Privacy Policy

  • 19 April, 2026

Preamble

Our Privacy Policy, Methodology, and Code of Conduct provides clarity on how New Design Congress operates and the standards we hold ourselves, our members and community to.

New Design Congress is the public research subsidiary of Para-Real Ltd., an Irish private limited company (CRO 784599), registered at:

Para-Real Ltd.
Penrose Quay, PMC2
Penrose Wharf Business Centre
Cork T23 XN53
Ireland

Our operational correspondence address is:

New Design Congress
C/O Cultivation Space
Gottschedstrasse 4
exRotaprint Aufgang 4
13357 Berlin
Germany

We adhere to the highest ethical standards in all of our operations. We are dedicated to protecting the privacy of everyone who interacts with us. We don't sell, barter, give away, rent, or permit anyone outside of New Design Congress or our project-scoped contractors to use or access information about our partners, collaborators, research participants, or website visitors.

Where possible, we administer our own infrastructure to ensure that our data stays within our control. We sometimes use third party services to publish work and keep in touch with people, and we understand the privacy implications of this. We review our infrastructure partners regularly. Below, you can find out what these services are and how we handle all sorts of data, from user research to job applications.

If there is additional information you would like to see in this document about our practices, or if you have other comments or questions, please email us at hello@newdesigncongress.org.

Our Sites and Services

We use the following services to run our websites and understand how they are being used:

Web Hosting

We host our websites in Europe on infrastructure we control. We maintain basic server access logs for reasons of security. Our server is located in Finland, and operated on our behalf by Hetzner, a Germany-based data infrastructure company.

CDN and DDOS Protection

Caching and DDOS protection for our web projects is provided by eQualitie Deflect. eQualitie is a Canadian organisation developing open and reusable systems with a focus on privacy, online security and freedom of association. We use Deflect to analyse traffic, detect threats and proactively defend our sites. Deflect is governed by eQualitie's values statement and Deflect's Terms of Service and Privacy Notice.

Analytics

Our analytics are provided by Plausible, an open-source, privacy-preserving web analytics platform. We maintain our own, siloed instance of Plausible. Our analytics responds to Do Not Track requests. Our protection service (Deflect) maintains their own analytics service that we do not use. Our traffic data is not monetised. We may provide generalised reporting on traffic.

We maintain basic analytics for our email newsletters. We track overall open rates for each email communication we publish. All emails are handled via our own self-hosted Ghost instance, and are sent via Mailgun. We only send our newsletter to people who expressly sign up for it.

Video and Audio Content

We self-host video content on our own Peertube instance.

Peertube is a federated video platform. It offers simple built-in analytics (such as view-counts, etc) for each video uploaded to the service. We use these analytics in reporting to funders or collaborators and other instances in which we seek to measure our impact. Peertube also offers an opt-out feature in which viewers can help distribute a video's playback load, which sometimes exposes an individual's IP address to others who are viewing our content at the same time. This is on by default.

Podcasts and other audio content are distributed via RSS through our website.

Data Storage

Our work is stored on a Nextcloud instance we administer.

Our team uses PGP and are happy to correspond via encrypted email, or honor requests to have files shared with us be not stored in services we do not completely control. We respect diverse threat models and work to accommodate our partners' needs and concerns.

All data stored locally is encrypted as per our internal data security policy.

Community

NDC Members and Donations

Our NDC Members programme helps us maintain contact with people invested in our work. Membership is free and does not involve financial contributions of any kind. We do not accept public donations. New Design Congress is funded through Para-Real Ltd. and project-specific research contracts.

Our membership profiles are limited to member details, and a corresponding email address. We do not collect additional personal information, nor are we able to link the personal info of members to other platforms, such as Discord, etc.

Collaboration

We use Discord for community and collaboration efforts. Please refer to Discord’s privacy policy for more information. Our use of Discord is currently under review.

When collaborating with partners, we sometimes use Slack as required. Slack stores your account information and usage data, and our administrators have access to all public channels. Please refer to Slack’s privacy policy.

Streaming & Events

We host livestreamed events in circumstances where in-person events have a significant environmental impact and/or as directed by public health advice.

We securely archive all New Design Congress events. Before publishing an archived event, we require written consent from all participants.

Social Media

New Design Congress maintains a presence on popular social media platforms (LinkedIn, etc), as well as alternatives (such as Mastodon and Bluesky). Many of these networks have their own individual policies or technical differences. We take all reasonable steps to ensure participant consent when sharing content that includes external participants.

