This policy has been updated on September 30, 2019
Minors: It is IIRR’s policy not to solicit knowingly any personally identifiable information from children under the age of 13. Children under 13 are not authorized to make a donation or purchase, sign up for an event or program, or otherwise provide any personally identifiable information without consent from a parent or legal guardian.
Sharing of information within IIRR network: We may share your data with other IIRR Country Program offices, such as in connection with your participation in any country-level activities, international training, or to enable country-to-country updates where you have expressed interest to update you about its own programs and campaigns. Before we share your personal data, IIRR requires that the Country Office receiving the data (the “Receiving Office”) maintain security controls that will assure that your data is securely stored and accessible only by appropriately trained personnel. Unless you inform us that you do not consent, the Receiving Office may in the future contact you about programs and activities.
Likewise, when you provide personal data to an IIRR Country Office in connection with your participation in any activities, international training or volunteer event that IIRR organized, your personal data may be shared between (i) the Receiving Office and any other IIRR Country Office that hosts the volunteer event unless you inform IIRR or the Receiving Office that you do not consent such sharing of your information. The Receiving Office may also contact you about its own programs and activities in the future.
- To keep a record of donations made and actions taken by our supporters and our communications with them
- To send our supporters marketing information about our projects, fundraising activities and appeals where we have their consent or are otherwise permitted to do so
- To fulfill contractual obligations entered into with supporters
- To support volunteers, such as organizational events or fundraising events
- To support community based fundraising and campaigning
- To ensure we do not send unwanted information to supporters or members of the public who have informed us they do not wish to be contacted
- To manage supporters’ accounts and provide customer service
- To offer contests, giveaways or other promotions
- To enforce the Website terms of service
- To perform other functions as described at the time IIRR collects information.
If you make a donation or a purchase with IIRR, or otherwise provide us your information, IIRR may contact you from time to time about opportunities to make additional donations or purchases or to provide you information about upcoming programs.
IIRR may also share data from its U.S. and Country Offices resident supporters with select third-party sponsors and service providers based on our assessment that the products or services may be of interest to these supporters or that the sponsor or provider can help IIRR identify what services or appeals may be of interest to our supporters. We may also provide our U.S. and Country Office resident supporters with information about services from third parties. If you do not wish your data to be used in this way, you may follow the instructions for modifying your consent (see below, “How to control what we send you or update your personal information”).
We will make it easy for you to tell us if you would like to receive marketing communications from us and hear more about our work and the ways in which you would like to receive this information. We will not send you marketing material if you tell us that you do not wish to receive it. Instructions for how to do so are below (see “How to control what we send you or update your personal information”).
Duration: If you are a U.S. resident, your ongoing consent is presumed unless you inform us that you wish to be removed from our contact list.
If you are not a U.S. resident, IIRR will presume your consent to last for 24 months, unless you withhold consent during this period. After 24 months, in order for us to continue to update you, IIRR will seek your refreshed consent. You can update or withdraw your consent at any time. (See below, “How to control what we send you or update your personal information”). IIRR will presume a longer period of consent in several exceptions:
- Where you have committed to making a regular (for example, monthly) donation. In this situation, and unless you withdraw your consent, we will treat consent as lasting until you cancel your donation, at which point your consent will expire 24 months after the last donation. This period allows IIRR to keep you up to date with the impact of your contributions, and to ask whether alternative support would be of interest.
- Where you have notified us that you will be leaving a legacy to IIRR.
Our Reliance on Your Prior Support: You may also receive marketing information from IIRR if you have previously made a similar donation to, or have previously purchased similar goods and services from, IIRR or a IIRR Country Office. However, we will not rely solely on the fact that you once supported us as the basis for our continued marketing to you if you have opted out of receiving emails, newsletters, or other marketing materials in your communications to IIRR or IIRR Country Office.
IIRR may obtain your personal data in the following circumstances:
a. When you give it to IIRR
We will obtain your personal data directly when you make a donation, sign up for one of our events, international training, purchase products from the IIRR online shop, or when you communicate with us directly in some other way.
b. When you give it to an IIRR Country Office
We may obtain your personal information indirectly when you sign up for an event sponsored by an IIRR Country Office. In such cases, the IIRR Country Office will share your data with IIRR to enable us to contact you about your volunteer event or about future IIRR programs and support opportunities. It may also be shared if it is a necessary part of completing a contract or other legal obligations to you in connection with your participation in an event.
c. When you give it to IIRR indirectly
We will obtain your personal data when you communicate to your employer or to IIRR online shop partner during your point of purchase that you affirmatively designate IIRR to receive a personal contribution from you.
