learning center
Privacy Policy
Effective Date: February 26, 2024
Mission MSA Privacy Policy Effective 2.26.24
Introduction and Scope
Mission MSA (“MSA”, “we”, “us” or “our”) respects the privacy of our visitors, users, customers, members, and donors (referred to as “you” or “your”). This privacy policy (as posted on our website and as amended from time to time and effective as of the date posted) (“Privacy Policy”) describes the types of information we collect from you or that you may provide when you visit or use our missionmsa.org website (“Website”), (“Website”), purchase our products (“Products”), or use our services (“Services”), and our practices for collecting, using, maintaining, protecting, disclosing, retaining, and transferring that information. This Privacy Policy applies to the data collected by us, or those working on our behalf, through information you enter or from the data imported from sources authorized or approved by us. It does not apply to data collected through third-party websites, or to products, or services not approved by us.
Our Privacy Policy describes:
- How and why we collect your Personal Information
- How your Personal Information is used and protected
- With whom and for what purposes we share your Personal Information
- How we store, retain, and transfer your Personal Information
- The choices you can make about how we collect, use, and share your Personal Information
- Your rights (where applicable) to learn about the Personal Information we collect, and what you can request that we do with it
If you are a resident of or subject to data privacy laws or regulations of a country outside of the United States, please see the additional provisions at the end of this Privacy Policy.
Acknowledgement and Consent
By visiting our Website or purchasing or using our Products or Services in any manner, you acknowledge that you accept the terms, practices and policies described in this Privacy Policy (and as updated from time to time), and you hereby consent that we may collect, use, process, share, retain, and transfer your information as described herein. If you do not agree with our policies and practices, your choice is not to use our Website, Products, or Services. Your use of our Website and our Services is at all times subject to our Terms of Use (available at ________and as amended from time to time and effective as of the date posted (the “Terms”)), which is incorporated by reference herein. Any capitalized terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms.
Changes to Our Privacy Policy
We are constantly working to improve our Website and Services and Mobile App, and we may need to change this Privacy Policy from time to time as well. Our current Privacy Policy will always be on our Website and any updates will be effective upon posting. You are responsible for periodically checking our Website for updates. Under certain circumstances, we also may elect to notify registered Users of changes or updates to this Privacy Policy by additional means, such as posting a notice on the Website or by sending you an email, but you should not rely on receiving such additional notice.
If you use the Website, purchase Products, or use our Services after any changes to the Privacy Policy have been posted, you agree to the new Privacy Policy. Our practices regarding information we collect now is subject to the Privacy Policy in effect at the time such information is collected.
What Information Does This Privacy Policy Cover?
This Privacy Policy covers our treatment of your personally identifiable information. “Personal Information” generally refers to any unencrypted or non-deidentified information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular person. However, the definition of Personal Information may vary depending on the state or country in which you reside, and that state’s or country’s definition will apply to your Personal Information in the context of this Privacy Policy. Please see additional information below on the particular information we may collect.
If you are a citizen or resident of the European Economic Area (“EEA”), United Kingdom, or Switzerland, the definition of Personal Information is defined under the General Data Protection Regulation (“GDPR”) and you have certain rights; therefore, please see the section below entitled “GDPR”.
Personal Information does not include information publicly available from government records or information excluded by applicable law. Personal Information also does not include your Personal Information that has been deidentified, pseudonymized, anonymized, aggregated, and/or otherwise processed so as to be unidentifiable in such a way that the data can no longer be attributed to a specific individual (by reasonable means) without the use of additional information, and where such additional information is kept separate and under adequate security to prevent unauthorized re-identification of a specific individual such that one could not, using reasonable efforts, link such information back to a specific individual (collectively, all of the foregoing in this sentence being referred to as “De-Identified Personal Information”).
We also may collect Personal Information from you through means other than our Website. This may include offline collection, such as if you submit a paper application, make a payment by check, or call or visit our office. It also may include emails, or other electronic communications that you send to us separate from our Website or by way of our Service Providers (as defined herein). However, if we combine the Personal Information we collect from you outside of our Website with Personal Information that is collected through our Website or by another means as described above, the Privacy Policy will apply to the combined information, unless specifically disclosed otherwise.
