Work in progress. The official copy is being drafted by CCCN's legal team and will replace this placeholder section by section. The structure below previews the headings that will be covered.
Section 1 Who we are
To be drafted. Identifies CCCN as the data controller, contact details and the scope of NCTE 2026 (date, venue, hybrid format).
Section 2 Information we collect
To be drafted. Covers data collected at registration (name, email, phone, institution, role, country), payment data (if any), session picks, check-in records, technical data (IP, device, cookies), and any voluntary information shared in the planner.
Section 3 How we use your information
To be drafted. Purposes include: confirming attendance, managing capacity, sending logistics emails (Day 2 Zoom links), generating the boarding-pass QR, validating entry, and improving the program.
Section 4 Lawful basis for processing
To be drafted. Consent (explicit at registration), contractual necessity, and legitimate interest (in safeguarding the event).
Section 5 Cookies and similar technologies
To be drafted. Lists the cookies used by the site and by Supabase Auth (session storage, refresh token), plus opt-out instructions.
Section 6 Who we share your information with
To be drafted. Names the processors: Supabase (database + auth), Azure (hosting), jsDelivr (CDN for client-side libraries), and any payment processor. No sale of personal data.
Section 7 International transfers
To be drafted. Supabase and Azure may process data outside Costa Rica. Lists the safeguards used (standard contractual clauses, etc.).
Section 8 Data retention
To be drafted. Retention periods per data category (registration records, check-in stamps, email logs) and deletion timelines after the event.
Section 9 Your rights
To be drafted. Right of access, rectification, deletion, objection, portability, and how to exercise them via ncte@centrocultural.cr.
Section 10 Children's privacy
To be drafted. NCTE 2026 is a professional event for teachers — not directed at children. Clarifies the minimum age and what we do if a minor's data is collected accidentally.
Section 11 Security
To be drafted. Technical and organizational measures: encrypted transport (HTTPS), Supabase RLS, hashed credentials, role-restricted database functions, ticket codes generated with a confusion-free alphabet.
Section 12 Changes to this policy
To be drafted. How material changes are communicated and when they take effect.
Section 13 Contact us
To be drafted. Mailing address (CCCN Los Yoses), data protection email and response times.