
the particular verification activity being performed.
A person performing a compatibility test does not normally need to know the applicant's legal name.
A person performing a skills assessment does not normally need to know the applicant's legal name.
A person performing an identity verification activity receives only the information and codes necessary to perform that activity.
This separation is one of the principal mechanisms through which DirectDemocracyS seeks to protect anonymity.
DirectDemocracyS uses strong technical and organisational separation between usernames and real identity.
However, the legal concept of anonymisation must be distinguished from pseudonymisation.
Where DirectDemocracyS retains protected information that could, under exceptional authorised circumstances, be used to establish a connection between a username and a real identity, that information remains personal data under applicable data protection law.
Therefore, this Privacy Policy uses the expression “anonymity and invisibility” to describe the protection experienced by ordinary users and unauthorised persons, while recognising that exceptional legally authorised access may exist.
This does not give ordinary users, ordinary administrators or unauthorised third parties a right to access the protected identity information.
DirectDemocracyS follows another fundamental principle:
Users decide what information they voluntarily make visible, to whom, when and in what manner, except where information must be processed privately for legal, security, technical or organisational reasons.
Where the platform provides a visibility option, users may determine, according to the applicable rules and technical possibilities:
whether information is public;
whether information is visible only internally;
whether information is visible to a specific group;
whether information is visible to specific authorised persons;
whether information remains private;
when information becomes visible;
when information stops being visible;
whether information is disclosed voluntarily during a specific activity.
The system does not interpret voluntary publication of one item of information as consent to publish all other information about the same person.
For example, publication of a user's username does not mean that the person's real name, telephone number, address or identity document may also be published.
Some information is processed for technical, legal or security reasons even when it is not publicly visible.
Examples may include:
registration email address;
verified telephone number;
authentication information;
security logs;
identity-verification records;
identity documents;
identity-verification videos;
verification codes;
administrative records;
payment or accounting information;
employment records;
security information;
incident records.
Such information is not made public merely because it exists within the DirectDemocracyS system.
Depending on the user's relationship with DirectDemocracyS, the system may process different categories of information.
This may include:
username;
password credentials in appropriately protected form;
personal email address;
telephone number;
country/operator telephone information;
account status;
user type;
registration date;
account activation information;
account security information.
A secure, non-temporary personal email address and a unique telephone number are part of the applicable registration and verification procedures.
A user's profile may contain information voluntarily provided by the user.
Depending on the user's settings and user type, this may include:
username;
profile description;
interests;
areas of activity;
voluntary biography;
languages;
voluntary professional information;
voluntary geographical information;
voluntary photographs;
voluntary contributions;
participation information;
public comments;
other content intentionally published by the user.
The existence of an account does not automatically mean that all of these categories must be publicly displayed.
For users requesting higher-level participation or identity verification, DirectDemocracyS may process information necessary to determine compatibility with the system.
This may include:
compatibility-test results;
answers to compatibility questions;
evaluation results;
decisions of the authorised verification group;
unique phase codes;
procedural communications;
information necessary to repeat or review a compatibility assessment.
The compatibility process is separate from the identity verification process.
The objective is to evaluate compatibility without unnecessarily exposing the applicant's real identity.
Where a user requests a user type or activity requiring demonstrated skills, DirectDemocracyS may process:
declared skills;
qualifications;
professional experience;
educational information;
evidence supplied by the user;
documents voluntarily or necessarily provided;
specialist assessments;
verification results;
skills-verification codes;
decisions of authorised specialist or verification groups.
A person does not have to possess prestigious qualifications merely to participate in DirectDemocracyS.
However, where a person claims specific professional or specialist competence for an activity requiring verification, DirectDemocracyS may request evidence appropriate to that activity.
Identity verification is a special and highly protected category of processing within the DirectDemocracyS architecture.
Depending on the procedure and applicable user type, identity verification may involve:
real first and last name;
date of birth where relevant;
nationality where relevant;
identity-document information;
passport information;
identity-card information;
another accepted photographic identity document;
photograph;
selfie;
live video;
verification video recording;
verification codes;
verification results;
information necessary to confirm authenticity;
information necessary to document the outcome of the verification.
DirectDemocracyS applies the principle of data minimisation.
The system should not retain information that is not necessary for the specific purpose.
The current DirectDemocracyS identity verification rules establish a structured process.
The process is divided into:
Phase 0 — request and initial information;
Phase 1 — compatibility;
Phase 2 — skills;
Phase 3 — identity verification.
Identity verification is therefore not automatically the first question asked of every participant.
This is an important privacy principle.
A user can participate at lower user levels without mandatory identity verification where the applicable rules permit this.
When a user requests identity verification, the system requires the information necessary to initiate the process.
The current rules require:
a unique username;
a unique personal email address;
a unique telephone number.
The username remains the user's operational identity.
The fact that the system has a personal email address or telephone number does not mean that these data become visible to ordinary users.
In Phase 1, DirectDemocracyS verifies compatibility with the system.
A unique code is generated.
A corresponding code is provided to an authorised and randomly selected member of an appropriate verification group.
The codes are designed to separate the phases and reduce the possibility of linking information between them without special authorisation.
The compatibility verifier does not ordinarily need to know the applicant's legal identity.
The applicant is operationally identified by their username and the relevant verification code.
The result may be:
approval;
rejection;
postponement;
reassignment to another authorised group.
The user receives the result through the appropriate communication channel.
Phase 2 concerns the skills declared by the applicant.
A new unique code is generated for the phase.
An authorised verification group and/or appropriate specialists assess the information and evidence supplied.
The information may include qualifications, documents or other evidence relevant to the claimed competence.
Again, the system uses separation between phases.
The skills verifier does not automatically receive the applicant's complete real identity information merely because the person is undergoing skills verification.
The objective is to verify competence while limiting unnecessary disclosure of personal information.
Only after the preceding requirements have been completed does the applicant proceed to identity verification.
The system generates another unique identity-verification code.
The applicant receives the code.
The authorised identity-verification member receives the corresponding information necessary to perform the verification.
The verifier does not ordinarily receive the applicant's username or other unnecessary information.
The purpose is to verify the identity document and the person without unnecessarily connecting the person's operational identity to their real-world identity.
The current DirectDemocracyS procedure uses a live video call for identity verification.
The applicant may be required to:
demonstrate that they are physically present;
perform simple live movements;
show their face;
present a valid photographic identity document;
show the identity document separately;
follow other security instructions necessary to establish that the person present corresponds to the document.
The call is recorded, encrypted and stored in a protected environment.
The video-verification material is not intended for ordinary public access.
One of the central privacy principles of DirectDemocracyS is that the person performing identity verification does not normally need to know the applicant's operational username.
This means that the verifier can perform the verification activity without automatically learning:
the applicant's public username;
their internal activities;
their political or social participation;
their previous activity history;
their ordinary DirectDemocracyS relationships.
The purpose is to reduce the possibility of unnecessary linking.
After successful verification, the system may mark the operational username as verified or guaranteed without making the real identity publicly visible.
When an identity document or identification file is uploaded or presented:
it is protected;
it is encrypted;
it is processed only for the verification purpose;
access is restricted;
it is not made publicly visible;
access is limited to highly authorised circumstances;
it may be analysed by authorised technical systems and AI systems where this is part of the implemented verification process;
human access is restricted according to the applicable security rules.
Identity documents are among the most sensitive forms of personal information processed by DirectDemocracyS.
They therefore receive a higher level of protection than ordinary profile information.
Where DirectDemocracyS uses its Artificial Intelligence systems to support identity verification, the AI system is used as part of the security and verification architecture.
AI-assisted processing may include:
document analysis;
consistency checking;
video analysis;
comparison of relevant information;
detection of anomalies;
verification assistance;
security analysis.
AI processing does not transform protected identity information into public information.
Where applicable, the system must also respect the legal rights relating to automated decision-making.
A user must not be subjected to an unlawful decision producing legal or similarly significant effects solely because an automated system has produced a particular result.
Where human review, reassessment or an additional verification is required by the applicable process, the appropriate human procedure must be followed.
