Charidy Privacy Notice
This Privacy Notice (the "Notice") describes the information that Charidy, Inc. ("Charidy", “we”, “us”, “our”) collects and processes from donors and representatives of fundraising organizations. It also covers information we collect and process from visitors to our website charidy.com and our smartphone apps (the “Platform”) and registered users on the Platform.
It also describes our practices for collecting, using, maintaining and processing your information, and the rights and options available to you with respect to the personal data we process.
PERSONAL DATA COLLECTED
We process information you provide us when you submit an inquiry through our Platform, by email or through another contact channel You can submit an inquiry through our online contact form or by calling, emailing or writing to us. We will collect the information you provide in the inquiry, which typically includes your name, email address, other contact information, country, and the text of your message. We refer to this as “Inquiry Information”. The mandatory fields for completion of our online contact-us forms will be marked.
We process your information when you register as a user on the Platform
If you register as a user on the Platform, we will collect and process your name, email address, chosen account password, fax and telephone number (optional), profile image (optional), your account preferences and, optionally, your selected payment method (which is not processed by Charidy but rather by our authorized payment processors). The above information is referred to as “User Account Information”.
If you register via your Facebook or Google account, we obtain some of this information from Facebook or Google.
We process your information when you donate
When you make a donation, whether through the Platform or through our call center representatives, we will collect the information necessary to process your donation such as your name, the name you would like to be displayed on the Platform with your donation (or whether you would like your donation to be displayed on the Platform as “anonymous”), your email address, phone number, address and payment information, donation message or dedication (optional), donation amount and currency, donation instalments and recurrence and the fundraising organization to receive the donation.
Your payment information is not processed by Charidy but rather by our authorized payment processors. We also process the donation invoice information. If you donated through the Platform, we also process the IP address of your device.
We refer to all this as “Donation Information”.
We process information as a representative of a fundraising organization when you register your organization on our Platform.
If you are a representative of an organization looking to engage in fundraising through the Platform, you may register your organization for this purpose. We will ask you to provide you name, work email address, phone number, organization name and country. We refer to this as Organization Representative Information.
You do not have a legal obligation to provide us with the abovementioned information; however, if you choose not to provide this information we may not be able to respond to your inquiry, process you donation or register you on the Platform.
We also collect analytics information about your use of the Platform.
When you use the Platform, we record and collect certain information about your interactions with the Platform, including the IP address from which you access the Platform, time and date of access, type of browser used, language used, links clicked, and actions taken while using the Platform. We refer to this as Analytics Information".
We may process contact information the organization provided us of potential donors. We are not the controller of such information and will only process such information on behalf of the organization.
Organizations who run fundraising campaigns via the Platform may upload to our systems a list with the contact information of potential donors. The fundraising organization can then use our systems to send emails about its fundraising campaigns to the potential donors on that list. That organization is the controller of such information and we are merely the processor of this information on behalf of the organization and as per its instructions. For more information on how that information is processed, please contact the fundraising organization.
HOW YOUR PERSONAL DATA IS USED
To respond to and handle your inquiry.
We will use your Inquiry Information to contact you about your inquiry and handle your inquiry.
To process your donation to your chosen organization.
We will use your Donation Information to process your donation to your chosen organization.
To allow you access to information about your past donations and to allow you to more seamlessly make future donations
We will use your User Account Information to administer your user account on the Platform. This allows you to manage more easily, and review your past donations and make future donations.
To allow your organization to raise donations via the Platform.
We will use your Organization Representative Information to register your organization to our Platform and allow your organization to run and manage its fundraising campaign via the Platform.
To send you administrative and marketing communications
We will use Donation Information, User Account Information and Organization Information to send you administrative communications regarding your donation (if you are a donor)
or fundraising campaigns (if you are the representative of a fundraising organization). If you provide us your explicit consent, we will also use your information to send you our newsletters and other marketing communications about Charidy’s services and donation campaigns. You will be able to withdraw your consent at any time via the “unsubscribe” link enclosed in each marketing communication you will receive from us.
If you are a donor from Israel donating to a donation campaign in Israel, we and other companies we have partnered with will use your information to email you offers for services complementary to your donation, such as assistance in receiving a tax refund for your donation. You can ask to unsubscribe from these emails via the “unsubscribe” link enclosed in each of these emails you receive.
We will use the Analytics Information for enhancing and developing our Platform.
We will use the Analytics Information for development and enhancement of the Platform, our email communications and the products and services we offer to customers and users.
We also use the Analytics Information to better understand the market in which Charidy operates in and for managerial reporting and business planning.
WHO WILL PROCESS YOUR DATA
We will not share your information with third parties, except in the events listed below or when you provide us your explicit and informed consent. These are also the categories of third parties with whom Charidy has disclosed personal information in the preceding 12 months.
