← Back to HomePrivacy Policy
Last Updated: April 2026
1. Introduction
Web3 Certification Board Inc. ("W3CB," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our Parametric Insurance Simulator application. It is intended to comply with applicable privacy laws across the jurisdictions represented in our learning scenarios, including the European Union, United Kingdom, Kenya, India, Thailand, Vietnam, the Caribbean, and the United States.
Because our simulator is designed for policymakers, government officials, NGO representatives, and climate negotiators from climate-vulnerable nations, we have taken particular care to address the data protection frameworks most relevant to our expected user base. Where multiple frameworks apply, we apply the most protective standard.
2. Information We Collect
2.1 Information You Provide
We may collect information you voluntarily provide, including:
- Contact information (name, email address) when you contact us or request support
- Feedback, comments, and correspondence you send us
- Survey responses or event registration information
- Participant name entered for educational completion certificates (stored locally on your device only — see Section 2.3)
2.2 Automatically Collected Information
When you access our application, we may automatically collect:
- Device and browser information (browser type, version, operating system, screen resolution)
- Usage data (pages visited, time spent on each section, simulation choices made, scenarios completed)
- IP address and derived approximate geographic location (city/country level only)
- Referral source (how you arrived at the application)
This information is collected for legitimate educational analytics purposes — specifically to improve the simulator's effectiveness for its intended audience — and is not shared with advertising networks or data brokers.
2.3 localStorage — On-Device Storage Only
This application stores the following data locally in your browser's localStorage. This data does not leave your device and is never transmitted to our servers:
- w3cb_visit_count — Tracks visit count to control when the welcome disclaimer modal is displayed
- w3cb_cookie_consent — Records your cookie consent choice ("Essential Only" or "Accept All")
- w3cb_completed_scenarios — Records which simulation modules you have completed, the coverage tier selected, and whether triggers were activated
- w3cb_participant_name — Your name as entered for educational completion certificates (entirely optional; you may leave this blank)
You can clear all this data at any time through your browser's site settings (typically Settings → Privacy → Site Data → this domain). Clearing this data will reset your completion progress and consent preferences.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain our educational simulator application
- Improve the simulator's content, usability, and effectiveness for its target audience
- Analyse usage patterns to understand which scenarios and features are most valuable
- Respond to your enquiries, feedback, or support requests
- Send administrative communications (e.g., material updates to this policy)
- Comply with legal obligations across all applicable jurisdictions
We do not sell, rent, or lease your personal data to third parties. We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
4. GDPR Rights — European Union and United Kingdom Users
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR) and UK GDPR respectively. These rights are substantive, not aspirational — we are obligated to fulfil them within statutory timeframes.
4.1 Your Rights
- Right of Access (Art. 15 GDPR): Request a copy of all personal data we hold about you, along with information about how it is processed. We must respond within one calendar month (extendable to three months for complex requests, with notice).
- Right to Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data without undue delay.
- Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR): Request deletion of your personal data where it is no longer necessary for the purpose collected, where you withdraw consent, or where you object and we have no overriding legitimate interests.
- Right to Restriction of Processing (Art. 18 GDPR): Request that we limit processing to storage only while a dispute about accuracy or lawfulness is resolved.
- Right to Data Portability (Art. 20 GDPR): Request your data in a structured, commonly used, machine-readable format (where processing is based on consent or contract).
- Right to Object (Art. 21 GDPR): Object to processing based on legitimate interests. We must stop processing unless we demonstrate compelling legitimate grounds that override your interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw at any time without affecting the lawfulness of prior processing.
4.2 Lawful Basis for Processing
Our primary lawful basis for processing automatically collected data is legitimate interests (Art. 6(1)(f) GDPR) — specifically, our interest in providing an effective educational training tool to policymakers, balanced against your fundamental rights and freedoms. For any direct communication you initiate, the basis is contract performance or pre-contractual steps (Art. 6(1)(b)).
4.3 Complaint Mechanism
To exercise any of the above rights, contact us at privacy@w3cb.org. If you are not satisfied with our response, you have the right to lodge a complaint with your national supervisory authority:
5. Regional Data Protection Rights
Our simulator is designed for and explicitly references communities and policymakers across multiple jurisdictions. We recognise the following applicable data protection frameworks and provide jurisdiction-specific detail on data subject rights and complaint mechanisms.