DirectDemocracyS applies an extremely restrictive approach to access to identity-verification data.
Identity documents, identity-verification files and recorded verification videos are stored in protected environments.
Access may be technically and organisationally restricted to a very small number of highly authorised persons.
Such access must have:
a legitimate purpose;
a serious reason;
appropriate authorisation;
traceability;
documentation;
accountability.
Curiosity is not a legitimate reason for accessing identity data.
A person's administrative position does not automatically give that person unrestricted access to identity information.
The privacy model is different for official representatives and political representatives because their activities require a higher degree of public or local identifiability.
For official and political representatives, additional identity verification may be required.
This can include direct, in-person verification.
The in-person process uses unique codes and mutual verification for security.
The persons participating in the specific verification activity may necessarily know each other's identity for that activity.
This is an exceptional and purpose-specific disclosure.
It does not mean that every administrator or ordinary user receives access to the person's complete identity-verification records.
Political representatives must be identifiable for the political activities they perform.
For political representative profiles, the applicable DirectDemocracyS rules require the username to contain the person's full name and surname, written according to the applicable linguistic rules.
This is an intentional exception to the ordinary anonymity principle.
The reason is functional and organisational: political representation requires identifiable representatives.
The person's protected verification records remain subject to the security and access restrictions described in this Privacy Policy.
Official representatives may use an anonymous operational username in accordance with the applicable rules.
However, official representatives must be identifiable by the people with whom they conduct their official activities.
This creates a distinction between:
ordinary public anonymity;
operational identity;
local or activity-specific identification;
protected legal identity.
The identity disclosed for an official activity may not be reused for unrelated purposes.
For user types for which anonymity is guaranteed by the applicable DirectDemocracyS rules, the system seeks to maintain continuous anonymity.
Ordinary users should therefore be represented operationally by their username.
The system is designed so that ordinary users, ordinary members and unauthorised internal personnel cannot simply connect the username with the person's protected identity information.
This is a central privacy feature of DirectDemocracyS.
DirectDemocracyS has introduced a system under which a new user is connected or matched with an authorised official member.
The purpose includes:
assistance;
orientation;
integration;
safety;
reduction of mistakes;
support during the initial stages;
human contact with the system.
The authorised member receives only the information necessary for the relevant activity.
The existence of this human connection does not automatically grant the authorised member access to the new user's protected identity information.
The matching system does not cancel the user's right to anonymity.
DirectDemocracyS may process information generated when users communicate through:
internal messages;
email;
support requests;
video calls;
group discussions;
administrative communications;
verification communications;
security communications.
The content and metadata of such communications are processed only for legitimate purposes, including:
providing the requested service;
security;
moderation;
verification;
preventing abuse;
resolving disputes;
complying with legal obligations;
maintaining the integrity of the system.
Access to private communications is restricted according to role and purpose.
Users may voluntarily create:
articles;
comments;
posts;
messages;
proposals;
documents;
votes or voting-related records;
specialist contributions;
multimedia content;
other material.
Before publishing personal information, users should consider whether the information is genuinely necessary.
A user who voluntarily publishes personal information may make themselves identifiable even when their username is anonymous.
DirectDemocracyS cannot guarantee anonymity against information that a user deliberately publishes about themselves or that they voluntarily provide to third parties.
For security and operation, DirectDemocracyS may process technical information such as:
IP address;
connection information;
browser information;
device information;
operating-system information;
login information;
authentication events;
failed authentication attempts;
security events;
system logs;
timestamps;
error logs;
fraud-prevention information;
abuse-prevention information.
These records are not intended to become public profile information.
They are primarily used to operate, secure and protect the system.
DirectDemocracyS may use cookies and similar technical mechanisms where necessary for:
authentication;
security;
session management;
functionality;
preferences;
technical operation;
statistics;
other purposes specifically disclosed to users.
The detailed rules governing cookies are contained in the DirectDemocracyS Cookie Policy.
Where consent is legally required, the appropriate consent mechanism must be used.
Depending on the specific processing operation, DirectDemocracyS may rely on one or more legal bases recognised under applicable data protection law.
These may include:
Where processing is necessary to provide the service requested by the user or to manage the user's relationship with DirectDemocracyS.
Where DirectDemocracyS must retain or process information because applicable law requires it.
This is particularly relevant to:
accounting;
taxation;
employment;
legally required records;
security obligations;
legally required disclosures.
Where processing is necessary for legitimate organisational, security, technical or administrative purposes and those interests are not overridden by the rights and freedoms of the person concerned.
Security, prevention of fraud, prevention of abuse and protection of system integrity may constitute legitimate interests where the applicable legal requirements are satisfied.
Where consent is legally required or is the appropriate legal basis, DirectDemocracyS will request it in an appropriate manner.
Consent may be withdrawn where applicable.
Withdrawal of consent does not invalidate processing lawfully carried out before withdrawal.
Personal data collected for one purpose should not automatically be reused for an unrelated purpose.
For example:
identity-verification data are not ordinary marketing data;
security logs are not public profile data;
a telephone number used for verification is not automatically a public contact number;
an identity document is not a profile photograph;
employee records are not community-profile information.
Any new use must have an appropriate legal basis and be compatible with applicable data protection requirements.
DirectDemocracyS seeks to collect and process only the information necessary for each purpose.
Where a purpose can be achieved without identifying a person, anonymous or less identifying information should be preferred.
Where pseudonymisation can reduce the risk, it should be used where appropriate.
Where encryption can reduce the risk, it should be used.
Where access can be limited, it should be limited.
Where information no longer needs to remain on an accessible system, it should be removed from that accessible environment according to the applicable retention procedure.
DirectDemocracyS uses a distinction between:
systems accessible through the network and used for ordinary operation;
protected private storage environments that are inaccessible from the public network and from the Internet.
As a general operational rule, data are retained on the network-accessible platforms for approximately 7 working days, after which information that must be retained is transferred or archived according to the applicable retention category and security procedure.
This does not mean that every category of information is automatically destroyed after seven working days.
Different categories have different legal and operational retention requirements.
The seven-working-day period is therefore primarily the standard operational-access retention period on the network-accessible platforms, while legally or organisationally necessary records may subsequently be maintained in protected private storage.
Where information must be retained after its normal operational period, DirectDemocracyS may store it on a private server or protected storage environment that is:
inaccessible from the public Internet;
inaccessible through ordinary external network access;
separated from ordinary operational systems;
protected through access restrictions;
accessible only to authorised personnel where necessary.
The purpose of this architecture is to reduce the attack surface and to prevent sensitive historical information from remaining continuously exposed through ordinary network-accessible systems.
DirectDemocracyS applies different retention periods according to the category and purpose of the data.
The principal periods currently applicable are:
| Category | Operational / network-accessible period | Protected retention |
|---|---|---|
| General operational data | Approximately 7 working days | According to purpose and applicable necessity |
| Accounting and tax records | Approximately 7 working days on ordinary platforms | Approximately 10 years where legally required |
| Employee data | Approximately 7 working days on ordinary platforms | According to the specific legal and employment retention period |
| Video-surveillance images | Generally 24–72 hours on the network-accessible server | Up to 365 days in protected private storage where required by the applicable security/organisational policy |
| Marketing data | Approximately 7 working days on ordinary platforms | 24 months from the last administrative contact, or longer where required by applicable law |
| Identity-verification records | Limited operational exposure | According to verification, security, legal and organisational necessity |
| Verification videos | Limited operational exposure | According to the applicable security and verification retention schedule |
| Security records | Limited operational exposure | According to security, legal and incident-management requirements |
| Backups | According to backup cycle | According to backup and disaster-recovery requirements |
The exact retention period must always be interpreted together with the applicable law.
Where a law requires a longer period, the legally required period prevails.
Where no legal requirement exists, DirectDemocracyS should retain the information only for as long as reasonably necessary for the stated purpose.
Accounting records and documents required by tax legislation are retained for approximately 10 years, where required by the applicable fiscal obligations.
The purpose is to comply with legal, accounting and tax requirements.
The longer retention of these records does not mean that they are publicly accessible.
