Minimal participant data
Standard participation works without a participant account or participant email address.
Privacy explained clearly
This page explains what Green Impact Report processes, what we deliberately do not collect, how photos are handled, and which controls are still manual today.
Last updated: 21 July 2026
Standard participation works without a participant account or participant email address.
We do not sell customer or participant data or use customer or participant photos to train AI models.
Campaigns and reports are unlisted by default. A valid link must still be treated like an access key.
We distinguish between automatic controls, manual processes, and future functionality.
Optional when enabled by the campaign.
The exact data protection role depends on the activity and customer agreement. Roles must be documented before a pilot with special requirements.
Green Impact Report determines how website, contact, and its own business data are processed and is the contact for that processing.
The organization normally determines the purpose, participant group, and process for its campaign. Green Impact Report processes campaign data to provide the platform. The exact roles belong in the customer agreement or data processing agreement.
Questions about the purpose of a specific campaign should first go to its organizer. Technical privacy and deletion requests can also be sent to Green Impact Report.
A QR code opens an unlisted campaign page. Participants select a team, accept required notices, and can submit a contribution.
Automatic periods are explicitly identified as automatic. Other data is reviewed and deleted through a controlled process using the operational criteria below.
Automatically deleted 30 days after upload
An authorized deletion request is handled manually sooner; we do not wait for automatic expiry.
For the active campaign and agreed reporting period
Deletion then, or earlier after an authorized request, is currently controlled and manual. A fixed automatic expiry is not active yet.
While the organization uses its current branding
The stored copy is re-encoded without embedded metadata. On replacement, the API deletes the safely attributed previous object; without an immediate invalidation, CDN or browser copies may remain for up to one hour.
For the active campaign, agreed reporting period, and required support
Complete deletion or anonymization is currently controlled and manual. Entries marked as removed in the dashboard remain stored until then.
For the agreed reporting period
PDFs remain in processed storage until controlled manual deletion.
7 days in the pilot environment, 30 days in stage/production
Security-related information may be retained longer where necessary for a specific incident.
1 day in the pilot environment, 7 days configured for stage/production
Deleted data may remain in access-controlled backups until they expire naturally and is not restored to recover intentionally deleted data.
Organizers and affected people can do more than view data. They can request correction, export, or deletion, and organizers can moderate submissions.
Authorized organizers can download a protected ZIP containing campaign, team, and submission data, visible processed photos, and the latest ready PDF. Raw photos and hidden or removed submissions are excluded.
Organizers can hide, restore, or remove incorrect or unsuitable submissions from visible campaign results. Hidden and removed data remains stored until controlled permanent deletion.
Authorized requests are handled after identity and authority checks. Public links are revoked first, followed by targeted removal of database records, photos, and reports within the agreed scope.
The export archive is generated on demand and streamed directly. Green Impact Report does not store an additional finished ZIP copy.
Only services needed for hosting, authentication, domains, analytics, or contact should receive data. Optional services depend on the contact or booking method selected.
Web hosting, API, database, file storage, media processing, queues, backups, and operational logs
Campaign, account, submission, photo, report, and technical operational data. Primary application infrastructure is configured for AWS Europe (Frankfurt), eu-central-1.
Organizer login and access protection
Organizer identity and authentication data. Participants do not use Auth0. The tenant is created for the Europe region.
DNS, domain protection, and optional privacy-friendly web analytics
Technical website requests and aggregated page-view and performance information, depending on the active Cloudflare configuration.
Delivery of voluntarily submitted pilot enquiries
Contact, company, and message information entered in the pilot form. The service may use its disclosed infrastructure and spam-protection providers.
Optional external meeting booking
Information entered on Calendly’s external page to arrange a meeting. Calendly is used only after the external link is opened.
Optional external communication
Technical connection and communication data processed by WhatsApp after the external link is deliberately opened and during communication there.
Primary campaign infrastructure is configured in AWS Europe (Frankfurt). Individual providers or their subprocessors may process data outside the European Economic Area. Their applicable agreements and transfer mechanisms, such as Standard Contractual Clauses where required, apply. Before a customer contract with specific location requirements, we review and document the exact service scope.
The platform does not yet have a finished school privacy mode. Before a campaign involving children, the organizer, permission process, photo use, public visibility, and shorter retention must be reviewed separately. Such campaigns should not require real names, participant emails, or precise locations.
Depending on applicable law, people may request access, correction, deletion, restriction, portability, or objection. We must verify identity, campaign, and scope sufficiently so that data belonging to the wrong person or organization is not disclosed or deleted.
No. The standard flow uses a technical session and requires neither a participant account nor participant email address.
The platform does not request or extract precise GPS. An original upload may temporarily contain device metadata. Processed display versions are generated without EXIF and other embedded original metadata.
Not completely. It is not publicly linked or indexed, but anyone with the valid link can open it. The link should be shared carefully, given an expiry, and revoked when necessary.
Yes. Authorized organizers can download a protected campaign export. It excludes raw photos and hidden or removed submissions.
Yes. Private raw-photo storage automatically expires original uploads after 30 days. Processed display versions do not yet have an automatic deletion job.
Clarified GPS metadata, manual retention, moderation, backups, and the AI-training statement.
First publication covering data categories, retention, providers, rights, and current limitations.
If you have special requirements for retention, schools, photos, or data location, we will document the scope before launch.