Last updated : September 18, 2023
Welcome!
- “Contributor”: You are making a payment to the benefit of an Organization via the Platform, registering for tickets to an Organization’s event and/or filling out an Organization’s form in some capacity.
- “End User”: You are a user authorized by an Organization to use the Services through that Organization’s Account.
- “Member”: You are a Contributor who has created an Account on the Platform. Please note that as a Contributor, you are not obligated to create an Account.
- “Visitor”: You are visiting an Organization’s website and you fill in your name and email address on the form that is powered by Zeffy, but you ultimately decide not to complete the form.
- “Website Visitor”: You are browsing our Website.
In this Policy, each of a Contributor, End User, Member, Visitor or Website Visitor may be referred to as “you” or “your”. For greater certainty, in this Policy, “you” or “your” refers to anyone for whom we have collected and are storing personal data. Please also note that these definitions are not exclusive – for example, it is possible to be both a Contributor and a Website Visitor.
Zeffy takes your privacy and the security of personal data very seriously. We have provided and will continue to provide a secure environment and this Privacy Policy (the “Policy”) describes the limited ways your information is used and the limited access to such information. We ask that you read it carefully.
Key elements / Summary of this policy
Personal data we collect from you but only with your consent | What we do with it | Third parties we share it with |
End User Account Information | Manage your Account and enable logging in to the Services; enable you to connect with Contributors | Companies providing technical infrastructure for the Services and companies that permit us to manage the End User relationship |
Member Account Information | Manage your Account and enable logging in to the Services | Companies providing technical infrastructure for the Services |
Contributor Information | Share it with an Organization to which you have chosen to contribute or communicate; send you tax receipts | Organizations; our email service provider(s) |
Transaction Billing Information | Process payments from Contributors | Stripe, our payment processor |
Visitor Information | Share it with an Organization whose form you have filled in | Organizations; our email service provider(s) |
Contact Information | Communicate with you | Our email service provider(s) |
Demo Information | Invite you to one of our demo meetings at your request | Our email service provider(s); Zoom, the platform used to host the demo meeting |
Chat Information | Communicate with you and respond to your inquiry | Companies that provide chat services |
Some Terms
Before we get started with the details, here are a few terms we think you should know as you read this Policy.
“Data Protection Laws” refers to the laws that are designed to protect your personal data and privacy in the place where you live. These include:
- The “GDPR”, the European Data Protection Law which stands for “General Data Protection Regulation”, with the official name Regulation (EU) 2016/679 of the European Parliament and of the Council;
- The “UK GDPR” which applies to our activities in the United Kingdom; please note that when this Policy refers only to the “GDPR”, this includes the UK GDPR as applicable;
- “PIPEDA” (Personal Information Protection and Electronic Documents Act), which is the Canadian Data Protection Law that applies to our activities in Canada;
- Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (the “Quebec Privacy Act”) as amended by Law 25, that applies to our activities in Quebec;
- The California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act which applies to our activities in the United States in certain circumstances; and
- Other state privacy laws in the United States, specifically those which are currently in force in Colorado, Connecticut, and Virginia.
Zeffy is committed to adhering to all these laws, and any other Data Protection laws that apply to us.
“Personal data” – this is information we collect from you or about you and which is defined in the GDPR as “any information relating to an identified or identifiable natural person.” It can be as simple as your name or your email, or something more complicated like an online identifier (usually a string of letters and / or numbers) that gets attached to you. Under PIPEDA, the Quebec Privacy Act and the CCPA, the equivalent concept is “personal information”, which is roughly the same. For example, the Quebec Privacy Act defines “personal information” as “any information which relates to a natural person and allows that person to be identified either directly or indirectly.” Any mention of “personal data” in this Policy will also mean personal information.
Additional definitions shall be made throughout this Policy, but they will be recognizable as they will be capitalized, bolded, and in quotation marks. Additional definitions may also be found in the Terms and Conditions of Use – NPO and Terms of Use - Users and will have the same meaning in this Policy as they do there.