Other than as stated herein, this Privacy Policy does not apply to information collected by any third party (including our affiliates and subsidiaries), including through any application or content (including advertising) that may link to or be accessible from or on our Website. We are not responsible for the practices of sites linked to or from our Website, and before interacting with any of these sites you are advised to review their rules and policies before providing them with any private information.
Individuals under the Age of 18
We do not knowingly collect, solicit or maintain Personal Information from anyone under the age of 18 or knowingly allow such persons to register for or use our Services. If you are under 18, please do not send any Personal Information about yourself (such as your name, address, telephone number, or email address) to us. In the event that we learn that we have collected Personal Information from a child under age 18 without verification of parental consent, we will use commercially reasonable efforts to delete that information from our database. Please contact us if you have any concerns.
Personal Information We Collect
We collect several categories of Personal Information from and about you as summarized in the following table:
Category | Specific Items of Personal Information |
Identifiers | · first and last name · email address · postal address · zip code · phone number |
Commercial information | · donation history |
Internet or other electronic network activity; device information | · type and manufacturer of device and its ID/UDID or similar device-specific code · Internet Protocol (IP) address, protocol, and/or sequence information · operating system and platform · Internet service provider or mobile carrier’s name, connection speed, and connection type · browsing, session, interaction, and search history related to our Website · cookies · pixel tags · browser type, language, and version · domain name system requests · Media Access Control (MAC) address of pages you have visited · material and pages viewed · time and date of access to our Website · number of clicks per visit · date stamp and URL of the last webpage visited before visiting our Website, and URL of the first page visited after leaving our Website · pages viewed, time spent on a page, click-through and clickstream data, queries made, search results selected, comments made · type of service requested · hypertext transfer protocol headers, application client and server banners, and operating system data |
Geolocation | · physical location or movements |
Sensory information | · voice and/or video recording |
Professional or employment information | · email address that identifies you (e.g., jane.r.smith@website.com versus jrs@website.com) |
Inferences drawn from any of the above to create a profile of a consumer | · a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes |
How We Collect Personal Information and from What Sources:
Information You Provide Us. The Personal Information we collect through our Website, or our service providers may include the following:
- Information that you provide by filling in webforms on our Website. This includes information provided when creating an online account, purchasing or using our Products or Services, subscribing to our e-newsletters or other communications, requesting information from us, submitting or posting material (where permitted) on our forums, or interacting with customer support or service, report a problem with our Website, Products, or Services, or otherwise communicating with us.
- Records and copies of your correspondence (including email addresses), if you contact us
- Registering for an event
- Your responses to surveys that we or our Service Providers might ask you to complete for research purposes
- Your search queries on the Website
- When communicating with customer service/support
- Joint marketing partners
- Online advertising companies
- Mailing list providers
- Social media companies
- Other Service Providers
- When making a donation via our Website or offline (e.g., telephone)
Information We Collect Through Automatic Data Collection Technologies. As you navigate through and interact with our Website, we may use automatic data collection technologies to collect certain information about your equipment, browsing actions and patterns, including the following:
- Details of your visits to our Website, including, but not limited to, website traffic data, logs, and other communication data and the resources that you access and use on the Website.
- Information about your computer, mobile device, and internet connection, including your IP address, operating system, browser type, clickstream patterns, the URL of the most recent website you visited before coming to our Website, the amount of time you spent on our Website, and the pages you viewed while on our Website.
Behavioral Tracking. We also may use these technologies to collect information about your online activities over time and across third-party websites or other online services, or associate Personal Information with other information collected in this manner.
Cookie Notice and Policy. The technologies we use for automatic data collection may include cookies, local storage cookies, web beacons, pixel tracking, GIF, IP address, and other technologies. Each of these is discussed below.
