Global Data Protection & Privacy Policy
Testimony Genesis Foundation
Effective Date: May 1 2026
Testimony Genesis Foundation (“we,” “our,” or “us”) is committed to safeguarding personal data in accordance with applicable global data protection and privacy laws, including the United States privacy framework, the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and relevant African data protection laws such as those inspired by the African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention) and national regulations.
1. Organization Information
Legal Name: Testimony Genesis Foundation
Address: 1763 Columbia Rd NW Ste 175 PMB 529264, Washington, District of Columbia 20009-2891, USA
EIN: 33-4625561
We are a registered 501(c)(3) nonprofit organization, and all donations are tax-deductible in accordance with applicable laws.
2. Scope and Applicability
This Policy applies to all individuals whose personal data we collect, including donors, partners, volunteers, beneficiaries, and website users globally.
Where required, we comply with:
- U.S. federal and state privacy laws (including the FTC Act and applicable state laws such as CCPA/CPRA where relevant)
- EU GDPR (Regulation (EU) 2016/679)
- UK GDPR and Data Protection Act 2018
- Applicable African national data protection laws
3. Categories of Personal Data Collected
We may collect and process the following:
- Identity Data: Full name, organization, title
- Contact Data: Email address, phone number, mailing address
- Financial Data: Donation and payment details (processed via secure third-party providers)
- Technical Data: IP address, browser type, device identifiers, cookies
- Usage Data: Interaction with our website and services
- Communication Data: Messages, inquiries, feedback
4. Legal Basis for Processing (GDPR/UK GDPR)
We process personal data based on:
- Consent (e.g., newsletter subscriptions)
- Contractual necessity (e.g., processing donations)
- Legal obligations (e.g., tax and compliance reporting)
- Legitimate interests (e.g., improving services, outreach, fraud prevention)
For African jurisdictions, processing aligns with principles of lawfulness, fairness, transparency, and purpose limitation.
5. Purpose of Data Processing
Your personal data is used to:
- Process donations and issue tax receipts
- Provide updates, newsletters, and program communications
- Respond to inquiries and support requests
- Improve website performance and user experience
- Ensure compliance with legal, financial, and regulatory obligations
- Prevent fraud, abuse, and security incidents
6. Data Sharing and International Transfers
We do not sell or rent personal data.
We may share data with:
- Trusted service providers (e.g., payment processors, cloud hosting, email systems)
- Regulatory authorities when legally required
- Partners assisting in program delivery under strict data protection agreements
International Transfers:
Where personal data is transferred outside the EU/UK or other jurisdictions, we ensure appropriate safeguards, including:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where applicable
- Equivalent legal safeguards in African jurisdictions
7. Data Security Measures
We implement robust safeguards, including:
- Encryption (SSL/TLS)
- Access control and authentication systems
- Secure data storage and transmission
- Regular system monitoring and vulnerability management
- Staff confidentiality and data protection training
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined, including:
- Legal and regulatory compliance
- Financial record-keeping (e.g., IRS requirements)
- Operational and reporting needs
Data is securely deleted or anonymized when no longer required.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Enhance user experience
- Analyze website traffic
- Improve service delivery
Users may manage cookie preferences through browser settings or cookie consent banners where applicable (GDPR/UK compliance).
10. Data Subject Rights
Depending on your jurisdiction, you may have the right to:
Under GDPR / UK GDPR:
- Access your data
- Rectify inaccurate data
- Erase data (“Right to be Forgotten”)
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
Under U.S. State Laws (e.g., CCPA/CPRA):
- Request disclosure of collected data
- Request deletion of personal information
- Opt-out of certain data uses
Under African Data Protection Laws:
- Right to access and correction
- Right to object to processing
- Right to lodge complaints with supervisory authorities
Requests can be made using the contact details below.
11. Children’s Data Protection
We do not knowingly collect personal data from children under:
- 13 years (U.S. COPPA compliance)
- 16 years (GDPR standard, unless member state law provides otherwise)
If such data is identified, it will be promptly deleted.
12. Third-Party Services and Links
Our website may contain links to external websites or services. We are not responsible for their privacy practices. Users are encouraged to review third-party privacy policies.
13. Compliance with African Data Protection Principles
We align with core African data protection principles, including:
- Lawfulness, fairness, and transparency
- Purpose limitation
- Data minimization
- Accuracy
- Storage limitation
- Integrity and confidentiality
14. Updates to This Policy
We may update this Policy periodically to reflect legal, regulatory, or operational changes. Updates will be posted with a revised effective date.
15. Contact and Data Protection Requests
For inquiries or to exercise your rights, contact:
Testimony Genesis Foundation
1763 Columbia Rd NW Ste 175 PMB 529264
Washington, District of Columbia 20009-2891, USA
Email: [Insert Official Email Address]
16. Supervisory Authorities (Where Applicable)
Individuals in the EU/UK or African jurisdictions have the right to lodge complaints with their respective data protection authorities if they believe their rights have been violated.
This policy reflects our commitment to global compliance, transparency, and responsible data stewardship while advancing our mission and serving communities worldwide.