PRIVACY POLICY
Last update: June 2026
1. PREAMBLE
This Privacy Policy (the “Policy”) outlines the data processing practices of the Cultural Heritage Committee’s website
(https://culturalheritagecommittee.com) (the “Platform”).
This Platform is implemented by the United Nations Development Programme office in Cyprus (the “Implementing Partner”) with financial support from the European Union.
The Implementing Partner is committed to protecting the privacy and security of Your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data Law of 2018 (Law 125(I)/2018) of the Republic of Cyprus.
The Implementing Partner acts solely as the provider of technical infrastructure. As this project is the result of contributions from various independent experts, the interpretations and opinions contained herein are solely those of the contributors and do not necessarily reflect the views of the United Nations Development Programme or the European Union.
2. IDENTITY OF THE DATA CONTROLLER
United Nations Development Programme – UNDP office in Cyprus,
P.O. BOX 25644, Nicosia 2063, Cyprus
3. DATA COLLECTION AND SOURCE
We process data to ensure the technical stability of the Platform and to report on the educational impact of the project.
3.1. Automated Technical Data (Telemetry)
Upon accessing the Platform, the Implementing Partner automatically collects the following technical data via Google Analytics 4 (GA4) and server logs:
- Internet Protocol (IP) address (IP anonymization is active).
- Browser type and version.
- Device operating system.
- Time and date of access.
- Referring URL (the website You visited before ours).
3.2. Behavioral Data (User Experience)
We utilize Microsoft Clarity to capture how Users interact with the 3D environments. This includes heatmaps and session recordings (mouse movements and clicks).
- Heatmaps (identifying areas of high engagement);
- Session Recordings (visual playback of mouse movements and clicks).
- Privacy Masking: Clarity is configured to strictly mask all text input fields. Any text You type into forms on the Platform is technically suppressed at the client side and is never transmitted to or recorded by the Implementing Partner.
3.3. Voluntary Data
We collect personal data only when You voluntarily submit it via:
- Contact Forms: Full Name, Email Address, and the content of your message.
- Newsletter Subscriptions: Email Address.
4. PURPOSE AND LEGAL BASIS OF PROCESSING
We process your data for several specific purposes under Article 6 of the GDPR.
- For Security and Fraud Prevention, we monitor server logs to protect the platform against DDoS attacks and unauthorized scraping, based on our Legitimate Interest in maintaining system integrity and availability.
- For Donor Reporting, we aggregate anonymous statistics (e.g., total visitors and content engagement such as Othello Tower views) to fulfill contractual obligations with the European Union under Performance of a Contract.
- For UX Optimization, we use Microsoft Clarity recordings to identify and fix interface issues, based on your Explicit Consent provided via the cookie banner.
- For Communication, we process data submitted via contact forms to respond to inquiries, based on your Consent at the time of submission.
5. DATA RETENTION POLICY
The Implementing Partner applies strict data minimization principles:
- Google Analytics Data: 14 months
- Microsoft Clarity Data: 30 days
- Server Logs: 90 days
- Contact forms and related submissions: up to 1 year after completion of the relevant request, unless legally required otherwise.
6. DATA SHARING AND INTERNATIONAL TRANSFERS
We do not sell, trade, or rent Your personal data to commercial third parties. Aggregated, non-identifiable data (such as total visitor counts) may be shared with the European Union for project monitoring and evaluation purposes. As the Implementing Partner is a United Nations organization, data may be processed on secure servers located outside the European Economic Area (EEA). You acknowledge that the archives and data of the United Nations are inviolable under the Convention on the Privileges and Immunities of the United Nations (1946), which affords Your data a high level of protection against unauthorized access by any national authority.
7. YOUR RIGHTS
Subject to applicable law and the privileges and immunities of the United Nations, You may exercise the following rights in relation to Your personal data:
- Right to Access: Request information about and access to the personal data we hold about You.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of Your personal data where appropriate and subject to applicable retention requirements.
- Right to Restriction of Processing: Request that the processing of Your personal data be limited under certain circumstances.
- Right to Withdraw Consent: Where processing is based on Your consent, You may withdraw that consent at any time. You may withdraw consent for tracking cookies through the cookie preferences tool available on the Platform.
To exercise any of these rights or to raise concerns regarding the processing of Your personal data, please contact us at: privacy@culturalheritagecommittee.com
8. SECURITY
The Implementing Partner employs enterprise-grade security measures, including industry-standard encryption protocols and secure network protections, to safeguard Your personal information. However, no method of transmission over the Internet is 100% secure.
9. CHANGES TO THIS POLICY
We reserve the right to update this Policy at any time. The “Effective Date” at the top of this page reflects the date of the most recent revisions. By continuing to use our services, you agree to be bound by the terms of the updated Policy.
