Search

Privacy Policy

INTRODUCTION

Actions Without Borders, Inc., and its affiliates (“Idealist” or “we” or “us”) respect your privacy and are committed to protecting it, as outlined in this policy (“Privacy Policy“). We provide tools for people and eligible organizations interested in bridging the gap between intention and action to do more good in the world.

This Privacy Policy is divided into three parts as follows:

(A) General Privacy Policy – The provisions falling under this part of this Privacy Policy are of general application to all Users of the Sites;

(B) The European Union General Data Protection Regulation Policy (“EU GDPR Policy“) – The provisions falling under this part of this Privacy Policy are of specific application to all Users of the Sites who are located in the European Economic Area (“EEA“) or the United Kingdom (together referred to as “Europe“); and

(C) The Applicant Tracking System Privacy Policy (“ATS Privacy Policy”) – The provisions falling under this part of the Privacy Policy apply to Organizations that use our ATS Services (as defined in our Terms of Service) for receiving and managing job applications from Individual Users of the Sites.

This Privacy Policy should be read in conjunction with our Terms of Service, and our Cookie Policy (all collectively, being our “Agreement“). Any defined terms used herein, but not defined herein, are as they are defined in the Terms of Service. By using or accessing any of our Offerings you agree to the terms of our Agreement, which includes this Privacy Policy.

While using Idealist’s Offerings can, in certain instances, involve sharing various pieces of information about yourself and communicating with us, or other Organizations, Individual Users, Groups, and the public at large, your privacy is of the utmost importance to us. This Privacy Policy explains what type of information we may collect from you when you use one of our Offerings, how we may use this information, who might have access to it, which choices you have about how it can be used and shared, and/or what measures Idealist takes to protect such information.

This Privacy Policy applies to information we collect:

  • on our Sites, through a Service or any of our other Offerings;
  • in email, text, and other electronic messages between Idealist and you;
  • through Idealist mobile and desktop pages you download or print from an Idealist Site or Mobile App, which provide dedicated, non-browser-based interaction between you and Idealist;
  • when you interact with our other Users and their websites, mobile applications, pages or via email or print;
  • when you interact with our advertising and pages on third-party websites and through third-party services; and
  • whether or not such Offerings, pages, advertising, anything else listed above, include links to this policy.

Please read this Privacy Policy, and the rest of our Agreement, carefully to understand our requirements, procedures and practices regarding your information and how we will treat it. If you do not agree with this Privacy Policy or any another part of our Agreement, or if you do not consent to having your Personal Information processed or collected, your choice is to opt out of part or all of our Offerings.  “Personal Information” means data relating to you from which you can be reasonably identified. Examples of Personal Information include your full name, postal address, email address and telephone number, IP address of your device, job title and the company you work for.

By using our Offerings you understand and acknowledge that our governing principles are outlined in our Agreement, and you should refrain from using our Offerings if you disagree with them. This Privacy Policy, as well as other parts of the Agreement, may change from time to time. Your continued use of an Idealist Offering after we make changes to our Agreement and its policies is deemed to be acceptance of those changes, so please check our Agreement periodically for updates.

A. GENERAL PRIVACY POLICY

1. INFORMATION WE COLLECT ABOUT YOU

As with any other services, sites or applications, we collect certain information that may be Personal Information, such as:

(a) Account Information: If you choose to use certain features and functions of our Offerings, we may ask you to provide certain personally identifiable information about yourself (“Account Information“) without which some of our Offerings’ features cannot work. By providing such Account Information, you are asked to consent to our collection and use of it, as further described in our EU GDPR Policy (for Users located in Europe), this General Privacy Policy and in accordance with this Agreement.

The Account Information that we collect may include, but shall not be limited to:

  • basic information that is provided during our member registration process, including your first and last name, location (city, state, and country), email address and password;
  • optional information about the kind of Listings and other information we may need to send you, or that you would like us to send to you, via email;
  • additional information for your or your Organization’s profile, such as your photos, logos, your mission, and a description of your services; and/or
  • information about your internet connection, your IP address, the equipment you use to access our Offerings and usage details.

We may collect this information:

  • directly from you when you provide it to us;
  • automatically as you navigate through one of our Offerings (information collected automatically may include usage details, IP addresses, and information collected through cookies, web beacons, and other tracking technologies); and/or
  • from third parties, for example, our business partners and suppliers. Information that we may collect from such third parties would typically be the kind that falls under the following categories:
  • General personal details e.g. name, title, address, telephone numbers, email address
  • Previous employment details e.g. names of former employers, duration worked, start and end dates of employment
  • Resume and any details that would ordinarily be contained in such a document

Any information we may collect about you when you visit our Sites or use our other Offerings, shall be subject to this General Policy, our EU GDPR Policy (for Users located in Europe) and any information derived from our use of cookies shall be subject to our Cookie Policy.