About Us and Contacting Us
9355-0861 Québec Inc., d.b.a. Zeffy™ (“Zeffy”), who owns and operates the Website, Platform and Services, is a Quebec corporation located in the province of Quebec, Canada, with an office at the address listed below. Where this Policy refers to “Zeffy”, it may refer to Zeffy and/or its affiliates, and their respective officers, directors, employees, agents, partners, principals, representatives, successors and assigns (collectively “Representatives”), depending on the context. Any reference to “we”, “our”, or “us” in this Policy shall also refer to Zeffy.
Under the GDPR, Zeffy is generally a “data controller”. That means we collect personal data directly from you and determine the purpose and means of “processing” that data. “Processing” is a broad term that means collection, use, storage, transfer or any other action related to your personal data; it is used in this Policy in that way. Sometimes, Zeffy acts as a “data processor” when we get personal data from Organizations. and process it on their behalf, for example when using email addresses that Organizations collect, and sending emails on their behalf.
Under PIPEDA, Zeffy is an “organization” and, under the Quebec Privacy Act, Zeffy is an “enterprise”. PIPEDA uses the phrase “collection, use and disclosure” and the Quebec Privacy Act uses “collects, holds, uses or communicates to third parties” as the rough equivalent to the “processing” of the GDPR. When we use “processing” in this Policy, you can substitute either of those phrases.
If you want to ask us anything about what’s in this Policy, or anything else privacy- or data- related, or exercise any of your available privacy rights, you can contact:
Or :
Your Rights
You have the following rights regarding your personal data held by Zeffy, and other privacy rights. Please note that not necessarily all of these rights may be available to you; this depends on the Data Protection Laws where you are located and that apply to you. These rights may be exercised without affecting any prices or costs charged by Zeffy, if any. Please note that exercising certain of these rights may affect your ability to use some or all of the Website, Platform or Services.
- The right to withdraw at any time your consent for Zeffy to process your personal data;
- The right to have your personal data erased from Zeffy’s records, and to have your name de-indexed if we link to any information about you (which we currently do not);
- The right to access your personal data and any relevant information around its processing and use;
- The right to have a copy of your personal data given to you in an easy-to-read format so that you can transfer it to any data controller or data processor or other third party;
- The right to have your personal data corrected or updated if you believe it is inaccurate or out of date;
- The right to opt out of marketing communications we send you, at any time;
- The right to know whether Zeffy shares your personal data (and if so, who gets it). Please refer to that information elsewhere in this Policy, though you can contact our Privacy and Data Protection Officer if you need additional information or clarifications;
- The right to demand that Zeffy not sell your personal data. Please note that Zeffy does not sell your personal data;
- The right to restrict the processing of your personal data if it is inaccurate or if our processing or use of it is against the law; and
- The right to refuse any marketing or advertising targeted at you by Zeffy.
If you wish to exercise any of these rights, please contact our Privacy and Data Protection Officer at the contact information above or refer to certain relevant sections further in this Policy.
Personal Data Collected from You and What We Use It For
Zeffy limits the amount of personal data that we collect to what is necessary and appropriate for the identified purposes. We will not use or disclose your personal data for purposes other than those for which it was collected, except with your consent or as permitted or required by applicable law.
In the table below, please find all the personal data we may collect from you directly, what we use it for, and the legal basis under the GDPR for us having and processing this personal data. Under PIPEDA, the Quebec Privacy Act, and the CCPA, the legal basis is your informed consent, and by submitting this personal data you acknowledge having granted this consent to Zeffy.
