Last updated October 17, 2024
This privacy notice for MACH Alliance, Inc ("we," "us," or "our"), describes how and why we might collect, store, use, and/or share ("process") your information when you use our services ("Services"), such as when you:
Visit our website at http://www.machalliance.org, or any website of ours that links to this privacy notice
We are participating in the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (collectively the “Data Privacy Framework” or “DPF”).
We are self-certified as compliant with the Data Privacy Framework Program administered by the US Department of Commerce International Trade Administration, as evidenced by and in accordance with the EU-US Privacy Notice, regarding the processing of personal data received from EEA member countries in reliance on the EU-U.S. DPF, from the UK (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF; and the Swiss-U.S. Data Privacy Framework Principles regarding the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. The DPF is set forth here. In the event of any conflict or inconsistency with the terms of this Privacy Policy and the terms of EU-US Privacy Notice, the terms of the EU-US Privacy Notice will control.
We are committed to the principles of the Data Privacy Framework with respect to all personal data collected from the European Union, the United Kingdom, and Switzerland.
We are subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
It is possible under certain conditions for you to invoke binding arbitration.
Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@machalliance.org
This summary provides key points from our privacy notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.
What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.
Do we process any sensitive personal information? We do not process sensitive personal information.
Do we receive any information from third parties? We may receive information from public databases, marketing partners, social media platforms, and other outside sources. Learn more about information collected from other sources.
How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.
In what situations and with which types of parties do we share personal information? We may share information in specific situations and with specific categories of third parties. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We have organizational and technical processes and procedures in place to protect your personal information. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Learn more about how we keep your information safe.
What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.
How do you exercise your rights? The easiest way to exercise your rights is by submitting a data subject access request, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.
Want to learn more about what we do with any information we collect? Review the privacy notice in full.
Personal information you disclose to us
In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.
Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:
Sensitive Information. We do not process sensitive information.
Payment Data. We may collect data necessary to process your payment if you make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is stored by Stripe . You may find their privacy notice link(s) here: https://stripe.com/gb/privacy.
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.
Information automatically collected
In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.
We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information. This information is primarily needed to maintain the security and operation of our Services, and for our internal analytics and reporting purposes.
Like many businesses, we also collect information through cookies and similar technologies.
The information we collect includes:
Information collected from other sources
In Short: We may collect limited data from public databases, marketing partners, and other outside sources.
In order to enhance our ability to provide relevant marketing, offers, and services to you and update our records, we may obtain information about you from other sources, such as public databases, joint marketing partners, affiliate programs, data providers, and from other third parties. This information includes mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), Internet Protocol (IP) addresses, social media profiles, social media URLs, and custom profiles, for purposes of targeted advertising and event promotion.
Residents of Europe and UK
If you reside in the European Union, UK, Switzerland, Norway, Lichtenstein, or Iceland, and are protected by European data protection requirements, we will treat your personal data in compliance with our EU-US Privacy Notice (below) and applicable law including the General Data Protection Regulation (GDPR).
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your consent.
We process your personal information for a variety of reasons, depending on how you interact with our Services, including:
To save or protect an individual's vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.
If you are located in the EU or UK, this section applies to you.
The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:
If you are located in Canada, this section applies to you.
We may process your information if you have given us specific permission (i.e., express consent) to use your personal information for a specific purpose, or in situations where your permission can be inferred (i.e., implied consent). You can
withdraw your consent
at any time.
In some exceptional cases, we may be legally permitted under applicable law to process your information without your consent, including, for example:
Other Users. When you share personal information (for example, by posting comments, contributions, or other content to the Services) or otherwise interact with public areas of the Services, such personal information may be viewed by all users and may be publicly made available outside the Services in perpetuity. Similarly, other users will be able to view descriptions of your activity, communicate with you within our Services, and view your profile.
In Short: We may share information in specific situations described in this section and/or with the following categories of third parties.
Vendors, Consultants, and Other Third-Party Service Providers. We may share your data with third-party vendors, service providers, contractors, or agents ("third parties") who perform services for us or on our behalf and require access to such information to do that work. We have contracts in place with our third parties, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct. The categories of third parties we may share personal information with are as follows:
We also may need to share your personal information in the following situations:
In Short: We may use cookies and other tracking technologies to collect and store your information.