(b) Information You Provide to Us (Including Application Information): The information we collect on or through our Offerings may include, but shall not be limited to:

  • Information that you provide by filling in Idealist forms. This includes information provided at the time of registering to use our Site or Mobile App, subscribing to our Services, posting material, or requesting further Services on our Site or Mobile App. We may also ask you for information when you enter a contest or promotion sponsored by us, and when you report a problem with one of our Offerings.
  • Information that you provide by directly applying on our Site, Mobile App or other Offering for an Organization's Listing, including, but not limited to, your name, contact details, details that you provide in your resume, cover letter and other documents uploaded on our Site, Mobile App or other Offering, and information in your answers to questions on the Listing (“Application Information”).
  • Records and copies of your correspondence (including email addresses), if you contact us.
  • Your responses to surveys that we might ask you to complete for research purposes.
  • Payment information from you, such as credit card numbers and billing addresses. Because payment transactions on or through an Offering are currently outsourced to third party service providers, it is necessary for us to provide access to your payment information to such third parties. In those cases, we take commercially reasonable steps to ensure that these providers do not use or otherwise disclose any information we collect about you except for the purpose of fulfilling their service obligations to us.
  • Your search queries on a Site or in a Mobile App.
  • The pages you visit and links you click on during every browser or Mobile App session.

(c) Member-Created Content

One reason people and organizations use our Offerings is to share content with others. Examples include when you create an organization profile, post Listings, or upload a photo. You, being an Organization or Individual User, also may provide information to be published, transmitted or displayed (hereinafter, “posted“) on public areas of one of our Offerings or transmitted to other Users or third parties (collectively, “Contributions“). Your Contributions are posted on and transmitted to others at your own risk. You receive others Contributions at your own risk. Although we limit access to certain pages, please be aware that no security measures are perfect or impenetrable. Additionally, we cannot control the actions of other Users of the Site with whom you may choose to share your Contributions. Therefore, we cannot and do not guarantee that your Contributions will not be viewed by unauthorized persons. Your Contributions will be subject to our Terms of Service under which it should be noted that Idealist has reserved the right to immediately remove from any of the Sites, any Contribution for any reason, including violations of this Agreement or any applicable Laws. Please see Section II, B (4) of our Terms of Service for more information regarding Contributions and particularly content removal.

(d) Children’s Use of Idealist Offerings

We welcome members of all ages to use our Offerings. While we are not required to comply with the Children’s Online Privacy Protection Act because of our non-profit status, we require Individual Users under thirteen years old to access our Sites, Services, Mobile Apps or any of our other Offerings only with parental consent and supervision.

Any personally identifiable information submitted by an Individual User under thirteen years old only may be done so with parental consent and supervision. If we learn that we have collected or received personally identifiable information from an Individual User under age 13 without verification of parental consent, we will delete that information with no obligation to such underage Individual User or his/her parent/guardian. If you believe we might have any information from or about a child under 13, please contact us using this Web Form.

(e) Payment Information. Some of our Offerings are fee-based and we therefore will collect payment information from you, such as credit card numbers and billing addresses.

(f) Use and Access. In order to monitor the effectiveness of our Offerings, identify areas of interest, and consider potential improvements to them, we may also keep track of the actions you take while engaged with our Offerings, which may include but shall not be limited to:

  • signing up for email alerts;
  • becoming an administrator;
  • saving Listings;
  • connections made with other Users; and
  • publishing content through Contributions.

As you navigate through and interact with our Offerings, we may use automatic data collection technologies (such as cookies and tokens) to collect or track certain information about your hardware, browsing actions, and patterns, which may include but shall not be limited to:

  • “Cookies” (small piece of data we store for an extended period of time at the location from where you access our Sites or Mobile Apps) to make our Sites and Mobile Apps easier to use and to protect both you and Idealist. For more information on our cookie use, please visit our Cookie Policy;
  • Authorization tokens and related digital information files;
  • Your login ID (but never your password which remains an inaccessible, encrypted hash) to make it easier for you to log in whenever you come back to a Site or Mobile App;
  • Assess the technical function of a Site or Mobile App; and
  • Track information about which pages you visit within a Site or Mobile App to help us gauge the effectiveness of these and our other Offerings, and our content.

Like many other websites and applications, we may automatically collect information about your Internet connection that does NOT identify you personally, which may include but shall not be limited to:

  • The IP address of the computer or device you used to access the Internet;
  • The browser type and operating system you use to access our Offering;
  • The name of the website from which you linked directly to our Site;
  • The date and time you access our Offering; and
  • The pages you visit.

This Privacy Policy does not apply to information collected by any third party, including through any application or content (including advertising) that may link to or be accessible from or through one of our Offerings. Please see the privacy and other policies applicable to such third-parties for information about how such third-parties will handle your information.

