Privacy Policy & Terms of Use

This is the website of Live Action / liveaction.org
Our postal address is:
2200 Wilson Blvd, Suite 102, #111
Arlington, VA 22201-3324

Live Action, (“LA”) respects your privacy as a visitor to its website and has developed the following privacy policy to inform you about how LA handles your personal information after receiving it. This Privacy Policy, together with Live Action’s SMS Disclosures available at liveaction.org/sms-disclosures/, governs LA’s use of your information both on the LA website (liveaction.org), on the LA App, and further governs the use of your personal information through LA-controlled automated telephone dialing systems and other technologies and systems to send SMS, personal messaging, and other text messages.

Please read this Online Privacy Policy carefully to understand our policies and practices regarding your information and how we will treat it. If you do not agree with our policies and practices, your choice is not to use our Website. By accessing or using this Website, you agree to this Policy. This Policy may change from time to time. Your continued use of this Website after we make changes is deemed to be acceptance of those changes, so please check the Policy periodically for updates.

This website is not intended for children and we do not knowingly collect data relating to children.

1. Controller

LA is the controller and responsible for your personal information (“LA”, “we”, “us” or “our” in this Privacy Policy).

We have appointed a Data Protection Officer (“DPO”) who is responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact the DPO using the details set out in Section 14 below.

You have the right to make a complaint at any time to EU supervisory authorities for data protection issues (https://edps.europa.eu/data-protection/our-role-supervisor/complaints_en). We would, however, appreciate the chance to deal with your concerns before you approach such authorities so please contact us in the first instance.

2. Types of Information Collected and Stored

2.1 Personal Information Summary

When you engage in activities such as sign up to receive an LA publication, register for an LA program, or other event hosted by LA, make a charitable contribution to LA, shop on our Website, or otherwise use the LA website, LA may gather your personally identifiable information (“Personal Information”).

Your Personal Information may include, but is not limited to, your name, address, phone number, email address, birthdate, electronic signature, personal identification numbers, IP addresses, mobile device identifiers, geo-location, or any other personally identifying data collected from you by LA or its authorized Data Processors.

By using the LA website, you agree to allow LA and its Data Processors to gather, store, and share your Personal Information subject to the limits of this Online Privacy Policy.

2.2 Data Collection Summary

There are specific types of data we collect about you. We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

2.2.1. Identity Data. Includes first name, maiden name, last name, username or similar identifier, marital status, title, date of birth and gender.

2.2.2. Contact Data. Includes billing address, delivery address, email address and telephone numbers, personal messaging, SMS, and other texting contact information. SMS-related data collection is also governed by LA’s SMS Disclosures, available here: liveaction.org/sms-disclosures/

2.2.3. Financial Data. Sign up to receive an LA publication, register for an LA program, register for an LA conference or other event hosted by LA, make a charitable contribution to LA, shop on our Website, LA utilizes third-party payment Data Processors as its Data Processors (“Payment Data Processors”) to process your payment and provide payment verification to LA concerning your payment. LA and its Payment Data Processors utilize systems whereby we substitute a proxy set of identifying information for your real financial information. Our Payment Data Processors, which do handle your credit cards and other payment information, are PCI Data Security Standard (“PCI DSS”) compliant. As a result, LA does not collect or store your credit card numbers or other similar financially-related Personal Information and it isn’t exposed more than necessary. For more information about PCI DSS visit http://www.pcisecuritystandards.org/about_us/.

2.2.4. Transaction Data. Includes details about payments to and from you and other details of LA products and services you have purchased from us.

2.2.5. Technical Data. Includes internet protocol (IP) address, your LA login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access this Website.

2.2.6. Profile Data. Includes your LA username and password, LA purchases or orders made by you, your interests, preferences, feedback and survey responses.