They remain protected and subject to access restrictions.
Employee information is subject to specific retention periods determined by:
labour legislation;
tax legislation;
social-security requirements;
contractual requirements;
employment-related legal obligations;
applicable national or local requirements.
Employee records therefore do not have a single universal retention period.
DirectDemocracyS maintains specific retention schedules for employee information according to the applicable legal requirements.
Where DirectDemocracyS uses video surveillance, images recorded by the surveillance system are generally removed from the network-accessible server after approximately 24–72 hours, subject to the applicable legal and operational requirements.
Where a longer retention is necessary for security, investigation, legal or organisational purposes, relevant material may be retained for up to 365 days on a private server that is inaccessible from outside and from the Internet.
Access to retained surveillance material is restricted.
Video surveillance is not intended to create a permanent public record of people's movements.
Where DirectDemocracyS lawfully processes marketing-related information, the standard retention period is approximately 24 months from the last administrative contact, unless a longer period is required by applicable law in the relevant country or local jurisdiction.
Marketing information is not automatically retained indefinitely.
Where applicable, users may exercise the right to object to direct marketing and may withdraw consent where consent is the applicable legal basis.
DirectDemocracyS applies technical and organisational measures intended to protect personal data against:
unauthorised access;
unauthorised disclosure;
alteration;
destruction;
accidental loss;
misuse;
unauthorised linking;
unlawful processing.
Depending on the system and purpose, security measures may include:
encryption;
encrypted communications;
encrypted identity documents;
encrypted video recordings;
protected servers;
private storage;
network segregation;
access control;
role-based permissions;
unique verification codes;
separation of verification phases;
restricted administrator access;
audit records;
authentication controls;
backup protection;
incident-management procedures;
least-privilege principles;
need-to-know access.
A person within DirectDemocracyS should have access only to information necessary for the activity they are authorised to perform.
For example:
A compatibility verifier does not need the user's identity document.
A skills verifier does not need unrestricted access to the user's identity document.
A technical administrator does not automatically need to know a user's real name.
A member helping a new user does not automatically receive access to identity-verification records.
A user does not receive access to another user's private personal information simply because both are members.
This principle applies regardless of organisational rank, subject to exceptional and documented security or legal requirements.
Administrators, SuperAdministrators, Guarantors and other privileged users may have access to systems containing more sensitive information.
However, higher organisational authority does not mean unlimited privacy access.
Privileged access should remain:
purpose-limited;
logged;
authorised;
justified;
reviewable;
limited to what is necessary.
The more sensitive the data, the more restricted access should be.
There may be exceptional situations in which protected information must be accessed.
Examples may include:
a serious security incident;
suspected identity fraud;
serious abuse;
legal proceedings;
a binding legal obligation;
a serious threat to the integrity of the system;
investigation of a serious violation of the rules;
a legitimate request by a competent authority;
technical recovery of critical data.
Exceptional access must not become ordinary access.
Where technically possible, exceptional access should be:
documented;
authorised;
attributable to a specific person;
limited in scope;
limited in time;
auditable.
DirectDemocracyS may disclose personal data to competent public authorities where this is:
legally required;
necessary to comply with a binding legal obligation;
authorised under applicable law;
necessary for a lawful investigation;
necessary to protect fundamental rights or serious security interests.
DirectDemocracyS does not interpret a general request from an authority as an automatic right to unrestricted access to all information.
The request must be handled according to applicable law and the principle of minimisation.
The effective DirectDemocracyS processing structure is intentionally limited.
The current operational environment consists primarily of:
the DirectDemocracyS system;
DirectDemocracyS platforms;
DirectDemocracyS websites;
authorised DirectDemocracyS groups and organisational units.
Authorised internal groups operate under DirectDemocracyS rules and access controls and do not automatically constitute independent external data controllers or processors merely because they are separate operational groups.
Where an external service provider or legally separate entity is actually engaged to process personal data on behalf of DirectDemocracyS, that relationship must be governed by the applicable data protection requirements and documented appropriately.
The list of actual external processors should therefore always reflect the providers actually used at the time this Policy is applied.
DirectDemocracyS does not sell or rent users' personal data.
DirectDemocracyS does not sell personal data.
It does not rent personal information to third parties for commercial exploitation.
Personal data are not treated as a commodity.
The existence of a DirectDemocracyS account does not constitute permission for unrelated organisations to commercially exploit the user's identity.
Where personal data are transferred outside the European Economic Area, DirectDemocracyS applies the safeguards required by applicable data protection law.
Depending on the circumstances, these may include:
an adequacy decision;
appropriate contractual safeguards;
Standard Contractual Clauses;
additional technical measures;
other legally recognised transfer mechanisms.
The specific transfer mechanism depends on the actual location of the receiving system and the applicable law.
DirectDemocracyS should maintain an up-to-date record of actual international transfers.
DirectDemocracyS seeks to maintain accurate information.
Users may be asked to correct information that is:
inaccurate;
incomplete;
obsolete;
inconsistent with the purpose for which it is used.
Where the user controls the information directly through their account, they should use the available profile-management tools.
Where the information cannot be changed directly, the user may contact the privacy team.
A person may have the right to request confirmation as to whether DirectDemocracyS processes their personal data and, where applicable, to obtain access to those data.
Access may include:
categories of data;
purposes;
applicable retention information;
recipients;
relevant processing information;
copies of personal data, subject to applicable legal limitations.
DirectDemocracyS may need to verify that the requester is entitled to receive the information.
This verification should be proportionate and should not unnecessarily undermine the user's anonymity.
Users may request correction of inaccurate personal data.
Where appropriate, DirectDemocracyS may also update information internally when an error is discovered.
Identity-verification information may be subject to specific verification procedures because changing such information can affect the integrity of the verification process.
Where applicable, a person may request deletion of their personal data.
However, the right to erasure is not absolute.
DirectDemocracyS may retain certain information where retention is necessary or legally required, including:
tax records;
accounting records;
employment records;
legally required documents;
security records;
evidence necessary for legal proceedings;
information necessary to prevent serious fraud or abuse;
records whose retention is required to protect the integrity of the system.
Where complete deletion is not legally possible, DirectDemocracyS should restrict processing and, where appropriate, anonymise or isolate the information.
Where applicable, a person may request restriction of processing, for example where:
accuracy is disputed;
processing is allegedly unlawful;
the person needs the information for legal claims;
the person has objected and the relevant assessment is pending.
Restricted data should not be used beyond the purposes permitted by applicable law.
Where the applicable legal basis permits objection, a person may object to certain processing.
This may be particularly relevant to:
direct marketing;
certain processing based on legitimate interests;
other processing for which the law provides a right to object.
DirectDemocracyS will assess the objection according to the applicable legal requirements.
Where the legal conditions for portability are satisfied, a person may request their personal data in a structured, commonly used and machine-readable format.
Portability generally applies only to the categories and legal circumstances defined by applicable data protection law.
DirectDemocracyS may use automated systems and AI to support certain processes.
Examples may include:
technical security analysis;
document analysis;
anomaly detection;
verification assistance;
classification;
system administration.
Automated processing must not unlawfully remove the rights of the person concerned.
Where applicable law grants a right not to be subject to a decision based solely on automated processing producing legal or similarly significant effects, DirectDemocracyS must respect that right and provide the safeguards required by law.
DirectDemocracyS recognises a particular difficulty created by strong anonymity.
If a person uses an entirely random username and DirectDemocracyS does not publicly connect that username to their real identity, the system may not be able to determine whether a person making a request is genuinely the account holder.
In such cases, DirectDemocracyS may request reasonable proof of control over the relevant account or another proportionate verification mechanism.
The purpose is not to destroy anonymity.
The purpose is to prevent one person from obtaining another person's private information.
DirectDemocracyS should therefore seek to verify entitlement without collecting unnecessary additional personal data.
DirectDemocracyS maintains procedures for identifying, containing, investigating and responding to security incidents.
Where a personal-data breach occurs, DirectDemocracyS will assess:
what happened;
what information was affected;
which users may be affected;
the level of risk;
what containment measures are required;
whether notification to a supervisory authority is legally required;
whether affected persons must be informed.
