ن
نور العلم
Nour-Elm Platform
Login
Data Rights

GDPR Compliance

Your rights under the General Data Protection Regulation (GDPR) and the Dutch Algemene Verordening Gegevensbescherming (AVG) — and how to exercise them.

Regulation: GDPR (EU) 2016/679
Dutch implementation: AVG
Supervisory authority: AP (Autoriteit Persoonsgegevens)

1What Is GDPR?

The General Data Protection Regulation (GDPR) is the EU's data protection law that gives individuals control over their personal data. In the Netherlands it is implemented as the Algemene Verordening Gegevensbescherming (AVG).

Nour-Elm is fully committed to compliance with GDPR/AVG. All personal data processed through the platform is handled lawfully, transparently, and for specified purposes only.

As a mosque using Nour-Elm, you are the data controller. Nour-Elm is your data processor. Both parties share responsibilities to protect the personal data of students, parents, and teachers.

2Your Eight GDPR Rights

📋

Right of Access

You can request a copy of all personal data we hold about you or your child.

Art. 15 GDPR
✏️

Right to Rectification

You can request correction of inaccurate or incomplete personal data.

Art. 16 GDPR
🗑️

Right to Erasure

You can request deletion of personal data ("right to be forgotten"), subject to lawful retention obligations.

Art. 17 GDPR
⏸️

Right to Restriction

You can request limited processing of your data in specific circumstances.

Art. 18 GDPR
📦

Right to Portability

You can receive your data in a structured, machine-readable format (CSV/JSON) and transfer it elsewhere.

Art. 20 GDPR
🚫

Right to Object

You can object to processing based on legitimate interest or for direct marketing purposes.

Art. 21 GDPR
🤖

Rights Re: Automated Decisions

You have the right not to be subject to solely automated decision-making that significantly affects you. Nour-Elm does not perform such processing.

Art. 22 GDPR
↩️

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without affecting prior processing.

Art. 7(3) GDPR

3How to Exercise Your Rights

Contact your mosque administrator

Most data requests (access, correction, deletion of student records) should first be directed to the mosque administration who manages the Nour-Elm account.

Submit a formal written request

Provide your full name, the nature of the request, and sufficient identification. Requests by email are accepted.

Response within 30 days

We will respond to all valid data subject requests within one calendar month (30 days) as required by GDPR Art. 12.

Escalate to the Dutch DPA if needed

If your request is not properly handled, you may file a complaint with the Autoriteit Persoonsgegevens at autoriteitpersoonsgegevens.nl.

4Our GDPR Compliance Measures

  • Data Processing Agreements (DPAs) in place with all sub-processors
  • All data stored exclusively within the EEA — no third-country transfers
  • Strict tenant isolation: each mosque's data is fully separated
  • Passwords hashed using bcrypt; all connections over HTTPS/TLS
  • Defined data retention periods with automatic deletion after expiry
  • Only data strictly necessary for educational management is collected (data minimisation principle)
  • Privacy by design: privacy considerations built into every platform feature
  • Subscription Tier Data Handling: Institutional (mosque/school) tenants receive the full platform with unlimited data retention and custom SLAs. Free-tier and trial-tier personal accounts have identical data residency (EEA-only) and identical security measures, but may have restricted API feature access based on fair-use quota limits. Account suspension for fair-use violations does not result in automatic data deletion — data remains stored for 30 days, allowing reinstatement and compliance review, then is purged permanently.

5Data Breach Procedure

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Nour-Elm will:

  • Notify the affected mosque (data controller) without undue delay and within 72 hours of becoming aware of the breach
  • Provide details of the breach, the data involved, likely consequences, and remedial measures taken
  • The data controller (mosque) is then responsible for notifying the Dutch DPA and affected individuals as required by Art. 33–34 GDPR

6Contact & DPA Details

Privacy & GDPR Contact

Platform: nour-elm.app

Dutch DPA: Autoriteit Persoonsgegevens — autoriteitpersoonsgegevens.nl

GDPR text: gdpr.eu

Powered by DeepSynergy.io

← Back to Nour-Elm
Privacy Policy GDPR Terms
Powered by  DeepSynergy.io