2.2.7. Usage Data. Includes information about how you use the LA Website, products and services.

2.2.8. Marketing and Communications. Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

2.2.9. Aggregated Data / Analytics Information. We also collect, use and share Aggregated Data. In an effort to improve visitors’ experiences on the LA Website, LA gathers this Aggregated Data related to individuals’ website visits. This information is used solely to measure and improve our Website and services and to better serve our members and customers. LA uses aggregate statistical data to compile reports. If we combine or connect Aggregated Data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy. This analytics information so gathered is likely to include the following:

2.2.9.1.  Device and network specific information, such as your unique device identifier, operating system and version, the browser you use, your Internet service provider (ISP), and your IP address.

2.2.9.2.  Non-personal information, such as language, zip code, area code, location, and the time zone.

2.2.9.3.  LA website visit information, such as the domain from which you came to our Website or referring links, and details of how you use our Website, including but not limited to what webpages you visit on the LA website, as well as downloads, purchases, and orders during the duration of your visit. At times we will track user behavior over time during interactions with the site in order to pursue legitimate business interests, including, but not limited to, troubleshooting technical user issues with site services.

2.3 Sensitive Information

We do not collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health, and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.

2.4 Cookies and Browser “Do Not Track” Notice

2.4.1.  LA may use cookies on your computer. A cookie is a small piece of data sent from a website and stored in a user’s web browser while the user is browsing that website.  Every time the user loads the website, the browser sends the cookie back to the server to notify the website of the user’s previous activity. Third parties that advertise on the LA website do not have access to LA cookies, but they may use their own cookies on your computer. Advertisers’ use of their cookies and device identifiers is subject to the advertisers’ own privacy policies. LA does not correlate its use of cookies with your Personal Information.

2.4.2.  LA websites may utilize page tags or web beacons to track information related to user visits as a part of LA data analytics processes and user experience customization as described below. Page tags are small pieces of Javascript embedded in webpages that collect data to help track web traffic on our website. Web beacons are very small, effectively invisible, graphic images we use to count and recognize users on our website. Such technologies enable us to improve and customize user experiences while users visit our website. LA does not correlate its tracking activities through the use of page tags or web beacons with your Personal Information.       

2.4.3.  LA may employ third party data analytics firms to track and analyze traffic on the LA website, to analyze visitor trends, to determine advertising effectiveness, browser types and usage trends, and to present targeted ads based on anonymous information collected through tracking. LA’s third party analytics firms, as described in this section, do not receive your Personal Information.

2.4.4.  Third parties that may advertise on LA websites may have content embedded that sets cookies on a visitor’s browser and/or tracks visitor information that a web browser visited a specific LA website. Such information may contain a visitor’s IP address. Third parties may not collect identifying Personal Information from the LA website unless you provide it to such third parties.

2.4.5.  You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this website may become inaccessible or not function properly.

2.5 Keeping Information Updated

It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your relationship with us.

3. Security of Personal Information

LA takes the security of your Personal Information very seriously. When your Personal Information is stored by LA, we use reasonable and appropriate measures to protect it from loss, misuse and unauthorized access, disclosure, alteration and destruction. Unfortunately, data transmission over public networks cannot be guaranteed to be one hundred percent secure. While LA will use all reasonable means to protect your Personal Information, LA cannot guarantee the security of your transmissions of such Personal Information, and you use the LA website at your own risk. If you suspect your Personal Information has been compromised, please notify LA’s Operations Director using the contact information provided below.

4. How we Collect Your Personal Information

4.1 Collection Methods

We use different methods to collect data from and about you including through the following methods:

4.1.1. Direct Interactions. You may give us your Identity, Contact and Financial Data by filling in forms or by corresponding with us by post, phone, email or otherwise. This includes Personal Data you provide when you:

4.1.1.1. apply for our products or services;

4.1.1.2. create an account on our website;

4.1.1.3. subscribe to our service or publications;

4.1.1.4. request marketing to be sent to you;

4.1.1.5. make a contribution to LA;

4.1.1.6. purchase goods or services from LA;

4.1.1.7. sign-up for, subscribe to, or otherwise request Live Action to send you personal messages, SMS, or other text messages.  SMS-related data collection is also governed by LA’s SMS Disclosures, available here: [liveaction.org/sms-disclosures/];

4.1.1.8. enter a program, event, promotion or survey; or

4.1.1.9. give us feedback or contact us.