5.1 Kenya — Data Protection Act 2019
The Kenya Data Protection Act 2019 (DPA 2019) came into force on 25 November 2019, with implementing regulations enacted in 2021. It applies to data controllers and processors who process personal data of individuals in Kenya, regardless of where the controller is established. This simulator's Drought Protection scenario is set in East Africa and is used in Kenyan training contexts, bringing Kenyan participants within scope.
Data Subject Rights Under the Kenya DPA 2019
- Right to be Informed (s.26(a)): You have the right to know the identity of the data controller, the purpose for which your data is collected, and any third parties to whom it may be disclosed — before collection occurs.
- Right of Access (s.26(b)): You may request confirmation of whether we process your personal data and, if so, a copy of that data. We must respond within 21 days of receiving a valid request.
- Right to Object (s.26(c)): You may object to processing of your personal data in certain circumstances, including direct marketing (absolute right) and processing based on legitimate interests (subject to balancing test).
- Right to Correction (s.26(d)): You may request correction of inaccurate, misleading, or incomplete personal data.
- Right to Deletion (s.26(e)): You may request deletion of personal data that is no longer necessary for the purpose for which it was collected, or where you have withdrawn consent and no other lawful basis exists.
- Right to Data Portability (s.38): Where processing is by automated means based on consent or contract, you may receive your data in a structured, commonly used format.
- Protection of Sensitive Personal Data (s.35): Health data, biometric data, racial or ethnic origin, and religious beliefs require explicit consent before processing. W3CB does not knowingly collect sensitive personal data of this nature from users of this simulator.
Complaint Mechanism — Kenya
The Office of the Data Protection Commissioner (ODPC) is the statutory supervisory authority under s.5 of the DPA 2019. To lodge a complaint:
- Website: www.odpc.go.ke
- Email: info@odpc.go.ke
- Postal Address: Office of the Data Protection Commissioner, Nairobi, Kenya
- The ODPC must acknowledge a complaint within 21 days and investigate within 60 days (extendable for complex matters)
- Decisions of the ODPC are subject to appeal before the High Court of Kenya
Before contacting the ODPC, we encourage you to first raise the matter with us at privacy@w3cb.org. We will respond within 21 days.
5.2 India — Digital Personal Data Protection Act 2023 (DPDP Act)
India's Digital Personal Data Protection Act 2023 (DPDP Act) received Presidential assent on 11 August 2023 and represents India's first comprehensive data protection legislation. It applies to the processing of digital personal data of individuals (called "Data Principals") within India, and to processing outside India if it involves offering goods or services to Data Principals in India. This simulator's Heatwave Protection scenario is contextualised within South Asian climate risk, bringing Indian participants within scope.
Data Principal Rights Under the DPDP Act 2023
- Right to Information About Processing (s.11): You have the right to obtain, upon request, a summary of personal data being processed by W3CB and the identities of all other data fiduciaries and data processors with whom it has been shared. We must respond within the period specified in the rules (anticipated to be 30 days under draft rules).
- Right to Correction and Erasure (s.12): You may request correction of inaccurate or misleading personal data, completion of incomplete data, and erasure of personal data that is no longer necessary for the purpose for which it was collected or for which consent was given.
- Right to Grievance Redressal (s.13): You may file a grievance with W3CB's designated Grievance Officer regarding any act or omission by W3CB in relation to the processing of your personal data. W3CB must acknowledge and resolve grievances within the period specified in applicable rules.
- Right to Nominate (s.14): You may nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or incapacity.
Consent and Notice Under the DPDP Act
Where W3CB relies on consent as the lawful basis for processing your personal data, that consent must be free, specific, informed, unconditional, and unambiguous (s.6). Before seeking consent, W3CB must provide a notice in clear and plain language explaining: (a) the personal data sought to be collected, (b) the purpose of processing, and (c) how you may exercise your rights and withdraw consent. Consent may be withdrawn at any time — withdrawal does not affect the lawfulness of prior processing.
Complaint Mechanism — India
The Data Protection Board of India is established under s.18 of the DPDP Act as the adjudicatory body. The complaint process operates as follows:
- Step 1 — Internal Grievance: File a complaint with W3CB's Grievance Officer at privacy@w3cb.org (subject line: "DPDP Act Grievance — India"). We will acknowledge within 72 hours and resolve within 30 days.