Browser Cookies
Browser cookies are small files placed on the hard drive of your computer or mobile device. They may contain certain data, including, but not limited to: the name of the server that has placed it there, an identifier in the form of a unique number, and, an expiration date (some cookies only). Browser cookies are managed by the web browser (Chrome, Microsoft Edge, Safari, etc.) on your computer or mobile device. Different types of cookies which have different purposes are used on our Website.
Essential Cookies
Essential cookies are essential to allow you to browse our Website and use its functions. Without them, services such as shopping baskets and electronic invoicing would not be able to work.
Performance Cookies
Performance cookies collect information on the use of our Website, such as which pages are consulted most often. This information enables us to optimize our Website and simplify browsing. Performance cookies also enable our affiliates and partners to find out whether you have accessed one of our Website pages from their site and whether your visit has led to the use or purchase of a Product or Service from our Website, including the references for the Product or Service purchased or used. These cookies do not collect any information which could be used to identify you. All the information collected is aggregated, and therefore anonymous.
Functionality Cookies
Functionality cookies enable our Website to remember the choices you have made when browsing. For example, we can store your general geographic area (but not precise geolocation) in a cookie so that the Website corresponding to your geographic area is shown. We can also remember your preferences, such as the text size, font, and other customizable aspects of the Website. Functionality cookies also may be able to keep track of the products, pages, or videos consulted to avoid repetition. The information collected by these cookies cannot be used to identify you and cannot monitor your browsing activity on sites which do not belong to us.
It is possible that you will come across third-party cookies on some pages of sites that are not under our control.
We also use cookies such as functionality cookies to implement tracking technology on our Website. This allows us to display advertising that is tailored to you on our Website, to understand which parts of our content interest you the most, and which Product or Service categories you request. This tracking uses De-Identified Personal Information data. Some of our service providers are allowed to place cookies on our Website. Those companies also may provide you with the option of preventing the use of cookies in the future. For more information, contact the relevant third-party provider.
At any time, you can prevent the use of cookies in the future. You may activate the appropriate setting in your browser to refuse to accept browser cookies. However, if you do, your experience on our Website may be affected; e.g., you may be unable to access certain parts of our Website. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our Website.
Local Storage Cookies
Certain features of our Website may use local stored objects to collect and store information about your preferences and navigation to, from and on our Website. Local storage cookies are not managed by the same browser settings as are used for browser cookies.
Web Beacons. Pages of our Website and our emails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that permit us, for example, to count visitors who have visited those pages or opened an email and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).
GIF. We may use tiny images known as clear GIFs to track behavior of users, including statistics on who opens our emails.
IP Address. Our servers (or those of our service providers) automatically record certain log file information reported from your browser when you access the Website. These server logs may include information such as which pages of the Website you visited, your internet protocol (“IP”) address, browser type, and other information on how you interact with the Website. These log files are generally deleted periodically.
Information We Collect from Third Parties
We may collect information that others provide about you when you use the Website, or obtain information from other sources and combine that with information we collect through the Website. To the extent permitted by applicable law, we may receive additional information about you, such as demographic data or fraud detection information, from third-party Service Providers and/or partners, and combine it with information we have about you. For example, we may receive background check results or fraud warnings from Service Providers like identity verification services for our fraud prevention and risk assessment efforts. We may receive information about you and your activities on and off the Website through partnerships, or about your experiences and interactions from our partner ad networks.
Third-Party Use of Cookies and Other Tracking Technologies
Some content or applications, including advertisements, on the Website is served by third parties, including advertisers, ad networks and servers, content providers and application providers. First-party or third-party cookies may be used alone or in conjunction with web beacons or other tracking technologies to collect or compile information regarding user interactions with ad impressions and other ad service functions as they relate to our Website. A first-party cookie is a cookie set by the domain name that appears in the browser address bar. A third-party cookie is a cookie set by (and on) a domain name that is not the domain name that appears in the browser address bar. It might be set as part of a side resource load (image, JS, iframe, etc., from a different hostname) or an AJAX HTTP request to a third-party server. The information that first-party and third-party cookies collect may be associated with your Personal Information or they may collect information, including Personal Information, about your online activities over time and across different websites and other online services (i.e., tracking such activities). They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. We, along with third-party vendors such as Google, use first-party cookies (such as the Google Analytics cookies) and third-party cookies (such as the DoubleClick cookie) or other third-party identifiers together to compile data regarding user interactions with ad impressions and other ad service functions as they relate to our Website. More information on how to opt-out of third-party advertiser tracking mechanisms is available here.
