Privacy & Data Protection Policy
At EMCC USA, trust is the foundation of everything we do. Members share their credentials, their practice and their professional stories with us. Volunteers give us their time, their networks and, often, access to other people's information. Each of them deserves to know that their personal data is treated with the same care, discretion and ethical discipline we expect inside a coaching relationship. This policy explains, in plain language, how EMCC USA, Inc. ("EMCC USA", "we", "us") collects, uses, shares, protects, keeps and deletes personal data, and the choices you have along the way.
Our Privacy Promise
We collect only what we need to serve our members and run the association. We tell you why we are asking for it. We never sell, rent or trade personal data. We keep it secure, share it only for a clear purpose, delete it once it has done its job, and respond promptly whenever you ask what we hold about you.
Who We Are
EMCC USA, Inc. is a Delaware nonprofit corporation and the United States country organization of the European Mentoring and Coaching Council (EMCC Global). Our mission is to raise the standard of mentoring, coaching and supervision across the United States.
Who This Policy Covers
This policy applies to everyone whose information we handle, including:
-
Members: current, lapsed and prospective members at every level, including individual practitioners, organizational members and their named contacts, students and trainees.
-
Volunteers: Directors, Officers, Portfolio Leaders, committee members, community-of-practice facilitators, event hosts, moderators, mentors, reviewers, and anyone applying for a volunteer or Board role.
-
Participants: non-members who register for our events, webinars, communities of practice, surveys or newsletters.
-
Contributors: speakers, panelists, authors, podcast or video guests, and people who share testimonials.
-
Partners: named contacts at sponsors, universities, fellow professional bodies, vendors, EMCC Global and other EMCC country organizations.
-
Website and social media visitors: people who browse our website, submit forms, or engage with us on LinkedIn, Facebook and other channels.
"Personal data" means any information that identifies, or could reasonably be linked to, a living person. It covers information in every format and location, from our membership records and shared drives to email, video-meeting recordings, social media tools and paper forms. Everyone who handles personal data on our behalf, whether a Board member, volunteer, contractor or service provider, is bound by this policy or by equivalent contractual terms.
The Principles We Follow
Eight principles guide every decision we make about personal data:
-
Fair and transparent: we explain what we collect and why, in plain language, at the moment we collect it.
-
Purpose-bound: information gathered for one reason, such as event registration, is not reused for an unrelated reason without telling you and, where needed, asking you.
-
Minimal: we ask only for what a task genuinely requires; "nice to have" fields are removed or made optional.
-
Accurate: we make it easy to update your details and we correct errors promptly.
-
Time-limited: we keep information only as long as our retention schedule allows, then delete or anonymize it.
-
Secure: we protect information with proportionate technical and organizational safeguards and limit access to those who need it.
-
Accountable: we document what we hold, who is responsible for it, and the decisions we make about it.
-
Confidential by default: we bring the ethic of the coaching room into our administration. What is shared with us in trust stays in trust.
The Laws and Standards We Follow
Our obligations come from three directions: United States law, European law where it applies to our activities, and the professional ethics of our field.
United States law. We follow the CAN-SPAM Act for email, the Telephone Consumer Protection Act for text messages, the Children's Online Privacy Protection Act, the Fair Credit Reporting Act where any background check is used, and IRS and nonprofit record-keeping rules. We also respect state data breach notification and data security laws. Several states, including Colorado, Delaware, Maryland, Minnesota, New Jersey and Oregon, apply their consumer privacy laws to nonprofits once certain thresholds are met. We adopt the core standards of these laws as good practice, whether or not a threshold applies to us.
European law. EMCC Global is based in Belgium and is subject to the EU General Data Protection Regulation (GDPR). Where we process the data of people in the European Union or United Kingdom, or exchange member data with EMCC Global, we apply GDPR-level standards, including a recorded lawful basis for processing, one-month responses to rights requests, safeguards for international transfers, and timely regulator notification of qualifying breaches.
Professional ethics. The EMCC Global Code of Ethics asks practitioners to maintain confidentiality, respect data protection law and handle records responsibly. We hold ourselves, our volunteers and our communities of practice to that same standard.