- Step 2 — Data Protection Board: If your grievance is not resolved satisfactorily, you may appeal to the Data Protection Board of India. The Board's digital complaints portal will be operational once implementing rules are notified by the Central Government.
- Step 3 — Appellate Tribunal: Appeals against Board orders lie before the Appellate Tribunal constituted under the DPDP Act, and further to the High Court on questions of law.
Note: The DPDP Act's implementing rules are pending notification as of the date of this policy. We will update this section as the regulatory framework is operationalised.
5.3 Thailand — Personal Data Protection Act B.E. 2562 (PDPA 2019)
Thailand's Personal Data Protection Act B.E. 2562 (2019) came into full effect on 1 June 2022. It applies to any organisation that collects, uses, or discloses personal data of individuals in Thailand, regardless of where the organisation is located. This simulator's Flood Protection scenario is contextualised within the Mekong region, bringing Thai participants within scope. SEADRIF, one of the real programs featured in the Education Center, operates across Thailand and neighbouring ASEAN nations.
Data Subject Rights Under the Thai PDPA
- Right to be Informed (s.23): You must be informed of the purpose of collection, the types of data collected, retention period, and the identity of the data controller before or at the time of collection.
- Right to Withdraw Consent (s.19 para. 3): Where processing is based on consent, you may withdraw at any time without penalty. Withdrawal does not affect the lawfulness of prior processing.
- Right of Access (s.30): You may request confirmation of whether W3CB processes your data and, if so, access to that data and information about the processing. We must respond within 30 days.
- Right to Data Portability (s.31): Where processing is by automated means based on consent or contract, you may request transmission of your data in a structured, machine-readable format to another controller, where technically feasible.
- Right to Objection (s.32): You may object to processing based on legitimate interests, public interest tasks, or direct marketing at any time. For direct marketing, we must cease processing immediately; for other bases, we conduct a balancing assessment.
- Right to Erasure (s.33): You may request deletion or anonymisation of personal data where it is no longer necessary for the purpose collected, where consent is withdrawn, or where processing is unlawful.
- Right to Restriction of Processing (s.34): You may request that we suspend processing (but not delete) during the period of any objection or accuracy dispute.
- Sensitive Personal Data (s.26): Processing of data related to race, ethnicity, political opinions, religious beliefs, sexual behaviour, criminal records, health data, disability, trade union membership, genetic data, or biometric data for identification purposes requires explicit consent unless a specific exemption applies. W3CB does not knowingly process such data.
Complaint Mechanism — Thailand
The Personal Data Protection Committee (PDPC) is the statutory supervisory authority under s.7 of the Thai PDPA. To lodge a complaint:
- Website: www.pdpc.or.th (Thai) / English version
- Email: pdpc@mdes.go.th
- The PDPC has authority to investigate complaints, impose corrective orders, and recommend administrative fines of up to THB 5,000,000 (approx. USD 140,000) per violation
- Criminal penalties apply for intentional unlawful disclosure of sensitive personal data
- Complaints to the PDPC should normally be preceded by an attempt to resolve the matter directly with the data controller
Contact us first at privacy@w3cb.org. We will respond within 30 days in accordance with PDPA obligations.
5.4 Vietnam — Personal Data Protection Decree (PDPD 2023)
Vietnam's Decree No. 13/2023/ND-CP on Personal Data Protection (PDPD) came into force on 1 July 2023. It is the first dedicated personal data protection instrument in Vietnam, replacing scattered provisions across sector-specific legislation. It applies to Vietnamese organisations and to foreign organisations that process personal data of Vietnamese citizens. This simulator contextualises scenarios within Southeast Asian climate risk and is used in Vietnamese training programs, bringing Vietnamese participants within scope.
Data Subject Rights Under Decree 13/2023
Chapter II of Decree 13/2023 establishes nine distinct rights for data subjects (called "Personal Data Subjects"):
- Right to Know (Art. 9.1): You have the right to know that your personal data is being processed, including the identity of the processor, the purpose, the scope of data processed, and the processing method.
