This Policy describes the types of data we may collect from you or that you may provide and describes our policies and practices for collecting, using, protecting, and disclosing that data.
Please also see Appendix A: EU Privacy Notice if you are located in the European Union or European Economic Area.
Data We Collect About You
We collect several types of personal data that can be used to identify you (“Personal Data”), including your:
- Postal address
- Email address
- Telephone number
- Donation history
- Payment cardholder data
- Sensitive authentication data
- Internet connection
- Equipment used to access our Website and usage details
Under limited circumstances, we may collect highly sensitive personal data, such as government ID numbers and/or health information.
How We Collect Your Data
We collect Personal Data from:
We collect this data:
Data You Provide to Us
We collect data you provide when you interact with Rotary, either through our Website or any interaction offline or in person. That data includes:
- The Brand Center
- The Grant Center
- The Learning Center
- Rotary Club Central
- Rotary Global Rewards
- Rotary Ideas
- Rotary Shop
- Rotary Showcase
Features that are developed in the future may result in the collection of additional new personal data.
You also may provide data to be published or displayed (hereinafter, “posted”) on public areas of the Website or transmitted to other users of the Website or third parties (collectively, “User Content”). Your User Content is posted on the Website and transmitted to others at your own risk. We limit access to certain pages and you may set certain privacy settings for this data from your account profile. However, we cannot control the actions of other Website users with whom you may choose to share your User Content.
Usage Details, IP Addresses, Cookies, and Other Technologies
As you navigate through and interact with our Website, we may automatically collect certain data about your equipment, browsing actions, and patterns, including:
When you are not signed in to a My Rotary account, the data collected in this way is anonymous. It is aggregated into statistical data to help us improve our Website and to deliver a better and more personalized service by enabling us to:
When you are signed in to a My Rotary account, we collect usage data that is tied to your individual account. This data is collected to improve site functionality and to tailor site behavior and content to you, and we process this personal data in accordance with this Policy.
How We Use Your Personal Data
We use data that we collect about you or that you provide to us, including any personal data:
- Fulfilling Rotary’s obligation to Rotarians, Rotaractors, and other individuals
- Financial processing
- Supporting The Rotary Foundation, including fundraising efforts
- Facilitating convention and special event planning
- Communicating key organizational messages through Rotary publications and other materials
- Supporting the programs and membership of Rotary
- Complying with any legal obligations
- Preserving Rotary’s legacy by building and maintaining accurate archives that effectively document Rotary’s history
Disclosure of Your Personal Data
We may disclose aggregated data about our users, and data that cannot be used to identify any individual, without restriction.
We may disclose personal data that we collect or you provide as described in this Policy:
- Travel service providers, such as airlines, hotels, ground transport, and travel agencies
- Companies that produce, publish, and/or ship Rotary publications and Rotary branded goods and other merchandise
- Online shop vendor Payment processing vendors
- Financial institutions and fiscal agents when processing financial transactions, such as expense reimbursements
- Software and applications used for administrative functions such as providing online forms/surveys/applications, newsletter services, online learning, webinar/teleconference services, electronic voting
- Cloud-based databases used for administrative functions
- Rotary convention host committees and other event organizers and vendors
- Email distribution services
- If you do not want us to share your personal data (even when anonymized) with unaffiliated or non-agent third parties for advertising or promotional purposes, you can send an email stating your request to firstname.lastname@example.org
We may also disclose your personal data:
Rotary Foundation Donor Privacy Personal Data
Rotary will not sell, trade, or share a Rotary Foundation donor’s personal data, including their name, phone number, email, or physical address, with non-Rotary entities, nor will it send donors mailings on behalf of other unrelated organizations. This policy applies to all donor data received by Rotary, both online and offline, as well as any electronic, written, or oral communication. Rotary occasionally uses third-party vendors to manage and process donor data. These vendors are bound by strict confidentiality agreements.
Accessing and Correcting Your Personal Data
You may access and correct your data by:
We may choose not to accommodate a request to change or delete data if we believe the change or deletion would violate any law or legal requirement or cause the data to be incorrect.
Children Under the Age of 16
Our Website is not intended for children under 16 years. We do not knowingly collect personal data from children under 16 without parental consent. No one under age 16 may provide any personal data to or on our Website.
If you are under 16, do not:
If we learn we have collected or received personal data from a child under 16 without verification of parental consent, we will delete that personal data. If you believe we might have any personal data from or about a child under 16, please contact us at email@example.com
We have implemented technical and operational measures designed to secure your personal data from accidental loss and from unauthorized access, use, alteration, and disclosure. Additionally:
The safety and security of your personal data also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Website, you are responsible for keeping this password confidential. Passwords registered with our Website are encrypted to ensure protection against unauthorized access to your personal data.
Unfortunately, the transmission of personal data via the internet is not completely secure. Although we do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our Website or over any public network. Any transmission of personal data is at your own risk. Without prejudice to any mandatory legal obligations to which we may be subject, we are not responsible for circumvention of any privacy settings or security measures on our Website.
Rotary may change, add, modify or remove portions of this Policy at any time, which shall become effective immediately upon posting on this page. The date the Policy was last revised is identified at the bottom of the policy. It is your responsibility to review this Policy for any changes. By continuing to use our Website, maintain your membership in our clubs, use our services, or participate in our programs, you agree to any changes in the Policy.
Rotary is headquartered in Illinois, in the United States. If you have any questions about Rotary’s privacy protection policies or practices, please contact us at firstname.lastname@example.org
Last modified: 25 June 2019
Appendix A: EU Privacy Notice
If you are a resident of the European Union (EU) or European Economic Area (EEA) whose personal data we collect, the following additional information applies.
