Privacy and GDPR
The General Data Protection Regulation (GDPR) is a law designed to protect the personal data of people. This article explains what happens when you make a request about your personal data under the GDPR to Ecosia.
In this article:
GDPR covers data processed by a company. We only collect data that is necessary to provide you with search results and our account feature, in case you choose to sign up. We don’t use your search data to personalize advertisements elsewhere. Search results removal requests are handled by our search result providers, please find more information in this article.
What are my rights under GDPR?
Under GDPR, you have several rights regarding your personal data. These include:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete personal data we hold about you.
- Right to Erasure (Right to be Forgotten): You can request that we delete your personal data under certain circumstances.
- Right to Restriction of Processing: You can request that we limit the way we use your personal data in certain situations.
- Right to Data Portability: You can request to receive your personal data in a structured, commonly used, and machine-readable format, and have the right to transmit that data to another controller.
- Right to Object: You can object to the processing of your personal data in certain circumstances.
- Rights in relation to Automated Decision-Making and Profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Right to lodge a complaint: You have the right to complain to a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.
- Right of withdrawal: You may withdraw your consent at any time with future effect without affecting the lawfulness of the processing carried out prior to withdrawal.
What data does Ecosia process and store?
We are only able to share information regarding our own data processing activities, a full overview of our providers and how we process and share user data can be found on our privacy page.
So here is a quick summary of how we use personal data on Ecosia:
We can only link your email address to data if you’ve created an Ecosia account. If no Ecosia account exists, we do not associate any personal data with you.
Cookie consent data isn’t linked to names or email addresses. You can withdraw consent anytime via the cookie preferences at the bottom of the settings page or by deleting browser cookies.
IP addresses and usage data are anonymized within 7 days. Our service providers may retain this data longer, please refer to privacy policies:
If your request involves accounts with other companies, please contact them directly, we can only assist with data processed by Ecosia.
How can I request the removal of private information or images on Ecosia
If you find personal information or images in our search results, please contact the original provider directly. This is because the removal process often involves sharing sensitive information, and it’s more efficient to make your request with the provider directly.
For search results and ads:
- Click the three dots next to the result.
You’ll see who the provider is and be taken directly to their removal request form.
Further information and how to request a search result removal can be found here.
For images:
- Image removal requests are handled by our search partner, Microsoft Bing. You can report a concern to the provider here.
How do I submit a GDPR request to Ecosia?
To submit a GDPR request, please follow these steps:
- Identify your request: Clearly state which GDPR right you are exercising (e.g., access, rectification, erasure).
- Contact us: You can submit your request via privacy[at]ecosia.org
- Provide necessary information: To help us process your request efficiently, please include:
- Your full name
- Your email address (or other contact information used with our service)
- A clear description of your request
- Any specific data or information you are seeking (for access requests)
What happens after I submit a request?
Once we receive your GDPR request, the following process typically occurs, depending on the nature of your request:
- Acknowledgement: You will receive a confirmation right away in your inbox. It is forwarded to our external DPO for further processing.
- Verification of Identity: To protect your privacy and ensure the security of your data, we will need to verify your identity.
- Processing Your Request: Once your identity is verified, we will review your request and begin processing it. The time it takes to fulfill your request can vary depending on its complexity and volume.
- Response: We aim to respond to all legitimate requests within one month of receiving them. In some cases, if the request is complex or numerous, it might take longer. We will inform you if we need more time and explain the reasons for the extension.
Who can I contact for more information?
For any further questions about our GDPR policy or your data rights, please contact our Data Protection Officer at privacy[at]ecosia.org.