Google Tools. We use tools provided by Google as described below.
Google Analytics. We use, and/or some of our third-party Service Providers may use, Google Analytics or other analytics service to help us understand the use of our Website and Services. Google Analytics is a web analysis service provided by Google. Google utilizes data it collects to track and examine the use of our Website to prepare reports on its activities and share them with other Google services. Google may use the data collected to contextualize and personalize the ads of its own advertising network. The Personal Information collected and processed may include cookies, usage data, and other internet information. Such service providers may place their own cookies in your browser. This Privacy Policy covers use of cookies by us only and not the use of cookies by third parties.
Google AdSense Advertising. We use Google AdSense Advertising (or other search engine or display network advertising) on our website. Google’s advertising requirements and principles are available here. They are put in place to provide a positive experience for users. We have implemented the following: (a) Remarketing with Google AdSense and (b) Google Display Network Impression Reporting.
Google Maps/Google Earth. We also use Google Maps (including the Google Maps API(s)) and/or Google Earth, which may, among other things, request access to your geolocation, and both of which are subject to their own terms of use and privacy policy.
How We Use Your Information
We use information that we collect about you or that you provide to us, including any Personal Information, for one or more of the following purposes:
- To present to you our Website and contents and provide information and notices (e.g., updates) related thereto.
- To provide you with Products, Services, and information related thereto that you request from us and your related questions.
- To provide customer Service and support.
- To process transaction payments, refunds, and reimbursements for any Products or Services that you choose to purchase from us.
- To send you emails and newsletters with Product, Service, company, and other information and offers.
- To contact you about and to process discounts, offers, loyalty rewards, promotions, contests, sweepstakes, awards, and/or rebate requests, forms, and applications (including those of the foregoing in which you have participated) and coordinate with the manufacturer, retailer and/or wholesaler.
- To allow you to participate in interactive features on our Website.
- To enhance and improve our Products and Services, for example, by performing internal research, analyzing user trends and measuring demographics and interests and for analyzing how the Products and Services are used, diagnosing Service or technical problems, and maintaining security.
- To de-identify, aggregate, anonymize, etc., your Personal Information or other data..
- For internal purposes, such as Website, Service, Product, Mobile App, and system administration or internal audits and reviews.
- To comply with applicable law(s) (e.g., to comply with a search warrant, subpoena or court order) or to carry out professional ethics/conduct investigations.
- In any other way we may describe and for which we obtain your consent when you provide the information.
- To manage donations and donor databases and communications
We use cookies, clear gifs, and log file information to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the Website; ((c) monitor the effectiveness of our Services; (d) monitor aggregate metrics such as total number of visitors, traffic, and demographic patterns;
Disclosure of Your Personal Information
We may or do disclose your Personal Information, in whole or in part, to the following types of third parties, and for one or more of the following purposes:
Type of Third Party | Purpose |
Data storage or hosting providers | Secure storage and transmission of your data |
Database and software service providers | Management and tracking of your data |
Legal and compliance consultants, such as external counsel, external auditors, or tax consultants | Provide professional services to us |
Identity management providers | Authentication purposes |
Payment solution providers | Secure processing of payments you provide to us |
Manufacturers, retailers, and wholesalers | Submission, processing, and management of rebates, discounts, offers, loyalty rewards, and the like |
Fulfillment and shipping vendors | Fulfillment and delivery of Products and Services |
Survey and research providers | Perform surveys or studies on our behalf |
Advertising partners, including social media providers | Deliver targeted advertisements |
Technology providers | Assist in the development and management of our Website |
Learning technology and online event providers | Delivery and improvement of web events and learning programs and the tracking of your progress |
Digital credential providers | Deliver digital badges earned through your participation in learning programs |
Our volunteers or committee members | Perform various functions on our behalf |
Disclosures to Service Providers. We may disclose your Personal Information to third parties for the purpose of providing or improving the Services to you. We may disclose your Personal Information to third-party service providers which perform services on our behalf (“Service Providers”). This includes, without limitation, Service Providers which provide services relating to: outbound and/or inbound communications, data analysis, creating, hosting, and/or providing customer or support services on our behalf, fulfilling orders, delivering packages, sending postal mail and email, removing repetitive information from customer lists,), processing credit card payments, or managing our conferences and other events. These Service Providers may have access to your Personal Information in order to provide these services to us or on our behalf. If we engage Service Providers for any of the foregoing, use of your Personal Information will be bound by obligations of confidentiality and their use of Personal Information will be restricted to providing their services to us. We may store Personal Information in locations outside our direct control (for instance, on servers or databases located or co-located with hosting Service Providers).