- Right to Consent (Art. 9.2): Your consent is required for processing of personal data (both ordinary and sensitive data). Consent must be voluntary, informed, for a specific purpose, and documented. For sensitive data, explicit consent is required.
- Right of Access (Art. 9.3): You may access your personal data and verify the accuracy of information about you. W3CB must respond to access requests within 72 hours of receipt.
- Right to Withdrawal of Consent (Art. 9.4): You may withdraw consent to processing at any time. W3CB must stop processing within 72 hours of receiving a withdrawal notice, unless another lawful basis exists.
- Right to Deletion (Art. 9.5): You may request deletion of personal data. W3CB must process deletion requests within 72 hours, unless retention is required by law.
- Right to Restriction of Processing (Art. 9.6): You may request restriction of processing pending resolution of a dispute about processing legality or accuracy.
- Right to Data Portability (Art. 9.7): You may receive personal data you have provided to W3CB in a structured format and request its transfer to another controller, where technically feasible.
- Right to Object (Art. 9.8): You may object to processing of your personal data in cases that affect your legitimate rights and interests, unless processing is required by law.
- Right to Complain, Denounce, and File Lawsuits (Art. 9.9): You may file a complaint with the competent authority, denounce violations to law enforcement authorities, or commence civil litigation — see the complaint mechanism below.
Sensitive Personal Data Under Decree 13/2023
Article 9 and Chapter III of the Decree establish a category of "Sensitive Personal Data" requiring explicit consent and heightened protections. Categories include: political views and religious beliefs, health and medical history, financial data (income, assets, accounts, transactions), biometric data, sexual life data, criminal records, and location data. W3CB does not knowingly collect sensitive personal data of this nature from simulator users.
Data Breach Notification
In the event of a data breach affecting Vietnamese personal data, W3CB is obligated to notify the Ministry of Public Security (Department A86 — Cybersecurity) within 72 hours of becoming aware of the breach, and to notify affected data subjects without undue delay.
Complaint Mechanism — Vietnam
Complaints about personal data protection violations in Vietnam are handled through a multi-tier mechanism:
- Step 1 — Controller: File a complaint with W3CB at privacy@w3cb.org (subject line: "PDPD Complaint — Vietnam"). We must acknowledge within 24 hours and respond substantively within 72 hours per Decree 13/2023 timeframes.
- Step 2 — Ministry of Public Security: You may submit a complaint to the Department of Cybersecurity and Hi-Tech Crime Prevention (A86), Ministry of Public Security, which is the primary regulatory authority for Decree 13/2023 enforcement. Address: 44 Pham Ngoc Thach, Dong Da, Hanoi, Vietnam. Website: www.bocongan.gov.vn
- Step 3 — People's Court: You may pursue civil claims before the competent People's Court (district or provincial level depending on the nature of harm) under general civil liability provisions of the Civil Code 2015.
- Step 4 — Denunciation: Where you believe a criminal violation has occurred (e.g., unauthorised sale or disclosure of personal data), you may submit a criminal denunciation to the Investigation Police Agency.
5.5 Caribbean — Regional and National Frameworks
Several Caribbean nations relevant to our Hurricane Coverage scenario have enacted dedicated data protection legislation. CCRIF SPC, featured prominently in this simulator, operates across 16 Caribbean nations, making jurisdictional compliance particularly relevant.
- Jamaica — Data Protection Act 2020: Grants rights of access, correction, deletion, and objection. Complaint mechanism: the Office of the Information Commissioner (OIC) — oic.gov.jm. Controllers must respond to access requests within 30 days.
- Trinidad and Tobago — Data Protection Act (Chap. 22:03): Establishes the right to access, correct, and complain about data held by data controllers. The supervisory authority is the Office of the Privacy Commissioner — privacy.gov.tt.
- Barbados — Data Protection Act 2019: Broadly aligned with GDPR principles; administered by the Data Protection Commissioner. Rights include access, correction, erasure, and portability.
- CARICOM Model Legislation: Other CARICOM member states are at various stages of enacting data protection legislation consistent with the CARICOM model law framework (based broadly on OECD Privacy Principles). Where a specific national law does not yet exist, we apply GDPR-equivalent standards as the baseline.
