Data We Collect About YouWe collect several types of personal data that can be used to identify you (“Personal Data”), including your:
- Postal address
- Email address
- Telephone number
- Donation history
- Payment cardholder data
- Sensitive authentication data
- Internet connection
- Equipment used to access our Website and usage details
- Birth year
- Marital status
- Spouse’s or parents’ name
- Wealth data
How We Collect Your DataWe collect Personal Data from:
- Users of our Website
- Members of Rotary and Rotaract clubs
- Donors to The Rotary Foundation
- People who attend Rotary events
- People who participate in Rotary’s programs
- Directly when you provide it to us through any interaction offline or in person
- From our website Rotary.org (our “Website”)
- From other Rotary websites that link to this Policy
- When you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this Policy
- Automatically, as you navigate through the Website (data collected automatically may include usage details, IP addresses, and information collected through cookies and other tracking technologies)
- When you become a member of a Rotary club or Rotaract club
- When you use our services
- When you participate in our programs or sign up for and/or attend any events that we host
- From third parties we contract with to provide services on our behalf, such as event organizers, travel service providers (used by the Rotary International Travel Service, or RITS), payment processing services, email marketing services, and software providers; these service providers may change, or new service providers may be added without notice to you
- When you interact with us in another way, for example, contacting us with an inquiry
- From publicly available resources
Data You Provide to UsWe collect data you provide when you interact with Rotary, either through our Website or any interaction offline or in person. That data includes:
- Personal data that you provide by making an inquiry or joining as a member of a Rotary or Rotaract club; this includes data provided when registering to Rotary.org through My Rotary.
- Personal data you provide when participating in services available on our Website, including in:
- The Brand Center
- The Grant Center
- The Learning Center
- Rotary Club Central
- Rotary Global Rewards
- Rotary Ideas
- Rotary Shop
- Rotary Showcase
- Personal data you provide when you enter a contest or promotion sponsored by us
- Personal data you provide when you report a problem with our Website
- Records and copies of your correspondence (including email, social media posts, and other electronic messages), if you contact us
- Your responses to surveys that we might ask you to complete for research purposes
- Your registration to attend and/or participate in Rotary events
- Personal data you provide when making a donation
- Personal data you provide when submitting applications, for example, for grants, fellowships, or scholarships
- Biographical or other data you provide to us, your Rotary club, or your Rotary district (for example, if you choose to put your name forth as a candidate for an office in a Rotary club, Rotary district, or RI)
- Details of transactions made through our Website and details of the fulfillment of your orders (you may be required to provide financial personal data before placing an order through our Website)
- Your search queries on our Website
Usage Details, IP Addresses, Cookies, and Other TechnologiesAs you navigate through and interact with our Website, we may automatically collect certain data about your equipment, browsing actions, and patterns, including:
- Details of your visits to our Website, including traffic data, location data, logs, and other communication data and the resources that you access and use on our Website
- Information about your computer and internet connection, including your IP address, operating system, and browser type
- Estimate our audience size, browser statistics, popularity of content, and usage patterns
- Speed up your searches
- Recognize you when you return to our Website
How We Use Your Personal DataWe use data that we collect about you or that you provide to us, including any personal data:
- To present our Website and its contents to you
- To provide you with information, products, or services that you request from us
- To offer and fulfill our core business purposes, which include:
- Fulfilling Rotary’s obligation to Rotarians, Rotaractors, and other individuals
- Financial processing
- Supporting The Rotary Foundation, including fundraising efforts
- Facilitating convention and special event planning
- Communicating key organizational messages through Rotary publications and other materials
- Supporting the programs and membership of Rotary
- Complying with any legal obligations
- Preserving Rotary’s legacy by building and maintaining accurate archives that effectively document Rotary’s history
- To fulfill any other purpose for which you provide it
- To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection
- To notify you about changes to our Website or any products or services we offer or provide through it
- To allow you to participate in interactive features on our Website
- To store information about your preferences, allowing us to customize our Website according to your individual interests
- To help us develop and test updates to this Website and other Rotary applications that support Rotary’s core business purposes
- In any other way we may describe when you provide the personal data
- For any other purpose where we have your consent
Disclosure of Your Personal DataWe may disclose aggregated data about our users, and data that cannot be used to identify any individual, without restriction. We may disclose personal data that we collect or you provide as described in this Policy:
- To the Rotary club or Rotaract club in which you are a member (if applicable), as well as the assigned Rotary district
- To contractors, service providers, and other third parties we use to support our business and who are bound by contractual obligations to keep personal data confidential and use it only for the purposes for which we disclose it to them, including:
- Travel service providers, such as airlines, hotels, ground transport, and travel agencies
- Companies that produce, publish, and/or ship Rotary publications and Rotary branded goods and other merchandise
- Online shop vendor
- Payment processing vendors
- Financial institutions and fiscal agents when processing financial transactions, such as expense reimbursements
- Software and applications used for administrative functions such as providing online forms/surveys/applications, newsletter services, online learning, webinar/teleconference services, electronic voting
- Cloud-based databases used for administrative functions
- Rotary convention host committees and other event organizers and vendors
- Email distribution services
- To third parties to promote Rotary or for the third party to market their products or services to you if you have consented to these disclosures. We contractually require these third parties to keep personal data confidential and use it only for the purposes for which we disclose it to them.
