Principle 1. We limit how, and with whom, we share your Personal Information.
TruAlly will only share your Personal Information with others for the following purposes:
Principle 2. We collect only the information necessary to deliver the products and services you request.
TruAlly collects only the Personal Information necessary to serve your needs, to protect against fraud, to fulfill legal and regulatory requirements, and for the other purposes set forth below:
|Personal Information||Purpose||Legal Basis|
|Information we receive from you when (i) you visit www.trually.org and other TruAlly websites and (ii) any other information you subsequently provide to us orally, in writing or through the internet: this may include your full name, postal address, e-mail address, employer/business and professional information, job titles, telephone and fax numbers, demographic information, IP address||The Personal Information is used in providing the website and answering requests from you (e.g. if you choose to register to receive information about our products and services or if you enquire about these, we will use your Personal Information in order to respond).||The processing is necessary for the performance of a contract to which you are party or in order to take steps at the request of you prior to entering into a contract. Processing is necessary for the purposes of our legitimate interests, i.e. providing a website for information and use. Your consent (if such consent is required by law).|
|Name, address, e-mail address and other information about your transactions and communications with us.||The Personal Information is used to process or service a transaction or product authorized or requested by you.||The processing is necessary for the performance of a contract to which you are party or in order to take steps at the request of you prior to entering into a contract.|
|Name, address, e-mail address and other contact information||To periodically contact you to inform you of new products, events and/or services we provide or that we consider to be of interest to you, and to provide to our event sponsors and business partners which enables them to inform you of products or services they provide that they consider to be of interest to you.||Your consent (if such consent is required by law)|
|IP address and other information submitted by your browser||To diagnose any problems with our server and administer our website.||Processing is necessary for the purposes of our legitimate interests, i.e. providing a website for information and use.|
|Application data, including your name, address, email, phone number, CV/resume, birthdate, education and job history, candidate job titles, any personal information you elect to provide via cover letters or links to third party sites (e.g., LinkedIn, Twitter, GitHub, Portfolio, etc.), gender, race, disability or veteran status if you elect to share that information during the job application process, photograph, travel-related information such as frequent flyer numbers (if applicable), and visa-related personal information (if applicable), such as passport numbers, proof of citizenship, and birth certificates.||Processing is required to enable us to administer the recruiting process, including the set-up of an electronic job applicant HR file, managing your application, organizing interviews. We may retain your Personal Information following your unsuccessful application so that we may contact you in case of future job vacancies. Your data may also be shared with other TruAlly group companies to consider your application for other job openings.||Primarily, the processing is necessary to take steps for entering into a contract with you. We also have a legitimate interest to (i) store your data for a period of up to 2 years (unless local legal or regulatory requirements prescribe a shorter period) following the conclusion of an unsuccessful application and/or (ii) to share it with the TruAlly group of entities and/or (iii) to retain and use your data as far as necessary for the establishment, exercise or defense of legal claims.|
|All of the above||For compliance with legal and regulatory requirements and corporate governance obligations.||Processing is necessary for compliance with legal obligations to which we are subject.|
We collect Personal Information for the purposes described above when you visit www.TruaAlly.org and other TruAlly websites and from public sources, such as recruiting and business portals (e.g. www.linkedin.com).
Principle 3. We establish safeguards to help ensure the security and confidentiality of your information.
TruAlly restricts access to your information to our employees who need it to do their job. Employees with access to your information are required to strictly maintain the confidentiality of such information.
TruAlly maintains physical, electronic, and procedural safeguards that comply with industry standards to protect your company’s information. We routinely test our information systems and websites to help ensure that unauthorized access does not occur.
Principle 4. We keep your Personal Information for as long as it is necessary to do so to fulfill the purposes for which it was collected as described above.