Event-Related Disclosure. From time to time, we may conduct events, run contests, make special offers, or other activities (“Events”), possibly together with an exhibitor, sponsor or other Service Provider. If you provide information to such third parties, you give them permission to use it for the purpose of that Event and any other use to which you consent. We cannot control such third parties’ use of your information that you provide directly to them. If you do not want your information to be collected by or disclosed to such third parties, you can choose not to participate in these Events.
Required Disclosures. Except as otherwise described in this Privacy Policy, we will not disclose your Personal Information to any third party unless required to do so by law, court order, legal process (e.g., subpoena), including, but not limited to, in order to respond to any government, regulatory, or licensing request, or if we believe that such action is necessary to: (a) comply with the law, comply with legal process served on us or our affiliates, subsidiaries, service providers, or partners, or investigate, prevent; (b) enforce our Terms or customer agreement (including for billing and collection purposes); (c) take precautions against liability; (d) investigate and defend ourselves against any third-party claims or allegations or to investigate, prevent, or take action regarding suspected or actual illegal activities; (e) assist government enforcement agencies or to meet national or other security requirements; (f) to protect the security or integrity of our Website, Products, or Services; or, (g) exercise or protect the rights, property, or personal safety of us, our users or others. We will attempt to notify you, where reasonably practicable, about these requests unless: (i) providing notice is prohibited by the legal process itself, by court order we receive, or by applicable law or regulation, or (ii) we believe that providing notice would be futile, ineffective, create a risk of harm to an individual or group, or create or increase a risk of acts of fraud done upon us or our users. In instances where we comply with legal requests without notice for these reasons, we will attempt to notify that user about the request after the fact if we determine in good faith that we are no longer legally prohibited from doing so and that no risk scenarios described in this paragraph apply.
Disclosure of De-Identified Personal Information. We may share De-Identified Personal Information with third parties for any purpose except as prohibited by applicable law, including, but not limited to, the following. De-Identified Personal Information or non-Personal Information may be aggregated for system administration and to monitor usage of the Website. It may be utilized to measure the number of visits to our Website, average time spent, number of pages viewed and to monitor various other Website statistics. This monitoring helps us evaluate how visitors use and navigate our Website so we can improve the content. We may share De-Identified Personal Information or anonymous information (including, but not limited to, anonymous usage data, referring/exit pages and URLs, IP address, platform types, number of clicks, etc.) with interested third parties in any way we choose and for any purpose.
Your Consent to Disclosure/Transfer/Assignment of Your Personal Information. You consent to (and shall not object) our disclosure, transfer, assignment, and/or sale of your Personal Information, De-Identified Personal Information, and other information you provide to us, as well as the rights you have granted or consented to in this Privacy Policy (collectively, “Transferred Information”) to a potential or actual buyer or acquirer of assets or equity of our company or other successor for the purpose of considering or undergoing a merger, divestiture, restructuring, reorganization, dissolution, change in control, or sale or transfer of some or all of our assets (each of the foregoing referred to as a “Transfer”), whether as a going concern or as part of bankruptcy, liquidation or other court proceeding, in which Personal Information held by us is among the assets transferred. We cannot make any representations regarding the use or transfer of Transferred Information that we may have in the event of our bankruptcy, reorganization, insolvency, receivership, or an assignment for the benefit of creditors. Furthermore, except as required by law, we are not and will not be responsible for any breach of security by any third parties or for any actions of any third parties that receive any of the Transferred Information that is disclosed to us.
