Skip to main content
CountryReports

Politique de confidentialité

Comment CountryReports collecte, utilise et protège vos données personnelles.

CountryReports respects your privacy. This Privacy Policy explains what personal data we collect, how we use and share it, how long we keep it, and the rights you have over it. It applies to visitors, members, institutional users, and anyone who contacts us through the site.

1. Introduction

CountryReports operates this website and related services ("the service"). We act as the controller of personal data collected through the site. In this policy, "we," "us," and "our" refer to CountryReports; "you" refers to any individual whose personal data we process.

This policy is written to satisfy obligations under the EU General Data Protection Regulation (GDPR), the United Kingdom GDPR, the California Consumer Privacy Act (CCPA) as amended by the CPRA, and other applicable privacy laws. It is provided in plain language so you can understand it without legal training. Where a specific legal framework grants you additional rights, we describe those rights in the relevant section below.

If you do not agree with how we handle personal data as described here, please do not use the service. If you have questions, you may contact us through our contact form.

2. Information We Collect

We collect the categories of information described below. We do not collect more than what is necessary to deliver the service, satisfy a legal obligation, or support a legitimate interest described in Section 4.

Account Data

When you register an individual or institutional account, we collect your name, email address, password (stored as a hash, never in plain text), preferred language, membership tier, and, for institutional accounts, your organization name, role, and associated IP ranges or single sign-on identifiers.

Payment Data

Payments are processed by Shopify. We receive the transaction reference, the last four digits of the card, the card brand, billing country, and the product purchased. We do not receive or store full card numbers, CVV codes, or bank credentials.

Usage and Log Data

Our servers automatically record the pages you view, the date and time of the request, the referring page, your approximate location (derived from IP address), browser type, device type, and operating system. We use this information for analytics, security, and service performance.

Content You Submit

If you submit comments, corrections, support tickets, or other content, we store that content together with the account or email address used to submit it. If you attach files, those files are scanned and stored with your submission.

Cookies and Tracking

We use a small number of first-party cookies to keep you logged in, remember your language preference, and measure aggregate site usage. We do not use third-party advertising cookies or cross-site tracking pixels. See Section 9 for details.

3. How We Collect It

We collect personal data through three channels.

Directly From You

Most of the data we hold is provided by you when you create an account, purchase a membership, submit content, complete a form, or contact us through our contact form. You decide what to share and may decline any optional field.

Automatically

When you visit the site, our servers and our content delivery partner (Cloudflare) automatically record log data and place essential cookies on your device. This collection is necessary for the site to function and for security.

From Third Parties

We receive limited data from Shopify about completed purchases and from identity providers (for example Apple or institutional single sign-on services) when you choose to sign in through them. We receive only what is needed to create or update your account.

4. Legal Basis for Processing

For users in the European Union, European Economic Area, and United Kingdom, Article 6 of the GDPR requires us to identify a lawful basis for each processing activity. The bases we rely on are:

  • Contract (Article 6(1)(b)). We process account, payment, and membership data to provide the service you have purchased and to honor the terms of service you have accepted.
  • Consent (Article 6(1)(a)). We rely on your consent for optional activities such as marketing emails and non-essential analytics. You may withdraw consent at any time without affecting prior lawful processing.
  • Legitimate Interest (Article 6(1)(f)). We rely on legitimate interest to secure the site, prevent fraud, improve the service, measure aggregate usage, and communicate important service notices. We balance these interests against your rights and freedoms.
  • Legal Obligation (Article 6(1)(c)). We process data where required by tax, accounting, consumer-protection, or other applicable law.

Where a processing activity relies on more than one basis, we identify each basis in the relevant section of this policy.

5. How We Use Your Information

We use personal data only for the purposes listed below.

Service Delivery

To authenticate you, display personalized account information, track your content access, and maintain the correctness of your profile and language preference across sessions.

Memberships and Entitlements

To apply the correct premium-content entitlements based on your membership tier, institutional subscription, or IP range, and to notify you of upcoming renewals or expirations.