The applicable notification deadlines and procedures are determined by law.
Privacy is incorporated into the DirectDemocracyS architecture from the beginning rather than added only after a system has been developed.
Examples include:
anonymous usernames;
separation of username and identity;
unique verification codes;
separate verification phases;
random selection of verifiers;
restricted access to identity documents;
encrypted verification videos;
private storage;
limited network exposure;
role-based access;
need-to-know access;
limited retention;
separate representative profiles;
controlled visibility.
The objective is to reduce the amount of personal information that any individual person can access.
Where a user has not actively chosen to make information public, the system should apply the most privacy-protective setting reasonably available.
This means that private information should not become public merely because a user has created an account.
The default should be:
minimum necessary visibility, unless greater visibility is deliberately chosen or required for the user's activity.
DirectDemocracyS recognises that security and privacy must work together.
Security procedures may require processing personal information.
However, security is not a general justification for unlimited access.
The appropriate approach is:
collect only what is necessary;
use it only for a legitimate purpose;
protect it;
restrict access;
record exceptional access;
retain it only as long as necessary;
remove or archive it appropriately.
DirectDemocracyS distinguishes between:
the right to participate;
the right to anonymity;
the right to verified identity;
the right to shared leadership;
the right to collective ownership;
the responsibilities of official representation;
the requirements of political representation.
These rights and responsibilities are not identical.
A person does not lose their general right to privacy merely because another person chooses to become an official or political representative.
At the same time, a person who voluntarily requests a role requiring verified identity must accept the additional verification requirements applicable to that role.
Collective ownership is one of the reasons for the identity-verification requirements applicable to official members.
Where the rules require a verified and guaranteed identity for official membership, the identity verification exists to establish eligibility for that specific legal and organisational function.
It does not mean that the person's identity becomes publicly available to every other member.
Verification of eligibility and public disclosure of identity are two different concepts.
Similarly, binding participation in shared leadership may require a verified identity.
The verification exists to ensure that the person exercising the corresponding rights is a real, eligible and uniquely identified participant.
The underlying identity remains protected from ordinary users unless the applicable role requires public identification.
DirectDemocracyS uses different user types because not every activity requires the same level of verification.
The general principle is:
Higher responsibility may require higher verification, but higher verification does not automatically mean unrestricted public disclosure.
A Free user may remain anonymous where the rules permit.
A Verified user may have a verified identity while still operating publicly through a username.
An official member may have additional rights and responsibilities while their real identity remains protected from ordinary users.
A political representative must be identifiable because political representation requires it.
Age-related processing is governed by the applicable DirectDemocracyS participation rules and by the law applicable to the relevant user.
Where age verification is required for a specific service or legal obligation, DirectDemocracyS processes only the information necessary for that purpose.
No unnecessary age-related information should be made public.
DirectDemocracyS may contain links to external websites or services.
When a user leaves a DirectDemocracyS platform and accesses an external service, that service may have its own:
Privacy Policy;
Cookie Policy;
Terms of Service;
data-processing practices.
DirectDemocracyS is not responsible for processing performed independently by an external website outside the DirectDemocracyS system.
Users should therefore review the privacy information of external services before providing them with personal data.
DirectDemocracyS provides strong privacy architecture, but no system can protect a user from every form of voluntary disclosure.
A user may unintentionally identify themselves through:
photographs;
documents;
writing style;
personal stories;
location information;
employment information;
social-media links;
external websites;
unique personal events;
communication with people who already know their identity.
Users who require strong anonymity should therefore avoid voluntarily publishing combinations of information that make identification easy.
The username is the primary operational identifier within DirectDemocracyS.
For an anonymous user, the username should not reveal the person's legal identity.
Protected information such as:
name;
surname;
identity-document information;
telephone number;
personal email;
verification records;
must not automatically be inferred from the username.
Where the technical architecture permits, identity information and operational information should be maintained in separate logical and technical environments.
Identity-verification data and other particularly sensitive information may be stored on servers inaccessible from the public network.
This architecture is intended to provide an additional security layer.
The fact that information exists on a private server does not eliminate the obligation to protect it.
Private storage must therefore also be subject to:
access controls;
authentication;
encryption where appropriate;
monitoring;
authorisation;
backup security;
retention rules;
deletion procedures.
Backups may contain personal data because they are necessary to restore system availability and integrity.
Backups should be protected with security measures appropriate to the data they contain.
Backup copies should not be treated as an excuse for indefinite retention.
Where data are deleted according to the applicable retention schedule, the deletion process should also consider backup cycles and technical limitations.
Where DirectDemocracyS investigates serious violations, fraud, identity misuse, abuse or security incidents, it may temporarily process additional information.
Such information may include:
account activity;
technical logs;
communications;
verification records;
reports;
evidence;
incident records.
Access is restricted to authorised persons.
The information must not be used for unrelated purposes without an appropriate legal basis.
Where the DirectDemocracyS rules provide for sanctions, a disciplinary or security process may require processing information necessary to:
identify the relevant account;
establish the facts;
protect other users;
document the decision;
provide appropriate procedural safeguards;
respond to appeals;
comply with legal requirements.
Disciplinary records remain subject to confidentiality and retention rules.
DirectDemocracyS operates through specialist, security, administrative, legal, verification and other internal groups.
Membership in an internal group does not grant unlimited access to all personal data.
Each group should receive only the information necessary for its authorised activity.
Information received for one activity must not be redistributed to another group unless there is a legitimate reason and appropriate authorisation.
Persons authorised to access protected personal information must respect confidentiality.
They must not:
disclose identity information without authorisation;
copy protected documents for unrelated purposes;
publish private information;
connect anonymous usernames with real identities for personal reasons;
use protected information for harassment;
use protected information for commercial purposes;
use verification information to obtain personal advantages.
Violations may result in the sanctions provided by DirectDemocracyS rules and, where applicable, legal consequences.
DirectDemocracyS may use human bridges between users and authorised members, and between humans and Artificial Intelligence systems.
The existence of a human bridge does not automatically authorise disclosure of the user's protected personal information.
The bridge should receive only what is necessary to perform its specific role.
Where an AI system is involved, personal data must also be protected according to the applicable privacy and security requirements.
DirectDemocracyS may use Artificial Intelligence systems as part of its technological architecture.
This may include ddsAI, allddsAI or other authorised AI systems where applicable.
AI may assist with:
verification;
analysis;
classification;
security;
translation;
moderation;
information organisation;
technical operations;
detection of anomalies;
other authorised activities.
AI systems do not automatically receive unrestricted access to personal data.
The same principles apply to AI processing as to human processing:
necessity;
purpose limitation;
minimisation;
confidentiality;
access control;
security;
retention limitation;
accountability.
Where AI processing is not necessary, personal data should not be provided merely because the technology is available.
The existence of an AI system inside the DirectDemocracyS ecosystem does not create a general right for that AI system to access all identity information.
Highly sensitive identity data remain protected.
Access should be technically restricted to the specific AI function for which processing is authorised.
DirectDemocracyS recognises that retaining personal information creates risk.
For this reason, the system follows a two-level approach:
Data remain on ordinary network-accessible systems for approximately seven working days as a general operational period.
Information that must be retained for legal, security, accounting, employment, verification, historical, administrative or other legitimate reasons may be transferred to protected private storage.
This separation reduces the continuous exposure of historical information.
Retention periods should be reviewed periodically.
If information is no longer required, it should be:
deleted;
securely destroyed;
anonymised where appropriate;
or isolated where legal retention still applies but operational access is no longer necessary.
The fact that storage is inexpensive does not constitute a justification for indefinite retention.
DirectDemocracyS operates from Romania and within the European Union while potentially interacting with users and activities in multiple jurisdictions.
Different legal systems may impose different retention, employment, accounting, tax, security, marketing or other requirements.
Where applicable law requires a different period from the general DirectDemocracyS retention period, the legally required period applies to the relevant processing activity.
The system therefore maintains category-specific retention requirements rather than treating all data identically.
Marketing communications are subject to applicable law.