We may use cookies and similar tracking technologies (like web beacons and pixels) to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Notice.
In Short: We may transfer, store, and process your information in countries other than your own.
Our servers are located in the United States. If you are accessing our Services from outside the United States, please be aware that your information may be transferred to, stored, and processed by us in our facilities and by those third parties with whom we may share your personal information (see "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" above), in the United States, and other countries.
If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this privacy notice and applicable law.
European Commission's Standard Contractual Clauses:
We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations. Our Standard Contractual Clauses can be provided upon request. We have implemented similar appropriate safeguards with our third-party service providers and partners and further details can be provided upon request.
In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this privacy notice unless otherwise required by law.
We will only keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). No purpose in this notice will require us keeping your personal information for longer than six (6) months past the termination of the user's account.
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize such information, or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
In Short: We aim to protect your personal information through a system of organizational and technical security measures.
We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Although we will do our best to protect your personal information, transmission of personal information to and from our Services is at your own risk. You should only access the Services within a secure environment.
In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly solicit data from or market to children under 18 years of age. By using the Services, you represent that you are at least 18 or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Services. If we learn that personal information from users less than 18 years of age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data from our records. If you become aware of any data we may have collected from children under age 18, please contact us at info@machalliance.org.
In Short: In some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information. You may review, change, or terminate your account at any time.
In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making. In certain circumstances, you may also have the right to object to the processing of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below.
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and you believe we are unlawfully processing your personal information, you also have the right to complain to your Member State data protection authority or UK data protection authority.
If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent: If we are relying on your consent to process your personal information, which may be express and/or implied consent depending on the applicable law, you have the right to withdraw your consent at any time. You can withdraw your consent at any time by contacting us by using the contact details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below or updating your preferences.
However, please note that this will not affect the lawfulness of the processing before its withdrawal nor, when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
Opting out of marketing and promotional communications: You can unsubscribe from our marketing and promotional communications at any time by clicking on the unsubscribe link in the emails that we send, or by contacting us using the details provided in the section "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?" below. You will then be removed from the marketing lists. However, we may still communicate with you — for example, to send you service-related messages that are necessary for the administration and use of your account, to respond to service requests, or for other non-marketing purposes.
Account Information
If you would at any time like to review or change the information in your account or terminate your account, you can:
Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases. However, we may retain some information in our files to prevent fraud, troubleshoot problems, assist with any investigations, enforce our legal terms and/or comply with applicable legal requirements.
Cookies and similar technologies: Most Web browsers are set to accept cookies by default. If you prefer, you can usually choose to set your browser to remove cookies and to reject cookies. If you choose to remove cookies or reject cookies, this could affect certain features or services of our Services.
If you have questions or comments about your privacy rights, you may email us at info@machalliance.org.
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this privacy notice.
In Short: If you are a resident of California, Colorado, Connecticut, Utah or Virginia, you are granted specific rights regarding access to your personal information.
What categories of personal information do we collect?
We have collected the following categories of personal information in the past twelve (12) months:
Category | Examples | Collected |
A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name |
YES
|
B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information |
YES
|
C. Protected classification characteristics under state or federal law | Gender and date of birth |
YES
|
D. Commercial information | Transaction information, purchase history, financial details, and payment information |
NO
|
E. Biometric information | Fingerprints and voiceprints |
NO
|
F. Internet or other similar network activity | Browsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisements |
YES
|
G. Geolocation data | Device location |
YES
|
H. Audio, electronic, visual, thermal, olfactory, or similar information | Images and audio, video or call recordings created in connection with our business activities |
NO
|
I. Professional or employment-related information | Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us |
YES
|
J. Education Information | Student records and directory information |
NO
|
K. Inferences drawn from collected personal information | Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics |
YES
|
L. Sensitive personal Information |
|
NO
|
We will use and retain the collected personal information as needed to provide the Services or for:
We may also collect other personal information outside of these categories through instances where you interact with us in person, online, or by phone or mail in the context of:
How do we use and share your personal information?
Learn about how we use your personal information in the section, "HOW DO WE PROCESS YOUR INFORMATION?"