Security
We have implemented technical, administrative, and organizational security measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, destruction, alteration and disclosure. Your Personal Information is stored behind secured networks and a firewall and is only accessible by our personnel and by a limited number of Service Providers who have special access rights to our systems, and who are required to keep the information confidential. Our Website is scanned on a regular basis for security holes and known vulnerabilities in order to make your visit to our Website safe.
Any payment transactions involving credit or debit cards will be performed using our third party payment processors or gateways, who will use appropriate security procedures designed to protect your information. We do not collect or store full credit card numbers.
Our agents, contractors, Service Providers, and partners who require access to your Personal Information in order to provide services to us or to you on our behalf are also required to keep the information confidential in a manner consistent with this Privacy Policy and are not permitted to disclose the information to third parties or use the information for any purpose other than to carry out the services they are performing for us, or as permitted pursuant to our agreement with them.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do use security measures designed to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted to us or which we obtain. Any transmission of Personal Information is at your own risk. Unauthorized entry or use, or hardware or software failure, and other factors, may compromise the security of user information at any time. We are not responsible for circumvention of any privacy settings or security measures contained on the Website or used with our Services.
Data Retention
In general, our retention of Personal Information is reasonably necessary and proportionate to achieve the purposes for which the Personal Information was collected or processed, or for another disclosed purpose that is compatible with the context in which the Personal Information was collected, and not further processed in a manner that is incompatible with those purposes. The time period for which we retain your Personal Information depend on the purposes for which we use it. This period of retention is subject to our review and alteration. We will also retain Usage Data for analytics purposes. “Usage Data” refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
Notices; Opting Out
By providing us with your phone number and/or email address (including by “following”, “liking”, linking your account to our Website or Service or other services, etc., on a third party website or network), you consent to our using the email address and/or phone number to send you Service-related notices by email, text, or by calling you, including any notices required by law (e.g., notice of data privacy or security incidents), in lieu of communication by postal mail. You also agree that we may send you notifications by email, phone, or text, of activity regarding our Products, Services, the Website, your Personal Information, or any aspect of our relationship, to the email address or phone number you give us, in accordance with any applicable privacy settings. We may use your email address to send you other messages or content, such as, but not limited to, newsletters, additions or changes to features of the Service, or special offers. If you do not want to receive such email messages, you may opt out by emailing us your opt-out request or, where available, by clicking “unsubscribe” at the bottom of our e-newsletter. Opting out may prevent you from receiving email messages regarding updates, improvements, special features, announcements, or offers. You may not opt out of Service-related emails.
You can add, update, or delete information as explained above. When you update information, however, we may maintain a copy of the unrevised information in our records. You may request deletion of your account by emailing us. It is your responsibility to maintain your current email address with us.
Contact Information
If you have any questions about this Privacy Policy or our privacy practices, please contact us: by email at info@missionmsa.org; by phone at 866-737-4999; or, by mail at 1660 International Drive Ste. 600, McLean, VA 22102 USA.
Where We Process and Store Personal Information
We have our headquarters in the United States. The Personal Information we or our service providers collect may be stored and processed in servers within or outside of the United States and wherever we and our service providers have facilities around the globe, and certain information may be accessible by persons or companies outside of the United States who provide services for us. You consent to our and our service providers’ transmission and/or transfer of your Personal Information to, or access it in, jurisdictions that may not provide equivalent levels of data protection as your home jurisdiction. We will take reasonable steps to ensure that your Personal Information receives an adequate level of protection in the jurisdictions in which we process it.
If you are a resident or citizen of the UK, European Economic Area (“EEA”), or Switzerland, please see the section below on GDPR compliance.
If you are a resident of a country other than the United States, you acknowledge and consent to our (and our Service Providers) collecting, transmitting, processing, transferring, and storing your Personal Information out of the country in which you reside.
