This Data Protection notice supplements our Privacy Policy and goes deeper into the security, retention and rights practices we apply to personal information collected through fedop.com and during FedOP professional engagements. It is written to align with the EU General Data Protection Regulation (Regulation (EU) 2016/679 — “GDPR”), the UK GDPR and Data Protection Act 2018, the EU–US Data Privacy Framework, ISO/IEC 27001:2022 and other major regional frameworks to the extent they apply.
1. Who this notice is for
This notice applies to every individual whose personal information we process, including Site visitors, intake-form respondents, applicants for funding programmes, clients of our professional services, named consultants on engagements, and authorised contacts at partner organisations.
2. Roles under data-protection law
For the purposes of data-protection law, FedOP Grant Services acts as the controller for personal information you submit through the Site (intake forms, contact requests, chat messages and similar) and as a processor for personal information you share with us as part of an engagement letter (where the engagement letter specifies a controller–client relationship). Our licensed partners may act as joint controllers for information they receive directly under their own privacy terms.
Where FedOP processes personal data on behalf of a partner or other controller, we do so under a written data-processing agreement that defines the subject matter, duration, nature and purpose of the processing, the type of personal data, the categories of data subjects and our obligations as processor.
3. What counts as personal information
“Personal information” means anything that identifies you, directly or indirectly. That includes obvious things — your name, email, phone, government ID — and less-obvious things — your IP address, device identifiers, the funding programmes you've viewed, the documents you upload, the consultants you've messaged. Special categories of data (race, religion, health, sexual orientation, criminal record) are processed only where you provide them voluntarily as part of an application that requires them.
4. Lawful bases for processing
We process personal information on the following legal bases:
- Consent — for marketing updates, optional analytics cookies and any optional survey responses. You can withdraw consent at any time without affecting earlier processing.
- Contract — to perform the services described in your engagement letter, including identification, application preparation, submission and post-decision support.
- Legitimate interest — to operate, secure and improve the Site, to respond to enquiries that are not yet engagements, and to assert or defend legal claims. We always balance our legitimate interest against your rights and freedoms.
- Legal obligation — to keep records that we are required to retain by tax, audit, licensing or anti-money-laundering law, and to respond to lawful requests from competent authorities.
5. How we store and secure data
We use industry-standard safeguards designed to protect personal information against unauthorised or unlawful processing, accidental loss, destruction or damage. Our security stack includes:
- Encryption in transit — all web traffic uses HTTPS/TLS 1.2 or higher; email and chat use TLS-encrypted channels; document upload uses end-to-end encrypted file transfer.
- Encryption at rest — document vaults and database storage are encrypted at the storage layer using AES-256 or equivalent; encryption keys are managed in a dedicated key management service with rotated access credentials.
- Access controls — least-privilege access, named consultants only; production data access requires two-factor authentication and is logged at the request level.
- Audit trails — significant access and changes to client records are logged with timestamped, append-only audit trails retained for 12 months.
- Vendor due diligence — third-party processors are reviewed for security posture (SOC 2 / ISO 27001 where available) and bound by written data-processing agreements that limit purpose, duration and onward use.
- Backup and resilience — encrypted daily backups stored in a separate region, with quarterly restore tests and a documented disaster-recovery runbook.
- Incident response — a documented process to investigate, contain, eradicate and recover from any personal-data breach, with supervisory-authority notification within 72 hours of awareness where GDPR Article 33 applies.
- Vendor and staff screening — staff and named consultants are subject to background checks and confidentiality undertakings before any production-data access is granted.
No online system can guarantee absolute security. We continually assess our controls against evolving threats and the requirements of ISO/IEC 27001:2022.
6. Where data is stored
Personal information is stored with reputable cloud providers in jurisdictions that offer adequate protection under applicable data- protection law. Where data is transferred across borders, we rely on appropriate safeguards: typically the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Agreement (IDTA), the EU–US Data Privacy Framework, or equivalent regional arrangements. On request we will provide a copy of the relevant safeguard that applies to your data.