Where consent is required, communications will be sent only where valid consent exists.
Where another legal basis is applicable, DirectDemocracyS will comply with the requirements governing that basis.
Users may unsubscribe or exercise applicable objection rights.
Marketing information is normally retained for approximately 24 months from the last administrative contact, unless a longer legally required period applies.
Administrative communications are different from marketing.
They may be necessary for:
account security;
registration;
verification;
password recovery;
important rule changes;
legal notices;
system maintenance;
security incidents;
user-requested services.
Because these communications may be necessary to operate the relationship with the user, they may not always be subject to the same opt-out rules as marketing.
DirectDemocracyS may update this Privacy Policy when:
the system changes;
technology changes;
legal requirements change;
new user types are introduced;
verification procedures change;
retention rules change;
new services are introduced;
security requirements change.
The version and date of the Policy will be updated.
Where legally required, users will receive appropriate notice of material changes.
A modification to this Privacy Policy does not automatically authorise DirectDemocracyS to process personal data for an unrelated new purpose.
Where a new processing activity requires:
a new legal basis;
additional information;
consent;
a contractual change;
another legal safeguard;
the applicable requirement must be satisfied.
DirectDemocracyS considers transparency and accountability fundamental to its privacy model.
The organisation should be able to demonstrate:
what data it processes;
why it processes them;
who can access them;
how long they are retained;
how they are protected;
which legal basis applies;
how users can exercise their rights.
Privacy is therefore not only a statement of intention.
It is an organisational responsibility.
The DirectDemocracyS privacy model can be summarised through the following principles:
You may use an anonymous username where the applicable user type permits it.
Even identity verification does not automatically mean public disclosure.
A person may be verified while remaining operationally anonymous.
Compatibility, skills and identity verification are separated.
Different phases use different verification codes.
They are not ordinary profile information.
They are recorded, encrypted and stored in protected environments according to the applicable rules.
A person does not receive access merely because they are a member or administrator.
The general operational period is approximately seven working days.
Where retention is necessary, information may be transferred to private storage inaccessible from the public network.
This is required by applicable tax and accounting obligations.
Where required, protected retention may extend to 365 days.
Applicable local or national legal requirements may require a different period.
This is a specific exception required by the nature of political representation.
Their real identity is not normally disclosed to other users.
They choose what they reveal, to whom, when and how, within the limits required by the system and applicable law.
It is not merely a document added after the system has been built.
| Data category | Main purpose | Ordinary visibility | Typical operational retention | Longer protected retention |
|---|---|---|---|---|
| Username | Operational identification | According to profile/user type | Approximately 7 working days on operational systems as applicable | While account/records require it |
| Email address | Registration, communication, security | Private | Approximately 7 working days operationally | According to account/legal necessity |
| Telephone number | Verification and security | Private | Approximately 7 working days operationally | According to account/security necessity |
| Password/authentication data | Account security | Never public | According to security requirements | According to security requirements |
| Profile information | User participation | User-controlled where available | According to account/activity requirements | According to purpose |
| Public posts/comments | User participation and publication | Public if deliberately published | According to publication/system rules | According to applicable content-retention rules |
| Compatibility information | Compatibility assessment | Restricted | Limited | According to verification/security requirements |
| Skills information | Skills assessment | Restricted | Limited | According to verification/security requirements |
| Identity documents | Identity verification | Never public | Extremely limited | Protected retention according to verification/legal necessity |
| Selfie/photo-ID verification | Identity verification | Never public | Extremely limited | Protected retention according to verification/legal necessity |
| Verification videos | Identity verification/security | Never public | Limited | Protected storage according to applicable rules |
| Verification codes | Secure process control | Restricted | Limited | Only as necessary |
| Security logs | Security and abuse prevention | Never public | Limited | According to security/legal requirements |
| Accounting information | Tax/accounting obligations | Restricted | Limited operational exposure | Approximately 10 years where required |
| Employee information | Employment obligations | Restricted | Limited operational exposure | According to applicable legal schedule |
| Video-surveillance images | Security | Never public | Generally 24–72 hours on accessible server | Up to 365 days in protected storage where applicable |
| Marketing information | Lawful marketing | Restricted | Limited | Approximately 24 months from last administrative contact or legal period |
| Support communications | Assistance and administration | Restricted | Limited | According to purpose/legal necessity |
| Incident records | Security/legal protection | Highly restricted | Limited | According to legal/security necessity |
A user wishing to exercise a privacy right should contact:
privacy_support@directdemocracys.org
The request should indicate, as appropriate:
the username;
the nature of the request;
the relevant account or activity;
the specific information concerned;
any information necessary to identify the relevant record.
Users should not send unnecessary copies of identity documents unless specifically requested through an authorised and secure procedure.
DirectDemocracyS will attempt to use the least intrusive method necessary to establish the applicant's entitlement.
The Data Protection Officer designated for DirectDemocracyS is:
Franco-Romeo Zaccherini
The DPO may be contacted through:
privacy_support@directdemocracys.org
The DPO's role includes supporting the organisation's compliance with applicable data protection requirements and serving as a contact point for privacy-related matters.
Where a person believes that their personal data have been processed unlawfully, they may have the right to lodge a complaint with the competent data protection supervisory authority.
For persons subject to European data protection law, the competent authority depends on the circumstances, including residence, workplace and the location of the relevant processing.
DirectDemocracyS encourages users to contact the organisation first where appropriate so that privacy issues can be investigated and resolved internally, without prejudice to the person's statutory right to contact a supervisory authority.
This Privacy Policy must be read together with the applicable DirectDemocracyS rules, particularly:
the Join Us Definitive Rules;
the Identity Verification Implementing Rules;
username rules;
security rules;
rules governing user types;
rules governing official representatives;
rules governing political representatives;
rules governing internal groups;
the Cookie Policy;
applicable Terms and Conditions;
other implementing rules concerning personal data and security.
Where a specific operational procedure provides additional privacy safeguards, those safeguards remain applicable.
DirectDemocracyS considers privacy to be closely connected with freedom.
A person should be able to:
participate without unnecessarily exposing their identity;
express ideas without automatically exposing their private life;
contribute without being forced to disclose information unrelated to the activity;
obtain verification where necessary without losing all anonymity;
choose what personal information to reveal;
control voluntary disclosure;
know why information is collected;
know who can access it;
know how long it is retained;
request correction or deletion where legally possible.
Privacy therefore protects not only data.
It protects the person's freedom to participate.
DirectDemocracyS is committed to protecting personal data through a combination of:
legal compliance;
privacy by design;
privacy by default;
anonymity;
operational invisibility;
identity separation;
encryption;
access control;
limited retention;
private storage;
controlled verification;
unique codes;
restricted privileged access;
transparency;
accountability.
The central principle is simple:
The fact that DirectDemocracyS may be able to know something about a person does not mean that everyone else has the right to know it.
The system distinguishes between what must be known, what may be known, what may be voluntarily disclosed and what must remain protected.
For ordinary users, the person's username is their operational identity.
For users requiring verified identity, verification establishes eligibility without automatically creating public disclosure.
For official and political representatives, additional identification requirements apply because of their responsibilities.
In all cases, personal information should be processed only for legitimate, necessary and proportionate purposes, protected against unauthorised access and retained only for as long as required.
DirectDemocracyS
European Commission PIC: 881951064
Registered international office:
str. Muzicii nr. 22
410514 Oradea
Bihor County
Romania
European Union
Privacy and data protection:
privacy_support@directdemocracys.org
Data Protection Officer:
Franco-Romeo Zaccherini
Privacy Policy version: 1.0
Publication date: 22 September 2026
This Privacy Policy is the general DirectDemocracyS privacy framework.
It is intended to govern the processing of personal data across the DirectDemocracyS system, its platforms, websites and authorised organisational structures.
Specific processing activities may be governed by additional notices, implementing rules, consent mechanisms, contractual provisions or legally required information.
Where a specific activity requires more detailed information than this general Policy provides, the relevant specific privacy notice must be provided to the person concerned.
