PPSA Statement of Privacy ("Privacy Statement")
Effective Date: August 2019
In keeping with the goals and objectives of The Project for Privacy & Surveillance Accountability ("PPSA"), we are committed to the highest degree of respect for the privacy of our members, visitors to our websites and attendees of our events. In this Privacy Statement, we use “we,” “us” or “our” to refer to ISOC and “you” or “your” to refer to you, the user, member or visitor to our web sites. For certain purposes of this Privacy Statement, we distinguish between individuals who choose to register and join PPSA as a member (“Members”) and users of our websites (the “Sites”, including protectprivacynow.org) who simply visit the Sites (“Visitors”) and do not choose to register as Members. Unless indicated otherwise, all provisions of this Privacy Statement apply to Visitors and Members. This Privacy Statement applies to all of our Sites.
When we do not rely on your consent to this Privacy Statement for use of “Your Data” (as defined below), we will tell you so. By accessing and using any of the Sites as a Visitor, you expressly and knowingly consent to the information collection and use practices as described in this Privacy Statement.
Our commitment to your privacy, is based on the following principles which we apply to our use of both your personally identifiable data (“Personal Data”) and to certain anonymous information we collect when you visit our Sites (“Technical Information”, and together with Personal Data, “Your Data”):
When we do not rely on your consent to this Privacy Statement for use of “Your Data” (as defined below), we will tell you so. By accessing and using any of the Sites as a Visitor, you expressly and knowingly consent to the information collection and use practices as described in this Privacy Statement.
Our commitment to your privacy, is based on the following principles which we apply to our use of both your personally identifiable data (“Personal Data”) and to certain anonymous information we collect when you visit our Sites (“Technical Information”, and together with Personal Data, “Your Data”):
- We will describe Your Data we will collect;
- We will inform you clearly about our collection and use of Your Data;
- We will either seek your express informed consent or rely on other legally permissible bases for the use of Your Data – either way, we will inform you of the basis for our use of Your Data;
- We will give you control over the privacy preferences that apply to Your Data, including the rights to (a) change your mind about our use, (b) have access to change or correct inaccurate aspects of Your Data, and (c) require that we delete all or parts of Your Data;
- We will not sell or rent Your Personal Data to others;
- We endeavor to maximize the protection of Your Data, and provide you with prompt notice in the unlikely event that a data loss incident or breach occurs; and
- We will endeavor to be completely transparent and open about our data privacy policies and practices.
How do We Collect Information?
We collect Your Data in the following basic ways:
- You give it to us when you register as a Member or if a Member or a Visitor registers for an event including but not limited to webinars, signing up for a newsletter or making a comment on a blog or social media;
- You give it to us in email inquiries or in your public comments;
- We automatically collect Technical Information when you visit our Sites; and
- We obtain legally available information from outside sources, including commercially available geographic and demographic information along with other publicly available information, such as public posts to social networking sites.
What Information Do We Collect?
On the Sites, we request certain Personal Data, for purposes such as registering to become a Member, renewing your membership, participating in discussion groups, submitting inquiries and comments, or registering for a webinar or our conferences or events. This may include name, title, company/organization name, postal address, email address, work, home and mobile phone numbers.
We or our authorized vendors may collect Technical Information that we do not associate with any individual Site user. This information includes –
We or our authorized vendors may collect Technical Information that we do not associate with any individual Site user. This information includes –
- how many visits we have to the Sites,
- when those Sites are visited,
- browser types used for Site visits,
- name of the Internet service providers,
- the Internet Protocol (IP) address through which you access the Internet;
- pages that you access while at one of the Sites, and
- the Internet address of the website from which you linked directly one of the Sites.
How Do We Use Your Data Collected at Our Sites?
We do not sell or rent any Personal Data supplied by you. We occasionally work with other companies, consultants, and contractors to provide limited services on our behalf, such as website hosting, public relations, mailing, answering customer questions about products and services, and sending information including but not limited to our research, white papers, policy positions and events. We will only provide those companies the Personal Data they need to perform the service for which they are retained and they agree to treat information confidentially and to only use it for the purposes of providing services under our agreement with them.
