Blueperch

Privacy policy

Blueperch Privacy Notice

Date updated: 2026-08-20

1. Who we are and how to contact us

2. The personal information we collect

Specifically, we may hold: name; e-mail address; physical address; mailing address; place of business; details of grantseekers’ and grantees’ projects; and employment-related details of prospective employees, board members, etc.

We do not routinely collect special category data (information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health, sex life or sexual orientation) or criminal offence data. Where we do, we rely on a lawful basis and a separate condition for processing, and we will tell you at the point of collection.

3. Where we get your information

Directly from you — when you fill out an expression-of-interest form, apply for a grant, subscribe to our newsletter, work with us, or otherwise contact us.

From others — we receive personal information indirectly from:

Where we obtain your information from a third party, we will provide you with this notice within a reasonable period and no later than one month after obtaining it, or at the point of our first communication with you if that is sooner. We check that the third party obtained the data lawfully and on a basis that covers our intended use. You can ask us at any time which specific source your information came from.

4. Why we use your information, and our lawful basis

Purpose Lawful basis
Evaluating and awarding grants to prospective grantseekers Legitimate interests — assessing applications we have been asked to consider
Collecting and holding expressions of interest from people who may want to work for us or join our board, including holding them on file to contact about future roles Legitimate interests — identifying and building a pool of candidates for current and future staff and board vacancies. If we keep your details on file beyond the role you enquired about, we will tell you and you can ask us to remove them at any time
Being transparent about the projects we have funded (subject to the restrictions below) Legitimate interests — public accountability for charitable funds
Reviewing our grantmaking to maximise impact, and sharing high-level findings with others in the Effective Altruism and animal advocacy communities Legitimate interests — improving grantmaking practice
Sending newsletters, updates and notifications to subscribers Consent
Answering queries submitted through our contact form or via email Legitimate interests — responding to your request
Keeping contact details for clients, vendors and others vital to our operations Legitimate interests — running the organization
Employment and HR records Contract, legal obligation, and legitimate interests
Meeting accounting, regulatory and other statutory duties Legal obligation
Website analytics Legitimate interests — essential website function

Where we rely on consent, you can withdraw it at any time by contacting contact [at] blueperch [dot] org or using the unsubscribe link in any e-mail. Withdrawing consent does not affect processing carried out before you withdrew it.

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your interests, rights and freedoms. You can ask us for details of that assessment, and you can object (see section 8).

We do not make decisions about you by solely automated means, and we do not use your personal information for profiling.

Do you have to give us your information?

You are not under any statutory or contractual obligation to give us your personal information, and we do not require it in order to enter into a contract with you. But some information is necessary for us to do what you have asked:

5. Who we share it with

We only share personal information with a third party where they need it for the service they provide to us, the sharing is consistent with this notice, and the third party has agreed to appropriate security standards. Where a provider processes personal information on our behalf, we put in place a written contract containing the terms required by Article 28 of the UK GDPR.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising or targeted advertising.

Forms are built and hosted by Fillout (Fillout, Inc., United States). Submissions are transmitted to Fillout’s servers and then piped into Airtable (Airtable / Formagrid, Inc., United States), where we store and review them. Both companies act as data processors on our behalf and use their own sub-processors for hosting and infrastructure. Fillout runs on Amazon Web Services (via Render.com), with data encrypted in transit over HTTPS/TLS and encrypted at rest. Airtable’s infrastructure is primarily US-based; its sub-processors are published at airtable.com/company/subprocessors. This data is processed in the United States. Where EU/UK data protection law applies, transfers rely on Standard Contractual Clauses (and, for Airtable, participation in the EU–US Data Privacy Framework).

You can request access to, correction of, a copy of, or deletion of your submission at any time by emailing the address listed in this privacy policy. Fillout deletes form responses and user data from its servers and backups within 45 days of a deletion request; note that a copy in Airtable must be deleted separately, which we will do as part of any request.

Email newsletter

If you subscribe to our email newsletter, we collect your email address (and any optional name you provide). Sign-ups are confirmed by double opt-in: you’ll receive a confirmation email and won’t be added to the list until you click the link in it.

We use Buttondown (Buttondown LLC, United States) as our email service provider. Your email address is stored on Buttondown’s servers and processed by them on my behalf as a data processor, along with their sub-processors (including hosting, email delivery, and error-monitoring providers). Data is processed in the United States; where EU/UK/Swiss data protection law applies, transfers rely on Standard Contractual Clauses. See Buttondown’s privacy policy, sub-processor list, and GDPR page.