2. HOW WE USE YOUR PERSONAL INFORMATION

We may use the Personal Information that you give us to:

  • provide Services or other Offerings that you request;
  • share it with an Organization at your request by applying for a Listing on our Site, Mobile App or other Offering;
  • respond to your questions or inquiries by email or otherwise;
  • identify areas of interest;
  • provide you with notices about your account, including expiration and renewal notices;
  • carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection or as otherwise requested by applicable Law;
  • notify you about changes to our Offerings or any other products or services we may offer or provide though it;
  • allow you to participate in interactive and offline features of our Offerings;
  • allow you to connect with other Users on our Sites, Mobile Apps or other Offerings;
  • allow you to apply for Listings through our Offerings;
  • allow you to request information from an Organization or grad school about their programs;
  • consider potential improvements to our Site, Services, Mobile Applications or other Offerings; and
  • provide a forum to connect people and organizations, such as yourself.

Subject to our EU GDPR Policy (applicable for Users located in Europe) and other terms of our Agreement, the following is a non-exhaustive list of some examples of the ways we may use information about you:

  • If you request it, we match your preferences with Organizations and Listings that meet your criteria. We use your Individual User Account Information to email you about these prospects.
  • If you request it by directly applying on our Site, Mobile App or other Offering for an Organization's Listing, we share your Application Information with the Organization that submitted the Listing.
  • If you request materials from us, we also ask that you provide us with certain Personal Information, such as your email address. We may also use that Personal Information to determine the level of interest in our offerings.
  • We may use your Individual User Account Information to get in touch with you regarding the status of your online requests for Services or any additional information you requested. We may also use your Individual User Account Information and Contributions to determine whether you qualify for any Services for which you request online.
  • We may use your Individual User Account Information and Contributions to contact you by email or otherwise, as (i) required by Law; (ii) regarding current Offerings, or their content, that you may be receiving or may have requested information about; (iii) regarding additional or new Offerings or features Idealist may be offering; or (iv) requesting your feedback about your experience with an Offering.
  • We may use your Individual User Account Information and Contributions to occasionally contact you, by email or otherwise, with Offering-related announcements. You may opt out of all communications (except those otherwise required by Law), though you acknowledge that opting out of essential Offering communications may impair or cancel certain functionality integral to your receipt and enjoyment of such Offerings.
  • You may contact us directly with questions or comments regarding the services or to request additional information by following the links on the “Contact Us” section of our Sites and Mobile Apps. These links require you to give certain Personal Information so that we may respond to your inquiry.

Subject to applicable Law, we may need to disclose your Personal Information to others, without first obtaining your consent, in the following circumstances:

  • Complying With Law Enforcement. Like any other service, site or application, we may be asked to provide Personal Information about our Individual Users and Organizations when subject to certain laws, rules, regulations, judicial or law enforcement proceedings, subpoenas, investigative demands, and other legal processes (collectively, “Law”) and may disclose such information if we have a good faith belief that doing so is required by Law. This may include respecting requests from jurisdictions outside of the United States.
  • Preventing Fraud and Other Illegal Activity. We may also share Personal Information about Organizations and Individual Users when we have a good faith belief it is necessary to prevent fraud or other illegal activity, to prevent imminent bodily harm, or to protect both ourselves and you from people violating our Agreement. This may include sharing information with other companies, lawyers, courts, or other government entities as required by Law.
  • Coordinating With Third Party Suppliers and Service Providers. We may use third party suppliers and service providers to facilitate our Offerings, and they may have access to your Personal Information. For example, we may outsource one or more aspects of our Offerings to a supplier or service provider who performs services according to our requirements, such as when you make a payment. We may also share Contributions made by Organizations or Individual Users with third-party, feed partners (such as other job listing websites), in order to further promote your organization or Listings. We endeavor to select only reputable companies who share our commitment to customer privacy, but cannot be held responsible when such third-parties breach any laws or governing agreements held with Idealist.
  • Enforcing our Agreement. In certain instances, we may have a good faith belief that it is necessary to disclose Personal Information in order to enforce our Agreement in order to protect our Offerings, Users, the public or reputation.

We do not sell or trade Individual User’s Personal Information to marketing companies or information brokers or any other organization or individual for commercial or marketing purposes.

3. YOUR CONTROL OVER YOUR INFORMATION

You can review and change your Personal Information by logging into the Site and visiting your account profile page.

If you are an Individual User, Idealist may share your information either with your consent, or as otherwise provided in this Agreement.

If you have an Organization account in the capacity of a non-profit for the purposes of hiring employees with Idealist, all information you share, including your organization profile, and all Listings you post, in addition to any of your Contributions, may be viewable through or shared within our Offerings.