We may use Your Data to provide you with more effective customer service and to improve the Sites and any related products or services we may provide or make available.
We may use Technical Information to periodically analyze Site logs to assess aggregate usage trends in order to better serve the needs of Visitors and Members and maximize the user viewing experience. Under some circumstances this information may be used for purposes of systems administration, fraud prevention or server troubleshooting and security. This information may also be used to help improve the Sites, analyze trends, and administer the Sites.
We may disclose Your Data if required to do so by law or in the good faith belief that such action is necessary to (a) conform to the requirements of the law or comply with legal process served on us or the Sites; (b) protect and defend our rights or property, (c) act in urgent circumstances to protect the personal safety of our employees and staff, agents, users of our products or services, or members of the public, or (d) effect any merger, acquisition, or sale of all or a portion of our assets, in which case you will be provided notice of the following via email and/or a prominent notice on the relevant Site, (i) the change in ownership, (ii) the uses of Your Data in the transaction, and (iii) choices you may have regarding Your Data. To the extent we are legally permitted to do so, we will take reasonable steps to notify you in the event that we are required to provide Your Data to third parties as part of legal process.
In addition, we will use Your Data to:
We may use Your Data to provide you with more effective customer service and to improve the Sites and any related products or services we may provide or make available.
We may use Technical Information to periodically analyze Site logs to assess aggregate usage trends in order to better serve the needs of Visitors and Members and maximize the user viewing experience. Under some circumstances this information may be used for purposes of systems administration, fraud prevention or server troubleshooting and security. This information may also be used to help improve the Sites, analyze trends, and administer the Sites.
We may disclose Your Data if required to do so by law or in the good faith belief that such action is necessary to (a) conform to the requirements of the law or comply with legal process served on us or the Sites; (b) protect and defend our rights or property, (c) act in urgent circumstances to protect the personal safety of our employees and staff, agents, users of our products or services, or members of the public, or (d) effect any merger, acquisition, or sale of all or a portion of our assets, in which case you will be provided notice of the following via email and/or a prominent notice on the relevant Site, (i) the change in ownership, (ii) the uses of Your Data in the transaction, and (iii) choices you may have regarding Your Data. To the extent we are legally permitted to do so, we will take reasonable steps to notify you in the event that we are required to provide Your Data to third parties as part of legal process.
In addition, we will use Your Data to:
- Provide information or a service requested or consented to by you.
- Assist in the performance of our activities and public interest functions.
- Comply with relevant contractual obligations with you and other third parties.
- Improve Site performance and content, including troubleshooting and diagnostics.
- Improve your engagement and interaction with other Members of our community.
- Improve our engagement and interaction with you.
- Facilitate your attendance at and participation in our events, communities or blogs.
- Confirm your identity.
- Process a request or payment / donation submitted to us.
- Comply with legal requests.
Can I Choose not to Receive Commercial Email Communications?
We realize that unwanted and non-relevant email notices and communications can be unwelcome. Every promotional, event or related communication we send to you via email contains instructions and an easily discoverable link that will allow you to unsubscribe and stop all subsequent commercial or marketing messages and/or direct you to a preference center to select topics of interest to you. Unless you consent (opt in) to the receipt of commercial or marketing emails, we will not use your email address for such purposes. You can always change your email preferences by visiting our membership portal and clicking through to the preferences page.
Those who signed up for email alerts may receive periodic email or postal mailings from us with information about us, upcoming events, or issues related to the Internet including but not limited to news, public policy and emerging best practices and standards. We offer you the opportunity to select which, if any, of these communications you would like to receive.
All of our practices are designed and intended at a minimum to satisfy state, national, provincial and federal legal requirements limiting email communications. In addition to these laws and regulations governing email marketing there are other laws and regulations governing telemarketing and direct mail. As a general rule, we do not engage in those types of targeted marketing activities including but not limited to device fingerprinting, profiling and or cross device tracking.
Those who signed up for email alerts may receive periodic email or postal mailings from us with information about us, upcoming events, or issues related to the Internet including but not limited to news, public policy and emerging best practices and standards. We offer you the opportunity to select which, if any, of these communications you would like to receive.