You can withdraw your consent from any of our published material at any time by emailing hello@newdesigncongress.org.

Collaborating With Us

ew Design Congress collaborates with individuals, organisations and companies across a range of research streams. In many cases, our collaborations involve sensitive information supplied to us via our consulting partner. We maintain strict confidentiality and secure data storage for all materials.

We maintain a transparency policy for our consultations and list active and former consultancies on our site. We are not able to work with organisations that cannot accommodate this policy.

Research Participants

Research is an important part of our work: it helps us understand people’s needs and helps us develop our perspectives with a greater degree of nuance.

All research participants are given a consent form that outlines what the research involves, what information will be recorded and how it will be used. If the participant is happy to proceed, we ask them to sign the form to confirm this. We scan signed consent forms and shred paper copies, then store consent forms on our infrastructure for one year.

At the moment, we do not conduct any research with people under the age of 18.

Using Information for Research

Research material is separated from any identifiable information, such as consent forms, while we are working with it.

Any notes we gather during research sessions are stored securely on infrastructure we control. Any digital files (like audio, photos and videos) are stored on the same infrastructure. Research data is only accessed by New Design Congress researchers. Partners who work with us on sensitive research adapt to our infrastructure; we do not place participant research material in third-party cloud services. At the end of the project, all notes and digital files are securely archived or, in more sensitive cases, destroyed and deleted.

Sometimes we may publish quotes from research sessions. We only do this if we have specific consent from the participant and any personally identifiable information has been removed. We will only publish audio, photos and video from a research session if a participant has given consent and has signed a model release form.

Working at Para-Real Ltd.

Individuals are employed by Para-Real Ltd., our parent company, rather than by New Design Congress directly. Only team members involved in the recruitment process have access to applications, CVs and emails we receive. We don't collect any special category data or ask for any background checks as part of the application process.

When people join Para-Real Ltd., we request information about them that is necessary for tax purposes. We hold information about their role and their professional development. Access to this information is controlled.

Institutional Continuity

If New Design Congress or Para-Real Ltd. is dissolved, acquired, or its infrastructure compromised, only published research will remain. Unpublished research material, consent forms, participant data, contact records, and membership information will be securely destroyed. Participant data does not transfer with the institution under any circumstances.

Where legally permissible, affected participants will be notified as quickly as possible in the event of compromise or seizure.

Data Policy Overview

New Design Congress does not participate in the following data processing activities:

  • Buying or selling marketing lists
  • Entering into data sharing agreements with other organisations
  • Telephone marketing
  • Postal marketing
  • CCTV surveillance

We do not use “soft opt-in”, meaning you won’t receive any marketing communication from us unless you’ve specifically agreed to it.

Data Protection

We carefully choose our services and tools at New Design Congress. It’s important that they follow good security practices, like HTTPS, two-factor authentication and the ability to set a strong password. We’ve reviewed the privacy policies and security practices of everything we use.

When a new team member joins The New Design Congress, we explain best practices for keeping their devices secure, maintaining the security of their online accounts, and working outside our offices.

In the event of a data breach, we are required to notify the relevant supervisory authority. We will do so following their guidance.

Every quarter, we review our documentation of the data we handle and third party services we use. This helps us continuously improve our processes and hold ourselves to account. We will update this document as necessary.

Transfer Outside the EEA

We have reviewed the privacy policies of third party services we use (most of which are listed above). They provide adequate protections when information is shared outside of the European Economic Area.

Exemptions

There are exemptions to data protection regulations that may require us to share data about you, including requests by law enforcement. A full list of EU exemptions are listed on the ICO website. This also applies to data held about you by third party services we use.

GDPR

The General Data Protection Regulation gives EU citizens the following rights:

To exercise any of these rights, please contact us at hello@newdesigncongress.org. You can find information specific to the services we use or our activities in the relevant sections of this document. If you are located in the EU and aren’t satisfied by our response, you can contact the EU Information Commissioner’s Office.

As Para-Real Ltd. is registered in Ireland, our lead supervisory authority under the GDPR one-stop-shop mechanism is the Irish Data Protection Commission (DPC). Complainants resident in Germany may also contact the Berliner Beauftragte für Datenschutz und Informationsfreiheit. If you are located elsewhere in the EU and aren't satisfied by our response, you can contact your local supervisory authority