Center for Justice and Accountability Privacy Policy
Updated May 25, 2018
Introduction
The Center for Justice & Accountability (CJA) is committed to safeguarding the privacy of our web site visitors, donors, and supporters. This Privacy Policy describes how CJA collects, uses, protects, deletes, and discloses information. This statement may be changed or updated at any time. By visiting www.cja.org, and/or providing the information described below, you acknowledge that you accept the terms of this Privacy Policy. If you do not agree to the terms of this Privacy Policy, please do not use the website.
Your Information: How We Collect It, What We Collect, and How Long We Keep It
When you visit CJA’s website, there are three main ways in which information about you may be collected. First, like most websites, CJA uses “cookies” to enhance your experience navigating the website. These cookies collect general traffic, site use, length-of-stay information, Internet Protocol (IP) address of the computer, mobile device or other device you used to access the website, the type of browser and operating system you used, the date and time you visited the website, the Internet address of the site from which you linked to the website, the links you follow from the website, including to the third party processor of donations to CJA, and the reading history and other analytics related to how visitors to the website use and view the content we’ve provided. CJA does not use cookies to track the activity of individual visitors. CJA does not store any personal information as a result of browsing the web site. You may set your web browser to refuse cookies or alert you when cookies are being used. Disabling cookies may affect your ability to use the web site properly.
Second, CJA will receive your email address if you provide it to us for the purposes of receiving future updates about our work. After electing to join CJA’s email list, you may unsubscribe at any time. CJA will keep your email for a period of ten years effective now, and will send a reminder to recommit to receiving CJA alerts at that time. Your ten year period will renew at any point you connect with CJA in a way that is identifiable, such as updating your email record or making a donation. You may ask CJA to delete your record from our database at any time.
Third, CJA will receive your email address and any other information you provide if you contact us by clicking on an information link such as center4justice@cja.org, jobs@cja.org, or interns@cja.org. CJA will add your email to our list serve. CJA will keep your email for a period of ten years effective now, and will send a reminder to recommit to receiving CJA alerts at that time. Your ten year period will renew at any point you connect with CJA in a way that is identifiable, such as updating your email record or making a donation. You may unsubscribe from our email list or ask CJA to delete your record from our database at any time.
Fourth, CJA will receive additional information about you should you choose to make an online donation for which we are enormously grateful. That information includes your name, email, phone, address, donation information, and any other information you provide. CJA does not keep your credit card information on file. We will maintain your donation history, and any other information you provide to us, or that we independently collect from public sources as information about our supporters provides important historic context for the organization. CJA will, however, keep your email for a period of ten years effective now, and will send a reminder to recommit to receiving CJA alerts at that time. Your ten year period will renew at any point you connect with CJA in a way that is identifiable, such as updating your email record or making a donation. You may unsubscribe from our email list or ask CJA to delete your record from our database at any time.
CJA uses third party service providers to help us operate the website and administer activities on CJA’s behalf, such as collecting donations online, providing analytics, maintenance or site improvement, and/or operational support. These third party vendors may have access to website visitor information, but are required to protect the confidentiality of the information and to use it only for the limited purpose for which it was provided.
CJA may obtain your personal information not through the web site, through friends, petitions, direct mail inquiries or other means. CJA will keep your information for a period of ten years effective now, and will send a reminder to recommit to receiving CJA alerts at that time. Your ten year period will renew at any point you connect with CJA in a way that is identifiable, such as updating your email record or making a donation. You may unsubscribe from our email list or ask CJA to delete your record from our database at any time.
How CJA May Use The Data It Collects
CJA collects information that it needs to, or that we believe would be useful to provide our services and fulfill our mission. By accepting this privacy policy, you agree to CJA’s reasonable use and maintenance of your data as described resulting from your visit to CJA’s website, donation, purchase of service (such as event registration) or providing information with the purpose of receiving CJA communications. CJA may use the information, for example, to:
- include you on our direct mail or email list
- respond to inquiries
- administer your donation
- acknowledge and thank you for donations, services, or volunteer work
- provide news and other updates
- invite you to events
- alert you to employment opportunities
- ask for financial support
- give us feedback
- participate in surveys
- communicate with you on other CJA matters not listed above.
CJA uses third parties who are obligated to secure and keep your information confidential, such as, but not limited to mail house vendors, email services, and public information screening aggregators.
Data Security
CJA is committed to keeping your personal information safe and secure. This website has security measures in place to protect against the loss, misuse or alteration of information under our control. In addition, CJA maintains data collection, storage and processing practices and security measures to help protect against unauthorized access, alteration, disclosure or destruction of your personal information.
Access to personal information is limited to those employees who have a legitimate business need to access it. CJA mandates login security controls on equipment and systems, multi-factor user authentication, mandatory password expiration, digital storage encryption, routine scheduled patching and updates, and ongoing cybersecurity user training and awareness for CJA staff.
Credit card information provided by you is not held by CJA. It is collected by our third party payment processors specializing in the secure processing of credit or debit card transactions.
We review our record retention periods for personal information on a regular basis. The periods of retention depend on the type of data collected, the purpose for which the data is given, and requirements of applicable law.
We have put in place procedures to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Despite these measures, CJA does not guarantee, represent or warrant that personal information will always be secure. CJA makes no guarantee, representation or warranty that the use of this website is protected from viruses, worms or other vulnerabilities.
Sharing Your Information
We will not sell your personal information, and we will not pass your personal information to any third parties except in the circumstances set out in this policy.