4.1.2. Automated Technologies or Interactions. As you interact with our Website, we will automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive Technical Data about you if you visit other websites employing our cookies. We may process your personal data through the use of automated technologies, such as automatic telephone dialing system to contact your wireless telephone number

4.1.3. Technical Data from the following parties:

4.1.3.1. analytics providers such as Google based outside the EU;

4.1.3.2. advertising networks based inside OR outside the EU; and

4.1.3.3. search information providers based inside OR outside the EU.

4.1.4. Contact, Financial and Transaction Data from providers of technical, payment and delivery services based inside OR outside the EU.

4.1.5. Identity and Contact Data from data brokers or aggregators based inside OR outside the EU.

4.1.6. Identity and Contact Data from publicly available sources.

5. How LA Uses and Shares Your Information

5.1 General Information and Your Rights

LA limits its use of your Personal Information to the stated purposes for which such information is collected. In some cases, LA may be required to disclose your Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. You have the right to the following regarding your Personal Information transferred to LA:

5.1.1. To know the types of Personal Information LA collects;

5.1.2. To know the purposes for which it collects and uses your Personal Information;

5.1.3. To know type or identity of third parties to which LA discloses your Personal Information, and the purposes for which it does so;

5.1.4. To access and update your Personal Information; and

5.1.5. To know the choices and means LA offers you for limiting the use and disclosure of your Personal Information.

5.2 LA Services to LA ID Holders.

When you create an LA ID, we may use information collected from technologies such as cookies, web beacons, and page tags, as described herein, to improve your experience of our website. For example, by saving information concerning the pages you visit and donations you make, we will be able to provide you with additional information on LA that may be of interest to you.

In creating an LA ID, and as a condition of having an LA ID, you expressly consent to LA’s use of your Personal Information and non-personally identifiable information as described in this section.  Moreover, in using an LA ID you expressly acknowledge and agree to our collection and use of such information as described in this section.

You can opt-out of the use of your Personal Information as described in this section by deleting your LA donor profile. To delete your LA donor profile, please contact LA’s Operations Director using the contact information provided below.

5.3 Other LA Services

LA may use your Personal Information to provide services to you upon your request. Such services may include sending you newsletters and publications, responding to your questions and comments, communicating with you concerning your donations on the LA website, emailing you updates concerning LA, and personalizing your visits to LA website.

You may opt-out of the use of your Personal Information as described in this Section by contacting LA’s Operations Director using the contact information provided below.

5.4 LA Internal Data Sharing

LA may also share your Personal Information with other LA offices in the country in which you reside and in other countries.

5.5 Information Sharing with Third Parties

5.5.1. This website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

5.5.2. LA may utilize third-party service providers that process your Personal Information solely on LA’s behalf (“Data Processors”). When LA transfers your Personal Information to its Data Processors, your Personal Information will be used only for limited and specified purposes. LA will take reasonable and appropriate steps to ensure that its Data Processors process your personal information in a manner consistent with the organization’s obligations under the Principles. LA remains responsible and liable if the Data Processors that LA engages to process your Personal Information on LA’s behalf do so in a manner inconsistent with this Online Privacy Policy and the Privacy Shield Principles, unless LA proves that it is not responsible for the event giving rise to the damage.

5.5.3. LA may share aggregated demographic information with our partners and advertisers. This is not linked to any Personal Information that can identify any individual person.

5.5.4. LA uses outside third parties for financial service-oriented third parties to bill users for goods and services. All parties with which LA shares your Personal Information are bound by confidentiality and data transfer agreements consistent with this Online Privacy Policy.