We collect and share your personal information through:
Will your information be shared with anyone else?
We may disclose your personal information with our service providers pursuant to a written contract between us and each service provider. Learn more about how we disclose personal information to in the section, "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
We may use your personal information for our own business purposes, such as for undertaking internal research for technological development and demonstration. This is not considered to be "selling" of your personal information.
We have disclosed the following categories of personal information to third parties for a business or commercial purpose in the preceding twelve (12) months:
The categories of third parties to whom we disclosed personal information for a business or commercial purpose can be found under "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?"
We have sold or shared the following categories of personal information to third parties in the preceding twelve (12) months:
The categories of third parties to whom we sold personal information are:
The categories of third parties to whom we shared personal information with are:
California Residents
California Civil Code Section 1798.83, also known as the "Shine The Light" law permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.
If you are under 18 years of age, reside in California, and have a registered account with the Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).
CCPA Privacy Notice
This section applies only to California residents. Under the California Consumer Privacy Act (CCPA), you have the rights listed below.
The California Code of Regulations defines a "residents" as:
(1) every individual who is in the State of California for other than a temporary or transitory purpose and
(2) every individual who is domiciled in the State of California who is outside the State of California for a temporary or transitory purpose
All other individuals are defined as "non-residents."
If this definition of "resident" applies to you, we must adhere to certain rights and obligations regarding your personal information.
Your rights with respect to your personal data
Right to request deletion of the data — Request to delete
You can ask for the deletion of your personal information. If you ask us to delete your personal information, we will respect your request and delete your personal information, subject to certain exceptions provided by law, such as (but not limited to) the exercise by another consumer of his or her right to free speech, our compliance requirements resulting from a legal obligation, or any processing that may be required to protect against illegal activities.
Right to be informed — Request to know
Depending on the circumstances, you have a right to know:
In accordance with applicable law, we are not obligated to provide or delete consumer information that is de-identified in response to a consumer request or to re-identify individual data to verify a consumer request.
Right to Non-Discrimination for the Exercise of a Consumer’s Privacy Rights
We will not discriminate against you if you exercise your privacy rights.
Right to Limit Use and Disclosure of Sensitive Personal Information
We do not process consumer's sensitive personal information.
Verification process
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. These verification efforts require us to ask you to provide information so that we can match it with information you have previously provided us. For instance, depending on the type of request you submit, we may ask you to provide certain information so that we can match the information you provide with the information we already have on file, or we may contact you through a communication method (e.g., phone or email) that you have previously provided to us. We may also use other verification methods as the circumstances dictate.
We will only use personal information provided in your request to verify your identity or authority to make the request. To the extent possible, we will avoid requesting additional information from you for the purposes of verification. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes. We will delete such additionally provided information as soon as we finish verifying you.
Other privacy rights
You can opt out from the selling or sharing of your personal information by disabling cookies in Cookie Preference Setting and clicking on the Do Not Sell or Share My Personal Information link on our homepage.
To exercise these rights, you can contact us by submitting a data subject access request, by email at info@machalliance.org, or by referring to the contact details at the bottom of this document. If you have a complaint about how we handle your data, we would like to hear from you.
Colorado Residents
This section applies only to Colorado residents. Under the Colorado Privacy Act (CPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
We sell personal data to third parties or process personal data for targeted advertising. You can opt out from the selling of your personal data, targeted advertising, or profiling by disabling cookies in Cookie Consent Preferences To submit a request to exercise any of the other rights described above, please email info@machalliance.org or submit a data subject access request.
If we decline to take action regarding your request and you wish to appeal our decision, please email us atinfo@machalliance.org. Within forty-five (45) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.
Connecticut Residents
This section applies only to Connecticut residents. Under the Connecticut Data Privacy Act (CTDPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
We sell personal data to third parties or process personal data for targeted advertising. You can opt out from the selling of your personal data, targeted advertising, or profiling by disabling cookies in Cookie Preference Setting. To submit a request to exercise any of the other rights described above, please email info@machalliance.org or submit a data subject access request.
If we decline to take action regarding your request and you wish to appeal our decision, please email us at info@machalliance.org. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions.
Utah Residents
This section applies only to Utah residents. Under the Utah Consumer Privacy Act (UCPA), you have the rights listed below. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law.