Information We Hold About Members
-
Identity and contact details (name, email, phone, city, state, country, preferred name): used to deliver your membership, send essential notices and verify identity.
-
Professional profile (practice type, specialisms, languages, employer, website, LinkedIn profile, headshot, bio): used for the member directory, networking, and matching speakers and volunteers. Directory listings are always opt-in.
-
Credentials and development (membership level, EMCC accreditation, other credentials, CPD hours attended): used to confirm eligibility, issue CPD certificates and support accreditation renewal.
-
Transactions (fees paid, invoices, payment dates, discount codes): used for accounting, audit and tax compliance. Card numbers stay with our payment processor and are never stored by EMCC USA.
-
Engagement (event attendance, email opens and clicks, survey responses, committee interest): used to improve programs, plan events and recognize contribution.
-
Communication preferences (newsletter opt-ins, unsubscribes, channel preferences): used to respect your choices and comply with email law.
-
Concerns and complaints (ethics concerns, correspondence, outcomes): used to uphold professional standards.
The member directory. Your listing is opt-in, and you choose which details appear. You can edit or remove it at any time, and changes take effect within 10 business days. Directory information may not be scraped, exported or used for bulk marketing by anyone, including other members. Misuse is treated as a breach of the EMCC Code of Ethics.
Our relationship with EMCC Global. EMCC Global operates the international membership platform and accreditation system. When you join or become accredited through that platform, EMCC Global acts as an independent data controller under its own published privacy policy. EMCC USA receives and uses only the portion of member data it needs to deliver country-level services, events and communications. The responsibilities of each organization are set out in a written data-sharing arrangement, and accreditation assessment files remain with EMCC Global.
Information About Volunteers and Board Candidates
Volunteers power EMCC USA, and they share personal information with us at every stage, from expressing interest to stepping down. We treat it with the same care as member data, and we are especially careful with candidate information, because selection decisions can be personal.
-
Applications and expressions of interest are seen only by the Nominations Committee and the relevant Portfolio Leader, and are stored in restricted folders rather than personal inboxes.
-
Selection and elections: interview notes stay factual and role-related, candidate statements are published only with consent, and individual ballots remain confidential. Only results are published.
-
Onboarding: volunteers sign a confidentiality agreement and conflict-of-interest disclosure. Emergency contact details are optional and used only in an emergency.
-
Active service: public profiles and photos are published only with the volunteer's approval, and attendance records are used for governance, never surveillance.
-
Background checks are used only for roles involving financial authority or unsupervised work with vulnerable people, and only after written disclosure and authorization.
-
References are provided externally only at the volunteer's request.
-
Stepping down: access is removed promptly (the same day for administrator roles), EMCC USA files are transferred to organizational accounts, and volunteers confirm that they have deleted EMCC USA personal data from personal devices and accounts.
Directors and Officers accept that some information about them is public by nature: their name, role, term and a short professional bio on our website, and their names and titles in annual nonprofit filings. We publish nothing beyond this without their agreement, and we never publish home addresses or personal phone numbers.
Events, Communities of Practice and Reflective Spaces
Our gatherings range from open webinars to intimate, confidential communities of practice such as The Supervision Circle. The more personal the space, the stricter our rules.
Registration. We ask only for what we need to run the event and issue CPD certificates. Accessibility and dietary needs are optional, used only to support you at that event, and deleted within 30 days. Attendee lists are never shared with speakers, sponsors or other attendees unless you opt in.
Recordings, photographs and chat.
-
Open webinars and conferences may be recorded, with notice at registration and at the start of the session. You can keep your camera off or change your display name, and participant faces are not published without consent. Chat is saved only if needed for follow-up and deleted within 30 days.
-
Workshops and training: only presenter segments are recorded, with advance notice. Breakout rooms are never recorded.
-
Communities of practice, supervision and peer reflection are never recorded. No screenshots or photographs of participants are taken, chat saving is disabled, and no automated transcription is used.
-
Board and committee meetings are recorded only with everyone's agreement, for minute-taking, and the recording is deleted once the minutes are approved. Executive sessions are never recorded.
-
In-person events display a photography notice and offer a clear way to opt out of photos.