5.5.5. LA may partner with third parties to provide other specific services, including, but not limited to registration for LA conferences, programs, events, and other LA program and educational materials. When you sign up for these services, we may share names, or other contact information that is necessary for the third party to provide these services. LA may auto-populate forms utilized by these third parties with data contained in LA managed cookies. These third parties are not allowed to use your Personal Information except for the purpose of providing these services. All parties with which LA shares your Personal Information are bound by confidentiality and data transfer agreements consistent with this Online Privacy Policy. Text messaging originator opt-in data and consent will not be shared with any third parties unless required by law.

5.6 Other Possible Disclosures

In addition to the other disclosures stated herein, LA may share your information in the following ways:

5.6.1. To comply with applicable laws, regulations, legal processes, or government enforced orders.

5.6.2. To enforce applicable terms of service, protect our legal rights or defend against legal claims.

5.6.3. To defend, prevent, take action, and otherwise address security or technical issues, as well as suspected or potential fraud.

5.6.4. To comply with LA’s obligations to address complaints arising under this Online Privacy Policy, EU Data Protection Authorities, or other necessary entities.

5.6.5. To guard against harm (whether actual or potential) to the legal rights, property or safety of LA, our visitors or the general public as required or permitted by law.

6. International Transfers

6.1 Personal Data

We share your personal data within LA. This will involve transferring your data outside the European Economic Area (EEA).

6.3 Third Parties

Many of our external third parties are based outside the EEA so their processing of your personal data will involve a transfer of data outside the EEA.

7. LA’s Purposes In Using Personal Information

7.1 Lawful Processing

Note that we may process your personal information for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your personal information where more than one ground has been set out in the table below.

7.2 Use of Personal Information

We have set out below, in a table format, a summary of the ways we plan to use your Personal Information, and which of the legal bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Table Summary


PURPOSE/ACTIVITY

TYPE OF DATA

LAWFUL BASIS FOR PROCESSING INCLUDING BASIS OF LEGITIMATE INTEREST

 

To register you as a new customer or member.

(a) Identity

(b) Contact

Performance of a contract with you

To register you for LA events, conferences and programs.

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(e)  Financial

(f)  Transactional

a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To process and deliver your order including:

(a) Manage payments, fees and charges

(b) Collect and recover money owed to us

(c) Manage contributions to LA

(a) Identity

(b) Contact

(c) Financial

(d) Transaction

(e) Marketing and Communications

(a) Performance of a contract with you

(b) Necessary for our legitimate interests (to recover debts due to us)

To manage our relationship with you which will include:

(a) Notifying you about changes to our terms or privacy policy

(b) Asking you to leave a review or take a survey

(c)  Managing LA member services.

(a) Identity

(b) Contact

(c) Profile

(d) Marketing and Communications

(e)  Financial

(f)  Transactional

(a) Performance of a contract with you

(b) Necessary to comply with a legal obligation

(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)

To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)

(a) Identity

(b) Contact

(c) Technical

(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganization or group restructuring exercise)

(b) Necessary to comply with a legal obligation

To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you

(a) Identity

(b) Contact

(c) Profile

(d) Usage

(e) Marketing and Communications

(f) Technical

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

To use data analytics to improve our website, products/services, marketing, customer relationships and experiences

(a) Technical

(b) Usage

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)

To send you automated messages, including SMS messages, about our upcoming events, our available goods and services, news, reports, with links to information that we believe will be of interest to you.

(a) Identity

(b) Contact

(c) Technical

Necessary for our legitimate business interests (to advance our important educational purposes, develop our marketing and other business objectives). SMS-related data uses are also governed by LA’s SMS Disclosures, available here: liveaction.org/sms-disclosures/

To make suggestions and recommendations to you about goods or services that may be of interest to you

(a) Identity

(b) Contact

(c) Technical

(d) Usage

(e) Profile

(f) Marketing and Communications

Necessary for our legitimate interests (to develop our products/services and grow our business)


8. Data retention

8.1 Purposes

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

8.2 Time Factors

To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

9. LA Email Uses

9.1 Consent

LA never rents or sells email addresses to outside parties without your consent. Occasionally, you may wish to receive information or communication from an LA client. In that instance, you will be asked for permission to share your email address.