- If you do not want us to share your personal data (even when anonymized) with unaffiliated or non-agent third parties for advertising or promotional purposes, you can send an email stating your request to email@example.com.
- To fulfill the purpose for which you provide it
- For any other purpose disclosed by us when you provide the data
- With your consent
- To comply with any court order, law, or legal process, including to respond to any government or regulatory request.
- If disclosure is necessary or appropriate to protect the rights, property, or safety of Rotary, Rotarians, Rotary clubs, Rotary districts, or others. This includes exchanging personal data with other companies and organizations for the purposes of fraud protection and credit risk reduction.
Rotary Foundation Donor Privacy Personal DataRotary will not sell, trade, or share a Rotary Foundation donor’s personal data, including their name, phone number, email, or physical address, with non-Rotary entities, nor will it send donors mailings on behalf of other unrelated organizations. This policy applies to all donor data received by Rotary, both online and offline, as well as any electronic, written, or oral communication. Rotary occasionally uses third-party vendors to manage and process donor data. These vendors are bound by strict confidentiality agreements.
Accessing and Correcting Your Personal DataYou may access and correct your data by:
- Visiting your account profile page on My Rotary, if you are a registered user on this Website. See Rotary’s Frequently Asked Questions for additional information.
- Emailing firstname.lastname@example.org to request access to, correct, or delete any personal data that you have provided.
Children Under the Age of 16Our Website is not intended for children under 16 years. We do not knowingly collect personal data from children under 16 without parental consent. No one under age 16 may provide any personal data to or on our Website. If you are under 16, do not:
- Use or provide any personal data on our Website or on or through any of its features
- Register on our Website, make any purchases through our Website
- Use any of the interactive or public comment features of our Website, or
- Provide any personal data about yourself to us, including your name, address, telephone number, email address, or any screen name or user name you may use.
Data SecurityWe have implemented technical and operational measures designed to secure your personal data from accidental loss and from unauthorized access, use, alteration, and disclosure. Additionally:
- When developing new or enhancing existing systems and processes, Rotary implements appropriate data protection throughout its data processing operations.
- All personal data you provide to us is stored on password-protected databases on our secure servers behind firewalls and we use Secure Sockets Layer (SSL) to ensure that the transmission of sensitive data for payments and contributions is encrypted and appropriately safeguarded.
- Employees are trained on the importance of data security and focus specifically on practices for protecting against unauthorized disclosure of personal data.
- We have a documented incident response plan for promptly acting upon events that violate Rotary’s security or privacy policies, should they occur, and this plan is reviewed and updated on an ongoing basis.
Contact InformationRotary is headquartered in Illinois, in the United States. If you have any questions about Rotary’s privacy protection policies or practices, please contact us at email@example.com. Last modified: 25 June 2019
Appendix A: EU Privacy NoticeIf you are a resident of the European Union (EU) or European Economic Area (EEA) whose personal data we collect, the following additional information applies.
How Personal Data is CollectedBecause of the global nature of Rotary and our clubs, Rotary may hold and process personal data that is collected from clubs, districts, and partner organizations around the world, including within the EU/EEA. This also means that if you contact the Rotary network and are a resident in the EU/EEA, your personal data may be transferred from the EU/EEA to Rotary headquarters in the United States, and may also be accessed and processed from Rotary’s international offices in Australia, Brazil, India, Japan, South Korea, and Switzerland. U.S. data privacy laws are currently not considered to meet the same legal standards of protection for personal data as those set out under EU Data Protection Law. However, to safeguard personal data received from the EU/EEA, we transfer personal data to the U.S. or other third countries only under an approved contract or another appropriate mechanism that is legally authorized under EU Data Protection Law. This is to make sure that the personal data that Rotary receives and processes (as it relates to residents of the EU/EEA) is properly safeguarded in accordance with similar legal standards of privacy provided by EU Data Protection Law.