Applying for Organization's Listings and ATS Services:

  • Where an Individual User requests that we share their Application Information with an Organization by the Individual User applying directly to the Organization on our Site, Mobile App or other Offering via that Organization's Listing, we make the Application Information available to view by the Organization on our Site, Mobile App or other Offering for the purpose of the Organization evaluating and processing the Individual User's job application.
  • We and the Organization with whom we share the Application Information with are jointly responsible for the Individual User's Application Information hosted on our Site, Mobile App or other Offering. Subject to our EU GDPR Policy (applicable for Users located in Europe) and other terms of our Agreement, Individual Users who wish to enquire about our or the Organization's processing of the Application Information on the Site, Mobile App or other Offering should, in the first instance, contact us for additional assistance using this Web Form. 
  • The Organization can export the Individual User's Application Information from our Site, Mobile App or other Offering onto the Organization's own system. Such export and any onward processing of the Application Information by the Organization is subject to that Organization's own privacy policy. The Organization is solely liable and responsible for any onward processing of the Application Information outside of our Site, Mobile App or other Offering.
  • We accept no responsibility and exclude all liability for the Organization's onward processing of the Application Information outside of our Site, Mobile App or other Offering. We only work with Organizations that meet our eligibility criteria but we cannot guarantee to you that the level of protection afforded by the Organizations to your Application Information held on their systems is compliant with applicable data protection law. Therefore, by submitting your application for the Organization's Listing, you agree to indemnify and hold us harmless against any losses that arise as a result of any Organization's processing of your Application Information on their systems.

Here are some additional things to remember:

  • Information you make available to others might be re-shared or copied by those individuals and organizations.
  • We may provide you with real-time chat features and enable your ability to connect with other Users in our Mobile App and other Offerings.
  • We may provide you with discussion or comment features for your use. In the event you voluntarily disclose Personal Information using an Offering, that information, along with any content in your Contribution, communication or post, can be collected, correlated, and used by others. This may result in unsolicited messages from or improper and unauthorized use of your Personal Information by third parties. Such activities are beyond our control, and by using our Offering you acknowledge that such publicly posted Contributions may be copied or stored by other Users or third-parties.
  • There are no privacy settings for certain types of information that you post on a Site or a Mobile App, such as Listings and organization pages. This information is public for all members of the Internet, regardless of Idealist membership status. Please do not post a Listing or onto an organization page if you desire private treatment for such posted information.

4. THIRD PARTY LINKS

We may provide links within an Offering to other sites of interest. We do not endorse the content of these sites or guarantee that they will abide by this Privacy Policy or the other standards outlined in our Agreement. Your use of such linked sites is subject to the terms of use and privacy policies of the providers of those sites. We encourage our Users to be aware when they leave an Offering of ours to read the terms of use and privacy policies of each site that collects your Personal Information.

5. DATA SECURITY & HOW WE PROTECT INFORMATION

We have implemented measures designed to secure your Personal Information from accidental loss and from unauthorized access, use, alteration, and disclosure. All information you provide to us is stored on secure servers behind firewalls. Any payment transactions will be encrypted. In the case that it is stored by any third parties that we use, your account information may be stored on a secured server behind a firewall. When you enter sensitive information (like your password), the information is encrypted using secure socket layer technology (SSL). Please note however that despite the implementation of the above security policies, Idealist cannot guarantee that these security measures will prevent other third parties from unauthorized and unlawful access, use, alteration and disclosure of your Personal Information. As such, any transmission of your Personal Information to us is at your own risk.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Sites or Mobile Apps, you are responsible for keeping such password(s) confidential. We ask you not to share your password(s) with anyone, and refresh such password(s) as is deemed prudent. You can reduce the inherent risks associated with using the Internet by exercising common sense and discretion: for example, you should choose a strong password, use different passwords for different websites and services, and use updated antivirus software.

We do our best to keep your information secure, but you must actively participate in the process of keeping your information safe. We reserve the right to analyze accounts for fraudulent or irregular behavior and we may limit use of site features in response to possible signs of abuse. We urge you to be careful about giving out information in public areas of our Offerings, like message boards. The information you share in public areas may be viewed by any user of our Site(s) and Mobile Apps. Please timely report any security violations to us as outlined in the section below.

Subject to the ATS Privacy Policy, each Organization is responsible for implementing and maintaining appropriate safeguards to ensure security and confidentiality of the Organization's Account Information (including its password and other login credentials). Where we share the Application Information with an Organization on the request from an Individual User, we accept no responsibility in relation to loss or misuse of the Application Information as a result of the Organization's failure to implement and maintain appropriate safeguards to protect from the misuse of the Organization's account. 

6. CHANGES TO THIS POLICY

We may change this Privacy Policy or other parts of our Agreement from time to time. If we do make a change to this Agreement, we will announce and post such revisions on our Sites and Mobile Apps. We encourage you to review our Agreement periodically. If you continue to use our Offerings after the announcement of any policy revisions, you will be deemed to have agreed to the changed terms and practices. Questions, comments, or complaints about our Privacy Policy or the rest of our Agreement should be submitted to us by one of the methods listed above.

