Legal and privacy
Privacy Policy
This policy explains how TUSIC collects, uses, shares, protects and retains personal information when you interact with our website, communications and activities.
01
Overview and scope
This Privacy Policy describes the personal information practices of [FULL LEGAL NAME OF TUSIC ENTITY], referred to in this policy as “TUSIC,” “we,” “us” or “our.”
It applies to personal information collected through tusics.org, our contact forms, membership and volunteer enquiries, donation enquiries, events, programs and other interactions where this policy is provided.
Separate notices may apply to employees, contractors, safeguarding cases, formal investigations or activities governed by a specific agreement.
This policy does not mean that every category or activity described below currently applies. TUSIC should retain only provisions that reflect its actual practices.
02
Personal information we collect
Depending on how you interact with TUSIC, we may collect:
Contact information
- Name, email address, telephone number and mailing address.
- Organization, role, country or preferred language.
- Your preferred method of communication.
Enquiry and correspondence information
- Messages submitted through our Bit Form contact form.
- Emails, letters and other communications.
- The subject, content and status of your enquiry.
- Documents or files you choose to provide.
Participation information
- Volunteer, membership or partnership interests.
- Skills, experience, availability and relevant preferences.
- Event registrations or attendance information.
- Program participation and feedback, where applicable.
Donation and transaction information
- Donation amount, date, currency, restrictions and acknowledgement preferences.
- Limited transaction references supplied by an approved payment provider.
- Information needed for financial records, fraud prevention or regulatory obligations.
TUSIC should not directly collect complete payment-card numbers or online-banking credentials through its general contact form.
Website and technical information
- Internet Protocol address and approximate location.
- Browser, device, operating system and language.
- Pages viewed, referring pages and interaction data.
- Cookie identifiers, security logs and form-submission metadata.
Complaints and safeguarding information
If you report a complaint or safeguarding concern, we may receive information about alleged conduct, affected people, witnesses, risks, communications and actions taken. Such information may be highly sensitive and should receive restricted handling.
03
How we obtain personal information
We may obtain information:
- Directly from you when you submit a form or contact us.
- From someone acting with your authorization.
- From community representatives, partners or witnesses where there is an appropriate reason.
- Automatically through website, security and cookie technologies.
- From approved payment, email, event or technology providers.
- From public sources where collection and use are appropriate.
Where information is received from another source, TUSIC should consider whether and when it is appropriate to inform the person concerned.
04
How we use personal information
We may use personal information to:
- Receive, review and respond to enquiries.
- Manage membership, volunteering and partnership interests.
- Plan and administer approved programs and events.
- Receive and account for authorized donations.
- Maintain financial, governance and organizational records.
- Provide requested news or organizational communications.
- Receive and respond to complaints or safeguarding concerns.
- Protect people, systems, funds and organizational resources.
- Prevent, identify and respond to fraud or misuse.
- Meet applicable legal, regulatory and contractual obligations.
- Improve our website, accessibility and organizational practices.
- Establish, exercise or defend legal rights where appropriate.
We should not use personal information for a materially different purpose without appropriate authority, notice or consent where required.
05
Authority, consent and lawful processing
The legal basis or authority for handling personal information depends on TUSIC’s jurisdiction, the information, the relationship and the purpose.
Depending on applicable law, processing may be based on:
- Your express or implied consent.
- Steps requested before entering an agreement.
- Performance or administration of an agreement.
- Compliance with a legal or regulatory obligation.
- Protection of an individual’s vital or safety interests.
- A legitimate organizational or public-interest purpose that is not overridden by individual rights.
- Another authority permitted by applicable law.
Where processing depends on consent, you may withdraw that consent subject to legal, contractual, safety and operational limitations.
06
When we share personal information
We do not sell personal information. We may share limited information with:
- Authorized TUSIC personnel who need it for their responsibilities.
- Website-hosting, form, email, security, storage, communications or technology providers.
- Approved banks, accountants, auditors and payment providers.
- Professional advisers such as lawyers, insurers or safeguarding specialists.
- Responsible program or event partners where appropriate.
- Emergency, child-protection, law-enforcement, regulatory or other competent authorities where appropriate or required.
- Another organization involved in a lawful restructuring or transfer, subject to appropriate safeguards.
Service providers should receive only the information necessary to perform the authorized service and should be subject to appropriate privacy and security requirements.
Website host: [PROVIDER AND COUNTRY]
Bit Form/WordPress hosting location: [LOCATION]
Email provider: [PROVIDER AND COUNTRY]
Analytics provider: [PROVIDER OR “NONE”]
Donation provider: [PROVIDER OR “NOT YET IMPLEMENTED”]
07
International processing and transfers
TUSIC’s activities may involve people, representatives and service providers in more than one country. Personal information may therefore be processed or accessed outside the country where it was collected.
