Legal

Privacy

Version 1.0 Effective 2026-05-13 Last updated 2026-05-13

This page explains what data MyCivic collects, why we collect it, how long we keep it, and what rights you have over it. We have written it in plain language. The underlying legal basis is the EU General Data Protection Regulation (GDPR) and, where applicable, equivalent laws in the regions we serve.

Plain summary. MyCivic collects the issue, not the citizen. We do not require a personal account to submit a civic report. We minimise what we collect, retain it only as long as needed, and never sell or share it with third parties for marketing. EU citizen data stays in EU jurisdictions.

1. Who we are

MyCivic is operated as part of the MyCivic Platform Operator (the "Operator"). For data-protection purposes, the Operator acts as a processor on behalf of the contracting municipality, regional authority, or city government (the "Controller"). If you have a question about a specific deployment, the Controller is the entity to contact first.

For general questions about this policy, contact us at marija@mycivic.eu.

2. What we collect

The data MyCivic processes depends on the surface you are using.

When you submit a civic report

You can submit reports anonymously. Anonymous reports are still tracked and resolved; they simply cannot be tied back to you for follow-up.

When you create an account (operators only)

When you visit our public websites

3. Why we collect it (lawful basis)

Performance of a task carried out in the public interest (Article 6(1)(e) GDPR)
Routing citizen reports to the responsible municipal team is a public-interest function. This is the lawful basis for processing report content and routing-related location data.
Consent (Article 6(1)(a) GDPR)
If you provide contact information to receive a resolution notification, we process that information under your explicit consent. You can withdraw it at any time.
Legitimate interests (Article 6(1)(f) GDPR)
Security, fraud prevention, and platform operation are processed under the legitimate interests of the Operator and the Controller. We do not use legitimate-interest framing for marketing, profiling, or advertising.
Contract performance (Article 6(1)(b) GDPR)
Operator accounts are processed under the employment or service contract between the Controller and the individual.

4. Retention

We retain data only as long as needed for the purpose it was collected for:

5. Who can access your data

Your report content is visible to:

We do not share your data with advertisers, data brokers, or third parties not directly involved in resolving your report. We do not sell data. We do not enrich your data with external sources.

6. Data residency

EU citizen data is processed and stored within the European Economic Area. Canadian deployments are processed within Canada. Australian deployments are processed within Australia. The platform architecture supports per-deployment data residency requirements. Citizen data does not move between jurisdictions unless legally required and explicitly authorised by the Controller.

7. Your rights

Under GDPR and equivalent regional laws, you have the right to:

To exercise any of these rights, contact marija@mycivic.eu. If your request concerns a specific municipal deployment, we will route you to the Controller.

8. Security

We use industry-standard technical and organisational measures to protect your data: AES-256 encryption at rest and in transit, access controls scoped to role, complete audit logging of operator actions, regular security testing, and incident response procedures. No system is perfectly secure; we work to minimise risk and respond promptly to issues.

9. Children

MyCivic is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, please contact us and we will delete it.

10. Changes to this policy

We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated through MyCivic's normal channels.

11. Contact

For any privacy-related question or to exercise your rights, write to marija@mycivic.eu. We respond within the statutory window required by applicable law (in the EU, within one month of receipt).

Note for legal review. This document is a working draft based on standard GDPR-aligned civic-tech practice. It should be reviewed by qualified counsel in each jurisdiction before being relied upon. The contracting Controller in each deployment may add or amend terms specific to their regulatory environment.