Communications

To send transactional emails (receipts, password resets, renewal notices, support replies, and material changes to this policy) and, where you have opted in, occasional product updates. Transactional emails are necessary to deliver the service and cannot be disabled while your account is active.

Analytics and Service Improvement

To understand which pages, countries, and features are used, and to improve content coverage and performance. Analytics data is aggregated and does not profile individuals for advertising.

Fraud Prevention and Security

To detect abuse, prevent unauthorized scraping, block automated attacks, protect paid content from credential sharing, and investigate suspected fraud or policy violations.

6. Sharing and Disclosure

We do not sell your personal data. We share it only with the service providers and parties described below, and only to the extent necessary for them to perform their role.

  • Shopify — our payment processor, which handles card authorization, subscription billing, tax calculation, and refunds.
  • AWS (Amazon Web Services) — our hosting and database provider, which stores account data, content, and logs in encrypted form within AWS facilities.
  • AWS SES (Simple Email Service) — our email-delivery provider, which transmits transactional and opt-in emails on our behalf.
  • Cloudflare — our content delivery and security provider, which caches public pages, terminates TLS, and mitigates abuse.
  • Analytics providers — first-party analytics stored in our own database; we do not send data to third-party advertising networks.
  • Legal and regulatory authorities — where we are required to disclose information by court order, subpoena, or applicable law, or to protect our rights, users, or the public.
  • Successors — in the event of a merger, acquisition, or sale of assets, personal data may transfer to the successor entity subject to equivalent privacy protections.

Each service provider is bound by a written agreement that restricts the use of personal data to our documented instructions.

7. International Data Transfers

CountryReports is operated from the United States. If you access the service from outside the United States, your personal data will be transferred to, stored in, and processed in the United States or in other countries where our service providers operate.

Where personal data originates in the European Economic Area, the United Kingdom, or Switzerland, we rely on one or more of the following transfer mechanisms, in order of preference:

  • An adequacy decision by the European Commission or the United Kingdom government covering the destination country.
  • The European Commission’s Standard Contractual Clauses (SCCs, 2021/914) for transfers to third countries without an adequacy decision.
  • The United Kingdom International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs.
  • Supplementary technical and organizational measures, including encryption in transit and at rest.

You may request a copy of the transfer mechanism that applies to your data by contacting us.

8. Data Retention

We keep personal data only as long as we need it for the purposes described in this policy or as required by law.

  • Account data is kept for the life of the account. If you close your account, identifying data is deleted or anonymized within 90 days, except where retention is required for legal or accounting purposes.
  • Payment and invoice records are retained for the period required by tax and accounting law in the relevant jurisdiction, typically seven years.
  • Pageview and analytics logs that are tied to an account are retained for 13 months for reporting and then purged after 15 months.
  • Security and abuse logs are retained for up to 12 months, after which they are deleted or fully aggregated.
  • Support tickets and correspondence are retained for 3 years after resolution so we can reference prior conversations if you reach out again.

When retention periods expire, data is deleted, anonymized, or, where deletion is not technically feasible, placed beyond further use until routine deletion takes place.

9. Cookies and Similar Technologies

We use two categories of cookies and similar technologies. We do not use advertising cookies, cross-site tracking pixels, or fingerprinting.

Essential Cookies

These cookies keep you logged in, remember your language choice, preserve your membership entitlements across pages, and protect the site from abuse. Essential cookies are required for the service to function and are set without consent on the basis of Article 6(1)(b) of the GDPR.

Analytics Cookies

These first-party cookies help us count unique visits, measure page performance, and understand aggregate navigation patterns. They do not contain advertising identifiers. In regions that require prior consent, analytics cookies are only set after you accept them through the cookie banner.

Managing Cookies

You may clear or block cookies through your browser settings at any time. Blocking essential cookies will prevent you from signing in or accessing premium content. A "Cookie Preferences" link in the footer lets you change your analytics choice at any time.