GDPR: The Following Provisions Apply only to Citizens and Residents of the United Kingdom, EEA, and Switzerland
The following provisions apply only if you are a citizen or resident of the UK, EEA, or Switzerland (collectively referred to in this section for convenience as the “EU Region”). For such citizens or residents, all processing of your Personal Information is performed in accordance with privacy rights and regulations, in particular, (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (“GDPR”, and which includes the UK’s and Switzerland’s similar laws), and our processing will take place in accordance with the GDPR. For purposes of the GDPR, we will be the “data controller” of Personal Information (defined in the GDPR as “Personal Data”, but still referred to herein as Personal Information) we collect through the Website, unless we collect such information on behalf of a “data controller” in which case we will be a “data processor.” This Privacy Policy does not apply to websites, applications or services that do not display or link to this Privacy Policy or that display or link to a different privacy policy. For EU Region residents and citizens only, to the extent any definition in this Privacy Policy conflicts with a definition under the GDPR, the GDPR definition shall control.
We provide adequate protection for the transfer of Personal Information to countries outside of the EU Region through one or more of the following methods: (a) a series of intercompany agreements based on or incorporating the Standard Contractual Clauses, (b) we may rely on the European Commission’s adequacy decisions about certain countries, as applicable, (c) we may obtain your consent for these data transfers from the EU Region to the United States to other countries, (d) we may adopt binding corporate rules, or (e) to the extent applicable, we may rely on derogations as set forth in GDPR Article 49 for the transfer and onward transfer of Personal Information collected from individuals in the EU Region to the United States and other countries that the EU Region may view as not providing adequate data protection. Regarding method (e), we may transfer Personal Information to a third party to perform a contract with you, with your explicit consent or in a manner that does not outweigh your rights and freedoms. If this Personal Information is not processed and transferred, we will not be able to execute the contract with you or you will not have access to any or all the benefits and features associated with your transaction.
We also may need to transfer your Personal Information to other group companies or service providers in countries outside the EU Region. This may happen if our servers or suppliers and service providers are based outside the EU Region, or if you use our Products and/or Services while visiting countries outside these areas.
Our Legal Basis for Processing Personal Information (UK, EEA, and Swiss Visitors Only)
If you are a visitor using our Website from the UK, EEA, or Switzerland, our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it. However, we will normally collect Personal Information from you only where we need the Personal Information to provide Products and/or Services for you for which you have contracted with us, or where the processing is in our legitimate interests or rely upon your consent where we are legally required to do so and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we also may have a legal obligation to collect Personal Information from you or may otherwise need the Personal Information to protect your vital interests or those of another person.
The collection and processing of your Personal Information may be necessary for the purposes of our legitimate interests. Such legitimate interest purposes may include:
- fraud prevention
- ensuring network and information security
- indicating possible criminal acts or threats to public security, including enhancing protection of our community against spam, harassment, intellectual property infringement, crime, and security risks of all kind, and enforcing legal claims, including investigation of potential violations of our Terms of Use
- when we are complying with legal obligations
- processing your data
- performing the function or service you requested of us
- providing our Services and their functionality to you where such processing is necessary for the purposes of the legitimate interests pursued by us or by our service providers related to the Services
- direct marketing
- the relevant and appropriate relationship we have with you
- analytics, e.g., assess the number of visitors, page views, use of the Website, etc., in order to understand how our Website, Products, and Services are being used, to optimize the Website and/or future communications, and to develop new services and Website features
- updating your information and preferences
- offering and improving our Website, Products, and Services
- enforcing legal claims, including investigation of potential violations of our Terms
Your Data Rights Under GDPR
If you are subject to GDPR, your rights include the following:
- The right to access – Upon request, we will confirm any processing of your Personal Information and, provide you with a copy of that Personal Information in an acceptable machine-readable format.
- The right to rectification – You have the right to have us correct any inaccurate Personal Information or to have us complete any incomplete Personal Information.
- The right to erasure – You may ask us to delete or remove your Personal Information and we will do so in some circumstances, such as where we no longer need it (we may not delete your data when other interests outweigh your right to deletion).
