Speak. Lead. Change the World.

Privacy and Data Protection Policy - Agora Speakers International Foundation

Sep 27th, 2026

1. About this Privacy Policy

Agora Speakers International Foundation (“Agora”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, disclose, retain and otherwise process personal data when you:

It also explains your rights under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data-protection and privacy laws.

This Policy should be read together with any additional privacy notice that we may provide for a particular service, event, activity or processing operation.

2. Who is responsible for your personal data?

For the processing described in this Policy, the data controller is:

Agora Speakers International Foundation
Registered address: ul Buntovnik 52, 3ap. 1421 Sofia (Bulgaria)
Country of establishment: Bulgaria
Registration number: 205228771
Email: support@agoraspeakers.org


3. Personal data we collect

The personal data we process depends on how you interact with Agora.


3.1 Website visitors

When you visit an Agora website, our systems may process:

Some technical information is required for websites to function securely. Other analytics or tracking technologies will be used only where permitted by applicable law and, where required, after obtaining your consent.

See Section 13, Cookies and similar technologies, for more information.

3.2 Members and Online Platform users

If you are an Agora member or use the Agora Speakers Online Platform, we may process information that you provide or that is generated through your participation, including:

3.3 Information you choose to make public

Depending on the settings and functionality available on the Online Platform, you may choose to make certain profile or Agora-related information visible to:

We will respect the privacy settings and visibility choices provided through the Platform.

Information will not be treated as public merely because it has been provided to Agora unless you have been clearly informed that the relevant information will be publicly visible and, where required, have chosen that visibility.

3.4 Professional opportunity profile

Agora may offer members an optional professional opportunity feature for members who want to be considered for opportunities relating to public speaking and related professional services.

Examples may include opportunities or contracts concerning:

Participation in this feature is entirely voluntary.

If you opt in, Agora may process information that you choose to include in your professional opportunity profile, which may include:

Agora will clearly identify which information will be made available through this feature before you opt in.

Participation in the professional opportunity feature is not required for Agora membership or access to ordinary Agora membership services.

3.5 Information obtained from public sources

Where appropriate and permitted by law, Agora may process information that you have deliberately made public through social-network profiles or other public sources.

Such information may include:

We obtain this information from public profiles in social and professional networks, as well as information relayed to us by clubs that you voluntarily provide to them.

We do not assume that all information available online may automatically be collected or reused. We process publicly available information only where we have an appropriate legal basis and where the processing is compatible with applicable data-protection law.

3.6 Information received from clubs and other members

We may receive personal data from:

This may include information concerning membership, participation in meetings or events, educational progress, positions held and other Agora activities.

3.7 Special categories of personal data

Agora does not generally require members to provide personal data revealing:

Members may occasionally disclose such information voluntarily in speeches, communications or other content.

Where Agora itself processes special-category data for a purpose covered by Article 9 GDPR, we will do so only where an appropriate Article 9 condition applies.

Members should not include special-category personal data in professional opportunity profiles unless Agora has specifically provided a mechanism and lawful basis for doing so.

4. Why we process personal data and our legal bases

Under the GDPR, Agora must have a lawful basis for each processing activity.

4.1 Operating websites and technical infrastructure

We process IP addresses, browser information, server logs and related technical data in order to:

Legal basis: our legitimate interests under Article 6(1)(f) GDPR in operating secure, reliable and efficient online services.

Where processing is strictly necessary to provide a service requested by a user, Article 6(1)(b) GDPR may also apply.

4.2 Website analytics and operational monitoring

We use information generated through operation of our websites and Online Platform to understand how our services are used, improve their performance and usability, identify technical problems, monitor service reliability and capacity, and maintain the security and resilience of our systems.

General usage analytics are performed internally and we do not use third-party advertising or behavioural-analytics services.

We do, however, use external observability and monitoring providers, including New Relic, for technical purposes such as application monitoring, debugging, error analysis, performance monitoring and service-level objective (SLO) monitoring. This may involve transmitting application logs and related telemetry to those providers as described in Section 7.4.

Legal basis: Article 6(1)(f) GDPR, based on our legitimate interests in operating, securing, maintaining, troubleshooting and improving our websites and services.

4.3 Creating and administering your membership and account

We process membership, profile and account data to:

Legal basis: Article 6(1)(b) GDPR where processing is necessary to administer the membership relationship.

Where particular processing is not necessary for the membership relationship, we may rely on Article 6(1)(f) GDPR where appropriate.