Personal data category | Personal data processed |
What we use it for (the “purpose” of processing)
|
Legal basis for processing under the GDPR |
End User Account Information | Name, email address, Organization name, phone number, country where you are located | To manage your Account and enable logging in to the Services | Your consent and performance of a contract between you and us |
Member Account Information | Name, email address, Organization name, phone number, country where you are located | To manage your Account and enable logging in to the Services | Your consent and performance of a contract between you and us |
Contributor Information | First name, last name, email address, address and any other information that an Organization may request from you | To share with an Organization to which you have chosen to contribute or communicate; to send you tax receipts | Your consent in giving us this information and the performance of a contract between you and us |
Payment Billing Information | Credit/Visa debit card holder name, number, expiration date, CVV number and billing address | To process payments from Contributors; to make sure an Organization to which you have decided to contribute receives your payment | Your consent in giving us this information |
Visitor Information | First name, last name, email address | To share with an Organization whose form you have filled in | Your consent in giving us this information |
Contact Information | Name and email address; optionally, the organization with which you are affiliated | To communicate with you | Your consent in giving us this information |
Demo Information | Name and email address; optionally, your phone number | To invite you to one of our demo meetings at your request | Your consent in giving us this information |
Chat Information | Any personal data submitted via the Website’s chat function | To communicate with you and to respond to your inquiry | Your consent in giving us this information |
Personal Data Collected About You from Third Parties and What We Use It For
Personal data category |
Personal data processed |
Who we get the data from |
What we use it for (the “purpose” of processing) |
Legal basis for processing under the GDPR |
Donation Billing Information |
Certain PayPal, Apple Pay or Google Pay account information |
PayPal, Apple or Google |
To allow you to use your PayPal, Apple Pay or Google Pay accounts to donate to an Organization via Stripe |
Your consent |
End User Account Information |
Name, email address, Organization name |
The Organization where you are employed can create an Account on your behalf |
To create your Account so that you can use the Services as an End User |
An Organization’s legitimate interest in setting up Accounts for its employees |
Member Information; Contributor Information |
First name, last name, email address, address and any other information that an Organization had previously requested and collected from you |
Other donation management platforms, if an Organization transfers its data (including all personal data) from another donation management platform to Zeffy |
To permit an Organization to use your Member Information and Contributor Information in connection with the Platform and as otherwise described in this Policy |
An Organization’s legitimate interest in switching between donation management platforms |
Who We Transfer Your Personal Data To
Personal data category |
Who we transfer it to |
What they do with it |
End User Account Information |
Companies providing technical infrastructure for the Services, specifically Amazon Web Services and Heroku Companies that permit us to manage the End User relationship, specifically HubSpot |
Control your logging in to the Platform and record-keeping Facilitate the functioning of the Services |
End User Account Information (name and email address only) |
Companies that are integrated with the Website and that allow you to provide direct feedback to us, specifically Canny |
Allow you to provide feedback to us about the Services and email you to let you know we have responded to your feedback |
Member Account Information |
Companies providing technical infrastructure for the Services, specifically Amazon Web Services and Heroku |
Control your logging in to the Platform and record-keeping |
Member Account Information (name and email address only) |
Companies that are integrated with the Website and that allow you to provide direct feedback to us, specifically Canny |
Allow you to provide feedback to us about the Services and email you to let you know we have responded to your feedback |
Contributor Information |
Organizations SendGrid, which provides email services on an Organization’s behalf, as detailed more fully in the Email Communications section below |
Contact you and interact with you as a Contributor Send you emails |
Donation Billing Information |
Stripe, our payment processor |
Process your donation to an Organization to which you have chosen to contribute |
Visitor Information |
Organizations SendGrid, which provides email services on an Organization’s behalf, as detailed more fully in the Email Communications section below |
Contact you Send you emails |
Contact Information |
Companies that provide email services, specifically Sendinblue and HubSpot, as detailed more fully in the Email Communications section below |
Send you emails |
Demo Information |
Companies that provide email services, specifically Sendinblue |
Send you an invitation to one of our weekly demo meetings at your request Give you access to the weekly demo meeting that you signed up for |
Chat Information |
Companies that provide chat services, such as HubSpot |
Operate the chat service on the Website; email you a transcript of the chat (if you have an End User Account) |
Advertising identifiers |
Companies that provide online advertising networks, such as Google and Facebook |
Show you ads for Zeffy and the Services when you are on the internet, as further detailed in the Zeffy Advertising section below |
Analytics identifiers and related information, including IP address |
Companies that provide data analytics for the Website, Platform and Services, such as Google Analytics and the other programs listed in the Limited Gathering of Information section below |
Provide us with analytics about the Contributors, End Users, Members, Visitors and Website Visitors, and how the Services are used, and to trace fraudulent activities if necessary, as further detailed in the Limited Gathering of Information section below |
Other Limited Circumstances When We May Transfer your Personal Data to Third Parties
In addition to the regular sharing of personal data with third parties as described in the previous section, we will share personal data with third parties under the limited circumstances described below.