Case material. Coaches, mentors and supervisors often bring client situations into reflective spaces. Participants remove or disguise anything that could identify a client, client organization or third party before sharing. Each session opens with a confidentiality agreement, any notes taken must contain no identifying details, and EMCC USA never stores case material.
Emails, Newsletters and Marketing
-
Essential messages such as membership renewals, event logistics, governance notices and policy updates are sent to members as part of their membership.
-
Newsletters and promotional messages go to members and to non-members who have opted in. Every message includes a working unsubscribe link, and opt-outs are honored within 10 business days.
-
Text messages are sent only to people who have given express consent.
-
Testimonials, quotes and success stories are published only with written consent, which you can withdraw for future use at any time.
-
Photographs and videos of identifiable people are used in marketing only with consent, or after clear notice at a public event with a genuine chance to opt out.
-
Social media accounts belong to EMCC USA and are managed by Board-approved administrators, with access reviewed every quarter.
-
We never sell, rent or trade our mailing lists, and we do not allow sponsors to email our members directly.
Sensitive Information
Some information carries a higher risk if misused. This includes health and disability information; racial or ethnic origin; national origin; religious beliefs; sexual orientation, sex life and gender identity; citizenship or immigration status; government identification numbers; financial account credentials; precise location; background-check results; and information about children.
We collect sensitive information only when there is a clear and necessary purpose, and with your explicit consent unless the law requires otherwise. Diversity, equity and inclusion surveys are always voluntary, always include a "prefer not to say" option, and are reported only in aggregate, never for groups smaller than five. Accommodation requests are used solely to provide the accommodation and are not added to member profiles. We do not collect Social Security numbers except where a tax form legally requires it. Sensitive information is never used for marketing or profiling.
When We Share Information
We share personal data only for a clear purpose, and only the minimum needed:
-
EMCC Global and other EMCC country organizations, for membership administration, accreditation, international events and joint programs, under a data-sharing arrangement.
-
Trusted service providers that power our website, email, video meetings, payments, storage, surveys and event ticketing. They act only on our instructions, under written terms, after a security review.
-
Sponsors and partners, only when you actively opt in, for example by ticking a box to receive a partner's offer.
-
Auditors, accountants and insurers, who are bound by professional confidentiality.
-
Authorities, only where required by law or a court order, or to protect someone's safety.
-
A successor organization, in the event of a merger, restructuring or dissolution, with notice to members and the same protections continuing.
Before we adopt any new tool that will hold personal data, we confirm that it has a published privacy policy and data processing terms, supports multi-factor authentication and role-based permissions, encrypts data in transit and at rest, allows data to be exported and deleted, and, where EU or UK data is involved, has appropriate transfer safeguards in place.
How We Keep Your Information Secure
Our safeguards are proportionate to a volunteer-led association and are reviewed every year. Every system is held in an organization-owned account with at least two administrators, so nothing depends on one person's login. Multi-factor authentication is required on our email, storage, website, social media, payment and membership systems. Credentials are kept in an organizational password manager and changed whenever someone with access leaves. Access is granted on a role-based, least-privilege basis and reviewed quarterly. Card payments are handled only by PCI-DSS compliant processors, and critical data is backed up in access-controlled locations.
Because much of our work is carried out by volunteers, every volunteer signs a confidentiality and data use agreement before receiving access to personal data. Our volunteers commit to:
-
conducting EMCC USA business only through @emccusa.org accounts and approved platforms;
-
requesting only the access their role needs, and returning it when no longer needed;
-
keeping member lists off personal devices, personal cloud storage and USB drives;
-
protecting every login with a unique password and multi-factor authentication;
-
using blind copy or our mailing platform for group emails so addresses are never exposed;
-
sharing documents through restricted links with named people only;
-
keeping personal data out of public AI tools;
-
respecting the confidentiality of communities of practice, supervision groups and Board executive sessions;
-
never using EMCC USA contacts to promote their own practice, book, program or employer; and
-
reporting any suspected data incident within 24 hours, in a culture where early reporting is always welcomed and never punished.