B. EU GDPR POLICY

1. Introduction

This policy (the “Policy”) applies if you are utilizing our Site, Mobile App or other offerings. 

Idealist.org and/or Idealistas.org will be the data controller of your personal information and will be referred to in this Policy as “Idealist”, “we”, “our” or “us.” “Personal Information” means data relating to you from which you can be reasonably identified. Examples of Personal Information include your full name, postal address, email address and telephone number, IP address of your device, job title and the company you work for. We recognize that your Personal Information is valuable and we endeavor to process your Personal Information in accordance with European Data Protection Legislation and other applicable law.

Idealist is responsible for ensuring that it uses your personal data in compliance with data protection law. The purpose of this Policy is to explain what personal data we collect and how we use it. This Policy also sets out the rights you have in relation to your Personal Information and explains how we will process your Personal Information under the applicable European Data Protection Legislation. Please take the time to read and understand this Policy.

For the purposes of this Policy, “European Data Protection Legislation” means all applicable legislation relating to data protection in the European Economic Area (“EEA”) and the United Kingdom (“UK”), including the European Union (“EU”) General Data Protection Regulation (“EU GDPR”) and the UK General Data Protection Regulation (“UK GDPR”) and all legislation implementing or made under or pursuant to or replacing or superseding the EU GDPR, including the Data Protection Act 2018 in the UK. Where this EU GDPR Policy uses terms, which are defined in the GDPR, the definitions in the GDPR will apply.

This Policy should be read in conjunction with our Terms of ServiceCookie Policy and General Privacy Policy (see section (A) above) (all collectively, being our “Agreement“). By using or accessing any of our offerings you agree to the terms of our Agreement, including this Policy. Please read this Policy, and the rest of our Agreement, carefully to understand our requirements, procedures and practices regarding your Personal Information and how we will treat it. If you do not agree with this Policy or any another part of our Agreement, your choice is to opt out of part or all of our offerings, as outlined below.

This Policy is not a contract and does not create any contractual rights or obligations except as otherwise required by applicable law.

2. What Personal Information Do We Collect?

We will collect and process (e.g. obtain, record, use, share or hold etc.) the following Personal Information about you, in each case in so far as permitted by local law:

Information that you provide to Idealist

The information that you provide to Idealist will depend upon, among other things, whether you are a guest, registered user or Candidate. Certain content and features of the offerings are available to registered users [and Candidates] that are not available to guests – we require this information in order to enable all of our offerings features to work. This information can include:

  • personal details such as, but not limited to, your full name, date and place of birth, email address, home address, other contact details including mobile telephone number, employment history and qualifications (both academic and professional), gender, nationality and right to work in the location where you are applying for a role, civil/marital status; and
  • any other details you provide in support of your application, including (but not limited to) information contained in your resume and/or covering email and your reasons for applying for a position.

Information we otherwise collect about you.

This includes information that is collected in connection with our offerings to registered users and candidates and is likely to include:

  • personal data that we collect through your communication and correspondence with us, by telephone, email or otherwise (including but not limited to the content, date and time of your email correspondence);
  • your responses to surveys that we might ask you to complete for research purposes;
  • payment information from you, such as credit card numbers and billing addresses; and
  • information obtained through any interviews and assessments with you.

Information we obtain from other sources

This may include: 

  • Personal Information that we collect from screening, background and/or reference checks we may perform on you as part of the application or recruitment process, which may include your address history, your credit history, your qualifications (both academic and professional), your previously held directorships (if any); and 
  • a criminal records check (where necessary for the role for which you are applying and as permitted by local law); 
  • information relating to your health, any ongoing conditions and any reasonable adjustments which may be necessary for the performance of the role for which you are applying. 

3. How may we use your Personal Information?

Idealist may store and process your Personal Information in the following ways and for the following purposes:

  • to fulfill our obligations to you. In order to properly supply our offerings to you, we may be required to take additional steps to perfect your requests of us, such as introducing you to other Users on our Site or Mobile App. We may send you updates or notifications about the offerings you have requested or purchased. We may process your information to protect our offerings and you from fraud or other criminal activity. 
  • with your consent, we may process your Personal Information, such as for marketing new services to you or sharing the information that you provide to us when using our Site, Mobile App, or other offering (“Application Information”) with Organizations whose Listing you are directly applying for on our Site, Mobile App or other offering. We use a number of mechanisms to obtain your consent. 
  • to maintain contact with you in the future and notify you of relevant job vacancies that you might be interested in. Please note that if you do not want us to retain your information, or want us to update it at any stage, please contact us in accordance with the “Contacting us” section of this Policy.

