1What Is GDPR?
The General Data Protection Regulation (GDPR) is the EU's data protection law that gives individuals control over their personal data. In the Netherlands it is implemented as the Algemene Verordening Gegevensbescherming (AVG).
Nour-Elm is fully committed to compliance with GDPR/AVG. All personal data processed through the platform is handled lawfully, transparently, and for specified purposes only.
2Your Eight GDPR Rights
Right of Access
You can request a copy of all personal data we hold about you or your child.
Art. 15 GDPRRight to Rectification
You can request correction of inaccurate or incomplete personal data.
Art. 16 GDPRRight to Erasure
You can request deletion of personal data ("right to be forgotten"), subject to lawful retention obligations.
Art. 17 GDPRRight to Restriction
You can request limited processing of your data in specific circumstances.
Art. 18 GDPRRight to Portability
You can receive your data in a structured, machine-readable format (CSV/JSON) and transfer it elsewhere.
Art. 20 GDPRRight to Object
You can object to processing based on legitimate interest or for direct marketing purposes.
Art. 21 GDPRRights Re: Automated Decisions
You have the right not to be subject to solely automated decision-making that significantly affects you. Nour-Elm does not perform such processing.
Art. 22 GDPRRight to Withdraw Consent
Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
Art. 7(3) GDPR3How to Exercise Your Rights
Contact your mosque administrator
Most data requests (access, correction, deletion of student records) should first be directed to the mosque administration who manages the Nour-Elm account.
Submit a formal written request
Provide your full name, the nature of the request, and sufficient identification. Requests by email are accepted.
Response within 30 days
We will respond to all valid data subject requests within one calendar month (30 days) as required by GDPR Art. 12.
Escalate to the Dutch DPA if needed
If your request is not properly handled, you may file a complaint with the Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl.
4Our GDPR Compliance Measures
- Data Processing Agreements (DPAs) in place with all sub-processors
- All data stored exclusively within the EEA — no third-country transfers
- Strict tenant isolation: each mosque's data is fully separated
- Passwords hashed using bcrypt; all connections over HTTPS/TLS
- Defined data retention periods with automatic deletion after expiry
- Only data strictly necessary for educational management is collected (data minimisation principle)
- Privacy by design: privacy considerations built into every platform feature
- Subscription Tier Data Handling: Institutional (mosque/school) tenants receive the full platform with unlimited data retention and custom SLAs. Free-tier and trial-tier personal accounts have identical data residency (EEA-only) and identical security measures, but may have restricted API feature access based on fair-use quota limits. Account suspension for fair-use violations does not result in automatic data deletion — data remains stored for 30 days, allowing reinstatement and compliance review, then is purged permanently.
5Data Breach Procedure
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Nour-Elm will:
- Notify the affected mosque (data controller) without undue delay and within 72 hours of becoming aware of the breach
- Provide details of the breach, the data involved, likely consequences, and remedial measures taken
- The data controller (mosque) is then responsible for notifying the Dutch DPA and affected individuals as required by Art. 33–34 GDPR
6Contact & DPA Details
Privacy & GDPR Contact
Platform: nour-elm.app
Dutch DPA: Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl
GDPR text: gdpr.eu
Powered by DeepSynergy.io