4.4 Educational and community activities

We process information about meetings, events, speeches, projects, educational progress, roles and feedback to:

Legal basis: Article 6(1)(b) GDPR where processing is necessary to provide Agora membership or services.

For related organisational activities that are not necessary for performance of the membership relationship, we may rely on Article 6(1)(f) GDPR and our legitimate interests in running and developing Agora's educational and community programmes.

4.5 Club administration

We process member and activity information to automate and facilitate administrative functions including:

Legal basis: Article 6(1)(b) GDPR where necessary to provide membership services, and Article 6(1)(f) GDPR where appropriate for Agora's legitimate interest in efficiently administering its organisation.

4.6 Member communications

We use contact information to communicate with members regarding:

Legal basis: Article 6(1)(b) GDPR where the communication is necessary for the membership relationship.

4.7 Safety, integrity and security

We process account, usage and activity information where necessary to:

Legal basis: Article 6(1)(f) GDPR, based on Agora's legitimate interests in protecting the organisation, its systems, its members and other users.

Where processing is necessary to comply with a specific legal obligation, Article 6(1)(c) GDPR applies.

4.8 Inter-cultural exchange and community cohesion

We may process basic profile, location, club and activity information to help members interact across clubs and geographical areas and to facilitate collaboration within the organisation.

Legal basis: Article 6(1)(f) GDPR, based on Agora's legitimate interests in facilitating communication, collaboration and inter-cultural exchange between members and clubs, and in pursuing its organisational mission of promoting dialogue, tolerance and peaceful coexistence.

We rely on this basis only where the processing is reasonably necessary for these purposes and where those interests are not overridden by the interests, rights or freedoms of the individuals concerned.

4.9 Organisational transparency

We may process information about roles, organisational responsibilities and relevant Agora activities where necessary to provide transparency concerning the governance and operation of Agora.

Legal basis: Article 6(1)(f) GDPR, based on Agora's legitimate interests in transparent governance, subject to the interests, rights and reasonable expectations of affected individuals.

Where publication is required by law, Article 6(1)(c) GDPR applies.

4.10 Member directory

As part of Agora membership, certain member information is made available to other authenticated Agora members through the global member directory.

The directory is an integral part of Agora's membership framework and is intended to enable members to identify and communicate with one another, participate in the international Agora community, coordinate club and organisational activities, and support collaboration between members and clubs.

The information made available through the directory may include:

Participation in the member directory is a condition of Agora membership and forms part of the membership terms. It is therefore not based on consent and cannot be disabled while maintaining membership, except where Agora is required by applicable law to restrict or suppress particular information.

Legal basis: Article 6(1)(b) GDPR, because processing of the information described above is necessary for the performance of the Agora membership relationship and for provision of the membership services of which the global member directory forms an integral part.

4.11 Public profiles and public disclosure

We make optional profile information publicly available only where:

Where public visibility is voluntary, the legal basis for publication is consent under Article 6(1)(a) GDPR.

Legal basis: consent under Article 6(1)(a) GDPR.

You may withdraw that consent through the relevant visibility setting in your profile

4.12 Professional speaking and training opportunities

Agora may provide an optional service intended to help members receive professional opportunities related to public speaking, events, training and related activities.

The service is intended to enable members who actively want such opportunities to be discovered or contacted by:

The purposes of this processing are to:

Legal basis: consent under Article 6(1)(a) GDPR.

Participation is voluntary and off by default.

Agora will obtain a specific opt-in from the member before making personal data available for this purpose.

Choosing not to participate will not:

Consent to this feature is separate from acceptance of Agora's general membership terms.

Before opting in, members will be informed of:

The feature will only be used for opportunities reasonably connected with professional speaking, presentation, training, facilitation, leadership, project management, events or closely related services. It is not intended to make member information generally available for unrelated recruitment, advertising or commercial solicitation.

4.13 Contact by recruiters and prospective customers

If you opt into the professional opportunity feature, persons or organisations seeking relevant services may contact you using the contact mechanism made available through the Platform.

Depending on the Platform's design, this may occur through:

Agora will not make members available for professional-opportunity contact unless they have opted into the feature.

Recipients are expected to use information obtained through the feature only for genuine opportunities connected with the purposes described above and in accordance with applicable law and Agora's applicable Terms & Conditions.