DirectDemocracyS will periodically review this document to ensure that it remains consistent with:
the actual technical architecture;
the actual data-processing activities;
applicable European Union law;
Romanian law;
applicable local and national legislation;
the DirectDemocracyS rules;
security requirements;
technological developments;
changes to the organisation's platforms and services.
End of Privacy Policy
DirectDemocracyS — 22 September 2026
Last updated: 22.09.2026
Effective date: 22.09.2026
This Cookie Policy explains how DirectDemocracyS and the websites, platforms, applications and digital services operated by or on behalf of DirectDemocracyS use cookies and similar technologies.
This Policy is intended to apply, where relevant, to the DirectDemocracyS digital ecosystem, including websites and platforms operated under the directdemocracys.org domain and its subdomains, such as:
and other official DirectDemocracyS websites, subdomains, applications and digital services to which this Policy is expressly linked.
Because different platforms may use different technologies and services, the actual cookies and similar technologies deployed on a particular website may differ. The specific cookie information displayed through the applicable cookie-management interface takes precedence for that particular service.
The purpose of this Cookie Policy is to provide clear, transparent and understandable information about:
what cookies are;
what similar technologies may be used;
why cookies and similar technologies are used;
which cookies are strictly necessary for the operation and security of the services;
which cookies require the user's consent;
how users can accept, reject or modify their preferences;
how long cookies may remain on a device;
whether cookies are first-party or third-party cookies;
how cookies may relate to personal data;
how users can withdraw consent;
how users can control or delete cookies through their browser;
how DirectDemocracyS protects users' privacy when using cookies and similar technologies.
This Cookie Policy should be read together with the applicable Privacy Policy, Terms and Conditions, and other legal or informational documents applicable to the relevant DirectDemocracyS service.
Cookies are small text files or similar pieces of information that may be stored on a user's computer, smartphone, tablet or other device when a website or online service is accessed.
Cookies can allow a website to:
remember information about a user's session;
maintain authentication;
remember technical or security settings;
remember language or accessibility preferences;
maintain a shopping or registration process, where applicable;
protect a service against abuse or attacks;
understand how a website is used;
measure performance;
remember privacy and cookie preferences;
provide embedded or third-party functionality, where applicable.
A cookie does not necessarily identify a person directly. However, a cookie identifier can constitute personal data when it can be associated with an identifiable person or combined with other information.
For this reason, DirectDemocracyS treats cookie-related information with appropriate care and applies the applicable data-protection requirements.
The European Commission expressly recognises cookie identifiers as potentially constituting personal data, while also noting that specific rules concerning cookies arise under the ePrivacy framework.
This Policy also applies, where relevant, to technologies that perform functions similar to cookies.
Depending on the services implemented on a particular platform, these technologies may include:
local storage;
session storage;
authentication tokens;
security tokens;
pixels or tracking pixels;
web beacons;
device or browser identifiers;
similar browser-side storage mechanisms;
technologies required to maintain a secure authenticated session;
technologies used to remember privacy choices.
References to "cookies" in this Policy should therefore be understood, where applicable, as including cookies and substantially similar technologies.
Cookies may be classified according to the entity that places them on the user's device.
First-party cookies are placed directly by the DirectDemocracyS website or service that the user is visiting.
They are normally controlled by the operator of that service and may be used for purposes such as:
authentication;
security;
session management;
language preferences;
accessibility preferences;
privacy preferences;
technical functionality;
service configuration;
performance and operational purposes.
Third-party cookies are placed by a third-party service that is integrated into or accessed through a DirectDemocracyS service.
Examples may include, depending on the actual implementation:
video services;
mapping services;
analytics providers;
communication services;
social-media services;
security services;
embedded external content;
payment services, where applicable;
other external technologies.
DirectDemocracyS does not automatically assume responsibility for the independent cookie practices of third parties. Users should consult the privacy and cookie information provided by the relevant third party when third-party technologies are used.
Where third-party technologies require consent under applicable law, DirectDemocracyS will seek the required consent before activating them, unless a specific legal exception applies.
Cookies used by DirectDemocracyS may generally fall into the following categories.
Strictly necessary cookies are cookies that are necessary for a website, application or service to operate or for a functionality explicitly requested by the user.
Examples may include cookies or similar technologies used for:
authentication;
maintaining a secure login session;
preventing fraudulent or abusive activity;
maintaining security;
load balancing;
routing;
maintaining technical sessions;
storing essential technical preferences;
remembering cookie-consent choices;
maintaining the integrity of forms;
protecting the service against automated attacks;
maintaining essential functionality of the platform.
These technologies are not used for advertising purposes.
Where a cookie is genuinely strictly necessary for the provision of a service requested by the user, consent may not be required under the applicable ePrivacy rules.
However, the fact that a technology is technically necessary does not automatically mean that every subsequent processing activity associated with the information is exempt from applicable data-protection requirements.
DirectDemocracyS therefore distinguishes, where applicable, between:
a) the technical storage or access necessary for the service; and
b) any subsequent processing of personal data for additional purposes.
Some DirectDemocracyS platforms may provide registered-user functionality.
Where authentication is available, cookies or similar technologies may be required to:
recognise an authenticated session;
maintain the user's login;
prevent unauthorised access;
protect the account;
maintain session continuity;
distinguish between authenticated and unauthenticated requests;
protect authentication mechanisms against abuse;
support secure single sign-on (SSO), where implemented.
These technologies may be essential for members, registered users, administrators, representatives or other authorised users.
Authentication cookies should not be used for advertising or unrelated behavioural profiling.
Where an authentication service is shared between DirectDemocracyS platforms, the relevant authentication technologies may be associated with the technical operation of the applicable SSO infrastructure.
The precise cookies and their duration depend on the authentication architecture actually deployed on the relevant service.
DirectDemocracyS may use cookies and similar technologies for security purposes.
These may help to:
identify suspicious activity;
detect automated attacks;
prevent abuse;
protect registration and login forms;
prevent session hijacking;
mitigate certain forms of fraud;
protect APIs and applications;
maintain rate-limiting mechanisms;
protect infrastructure;
maintain the integrity of authentication;
detect abnormal requests;
protect the availability and reliability of the service.
Security technologies may operate without consent where they are genuinely necessary to provide a secure service or to protect the service from abuse, subject to applicable law.
Security-related identifiers must not be repurposed for advertising or unrelated tracking without an appropriate legal basis and, where required, prior consent.
Where implemented, functional cookies may remember choices made by the user.
Examples include:
language;
accessibility settings;
interface preferences;
display preferences;
region or service configuration;
previously selected options;
cookie preferences.
These technologies may improve the user experience without necessarily being strictly necessary for the basic operation of the service.
Where applicable law requires consent for a particular functional technology, the technology will remain inactive until the required consent is obtained.
DirectDemocracyS may use analytics or measurement technologies to understand how its websites and services are used and to improve their operation.
Depending on the actual implementation, analytics may include information such as:
pages viewed;
approximate time spent on a page;
browser type;
operating-system type;
device type;
language;
referring page;
approximate geographic information;
technical performance information;
errors encountered;
interaction with particular website functions.
Analytics should be configured, where technically possible, according to privacy-preserving principles.
Where analytics technologies are not strictly necessary and applicable law requires prior consent, they will only be activated after the user has provided the required consent.
DirectDemocracyS will not describe an analytics technology as "anonymous" merely because a name or email address is not collected. The actual configuration and ability to identify or single out users must be considered.
Where analytics data is genuinely anonymised so that individuals can no longer be identified, the resulting information may be treated differently under applicable data-protection law.
DirectDemocracyS is not intended to use cookies or similar technologies to create advertising profiles of users unless such functionality is expressly introduced and appropriately disclosed.
If advertising, behavioural profiling, cross-site tracking, personalised advertising or similar technologies are introduced in the future, the applicable Cookie Policy will be updated before or when such technologies are deployed.
Where required by law, users will be asked for prior consent before such technologies are activated.
Refusing non-essential advertising or tracking cookies must not result in the user being forced to accept those cookies.
Some DirectDemocracyS pages may contain links to, or embedded content from, external services.
