Privacy Policy

Introduction

SUSAR is committed to safeguarding the personal information entrusted to it. This Privacy Policy explains how the State Urban Search and Rescue Alliance, Inc., a New Jersey nonprofit corporation (“SUSAR”), collects, stores, uses, and discloses information about you through the SUSAR website, event and registration management applications, office and meeting applications, and any other SUSARoperated sites and applications (collectively, the “SUSAR Platforms”). SUSAR complies with applicable federal and state privacy laws and, where applicable, international requirements.

SUSAR is based in the United States, and its service providers host data in the United States. By using the SUSAR Platforms you consent to the transfer to, and processing of, your information in the United States. SUSAR meetings may be recorded; participation in a SUSAR-organized meeting after notice of recording constitutes consent to be recorded. Links to third-party websites are governed by those parties’ own privacy policies. This policy may be modified at any time; continued membership or use of the SUSAR Platforms constitutes agreement to the current version, and material changes will be announced through the SUSAR Platforms.

Information We Collect and How We Use It

The SUSAR Platforms may store personal information including your name; contact information; demographic data; login credentials; membership sign-up and renewals; event registrations; donations; payments and payment history; biographical or business information you choose to share; socialnetwork links; forum and survey posts; volunteering and committee assignments; document and photo uploads and downloads; custom form submissions; certifications and training records; storefront purchases; interest-group registrations; and email-engagement data. Some information is required to maintain accurate records, for legal protection, or to provide services; other information is optional.

SUSAR uses this information to operate the organization; provide coordination and support services to members; maintain accurate financial records; fulfill legal obligations applicable to nonprofits; promote the organization; communicate news and activities; and advocate for issues important to members. Only authorized administrators appointed by SUSAR have access to member personal information. The Platforms also automatically collect standard technical information (IP address, log files, access times, device and browser data, session cookies, pixel tags) used to provide and maintain the site, manage performance, perform accounting and billing, and for security purposes, including detecting and preventing fraud, abuse, and security breaches; protecting the rights and property of SUSAR and others; providing a safe online environment; and managing and resolving legal claims.

Information disclosed in public discussion forums may become public; exercise caution when posting. If a third-party membership-verification module is enabled, your provision of credentials to that third party is governed by its privacy policy.

Mobile Application Permissions

If SUSAR enables a mobile app, the app may request device permissions, used only as follows: Calendar (adding events only at your direction); Location (stored and displayed to other users only when you affirmatively share it, for a limited time, and not shared with third parties); Microphone (no audio is stored or recorded); Phone (pre-loading the dialer when you tap a number; no contact logs or numbers retained); Contact logs (never accessed); Notifications (chat and message alerts); Storage (saving or displaying files only at your direction, plus automatic caching); Carrier/network information (not retained or shared); Camera (only when you choose to add a photo); and session cookies (deleted on logout; no financial information is kept in persistent cookies).

Legal Basis for Processing

SUSAR is the data controller for personal information processed through the SUSAR Platforms and is responsible for its security and integrity; SUSAR’s technology vendors act as data processors on SUSAR’s behalf. SUSAR collects and stores your personal information to manage your membership and your participation in its activities. Paying a membership fee, registering for an event, making a donation, purchasing from the storefront, requesting to join the mailing list, or logging in as a member each indicates your intent to establish a relationship with SUSAR permitting that collection. You may end this relationship at any time and request removal of your data, subject to SUSAR’s obligation to maintain accurate records.

Sharing of Information

Information about you is shared only as described in this policy. SUSAR may display certain information (generally your name and, in some cases, contact information) publicly, such as committee membership, event or volunteer registration, uploaded photos or documents, and directory participation; you may control much of this through your privacy settings and may decline to participate in activities that involve sharing. Logged-in members may see more information about other members. SUSAR administrators and coordinators with access to data assume responsibility to protect its privacy and integrity.

SUSAR may share data with vendors and service providers that help operate the SUSAR Platforms — including hosting, payment processing, address verification, analytics, and platform consultants — strictly limited to what is necessary for the vendor to perform its services and subject to contractual confidentiality obligations. SUSAR may also retain and disclose information where required by applicable law or legal process, as part of an audit, or where necessary to enforce its Terms of Service or defend against threats or fraud.

What SUSAR Will Not Do

SUSAR will not sell, rent, or trade your personal information. Board members, Officers, and agents of SUSAR do not have direct access to your password or full banking or credit card information; this data is encrypted by the system. Following authorization of a card transaction, only the first four and last four digits are retained, consistent with Payment Card Industry (PCI) requirements. SUSAR may publish aggregate statistics that cannot be linked to an identifiable person.

Security and Data Retention

SUSAR data is maintained on servers hosted by an independent provider in a secure data center behind a firewall, with physical access limited to authorized personnel, and protected by technical and operational measures. No method of electronic storage or transmission is completely secure; email in particular may not be secure. Use strong credentials, do not share them, and log out on shared devices.

SUSAR retains records of memberships, events, fundraising, and platform use for as long as needed to serve members, maintain accurate membership, financial, and accounting records, honor communication preferences, secure the platform, and comply with legal and financial requirements, in accordance with SUSAR’s records-retention policy. Exported backups may persist for an additional period.

Your Rights and Options

Members may log in to view and update their contact information, transaction and payment history, registrations, stored payment details, and privacy settings, including opting out of general announcements. Non-members may request access to and correction of their personal data. Members and non-members may request deletion of their information (for members, this constitutes resignation); such requests may be made through the profile screen, the email opt-out screen, or by email to SUSAR’s designated privacy contact. Requests to object to or restrict processing, or to withdraw consent, are treated as deletion requests and are not retroactive. Requests will be logged; SUSAR will accept or decline a request within 30 days (with reasons if declined), after which information without a compelling business reason for retention will be deleted and information with such a reason (such as transaction and donation records) will be anonymized. You may also complain to your local data protection authority.

International, UK, and California Provisions

For personal data of individuals located in the European Union, United Kingdom, or Switzerland, SUSAR processes personal data consistent with applicable data-protection laws, including the GDPR and UK GDPR where they apply. SUSAR warrants that transfers and processing are carried out in accordance with applicable data-protection law; that security measures appropriate to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access are used; and that sub-processors involved in processing are bound by equivalent obligations.

California residents have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including the right to know the categories and sources of personal information collected, the business purpose for collection, and the third parties with which it is shared; the right to access and correct personal information; the right to request deletion; and the right to non-discrimination for exercising these rights. Verified requests will be answered within 45 days. SUSAR does not sell or share personal information for cross-context behavioral advertising.

Children

The SUSAR Platforms are not intended for unsupervised use by children under 13, and SUSAR does not knowingly collect information from children under 13.

Contact

Questions, comments, or concerns about this Privacy Policy or your rights should be directed to SUSAR’s designated privacy contact: SUSAR, 971 US Highway 202N, Suite #5011, Branchburg, NJ, 08876; support@susar.org.

Questions and Exceptions

Questions regarding this policy, and requests for policy exceptions, shall be directed to the Executive Committee. Exceptions may be granted only by the Executive Committee or the Board of Directors and shall be documented in the minutes.