We sell personal data to third parties or process personal data for targeted advertising. You can opt out from the selling of your personal data or targeted advertising by disabling cookies in Cookie Preference Setting. To submit a request to exercise any of the other rights described above, please email info@machalliance.org or submit a data subject access request.
Virginia Residents
Under the Virginia Consumer Data Protection Act (VCDPA):
"Consumer" means a natural person who is a resident of the Commonwealth acting only in an individual or household context. It does not include a natural person acting in a commercial or employment context.
"Personal data" means any information that is linked or reasonably linkable to an identified or identifiable natural person. "Personal data" does not include de-identified data or publicly available information.
"Sale of personal data" means the exchange of personal data for monetary consideration.
If this definition of "consumer" applies to you, we must adhere to certain rights and obligations regarding your personal data.
Your rights with respect to your personal data
We sell personal data to third parties or process personal data for targeted advertising. Please see the following section to find out how you can opt out from further selling or sharing of your personal data for targeted advertising or profiling purposes.
Exercise your rights provided under the Virginia VCDPA
You can opt out from the selling of your personal data, targeted advertising, or profiling by disabling cookies in Cookie Preference Setting. You may contact us by email at info@machalliance.org or submit a data subject access request.
If you are using an authorized agent to exercise your rights, we may deny a request if the authorized agent does not submit proof that they have been validly authorized to act on your behalf.
Verification process
We may request that you provide additional information reasonably necessary to verify you and your consumer's request. If you submit the request through an authorized agent, we may need to collect additional information to verify your identity before processing your request.
Upon receiving your request, we will respond without undue delay, but in all cases, within forty-five (45) days of receipt. The response period may be extended once by forty-five (45) additional days when reasonably necessary. We will inform you of any such extension within the initial 45-day response period, together with the reason for the extension.
Right to appeal
If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please email us at info@machalliance.org. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney General to submit a complaint.
In Short: You may have additional rights based on the country you reside in.
AustraliaandNew Zealand
We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020 (Privacy Act).
This privacy notice satisfies the notice requirements defined in both Privacy Acts, in particular: what personal information we collect from you, from which sources, for which purposes, and other recipients of your personal information.
If you do not wish to provide the personal information necessary to fulfill their applicable purpose, it may affect our ability to provide our services, in particular:
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?"
If you believe we are unlawfully processing your personal information, you have the right to submit a complaint about a breach of the Australian Privacy Principles to the Office of the Australian Information Commissioner and a breach of New Zealand's Privacy Principles to the Office of New Zealand Privacy Commissioner.
Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section "HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?"
If you are unsatisfied with the manner in which we address any complaint with regard to our processing of personal information, you can contact the office of the regulator, the details of which are:
The Information Regulator (South Africa)
General enquiries: enquiries@inforegulator.org.za
Complaints (complete POPIA/PAIA form 5): PAIAComplaints@inforegulator.org.za & POPIAComplaints@inforegulator.org.za
This EU-US Privacy Notice explains how we adhere to the privacy principles of the Data Privacy Framework with respect to transfers of personal information from the European Union, as well as Norway, Lichtenstein, and Iceland (collectively, “EU”), the United Kingdom, and Switzerland, to the United States. We are subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
The United States Department of Commerce and the European Commission have agreed on a set of Data Privacy Framework Principles, to enable U.S. companies to satisfy the requirement under European Union law that adequate protection be given to personal information transferred from the EU to the United States. The UK has also recognized the Data Privacy Framework Principals as providing adequate data protection for UK citizens whose personal information is transferred from the UK to the United States. The United States Department of Commerce and the government of Switzerland have agreed on a similar set of Data Privacy Framework Principles, to enable U.S. companies to satisfy the requirement under applicable Swiss law that adequate protection be given to personal information transferred from Switzerland to the United States.
We comply with the Data Privacy Framework Principals regarding the collection, use, and retention of personal information transferred from the European Union, United Kingdom, and Switzerland to the United States. We have certified to the Department of Commerce that we adhere to the Data Privacy Framework Principles.
A. Scope
This EU-US Privacy Notice applies to all personal information received by us in the United States from the EU and from Switzerland, in any format, including electronic, paper or verbal.