Artificial Intelligence
AI tools can help a volunteer-led association do more with less, and we explore them thoughtfully. Personal data may be processed only in approved AI tools, under organizational accounts whose terms prevent our data from being used to train public models. Names, emails, application materials, survey comments and case material are never entered into free or personal AI accounts. AI note-takers may join a meeting only when everyone present has been told in advance and no one objects, and they are never used in communities of practice, supervision spaces, ethics matters or executive sessions. AI may support, but never replace, human judgment in selecting volunteers, awarding recognition, handling complaints or making any decision with significant effects on a person. Where AI materially shapes content we send you, or a service you interact with, we will say so.
How Long We Keep Information
Keeping data "just in case" adds risk without adding value. Each type of record has a set retention period, after which it is securely deleted or anonymized across every copy, including exports, attachments, shared drives and personal devices. Retention is paused only when information is relevant to a legal claim, investigation or open complaint. Our main retention periods are:
-
Current member records: for the duration of membership.
-
Lapsed member records: 2 years after lapse, then deleted or anonymized (we may keep your email address on a suppression list so that your opt-out is honored).
-
CPD attendance and certificates: 5 years, to support accreditation renewal.
-
Financial records: 7 years after the end of the fiscal year.
-
Board ballots: 90 days after results are certified, unless challenged.
-
Unsuccessful volunteer or Board applications: 12 months after the decision, unless the candidate asks us to keep them longer.
-
Volunteer service records and signed agreements: 7 years after service ends.
-
Emergency contact details: deleted when volunteer service ends.
-
Event registrations: 2 years after the event.
-
Accessibility and dietary requests: 30 days after the event.
-
Public webinar recordings: 2 years, or longer as part of a resource library with presenter consent.
-
Meeting chat logs and automatic transcripts: 30 days.
-
Identifiable survey responses: 12 months, then aggregated or anonymized.
-
Testimonials, photos and consent forms: while in use plus 2 years, or sooner if consent is withdrawn.
-
Ethics concerns and complaints: 7 years after closure.
-
Website analytics: 14 months.
Anonymized, aggregated statistics, such as membership growth by state, may be kept indefinitely. Bylaws, Board minutes, resolutions and policies are kept permanently as part of our governance record.
Your Rights
Wherever you live, you can ask us to:
-
Know and access: confirm whether we hold your data, give you a copy, and explain how it is used and shared.
-
Correct information that is inaccurate or incomplete.
-
Delete your data, unless we must keep it for legal, financial or governance reasons, in which case we will explain why.
-
Receive your data in a commonly used electronic format.
-
Opt out of marketing communications and profiling. We do not sell personal data or use it for targeted advertising.
-
Withdraw consent at any time for anything based on consent, such as your directory listing or the use of your photograph.
-
Object or restrict: if you are in the EU or UK, object to processing based on legitimate interest, or ask us to pause processing while a concern is resolved.
-
Appeal our response to a different Officer, and complain to a regulator.
How to make a request. Email info@emccusa.org with "Privacy request" in the subject line, or contact any Board member, who will pass it to our Privacy Lead within two business days. We will acknowledge your request within 10 business days, verify your identity in a proportionate way (usually by replying to the email address we hold for you), and respond in full within 45 days, or within one month if you are in the EU or UK. If a request is complex, we may extend this once and will explain why. Requests are free of charge, and no one is ever treated less favorably for exercising their rights.
If Something Goes Wrong
A data incident is any event that puts personal data at risk, such as a lost laptop, an email sent to the wrong list, a compromised account or a provider's breach. Every incident, however small, is reported to our Privacy Lead within 24 hours. We act immediately to contain it, assess within 72 hours what information and which people are affected, and fix the root cause. Where the law requires, we notify affected individuals, state regulators, EMCC Global and, for EU or UK data, the relevant supervisory authority within the required timeframes. Significant incidents are reported to our Board of Directors, and every incident is recorded so that we keep learning and improving.
Children
Our services are designed for adults. We do not knowingly collect personal data from children under 13. If you believe a child has shared information with us, please contact us and we will delete it promptly.