The criteria we use to determine data retention periods for Personal Information includes the following: (i) Retention in case of queries: We will retain it for a reasonable period after the relationship between us has ceased in case of queries from you; (ii) Retention in case of claims: We will retain it for the period in which you might legally bring claims against us; (iii) Retention in accordance with legal and regulatory requirements: We will consider whether we need to retain it after the period described in (ii) because of a legal or regulatory requirement, e.g. to comply with tax or fiscal duties; (iv) Retention in case of job applications: If you applied for a job offering with TruAlly and have not been successful, your application data will be retained in our talent pool for a limited period as defined in Principle 2.
Our goal is to protect your privacy. To comment or help us improve, please contact us via email (see email contacts below) or telephone (+1 469 626 8309). You may also contact us via a written letter at TruAlly’s address listed above. We may ask you to provide a copy of your proof of identity.
If you consider that we are in breach of our obligations under data protection laws, you may lodge a complaint with the competent Data Protection Authority, which may be the supervisory authority in your country of residence or place of work, of an alleged violation of data protection laws.
Transfers outside the EU/EEA. We also transfer the Personal Information we process to countries outside the European Economic Area (”EEA”) (e.g., when one of our service providers or equipment is based outside the EEA, such as for hosting your Personal Information). We have put in place adequate safeguards with respect to the protection of your privacy, fundamental rights, and freedoms, and the exercise of your rights, e.g. we establish an adequate level of data protection, usually through EU Standard Contractual Clauses based on the EU commission’s model clauses.
Provision of Personal Information / Automated decision making. Please note that the Personal Information we collect from you is necessary to provide the services and the website to you. Failure to provide such data may not enable us to provide our services to you or make our website accessible. We do not use automatic decision-making or profiling of individuals.
Your Rights. You may have various rights under data privacy laws in your country or state. These may include (where required by law): the right to request access to the Personal Information we hold about you; the right to rectification including to require us to correct inaccurate Personal Information; the right to request the restriction of processing concerning you or to object to the processing of your Personal Information, the right to request the erasure of your Personal Information where it is no longer necessary for us to retain it; the right to data portability including to obtain Personal Information in a commonly used machine-readable format in certain circumstances such as where our processing of it is based on a consent; the right to object to automated decision making including profiling (if any) that has a legal or significant effect on you as an individual; and the right to withdraw your consent to any processing for which you have previously given that consent.
Marketing Information. With your consent (if obtaining such consent is required by law), we will keep your name, address and contact details (including telephone numbers and email addresses) in our databases and may from time to time use that information to make you aware of our related products and services as well as updates on developments in our industry sector generally which may be of interest to you. We may contact you in writing, by telephone or email for this. If permitted by applicable law, we may share such information with our event sponsors and/or partners for their own commercial purposes without your consent. If at any time you decide that you do not want your contact details used or shared for these purposes, where applicable, you may object or revoke your consent for receiving marketing communications by following the instructions in the relevant marketing communication (e.g., clicking on the “Unsubscribe” button), by contacting us (see “Give Us Your Feedback” above).
Security Statement. We take reasonable precautions to protect your information. In particular, we implemented appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including as appropriate: (a) pseudonymization (such as where data is separated from direct identifiers so that linkage to an identity is not possible without additional information that is held separately) and encryption, (b) protecting the ongoing confidentiality, integrity, availability, and resilience of systems and services used to process your Personal Information, (c) providing the ability to restore the availability and access to Personal Information in a timely manner in the event of a physical or technical incident; and (d) maintaining a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational security measures. When you submit information to us through our website, your information is protected both online and offline. All data transferred to/from the TruAlly internal network, from/to an external entity, is encrypted to industry standards (256-bit encryption). Please keep in mind that messages you send to us by Internet e-mail may not be secure. We maintain appropriate physical, electronic, and procedural safeguards to ensure the security, integrity, and privacy of your personal information within our company. Only those employees who may require your information to perform a specific job are granted access to your organization’s identifiable information. Furthermore, all employees are kept up to date on our security and privacy practices.