Privacy Policy and Research Data Handling
EK Strategic Communications Center (“EK Strategies”, “EK”, “we”, “us” or “our”) respects the privacy of people who visit our website, contact us, work with us, or may be referred to in our research. This Policy explains what personal data we process, where it comes from, why we use it, how long we retain it, and what rights may be available to you. It also explains the additional safeguards we apply when personal data is used in public-interest research, disinformation monitoring, FIMI analysis, and related publications.
1. Who We Are and Who Controls Your Data
The controller responsible for the processing described in this Policy is:
Mittetulundusühing NATIONAL RESILIENCE CENTRE Non-profit association registered in Estonia, registry code 80650278 Poordi tn 3-60, 10156 Tallinn, Harju maakond Estonia Email: privacy@ekstrategies.org
No data protection officer or local representative is currently required to be appointed. Privacy matters are handled by the organisation’s management and can be raised through the contact details in this Policy.
“EK Strategic Communications Center” and “EK Strategies” are the names used on this website by the organisation identified above.
2. Scope of This Policy
This Policy applies to personal data processed in connection with:
visits to ekstrategies.org;
email and other direct communications with EK;
professional, media, partnership and project enquiries;
website security and audience measurement;
EK’s research, monitoring, analysis and publication activities.
It does not automatically govern independent third-party websites, platforms or services linked from our website. Those organisations process personal data under their own privacy notices.
3. Personal Data We Collect
Data you provide directly
When you contact EK, we may receive:
your name;
email address and other contact details;
organisation, role or professional affiliation;
the contents of your message;
attachments and any other information you choose to provide.
Please do not send sensitive personal data unless it is necessary and you have an appropriate and secure way to provide it.
Website and technical data
When you use our website, our systems or service providers may process:
IP address;
browser and device information;
operating system;
referring page;
pages viewed and interactions with the website;
date, time and approximate location derived from technical information;
cookie or similar identifiers;
security and diagnostic logs.
Some of this information is necessary for website delivery and security. Analytics data is handled as described in the Cookies and Analytics section.
Research and public-source data
EK analyses information relevant to disinformation, foreign information manipulation and interference, strategic communications, political developments, security and democratic resilience.
Depending on the project, research data may include:
names, public roles and professional affiliations;
publicly visible usernames, account identifiers and channel names;
public statements, posts, publications, images and videos;
links between publicly documented individuals, organisations, media outlets or online accounts;
geographic and temporal information relevant to a publication;
information contained in official records, public databases, archives, media reports and research supplied by partners;
records needed to verify the origin, context and authenticity of source material.
Research into political narratives and influence operations can involve two kinds of information that data protection law treats differently, and we keep them apart.
Special category data (Article 9 GDPR). Political opinions, and occasionally religious or philosophical beliefs, ethnic origin or trade union membership, can be apparent from a person’s own public statements, public role or public affiliations. We process such information only where it is necessary and proportionate for reporting or research in the public interest, on the freedom-of-expression and research grounds set out below.
Data relating to criminal convictions and offences (Article 10 GDPR). This is not a special category under Article 9; it is governed by a separate and stricter rule, and we do not rely on legitimate interests for it. We keep no register of criminal convictions and we do not collect criminal-record data as a matter of routine. Most of the conduct we document — coordinated inauthentic behaviour, undisclosed affiliation, propaganda and information manipulation — is not a criminal offence, and we do not present it as one. Where a publication refers to criminal proceedings, an official investigation, a prosecution or an allegation of criminal conduct, we rely on the Estonian law giving effect to Article 85 of the GDPR: § 4 of the Personal Data Protection Act (Isikuandmete kaitse seadus), which allows personal data to be processed without the data subject’s consent for journalistic purposes, in particular disclosure in the media, where there is a public interest and the processing accords with the principles of journalism ethics, and § 5, which covers academic, artistic and literary expression. Both require that disclosure does not cause excessive damage to the rights of the person concerned, and we treat that as a condition met before publication, not afterwards. In each such case we verify the factual allegations, keep an allegation, an official finding and our own analytical assessment distinct from one another, and record why identifying the person is necessary and proportionate, as set out in Section 6.
4. How and Why We Use Personal Data
Where applicable privacy law requires a legal basis, EK relies on the basis appropriate to the particular activity.
Purpose | Typical data | Basis where applicable |
|---|---|---|
Operating and securing the website | IP address, device and security logs | Legitimate interests in providing and protecting the website; legal obligations where applicable |
Responding to enquiries | Contact details and correspondence | Steps taken at your request; legitimate interests in managing communications |
Measuring website use | Cookie identifiers and usage data | Consent |
Conducting research and analysis | Public-source and partner-supplied research data | Legitimate interests, public-interest research or freedom-of-expression grounds, depending on the activity and applicable law |
Publishing reports | Verified information relevant to the publication | Public-interest and freedom-of-expression grounds under Article 85 of the GDPR, as given effect by §§ 4–5 of the Estonian Personal Data Protection Act, subject to necessity, proportionality and applicable law |
Protecting legal rights | Correspondence, evidence and logs | Legal obligations, legitimate interests and the establishment or defence of legal claims |
EK does not rely on a research or journalistic exemption automatically. We assess the appropriate basis and any national-law exceptions for each project and jurisdiction.