Accountability and Review
Our Board of Directors adopts this policy and oversees it through the Governance Committee, which reviews it every year and sooner if the law changes, a significant incident occurs, or we launch a new type of program or partnership. A Privacy Lead appointed by the Board is the day-to-day point of contact for privacy questions, requests and incidents. Every volunteer completes a privacy briefing before receiving access to personal data and an annual refresher after that. When we make meaningful changes to this policy, we will update the date at the top of this page and, where appropriate, let members know directly.
Contact Us
Questions, concerns or requests about your personal data are always welcome.
Privacy Lead, EMCC USA, Inc.
Email: info@emccusa.org
Website: www.emccusa.org
If you are in the European Union, you may also contact EMCC Global at privacy@emccglobal.org or your local data protection authority. If you are in the United States, you may also contact the Attorney General of your state.
Once it's pasted in, apply your site's heading and body text styles so it matches the rest of the site.
i need it to speak to volunteers, speakers, site visitors and members
Created a file, edited a file, ran a command
I've rewritten it to speak to each group directly. There's now a short "Find What Applies to You" guide near the top, then sections for site visitors, members, speakers and volunteers, then the shared sections that apply to everyone. The Word file is updated too, but here's the full text:
Privacy & Data Protection Policy
EMCC USA, Inc. · Last updated: September 2026
Whether you are a member, a volunteer, a speaker or simply visiting our website, you trust us with information about you. We take that trust seriously. At EMCC USA, we handle personal data with the same care, discretion and ethical discipline we expect inside a coaching relationship. This page explains, in plain language, what we collect, why we collect it, how we protect it, and the choices you have.
Our Promise to You
We collect only what we need. We tell you why we are asking. We never sell, rent or trade your personal data. We keep it secure, share it only for a clear purpose, delete it once it has done its job, and respond promptly whenever you ask what we hold about you.
Who We Are
EMCC USA, Inc. ("EMCC USA", "we", "us") is a Delaware nonprofit corporation and the United States country organization of the European Mentoring and Coaching Council (EMCC Global). Our mission is to raise the standard of mentoring, coaching and supervision across the United States.
Find What Applies to You
This policy covers everyone we interact with. The sections below speak directly to each group, and the sections that follow apply to all of you.
-
Site visitors and social media followers: see "If You Visit Our Website or Follow Us Online".
-
Members: see "If You Are a Member".
-
Speakers, presenters and contributors: see "If You Speak, Present or Contribute".
-
Volunteers and Board candidates: see "If You Volunteer With Us".
-
Everyone: events, communications, sharing, security, retention and your rights are explained from "When You Join Our Events" onward.
The Principles We Live By
-
Transparent: we explain what we collect and why, at the moment we collect it.
-
Purpose-bound: information you give us for one reason is not reused for an unrelated reason without telling you and, where needed, asking you.
-
Minimal: we ask only for what we genuinely need; optional means optional.
-
Accurate: you can update your details easily, and we correct errors promptly.
-
Time-limited: we keep information only as long as necessary, then delete or anonymize it.
-
Secure: we protect information with sensible safeguards and limit access to those who need it.
-
Accountable: we document what we hold, who is responsible for it, and the decisions we make about it.
-
Confidential by default: what is shared with us in trust stays in trust.
If You Visit Our Website or Follow Us Online
You can browse www.emccusa.org without telling us who you are. When you use our website or social media channels, here is what happens:
-
Forms and messages. If you contact us, subscribe or register through a form, we collect only the details the form asks for and use them only to respond to you or provide what you requested.
-
Website analytics. We use analytics to understand, in general terms, how our pages are used so we can improve them. Analytics data is kept for 14 months.
-
Social media. Our LinkedIn, Facebook and other pages are owned by EMCC USA and managed by Board-approved administrators. If you send us personal details through a social media message, we move them to a secure system and delete them from the platform where practical. Each platform also has its own privacy policy, which applies to your use of it.
-
No selling, no targeted advertising. We never sell visitor data and we do not use it for targeted advertising.
If You Are a Member
As a member, you share information with us so that we can serve you well. We hold:
-
Your identity and contact details (name, email, phone, city, state, country, preferred name), to deliver your membership and send essential notices.