Once a recruiter, event organiser, prospective customer or other third party independently communicates with a participating member or receives personal data in connection with a potential engagement, that third party may process personal data as an independent data controller for its own recruitment, procurement, contracting or business purposes.

Where this occurs, the third party is responsible for complying with its own data-protection obligations. Members should review any privacy information supplied by that third party.

4.14 Withdrawal from professional opportunities

A member may withdraw consent to participation in the professional opportunity feature at any time through the relevant setting in their account profile,

or by contacting:

support@agoraspeakers.org

Withdrawal will:

Withdrawal from the professional opportunity feature does not require cancellation of Agora membership.

Where a third party obtained a member's information lawfully before withdrawal, that third party may already hold a copy. Agora cannot automatically delete information independently retained by an external controller. The member may exercise applicable data-protection rights directly against that third party.

4.15 Legal compliance and legal claims

We process personal data where necessary to:

Legal basis: Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation.

Where processing is necessary to establish, exercise or defend legal claims and no specific legal obligation applies, we may rely on Article 6(1)(f) GDPR.

5. Our legitimate interests

Where we rely on Article 6(1)(f) GDPR, we consider whether:

  1. we have a legitimate purpose;
  2. processing is necessary for that purpose; and
  3. your interests, rights or freedoms override our interests.

Our legitimate interests may include:

The professional opportunity feature described in Sections 4.12–4.14 does not rely on legitimate interests for the member's participation or disclosure of the member's opportunity profile. It relies on the member's consent.

6. When providing personal data is required

Certain information is required as part of Agora membership, including the information necessary to maintain the member directory described in Section 4.10. Because the member directory is an integral part of the Agora membership framework, a member cannot opt out of directory participation while maintaining membership, except where applicable law requires otherwise.

Required fields are identified when information is requested.

If you do not provide information necessary for us to create an account, administer membership, provide a requested service, meet legal requirements or maintain account security, we may be unable to provide the relevant service.

Other information is optional.

In particular, participation in the professional opportunity feature and the provision of information for that feature are optional.

Members do not need to participate in that feature in order to join, remain a member of, or participate in Agora.

7. How we share personal data

We do not sell personal data.

We disclose personal data only where there is a lawful basis and where disclosure is reasonably necessary for the relevant purpose.

7.1 Other Agora members

Authenticated members may have access to information made available through the member directory or other community functionality, subject to applicable access and visibility settings.

7.2 Agora clubs, officers and volunteers

Personal data may be available to relevant club officers, event organisers, volunteers or other persons carrying out Agora functions where access is necessary for:

Access should be limited according to role and need.

7.3 Recruiters, event organisers and prospective customers

If, and only if, you have opted into the professional opportunity feature, personal data included in your professional opportunity profile may be made available to categories of recipients seeking relevant professional services, including:

Only information covered by the professional-opportunity consent and applicable settings will be disclosed through this feature.

The specific recipient-access model is through the mechanisms provided by the platform.

7.4 Service providers and processors

We may use service providers to perform functions on our behalf, such as:

Processors may process personal data only under our instructions and under contracts meeting Article 28 GDPR requirements.

Where a provider processes personal data on our behalf as a processor, we require appropriate contractual data-protection obligations, including the requirements of Article 28 GDPR where applicable. Some providers may also act as independent controllers for particular services or processing activities, in which case their own privacy terms also apply.

Current material service providers include:

Hetzner Online GmbH.

We use Hetzner for the hosting of Agora's principal application, database and related server infrastructure. Personal data processed through Hetzner may include account and profile information, membership and educational records, application data, uploaded content, IP addresses, server logs and other information stored in or generated by the Agora Online Platform. Our principal application infrastructure is hosted in Germany. Hetzner processes personal data on our behalf under the applicable contractual data-processing arrangements.

Cloudflare, Inc.

We use Cloudflare as a reverse proxy, content-delivery and network-security provider in front of certain Agora websites and online services. Requests made to those services may therefore pass through Cloudflare's infrastructure before reaching Agora's origin servers. In providing these services, Cloudflare may process IP addresses, connection and request information, requested URLs, HTTP headers, cookies or similar identifiers, security-event information, and, where technically necessary for the enabled services, content transmitted between the user and Agora. Cloudflare operates a global network and may process personal data in the European Economic Area and in other countries, including the United States. Where Cloudflare acts as our processor, the processing is governed by Cloudflare's Data Processing Addendum and applicable international-transfer safeguards. Cloudflare confirms that its DPA applies where it processes personal data as a processor on behalf of a customer.

