UGIF GOVERNANCE
Privacy Policy
United Global Impact Federation (UGIF) respects the privacy of individuals and organizations interacting with its website and digital services. This Privacy Policy explains the categories of information UGIF may collect, the purposes for which it may be processed, how it may be protected and retained, and the choices and rights that may be available under applicable law.
Last updated: September 2026
1. Scope
This policy applies to information collected through the UGIF website, membership registration, partner applications, contact and enquiry forms, event or programme registrations, communications, knowledge resources and related digital services.
2. Information UGIF may collect
Depending on the service used, UGIF may collect name and identity details; date of birth and other profile information; email address and mobile number; country, state, city, address and postal information; profession, organization, designation, qualification and expertise; membership category and Main Stream; photograph; partnership and organizational information; documents voluntarily uploaded; communications and enquiries; consent records; OTP verification status; and technical information such as browser, device, IP address, logs and security events.
3. Membership data
Membership forms require the information identified as mandatory. Email OTP and mobile OTP verification are mandatory. UGIF may use verified information to complete registration, administer membership, generate and maintain a permanent Member ID, manage membership validity and renewal, communicate with members and maintain appropriate membership records.
4. Partner and enquiry data
Information submitted through partnership, contact, volunteer, event or other enquiry forms may be used to understand the request, assess collaboration opportunities, communicate with the applicant, coordinate follow-up and maintain appropriate organizational records.
5. Why UGIF processes personal data
UGIF may process information for service and programme administration, membership management, identity/contact verification, communication, programme implementation, community engagement, research and learning, monitoring and evaluation, event administration, safeguarding and security, fraud or misuse prevention, reporting, legal or regulatory compliance and other legitimate organizational purposes consistent with the context in which information was provided.
6. Data minimisation and accuracy
UGIF should request information reasonably necessary for the stated purpose. Users should provide accurate information and should not submit unnecessary sensitive personal information, passwords, OTPs, payment credentials or information belonging to another person without authorization.
7. How information may be shared
Information may be accessed by authorized UGIF personnel and service providers supporting hosting, authentication, OTP delivery, email, SMS, storage, analytics, security, communications and other website operations. UGIF does not sell personal information. Where third-party services are used, UGIF should apply appropriate contractual, technical and organizational safeguards.
8. Technology, APIs and AI services
UGIF may connect its website or administrative systems to external technology and API providers in the future, including communication, analytics, storage, mapping, payment, automation or AI services. Only information necessary for the relevant function should be transmitted, and production integrations should use server-side controls, access restrictions and appropriate provider terms. API secrets must never be exposed in public website code.
9. International processing
Some service providers may process information in locations outside the user's country. Where applicable, UGIF will use appropriate safeguards and comply with applicable legal requirements.
10. Security
UGIF will use reasonable technical and organizational measures appropriate to the nature of the information, including access controls, secure authentication, encryption where appropriate, least-privilege administration, rate limiting, logging, backups and security monitoring. No online system can be guaranteed to be completely secure.
11. OTP and verification security
OTP systems should use short expiry periods, resend cooldowns, attempt limits, rate limiting and abuse protection. OTP values should not be stored in plaintext. Verification records should be retained only as necessary for security, administration and applicable legal requirements.
12. Cookies and analytics
UGIF may use essential technologies required to operate and secure the website and, where enabled, analytics or similar technologies to understand website usage and improve services. Where consent or notice is legally required, the production website should provide the appropriate controls.
13. Data retention
UGIF should retain information only for as long as reasonably necessary for the purpose for which it was collected, membership or partnership administration, organizational records, security, dispute resolution and applicable legal obligations. Retention periods should be defined and managed by data category.
14. Individual rights
Subject to applicable law, individuals may have rights relating to access, correction, deletion, restriction, objection, withdrawal of consent or other control over their personal data. Requests should be handled through UGIF's designated privacy/data contact and applicable procedures.
15. Children's information
UGIF should not knowingly collect personal information from children through services not intended for them without appropriate authorization and safeguards.
16. External websites
UGIF may provide links to initiative, partner, institutional or other external websites. Those websites operate under their own policies and terms. UGIF is not responsible for their privacy practices, content or security.
17. Policy changes
UGIF may update this policy when its services, technology, data practices or legal requirements change. The current version and revision date should be maintained on this page.
18. Contact
The production website should publish UGIF's verified official privacy/data contact channel for privacy questions and requests.