All of our practices are designed and intended at a minimum to satisfy state, national, provincial and federal legal requirements limiting email communications. In addition to these laws and regulations governing email marketing there are other laws and regulations governing telemarketing and direct mail. As a general rule, we do not engage in those types of targeted marketing activities including but not limited to device fingerprinting, profiling and or cross device tracking.
Other Legal Bases for Using Your Data
In the event we do not rely on your consent to this Privacy Statement as the basis for our permitted use of Your Data, we will tell you so. For example, we may tell you that we are relying on our obligation to meet our contractual obligations to you. We may also rely on a “legitimate interests assessment” to process Your Data. We will separately notify or disclose to you when we rely on an alternative legal basis for the use or processing of Your Data.
Credit Card Information
Credit card information is not collected or stored on our servers. When you conduct transactions through a Site, payment and payment card information for transactions with us is entered directly into a third-party processor’s systems and is not transmitted through or stored by us. The card processor provides us with an authorization code which is securely stored with the payment record on our servers.
Use of Cookies; Technical Information Collection
Our Sites use third parties for web analytics services, including Google Analytics, to collect Technical Information. These third parties do or may use “cookies” or similar technologies, which are text files placed on your computer, to help analyze how you use a Site. The information generated by the cookie about your use of a Site (including your IP address) will be transmitted to and stored by these service providers servers in the United States. They will use this information for the purpose of evaluating your use of a Site, compiling reports on website activity for website operators and providing other services relating to website activity and Internet usage. They may also transfer this information to third parties where required to do so by law, or where such third parties process the information on their behalf.
You may refuse and block the use of all of our (and third party) cookies by selecting the appropriate settings on your browser. However please note that if you do this you may not be able to use the full functionality of our Sites and it might impact your overall experience.
You may refuse and block the use of all of our (and third party) cookies by selecting the appropriate settings on your browser. However please note that if you do this you may not be able to use the full functionality of our Sites and it might impact your overall experience.
Data Security
While no data transmission over the Internet can be guaranteed to be 100 percent secure, we take reasonable and appropriate measures designed to protect the security of data transmitted to us upon receipt. PPSA is a strong advocate of privacy enhancing technologies including our efforts with respect to encryption. By default, the Sites encrypt connections between client devices and our servers to minimize the ability of any third party to “eavesdrop” on Your Data. In addition, where feasible, data is stored encrypted. If your browser does not support HTTPS encryption, you are encouraged to contact us by phone or in writing.
Our databases and system administration logs, are restricted to access by authorized and authenticated users. We use reasonable industry security standard safeguards (which may include physical, procedural and technical measures) to protect against the unauthorized disclosure of Personal Data. We take reasonable steps to ensure that Your Data is complete and relevant to its intended use. We will take reasonable and appropriate security measures to protect against unauthorized access, disclosure, alteration or destruction of Your Data.
Our databases and system administration logs, are restricted to access by authorized and authenticated users. We use reasonable industry security standard safeguards (which may include physical, procedural and technical measures) to protect against the unauthorized disclosure of Personal Data. We take reasonable steps to ensure that Your Data is complete and relevant to its intended use. We will take reasonable and appropriate security measures to protect against unauthorized access, disclosure, alteration or destruction of Your Data.
Cross Border Transfers
If you visit our Sites from a country other than the United States, your communications will likely result in the transfer of Your Data across national borders. Our servers or offices may be located in countries other than the country from which you access our Sites, also resulting in the transfer of Your Data across international borders. If you provide Your Data when visiting one of our Sites from outside of the United States, you acknowledge and agree that this data may be transferred from your then current location to our offices and servers and to those of our affiliates, agents, and service providers located in the United States and in other countries. The United States and such other countries may not have the same level of data protection as those that apply in the jurisdiction where you live.
For site visitors who reside in the European Economic Area, Switzerland or the United Kingdom, we will only transfer Your Data (a) to jurisdictions with “adequate protection” as used in the General Data Protection Regulation governing transfer of personal data outside of the European Union (the “GDPR”), or (b) to recipients with appropriate safeguards in place, including where contractual arrangements exist which include Standard Contractual Clauses (as defined in the GDPR) without any additions, modifications, or omissions.