Examples may include:
videos;
audio;
maps;
social-media content;
external documents;
external communication tools;
other embedded resources.
An embedded third-party service may potentially place cookies or access information on the user's device.
Where technically possible, DirectDemocracyS may use privacy-enhancing configurations or a consent-based activation mechanism so that third-party content does not automatically activate non-essential tracking technologies before the required consent has been obtained.
Third-party providers may change their technologies, cookie names, purposes or retention periods. DirectDemocracyS will make reasonable efforts to keep the information presented to users up to date.
Where consent is legally required, DirectDemocracyS will request consent before placing or accessing non-essential cookies or similar technologies covered by the consent requirement.
A valid consent mechanism should allow the user to make a genuine choice.
The consent interface should therefore provide, as applicable:
a clear explanation of the purposes;
a clear distinction between necessary and non-essential technologies;
an option to accept non-essential cookies;
an option to reject non-essential cookies;
an option to manage individual categories;
information about third parties where relevant;
a way to change the user's decision later.
Consent must not be inferred merely from:
visiting the website;
scrolling;
continuing to browse;
closing the cookie banner;
using the website without taking a clear affirmative action.
The European Data Protection Board has specifically stated that continued browsing, scrolling or similar passive behaviour does not constitute valid affirmative consent.
DirectDemocracyS aims to ensure that users can reject non-essential cookies as easily as they can accept them.
The consent interface should not deliberately make rejection substantially more difficult than acceptance.
DirectDemocracyS will avoid deceptive or manipulative consent mechanisms, including designs that attempt to pressure users into accepting optional cookies.
The European Commission has specifically highlighted the importance of avoiding "dark patterns" in cookie consent interfaces and states that, under EU rules, refusing should be as easy as accepting.
Where consent is required, DirectDemocracyS will not rely on pre-ticked boxes as a method of obtaining valid consent.
Optional categories should normally be disabled by default until the user actively chooses to enable them.
Consent must represent an affirmative and informed action by the user.
The EDPB's consent guidance specifically addresses the requirement for affirmative consent and the problems associated with pre-ticked mechanisms.
Users may withdraw or modify consent at any time where consent is the legal basis for the relevant cookies or similar technologies.
DirectDemocracyS should provide a persistent and easily accessible mechanism such as:
"Cookie Settings"
or
"Manage Cookie Preferences"
through which users can:
review their current choices;
withdraw consent;
grant consent;
change individual categories;
disable optional technologies.
Withdrawal of consent should be as easy as giving consent.
When consent is withdrawn, DirectDemocracyS will stop activating the relevant optional technologies as soon as reasonably practicable and according to the technical architecture of the service.
Previously collected data may continue to be retained where there is another valid legal basis for its retention or processing, subject to the applicable Privacy Policy and legal requirements.
Where consent is required, DirectDemocracyS may retain a record of the user's cookie choices.
The consent record may contain information such as:
the date and time of the choice;
the version of the consent notice;
the categories accepted or rejected;
a technical identifier necessary to associate the preference with the relevant browser or session;
information necessary to demonstrate that consent was obtained.
The purpose of retaining such information is to:
remember the user's preferences;
avoid repeatedly asking the same question;
demonstrate compliance where required;
maintain the integrity of the consent system.
Consent records should not be used for unrelated profiling.
Cookies can be either:
Session cookies are normally deleted when the browsing session ends or when the browser is closed, depending on the specific technology and browser configuration.
Persistent cookies remain on the device for a defined period or until they are manually deleted.
The duration of a persistent cookie depends on its purpose.
DirectDemocracyS will seek to use the shortest reasonable retention period consistent with the purpose for which the technology is used.
The following table provides the structure that should be used for the actual cookie inventory of each DirectDemocracyS platform.
The final published version should contain only cookies and technologies that are actually deployed.
| Cookie / Technology | Provider | Type | Purpose | First / Third Party | Duration | Consent Required |
|---|---|---|---|---|---|---|
| [COOKIE NAME] | DirectDemocracyS | Necessary | Authentication / security / session | First party | [DURATION] | No, where legally exempt |
| [COOKIE NAME] | DirectDemocracyS | Necessary | Cookie preference management | First party | [DURATION] | No, where legally exempt |
| [COOKIE NAME] | DirectDemocracyS | Functional | Language / preferences | First party | [DURATION] | [YES/NO] |
| [COOKIE NAME] | [PROVIDER] | Analytics | Website measurement | [First/Third] party | [DURATION] | [YES/NO] |
| [COOKIE NAME] | [PROVIDER] | External content | Embedded service | Third party | [DURATION] | [YES/NO] |
| [COOKIE NAME] | [PROVIDER] | Security | Abuse prevention / security | Third party | [DURATION] | [YES/NO] |
Important: this table must be updated whenever a new cookie, SDK, embedded service, analytics service, advertising technology or similar technology is introduced.
A generic Cookie Policy should never be used as a substitute for an actual technical cookie inventory.
Because DirectDemocracyS operates or plans to operate multiple technically different platforms, each platform may maintain its own detailed cookie inventory.
For example:
Domain: directdemocracys.org
Possible technologies may relate to:
website functionality;
security;
authentication;
language;
privacy preferences;
other services actually deployed on the website.
Domain: free.directdemocracys.org
Possible technologies may relate to:
registration;
authentication;
session management;
security;
identity verification;
user preferences;
SSO, where applicable.
Domain: ddsai.directdemocracys.org
The cookie inventory should reflect the technologies actually used by the WordPress-based service and any integrated authentication, security, analytics or external services.
Domain: allddsai.directdemocracys.org
The cookie inventory should reflect the technologies actually used by the Laravel-based service and any integrated authentication, security, analytics or external services.
Other official DirectDemocracyS services may have separate inventories where their technical architecture differs.
Where DirectDemocracyS implements Single Sign-On (SSO), authentication-related cookies or tokens may be used to maintain a secure authenticated session.
Such technologies may allow an authorised user to authenticate across compatible DirectDemocracyS services without unnecessarily repeating the entire authentication process.
SSO technologies may involve:
authentication sessions;
security tokens;
domain-specific session information;
expiration mechanisms;
anti-replay mechanisms;
secure transmission;
session invalidation;
logout mechanisms.
The existence of an SSO system does not automatically mean that every DirectDemocracyS website receives access to all user information.
Access should be limited according to the architecture, permissions and purposes applicable to each service.
SSO cookies and authentication technologies should be treated as security-sensitive technologies.
Where technically appropriate, DirectDemocracyS may configure cookies using security attributes such as:
Secure, so that cookies are transmitted only over secure connections;
HttpOnly, where JavaScript access is not required;
SameSite, to reduce certain cross-site request risks;
appropriate expiration times;
appropriate domain and path restrictions.
The exact configuration depends on the function of each cookie.
Security configuration is part of the technical protection of the service and does not, by itself, determine whether a cookie requires consent.
A cookie itself is not necessarily personal data in every situation.
However, information associated with a cookie may constitute personal data where it can be linked, directly or indirectly, to an identifiable individual.
For example, this may occur where a cookie identifier is associated with:
an account;
an authenticated session;
an IP address;
an email address;
a user profile;
other identifying information.
Where cookie-related information constitutes personal data, DirectDemocracyS processes it in accordance with applicable data-protection law and the applicable Privacy Policy.
The legal basis applicable to cookie-related processing depends on the purpose and technology involved.
For strictly necessary technologies, the applicable ePrivacy rules may permit their use without prior consent where the relevant legal conditions are satisfied.
For non-essential technologies requiring consent, the applicable legal basis may include the user's valid consent.
Where personal data is subsequently processed, the relevant GDPR legal basis must also be considered separately.
The fact that a particular cookie does not require consent for its technical storage or access does not automatically establish the legal basis for every subsequent processing activity involving information obtained through that cookie.
DirectDemocracyS will therefore assess cookie technologies according to their actual function and the applicable legal framework.
Some DirectDemocracyS services may use technical providers located in countries other than the country in which the user is located.
Where personal data is transferred outside the European Economic Area or otherwise subject to international-transfer rules, DirectDemocracyS will apply the safeguards required by applicable law.