9.2 Notice

After you create a LA donor profile, you will receive information about LA products, services, and educational offerings that relate to your areas of interest unless you choose to opt-out. If you have questions or concerns about LA’s Online Privacy Policy or wish to no longer receive such offers (opt-out), please contact LA’s Operations Director using the contact information provided below.

10. How to Access or Change Your Personal Information

10.1 Methods

To review or make changes to the content of your Personal Information, or to request that we limit the use of your Personal Information, you may make changes and updates by logging into your user profile and making such changes. Alternatively, you may request such changes by contacting LA’s Operations Director using the contact information provided below.

10.2 Request

In your request, clearly state what information you would like to have changed or updated.  LA will try to comply with your request as soon possible.

10.3 Retention Purposes

LA may retain certain Personal Information to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes, and enforce agreements.

11. Your Legal Rights

You have a right to:

11.1 Request Access Personal Data

Request access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.

11.2 Request Correction of Personal Data

Request correction of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.

11.3 Request Erasure of Personal Data

Request erasure of your personal data. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.

11.4 Object to Personal Data Processing

Object to processing of your personal data where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes. For example, you may have received automated personal, SMS, and other text messages, but no longer wish to receive such messages.  We will provide a simple mechanism to stop receiving such messages.  In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.  Objections to SMS-related data processing are also governed by LA’s SMS Disclosures, available here: liveaction.org/sms-disclosures/

11.5 Request Restriction of Personal Data Processing

Request restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios:

11.5.1. If you want us to establish the data’s accuracy.

11.5.2. Where our use of the data is unlawful but you do not want us to erase it.

11.5.3. Where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims.

11.5.4. You have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.

11.5.5. You have received automated personal, SMS, or other text messages and wish to stop receiving such messages. Opt-out and other restrictions on SMS-related data collection is also governed by LA’s SMS Disclosures, available here: [liveaction.org/sms-disclosures/]

11.6 Request Transfer of Personal Data

Request the transfer of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

11.7 Withdraw Consent

Withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

12. Verification

The Data Protection Act 2018 and the General Data Protection Regulation (GDPR) are now in force and give individuals in the UK and the European Union enhanced rights over the use of their data.  Under the GDPR, we can only hold and process your personal data on one or more of the grounds authorized by the GDPR. If you feel that any of your rights have been infringed, you have the right to lodge a complaint with the Data Protection Authority for your country. LA will regularly self-assess its compliance with all applicable laws regarding Personal Information that is received from the EU.

13. Notices of Changes to Privacy Policy

In the event of any change to the LA Online Privacy Policy, notice of such changes will be posted on the LA website. Any changes to this Online Privacy Policy will become effective when we post the revised Online Privacy Policy on the LA website. Your use of the LA website following these changes means that you accept the revised Online Privacy Policy.

14. Donor Privacy Policy

LA collects Personal Information of its donors through the various methods described herein, and for the purposes and uses described herein. This policy further describes how donors may contact LA to opt out of sharing their information with third-parties. LA uses industry best practices for encryption in transit and at rest when processing and storing donors’ Personal Information. For example. SSL certificates on LA’s website protect the information provided on a donation form, and LA utilizes a secure owned/first-party cloud infrastructure to process Personal Information other than payment method information. LA minimizes the number of third-party platforms that store or process donors’ Personal Information, and implements a “least privilege” methodology when evaluating any third-party data storage or processing solutions.

15. Contact LA

For any questions, comments, or further information concerning the terms of this Online Privacy Policy, to contact the Data Protection Officer, or to request changes to your Personal Information, subject to such limitations as provided herein, please contact:

Live Action Chief Operations Officer

Josef Lipp

operations@liveaction.org

Phone: (510) 854-9867