We may allow our staff, volunteers, consultants, or other providers acting on our behalf (for example, our website hosts) to access and use your personal information for the purposes for which you have provided it to us. If we do this, we will not give those individuals/organizations any rights to use your personal information (or to contact you) except in accordance with this policy.
The times we will pass your details to another include:
- to enable payment providers to complete transactions
- to prevent online fraud
- where we are required to do so by any law or court order
- if you are a client, and the details are provided to others who are assisting us with your case
- where CJA or substantially all of its assets are acquired by a third party, in which case personal data held by us will be one of the transferred assets.
From time to time, a donor’s name and address may be shared with other not-for-profit organizations whose missions may be of interest to the donor. Those organizations may use that data for a one-time communication and may not retain the donor’s name and address unless the donor provides that information through a donation or other instruction by you. CJA seeds such lists with CJA accounts so that we can be alerted to any misuse. E-mail addresses and telephone numbers are never shared with third parties. If you do not wish to have your name and address shared with other not-for-profit organizations, please contact us at datacontroller@cja.org.
As always, you may change your subscription preferences or unsubscribe from CJA emails at any time by clicking the link at the bottom of our communications.
Your Right To Access, Update, & Delete Personal Information
You have the right to:
- Update the information we hold about you if it is wrong
- Change your communication preferences at any time
- Request a copy of the information we hold about you
- Object to the processing of your information for marketing purposes
- Request restriction of processing of your personal data
- Request the transfer of your personal data to you or to a third party
- Withdraw consent at any time where we are relying on consent to process your personal data
- Ask us to delete your personal information from our records
Please note that if you request that your information be deleted, we may be required to keep such information and not delete it, or keep it for a certain time for legal or administrative reasons. When we delete any information, it will be deleted from the active database, but it may remain in our archives. We may also retain information for fraud prevention or similar purposes. Also, note that we may need to delete your user account in order to delete your personal information.
You can contact us by:
- sending an email to datacontroller@cja.org
- writing to CJA at 268 Bush St #3432, San Francisco, CA 94104
- calling (415) 544-0444.
Our aim is for all information that we hold about you to be accurate and, where necessary, kept up-to-date. If any of the information we hold about you is inaccurate and either you advise us of this or we become aware in another way of its inaccuracy, we will ensure it is updated as soon as possible. If you contact us with changes, we will make good faith efforts to make requested changes in our then-active databases as soon as reasonably practicable. Note, however, that information may persist internally for our administrative purposes and that residual data may remain on backup media or for other reasons.
Legal Compliance
CJA will share personally identifiable information about those who use our website or communicate with us to:
- comply with a valid legal inquiry or process such as a search warrant, subpoena, statute or court order, or if in our opinion such disclosure is required by law
- obtain or maintain insurance coverage, manage risks, obtain professional advice, or establish, exercise or defend legal claims, whether in court proceedings or in an administrative or out-of-court procedure
- protect the safety, interests, rights, property or security of CJA, you, or any third party;
- respond to a breach or attempted breach of the security of our website
- defend or assert our legal rights
- comply with the request of governmental authorities conducting an investigation.
External Links
This Privacy Policy applies only to your use of the CJA website. This site contains links to other sites. We are not responsible for the privacy practices of those other sites. The presence of a link to another site does not imply that CJA endorses the content or policies of that site. We recommend that you read the privacy policies of each site you visit to determine what information they may be collecting from you.
Compliance with Children’s Online Privacy Protection Act
Protecting the privacy of minors is especially important. For that reason, CJA never knowingly collects information at the website from users who are under 16 years of age, and no part of the website is structured specifically to attract anyone under 16. If CJA becomes aware of having information about anyone under 16, CJA will promptly delete the information.
California Privacy Rights
Pursuant to California Civil Code Section 1798.83, residents of the State of California may request information once per calendar year about CJA’s disclosures of certain categories of your personally identifiable information to third parties for their direct marketing purposes. Such requests must be submitted to CJA datacontroller@cja.org.
GDPR
The website is published in the United States and subject to laws of the United States. If you are located outside of the United States, please be aware that any information you provide to us may be transferred to and processed in the United States and other countries. By using the website, or providing us with any information, you consent to this transfer, processing and storage of your information in countries where the privacy laws may not be as comprehensive as those in the country where you reside or are a citizen.
If you are an EU resident or citizen, you have additional rights in connection with your personal information pursuant to the General Data Protection Regulation (“GDPR”), including the right to request a copy of your personal information that CJA may have, and the right to request that we update, delete or anonymize that information.
If you have any GDPR-specific questions or requests, please contact CJA at datacontroller@cja.org.
Changes to this Privacy Policy
CJA may update this Privacy Policy at any time. When it does, CJA will revise the updated date at the top of this page. We encourage you to frequently check this page for any changes to stay informed about what information CJA collects and how it uses that information. You acknowledge and agree that it is your responsibility to review this Privacy Policy periodically and become aware of any modifications since your last visit.
Acceptance of These Terms
By using the website, you acknowledge your acceptance of this Privacy Policy, including as it is amended from time to time. If you do not agree to this policy, please do not use the website. Your continued use of the website following the posting of changes to this Privacy Policy will be deemed your acceptance of those changes.
Contacting CJA
If you have any questions about this Privacy Policy or anything relating to the website, please contact CJA at datacontroller@cja.org.
CJA Data Controller may be reached by emailing datacontroller@cja.org. Please write “Data Controller Request” in the subject line to ensure it is received and processed in a reasonable time.