10. Children’s Privacy

CountryReports is an educational site used by students, teachers, and researchers. Although our content is appropriate for a wide age range, individual accounts are intended for users aged 13 and over.

We do not knowingly collect personal data directly from children under the age of 13 in the United States, under the age of 16 in the European Economic Area, or below the applicable age of digital consent in other regions. We do not serve targeted advertising to any user, and we do not build advertising profiles of children.

Schools, districts, libraries, and universities may subscribe on behalf of students through an institutional account. In that arrangement, the institution is the controller of any student personal data processed through the site, and we act as a processor on the institution’s written instructions. The institution is responsible for any parental notice or consent required by the Children’s Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), or local law.

If you believe a child has created an individual account without the consent of a parent or guardian, please contact us through our contact form and we will promptly close the account and delete the associated data.

11. Your Privacy Rights

Depending on where you reside, you may exercise the following rights with respect to your personal data.

Rights Under GDPR and UK GDPR

  • Access. Obtain a copy of the personal data we hold about you.
  • Rectification. Correct inaccurate or incomplete personal data.
  • Erasure. Ask us to delete your personal data, subject to legal retention obligations.
  • Portability. Receive your data in a structured, commonly used, machine-readable format.
  • Restriction. Ask us to limit the processing of your data in specific circumstances.
  • Objection. Object to processing that relies on legitimate interest.
  • Withdraw consent. Withdraw consent at any time, without affecting the lawfulness of processing that took place before withdrawal.

Rights Under CCPA / CPRA

  • Right to know. Ask what categories of personal information we collect, use, and disclose about you.
  • Right to delete. Ask us to delete personal information we have collected from you.
  • Right to correct. Ask us to correct inaccurate personal information.
  • Right to opt out of sale or sharing. We do not sell personal information and do not share it for cross-context behavioral advertising, so there is nothing to opt out of; this notice is provided for transparency.
  • Right to non-discrimination. You will not be denied service or charged a different price for exercising any CCPA right.

How to Exercise Your Rights

To exercise any of these rights, please contact us through our contact form. We will verify your identity before responding and will respond within the time required by applicable law (one month under GDPR, 45 days under CCPA, each extendable where permitted). You may also authorize an agent to submit a request on your behalf.

12. Security

We take reasonable and appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, alteration, and disclosure. Our measures include:

  • Encryption of data in transit using TLS 1.2 or higher.
  • Encryption of data at rest within our AWS infrastructure.
  • Password hashing using industry-standard algorithms; passwords are never stored in plain text.
  • Role-based access controls so staff may access only the data needed for their role.
  • Multi-factor authentication on administrative access.
  • Routine patching, logging, backup, and vulnerability scanning.
  • Written agreements and periodic review of our processors and sub-processors.

No method of transmission or storage is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and we will notify affected users without undue delay where required by law.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the services we offer, or the law. The updated policy will be posted on this page with a revised "Last Updated" date at the top.

Where a change is material — for example, a new category of data, a new processing purpose, or a new recipient of your data — we will provide advance notice by displaying a banner on the site and by emailing registered account holders. Where applicable law requires us to obtain renewed consent, we will ask for it before the change takes effect.

Your continued use of the service after the effective date of the revised policy constitutes acceptance of the changes, subject to any consent requirements.

14. How to Contact Us

If you have questions about this Privacy Policy, wish to exercise a privacy right, or need to report a concern, please contact us through our contact form. We will route your message to the appropriate team and respond within the timeframes described in Section 11.

We do not currently have a designated EU or UK representative. Residents of the European Economic Area, the United Kingdom, and Switzerland may correspond with us in English, and we will treat all such correspondence with the same care and urgency as a request from any other region.

If you believe we have not resolved your concern satisfactorily, you have the right to lodge a complaint with your national data protection authority. In the European Union, that is the supervisory authority of the member state where you live, work, or where the alleged infringement took place. In the United Kingdom, that is the Information Commissioner’s Office. In the United States, state attorneys general and the Federal Trade Commission accept complaints about privacy practices.