We do not use legitimate interests as a basis for information relating to criminal convictions and offences. For that information we rely only on the journalistic and academic-expression provisions of Estonian law described in Section 3, or on the establishment, exercise or defence of legal claims.
5. Research and Public-Source Data
EK may obtain personal data from sources other than the individual concerned, including:
publicly accessible websites;
social media and messaging platforms, including public Telegram channels;
public statements and publications;
official records and public databases;
media reports and academic research;
archives and web archives;
research partners, contractors and collaborating organisations.
The fact that information is publicly accessible does not mean that it may be used without limits. Before using or publishing identifying information, EK considers its relevance, reliability, context, public-interest value and the potential impact on the people concerned.
Where direct notice to every person would be impossible or involve disproportionate effort, EK may provide transparency through this Policy and other appropriate measures, but only where permitted by applicable law and supported by documented safeguards.
6. Research Data Safeguards
EK applies safeguards proportionate to the sensitivity and risk of each research activity. These may include:
collecting only information needed for a defined research purpose;
documenting the source, date and relevant context of evidence;
distinguishing source statements from verified facts and EK’s own analytical assessments;
corroborating material claims before publication;
limiting access to unpublished research materials;
using secure accounts, access controls and protected storage;
pseudonymising or anonymising individuals where their identity is not necessary;
removing personal contact details and unrelated identifiers;
applying additional review before publishing sensitive or potentially harmful information;
assessing whether naming a private individual is necessary and proportionate;
protecting confidential sources and people at heightened risk;
periodically reviewing whether working data still needs to be retained;
providing routes for privacy, correction and contextualisation requests.
EK does not publish personal contact details — such as home addresses, personal telephone numbers or private email addresses — unless publication is documented as necessary for the reporting and has a lawful basis. Contact details that are not necessary are removed from working material and from anything we publish.
Public-interest reporting may require EK to preserve source evidence supporting a published finding. A request relating to such material will therefore be assessed against applicable privacy rights, freedom of expression, the public interest, the rights of others and the need to establish or defend legal claims.
Privacy requests are handled separately from editorial correction requests. Requests concerning the accuracy or context of published content may be sent to corrections@ekstrategies.org.
7. Cookies and Analytics
Our website uses essential technologies required for delivery and security. With your permission we also use Google Analytics 4 and Hotjar to understand how visitors use the website, and Google Tag Manager to load the LinkedIn Insight Tag and the X (formerly Twitter) pixel, which measure our campaigns.
Hotjar records individual browsing sessions and produces aggregated heatmaps. A recording may capture the pages you open, mouse movement, clicks, scrolling and interactions with page elements, and may be reviewed by our team to understand how the website is used. Hotjar is loaded only after you accept analytics cookies, and we do not use recordings to identify individual visitors.
Analytics may process device, browser, page-view, interaction and cookie identifier information. Non-essential analytics and marketing technologies are not activated until you have made a choice.
You can accept, reject or change non-essential cookie preferences through our cookie controls: Cookie Settings (opens the consent preferences centre).
Further details — including cookie names, providers, purposes and durations — are available in our Cookie Policy.
Our Google Analytics 4 property is configured as follows: event-level data is retained for 2 months and user-level data for 14 months, after which Google deletes it automatically; Google Signals is enabled, which lets Google associate activity with signed-in Google accounts that have Ads Personalisation switched on; and the property is linked to our Google Ads account so that audiences of past visitors can be used for advertising. Google Analytics loads only after you accept analytics cookies, and the Google Signals and advertising features additionally require your consent to marketing cookies; until then no analytics or advertising identifiers are set.
8. How We Share Personal Data
EK may disclose personal data to:
hosting, content-management, analytics, communications, storage and security providers;
professional advisers;
researchers, contractors and project partners where access is necessary and appropriately controlled;
authorities or other recipients where disclosure is required by law;
parties involved in protecting EK, our users or others from security threats, fraud or unlawful conduct.
Service providers receive only the information necessary to perform their functions and are bound by appropriate contractual and security obligations.
EK does not sell personal data or allow service providers to use it for their own direct advertising, other than the advertising-measurement and audience features described in section 7, which those providers carry out under their own terms.
EK maintains an internal inventory of its processors and the countries in which they process data. A summary is provided in section 9 and further details are available on request through the contact details below.
9. International Data Transfers
EK’s website, providers, staff and project partners may operate in more than one country. Personal data may therefore be processed outside the country in which it was originally collected.
Where applicable law requires additional safeguards for an international transfer, EK will use an available lawful mechanism, such as an adequacy decision, contractual safeguards or another permitted transfer basis.
Details of relevant safeguards may be requested through the contact information below.