Amazon Web Services - Amazon Simple Email Service (Amazon SES).

We use Amazon SES to send transactional, operational and other authorised email communications, such as account messages, notifications and service-related communications. When an email is sent through Amazon SES, AWS may process sender and recipient email addresses, sender and reply-to information, email subject lines and message content, message headers and routing information, delivery status, bounce and complaint information, and related technical and security data. Agora currently uses Amazon SES in the US East (N. Virginia) – us-east-1 Region. This involves processing of personal data in the United States. AWS states that its Data Processing Addendum applies automatically when AWS services are used to process customer data and that Standard Contractual Clauses are available for relevant transfers outside the EEA where required.

Amazon Web Services – Amazon Simple Storage Service (Amazon S3).

We use Amazon S3 to store backup copies of data held in Agora's systems. Those backups may include account information, profile information, membership and club records, educational and participation records, uploaded files, system data, communications and other personal data contained in the systems being backed up. The purpose of these backups is to support business continuity, disaster recovery, restoration following data loss or technical failure, and the security and resilience of our services. The AWS Region used for S3 backups is US East (N. Virginia) – us-east-1. AWS acts as a processor for customer data stored on our behalf under the AWS Data Processing Addendum. AWS states that customer content is generally kept in the selected AWS Region unless transfer is necessary to provide or maintain the requested service, to comply with law, or where the customer instructs a transfer. Where backups are stored or otherwise processed outside the EEA, applicable Chapter V GDPR safeguards, including the Standard Contractual Clauses where required, are used.

Backup copies are retained in accordance with our backup and retention schedule and are not used for unrelated purposes. When personal data is deleted from the live system, residual copies may remain temporarily in backups until the relevant backup set expires or is overwritten in accordance with our retention schedule.

Google / YouTube.

We use YouTube to store and deliver videos and recordings of speeches or presentations submitted by Agora members. Depending on the recording, such videos may contain the member's image and voice, name, the contents of the speech, opinions or experiences voluntarily disclosed during the presentation, titles, descriptions and other associated metadata. Videos are made available according to the privacy or visibility setting used for the relevant video. Google states that uploaded YouTube content is stored by YouTube and that who may view it depends on the video's privacy settings.

Because YouTube may process information for its own service purposes in addition to providing video hosting, Google may act as an independent controller for some YouTube processing under Google's and YouTube's applicable terms. Agora will not describe YouTube merely as an Article 28 processor unless the contractual terms applicable to our particular YouTube use establish that role. Our default video visibility setting is unlisted.

Google – Gemini.

We use Gemini to provide optional automated analysis of speeches and presentations when a member specifically requests that feature. Depending on how the feature is implemented, we may send a speech transcript, audio or video content, presentation text, member-supplied context, prompts or instructions necessary to perform the requested analysis, and the resulting generated feedback. The feature is not used automatically for every member speech; the analysis is initiated only when requested by the member.

Where Agora uses a paid Gemini API service covered by Google's applicable processor terms, Google processes the submitted customer data on Agora's behalf. Google states that, for Gemini API Paid Services, prompts, associated files and responses are not used to improve Google's products. Google may retain certain prompts and responses for limited periods for purposes such as abuse monitoring, depending on the configuration used.

Agora does not intentionally opt member speech data into datasets or programmes that allow Google to use that content for general model improvement.

OpenAI.

We use OpenAI services, including ChatGPT and/or the OpenAI API, to provide optional automated analysis of speeches and presentations when a member requests that functionality. The information sent for analysis may include speech transcripts, recordings or extracts, presentation text, contextual information supplied by the member, prompts and analysis instructions, generated feedback and related technical information.

Where Agora uses an OpenAI business or API service covered by OpenAI's Data Processing Addendum, OpenAI processes Customer Data on Agora's behalf as a processor. OpenAI states that inputs and outputs from its business offerings and API platform are not used to train or improve its models by default unless the customer explicitly opts in.

The OpenAI API may retain abuse-monitoring logs containing prompts, responses and related metadata for a limited period, currently up to 30 days by default unless longer retention is required by law or necessary to protect the service or third parties.

Agora does not intentionally opt member speech content into model-training or model-improvement programmes.

New Relic.

We use New Relic for application monitoring, debugging, performance monitoring, service-level objective (SLO) monitoring, error analysis and related observability functions.