7. Retention
We retain personal information for as long as necessary for the purposes described in our Privacy Policy, plus any period required by law. Practical defaults are:
- Site enquiries that don't convert — up to 24 months from the last interaction, then deleted or anonymised.
- Engagement records — invoices, scope letters, signed deliverables and consultant notes — 7 years after engagement closure, to satisfy tax, audit and licensed-partner reporting obligations.
- Applicant documents in the client portal — engagement lifetime plus 12 months, then permanently deleted from primary storage and backups within 90 days.
- Marketing subscription records — until you unsubscribe, plus 12 months of records (proof of consent and unsubscribe).
- Backups and audit logs — up to 12 months for audit logs, up to 90 days for backup snapshots.
- Special-category data — only retained as long as strictly necessary for the engagement that required it; deleted within 30 days of engagement closure unless you request otherwise.
On expiry of the retention period, records are securely deleted or anonymised so they can no longer identify you, except where we are required to keep them longer by law.
8. Your rights
You have the following rights in relation to your personal information. Many of these rights are subject to specific conditions under applicable law.
- Access — request a copy of the personal information we hold about you (GDPR Art. 15).
- Rectification — ask us to correct anything that is wrong or incomplete (GDPR Art. 16).
- Erasure — ask us to delete your personal information, subject to our legal-record obligations (GDPR Art. 17).
- Restriction — ask us to suspend processing while we investigate a concern (GDPR Art. 18).
- Portability — receive a machine-readable copy of information you provided, where the legal basis is consent or contract (GDPR Art. 20).
- Objection — object to processing based on legitimate interest, including direct marketing (GDPR Art. 21).
- Withdraw consent — where processing is based on consent, you can withdraw it at any time, without affecting earlier processing.
- Lodge a complaint — with the data-protection authority in your jurisdiction (GDPR Art. 77).
- Automated decisions — not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you (GDPR Art. 22).
To exercise any of these rights, email us at privacy@fedop.com. We acknowledge within 5 business days and respond substantively within 30 days. If your request is complex we may extend this to 60 days, but we will let you know if that applies and explain why.
9. Automated decision-making
We do not use your personal information to make automated decisions that produce legal or similarly significant effects on you. Where we use AI-assisted tools to draft or summarise content, a human consultant always reviews and signs off before anything is sent to a funder or shared with you as a deliverable. A human remains accountable for every decision that affects you.
10. Children's data
The Site is not directed to children under 18 (or the age of digital consent in your jurisdiction) and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact us at privacy@fedop.com and we will delete the information without delay.
11. International data transfers
Where personal information is transferred from your country to another jurisdiction — for example, to a cloud region or to one of our licensed partners — we rely on appropriate safeguards: the European Commission's Standard Contractual Clauses (SCCs, 2021/914), the UK International Data Transfer Agreement (IDTA), the EU–US Data Privacy Framework, or equivalent regional instruments. On request we will provide a copy of the relevant safeguard.
12. Breach notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours of becoming aware of it (where required by GDPR Article 33 or applicable national law) and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights (GDPR Article 34).
13. Data Protection Officer
FedOP has appointed a Data Protection Officer who oversees our compliance with this notice and with applicable data-protection law. You can contact the DPO at privacy@fedop.com with any question, complaint or request. If we can't resolve a concern between us, you have the right to lodge a complaint with the supervisory authority in your jurisdiction. For the EU/UK, the lead authority is the data-protection authority in the country where the licensed partner handling your data is registered; we can point you to the right authority on request.
14. Changes to this notice
We may update this Data Protection notice from time to time to reflect changes in our practices, the law or our service offering. The “Last updated” date at the top of this page indicates when the latest revision took effect. Material changes will be announced on the Site and, where appropriate, by email.
15. Contact
Questions about this notice — or any data-protection request — email:
- General privacy email — privacy@fedop.com
- General contact — hello@fedop.com
- Data Protection Officer — privacy@fedop.com
Questions about this policy? Reach our compliance team at hello@fedop.com. We respond within two business days.
