Contact details, institutional profile, messages, country, territory of interest and basic technical data where applicable.
Privacy policy
How we process personal data.
This policy explains how Exodus & Resilience processes personal data received through the institutional website, forms, subscriptions, press requests, partnership conversations and direct communications.
Understand privacy in ten seconds
Minimum data, institutional purpose and responsible traceability.
Privacy is part of institutional trust. We collect only the information needed to respond, document and manage relationships connected to the platform.
To respond to enquiries, manage partnerships, send requested updates, handle press, research, governance and privacy matters.
We do not sell personal data and do not share it with third parties for advertising unrelated to the institutional purpose.
Who is responsible for processing
The website exodusandresilience.org operates as the digital institutional headquarters of Exodus & Resilience, an international platform for contemporary art, migration, living archives, education and public memory in its founding phase.
Until segmented inboxes are active, privacy, legal, governance, press, partnership, research and institutional requests are managed through contact@exodusandresilience.org.
Categories of personal data
We may process data that users provide voluntarily through forms, email, subscriptions, institutional requests or collaboration conversations.
- Identification data. Name, surname, role, organization or institutional affiliation.
- Contact data. Email address, country, preferred language or communication channel.
- Professional context. Type of entity, area of interest, collaboration profile or chapter of interest.
- Message content. Information included in forms, emails, proposals, press requests or academic enquiries.
- Technical data. Browser, device, IP address, pages visited, access date and cookie identifiers where applicable.
We recommend not sending sensitive, confidential or privileged data through web forms unless strictly necessary and unless sufficient authorization exists.
Why we process data
Personal data is processed for institutional, operational, communication, transparency and relationship-management purposes connected to Exodus & Resilience.
Handling messages from foundations, cultural institutions, universities, communities, artists, media, donors or potential partners.
Evaluating collaborations, dossier requests, territorial conversations, academic proposals or institutional opportunities.
Sending institutional communications only when the person has subscribed or requested information.
Reviewing functionality, security, accessibility, performance and technical errors.
Addressing legal, fiscal, accounting, documentary, governance or due-diligence needs.
Preventing misuse, security incidents or communications that may affect people, communities or participants.
Grounds for processing
Depending on the context and applicable jurisdiction, we may process personal data on the basis of consent, legitimate interest, pre-contractual or institutional steps, and legal obligations.
- Consent. When a form is submitted, a communication is accepted or updates are requested.
- Legitimate interest. To respond to enquiries, keep reasonable traceability, protect the website and manage institutional relationships.
- Institutional management. When a communication may lead to a partnership, grant, donation, research project, collaboration or service relationship.
- Legal obligation. When retention or communication is necessary under applicable law, audit, due diligence or compliance.
Where processing is based on consent, it may be withdrawn by writing to contact@exodusandresilience.org.
Forms, newsletter, hosting and analytics
Forms may be managed through external technical providers needed to receive, route and store institutional messages. Subscriptions or updates may be managed through a newsletter provider when active.
The website may use hosting, security, email, analytics, form-management and technical-maintenance services. These providers process data only to deliver the corresponding service and according to their own privacy and security standards.
Highly sensitive, confidential or privileged information should not be submitted through a web form unless an appropriate channel has been confirmed in advance.
When data may be shared
We do not sell personal information. We may share data only when necessary, proportionate and connected to the purpose for which it was provided.
- With technical providers for forms, hosting, security, email or analytics.
- With institutional partners when the enquiry concerns a specific chapter, partnership or collaboration.
- With legal, fiscal, accounting or compliance advisors when required for governance, due diligence, donations or reporting.
- With public authorities when a valid legal obligation exists.
Cookies and similar technologies
The website may use technical cookies needed for navigation, security, accessibility, forms and performance. It may also use analytics cookies when configured and accepted where consent is required.
For more information about cookie types, purposes, duration and management options, read our Cookie Policy.
How long data is kept
We retain personal data only for as long as needed to respond to the request, manage the institutional relationship, comply with applicable obligations, protect legitimate interests or document relevant processes.
- Contact enquiries. For the time needed to respond and maintain reasonable institutional traceability.
- Partnerships or donations. According to due diligence, governance, reporting, accounting or compliance needs.
- Subscriptions. Until the person unsubscribes or requests deletion.
- Technical records. For limited periods connected to security, maintenance and performance.
Rights
User options and rights
You may contact us to request access, correction, updating, objection, restriction, portability or deletion of personal data, subject to applicable legal and technical requirements.
Request information about personal data we hold.
Ask for inaccurate information to be updated or corrected.
Request deletion where legally and technically appropriate.
Ask to stop receiving non-essential institutional communications.
Ask us to limit certain processing where applicable.
Raise questions about privacy, consent, image rights or sensitive documentation.
External services and international transfers
Exodus & Resilience operates as an international platform with chapters in New York/Venezuela, Caracas and Acarigua. Communications, technical services or collaborations may involve providers or counterparts located in different jurisdictions.
When data is processed or accessed from another jurisdiction, we seek to apply reasonable contractual, technical and organizational safeguards according to the nature of the data and applicable law.
Minors, image rights and sensitive content
The institutional website is not directed to children as an online service. Any future collection or publication of data, images, testimonies or records involving minors or vulnerable persons must follow safeguarding, informed consent, dignity, context and proportionality standards.
The corresponding framework is available in the Safeguarding Policy.
Security measures
We apply reasonable administrative, technical and organizational measures to protect personal information against unauthorized access, loss, alteration, disclosure or misuse.
No transmission or storage system is completely secure. To report a security or privacy incident, write to contact@exodusandresilience.org.
Changes to this policy
We may update this policy to reflect changes in institutional operations, technical providers, forms, newsletter, cookies, legal obligations or platform structure.
Last editorial update: June 2026.
Privacy is part of institutional trust.
For questions about personal data processing, institutional communications or information updates, contact the team directly.