We may share your personal data with law enforcement or other public authorities if: (1) we are required by applicable law in response to lawful requests, including to meet national security or law enforcement requirements; (2) if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, fraud, or situations involving potential threats to the safety of any person; or (3) if we believe it is necessary to investigate, prevent, or take action regarding situations that involve abuse of the Website, Platform or Services infrastructure or the Internet in general (such as voluminous spamming or denial of service attacks).
We may also share personal data: (1) to a parent company, subsidiaries, joint ventures, or other companies under common control with Zeffy (in which case we will require such entities to honour this Policy); (2) if Zeffy merges with another entity, is subject to a reorganization, sells or transfers all or part of its business or assets (in which case we will require such entity to assume our obligations under this Policy, or inform you that you are covered by a new privacy policy).
We will never share your personal data with other third parties, except under these circumstances. We do not sell or rent your personal data to any third party for direct marketing purposes or any other purpose.
Sensitive Personal Information
Email Communications and Compliance with Anti-Spam Laws
Zeffy uses (i) Sendinblue to send out emails related to the Services; and (ii) HubSpot to manage our mailing list and to send out our newsletter and promotional emails. Zeffy also allows Organizations to send you emails related to the Services directly from the Platform, including, but not limited to, emails regarding donations and ticket purchases, which is done using SendGrid (together with Sendinblue and HubSpot, the “Email Service Providers”). Personal data is transferred to the Email Service Providers in order for the emails to be sent out properly. Your email address is only used to send out emails; the Email Service Providers do not use this personal data for any other purpose and will not transfer or sell your personal data to any other third party. For more information, please refer to Sendinblue's Privacy Policy, HubSpot's Privacy Policy and Twilio's Privacy Policy, which applies to SendGrid.
You may unsubscribe from the Zeffy mailing list or emails that you receive from Organizations via Zeffy (as described above) at any time, by following the link at the bottom of the Zeffy or Organization emails. Other types of emails, such as emails related to the Platform and emails that you will receive from Organizations with your tax receipts will not have an opt-out option as they are necessary for the use of the Services.
Zeffy’s practices with respect to its email are designed to be strictly compliant with anti-spam laws, including, but not limited to, the law unofficially called “CASL”, or Canada’s Anti-Spam Law (S.C. 2010, c. 23) and the American CAN-SPAM Act of 2003. If you believe you have received email in violation of these laws, please contact our Privacy and Data Protection Officer using the contact information further up in this Policy.
Zeffy Advertising and Opting Out
Generally, these ad networks work by delivering you advertisements that will be of particular interest to you when you use their websites, apps, or services, based on your browsing and activity history interacting with the Websites, Platform and Services. Certain advertising networks use your email address that you submit to us to match with your online profile in order to better target the advertising to your preferences, which is known as email retargeting.
The table blow identifies the advertising networks we currently use, as well as links and instructions on opting out. By visiting the Website or Platform or by using the Services or submitting your email address to us, you consent to our advertising to you in this manner, understanding that you can opt out at any time, or refuse or delete the cookie (as described below) which will prevent such advertising.