-
Your professional profile (practice type, specialisms, languages, employer, website, LinkedIn profile, headshot, bio), for the member directory, networking and matching you with speaking or volunteering opportunities.
-
Your credentials and development (membership level, EMCC accreditation, other credentials, CPD hours), to confirm eligibility, issue CPD certificates and support your accreditation renewal.
-
Your transactions (fees, invoices, payment dates, discount codes), for accounting, audit and tax purposes. Your card number stays with our payment processor and is never stored by EMCC USA.
-
Your engagement (event attendance, email opens and clicks, survey responses, committee interest), to improve our programs and recognize your contribution.
-
Your communication preferences, so that we always respect your choices.
-
Any concerns or complaints, handled confidentially to uphold professional standards.
Your directory listing is your choice. The member directory is opt-in, and you decide which details appear. You can edit or remove your listing at any time, and changes take effect within 10 business days. No one, including other members, may scrape, export or use directory information for bulk marketing. Misuse is treated as a breach of the EMCC Code of Ethics.
EMCC Global and your membership. EMCC Global runs the international membership platform and accreditation system. When you join or become accredited through that platform, EMCC Global handles your data as an independent organization under its own privacy policy. EMCC USA receives only the portion of your data it needs to deliver US services, events and communications. Our respective responsibilities are set out in a written data-sharing arrangement, and your accreditation assessment files remain with EMCC Global.
If You Speak, Present or Contribute
We are grateful to the speakers, panelists, authors, podcast and video guests, and members who share their stories with our community. When you contribute:
-
Your bio and photo are used to promote your session or contribution, and published only in the form you approve.
-
Recordings of your session are made only with advance notice. Public webinar recordings are kept for 2 years, or longer as part of our resource library only with your consent.
-
Testimonials, quotes and success stories are published only with your written consent, and you can withdraw that consent for future use at any time.
-
Attendee lists are not shared with speakers unless attendees opt in, so the choice to connect always remains theirs.
-
Confidential spaces stay confidential. If you facilitate or contribute to a community of practice or supervision space, the confidentiality rules described below apply to you as well.
If You Volunteer With Us
Volunteers power EMCC USA. You share personal information with us at every stage of your journey, and you may also handle other people's information on our behalf. Both deserve care.
How we treat your information:
-
Applications and expressions of interest are seen only by the Nominations Committee and the relevant Portfolio Leader, and are kept in restricted folders, never in personal inboxes.
-
Selection and elections: interview notes stay factual and role-related, candidate statements are published only with your consent, and individual ballots remain confidential. Only results are published.
-
Onboarding: you sign a confidentiality agreement and a conflict-of-interest disclosure. Emergency contact details are optional and used only in an emergency.
-
Active service: your public profile and photo are published only with your approval, and attendance is used for governance, never surveillance.
-
Background checks apply only to roles involving financial authority or unsupervised work with vulnerable people, and only after written disclosure and your authorization.
-
References are provided externally only at your request.
-
Unsuccessful applications are kept for 12 months after the decision, unless you ask us to keep them longer. Service records and signed agreements are kept for 7 years after your service ends, and emergency contact details are deleted when you step down.
If you serve as a Director or Officer, some information about you is public by nature: your name, role, term and a short professional bio on our website, and your name and title in our annual nonprofit filings. We publish nothing beyond this without your agreement, and we never publish home addresses or personal phone numbers.
What we ask of you. Before you receive access to anyone's personal data, you will complete a short privacy briefing and sign our Volunteer Confidentiality and Data Use Agreement. As a volunteer, you agree to:
-
conduct EMCC USA business only through @emccusa.org accounts and approved platforms;
-
request only the access your role needs, and return it when you no longer need it;
-
keep member lists off personal devices, personal cloud storage and USB drives;
-
protect every login with a unique password and multi-factor authentication;
-
use blind copy or our mailing platform for group emails, so addresses are never exposed;
-
share documents only through restricted links with named people;
-
keep personal data out of public AI tools;
-
respect the confidentiality of communities of practice, supervision groups and Board executive sessions;
-
never use EMCC USA contacts to promote your own practice, book, program or employer; and
-
report any suspected data incident to our Privacy Lead within 24 hours.