Privacy and government-access rules differ between jurisdictions. Where required, TUSIC should use appropriate contractual, organizational or other transfer safeguards.
Identify the countries in which TUSIC stores or regularly accesses website, contact, volunteer, membership, donor and safeguarding information.
08
How long we retain information
We should retain personal information only for as long as reasonably necessary for the identified purpose, legal obligations, financial records, safeguarding, dispute resolution and legitimate organizational needs.
Retention periods may differ according to the type and sensitivity of information. TUSIC should maintain an internal retention schedule covering:
- General enquiries and correspondence.
- Unsuccessful volunteer and membership enquiries.
- Active and former personnel records.
- Financial transactions and donation records.
- Consent records, photographs and community stories.
- Complaints, safeguarding concerns and investigation records.
- Website logs, backups and security records.
At the end of the applicable period, information should be securely deleted, destroyed or anonymized unless further retention is permitted or required.
09
How we protect personal information
TUSIC should use administrative, technical and physical safeguards proportionate to the sensitivity, amount, format and risks associated with the information.
Safeguards may include:
- Role-based access and least-privilege controls.
- Strong passwords and multi-factor authentication.
- Encryption in transit and where appropriate at rest.
- Secure backups, software updates and malware protection.
- Confidentiality requirements and personnel training.
- Provider assessment and contractual safeguards.
- Incident identification, response and documentation.
- Secure deletion and destruction methods.
No electronic system is completely secure. TUSIC cannot guarantee absolute security but should take reasonable steps to prevent unauthorized access, use, alteration, disclosure, loss or destruction.
10
Sensitive and safeguarding information
Information concerning health, disability, displacement, identity documents, finances, children, alleged misconduct, sexual exploitation, abuse or personal safety may require heightened protection.
Please do not use the general contact form to send passwords, complete payment-card details, banking credentials or unnecessary copies of identity documents.
Safeguarding information should be accessible only to appropriately authorized people and shared on a need-to-know basis.
For reporting guidance, visit our Safeguarding page.
11
Children’s personal information
TUSIC’s public website is not intended to invite children to submit personal information without appropriate adult awareness or authorization.
Where an approved activity involves children, TUSIC should use age-appropriate information, suitable consent or authorization procedures, data minimization and heightened safeguards.
If you believe a child has submitted personal information inappropriately, contact TUSIC using the details below.
13
Email and organizational communications
We may send administrative messages necessary to respond to your enquiry, manage a relationship, confirm an application or provide requested information.
Where required, promotional or newsletter communications should be sent only with appropriate consent or another valid authority. Each marketing message should provide an appropriate way to unsubscribe.
Unsubscribing from optional communications does not necessarily prevent essential administrative, financial, safety or legal communications.
14
Your privacy rights
Depending on applicable law and relevant exceptions, you may have the right to:
- Ask whether TUSIC holds personal information about you.
- Request access to that information.
- Request correction of inaccurate or incomplete information.
- Withdraw consent where processing depends on consent.
- Object to or request restriction of certain processing.
- Request deletion where the law provides that right.
- Request transfer or portability where applicable.
- Complain to TUSIC or an applicable privacy regulator.
These rights are not absolute. TUSIC may need to retain or withhold certain information to protect another person, preserve confidentiality, address safeguarding risks, comply with law or establish or defend legal rights.
15
Making a privacy request
To make a request, contact the privacy role listed below and describe the information or concern clearly.
TUSIC may need to verify your identity before disclosing, correcting or deleting information. Identity verification should be proportionate and should not involve collecting more information than reasonably necessary.
If TUSIC cannot fulfill all or part of a request, it should explain the reason where permitted.
16
Third-party websites and services
Our website may link to external websites, social platforms or services. TUSIC does not control every external party’s privacy, security or cookie practices.
Review the privacy notice of an external service before submitting personal information to it.
17
Changes to this policy
We may update this Privacy Policy to reflect changes in our activities, technologies, providers, legal obligations or organizational practices.
The current version should display its effective and last-updated dates. Material changes may also be communicated through the website or another appropriate channel.
18
Contact TUSIC about privacy
Questions, requests or complaints about personal information can be directed to:
[FULL LEGAL NAME OF TUSIC ENTITY] Attention: [PRIVACY OFFICER OR RESPONSIBLE ROLE] Email: [PRIVACY EMAIL ADDRESS] Postal address: [COMPLETE POSTAL ADDRESS] Country of establishment: [COUNTRY] Registration number, if applicable: [NUMBER]You may also use the contact form and select Privacy request.
Depending on where you live and which law applies, you may also have the right to contact the privacy or data protection authority responsible for your jurisdiction.