How we handle personal data.
LEAD Conservation works with personal data about the people who keep wild places safe — rangers, instructors and the teams that manage them. This notice explains what we hold, why, who can see it, and the rights you and your organisation have over it. We keep it in plain language on purpose.
- Who is responsible
- LEAD Conservation Foundation (stichting), the Netherlands
- Data protection contact
- privacy@leadconservation.org
- Where data is hosted
- Within the European Economic Area
- We never
- Sell your data, or share identifiable personnel data with funders
- Your rights
- Access, correct, delete, export, object — any time
- Supervisory authority
- Autoriteit Persoonsgegevens (NL)
Last updated: July 2026 · Applies to leadconservation.org and the myLEAD platform.
On this page
Who we are
LEAD Conservation Foundation is a not-for-profit foundation (stichting) registered in the Netherlands, based at Plataanlaan 19, 6708 PT Wageningen. We set and support a professional standard for conservation security, and we run the myLEAD platform through which partner organisations manage their people's training, certification and development.
For any question about your personal data, or to exercise any of the rights below, contact our data protection lead at privacy@leadconservation.org.
The two roles we play
Data protection law distinguishes between the organisation that decides why data is processed (the controller) and the one that processes it on the controller's behalf (the processor). Which role we hold depends on the data.
your personnel's data in myLEAD
When a partner organisation puts data about its rangers and staff into myLEAD, that organisation is the controller — it owns the data. We process it only on their instructions, under a Data Processing Agreement.
our own contacts and website
For people who contact us, subscribe, donate, or browse our website, LEAD is the controller and decides how that limited data is used.
If you are a ranger or staff member whose data sits in myLEAD, your employer or organisation is the first point of contact for your data. We support them in answering you, and you can always reach us directly too.
What data we hold
In myLEAD (on behalf of partner organisations)
Identity and contact details — name, role, organisation, contact information;
Engagement status and unit or post;
Training and certification records, qualifications and course history;
Assessment outcomes, competency stage and eligibility status;
Development-pathway and course-place allocations;
Account and audit metadata — who changed a record, and when.
The platform is not designed to hold special categories of data (such as health or biometric data), and organisations are asked not to enter such data except where specifically agreed.
On our website and in our work as controller
Contact details you give us when you email, enquire, partner or donate;
Basic, privacy-respecting analytics about how the website is used.
Why we process it, and our lawful basis
We process personnel data to deliver the myLEAD services on the controller's behalf: to register people, allocate and track development pathways and course places, record assessments and certifications, coordinate training, and report on programme outcomes in aggregated, anonymised form that does not identify individuals.
Depending on the context, our lawful bases under the GDPR are the performance of a contract, our (or the controller's) legitimate interests in running a professional certification programme, compliance with a legal obligation, and — where required — consent. Where we rely on legitimate interests, we balance them against your rights and freedoms.
Who can see it
Access is tightly limited:
Your own organisation sees only its own people. One partner can never see another's personnel.
LEAD staff see what they need to run the programme and support you, on a least-privilege basis.
Sub-processors — carefully selected service providers (such as our hosting and platform partner) — process data only under written contracts with the same protections set out here.
We do not sell personal data, and we do not share identifiable personnel data with funders, donors or other third parties. Funder and public reporting uses aggregated, anonymised figures only.
International transfers
Personal data in myLEAD is hosted within the European Economic Area (EEA). Because our partners operate across Africa, Asia and beyond, the data may be accessed by authorised users from outside the EEA. Where that happens, or where a service provider sits outside the EEA, we rely on an adequacy decision or on appropriate safeguards under the GDPR — such as the European Commission's Standard Contractual Clauses — to keep the protection with the data wherever it travels.
How long we keep it
We keep personnel data for as long as the partner organisation uses the services, and as long as needed to maintain a meaningful record of training and certification. When a partnership ends, we return or securely delete the organisation's data at their choice, keeping only what the law requires us to retain. Contact, donation and financial records are kept only as long as needed for their purpose or a legal obligation.
Little Guide feedback is anonymised one year after submission: we remove the email address, free-text feedback and technical visitor data, while retaining only the guide, rating, language and submission date for aggregated analysis. Metadata for successfully delivered emails is deleted after one year. LEAD’s own consent and optional visitor cookies expire after one year.
How we protect it
We hold personal data under appropriate technical and organisational measures, including encryption in transit and at rest, role-based access control, an audit trail that records who changed each record and when, regular backups, staff confidentiality undertakings, and a defined breach-response process. Our systems are built to the controls of recognised security standards (ISO/IEC 27001 and ISO/IEC 27701 / GDPR), hosted on certified infrastructure, with formal certification on our roadmap.
Partner organisations can review the full terms on which we process their people’s data in our Data Processing Agreement, which sets out our security measures and sub-processors in detail.
Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent where we rely on it. To exercise any of these, contact your organisation (for data held in myLEAD) or us directly at privacy@leadconservation.org. We respond without undue delay and within the timeframes the law sets.
Questions & complaints
We would always rather hear from you first, so please contact us with any concern about how we handle your data. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority in your own country. We may update this notice as our services and the law evolve. The date at the top shows when it was last revised.
Partnering with LEAD?
Your people's data stays yours. Read exactly how we hold and protect it, or talk to us.