We will share your information with our service providers who help us to operate the Platform and our business.
We will share your information with our service providers who assist us with the internal operations of our business and the Platform. These companies are authorized to use your personal information in this context only as necessary to provide these services to us and not for their own promotional purposes. They include Amazon Web Services, Google, Rocket Science Group (Mailchimp), Mailgun Technologies, ZenDesk, JN Projects (HelloSign), our sales freelance contractors, and our Israeli operations subsidiary. We do not sell your personal information to third parties.
We will share your Donation Information with the organization you donated to.
We will share your Donation Information with the organization you donated to, for their bookkeeping and other purposes. We do this even if you indicated that you would like your donation to be anonymous, because your choice for anonymity applies only to publicly posting your donation. The fundraising organization is a separate and independent controller of that information when it receives and uses it. To learn more about how these organizations will process your information, please review their privacy policy.
We will share your Information with competent authorities, if you abused your right to donate or use the Platform, or violated any applicable law.
If you have abused your rights to use the Platform, or violated any applicable law, we may share your information with competent authorities and with third parties (such as legal counsels and advisors), for the purpose of handling of the violation or breach.
We will share your Information if we are legally required to do so.
If we are required to disclose your information by a judicial, governmental or regulatory authority.
We will share your Information with third-parties in any event of change in Charidy’s structure.
If Charidy’s operation is reorganized within a different framework, or through another legal structure or entity (such as due to a merger or acquisition), we will share your information only as required to enable the structural change in the operation of Charidy.
We do not sell your information.
We do not sell your information, nor have we done so in the past 12 months.
COOKIES
What are cookies?
Cookies are text files, comprised of small amount of data, that are saved on your computer or other device (e.g. smartphone, tablet, etc.) when you use the internet and visit various websites.
The information that the cookies maintain is read by the website you visit, during the session of your visit to the website (these are called ‘session’ cookies), and when you return to visit it again (these are called ‘persistent’ cookies). We also use techniques called web beacons and web pixels for purposes similar to the use of cookies.
We use cookies necessary to operate the Platform, for statistics and to remember your preferences.
We use cookies when you visit our Platform for a number of purposes, as briefly explained below:
Necessary. Cookies that are strictly necessary for the functioning of the Platforms. The Platform cannot operate properly without these cookies. You can set your browser to block or alert you about these cookies, but some parts of the Platforms may not function properly. Statistics. Analytics cookies that help us understand how you and other users interact with our Platforms by collecting data that does not directly identify you.
You can always delete or disable cookies.
You can always delete the cookies saved on your device through the settings of your computer browser or device. You can also disable cookies for future use through the settings of your computer browser or device.
SECURITY AND DATA RETENTION
We will retain your information for as long as we need it to operate the Platform and interact with donors and organizations, and thereafter as needed for record-keeping purposes.
We will retain your Information for the duration needed to support our ordinary business activities operating the Platform and interacting with donors and organizations who raise funds via the Platform. Thereafter, we will still retain your personal information as necessary to comply with our legal obligations, resolve disputes, establish and defend legal claims and enforce our agreements.
We implement measures to secure your Information
We implement measures to reduce the risks of damage, loss of information and unauthorized access or use of information. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure your personal information, it is not guaranteed, and you cannot expect that the Platform will be immune from information security risks.
INTERNATIONAL DATA TRANSFERS
We will internationally transfer your Information only in accordance with applicable data protection laws.
If we transfer your personal data for processing at locations outside your jurisdiction, we will abide by data transfer rules applicable to these situations.
If you are an EU resident, any transfer of your personal data out of the EU will be in accordance with adequate safeguards determined by the EU Commission.
ADDITIONAL INFORMATION FOR INDIVIDUALS IN THE EU
Charidy is the data controller of the personal information covered by this Notice.
The following is the data controller for the purposes of the personal data covered by this Notice:
Charidy Inc.
1002 Dean Street,
Brooklyn, NY 11238 United States of America
Contact details of our representative in the European Union.
Our representative in the European Union for the purposes of this Notice is Symmetry Solutions Ltd in Ireland.
If you are within the European Economic Area, you may contact our European representative the at the following address:
Symmetry Solutions Ltd
The Tara Building, 11-15 Tara Street Dublin 2, D02RY83, Ireland charidy@symmetrygroup.ie
Legal basis under EU law for processing your personal data
The legal basis under EU law for processing Analytics Information is our legitimate interest in maintaining, developing and enhancing the Platform.
The legal basis for collecting and processing Inquiry Information is our legitimate interests in responding to your inquiry.
The legal basis under EU law for collecting and processing Donation Information to administer your donation and send your administrative messages about your donation, is the performance of the donations contract between Charidy and the data-subject donor.
