This policy has been updated on May 31, 2021
Minors: It is IIRR’s policy not to solicit knowingly any personally identifiable information from children under the age of 13. Children under 13 are not authorized to make a donation or purchase, sign up for an event or program, or otherwise provide any personally identifiable information without consent from a parent or legal guardian.
II. What about the data that you provide to other IIRR offices outside the U.S.?
Outside the U.S.: Most country-level IIRR offices (“IIRR Country Office”) are responsible for their own compliance with local data protection laws and regulations.
Sharing of information within IIRR network: We may share your data with other IIRR Country Program offices, such as in connection with your participation in any country-level activities, international training, or to enable country-to-country updates where you have expressed interest to update you about its own programs and campaigns. Before we share your personal data, IIRR requires that the Country Office receiving the data (the “Receiving Office”) maintain security controls that will assure that your data is securely stored and accessible only by the appropriately trained persons unless you explicitly inform us that you do not consent the Receiving Office to contact you about programs and activities in the future.
Likewise, when you provide personal data to an IIRR Country Office in connection with your participation in any activities, international training, or volunteer event that IIRR organized, your personal data may be shared between (i) the Receiving Office and any other IIRR Country Office that hosts the volunteer event unless you inform IIRR or the Receiving Office that you do not consent such sharing of your information. The Receiving Office may also contact you about its own programs and activities in the future.
IIRR may request from you, or you may volunteer to provide, your contact information, including your name, mailing address, phone number(s), social media handles and email address(es). We hold and process supporters’ personal data for a number of reasons:
- To keep a record of donations made and actions taken by our supporters and our communications with them
- To send our supporters marketing information about our projects, fundraising activities, and appeals where we have their consent or are otherwise permitted to do so
- To fulfill contractual obligations entered into with supporters
- To support volunteers, such as organizational events or fundraising events
- To support community-based fundraising and campaigning
- To ensure we do not send unwanted information to supporters or members of the public who have informed us they do not wish to be contacted
- To manage supporters’ accounts and provide customer service
- To offer contests, giveaways, or other promotions
- To enforce the Website terms of service
- To perform other functions as described at the time IIRR collects information.
If you make a donation or a purchase with IIRR, or otherwise provide us your information, IIRR may contact you from time to time about opportunities to make additional donations or purchases or to provide you information about upcoming programs.
If you make a donation or a purchase with IIRR or otherwise provide us your information, IIRR may contact you from time to time about opportunities to make additional donations or purchases or to provide you information about upcoming programs, unless you have explicitly expressed that you may not wish to be contacted or receive such information.
IIRR will not trade, share, or sell a donor’s personal information, nor send donor mailings from its U.S. and Country Offices with select third-party sponsors and service providers unless you give your consent for us to do so.
IIRR will contact you for marketing purposes—for example, to keep you up to date on our work, or let you know how you can support that work—only where we have your consent or we are otherwise allowed to do so because of your prior engagement with IIRR, as explained further below (see “Our Reliance on Your Prior Support”).
We will make it easy for you to tell us if you would like to receive marketing communications from us and hear more about our work and how you would like to receive this information. We will not send you marketing material if you tell us that you do not wish to receive it. Instructions for how to do so are below (see “How to control what we send you or update your personal information”).
Duration: If you are a U.S. resident, your ongoing consent is presumed unless you inform us that you wish to be removed from our contact list. If you are not a U.S. resident, IIRR will presume your consent to last for 24 months, unless you withhold consent during this period. After 24 months, in order for us to continue to update you, IIRR will seek your refreshed consent. You can update or withdraw your consent at any time. (See below, “How to control what we send you or update your personal information”). IIRR will presume a longer period of consent in several exceptions: Where you have committed to making a regular (for example, monthly) donation. In this situation, and unless you withdraw your consent, we will treat consent as lasting until you cancel your donation, at which point your consent will expire 24 months after the last donation. This period allows IIRR to keep you up to date with the impact of your contributions, and to ask whether alternative support would be of interest. Where you have notified us that you will be leaving a legacy to IIRR.
Our Reliance on Your Prior Support: You may also receive marketing information from IIRR if you have previously made a similar donation to, or have previously purchased similar goods and services from, IIRR or an IIRR Country Office. However, we will not rely solely on the fact that you once supported us as the basis for our continued marketing to you if you have opted out of receiving emails, newsletters, or other marketing materials in your communications to IIRR or IIRR Country Office.