Our principal service providers and the locations where they may process data are: Hetzner (website hosting, data centre in the United States); Contentful (content management, European Union and United States); Google (analytics and advertising, United States); Hotjar (session analytics, European Union); LinkedIn and X (advertising measurement, United States); CookieYes (cookie-consent management, United Kingdom and European Union); Namecheap Private Email (email hosting, United States). Transfers to the United States rely on the EU-U.S. Data Privacy Framework where the recipient is certified under it and otherwise on the European Commission’s Standard Contractual Clauses, supplemented by measures such as encryption in transit and access controls. Transfers to the United Kingdom rely on the European Commission’s adequacy decision.
10. Data Retention
EK retains personal data only for as long as needed for the purpose for which it was collected, including security, research integrity, publication support, dispute resolution and legal compliance.
When identifiable data is no longer necessary, it is deleted, anonymised or retained in a restricted archive where continued retention has a documented lawful purpose.
Our current retention periods are:
Server and security logs: web-server access and error logs are rotated after 14 days; application logs are kept no longer than 12 months.
Google Analytics data: event-level data 2 months, user-level data 14 months (the data-retention settings of our Google Analytics 4 property); aggregated reports without identifiers may be kept longer.
Hotjar session recordings and heatmaps: retained for the data-retention period configured in our Hotjar account, after which Hotjar deletes them automatically.
Email enquiries and professional correspondence: up to 3 years after the last exchange, unless an ongoing project or legal matter requires longer.
Cookie-consent records: for as long as needed to demonstrate consent and no longer than 12 months after the consent expires or is withdrawn; the consent itself is renewed at least every 6 months.
Active research working files: for the duration of the project and up to 2 years after its completion.
Source evidence supporting published reports: for as long as the report remains published and for 6 years afterwards, so that findings can be substantiated and challenges answered.
Confidential-source information: only for as long as strictly necessary for the research purpose, in a restricted archive that is reviewed at least once a year.
Legal and compliance records: 7 years, in line with Estonian accounting and limitation rules, or longer while a legal claim is pending.
11. Security
EK uses technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
Measures are selected according to the nature and sensitivity of the data and may include access controls, secure authentication, encrypted transmission, restricted storage, backups, staff guidance and incident-response procedures.
No system can be guaranteed to be completely secure. EK therefore reviews its safeguards and access arrangements as technologies and risks change.
12. Your Privacy Rights
Depending on your location and the applicable law, you may have the right to:
request access to your personal data;
correct inaccurate or incomplete information;
request deletion;
restrict certain processing;
object to processing based on legitimate interests;
withdraw consent;
receive certain data in a portable format;
lodge a complaint with a competent supervisory authority.
These rights are not absolute. For example, EK may need to retain or continue processing information for freedom of expression, public-interest research, the rights of others, legal compliance or the establishment and defence of legal claims.
Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia — www.aki.ee/en. You may also lodge a complaint with the supervisory authority of the EU or EEA country where you live or work.
To submit a request, contact:
We may request information reasonably necessary to verify your identity and identify the relevant records. We will respond within the period required by applicable law.
If your request concerns a published statement rather than the underlying processing of personal data, please write to corrections@ekstrategies.org.
13. Children’s Privacy
The website and EK’s research services are not aimed at children. The website has no registration, no user accounts and no forms, we do not ask visitors for their age, and we do not knowingly seek out or use data about children obtained through it. Analytics and marketing cookies are set only where a visitor has accepted them.
Research that may concern a child or young person requires heightened necessity, harm and publication review. We do not publish identifying details unless there is a compelling and lawful reason to do so.
If you believe we have processed a child’s personal data inappropriately, contact us at privacy@ekstrategies.org.
If you believe we have collected a child’s personal data inappropriately, contact us at privacy@ekstrategies.org.
14. Automated Decision-Making
EK does not use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Analytical tools may assist researchers in organising or identifying material, but publication and material research conclusions remain subject to human review.
15. Third-Party Websites
Our website and publications contain links to third-party websites, media outlets, social networks and messaging platforms. EK does not control how those third parties collect or use personal data.
A link or citation does not mean that EK endorses the third party’s privacy practices. You should review the privacy information provided by the relevant service.
16. Changes to This Policy
We may update this Policy when our services, research practices, providers or legal obligations change.
The current version will always be published at this URL. We will update the “Last updated” date and provide additional notice where a change materially affects how personal data is used.
17. Contact Us
Questions, privacy requests and concerns may be sent to:
Mittetulundusühing NATIONAL RESILIENCE CENTRE Non-profit association registered in Estonia, registry code 80650278 Poordi tn 3-60, 10156 Tallinn, Harju maakond, Estonia Email: privacy@ekstrategies.org
Where applicable, you may also contact or lodge a complaint with the data protection authority responsible for your place of residence, work or the location of an alleged infringement.
You can review or change your cookie choices at any time via Cookie Settings. See also our Privacy Policy and Cookie Policy.