5.6 United States — Sectoral and State Approach
The United States does not have a comprehensive federal privacy law equivalent to GDPR or the Kenya DPA. Applicable frameworks include:
- California CCPA/CPRA: California residents have the right to know what personal data is collected, the right to delete, the right to opt out of sale, and the right to non-discrimination for exercising rights. Contact us at privacy@w3cb.org to exercise any CCPA right. We do not sell personal data.
- State Privacy Laws: Colorado, Virginia, Connecticut, and other states have enacted GDPR-inspired privacy laws. We endeavour to honour data subject rights requests from residents of any US state on terms equivalent to the most protective applicable state law.
- Contact privacy@w3cb.org for any request — we do not require state residency proof to consider data subject requests in good faith.
6. International Data Transfers
Where personal data is transferred outside the jurisdiction in which it was collected, we rely on appropriate safeguards. For transfers from the EU/UK, this means Standard Contractual Clauses (SCCs) approved by the European Commission or UK International Data Transfer Agreements (IDTAs). For transfers from Kenya, we comply with s.49 of the DPA 2019 (adequacy determination or appropriate safeguards). For transfers from Vietnam, we comply with Chapter IV of Decree 13/2023 including notification requirements. We do not transfer personal data to jurisdictions without adequate data protection standards without appropriate safeguards in place.
7. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required by applicable law. Specifically:
- Contact and correspondence data: retained for up to 3 years after last contact, or as required by applicable law
- Automated analytics data (aggregated): retained for up to 2 years for trend analysis
- On-device localStorage data: persists until you clear your browser's site data or the application removes it on update — W3CB has no server-side copy
When data is no longer required, it is securely deleted or anonymised such that it can no longer be attributed to any individual.
8. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. The majority of this application's user-specific data is stored on your own device via localStorage and is never transmitted to our servers, inherently limiting our data exposure. For server-side data, we apply encryption in transit (TLS 1.2 or higher) and at rest, access controls, and regular security reviews.
In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the applicable supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Art. 33, Vietnam Decree 13/2023, and equivalent provisions) and will notify you without undue delay where the breach is likely to result in high risk to you.
9. Third-Party Services
Our application may contain links to third-party websites or services (such as UNDRR, CCRIF, or World Bank resources referenced in the Education Center). We are not responsible for the privacy practices of these external sites. We recommend reviewing their privacy policies before providing any personal data to them.
This application does not embed third-party tracking scripts, advertising networks, social media pixels, or analytics services that transmit personal data to third parties without your knowledge.
10. Children's Privacy
Our simulator is designed for adult policymakers, government officials, NGO staff, and climate negotiators. It is not intended for children under 16 years of age (or the applicable minimum age in your jurisdiction — 13 in the United States, 16 in the EU, 18 for certain Indian purposes). We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child below the applicable age, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in applicable law or our practices. We will post the updated policy on this page and revise the "Last Updated" date. For material changes — particularly those affecting data subject rights or our lawful basis for processing — we will provide a more prominent notice. We encourage you to review this policy periodically.
12. Contact Information and Supervisory Authorities
For questions about this Privacy Policy, to exercise your rights, or to make a complaint:
Web3 Certification Board Inc. (W3CB)
Privacy enquiries: privacy@w3cb.org
Subject line guidance: Include your jurisdiction (e.g., "GDPR Request," "Kenya DPA Request," "DPDP Act Grievance — India," "PDPA Request — Thailand," "PDPD Complaint — Vietnam") to ensure routing to the appropriate compliance contact.
Supervisory Authority Directory
You also have the right to lodge a complaint directly with your relevant supervisory authority. Key authorities include:
- EU: Your national Data Protection Authority — directory at edpb.europa.eu
- UK: Information Commissioner's Office (ICO) — ico.org.uk
- Kenya: Office of the Data Protection Commissioner (ODPC) — odpc.go.ke
- India: Data Protection Board of India (operational upon rules notification) — Ministry of Electronics and IT: meity.gov.in
- Thailand: Personal Data Protection Committee (PDPC) — pdpc.or.th
- Vietnam: Department A86 (Cybersecurity), Ministry of Public Security — bocongan.gov.vn
- Jamaica: Office of the Information Commissioner — oic.gov.jm
- Trinidad and Tobago: Office of the Privacy Commissioner — privacy.gov.tt
- California (US): California Privacy Protection Agency (CPPA) — cppa.ca.gov