DOCUMENTATION · HELPMAP
Privacy policy
HelpMap processes data about identified people during an emergency, including minors and deceased persons. This policy explains what data we process, on what basis, who we share it with, how long we keep it and how to exercise your rights. Last updated: August 2026.
1. Who is responsible
HelpMap Venezuela is a non-profit citizen initiative built by the volunteer collective Tropical Sadness x Imágenes Nacionales, based in Mérida, Venezuela. We currently operate as a volunteer collective; the constitution of a formal legal entity is under way.
- Data protection contact: Jorge Márquez (technical lead).
- Contact: info@helpmapvzla.net
- Site: www.helpmapvzla.net
2. What data we process and why
a) People located at health centres, shelters, or rescued: We publish surnames, names, national ID (adults only), age, sex, location, status and, only for adults with a verified record, a photograph. There is one purpose: enabling a family to find a relative during an emergency.
This data does not come from the data subject: it reaches us aggregated from health centres, medical staff and field volunteers, and from official lists. We say this plainly because it is materially relevant: the listed person has usually not been able to give us consent, often because they are hospitalised, unreachable or a minor. That is why processing is limited to the minimum needed to reunite families, and why anyone can ask us to take their record down (section 8).
b) People who write to us or contribute: If you report a missing person, contribute data or a photo about a record, apply as a volunteer or write to us, we process what you send: name, email, phone, the text of your message and any images you attach. The purpose is to handle that specific request. Here there is consent: you give it by submitting the form, after reading the notice shown on it.
Nothing submitted by the public is published automatically. Everything goes through cleanup, deduplication and human verification before reaching the map; a contribution with a photograph additionally requires explicit confirmation by a member of the team.
3. Legal basis for processing
In Venezuela the framework is constitutional: article 60 protects private life and the confidentiality of data, and article 28 recognises everyone's right to access data held about them and to request its rectification or deletion. For minors, the LOPNNA additionally applies.
The platform is additionally designed in line with the principles of the European General Data Protection Regulation (GDPR), as a reference standard and because HelpMap is designed to be replicated in other countries. Under that framework the applicable bases are:
- Vital interests of the data subject and of others (art. 6(1)(d)) for the location data of people during the emergency.
- For health data and other special categories: vital interests where the person is incapable of giving consent (art. 9(2)(c)) and substantial public interest in a disaster context (art. 9(2)(g)).
- Consent (art. 6(1)(a)) for those who write to us, report, contribute or apply as volunteers.
We are not established in the European Union and have not appointed a data protection officer or an article 27 representative: we state alignment with these principles, not certified compliance.
4. What we never publish
These rules do not depend on the good will of whoever enters a record: they are enforced in the database itself, so the public application has no technical way of displaying them even if someone tried.
- The person's home neighbourhood or area of origin. Home origin plus name plus photograph is a direct risk vector.
- The medical service or ward the person is in.
- The national ID and the photograph of minors: never, under any circumstance.
- The photograph of any record that is not verified.
- Deceased status before it is verified, and never presented as a casualty count.
The application code is open and MIT-licensed: you can review in the repository how data is filtered before being displayed, instead of taking our word for it. The database configuration that enforces these rules is available on request, and we are working on adding it to the repository too.
5. Minimisation and privacy by design
- The public application does not read the people table: it reads a filtered view that already excludes the sensitive fields.
- Minor protection is re-applied at every point where data enters, not only in the database.
- The public read API excludes photographs by default: a bulk feed of faces is a re-identification risk of a different order than looking up one record.
- Searches happen on your device and are not logged: we neither know nor store who searches for whom.
6. Providers and third parties
We do not sell data, do not transfer it for commercial purposes and do not run advertising. To operate the platform we use these providers, which process data on our behalf:
- Supabase: database and image storage.
- Vercel: application hosting and cookieless web analytics.
- Google Sheets and n8n: intake, cleanup and deduplication of data before verification.
- Telegram: intake channel for lists from the field.
- Our own mail server at mail.helpmapvzla.net: team email delivery.
- OpenStreetMap and Nominatim: base maps and address geocoding. When the map loads, your browser requests the tiles directly from their servers.
- USGS: public seismic data for the damage layer. We send no personal data.
- AcopioVE: exchange of information about shelters and donation points, under a CC BY 4.0 licence. This is data about places, not people.
These providers operate servers outside Venezuela, so there is an international transfer of data. The data about located people is, moreover, public by design: the map exists so that anyone can consult it.
7. Analytics and tracking
We use Vercel Web Analytics, which sets no cookies and collects no personal data, only aggregate usage figures. In addition, before any event leaves your device, the application strips the record identifier from URLs of the form /p/<id>: we know how many records were viewed, never which ones. We use no advertising or third-party trackers.
8. Your rights and how to exercise them
You can ask us to access the data we hold about you, correct it, remove it from the map or object to its publication. Write to info@helpmapvzla.net stating the published name and what you need. The most common request, "please take my relative off the map", is honoured without asking for reasons or justification.
How we handle the request: - We reasonably verify that the requester is the data subject or a direct relative. We do not ask for documents by email: we cross-check details only that person or their family would know. This is a deliberate balance: demanding formal ID in the middle of an emergency would block the people who need it most.
- We aim to respond within 72 hours and carry out the removal as soon as we confirm it. We are a volunteer team: if we take longer, write again. We are not ignoring you.
- A takedown removes the record from the public app, the map, the read API and the shareable pages. Images others have already shared on social networks are technically beyond our reach.
- We record every change in an append-only internal log, so there is a record of who did what and when.
9. How long we keep data
Data about located people stays published while the emergency response is active, because that is when it serves to reunite families. When the response closes, the team reviews the full dataset and takes the publication down, keeping only aggregate figures that identify no one. We do not set a deadline in months because the duration of an emergency is not known in advance; we do commit that publication ends with it and does not stay online out of inertia.
Messages, reports and applications are kept as long as they are needed to handle them and to document the verification process. Contributed photographs that are rejected are never published at any point: they live in private storage and are discarded.
10. Security
- Access is restricted in the database itself through row-level policies: an anonymous visitor cannot read the base table, only the already-filtered public view. We verify this with a check script that is part of the repository.
- The team works with differentiated roles. Volunteers publish live because they are vetted, and their access is revocable at any time; deleting a record or a centre is reserved to administrators.
- Photographs contributed by the public are held in private storage while unreviewed: they are not reachable by direct link, even knowing it.
- Every modification is recorded in an append-only log the team reviews daily.
11. Minors
A minor never carries a national ID or a photograph in HelpMap: we show "MENOR" and a neutral avatar. The rule is enforced at the database layer and re-applied at every entry point, so it does not depend on who enters the data or on anyone remembering to apply it.
This follows article 65 of the LOPNNA, which prohibits exposing the image or identifying data of children and adolescents in ways that may harm them, and article 16 of the Convention on the Rights of the Child.
12. Legal framework and standards
- Constitution of the Bolivarian Republic of Venezuela, articles 28 and 60.
- Organic Law for the Protection of Children and Adolescents (LOPNNA), article 65.
- Special Law against Computer Crimes (2001), articles 20 to 22.
- General Data Protection Regulation (EU) 2016/679, as a reference standard.
- Convention on the Rights of the Child, article 16, and United Nations Principles on Personal Data Protection and Privacy (2018).
- ICRC Handbook on Data Protection in Humanitarian Action and OCHA Data Responsibility Guidelines.
13. Changes and contact
If this policy changes, we update the date in the header. For any question, request or complaint about data processing, write to info@helpmapvzla.net.
Need something or want to collaborate? info@helpmapvzla.net