Sometimes your personal data is collected by an organization working on IIRR’s behalf (for example, a professional fundraising agency). In such cases, the agency is acting on our behalf, and we are the “data controller” responsible for the security and proper processing of your data, just as if you had given it to IIRR directly.
d. When you access IIRR’s sponsored social media
We might also obtain your personal data through your use of social media such as Facebook, Instagram, YouTube, Twitter or LinkedIn, depending on your settings or the privacy policies of these social media and messaging services. To change your settings on these services, please refer to their privacy notices, which will tell you how to do this.
IIRR will only collect personal data about you that is relevant to the type of transaction or project you have engaged in with us.
For example, we may receive and retain personal information about you when you contact IIRR to make a donation, purchase an item at IIRR online shop, or sign up to any IIRR activities, training or online content (such as newsletters); or when you telephone, email, or write to us, or engage with us via social media channels. In each of these cases, the information we collect is relevant to the type of transaction you are entering into.
Credit card and billing information: In addition to your contact information, when you make a donation or purchase, IIRR asks for your billing address and credit card or other financial services information. IIRR uses a third-party to process your payments via a secured socket layer connection (TLS 1.2 using SHA 256 encryption) to a secured server that verifies your credit card/bank information. They return a unique tracking number only, which cannot be decrypted to obtain the payment card information, and IIRR never retains your complete credit card number. Only employees who need access to your personal information to perform a specific job are granted access to that information, and IIRR and our banking agent will not share your credit card/bank information with any other third party.
Sensitive Personal Data: We do not collect your “sensitive personal data” (e.g., health or dietary information) unless there is a clear reason for doing so—such as your participation in a sponsored physical event—and then only to the extent such data is required to ensure that we provide appropriate facilities or support to enable you to participate in the event.
All sensitive personal data is stored on a password-protected system to which only a limited number of relevant staff have access. It is deleted when no longer needed by us, is never shared with third parties, and is available to you at any point should you wish to see it.
IIRR will use your personal information for the following purposes:
a. Administrative reasons, including:
- “service administration”, which means that IIRR may contact you for reasons related to administering any donations you have made, the completion of other transactions you have entered into with us, or the activity or online content you have signed up for;
- to confirm receipt of donations (unless you have asked us not to do this), and to say thank you and provide details of how your donation might be used;
- in relation to correspondence you have entered into with us whether by letter, email, text, social media, message board or any other means, and to contact you about any content you provide;
- for internal record keeping so as to keep a record of your relationship with us;
- to complete sales transactions you have entered into with us, for example at IIRR online shop;
- to implement any instructions you give us with regard to withdrawing consent to send marketing information;
- to use IP addresses to identify the location of users, to block disruptive use and to establish the number of visits from different countries
b. Marketing and fundraising
Sections III and IV above describe what data may be used for marketing and fundraising purposes and under what circumstances.
IIRR may share your personal data with IIRR partner organizations as well as other companies whose products and services may be of interest to you. In these cases, we may also provide you with information about services from third parties, unless you inform us that you do not want to receive this information.
IIRR suppliers: We may need to share your information with service providers who help deliver our projects and fundraising activities. These “data processors” will only act under our instruction and are subject to contractual obligations containing strict data protection clauses. We do not allow these organizations to use your data for their own purposes or disclose it to other third parties without our consent, and we will take all reasonable care to ensure that they keep your data secure.
The accuracy of your information is important to us. We want to ensure that we are able to communicate with you in ways that you are happy with, and to provide you with information that is of interest.
If you wish to change how we communicate with you, or update the information we hold, then please contact us:
To amend your contact preferences for any type of communication, email us firstname.lastname@example.org, or write to us at: 01 W. 26th St. #325-1, New York, NY 10001, USA (to amend your preferences for any communication channel);
We ensure that there are appropriate technical controls in place to protect your personal details. For example, our online forms that ask for personal information are stored on networks that are password-protected and routinely monitored.