B. Definitions
For purposes of this EU-US Privacy Notice, the following definitions will apply:
· “agent” means any third party that collects or uses personal information under our instructions and for us, or to which we disclose personal information for use on our behalf.
· “personal information” and “personal data” means any data, information or data/information set(s) that identifies or could be used by or on behalf of us to identify an individual. Personal information does not include information that is encoded or anonymized, or publicly available information that has not been combined with non-public personal information.
· “sensitive personal information” means personal information that reveals race, ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, views or activities, that concerns health or sex life, ideological views or activities, information on social security measures or benefits, or information on criminal or administrative proceedings and sanctions other than in the context of pending proceedings. In addition, we will treat as sensitive personal information any information received from a third party where that third party treats and explicitly identifies the information as sensitive within the same meaning as used here.
Data Privacy Framework Principles
The privacy principles in this EU-US Privacy Notice have been developed based on the Data Privacy Framework Principles. For purposes of these principles and this Data Privacy Framework Principles section, the term “EU” includes Switzerland.
(i) Notice. Where we collect personal information directly from individuals in the EU, we will inform such individuals about the purposes for which we collect and use personal information about them, the types of non–agent third parties to which we disclose that information, the choices and means, if any, we offer individuals for limiting the use and disclosure of personal information about them, and how to contact us. Notice will be provided in clear and conspicuous language when individuals are first asked to provide personal information, or as soon as practicable thereafter, and in any event before we use or disclose the information for a purpose other than that for which it was originally collected.
Where we receive personal information from our subsidiaries, affiliates, or other entities in the EU, we will use and disclose such information in accordance with the notices provided by such entities and the choices made by the individuals to whom such personal information relates.
(ii) Choice. We will offer individuals the opportunity to choose (opt-out) whether their personal information is (a) to be disclosed to a non-agent third party, or (b) to be used for a purpose that is
materially different than the purpose for which it was originally collected or subsequently authorized by the individual.
In relation to sensitive personal information, we do not solicit such information and there is no need to disclose such information in order to use our services or sites. If we elect in the future to solicit such information, we will give individuals the opportunity to affirmatively and explicitly (opt-in) consent to the disclosure of such solicited information to a non-agent third party or the use of the information for a purpose other than the purpose for which it was originally collected or subsequently authorized by the individual. We will provide individuals with reasonable mechanisms to exercise their choices.
(iii) Data Integrity. We will use personal information only in ways that are compatible with and relevant to the purposes for which it was collected or subsequently authorized by the individual. We will take reasonable steps to ensure that personal information is reliable to its intended use, accurate, complete, and current. We will remain compliant for as long as we retain personal information. Personal information will be retained in a form identifying or making identifiable an individual only for so long as necessary to process such information, subject to our right to retain such information for longer periods for the time and to the extent such processing reasonably serves the purposes of archiving in the public interest, journalism, literature and art, scientific or historical research, and statistical analysis.
(iv) Accountability for Onward Transfer. To transfer personal data to an agent, we will: (a) transfer such data only for limited and specified purposes; (b) ascertain that the agent is obligated to provide at least the same level of privacy protection as is required by the Data Privacy Framework Principles; (c) take reasonable and appropriate steps to ensure that the agent effectively processes the personal information transferred in a manner consistent with our obligations under the Data Privacy Framework Principles; (d) require the agent to notify us if it makes a determination that it can no longer meet its obligation to provide the same level of protection as is required by the Data Privacy Framework Principles; (e) upon notice, including under (d), take reasonable and appropriate steps to stop and remediate unauthorized processing; (f) provide a summary or a representative copy of the relevant privacy provisions of its contract with that agent to the Department of Commerce upon request; and (g) enter into enforceable contracts with agents consistent with this policy.
We will undertake to obtain assurances from our agents that they will safeguard personal information consistent with this policy. Examples of appropriate assurances that may be provided by agents include: (h) a contract obligating the agent to provide at least the same or substantially similar level of protection as is required by the relevant Data Privacy Framework Principles, (i) such agent being certified as Data Privacy Framework Principles-compliant, (j) such agent being subject to the EU Data Protection Directive, or (k) such agent being subject to another EU or Swiss adequacy finding (e.g., companies located in Canada). Where we have knowledge that an agent is using or disclosing personal information in a manner contrary to this policy, we will take reasonable steps to prevent or stop such use or disclosure.