For these purposes, application, infrastructure and service logs and other telemetry data may be transmitted to New Relic. Depending on the content of the relevant logs or telemetry, this information may include IP addresses, request and transaction information, timestamps, application events, error messages, identifiers, technical metadata and, in some circumstances, other personal data contained in application logs.

New Relic processes this information on our behalf as a processor under its applicable Data Processing Addendum. We configure our logging and monitoring systems with the aim of limiting the personal data transmitted to New Relic to information reasonably necessary for debugging, security, reliability, performance monitoring and related operational purposes.

New Relic may process personal data outside the European Economic Area. Where such processing constitutes an international transfer under the GDPR, the transfer is governed by an applicable adequacy mechanism, the European Commission Standard Contractual Clauses or another lawful transfer mechanism under Chapter V GDPR.

7.5 Professional advisers

Where necessary, we may disclose information to professional advisers such as lawyers, accountants, auditors or insurers, subject to appropriate confidentiality obligations.

7.6 Authorities and legal requests

We may disclose or preserve personal data in response to a legally valid request from courts, regulators, law-enforcement agencies or public authorities.

We assess requests in accordance with applicable law and disclose only information we consider legally required or otherwise lawfully permitted.

7.7 Corporate or organisational restructuring

If Agora undergoes a merger, restructuring, reorganisation or transfer of functions, relevant personal data may be transferred where permitted by law and subject to appropriate safeguards.

8. Agora clubs and responsibility for data processing

Agora Speakers International Foundation operates an international affiliation framework under which local Agora Clubs may voluntarily choose to affiliate with Agora.

Agora Clubs are independent entities. Affiliation with Agora does not mean that a club is owned, managed, controlled or operated by Agora Speakers International Foundation. Agora does not exercise direct control over a club's internal management, governance, activities, membership administration or day-to-day decisions.

Affiliation is voluntary. An Agora Club may decide, on its own initiative, to end its affiliation with Agora at any time, subject only to any administrative procedures applicable to ending that affiliation. A club does not require Agora's approval to make the decision to cease being affiliated.

Similarly, Agora's affiliation framework does not create an employment, agency, partnership, franchise, subsidiary or other relationship under which a local club acts on behalf of Agora Speakers International Foundation merely by virtue of being affiliated.

Each Agora Club is responsible for determining how it operates and, where applicable, how it collects and uses personal data in connection with its own local activities.

Accordingly, where an Agora Club independently determines the purposes and means of processing personal data, that club acts as an independent data controller and is responsible for complying with the data-protection laws applicable to its own processing. This includes responsibility for establishing an appropriate legal basis for processing, providing privacy information where required, responding to data-subject requests, implementing appropriate security measures and complying with applicable retention and disclosure requirements.

Affiliation with Agora does not, by itself, make a local club:

Agora Speakers International Foundation is responsible for personal-data processing for which it determines the purposes and means, including processing carried out through the central Agora websites, Online Platform and other services operated by Agora.

A local Agora Club may provide certain information to Agora, or receive certain information from Agora, in connection with central services such as membership administration, educational records, organisational coordination or functionality provided through the Agora Online Platform. In such circumstances, Agora and the relevant club remain responsible for their respective processing activities unless a specific arrangement establishes a different legal relationship for a particular processing operation.

Where a club collects or processes personal data independently of the central Agora Platform—for example through local membership or event forms, mailing lists, messaging services, payment systems, websites, social-media accounts or other tools chosen by the club—that processing is undertaken under the responsibility of the club concerned and is not controlled by Agora Speakers International Foundation.

If a club ceases its affiliation with Agora, the club remains independently responsible for personal data that it has collected or otherwise processes for its own purposes. Agora remains responsible for personal data retained in Agora's own systems and will process such information in accordance with this Privacy Policy, the applicable retention periods and applicable data-protection law.

The end of a club's affiliation does not automatically require Agora to delete historical records that Agora has a lawful basis to retain, such as records relating to membership history, educational achievements, organisational activities, security, legal obligations or the establishment, exercise or defence of legal claims.

Individuals with questions or requests concerning personal data processed directly by a local Agora Club should contact that club regarding the processing for which the club is responsible. Questions or requests concerning personal data processed through services operated by Agora Speakers International Foundation may be directed to us using the contact details in this Privacy Policy.

9. International transfers

Agora's own servers are currently located in Germany.