- The right to restrict processing – You have the right to ask us to suppress the processing of your Personal Information but we may still store your Personal Information. See below for more information.
- The right to object to processing – You have the right to object to your Personal Information used in the following manners: (a) processing based on legitimate interests or the performance of a task in the public interest/exercise of official authority (including profiling); (b) direct marketing (including profiling); and, (c) processing for purposes of scientific/historical research and statistics. See below for more information.
- The right to data portability – You have the right to obtain your Personal Information from us that you consented to give us or that is necessary to perform fulfillment of member benefits with you. We will give you your Personal Information in a structured, commonly used and machine-readable format.
- Rights regarding automated decision making – You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, except for the exceptions applicable under relevant data protection laws.
- The right to complain to a supervisory authority – You have the right to file a complaint with a supervisory authority, in particular in the European member state of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of Personal Information relating to you infringes upon your rights.
- The right to withdraw consent – If we are processing your Personal Information based on your consent to do so, you may withdraw that consent at any time.
Privacy Notice for Colorado Residents
Residents of Colorado have certain rights, many of which are described elsewhere in this Privacy Policy.
Such rights include the following:
- Right to Access Information. You have the right to access information practices. Much of the information you are entitled to access is disclosed in this Privacy Policy. You also have the right to access the categories of Personal Information we collect, with whom we share that information, and, in some cases, what specific Personal Information we associate with you or your account (where applicable).
- Right to Data Portability. If you request a copy of your specific information then we will provide it in an easily accessible format.
- Right to Deletion or Erasure. You may request that we delete the Personal Information we have collected about you. Depending on the applicable law, in some cases we are required or permitted to retain your information, even if you validly requested we delete or erase it.
- Right to Correct Information. You may request we correct or rectify inaccurate information we have collected about you.
- Right to Withdraw Consent. You may withdraw your consent to our data privacy practices.
- Right to Non-Discrimination. You have the right to not experience discrimination from us for exercising the rights listed in this section.
- “Opt Out” of Sales: As permitted by applicable law, we may share your Personal Information for monetary or other valuable consideration (under Colorado law, this is considered a “sale”). You may opt out of such a “sale” of your Personal Information to third parties. You can exercise your right to opt-out by emailing us (see our contact information below).
- Right to Opt-Out of Targeted Advertising. Colorado consumers have the right to opt-out of the processing of Personal Information for purposes of targeting advertising, You may also submit an opt-out privacy request with your email, phone number and other Personal Information for us to complete the opt-out process.
Exercising Access, Data Portability, and Deletion Rights
To exercise the foregoing rights which you may be accorded, if any, as a resident of your state, please submit a verifiable consumer request to us by: sending an email to us at info@missionmsa.org. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must:
- Provide sufficient information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative.
- Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.
We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
Upon receiving a data access or deletion request from you we will send an email to you at the email address we have for you on file. The email will ask you to respond to verify you as the consumer making the request. Upon receipt of your verification we will match your information to that which is in our file. Upon verification of your identity we will proceed to process your request (subject to the exceptions stated above).
Response Timing and Format
Unless applicable state law requires otherwise, we will confirm receipt of your request within the applicable statutory time limit, if any, of receiving it. We will respond to a verifiable consumer request within the applicable statutory time limit, if any. If we require more time (up to an additional period as permitted by applicable statute), we will inform you of the reason and extension period in writing.
Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Please note that this right does not apply if the disclosure of Personal Information is for purposes consistent with the California resident’s reasonable expectations, when considering the submission’s circumstances.
Where permitted under applicable law (e.g., Colorado), you may appeal our denial of your request if you feel we have made a mistake. To submit an appeal, please use the same method of contact that you used to submit your request.
Non-Discrimination
We will not discriminate against you simply for your exercising any of rights accorded by the state in which you reside. Unless permitted by applicable law, we will not:
- Deny you goods or services;
- Charge you different prices or rates for goods or services, including by refusing to grant discounts or other benefits, or imposing penalties;
- Provide you a different level or quality of goods or services; or,
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.