Global Privacy & Data Protection Policy
This policy outlines our commitment to international compliance and the rights you hold regardless of where you live.
1. Our Global Compliance Framework
We maintain a “Privacy First” infrastructure that meets or exceeds the requirements of the world’s most stringent data protection regulations.
| Framework | Region | Key Requirement / Law Reference |
|---|---|---|
| GDPR / UK-GDPR | EU & UK | Right to Access (Art. 15), Right to be Forgotten (Art. 17), Data Portability (Art. 20) |
| POPIA | South Africa | Accountability of Responsible Parties (Sections 8–10), Right to Access (Section 23) |
| CCPA / CPRA | USA (California) | Right to Opt-Out of Sale (Cal. Civ. Code §1798.120), Global Privacy Control (GPC) support |
| PIPEDA / CPPA | Canada | Meaningful Consent (Sections 5–7), Mandatory Breach Reporting (Section 10.1) |
| Privacy Act 1988 | Australia | Transparency on Automated Decisions (2026 Rule), Access & Correction rights |
| Privacy Act 2020 | New Zealand | IPP 3A (Indirect Collection Notification), Right to Access & Correction |
2. Data We Collect & Why
We follow the principle of Data Minimization: if we don’t need it to provide our service, we don’t ask for it.
- Information You Provide: Identity details (name, email) and content uploaded during mediation.
- Information Collected Indirectly: Under NZ IPP 3A (2026), if we receive your data from a third party, we notify you of the source and purpose as soon as reasonably practicable.
- Automated Interactions: Cookies, session data, and tools to secure logins and improve performance. We honor Global Privacy Control (GPC) signals.
3. AI & Automated Decision-Making (ADM)
In compliance with Australia Privacy Act (2026) and EU AI Act, we are transparent about automated decision-making:
- Any automated decision affecting your rights or interests will be clearly labeled.
- You may request a human review of any automated decision.
4. Security: AES-256 Standard
We treat your data like our own.
- Encryption: All data is encrypted at rest and in transit using AES-256.
- Sovereignty: We store data in your local region whenever technically feasible, complying with local data sovereignty requirements.
5. Your Global Rights
Regardless of your location, you have these “Golden Rights”:
- Access & Correction: View and correct your personal information.
- Erasure (“Right to be Forgotten”): Request permanent deletion of your account and data.
- Data Portability: Download your data in a machine-readable format.
- Non-Discrimination: Exercising your privacy rights will not result in penalties.
6. Contact & Redress
For questions or formal requests under your local law (such as a DSAR):
Email: notifications@imedi8.online
Response Time: Within 3 days