Advertising network |
Link(s) and instructions to opt out |
Adjust your Google ad settings or use the WebChoices online opt-out tool. |
|
Adjust your Ad Preferences settings while logged in to Facebook |
Limited Gathering of Information for Statistical, Analytical and Security Purposes
Zeffy automatically collects certain information using “Third-Party Analytics Programs” such as Google Analytics to help us understand more about Contributors, End Users, Members, Visitors and Website Visitors and how they use the Website, Platform and Services, but none of this information identifies you personally, except via an alphanumeric string. For example, each time you visit the Website, Platform or an Organization’s website, on a page powered by Zeffy, we automatically collect (as applicable) your IP address, browser and computer or device type, access times, the web page from which you came, the web page(s) or content you access, and other related information. We use information collected in this manner only to better understand your needs and the needs of Contributors, End Users, Members, Visitors and Website Visitors in the aggregate. Zeffy also makes use of information gathered for statistical purposes to keep track of the number of visits to the Website and the Platform, the specific pages on the Website and the Platform, and the number of Website Visitors, with a view to introducing improvements to the Website, Platform, Services and our activities.
We also use certain Third-Party Analytics Programs such as Amplitude, Hotjar, Canny, HubSpot, Hevo, dbt, Snowflake and Tableau to monitor and analyse performance of the Services generally.
Your IP address and other relevant information that we collect using the Third-Party Analytics Programs may be used in order to trace any fraudulent or criminal activity.
Tracking Technology ("Cookies") and Related Technology
Zeffy uses tracking technology (“cookies” and related technology such as tags, pixels and web beacons) on the Website, Platform and Services and in emails. Cookies are small text files placed on your computer or device when you visit a website, in order to track use of the site and to improve the user experience by storing certain data on your computer. By visiting or using the Website, Platform or Services you agree to their use, but only if you explicitly consent to such use, according to the cookie banner presented to you when you visit the Website or Platform.
Specifically, we use cookies and related technologies for the following functions:
- to provide general internal and user analytics and to conduct research to improve the content of the Website, Platform and Services, and to monitor the performance of the Services, using the Third-Party Analytics Programs as described above in this Policy;
- to facilitate your logging in to the Platform;
- to facilitate the proper functioning of the Services;
- to facilitate payment processing;
- to facilitate online advertising, as described above in this Policy;
- to track information about emails you receive, for example whether you opened it or clicked on any links in it; and
- to assist in identifying possible fraudulent activities.
Your browser can be set to refuse cookies or delete them after they have been accepted and stored. You can refer to your browser’s help section for instructions, but here are instructions for the most commonly-used browsers and operating systems:
Please note that deleting or refusing cookies may reduce your user experience on the Website, Platform or Services. Furthermore, deleting cookies may prevent certain functions from working at all.
How we protect your Personal Data
We have implemented strict technical and organisational procedures for ensuring that, by default, only personal data which are necessary for each specific purpose of the processing are processed by us. These procedures prevent your personal data from being lost; or used or accessed in any unauthorised way.
We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable supervisory authority of a suspected data security breach where the Data Protection Laws requires us to do so, and within the time frame required by the applicable Data Protection Law.
Zeffy uses only industry best practices (physical, electronic and procedural) in keeping any data collected (including personal data) secure. In addition, we use third-party vendors and hosting partners to provide the necessary hardware, software, networking, storage, and related technology required to operate the Website and Platform, and these third parties have been selected for their high standards of security, both electronic and physical. For example, Zeffy uses vendors such as Amazon Web Services (AWS) and Heroku, both recognized leaders in secure data and other vendors who have very strict security protocols, for hosting of the Services and related data, and collection and storage of data, including personal data.
Finally, all information, including personal data, is transferred with encryption using Secure Sockets Layer (“SSL”) or Transport Layer Security (“TLS”), robust security standards for Internet data transfer and transactions. You can use your browser to check Zeffy’s valid SSL security certificates on the Website, Platform and in the Services.
Internal Procedures and Policies
In addition to the measures to protect your personal data described in the previous section, we have drafted and implemented certain internal procedures and policies regarding personal data, including the following:
- A framework for the keeping and destruction of the personal data that we collect, including where we may keep anonymized data;
- Defining and describing the roles and responsibilities of the members of Zeffy personnel throughout the life cycle of the personal data that we collect; and
- A process for dealing with individual complaints and requests for personal data and exercising of individuals’ rights under Data Protection Laws.
Transfer of Your Personal Data Outside of the European Economic Area (EEA) and the U.K.