The legal basis under EU law for collecting and processing User Account Information is our legitimate interests in providing enhanced user-experience for donors who use our Platform.
The legal basis under EU law for processing Organization Representative Information to allow the fundraising organization to raise donations via the Platform and to send administrative messages, is our own and the fundraising organization’s legitimate interests in properly providing (and receiving) our donation-platform services.
The legal basis under EU law to process Donation Information, User Account Information and Organization Information for direct marketing purposes is your explicit consent.
The legal basis under EU law for sharing Donation Information with the organization you donated to, for their bookkeeping and other purposes, is their legitimate interests in administering donations made to them.
The legal basis under EU law for processing your information for the purpose of handling instances of abusive use of the Platforms is our legitimate interests in defending and enforcing against violations and breaches that are harmful to our business.
The legal basis under EU law for processing your information where we are legally required to share it, is our legitimate interests in complying with mandatory legal requirements imposed on us.
The legal basis under EU law for us processing your information in the event of a change in our corporate structure is our legitimate interests in our business continuity.
You have certain rights to access, update or delete your information, obtain a copy of your information, withdraw your consent and object or restrict certain data processing activities.
If you are in the EU, you have the following rights under the GDPR:
Right to Access your personal data that we process and receive a copy of it.
Right to Rectify inaccurate personal data we have concerning you and to have incomplete personal data completed.
Right to Data Portability, that is, to receive the personal data that you provided to us, in a structured, commonly used and machine-readable format. You have the right to transmit this data to another service provider. Where technically feasible, you have the right that your personal data be transmitted directly from us to the service provider you designate.
Right to withdraw your consent to send you our newsletters and other marketing communications about Charidy’s services and donation campaigns.
Right to Object, based on your particular situation, to using your personal data on the basis of our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or for the establishment, exercise of defense of legal claims.
Right to Restrict the processing your personal data (except for storing it) if you contest the accuracy of your personal data, for a period enabling us to verify its accuracy; if you believe that the processing is unlawful and you oppose the erasure of the personal data and request instead to restrict its use; if we no longer need the personal data for the purposes outlined in this Policy, but you require them to establish, exercise or defense relating to legal claims, or if you object to processing, pending the verification whether our legitimate grounds for processing override yours.
Right to be Forgotten. Under certain circumstances, such as when you object to us processing your data and we have no compelling legitimate grounds to override your objection, you have the right to ask us to erase your personal data. However, we may still process your personal data if it is necessary to comply with a legal obligation that we are subject to under laws in EU Member States or for the establishment, exercise or defense of legal claims.
If you wish to exercise any of these rights, contact the merchant/e-wallet through the channels listed on their privacy notices.
If you wish to exercise any of these rights, you may do so by contacting us by email to GDPR@charidy.com or through our support portal at https://www.charidy.com/contacts. If you are a registered user on the Platform, you may exercise some of these rights directly through the settings page of your account.
We reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. Where we are not able to provide you with information that you have asked for, we will explain the reason for this.
You have a right to submit a complaint to the relevant supervisory data protection authority.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint to the supervisory authority, in particular in the Member State of your residence, place of work or place of alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here.
ADDITIONAL INFORMATION FOR INDIVIDUALS IN CALIFORNIA
Below is a detailed description of the information we collect from visitors to our Platform and the business or commercial purposes for which we use each category of personal information. This is also the information we have collected in the past 12 months.
Categories of Personal Information | Typical Types of Personal Information Collected | Business or commercial purposes pursuant to the CCPA | Specific purposes |
Identifiers | Name, email address, telephone number | Providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments. Performing services on behalf of the business or service provider, including maintaining or servicing accounts, providing customer service, providing analytic services, or providing similar services on behalf of the business or service provider. | |
Professional-related information | For a representative of an organization looking to engage in fundraising through the Platform: name, work email address, phone number, organization name and country | ||
Information that identifies, relates to, describes, or is capable of being associated with, a particular individual | Information you provide when you interact with us. Your donation message or dedication. | ||
Your account preferences | |||
Commercial information, including records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. | Information about donations you make, including payment information, donation amount and currency, donation instalments and recurrence, the fundraising organization to receive the donation | ||
Internet or other electronic network activity information | Your browser type, operating system, IP address. | Detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity, prosecuting those responsible for that activity. Undertaking internal research for technological development and demonstration. | See above in “How your data is used” and “Who will process your data” |
Undertaking activities to verify or maintain the quality of the service and to improve, upgrade or enhance the service. | |||
Debugging to identify and repair errors. | |||
Performing services on behalf of the business or service provider, including maintaining or servicing accounts, providing customer service, providing analytic services, or providing similar services on behalf of the business or service provider. |