Mistakes happen to careful people. What turns a small slip into a serious problem is silence, so early reporting is always welcomed and never punished. When you step down, your access is removed promptly (the same day for administrator roles), any EMCC USA files you created move to an organizational account, and we ask you to confirm that you have deleted EMCC USA personal data from your own devices and accounts. Your confidentiality obligations continue after your service ends.
When You Join Our Events
Our gatherings range from open webinars to intimate, confidential communities of practice such as The Supervision Circle. The more personal the space, the stricter our rules.
Registration. We ask only for what we need to run the event and issue CPD certificates. Accessibility and dietary needs are optional, used only to support you at that event, and deleted within 30 days. Attendee lists are not shared with speakers, sponsors or other attendees unless you opt in. Registration records are kept for 2 years.
Recordings, photographs and chat.
-
Open webinars and conferences may be recorded, with notice at registration and at the start. You can keep your camera off or change your display name, and your face will not be published without your consent. Chat is saved only if needed for follow-up and deleted within 30 days.
-
Workshops and training: only presenter segments are recorded, with advance notice. Breakout rooms are never recorded.
-
Communities of practice, supervision and peer reflection are never recorded. No screenshots or photographs of participants, no saved chat and no automated transcription.
-
Board and committee meetings are recorded only with everyone's agreement, for minute-taking, and the recording is deleted once the minutes are approved. Executive sessions are never recorded.
-
In-person events display a photography notice and offer you a clear way to opt out of photos.
Case material. When you bring a client situation into a reflective space, please remove or disguise anything that could identify a client, client organization or third party. Each session opens with a confidentiality agreement, any notes you take must contain no identifying details, and EMCC USA never stores case material.
How We Stay in Touch
-
Essential messages such as membership renewals, event logistics, governance notices and policy updates are sent to members as part of membership.
-
Newsletters and promotional emails go only to members and to people who have opted in. Every message includes a working unsubscribe link, and we honor opt-outs within 10 business days.
-
Text messages are sent only if you have given express consent.
-
Photographs and videos of identifiable people are used in marketing only with consent, or after clear notice at a public event with a genuine chance to opt out.
-
We never sell, rent or trade our mailing lists, and we never allow sponsors to email you directly.
Sensitive Information
Some information deserves extra protection: health and disability information; racial or ethnic origin; national origin; religious beliefs; sexual orientation, sex life and gender identity; citizenship or immigration status; government identification numbers; financial account credentials; precise location; background-check results; and information about children.
We collect sensitive information only when there is a clear and necessary purpose, and with your explicit consent unless the law requires otherwise. Diversity, equity and inclusion surveys are always voluntary, always include a "prefer not to say" option, and are reported only in aggregate, never for groups smaller than five. Accommodation requests are used solely to provide the accommodation. We do not collect Social Security numbers except where a tax form legally requires it. Sensitive information is never used for marketing or profiling.
When We Share Information
We share personal data only for a clear purpose, and only the minimum needed:
-
EMCC Global and other EMCC country organizations, for membership administration, accreditation, international events and joint programs, under a data-sharing arrangement.
-
Trusted service providers that power our website, email, video meetings, payments, storage, surveys and event ticketing. They act only on our instructions, under written terms, after a security review.
-
Sponsors and partners, only when you actively opt in, for example by ticking a box to receive a partner's offer.
-
Auditors, accountants and insurers, who are bound by professional confidentiality.
-
Authorities, only where required by law or a court order, or to protect someone's safety.
-
A successor organization, in the event of a merger, restructuring or dissolution, with notice to members and the same protections continuing.
How We Protect Your Information
Our safeguards are proportionate to a volunteer-led association and are reviewed every year. Every system sits in an organization-owned account with at least two administrators, so nothing depends on one person's login. Multi-factor authentication is required on our email, storage, website, social media, payment and membership systems. Credentials are held in an organizational password manager and changed whenever someone with access leaves. Access is role-based and reviewed quarterly. Card payments are handled only by PCI-DSS compliant processors, and critical data is backed up securely. Before we adopt any new tool that will hold personal data, we check that it encrypts data, supports strong access controls, and allows data to be exported and deleted.