Your email address is used only to send you the newsletter — new posts from this website containing general information about Blueperch, grants, updates about animal advocacy, etc — delivered automatically from this website’s RSS feed. Your email address is never sold or shared with advertisers.

Every email includes an unsubscribe link, and unsubscribing takes effect immediately. You can also request a copy of your data or its deletion at any time by contacting the email address listed in this privacy or contacting Buttondown support directly.

6. International transfers

Some of our service providers are based outside the UK and the EEA.

You can ask us for a copy of the safeguards in place.

7. How long we keep it, and how we protect it

Your information is held in the cloud software we use to evaluate grants (Airtable), similar databases, and Buttondown (our newsletter software).

Data Retention
Unsuccessful grant applications 2 years from decision, then aggregated as an anonymized report then deleted
Successful grant applications and grantee records 2 years from the end of the grant period, then aggregated as an anonymized report then deleted
Personal information we receive from referees, other funders, and public sources 2 years from decision or the end of the grant period (whichever is later), then aggregated as an anonymized report and deleted
Expressions of interest from prospective grantees 2 years, then deleted
Expressions of interest from prospective employees or board members 2 years, then deleted
Questions sent via email or contact form 2 years, then deleted
Newsletter subscriber data Until you unsubscribe, then suppression-only records to honour your preference
Employee records 6 years after employment ends
Website analytics Aggregated and non-identifying; underlying records deleted after 14 months

When information is no longer needed for the purpose it was collected for, we delete or anonymise it, and require our providers to do the same.

We apply technical and organisational measures appropriate to our size and the risks involved, including access controls on a need-to-know basis, encryption and pseudonymisation where applicable, supplier due diligence, staff training, and periodic review of our systems. We assess privacy by design when building new processes, and carry out a Data Protection Impact Assessment before high-risk processing. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours where required, and we will tell you directly where the risk to you is high.

8. Your data protection rights

Under data protection law you have the right to:

  1. Be informed about how we collect and use your information — that is what this notice is for.
  2. Access — ask for copies of the personal information we hold about you.
  3. Rectification — ask us to correct information you think is inaccurate, or complete information you think is incomplete.
  4. Erasure — ask us to delete your personal information in certain circumstances.
  5. Restriction of processing — ask us to limit how we use your information in certain circumstances.
  6. Object — object to processing based on our legitimate interests. You have an absolute right to object to direct marketing, which we will always honour.
  7. Data portability — ask us to transfer information you gave us to you or another organization, in a structured, commonly used, machine-readable format, in certain circumstances.
  8. Withdraw consent at any time, where consent is our basis for processing.
  9. Not be subject to solely automated decision-making that produces legal or similarly significant effects.
  10. Complain — to us (see section 10) and to a supervisory authority.

To make a request, e-mail contact [at] blueperch [dot] org. There is normally no charge. We will respond without undue delay and within one month of receiving your request; if your request is complex, or you have made several, we may extend this by up to two further months and will tell you within the first month if so. We may ask for information to confirm your identity, and the time limit does not start until we have it.

9. Grant transparency

We publish information about the projects we fund. Before publishing, we will discuss with you what will appear. If you have concerns about being identified, indicate this in the application form or tell us at contact [at] blueperch [dot] org and we will discuss options, including anonymised or aggregated publication.

10. How to complain

Complain to us first. If you think we have not handled your personal information in line with data protection law, you have the right to complain directly to us. You can do this by e-mail to contact [at] blueperch [dot] org, with “Data protection complaint” in the subject line.

You do not have to use these routes or label your complaint in any particular way — we will treat any complaint about our handling of personal information as a data protection complaint however it reaches us. We will acknowledge your complaint within 30 days of receiving it, take appropriate steps to investigate and respond, and tell you the outcome.

If you are still unhappy, or in the UK: you can complain to the Information Commissioner’s Office: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 Website: https://www.ico.org.uk

If you are in the EU or EEA: you can complain to the data protection authority in your country of residence, work, or where the alleged infringement took place, or take the matter to the courts of that Member State. A list of national authorities is available from the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en

11. If you are in the United States

Blueperch is a fiscally sponsored project of Anti Entropy, a not-for-profit organization. Most US state privacy laws, including the California Consumer Privacy Act, apply only to entities operated for the profit or financial benefit of their owners, and so do not apply to us. A small number of states — including Colorado, Delaware, New Jersey, Oregon, Maryland and Minnesota — do not exempt non-profits, but their laws apply only above processing thresholds (typically 35,000–100,000 state residents a year) that our activities do not reach.