IIRR may obtain your personal data in the following circumstances:
a. When you give it to IIRR
We will obtain your personal data directly when you make a donation, sign up for one of our events, international training, purchase products from the IIRR online shop, or when you communicate with us directly in some other way.
b. When you give it to an IIRR Country Office
We may obtain your personal information indirectly when you sign up for an event sponsored by an IIRR Country Office. In such cases, the IIRR Country Office will share your data with IIRR to enable us to contact you about your volunteer event or about future IIRR programs and support opportunities. It may also be shared if it is a necessary part of completing a contract or other legal obligations to you in connection with your participation in an event.
c. When you give it to IIRR indirectly
We will obtain your personal data when you communicate to your employer or to IIRR online shop partners during your point of purchase that you affirmatively designate IIRR to receive a personal contribution from you. Sometimes your personal data is collected by an organization working on IIRR’s behalf (for example, a professional fundraising agency). In such cases, the agency is acting on our behalf, and we are the “data controller” responsible for the security and proper processing of your data, just as if you had given it to IIRR directly.
d. When you access IIRR’s sponsored social media
We might also obtain your personal data through your use of social media such as Facebook, Instagram, YouTube, Twitter or LinkedIn, depending on your settings or the privacy policies of these social media and messaging services. To change your settings on these services, please refer to their privacy notices, which will tell you how to do this.
e. When you provide it at a special event or any face-to-face meeting
We will obtain your personal data at offline sites such as community and special events and/or face-to-face meetings.
IIRR will only collect personal data about you that is relevant to the type of transaction or project you have engaged in with us.
For example, we may receive and retain personal information about you when you contact IIRR to make a donation, purchase an item at IIRR online shop, or sign up to any IIRR activities, training or online content (such as newsletters); or when you telephone, email, or write to us by mail from your physical address, or even engage with us via social media channels. In each of these cases, the information we collect is relevant to the type of transaction you are entering into.
Credit card and billing information: In addition to your contact information, IIRR asks for your billing address and credit card or other financial services information when you make a donation or purchase. IIRR uses a third party to process your payments via a secured socket layer connection (TLS 1.2 using SHA 256 encryption) to a secured server that verifies your credit card/bank information. They return a unique tracking number only, which cannot be decrypted to obtain the payment card information, and IIRR never retains your complete credit card number. Only employees who need access to your personal information to perform a specific job are granted access to that information, and IIRR and our banking agent will not share your credit card/bank information with any other third party.
Sensitive Personal Data: We do not collect your “sensitive personal data” (e.g., health or dietary information) unless there is a clear reason for doing so—such as your participation in a sponsored physical event—and then only to the extent such data is required to ensure that we provide appropriate facilities or support to enable you to participate in the event.
All sensitive personal data is stored on a password-protected system to which only a limited number of relevant staff have access. It is deleted when no longer needed by us, is never shared with third parties, and is available to you at any point should you wish to see it.
IIRR will use your personal information for the following purposes:
a. Administrative reasons, including:
- “service administration”, which means that IIRR may contact you for reasons related to administering any donations you have made, the completion of other transactions you have entered into with us, or the activity or online content you have signed up for;
- to confirm receipt of donations (unless you have asked us not to do this), and to say thank you and provide details of how your donation might be used;
- in relation to correspondence you have entered into with us whether by letter, email, text, social media, message board or any other means and to contact you about any content you provide;
- for internal record keeping so as to keep a record of your relationship with us;
- to complete sales transactions you have entered into with us, for example at IIRR online shop;
- to implement any instructions you give us with regard to withdrawing consent to send marketing information;
- to use IP addresses to identify the location of users, to block disruptive use, and to establish the number of visits from different countries
b. Marketing and fundraising
Sections III and IV above describe what data may be used for marketing and fundraising purposes and under what circumstances.
IIRR will not share your personal data with IIRR partner organizations as well as other companies. However, we may process your data for the ff. reasons:
IIRR suppliers: We may need to share your information with service providers who help deliver our projects and fundraising activities. These “data processors” will only act under our strict instruction and are subject to contractual obligations containing strict data protection clauses. We do not allow these organizations to use your data for their own purposes or disclose it to other third parties without our consent, and we will take all reasonable care to ensure that they keep your data secure.
Compliance with the law, responding to legal requests, preventing harm, and protection of our rights: We may need to disclose your data to courts, law enforcement or governmental authorities, or authorized third parties, if and to the extent we are required or permitted to do so by law or if such disclosure is reasonably necessary:
(a) comply with our legal obligations,
(b) to comply with legal process and to respond to claims asserted against NGOsource,
(c) to respond to verified requests relating to a criminal investigation or alleged or suspected illegal activity or any other activity that may expose us, you, or any other of our users to legal liability,
(e) to protect the rights, property, or personal safety of IIRR, its employees, its users, customers, or members of the public.
IX. How to control what we send you and update your personal information
The accuracy of your information is important to us. We want to ensure that we can communicate with you in ways that you are happy with and provide you with information that is of interest.
If you wish to change how we communicate with you or update the information we hold, then please contact us:
To amend your contact preferences for any type of communication, email us at firstname.lastname@example.org, or write to us at: 01 99 Wall Street, Suite 1258 New York, NY 10005, USA (to amend your preferences for any communication channel);
To amend your contact preferences for any type of communication, email us email@example.com, or write to us at: 01 W. 26th St. #325-1, New York, NY 10001, USA (to amend your preferences for any communication channel);
X. How IIRR keeps your data safe
We ensure that there are appropriate technical controls in place to protect your personal details. For example, our online forms that ask for personal information are stored on password-protected and routinely monitored networks.