This policy has been updated on, and is valid as of, September 5, 2022.
It is The PUSO Foundation’s policy not to solicit knowingly any personally identifiable information from children under the age of 13. Children under 13 are not authorized to make a donation or purchase, sign up for an event or program, or otherwise provide any personally identifiable information without consent from a parent or legal guardian.
What about data you provide to local PUSO Foundation organization?
Why do we hold and process personal data?
The PUSO Foundation may request from you, or you may volunteer to provide, your contact information, including your name, mailing address, phone number(s), social media handles and email address(es). We hold and process supporters’ personal data for a number of reasons:
To keep a record of donations made and actions taken by our supporters and our communications with them
To send our supporters marketing information about our projects, fundraising activities and appeals where we have their consent or are otherwise permitted to do so
To fulfill contractual obligations entered into with supporters
To support volunteers, such as during build or fundraising events
To support community based fundraising and campaigning
To ensure we do not send unwanted information to supporters or members of the public who have informed us they do not wish to be contacted
To manage supporters’ accounts and provide customer service
To offer sweepstakes, contests, giveaways or other promotions
To enforce the Website Terms & Conditions
To perform other functions as described at the time The PUSO Foundation collects information.
If you make a donation or a purchase with The PUSO Foundation, or otherwise provide us your information, The PUSO Foundation may contact you from time to time about opportunities to make additional donations or purchases or to provide you information about upcoming programs.
We may also analyze your personal information to create a record of your interests and preferences. This allows us to ensure communications are relevant and timely, to contact you in the most appropriate and relevant way and in general to provide you with an improved user experience. It also helps us to understand the background of our supporters so that we can make appropriate requests for support, enabling us to raise funds and help beneficiaries sooner and more cost-effectively.
The PUSO Foundation may also share data from its U.S. and Philippines resident supporters with select third-party sponsors and service providers based on our assessment that the products or services may be of interest to these supporters or that the sponsor or provider can help The PUSO Foundation identify what services or appeals may be of interest to our supporters. We may also provide our U.S. and Philippines resident supporters with information about services from third parties. If you do not wish your data to be used in this way, you may follow the instructions for modifying your consent (see below, “How to control what we send you or update your personal information”).
How and when do we obtain information about you?
The PUSO Foundation may obtain your personal data in the following circumstances:
When you give it to The PUSO Foundation
We will obtain your personal data directly when you make a donation, sign up for one of our events, purchase products from the The PUSO Foundation on-line retail store (wearepuso.co), or when you communicate with us directly in some other way.
When you give it to The PUSO Foundation indirectly
We will obtain your personal data when you communicate to your employer or to a retail partner of The PUSO Foundation during your point of purchase that you affirmatively designate The PUSO Foundation to receive a personal contribution from you.
Sometimes your personal data is collected by an organization working on or with The PUSO Foundation’s behalf. In such cases, the agency is acting on our behalf, and we are the “data controller” responsible for the security and proper processing of your data, just as if you had given it to The PUSO Foundation directly.
When you access The PUSO Foundation’s sponsored social media
We might also obtain your personal data through your use of social media such as Facebook, Twitter or LinkedIn, depending on your settings or the privacy policies of these social media and messaging services. To change your settings on these services, please refer to their privacy notices, which will tell you how to do this.
When the information is publicly available
We might also obtain personal data about individuals who may be interested in giving major gifts to charities or organizations like The PUSO Foundation. In these cases, we may seek to find out more about these individuals’ interests and motivations for giving through publicly available information. The information sources may include newspaper or other media coverage, open postings on social media sites such as LinkedIn, and services that aggregate data on charitable giving. If you are a resident of the European Economic Area and your country has adopted the provisions of the GDPR, The PUSO Foundation will not retain publicly available data relating to you without your consent, which we will seek at the earliest practical opportunity.
What personal information might The PUSO Foundation collect?
The PUSO Foundation will only collect personal data about you that is relevant to the type of transaction or project you have engaged in with us.
For example, we may receive and retain personal information about you when you contact The PUSO Foundation to make a donation, purchase an item at The PUSO Foundation Store online (wearepuso.co), or sign up to any of The PUSO Foundation’s activities or online content; or when you telephone, email, or write to us, or engage with us via social media channels. In each of these cases, the information we collect is relevant to the type of transaction you are entering into. Data such as your name email or postal address, telephone or mobile number will be necessary both to execute these transactions as well as to enable us contact you for further engagement. Bank account or credit card details will be necessary to process any donations. Age and travel restrictions will be relevant if you are signing up for an international build.
Credit card and billing information: In addition to your contact information, when you make a donation or purchase, The PUSO Foundation asks for your billing address and credit card or other financial services information. The PUSO Foundation uses a third-party banking agent to process your payments via a secured socket layer connection (TLS 1.2 using SHA 256 encryption) to a secured server that verifies your credit card/bank information. They return a unique tracking number only, which cannot be decrypted to obtain the payment card information, and The PUSO Foundation never retains your complete credit card number. Only employees who need access to your personal information to perform a specific job are granted access to that information, and The PUSO Foundation and our banking agent will not share your credit card/bank information with any other third party.