For site visitors who reside in the European Economic Area, Switzerland or the United Kingdom, we will only transfer Your Data (a) to jurisdictions with “adequate protection” as used in the General Data Protection Regulation governing transfer of personal data outside of the European Union (the “GDPR”), or (b) to recipients with appropriate safeguards in place, including where contractual arrangements exist which include Standard Contractual Clauses (as defined in the GDPR) without any additions, modifications, or omissions.
Links
The Sites contain links to other sites, organizations and resources. Please be aware that we cannot be and are not responsible for the privacy or security practices of such other sites. We encourage you, when you leave our Site(s), to read the privacy statements of those other sites that collect personally identifiable information and have up-to date security and anti-virus software on all of your devices. This Privacy Statement applies only to the Sites.
Data Retention
We will only retain Your Data stored on our servers in accordance with the legitimate needs of our business and as required or permitted by applicable law. We will not retain any unused Personal Data on our systems longer than necessary for legitimate business purposes.
Social Media, Blogs & Other Discussion Groups
Please note that this Privacy Statement does not apply to any posting by you in any of our discussion groups, blogs, discussion threads, elists, chat areas or similar interactive areas of our Sites. Your participation in those discussion areas and anything you post in those areas constitutes your public disclosure and may be attributed to you and displayed, republished and otherwise disseminated by us in accordance with the terms of use agreement you agree to abide by in order to participate in those areas.
Compliance
Our collection and use of any of Your Data is subject to the laws and regulations of the countries and political subdivisions in which our Visitors and Members reside. We are and remain committed to complying with all such legal obligations and use these legal requirements as the minimum beginning point for our use and collection of Your Data. Included in these laws and regulations are (a) the GDPR, which governs among other things, consents, uses and cross-border transfers of personal data concerning European Union residents, and (b) the California Online Privacy Protection Act, governing such matters with respect to California residents. If you have any questions regarding this Privacy Statement or you feel that the Sites are not following these legal requirements or our stated information policy, please contact us by email to privacy at isoc.org or at either of the addresses or phone numbers listed in the Contact Us section of the Sites. You may also contact us at that address if you have any concerns about the accuracy of, or wish to correct, your Personal Data we have collected from you.
Control of Your Personal Information “Do Not Track” Notice:
We respect enhanced user privacy control and support the development and implementation of a standard “Do Not Track” (DNT) browser feature, designed to provide users universal and persistent control over the collection, sharing and use of information by third parties regarding their web-browsing activities. Once the specification is finalized we intend to honor user’s requests with respect to browser tracking.
Children / Minors
The Sites are not targeted at, directed to or intended for the use of children under the age of thirteen. No person under the age of thirteen should use any Site or under any circumstances provide any Personal Data or other information at a Site. If you become aware that any individual under the age of thirteen has used any Site, please contact us immediately at privacy at isoc.org. By use of any Site you represent and warrant that you are over the age of thirteen.
Your California Privacy Rights
California Civil Code Section 1798.83 entitles California residents to request information concerning whether a business has disclosed Personal Data to any third parties for their direct marketing purposes. As stated in this Privacy Statement, we will not sell your Personal Data to other companies and we will not share it with other companies for them to use for their own marketing purposes without your consent. For further information concerning your California Privacy Rights including “Do Not Track,” visit https://oag.ca.gov/sites/all/files/agweb/pdfs/cybersecurity/making_your_privacy_practices_public.pdf
California Website Data Collection
We do not knowingly allow other parties to collect personally identifiable information about your online activities over time and across third-party web sites when you use the Sites. We provide information about the opt-out or opt-in choices available to users.
Contact Us
Any user, including California residents, who wish to request further information about our compliance with these requirements, or have questions or concerns about our privacy practices and policies, may contact us at: [email protected]
Changes To This Privacy Statement
We routinely update this Privacy Statement to provide additional explanation and clarification of our practices and to reflect new or different privacy practices, such as when we add new services, functionality or features to our Sites. You can determine when this Privacy Statement was last revised by referring to the Effective Date above on this page. We will also provide an archive of our past privacy policies with the ability to plainly see the changes from one to another. Any changes to this Privacy Statement will also be announced on our home page.