If you are an EU or EEA resident and Rotary knowingly collects your personal data, we will do so in accordance with applicable laws that regulate data protection and privacy. This includes, without limitation, the EU General Data Protection Regulation (2016/679) (“GDPR”) and EU member state national laws that implement or regulate the collection, processing and privacy of your personal data (together, “EU Data Protection Law”).
This Privacy Notice also provides information on your legal rights under EU Data Protection Law and how you can exercise them.
How Personal Data is Collected
Because of the global nature of Rotary and our clubs, Rotary may hold and process personal data that is collected from clubs, districts, and partner organizations around the world, including within the EU/EEA.
This also means that if you contact the Rotary network and are a resident in the EU/EEA, your personal data may be transferred from the EU/EEA to Rotary headquarters in the United States, and may also be accessed and processed from Rotary’s international offices in Australia, Brazil, India, Japan, South Korea, and Switzerland.
U.S. data privacy laws are currently not considered to meet the same legal standards of protection for personal data as those set out under EU Data Protection Law. However, to safeguard personal data received from the EU/EEA, we transfer personal data to the U.S. or other third countries only under an approved contract or another appropriate mechanism that is legally authorized under EU Data Protection Law.
This is to make sure that the personal data that Rotary receives and processes (as it relates to residents of the EU/EEA) is properly safeguarded in accordance with similar legal standards of privacy provided by EU Data Protection Law.
If Rotary provides direct marketing communications to individuals in the EU/EEA regarding services and/or events that may be of interest, this will be done in accordance with EU Data Protection Law. Where we contact individuals for direct marketing purposes by SMS, email, fax, social media, and/or any other electronic communication channels, this will only be with the individual’s consent or in relation to similar services to services that the individual has purchased (or made direct inquiries about purchasing) from Rotary before.
Individuals may also object or withdraw consent to receive direct marketing from us at any time, by contacting us at email@example.com
Lawful Grounds on Which We Collect and Process Personal Data
Please also note that some of the personal data we receive and that we process may include what is known as “sensitive” or “special category” personal data about you, for example, personal data regarding your ethnic origin or political, philosophical, and religious beliefs. This is not the type of data that Rotary or its clubs routinely collect, but if we process this sensitive or special category data, we will do it only in situations where:
Disclosing Your Personal Data to Third Parties
We may disclose your personal data to certain third-party organizations that are processing data solely in accordance with our instructions (“Data Processors”), such as companies and/or organizations that support our business and operations (for example, providers of web or database hosting, IT support, payment providers, event organizers, agencies we use to conduct fraud checks, or mail management service providers), as well as professionals we use such as lawyers, insurers, auditors, or accountants. We use only those Data Processors that can guarantee to us that they have put adequate safeguards in place to protect the personal data they process on our behalf; these guarantees are established by entering data processing agreements that contain appropriate data transfer mechanisms (such as the inclusion of “Standard Contractual Clauses”) or provisions where the Data Processors state they are certified under the EU-US Privacy Shield Framework).
In certain circumstances, for example, if you travel on Rotary business, we may also disclose your personal data to third parties called “Data Controllers.” These third parties may include travel agencies, airlines, car rental agencies, and hotels. Because of the nature of the business of the Data Controllers, they will make their own determinations as to how they process your personal data. As Data Controllers, they are required to follow the EU Data Protection Law and are required to protect personal data with adequate safeguards and provide you with notice if their processing goes beyond the instructions Rotary provided. The types of external third-party Data Controllers listed above may handle your personal data in accordance with their own procedures, and you should check the relevant privacy policies of these companies or organizations to understand how they may use your personal data.
Other than as described above, we will treat your personal data as private and will not routinely disclose it to third parties without your knowing about it. The exceptions are in relation to legal proceedings or where we are legally required to do so and cannot tell you (such as a criminal investigation). We always aim to ensure that your personal data is used only by third parties we deal with for lawful purposes and who observe the principles of EU Data Protection Law.
How Long We Retain Your Personal Data
Rotary retains your personal data for as long as necessary in the circumstances — for instance:
Rotary has adopted a Records Management Policy (which we may make available on request). The criteria we use for determining the relevant retention and disposal periods we adopt are based on the purpose for which we hold data and the reasonable expectations of those whose personal data we collect in these circumstances, taking into account various legislative requirements and guidance issued by relevant EU regulatory authorities.
In accordance with the above retention policy, the personal data that we no longer need will be disposed of and/or anonymized so you can no longer be identified from it.
History and archives
To preserve Rotary’s history and legacy, Rotary retains historical and archival information about its clubs, which may also include limited personal data of its members.
Your Personal Data Rights
In accordance with your legal rights under EU Data Protection Law, you have a “subject access request” right, under which you can request information about the personal data that we hold about you, what we use that personal data for and who it may be disclosed to, as well as certain other information.
Usually we will have one month to respond to a subject access request. However, we reserve the right to verify your identity, and we may, in case of complex requests, require an additional two months to respond. We may also charge for administrative time in dealing with any manifestly unreasonable or excessive requests. We may also require additional information to locate the specific data you seek, and certain legal exemptions under EU Data Protection Law may apply when we respond to your subject access request.
Under EU Data Protection Law, EU/EEA residents also have the following rights, which you may exercise by making a request to us in writing:
So we can fully comply, please note that these requests may also be forwarded to third-party data processors that are involved in the processing of your personal data on our behalf.
If you would like to exercise any of the rights set out above, please contact us at firstname.lastname@example.org
If you make a request and are not satisfied with our response, or you believe that we are illegally processing your personal data, you have the right to complain to the Office of the Information Commissioner in the United Kingdom.