We are entitled to use your personal data in these ways because:

  • we are obligated to supply services that are compliant with various laws, rules, regulations and contracts
  • we need to, in order to supply you the offerings you request, ranging from sending you updates or notifications about the offerings you have requested or purchased to the protection of our offerings and you from fraud or other criminal activity;
  • we have legal and regulatory obligations that require us to adhere to certain recordkeeping and document retention standards, which shall include keeping your Personal Information to remain legally compliant;
  • we may need to keep any information in our archives that we deem necessary to comply with our legal obligations, including, but not limited to, resolving disputes and enforcing our agreements or establishing, exercising or defending our legal rights; and/or
  • the use of your Personal Information is necessary for our legitimate business interests (or the legitimate interests of an Organization), such as:
  • allowing us to effectively assess your skills, qualifications and/or the strength and merits of your application and your suitability for the role applied for;
  • allowing us to effectively verify your information;
  • allowing us to effectively and efficiently administer and manage the operation of our business; or
  • being able to contact you in relation to your application and the recruitment process.

Please note, if you successfully apply for a position at Idealist and you are subsequently offered and accept employment at Idealist, the information we collect during the application and recruitment process will become part of your employment record.

Sensitive personal data

Certain forms of “sensitive personal data” are subject to specific protection or restriction by law in certain territories, including the EU. For these purposes, “sensitive personal data” may include data relating to: racial or ethnic origin; criminal activity or proceedings; political opinions; religious philosophical beliefs; trade union membership; genetic data; biometric data; data concerning health or sex life or sexual orientation. To the extent that we collect sensitive personal data, we will not process your sensitive personal data unless any legal conditions in connection with the lawful processing of such data are met and/or in accordance with any relevant local laws. This may include the following:

  • the processing is necessary for carrying out obligations and specific rights of Idealist or an Organization in the field of employment law, social security or social protection law (including obligations in relation to public health, health and safety and disability discrimination, the legality of personnel working in a particular jurisdiction, which will involve processing data in relation to nationality, work permits and visas, monitoring equality of racial or ethnic opportunity or treatment, and vetting (where necessary);
  • the processing is necessary to protect the vital interests of you or another person where you are physically or legally incapable of giving consent;
  • you have made public the sensitive personal data in question;
  • the processing is necessary for the purpose of, or in connection with, any actual or prospective legal proceedings, for the purpose of obtaining legal advice or otherwise for the purposes of establishing, exercising or defending legal rights subject to applicable local legislation or where courts are acting in their judicial capacity;
  • the processing is necessary for reasons of substantial public interest on the basis of local law which is proportionate to the aim pursued and which contains appropriate safeguarding measures;
  • the processing is necessary for archiving purposes in the public interest or scientific and historical research purposes or statistical purposes;
  • you have given explicit consent in writing to the processing of the sensitive personal data; or
  • as otherwise permitted by law; and

In each case we will meet any additional local legal requirements and enforce any applicable duties of confidentiality effectively, for example in relation to access to health records.

4. To which Third Parties May We Disclose Your Personal Information?

  • When you request us to share your Application Information with an Organization, we make the Application Information available to view by the Organization on our Site, Mobile App or other offering. We and the Organization with whom we share the Application Information are joint controllers of the Application Information on our Site, Mobile App or other offering for purposes of the European Data Protection Legislation.
  • The Organization can export your Application Information from our Site, Mobile App or other offering onto its own system. The Organization is an independent controller in respect of any onward processing of the Application Information outside of our Site, Mobile App or other offering for purposes of the European Data Protection Legislation. As a result, the export and any onward processing of the Application Information by the Organization is not subject to this Policy. Instead it is subject to that Organization's own privacy policy, which is available to the Individual User on the Listing.
  • We may disclose your Personal Information to third party agents or contractors, bound by obligations of confidentiality, in connection with the processing of your Personal Information for the purposes described in this notice. This may include outsourced HR service providers and consultants, pre-employment vetting agencies, IT and communications service providers, law firms, accountants and auditors;
  • to the extent required by law, regulation or court order, for example if we are under a duty to disclose your Personal Information in order to comply with any legal obligation; and
  • if we sell any of our business or assets or if we are acquired by a third party, we may disclose your Personal Information to the prospective buyer for due diligence purposes.

5. When may we transfer your Personal Information Internationally?

Your Personal Information may be transferred to and stored in databases hosted and maintained outside the location where you live or register with Idealist. It may be stored and processed by third parties in other countries, which (in relevant cases) may include destinations outside of the EEA and the UK. Where you are already outside of the EEA and United Kingdom, your Personal Information may be transferred to other jurisdictions, including locations which have lower levels of protection for Personal Information.