Sensitive Personal Data: We do not collect your “sensitive personal data” (e.g., health or dietary information) unless there is a clear reason for doing so—such as your participation in a sponsored physical event—and then only to the extent such data is required to ensure that we provide appropriate facilities or support to enable you to participate in the event.
Should you support The PUSO Foundation in a substantial way, we may provide an account manager to help tailor your relationship to us and the information you receive from us to suit your interests. If this is the case, we may collect demographic data where relevant to your relationship with Habitat for Humanity. If you provide us with information about your health or your family, this may also be recorded so we can communicate with you in a considerate and appropriate manner.
All sensitive personal data is stored on a password-protected system to which only a limited number of relevant staff have access. It is deleted when no longer needed by us, is never shared with third parties, and is available to you at any point should you wish to see it.
How will The PUSO Foundation use your personal data?
The PUSO Foundation will use your personal information for the following purposes:
For administrative reasons, including:
“service administration”, which means that The PUSO Foundation may contact you for reasons related to administering any donations you have made, the completion of commercial or other transactions you have entered into with us, or the activity or online content you have signed up for;
to confirm receipt of donations (unless you have asked us not to do this), and to say thank you and provide details of how your donation might be used;
in relation to correspondence you have entered into with us whether by letter, email, text, social media, message board or any other means, and to contact you about any content you provide;
for internal record keeping so as to keep a record of your relationship with us;
to complete sales transactions you have entered into with us, for example at The PUSO Foundation Store (wearepuso.co);
to implement any instructions you give us with regard to withdrawing consent to send marketing information;
to use IP addresses to identify the location of users, to block disruptive use and to establish the number of visits from different countries.
To analyze and improve the activities and content offered by The PUSO Foundation website to provide you with the most user-friendly navigation experience. We may also use and disclose personal information in aggregate (so that no individuals are identified) for marketing and strategic development purposes.
Will we share your information outside The PUSO Foundation network?
If you reside in the U.S. or Philippines, and unless you instruct us otherwise, The PUSO Foundation may share your personal data with organizations with which The PUSO Foundation partners, as well as other companies whose products and services may be of interest to you. In these cases, we may also provide you with information about services from third parties, unless you inform us that you do not want to receive this information.
The PUSO Foundation’s suppliers: We may need to share your information with service providers who help deliver our projects and fundraising activities. These “data processors” will only act under our instruction and are subject to contractual obligations containing strict data protection clauses. We do not allow these organizations to use your data for their own purposes or disclose it to other third parties without our consent, and we will take all reasonable care to ensure that they keep your data secure.
Facebook and other Social Media Sites: We may also use your email address and phone number to match to your Facebook or other social media account in order to show you The PUSO Foundation content while you use those services. We only do this where you have consented to receiving marketing emails, either by opting in (where you reside in the European Economic Area) or by not opting out (where you reside in the United States and Philippines). In addition, we may also use your email address and phone number to link to Facebook or other social media sites in order to identify other users of these sites whom we believe would be interested in The PUSO Foundation.
There are two ways to prevent this use of your data. You can either update your consent preferences directly with us at The PUSO Foundation (see below, “How to control what we send you or update your personal information”) or via the social media sites:
Updating your preferences with The PUSO Foundation will not guarantee that you never see The PUSO Foundation content on social media, since the social media site may select you based on other criteria.
Where legally required: We will also comply with legal requests where disclosure is required or permitted by law (for example to government bodies for tax purposes or law enforcement agencies for the prevention and detection of crime, subject to such bodies providing us with a relevant request in writing).
How long will The PUSO Foundation keep your personal information?
We will hold your personal information on our contact lists only for as long as you continue to provide your consent. If you are a U.S. or Philippines resident, your ongoing consent is presumed unless you inform us that you wish to be removed from our contact list. If you are not a U.S. or Philippines resident, your consent will be presumed to expire after 24 months, unless renewed consent is provided by you. Beyond that, we will hold your information only for as long as necessary to comply with our legal and regulatory obligations—such as, for example, to provide documentation on funding sources in connection with a review or audit of our compliance with U.S.C. Sec. 501(c)(3).
If you request that we stop sending you marketing materials, we will keep a record of your contact details and appropriate information to enable us to comply with your request not to be contacted by us.
Legacy income is vital to the running of the charity. We may keep data you provide to us indefinitely, to carry out legacy administration and communicate effectively with the families of people leaving us legacies. This also enables us to identify and analyze the source of legacy income we receive.
How The PUSO Foundation keeps your data safe
We ensure that there are appropriate technical controls in place to protect your personal details. For example, our online forms that ask for personal information are stored on networks that are password-protected and routinely monitored. Laptops are not used to store sensitive personal information unless they are both password protected or encrypted. All sensitive personal data is stored on a secure database, to which only a limited number of relevant personnel have access. It is deleted when no longer needed by us and is never shared with third parties, except as expressly set forth in section Why do we hold and process personal data?
Within The PUSO Foundation, we undertake regular reviews of who has access to information that we hold to ensure that your information is only accessible by appropriately trained staff, volunteers and contractors.
We use external companies to collect or process personal data on our behalf. We do comprehensive checks on these companies before we work with them, and in our legal agreements, we clearly set out our requirements regarding how they manage the personal data to which they have access. We have a robust partner-monitoring framework to ensure these contractual obligations are met.