However, server location alone does not determine whether all personal data remains within the European Economic Area (“EEA”). Service providers and other recipients may process data in other countries.

Where personal data is transferred outside the EEA to a country that has not been recognised by the European Commission as providing an adequate level of protection, Agora will use an appropriate safeguard permitted by Chapter V GDPR.

This may include:

Current international transfers and safeguards:

Current international transfers may include processing in the United States, including through Amazon Web Services for Amazon SES email delivery and Amazon S3 backups, both currently configured in the US East (N. Virginia) (us-east-1) Region. Cloudflare operates a global network and may also process network and security information outside the EEA. Google, OpenAI, and New Relic may process personal data outside the EEA depending on the services, configurations and subprocessors used.

Where such processing constitutes a restricted international transfer under the GDPR, Agora relies on an applicable European Commission adequacy decision, the European Commission Standard Contractual Clauses, or another transfer mechanism permitted under Chapter V GDPR, together with supplementary safeguards where required.

Where a member voluntarily opts into professional opportunity visibility that permits access by recipients outside the EEA, Agora will clearly explain the access model and applicable transfer mechanism before such disclosure occurs.

10. How long we keep personal data

We retain personal data only for as long as necessary for the purposes for which it was collected and for any additional period required or permitted by law.

Our principal retention periods are:

Data category Retention period
Active member account and core membership information For the duration of membership
Profile information For the duration of membership
Educational achievements and programme records For the duration of membership
Meeting/event participation records For the duration of membership
Communications and support records For the duration of membership, plus 1 year
Authentication/security logs 1 year
Data backups 1 year
Website server logs 1 year
Operational analytics and telemetry data 1 year
Professional opportunity profile Until the member withdraws consent, disables the feature, deletes the relevant information.
Records required for legal/compliance purposes Applicable statutory period
Records concerning legal disputes or investigations Until the matter and applicable limitation periods have concluded

When a member disables the professional opportunity feature, Agora will remove the member's profile from future availability through that feature subject to reasonable technical processing and backup-retention arrangements.

11. Account closure and deletion

Members may request deletion through the “My Data” page or by contacting us.

Deletion requests are subject to the GDPR and other applicable law.

Some information may be retained where necessary for:

Deleting an Agora account or withdrawing professional-opportunity consent cannot automatically remove copies of information already lawfully obtained and independently retained by an external controller.

12. Security

We use appropriate technical and organisational measures designed to protect personal data against:

Measures may include, as appropriate:

13. Cookies and similar technologies

Agora does not use third-party analytics or advertising cookies.

We may use first-party cookies or similar technologies that are necessary to operate our websites and Online Platform. These may be used to:

Where a cookie or similar technology is strictly necessary to provide a service requested by the user or to operate the service securely, it may be used without consent where permitted by applicable law.

Agora's analytics are performed internally using information generated through operation of our own websites and services. We do not use third-party cookies for analytics, advertising or cross-site behavioural tracking.

If Agora introduces non-essential cookies or similar technologies in the future, we will update this Privacy Policy and obtain consent where required by applicable law before using them.

14. Automated decision-making and profiling

Agora does not make decisions producing legal effects, or similarly significant effects, about individuals solely by automated means within the meaning of Article 22 GDPR.

In particular, participation in the professional opportunity feature does not mean that Agora automatically decides whether a member is suitable for a particular paid engagement unless such functionality is later introduced and separately disclosed.

The optional automated analysis of speeches or presentations described in this Policy provides educational feedback and is not used by Agora to make decisions producing legal or similarly significant effects concerning the member.

15. Children and young people

Agora's services and educational programmes are intended to be accessible to people of all ages, including children and young people.

Agora Speakers International Foundation does not impose a universal minimum age for participation in Agora activities. However, participation in a local Agora Club is organised by the relevant club, and each club is responsible for complying with the laws and requirements applicable to minors in the jurisdiction in which that club operates.

As explained in Section 8, Agora Clubs are independent entities that voluntarily affiliate with Agora. Agora Speakers International Foundation does not control the internal management or day-to-day activities of local clubs.

Accordingly, each local Agora Club is responsible for determining and complying with any local requirements applicable to children and young people participating in its activities. Depending on the jurisdiction and the nature of the activity, these requirements may include:

Where a local club independently collects or processes personal data relating to a child—for example through local registration forms, event records, photographs, recordings, mailing lists, messaging applications or other locally selected systems—the club is responsible for establishing the appropriate legal basis and complying with applicable data-protection and child-protection requirements.

