Privacy
This page explains what data MyCivic collects, why we collect it, how long we keep it, and what rights you have over it. We have written it in plain language. The underlying legal basis is the EU General Data Protection Regulation (GDPR) and, where applicable, equivalent laws in the regions we serve.
1. Who we are
MyCivic is operated as part of the MyCivic Platform Operator (the "Operator"). For data-protection purposes, the Operator acts as a processor on behalf of the contracting municipality, regional authority, or city government (the "Controller"). If you have a question about a specific deployment, the Controller is the entity to contact first.
For general questions about this policy, contact us at marija@mycivic.eu.
2. What we collect
The data MyCivic processes depends on the surface you are using.
When you submit a civic report
- The report content you provide: category, description, photo (optional), location pin
- Approximate device-derived location at the moment of submission, used only for routing
- A submission timestamp and a generated report reference (e.g.
MYC-2841) - Optional contact information you choose to provide (name, email, phone) if you want to receive a notification when the report is resolved
You can submit reports anonymously. Anonymous reports are still tracked and resolved; they simply cannot be tied back to you for follow-up.
When you create an account (operators only)
- Email address, role, and the city / agency you are associated with
- Authentication credentials, hashed and salted, never stored in plaintext
- Session activity needed to operate the platform (login times, actions taken on records)
When you visit our public websites
- Standard server access logs (IP address, user agent, page visited, timestamp)
- Strictly necessary cookies for session continuity and security
- No advertising trackers. No third-party analytics that fingerprint visitors.
3. Why we collect it (lawful basis)
- Performance of a task carried out in the public interest (Article 6(1)(e) GDPR)
- Routing citizen reports to the responsible municipal team is a public-interest function. This is the lawful basis for processing report content and routing-related location data.
- Consent (Article 6(1)(a) GDPR)
- If you provide contact information to receive a resolution notification, we process that information under your explicit consent. You can withdraw it at any time.
- Legitimate interests (Article 6(1)(f) GDPR)
- Security, fraud prevention, and platform operation are processed under the legitimate interests of the Operator and the Controller. We do not use legitimate-interest framing for marketing, profiling, or advertising.
- Contract performance (Article 6(1)(b) GDPR)
- Operator accounts are processed under the employment or service contract between the Controller and the individual.
4. Retention
We retain data only as long as needed for the purpose it was collected for:
- Report content is retained for the duration of the case lifecycle plus an audit window set by the Controller (typically 12–36 months). After that window, content is anonymised or deleted per the Controller's retention policy.
- Optional contact information attached to a report is deleted within 30 days of case closure unless you opt in to ongoing notifications.
- Operator account data is retained for the duration of the operator's relationship with the Controller and a 24-month archival window thereafter for audit purposes.
- Server access logs are retained for 30 days and aggregated thereafter.
5. Who can access your data
Your report content is visible to:
- The municipal team or contractor responsible for resolving the issue
- Authorised staff at the contracting Controller (e.g., supervisors, audit staff)
- Operator engineering and support staff strictly for platform maintenance and security, on a need-to-know basis, under contractual confidentiality
We do not share your data with advertisers, data brokers, or third parties not directly involved in resolving your report. We do not sell data. We do not enrich your data with external sources.
6. Data residency
EU citizen data is processed and stored within the European Economic Area. Canadian deployments are processed within Canada. Australian deployments are processed within Australia. The platform architecture supports per-deployment data residency requirements. Citizen data does not move between jurisdictions unless legally required and explicitly authorised by the Controller.
7. Your rights
Under GDPR and equivalent regional laws, you have the right to:
- Access the personal data we hold about you
- Rectify inaccurate personal data
- Erase your personal data ("right to be forgotten"), subject to legal retention requirements
- Restrict or object to processing in certain circumstances
- Portability of your data in a structured, machine-readable format
- Withdraw consent at any time for processing based on consent
- Lodge a complaint with a national supervisory authority (in the EU) or equivalent regulator
To exercise any of these rights, contact marija@mycivic.eu. If your request concerns a specific municipal deployment, we will route you to the Controller.
8. Security
We use industry-standard technical and organisational measures to protect your data: AES-256 encryption at rest and in transit, access controls scoped to role, complete audit logging of operator actions, regular security testing, and incident response procedures. No system is perfectly secure; we work to minimise risk and respond promptly to issues.
9. Children
MyCivic is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe we have collected such data, please contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Material changes will be communicated through MyCivic's normal channels.
11. Contact
For any privacy-related question or to exercise your rights, write to marija@mycivic.eu. We respond within the statutory window required by applicable law (in the EU, within one month of receipt).