Where your Personal Information is transferred to other locations, including (where relevant) outside the EEA, we will ensure that it is protected in a manner that is consistent with how your Personal Information will be protected by us in accordance with the protection given in the jurisdiction where the Personal Information is collected. This can be done in a number of different ways, for instance:

  • the country that we send the data to might be approved by the European Commission or relevant local data protection authority;
  • the recipient signed up to a contract based on “model contractual clauses” approved by the European Commission, obliging it to protect your Personal Information and we assessed that the legislation of the third country of destination enables the recipient to comply with those clauses.
  • In other circumstances the law may permit us to otherwise transfer your Personal Information to other jurisdictions, including outside the EEA where relevant. In all cases, however, we will ensure that any transfer of your Personal Information is compliant with applicable data protection law.

If you provide your Personal Information to us in circumstances where our processing of it is subject to European Data Protection Legislation, please note that you are doing so on the basis that you explicitly consent to the transfer of your Personal Information outside the EEA and the UK.

If you request us to share your Application Information with an Organization outside the EEA or UK, you explicitly consent to the transfer of your Application Information outside the EEA or UK.

The potential consequence of you explicitly consenting to the transfer of your Personal Information outside the EEA or UK are that there is a risk that your Personal Information will not be protected in a manner that complies with European Data Protection Legislation. 

You can withdraw your consent for this reason at any time by contacting us using this Web Form. Withdrawing your consent will not affect our use of the Personal Information prior to your withdrawing that consent but it will mean that we will not be able to contact you about the services we may be able to offer you in the future.

If you require further information about these protective measures, you can request it from Idealist’s data privacy office, the details of which are set out under Section 7 (How Can You Contact Us) below.

6. How Long Will We Retain Your Personal Information?

How long we hold your Personal Information for will vary. The retention period will be determined by various criteria including:

  • the purpose for which we are using it – we will need to keep your Personal Information for as long as is necessary for that purpose, including for the purposes of satisfying any obligations to you;
  • whether we can achieve the purpose
  • legal obligations – laws or regulation may set a minimum period for which we have to keep your Personal Information;
  • the amount, nature and sensitivity of the Personal Information;
  • the potential risk of harm from unauthorized use or disclosure of the Personal Information, and
  • our legitimate interest – we need to retain the data in order to establish, exercise or defend our legal rights and to verify compliance with our internal processes.

An Organization will retain any Personal Information contained in an Individual User's Application Information which is downloaded by the Organization from our Site, Mobile App or other offering for the period of time identified in their own privacy policy available to the Individual User on the Listing.

7. What are Your Rights?

You have a number of legal rights in relation to the Personal Information that we hold about you and you can exercise your rights by contacting privacy@idealist.org.

Within the EU and UK, these rights include:

  • the right to obtain information regarding the processing of your Personal Information and access to the Personal Information which we hold about you;
  • where processing is based on your consent, the right to withdraw your consent to our processing of your Personal Information at any time. Please note, however, that we may still be entitled to process your Personal Information if we have another legitimate reason (other than consent) for doing so;
  • in some circumstances, the right to receive some Personal Information in a structured, commonly used and machine-readable format and/or request that we transmit those data to a third party where this is technically feasible. Please note that this right only applies to Personal Information which you have provided to us (and not, for the avoidance of doubt, information we otherwise collect about you or information we obtain about you from other sources);
  • the right to request that we rectify your Personal Information if it is inaccurate or incomplete;
  • the right to request that we erase your Personal Information in certain circumstances. Please note that there may be circumstances where you ask us to erase your Personal Information but we are legally entitled to retain it;
  • the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you (note that we do not anticipate that any decisions having a legal or significant impact on you will be taken about you using solely automated means, we will update this Policy if our position or policy changes);
  • the right to request that we restrict our processing of your Personal Information in certain circumstances (for example, if you contest the accuracy of your Personal Information). Again, there may be circumstances where you ask us to restrict our processing of your Personal Information but we are legally entitled to refuse that request;
  • the right to object to our processing of your Personal Information in certain circumstances. Please note that there may be circumstances where you object to our processing of your Personal Information but we are legally entitled to continue to process it; and
  • the right to lodge a complaint with the relevant data protection supervisory authority, details of which can be found by following the link below, if you think that any of your rights have been infringed by us.

EU data protection supervisory authorities: https://edpb.europa.eu/about-edpb/about-edpb/members_en

UK data protection supervisory authority: https://ico.org.uk/

7. How Can You Contact Us?

If you would like further information on the collection, use, disclosure, transfer or processing of your Personal Information or the exercise of any of the rights listed in this notice, please contact us using the following contact information:

Address:

Idealist

389 5th Avenue, 9th Floor

New York, NY 10016

USA

Attention: Data Privacy Office

If you would like to exercise your rights in relation to your Personal Information, you may also contact us by using this Web Form.

8. What if You Do Not Provide Your Personal Information to Us?

If you fail to provide information when requested, which is necessary for us to perform functions such as to properly supply our offerings to you, then we may not be able to take actions such as register you as a User, or share your Application Information with an Organization. 