Personal data processed by Agora

Agora Speakers International Foundation remains responsible for personal data concerning children and young people that Agora itself processes through the central Agora websites, Online Platform or other services operated by Agora.

We recognise that children's personal data requires particular protection. Where we know that we are processing personal data relating to a child, we take appropriate account of the child's age, the nature of the processing and the risks involved.

Privacy information intended for children will, where appropriate, be presented in language that is clear and reasonably understandable to the relevant age group.

Consent and parental authorisation

Where Agora relies on consent as the legal basis for an online service offered directly to a child, we apply the requirements of Article 8 GDPR and applicable national law.

Under the GDPR, the age at which a child may independently consent to this type of processing may differ between European countries. Member States may set the applicable age between 13 and 16 years.

Where parental or guardian authorisation is legally required, Agora will take reasonable steps appropriate to the nature and risk of the processing to obtain or verify that authorisation.

The requirement for parental authorisation under Article 8 GDPR applies specifically where the relevant processing is based on consent in connection with an information-society service offered directly to a child. Other processing activities may rely on a different lawful basis where appropriate.

Public profiles, recordings and optional features

Additional care should be taken before making information about children publicly available.

Where an Agora feature involves optional public disclosure of a child's personal data, publication of recordings, professional opportunity visibility, or another activity presenting increased privacy risks, Agora may require additional consent or parental/guardian authorisation where required by applicable law.

The Professional Speaking Opportunities feature described in this Policy is available to persons under 18 years of age only with the explicit consent of a parent or legal guardian, regardless of the country in which the member resides.

Similarly, where a speech or presentation involving a minor is uploaded to YouTube or submitted for optional automated analysis using Gemini or OpenAI, Agora will apply the consent, authorisation and safeguarding requirements applicable to the particular processing.

Responsibilities of local clubs

The inclusion of children and young people in Agora's services does not transfer responsibility for local legal compliance from an independent Agora Club to Agora Speakers International Foundation.

Each club must assess the laws applicable to its own activities, including requirements relating to:

Agora may provide guidance or platform functionality intended to assist clubs, but the provision of such guidance or tools does not make Agora responsible for a club's independent compliance obligations.

Questions concerning the handling of a child's personal data by a local club should normally be directed to that club. Questions concerning personal data processed through systems operated by Agora Speakers International Foundation may be directed to Agora using the contact details in this Privacy Policy.

16. Your data-protection rights

Subject to applicable conditions and exceptions, you may have the following rights.

This includes consent to: optional professional opportunity participation;optional cookies, if introduced.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Withdrawing consent to the professional opportunity feature does not affect your Agora membership.

Where Bulgaria is Agora's main GDPR establishment, the relevant lead supervisory authority is: Bulgarian Commission for Personal Data Protection (https://cpdp.bg)

17. How to exercise your rights

If you are an Agora member, you may use the “My Data” area of the Online Platform to access functionality that may include:

You may also contact:

support@agoraspeakers.org

We may request information reasonably necessary to confirm your identity.

We will respond within the periods required by Article 12 GDPR.

18. Information obtained from someone other than you

Where we receive personal data about you from another source, such as:

we provide the information required by Article 14 GDPR within the applicable period unless an exception applies.

19. Accuracy of information

We take reasonable steps to keep personal data accurate where necessary.

Members are encouraged to maintain accurate profile information.

Members participating in the professional opportunity feature should keep professional profile information current so that prospective opportunities are not based on materially outdated information.

20. Links and third-party services

Agora websites or member content may contain links to third-party websites, social networks or services.

Third parties may process personal data under their own privacy notices and as independent controllers.

This includes recruiters, event organisers, prospective customers or other professional contacts once they independently receive or collect a member's information.

21. Changes to this Privacy Policy

We may update this Privacy Policy to reflect:

We will publish the current version on our website and identify its effective date.

Where a change is material, we will take reasonable steps to bring it to the attention of affected individuals.

Where a proposed change requires new consent—including a material expansion of the purposes for which professional opportunity information is disclosed—we will obtain any required new consent before beginning that processing.

22. Contact us

Questions, concerns and requests concerning privacy or the processing of personal data may be sent to:

Agora Speakers International Foundation - Data Protection and Privacy Office
Laguna de Antela 9, 28980 Parla, (Spain)

 
Email: support@agoraspeakers.org