Data Ethics
How we handle beneficiary, citizen, and partner data — with dignity, transparency, and accountability.
Effective: June 2026
Our principles
Working with governments, NGOs, UN agencies, and donor programmes means handling some of the most sensitive data in the region. We commit to:
- Dignity first — beneficiaries are people, not records
- Minimum necessary — collect only what the use case truly requires
- Informed consent — make purpose, sharing, and rights explicit
- Sovereignty — respect data residency choices of governments and donors
- Accountability — keep audit trails and act on data subject requests promptly
Beneficiary and citizen data
For systems handling beneficiary or citizen data, we design for purpose limitation, role-based access, and secure deletion. We do not use beneficiary data for any purpose other than the explicit programme purpose, and never for marketing.
AI and automation
When we build AI features, we keep humans in the loop for consequential decisions, log model decisions for review, and avoid using sensitive data for model training without explicit permission.
Vulnerability disclosure
Report security issues to security@novacoredigital.com. We commit to acknowledging reports within two business days and remediating critical issues quickly.
Note: This document is a starting template. Have it reviewed by qualified legal counsel in your jurisdiction before relying on it.