C. ATS Privacy Policy

1. INTRODUCTION

This section of the Privacy Policy applies if you are an Organization that uses the ATS Services for receiving and managing job applications for your Listings from Individual Users and processes the Application Information on our Sites, Mobile Apps or other Offerings.

This ATS Privacy Policy should be read in conjunction with our Terms of ServiceCookie Policy and other parts of the Privacy Policy (all collectively, being our “Agreement“).

2. Sharing the Application Information with Organizations

An Organization that uses the ATS Services can submit Listings on our Sites, Mobile Apps or other Offerings in accordance with the Agreement for which Individual Users can directly apply on our Sites, Mobile Apps or other Offerings. 

When an Individual User applies directly for an Organization's Listing, the Individual User gives us their consent to share the Application Information with the Organization. After receiving the Individual User's consent for sharing the Application Information with the Organization, we will make the Application Information available to the Organization in accordance with the Agreement on the Sites, Mobile Apps or other Offerings for the purpose of the Organization evaluating and processing the Individual User's job application.

We and the Organization that processes the Application Information acknowledge that we and the Organization each act as a joint controller of the Application Information shared with the Organization on the Sites, Mobile Apps and other Offerings. 

Notwithstanding anything to the contrary in this ATS Privacy Policy, we remain an independent controller of all other Personal Information that we process under this Privacy Policy.

Where we share the Application Information with an Organization in response to the request of the Individual User, we will, in respect of the Application Information:

  • comply with this Privacy Policy and all applicable data protection and privacy legislation (including, but not limited to, the European Data Protection Legislation for Users located in Europe); 
  • provide the Individual User with the Organization's privacy policy explaining how the Organization will process the Individual User's Application Information outside the Sites, Mobiles Apps or other Offerings, and what rights the Individual User has in relation to such Application Information; 
  • take sole responsibility for notifying competent data protection authorities of any personal data breach of the Application Information processed on our Site, Mobile App or other Offering by us or the Organization; and
  • take sole responsibility under the European Data Protection Legislation for responding to Individual Users located in Europe with regards to exercise of their rights in relation to the Application Information processed on our Site, Mobile App or other Offering by us or the Organization. If an Individual User located in Europe wants to exercise their rights in relation to the Application Information, they can contact us using this Web Form. Please see Section 4 (Your Rights under the EU GDPR) of the EU GDPR Policy for more information how Individual Users located in Europe can exercise their rights.

An Organization that processes the Application Information on the Sites, Mobile Apps or other Offerings will, in respect of such Application Information:

  • comply with all applicable data protection and privacy legislation (including, but not limited to, the European Data Protection Legislation for Users located in Europe);
  • implement appropriate technical and organizational measures to ensure the security of the Application Information in its possession or control in accordance with all applicable data protection and privacy legislation (including, but not limited to, maintaining appropriate safeguards to ensure security and confidentiality of the Organization's account, password and other login credentials used to access the Application Information on the Site, Mobile App or other Offering);
  • be responsible for responding to communications from competent data protection authorities where such requests relate to the Organization's own processing activities and will without undue delay, and in any event within three (3) days, pass on requests to us where such communications concern our processing activities in respect of the Application Information; 
  • be responsible for responding to communications from Individual Users where such requests relate to the Organization's own processing activities and will without undue delay, and in any event within three (3) days, pass on requests to us where such requests concern our processing activities in respect of the Application Information; 
  • cooperate with us in good faith and promptly provide us with reasonable assistance and information when we respond to Individual User's exercise of their rights in relation to the Application Information or communications from data protection supervisory authorities in relation to the Application Information; and
  • inform us without undue delay and, in any event, within 24 hours after becoming aware of any personal data breach in relation to the Application Information that was in the Organization's possession or control, provide us with a clear description of the personal data breach affecting the Application Information as soon as it becomes available, and cooperate with us in good faith during investigation, litigation, notification, mitigation and remediation of any personal data breach affecting the Application Information.

3. Onward processing of the Application Information by Organizations

An Organization that receives the Application Information from us on Individual User's request might export and process the Application Information outside of our Sites, Mobile Apps or other Offerings.

Where the Organization processes the Application Information for purposes other than those described by Section 2 (Sharing the Application Information with Organizations) of the ATS Privacy Policy or in any circumstances outside of our Sites, Mobiles Apps or other Offerings, the Organization acts as an independent controller of the Application Information and we accept no liability or responsibility for such processing of the Application Information. The Organization warrants, represents and undertakes that any such processing of the Application Information will be strictly in accordance with the privacy policy and that such processing will comply with all applicable data protection and privacy legislation.

The Organization agrees to indemnify, keep indemnified and defend at its own expense Idealist against all costs, claims, damages or expenses incurred by Idealist or for which Idealist may become liable due to any failure by the Organization or its employees, subcontractors or agents to comply with any of its obligations under this ATS Privacy Policy or applicable data protection and privacy legislation.