Strategic Management Workbook

For Islamic Organizations

Workshop mode active

Privacy policy

Last updated: 16 July 2026 · Applies to stratworkbook.com and related domains (.net, .org). This page is written for transparency under GDPR, US state privacy laws, and Bosnia and Herzegovina's personal-data law. It is product documentation — not legal advice. Have counsel review before a formal compliance claim.

Who is responsible (data controller)

The operator of the Strategic Workbook Portal (the site owner listed on domain registration for stratworkbook.com) decides why and how personal data is processed. For organization-hosted deployments, your conference host or employer may also process data as a separate controller for their members.

Privacy requests: privacy@stratworkbook.com. We aim to respond within 30 days (GDPR) or the timeframe required by applicable US state law.

What we collect

  • Account & sign-in: email, display name, organization membership, authentication events. Passwords are stored by our identity provider (Zitadel), not in the portal database.
  • Workbook data: worksheet answers saved to your account or shared with your organization.
  • Collaboration: contributions on shared boards (for example SWOT, vision, mission), including display name and email used for attribution.
  • Feedback (optional): messages and screenshots you submit, page path, and technical metadata.
  • Security & operations: server logs (IP address, user agent, timestamps) for abuse prevention and reliability.
  • This device: optional local drafts in browser storage (localStorage) until you clear them or delete your account.

We do not knowingly collect personal data from children under 13 (US COPPA) or under 16 without parental authority where EU/UK law requires it. The portal is intended for organizational learners and conference participants.

Why we use it (lawful bases)

  • Contract / service delivery (GDPR Art. 6(1)(b)): account, worksheets, collaboration features you request.
  • Legitimate interests (Art. 6(1)(f)): security, fraud prevention, product improvement from voluntary feedback, balanced against your rights.
  • Legal obligation (Art. 6(1)(c)): where we must retain records for tax, court order, or regulatory request.
  • Consent (Art. 6(1)(a)): where we ask explicitly (for example accepting this policy at onboarding). You may withdraw consent by deleting your account; that does not affect processing already lawfully performed.

Under Bosnia and Herzegovina's Law on Protection of Personal Data (Official Gazette 49/06 and amendments), processing must be lawful, limited, and transparent; you have rights of access, correction, deletion, and objection as described below.

Processors & international transfers

We use subprocessors to run the service, including hosting (DigitalOcean), identity (Zitadel), and optionally AI inference when enabled. Transfers outside your country may occur. Where GDPR applies, we rely on appropriate safeguards (for example Standard Contractual Clauses) when required.

Cookies & session storage

Essential cookies only. We use a session cookie for sign-in (NextAuth). We do not use advertising or third-party tracking cookies.

  • Session cookie: keeps you signed in; maximum lifetime 7 days, extended while you use the site actively (rolling refresh every 24 hours of use).
  • Local storage: optional worksheet drafts on your device; not sent to our servers unless you save or sync.

Is "delete cookies after inactivity" required? No — GDPR and BiH law require transparency, a lawful basis, and storage limitation, not a specific idle-timeout on cookies. We limit session length and let you sign out or delete your account at any time. A separate cookie consent banner is not required for strictly necessary authentication cookies.

Retention

  • Account and worksheet data: while your account exists.
  • After account deletion: removed from active application stores as described in "Your rights".
  • Server logs and backups: retained only as long as needed for security and disaster recovery, then deleted or anonymized.
  • Collaborative board text may remain for teammates; your email and display name on those items are replaced with "Former member".

Your rights

Depending on where you live, you may have some or all of the following:

  • Access & portability: view your profile on Account; contact us for an export if needed.
  • Rectification: edit your display name and organization on Account.
  • Erasure: Delete my account on Account removes portal profile, personal and org worksheet saves, feedback, organization membership, anonymizes your attribution on shared boards, and deletes your identity-provider login when the session allows.
  • Restriction & objection: contact us; we will assess per request.
  • US state rights (for example California CCPA/CPRA, Colorado CPA, Virginia VCDPA): right to know, delete, correct, and opt out of "sale" or "sharing" for cross-context behavioral advertising. We do not sell personal information or use it for cross-context behavioral ads.
  • Bosnia and Herzegovina: contact the Agency for Personal Data Protection (APDP) in Sarajevo if you believe processing violates PD BiH after raising the issue with us.
  • EU/UK: lodge a complaint with your supervisory authority.

We may need to verify your identity before fulfilling a request. We do not discriminate against you for exercising privacy rights.

Security

We use HTTPS, tenant isolation for organization data, access controls, CSRF protections on mutating API routes, and rate limits on sensitive endpoints. No method of transmission is 100% secure; report concerns to privacy@stratworkbook.com.

Changes

We may update this policy. Material changes will be reflected in the "Last updated" date. Continued use after changes constitutes notice; where consent is required by law, we will ask again.

See also Terms of use.