Information concerning specific processors, international transfers and data-protection safeguards should be provided in the applicable Privacy Policy.
Most modern browsers allow users to:
view cookies;
delete cookies;
block cookies;
block third-party cookies;
restrict cookies;
configure cookie permissions;
receive warnings before certain cookies are stored.
Users can therefore also manage cookies through their browser settings.
However, disabling strictly necessary cookies may prevent certain functions from operating correctly.
For example, disabling authentication or session cookies may prevent a user from:
logging in;
remaining logged in;
accessing restricted areas;
completing certain registration processes;
using other authenticated functionality.
Browser controls do not necessarily replace a website's consent-management mechanism because they may not distinguish between all individual purposes and categories.
Users can delete cookies already stored on their device through their browser settings.
Deleting cookies may also delete:
authentication sessions;
saved preferences;
language settings;
cookie-consent preferences;
other locally stored configuration information.
After cookies are deleted, a website may ask the user to make cookie choices again.
Browsers may provide privacy-related signals or settings, including "Do Not Track" or similar mechanisms.
The technical and legal interpretation of such signals varies depending on the technology and applicable legislation.
Where a legally recognised privacy signal is applicable to a particular service, DirectDemocracyS will assess and implement it according to the applicable legal and technical requirements.
DirectDemocracyS services are designed and operated according to the age requirements and access conditions applicable to each service.
Where cookies or similar technologies involve the processing of personal data relating to children, DirectDemocracyS will apply the safeguards required by applicable law.
Where parental consent or other specific requirements apply, those requirements will be addressed through the relevant registration, access and privacy procedures.
This Cookie Policy does not replace any age-related requirements contained in the Terms and Conditions or Privacy Policy.
DirectDemocracyS may update this Cookie Policy when:
the website architecture changes;
new technologies are introduced;
existing cookies are removed;
third-party services change;
legal requirements change;
security requirements change;
the purposes of technologies change;
new DirectDemocracyS platforms are introduced.
The "Last updated" date at the beginning of this Policy will be changed whenever a substantive update is made.
Where required, users will be informed of material changes and asked to provide consent again if the changes introduce new consent-requiring purposes.
The introduction of any of the following should trigger a review of the Cookie Policy and cookie-consent configuration:
a new plugin;
a new WordPress extension;
a new Joomla extension;
a new Laravel package;
a new JavaScript library;
a new analytics system;
a new advertising system;
a new video provider;
a new social-media integration;
a new payment provider;
a new authentication provider;
a new CDN;
a new security service;
a new external API;
a new embedded service;
a new monitoring system.
Developers and administrators should not assume that a new component is "cookie-free" without checking its technical behaviour.
DirectDemocracyS should periodically review its websites and applications to identify:
cookies actually being set;
local-storage technologies;
third-party requests;
embedded services;
JavaScript-based tracking;
analytics technologies;
authentication technologies;
security technologies;
cookie duration;
cookie domains;
consent dependencies.
The published cookie inventory should correspond to the technologies actually deployed.
A cookie scanner or browser inspection tool may assist the technical audit, but the results should also be reviewed manually because some technologies are activated only after specific actions, login states, geographic conditions, consent choices or interaction with embedded content.
DirectDemocracyS seeks to apply the principle of data minimisation to cookies and similar technologies.
Where the same technical purpose can be achieved with:
fewer cookies;
shorter retention;
less information;
first-party rather than third-party technologies;
anonymised or aggregated information;
privacy-preserving configurations;
the technically and legally appropriate solution should be considered.
Optional tracking should not be introduced merely because a technical service makes it possible.
DirectDemocracyS does not consider a user to have consented merely because the user:
visits a page;
reads content;
scrolls;
clicks ordinary navigation links;
remains on the website;
closes a banner without making an affirmative choice;
creates an account, unless the specific consent mechanism clearly and lawfully obtains consent for the relevant purpose.
Consent must be associated with a specific purpose or category where required.
Where consent is required, DirectDemocracyS should avoid combining unrelated purposes into a single vague consent request.
For example, where applicable, the following should be distinguishable:
analytics;
personalised advertising;
social-media tracking;
embedded third-party content;
functional technologies;
other optional tracking.
Users should be able to understand what they are accepting.
Refusing optional cookies should not prevent access to content or services that do not technically require those cookies.
However, certain optional features that depend on third-party technologies may not function when the corresponding technology is refused.
For example, an embedded external video may require activation of the relevant external service.
In such cases, the user should be informed that the functionality is unavailable because the corresponding optional technology has not been activated.
Strictly necessary cookies may continue to operate even when a user rejects optional cookies, because disabling essential technical mechanisms could prevent the website or requested service from functioning.
DirectDemocracyS will seek to ensure that necessary cookies are limited to what is genuinely necessary for the relevant technical purpose.
A cookie should not be classified as "necessary" merely because it is convenient, useful or commercially desirable.
This Cookie Policy explains the use of cookies and similar technologies.
The applicable Privacy Policy provides broader information concerning the processing of personal data, including, where applicable:
categories of personal data;
purposes of processing;
legal bases;
data recipients;
processors;
international transfers;
retention periods;
data-subject rights;
security measures;
contact details;
supervisory-authority rights.
Where information obtained through cookies constitutes personal data, the relevant Privacy Policy also applies.
Privacy Policy: [INSERT LINK]
For questions concerning this Cookie Policy or the use of cookies and similar technologies, users may contact DirectDemocracyS through the official contact channels provided on the relevant website.
Organisation: DirectDemocracyS
Official website: https://www.directdemocracys.org
Privacy contact: [INSERT PRIVACY EMAIL]
Data Protection Officer, where applicable: [INSERT DPO INFORMATION OR DELETE IF NOT APPLICABLE]
Postal address: [INSERT OFFICIAL LEGAL ADDRESS]
Where applicable, individuals have the right to lodge a complaint with the competent data-protection supervisory authority.
For individuals located in the European Union, this may generally be the supervisory authority in the Member State of their habitual residence, place of work, or place of the alleged infringement, subject to the applicable rules.
For Romania, the competent supervisory authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Official website:
https://www.dataprotection.ro/
Users should consult the competent supervisory authority for the most current information concerning complaints and available procedures.
DirectDemocracyS considers transparency an essential principle of its digital infrastructure.
Accordingly, DirectDemocracyS aims to:
clearly identify non-essential cookie categories;
explain their purposes;
avoid unnecessary tracking;
avoid deceptive consent mechanisms;
provide meaningful choices;
make withdrawal of consent accessible;
maintain an accurate cookie inventory;
review third-party technologies;
minimise unnecessary data collection;
protect authentication and security technologies;
update this Policy when material technical changes occur.
The objective is not merely to display a cookie banner, but to provide users with meaningful control over optional technologies.
When the applicable consent mechanism is displayed, users should be able to choose, according to the technologies actually deployed:
Accept all optional cookies
Reject all optional cookies
Manage preferences
The "Manage preferences" interface should provide sufficiently granular choices for the purposes actually used by the relevant platform.
Strictly necessary technologies should remain available where legally permitted and technically necessary for the requested service.
Cookie Policy version: [VERSION NUMBER]
Effective date: [DATE]
Last reviewed: [DATE]
Last updated: [DATE]
Next scheduled review: [DATE]
Responsible department/team: [INSERT RESPONSIBLE TEAM]
This Cookie Policy is a legal-information document and should be implemented together with an actual technical cookie inventory.
Before publication, DirectDemocracyS should verify the cookies and similar technologies actually generated by each platform, including cookies generated by:
Joomla;
WordPress;
Laravel;
plugins and extensions;
themes;
JavaScript libraries;
SSO/authentication systems;
security systems;
analytics systems;
embedded content;
CDN or infrastructure services;
external APIs;
monitoring systems;
other third-party services.
The names, purposes, providers, durations and consent requirements in the final cookie table should reflect the actual technical configuration, rather than assumed or generic cookie names.
This distinction is important because a cookie policy is most useful when it accurately describes what the website actually does.
End of Cookie Policy
Register