For our European users, we endeavour to keep your personal data inside the EEA or the U.K. (as applicable).
Certain of our data processors (and Zeffy) are in other countries where your personal data may be transferred. However, these countries are limited to countries with particular circumstances that protect your data, specifically:
- Canada. We transfer personal data to our operations in Canada, but Canada has been determined to have an “adequate level of protection” for your personal data under European data protection law.
- The United States. Your personal data is only transferred to companies in the United States that: (1) have signed agreements with us or have informed us that they are GDPR-compliant; and (2) have concluded the Standard Contractual Clauses for the transfer of personal data outside the EEA and the U.K..
That’s it! You have the right, however, to refuse to have your data transferred outside the EEA or the U.K. Please contact our Privacy and Data Protection Officer to make that request. Please note that making this request may prevent you from being able to use certain portions of the Website, Platform or Services.
Transfer of your Personal Data Outside of Quebec
For our Quebec Contributors, End Users, Members, Visitors and Website Visitors, we endeavour to keep your personal data in Quebec. However, certain of our third-party service providers are in other provinces or countries where your personal data may be transferred. When this happens, we do the following to safeguard your personal data:
- We will perform what the Quebec Privacy Act calls an “Assessment of the privacy-related factors” (what is generally called a “Privacy Impact Assessment,” or “PIA”) prior to the personal data leaving Quebec. If the PIA does not meet our standards and the standards required by the Quebec Privacy Act, we will not transfer your personal data to such a service provider; and
- If the PIA allows us to transfer the personal data to such a service provider outside Quebec, we will sign what is generally called a “Data Processing Agreement,” or DPA, with the service provider, which protects the personal data transferred to them and limits their use of it to what we have contracted with them to do. This DPA will adhere to the requirements of the Quebec Privacy Act.
Supervisory Authorities and Complaints
If you are in the EEA or the U.K., under the GDPR you have the right to make a complaint to the appropriate supervisory authority. If you are not satisfied with the response received or the actions taken by our Privacy and Data Protection Officer, or if you would like to make a complaint directly about Zeffy’s data practices, we invite you to contact the supervisory authority in your country.
If you are in the U.K., you should contact the Information Commissioner’s Office who is the supervisory authority. You can reach them in a variety of ways, including by phone (0303 123 1113 in the UK) and mail (Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF). If you are in France, you should contact the Commission Nationale de l'Informatique et des Libertés which is the supervisory authority there. Their contact information can be found here.
The full listing of all Data Protection Authorities (the supervisory authorities) across the EEA can be found here.
If you are in Canada and you are not satisfied with the response received or the actions taken by our Privacy and Data Protection Officer, you can make a complaint to the Office of the Privacy Commissioner of Canada. Instructions on how to do so can be found on their website. If you are in Québec, you can make a complaint to the Commission d’accès à l’information, with the instructions for contacting them on their website.
In California you can make a complaint to the California Privacy Protection Agency, using their online form.
Data Retention and Anonymization
Your personal data will only be kept for as long as it is necessary for the purpose needed for that processing. For example, we will retain your End User Account Information for as long as you have an account with us to use the Services. If you request that we delete your account, we will delete your End User Account Information.
We may have to keep your data for a longer period of time to satisfy our requirements under any applicable law including anti-spam laws, or to protect our legal interests.
In some cases, where permitted by the Data Protection Laws, we may keep personal data that has been anonymized, for our legitimate business purposes.
Automated Decision-Making
Children’s Privacy Statement
The Services are only intended for persons who are 18 years old for a resident of a Canadian province or 21 years old for a resident of a state in the U.S., or the age of majority in any other country.
The Data Protection Laws have various age limits as to the minimum age required for us to hold personal data about an individual. We do not knowingly collect any personal data from a child under those minimum ages. If we become aware that we have inadvertently received personal data from a person under the minimum ages through the Website, Platform or Services, we will delete such information from our records.
Changes to This Privacy Policy
Thanks for reading! Please keep your personal data safe; we promise to do the same.
© 9355-0861 Québec Inc., d.b.a. Zeffy™. 2023