This policy explains how The Change Architect collects, uses and protects personal data when you use this website. We aim to handle your data lawfully, fairly and transparently, in line with the EU General Data Protection Regulation (GDPR) and applicable law.
This notice is provided in good faith as a general statement of our practices. It is not legal advice; specific situations may require tailored legal guidance.
1. Who we are
The Change Architect is an independent research programme run by Mohammed Al-Hajjaj (who also publishes under the pen name Olaf Dawson), based in Belgium. For any privacy question or request, contact contact@thechangearchitect.org. The Change Architect is the data controller for the personal data described here.
2. What information we collect
Newsletter and contact forms
If you subscribe to updates or send us a message, we collect the details you provide — typically your name, email address and message. These forms are delivered to us through the form-processing service FormSubmit.
Publishing submissions
If you submit a paper, study, field note, essay or similar work for review, we collect the information you provide in the submission form. This can include your name, email address, affiliation, role or discipline, profile URL, country or region focus, title, keywords, abstract or summary, rights and prior-publication status, AI-assistance disclosure, preferred public label, and sensitivity or confidentiality note.
The public submission form sends the manuscript attachment through FormSubmit email. We also store submission metadata in our internal publishing register so we can track intake, review status, reviewer notes, corrections, takedowns, publication URLs and decision history. Please do not submit confidential personal data, survivor or beneficiary identifiers, staff files, security-sensitive field information, or material you do not have the right to share.
Member accounts
If you create a free account, we collect your email address and authentication details. Sign-in and accounts are handled through Google Firebase Authentication. If you sign in with Google, Google shares basic profile information with us in line with your Google settings.
Member learning records
If you use free learning features, we may store course progress, completion status, quiz attempts, quiz scores, pass dates and free learning record readiness in our member-learning database. Free learning records are for member tracking only and are not paid certificates, public credentials or external verification records.
Organisation directory
If you submit an organisation to the directory, we collect the details you enter — for example organisation name, type, registration number and date, country, areas of activity, description, website, logo link, and a contact name and email. You confirm consent before submitting. Submissions are reviewed before any are published, and only the organisational fields (not your contact email) are shown publicly.
Member tools and browser storage
Some tools, such as the planner and procurement tracker, save your entries locally in your own browser (local storage) on your device. That data stays on your device and is not transmitted to or stored on our servers unless a tool clearly says it syncs to your account.
Governance Assistant
When you use the AI assistant, the messages you send are processed through the Anthropic API to generate a reply. We do not store your conversations on our servers, and the content is not used to train AI models.
Donations
Donations are processed by Stripe. Stripe handles your payment details directly; we do not receive or store your card information.
Technical data
Like most websites, our hosting provider automatically records basic technical information (such as IP address and browser details) in server logs, used for security and to keep the site running.
3. How we use your information and our legal basis
- To send updates you asked for — based on your consent.
- To respond to your messages and requests — based on our legitimate interest in communicating with you.
- To operate member accounts and member tools — to provide the service you requested.
- To operate free member learning records and progress sync — to provide the learning service you requested and maintain account records.
- To run the organisation directory and review submissions — based on your consent and our legitimate interest in maintaining an accurate directory.
- To review publishing submissions, maintain an editorial decision trail, handle corrections or takedowns, and communicate with authors — based on your consent when you submit work and our legitimate interest in operating a responsible publishing pathway.
- To process donations — to complete the transaction you initiated.
- To keep the site secure and working — based on our legitimate interest.
4. Who we share it with
We do not sell your personal data. We share it only with service providers that help us run the site, who process it on our behalf: FormSubmit (forms and submission attachments), Google Firebase (accounts), Anthropic (AI assistant), Stripe (payments), and our hosting provider. Some of these providers may process data outside the European Economic Area; where they do, appropriate safeguards are intended to apply. We may also disclose information where required by law.
5. How long we keep it
We keep personal data only as long as needed for the purposes above or as required by law. Newsletter data is kept until you unsubscribe; directory listings until you ask us to remove them or they are withdrawn; account data while your account is active; free learning progress while your member account or learning record remains active; and publishing submission records while needed for editorial review, author communication, correction/takedown handling, rights questions, or publication history. You can ask us to delete your data at any time, although we may need to keep limited records where required for legal, security, rights, dispute, or accountability reasons.
6. Your rights
Subject to applicable law, you have the right to access your data; to correct it; to ask us to delete it; to restrict or object to processing; to data portability; and to withdraw consent at any time. To exercise any of these, email contact@thechangearchitect.org. You also have the right to lodge a complaint with your local data protection authority (in Belgium, the Data Protection Authority / Autorité de protection des données).
7. Cookies and local storage
We keep cookies to a minimum. Some features — sign-in and the member tools — use cookies or browser local storage on your device to work properly. You can clear these through your browser settings, though some features may then stop working.
8. Children
This site and its services are intended for professionals and organisations, not for children, and we do not knowingly collect data from children.
9. Changes to this policy
We may update this policy from time to time. We will change the "last updated" date above when we do, and significant changes will be made clear on this page.
10. Contact
For any question or request about your data, contact contact@thechangearchitect.org or write to The Change Architect, Brussels, Belgium.