(v) Access and Correction. Upon request, we will grant individuals reasonable access to personal information that it holds about them. In addition, we will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete, or that has been processed in violation of the Data Privacy Framework Principles, except where the burden or expense of providing access would be disproportionate to the risks to the individual’s privacy in the case in question, or where the rights of persons other than the individual would be violated.
(vi) Security. We will take reasonable and appropriate measures to protect personal information in our possession from loss, misuse and unauthorized access, disclosure, alteration, and destruction, taking into account the risks involved in the processing and nature of the personal data.
(vii) Enforcement. We will conduct compliance reviews of our relevant privacy practices to verify adherence to this EU-US Privacy Notice and appropriate employee and agent training as necessary. Any employee or agent of ours that we determine is in violation of this policy will be subject to disciplinary action up to and including termination of employment or service. We will be responsible if our agent processes personal information in a manner inconsistent with the Data Privacy Framework Principles, unless we prove that we are not responsible for the event giving rise to the damage.
(viii) Dispute Resolution. Any questions or concerns regarding the use or disclosure of personal information should be directed to the Data Processing Officer. We will investigate and attempt to resolve complaints and disputes regarding use and disclosure of personal information by reference to this policy in an expeditious manner, and at no cost to the individual.
We have further committed to refer unresolved Data Privacy Framework complaints to JAMS (jamsadr.com), an alternative dispute resolution provider located in the United States, which serves as our third-party dispute resolution provider for Data Privacy Framework Principles-related disputes. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit JAMS for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Individuals may submit complaints on an individualized basis (and not purporting to be acting in a representative capacity or on behalf of a class) to JAMS. No damages, fees, or other remedies are available. Arbitrators will have the authority only to award individual-specific non-monetary equitable relief (such as access, correction, deletion, or return of the individual data in question). Each party will bear its own attorneys fees, subject to the rules of JAMS.
In addition, individuals may submit disputes to binding arbitration who first comply with pre-arbitration requirements. Arbitration may not be invoked and is not available if the individual’s same claimed violation of the Data Privacy Framework Principles: (a) has previously been subject to binding arbitration; (b) was the subject of a final judgment entered in a court action to which the individual was a party; or (c) was previously settled by the parties. In addition, arbitration is not available if an EU Data Protection Authority: (d) has authority under sections III.5 or III.9 of the Data Privacy Framework Principles; or (e) has the authority to resolve the claimed violation directly with us.
Limitation
Adherence to this EU-US Privacy Notice is limited to the extent (i) required to respond to a legal or ethical obligation; (ii) necessary to meet national security, public interest, or law enforcement obligations; and (iii) expressly permitted by an applicable law, rule or regulation.
Privacy Policy
We recognize the importance of maintaining the privacy of information collected online and via applications, and have created this policy governing the treatment of personal information collected through web sites, services, operations and applications that we operate. The policy reflects additional legal requirements and evolving standards with respect to privacy, and in fact, we utilize this policy in facilitating adherence to the Data Privacy Framework Principles and applicable EU data protection laws. As such, this EU-US Privacy Notice and the Privacy Policy should be construed harmoniously wherever possible; however, with respect to personal information that is transferred from the EU or Switzerland to the US, the Privacy Policy is subordinate to this EU-US Privacy Notice.
Contact Information
Questions or comments regarding this policy should be submitted to the Data Protection Officer as set forth below.
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this privacy notice from time to time. The updated version will be indicated by an updated "Revised" date and the updated version will be effective as soon as it is accessible. If we make material changes to this privacy notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this privacy notice frequently to be informed of how we are protecting your information.
If you have questions or comments about this notice, you may contact our Office of Data Protection by email at info@machalliance.org, or contact us by post at:
MACH Alliance, Inc
Office of Data Protection
48 Wall Street
Suite 1100
New York, NY 10005
United States
You have the right to request access to the personal information we collect from you, change that information, or delete it. To request to review, update, or delete your personal information, please fill out and submit a data subject access request.