Direct MarketingIf Rotary provides direct marketing communications to individuals in the EU/EEA regarding services and/or events that may be of interest, this will be done in accordance with EU Data Protection Law. Where we contact individuals for direct marketing purposes by SMS, email, fax, social media, and/or any other electronic communication channels, this will only be with the individual’s consent or in relation to similar services to services that the individual has purchased (or made direct inquiries about purchasing) from Rotary before. Individuals may also object or withdraw consent to receive direct marketing from us at any time, by contacting us at firstname.lastname@example.org.
Lawful Grounds on Which We Collect and Process Personal DataWe process your personal data for the above purposes, relying on one or more of the following lawful grounds under EU Data Protection Law:
- When you have freely provided your specific, informed, and unambiguous consent for Rotary to process your personal data for particular purposes
- Where we agree to provide services to you to set up and perform our contractual obligations to you and/or enforce our rights
- Where we need to process and use your personal data in connection with our legitimate interests and need to effectively manage and operate our global organization consistently across all territories. We will always seek to pursue these legitimate interests in a way that does not unduly infringe on your legal rights and freedoms and, in particular, your right to privacy; and/or
- Where we need to comply with a legal obligation or to establish, exercise, or defend legal claims
- You have provided us with your explicit consent to use it
- We have a legal obligation to process this data in accordance with EU Data Protection Law
- It is needed to protect your vital interests (or those of someone else), such as in a medical emergency
- You have clearly chosen to publicize this information; or
- It is needed in connection with a legal claim that we have or may be subject to
Disclosing Your Personal Data to Third PartiesWe may disclose your personal data to certain third-party organizations that are processing data solely in accordance with our instructions (“Data Processors”), such as companies and/or organizations that support our business and operations (for example, providers of web or database hosting, IT support, payment providers, event organizers, agencies we use to conduct fraud checks, or mail management service providers), as well as professionals we use such as lawyers, insurers, auditors, or accountants. We use only those Data Processors that can guarantee to us that they have put adequate safeguards in place to protect the personal data they process on our behalf; these guarantees are established by entering data processing agreements that contain appropriate data transfer mechanisms (such as the inclusion of “Standard Contractual Clauses”) or provisions where the Data Processors state they are certified under the EU-US Privacy Shield Framework). In certain circumstances, for example, if you travel on Rotary business, we may also disclose your personal data to third parties called “Data Controllers.” These third parties may include travel agencies, airlines, car rental agencies, and hotels. Because of the nature of the business of the Data Controllers, they will make their own determinations as to how they process your personal data. As Data Controllers, they are required to follow the EU Data Protection Law and are required to protect personal data with adequate safeguards and provide you with notice if their processing goes beyond the instructions Rotary provided. The types of external third-party Data Controllers listed above may handle your personal data in accordance with their own procedures, and you should check the relevant privacy policies of these companies or organizations to understand how they may use your personal data. Other than as described above, we will treat your personal data as private and will not routinely disclose it to third parties without your knowing about it. The exceptions are in relation to legal proceedings or where we are legally required to do so and cannot tell you (such as a criminal investigation). We always aim to ensure that your personal data is used only by third parties we deal with for lawful purposes and who observe the principles of EU Data Protection Law.
How Long We Retain Your Personal DataRotary retains your personal data for as long as necessary in the circumstances — for instance:
- As long you are a member of a club or have a relationship with our network
- For a reasonable period to send you donation information, program information, and marketing materials where we have regular contact with you, or
- As may be needed to enforce or defend contract claims or as is required by applicable law.
Your Personal Data RightsIn accordance with your legal rights under EU Data Protection Law, you have a “subject access request” right, under which you can request information about the personal data that we hold about you, what we use that personal data for and who it may be disclosed to, as well as certain other information. Usually we will have one month to respond to a subject access request. However, we reserve the right to verify your identity, and we may, in case of complex requests, require an additional two months to respond. We may also charge for administrative time in dealing with any manifestly unreasonable or excessive requests. We may also require additional information to locate the specific data you seek, and certain legal exemptions under EU Data Protection Law may apply when we respond to your subject access request. Under EU Data Protection Law, EU/EEA residents also have the following rights, which you may exercise by making a request to us in writing:
- That we correct your personal data if it is inaccurate or incomplete
- That we erase your personal data without undue delay if we no longer need to hold or process it
- To object to any automated processing (if applicable) that we carry out in relation to your personal data
- To object to our use of your personal data for direct marketing
- To object to and/or to restrict the use of your personal data for a purpose other than those set out above unless we have a compelling legitimate reason; or
- That we transfer personal data to another party where the personal data has been collected with your consent or is being used to perform services under a contract with you and is being processed by automated means