Regardless of whether those laws apply to us, we do not sell personal information or share it for targeted advertising, and we will honour requests from US residents to access, correct or delete their personal information on the same basis as set out in section 8. We will not discriminate against you for exercising these rights. E-mail contact [at] blueperch [dot] org.

12. Cookies, Logs and Analytics

1. Hosting and server logs

This website is a static site hosted on Cloudflare Pages, a service provided by Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA. Cloudflare also serves as our content delivery network (CDN) and provides network security for the site.

When you visit this website, your request is routed through Cloudflare’s global network. As a technically necessary part of delivering the page to you, Cloudflare processes and logs data including:

Cloudflare refers to this collectively as “Log Data” and processes it as our data processor, on our instructions and on our behalf. Cloudflare does not use this data to build cross-site profiles of you.

Purpose and legal basis: we rely on our legitimate interests (Art. 6(1)(f) UK GDPR / EU GDPR) in delivering this website reliably, maintaining its security and integrity, defending against denial-of-service attacks and other abuse, and diagnosing technical faults. We do not use server logs for marketing or profiling.

International transfers: Cloudflare operates a global network and may process this data outside the UK/EEA, including in the United States. These transfers are covered by the Standard Contractual Clauses and Cloudflare’s supplementary measures, as set out in Cloudflare’s Data Processing Addendum.

Retention: log data is retained by Cloudflare for a short period for operational and security purposes and is then deleted. We do not download, export or separately store raw server logs.

Cloudflare’s privacy policy is available at https://www.cloudflare.com/privacypolicy/.

2. Cookies set by our security and network infrastructure

We do not set any cookies of our own, and we do not use advertising, marketing or cross-site tracking cookies.

Cloudflare may set a small number of strictly necessary cookies on your device where the corresponding security feature is active on this site. These cookies exist to protect the site from automated abuse and to keep it available; they do not contain a user ID, are not linked to any account, and are not used to track you across other websites. A separate value is generated for each site you visit.

Legal basis: these cookies are strictly necessary for the provision of the service you have requested, and are therefore exempt from the consent requirement under Regulation 6(4) of the Privacy and Electronic Communications Regulations 2003 / Article 5(3) of the ePrivacy Directive. Because they are strictly necessary, we do not display a consent banner for them. Blocking these cookies in your browser may prevent you from accessing the site.

A current list of the cookies Cloudflare may set is published at https://developers.cloudflare.com/fundamentals/reference/policies-compliances/cloudflare-cookies/.

3. Website analytics

We use Cloudflare Web Analytics (also referred to as Real User Monitoring, or RUM) to understand how many people visit this site and how quickly pages load. A small JavaScript file is loaded from static.cloudflareinsights.com when you open a page.

This tool is designed to work without identifying you:

It collects only page-performance information, which is held in memory for the duration of the page view and then discarded. This includes a randomly generated identifier for the individual page load, the address of the page you are viewing, the referring page address if your browser sends one, and timing measurements such as time to first byte, first contentful paint, largest contentful paint, cumulative layout shift and interaction to next paint. Cloudflare receives your IP address as an unavoidable part of the network request, but discards it at the receiving data centre and does not store it.

Purpose and legal basis: we rely on our legitimate interests (Art. 6(1)(f)) in measuring aggregate audience numbers and monitoring the technical performance of the site. As no information is stored on or read from your device, this measurement does not require consent under Regulation 6 PECR / Article 5(3) ePrivacy Directive.

Further detail is published at https://developers.cloudflare.com/speed/observatory/rum-beacon/.

4. What we do not do

We do not use Google Analytics or any comparable third-party analytics product; we do not embed advertising or social media tracking pixels; we do not use third-party comment systems; and we do not sell or share personal information for cross-context behavioural advertising as those terms are defined under the California Consumer Privacy Act.

13. Children

Our services are not directed at children, and we do not knowingly collect personal information from anyone under 18. If you believe we hold information about a child, contact us at contact [at] blueperch [dot] org and we will delete it.

14. Changes to this notice

We review this notice periodically and will post any updates on this page with a revised “date updated”. Where changes are significant, we will tell affected individuals directly. This notice does not override national data protection laws in countries where we operate.