Artificial Intelligence
We explore AI thoughtfully, and we set firm limits. Personal data is processed only in approved AI tools, under organizational accounts whose terms prevent our data from being used to train public models. AI note-takers join a meeting only when everyone has been told in advance and no one objects, and they are never used in communities of practice, supervision spaces, ethics matters or executive sessions. AI may support, but never replace, human judgment in selecting volunteers, awarding recognition, handling complaints or making any decision that significantly affects you. Where AI materially shapes content we send you, or a service you interact with, we will say so.
How Long We Keep Information
Keeping data "just in case" adds risk without adding value. When a retention period ends, we securely delete or anonymize the information across every copy. Our main retention periods are:
-
Current member records: for the duration of membership.
-
Lapsed member records: 2 years after lapse (we may keep your email address on a suppression list so your opt-out is honored).
-
CPD attendance and certificates: 5 years, to support accreditation renewal.
-
Financial records: 7 years after the end of the fiscal year.
-
Event registrations: 2 years after the event.
-
Accessibility and dietary requests: 30 days after the event.
-
Meeting chat logs and automatic transcripts: 30 days.
-
Public webinar recordings: 2 years, or longer with presenter consent.
-
Testimonials, photos and consent forms: while in use plus 2 years, or sooner if consent is withdrawn.
-
Identifiable survey responses: 12 months, then aggregated or anonymized.
-
Board election ballots: 90 days after results are certified, unless challenged.
-
Volunteer and Board applications (unsuccessful): 12 months after the decision.
-
Volunteer service records and signed agreements: 7 years after service ends.
-
Ethics concerns and complaints: 7 years after closure.
-
Website analytics: 14 months.
Retention is paused only when information is relevant to a legal claim, investigation or open complaint. Anonymized statistics may be kept indefinitely, and Board minutes, resolutions and policies are kept permanently as part of our governance record.
Your Rights
Whether you are a member, volunteer, speaker or visitor, and wherever you live, you can ask us to:
-
Tell you what we hold about you, give you a copy, and explain how it is used and shared.
-
Correct information that is inaccurate or incomplete.
-
Delete your data, unless we must keep it for legal, financial or governance reasons, in which case we will explain why.
-
Give you your data in a commonly used electronic format.
-
Stop marketing communications and profiling.
-
Withdraw your consent at any time for anything based on consent, such as your directory listing, your photograph or your testimonial.
-
Object or restrict processing, if you are in the EU or UK.
-
Review our response through a different Officer, and you may also complain to a regulator.
How to make a request. Email info@emccusa.org with "Privacy request" in the subject line, or speak to any Board member, who will pass your request to our Privacy Lead within two business days. We will acknowledge it within 10 business days, verify your identity in a simple, proportionate way, and respond in full within 45 days, or within one month if you are in the EU or UK. Requests are free, and no one is ever treated less favorably for exercising their rights.
If Something Goes Wrong
If personal data is ever put at risk, for example through an email sent to the wrong list, a lost device or a compromised account, we act immediately to contain it, assess within 72 hours who and what is affected, and fix the cause. Where the law requires, we notify affected individuals, state regulators, EMCC Global and, for EU or UK data, the relevant supervisory authority within the required timeframes. Significant incidents are reported to our Board of Directors.
Children
Our services are designed for adults. We do not knowingly collect personal data from children under 13. If you believe a child has shared information with us, please contact us and we will delete it promptly.
The Laws and Standards We Follow
We comply with applicable United States law, including the CAN-SPAM Act, the Telephone Consumer Protection Act, the Children's Online Privacy Protection Act, the Fair Credit Reporting Act, and state data breach and data security laws. We also adopt the core standards of state consumer privacy laws, such as those of Colorado, Delaware, Maryland, Minnesota, New Jersey and Oregon, as good practice. Where we handle the data of people in the European Union or United Kingdom, or exchange data with EMCC Global, we apply the standards of the GDPR. Above all, we hold ourselves to the confidentiality commitments of the EMCC Global Code of Ethics.
Keeping This Policy Current
Our Board of Directors oversees this policy through its Governance Committee, which reviews it every year and sooner if the law changes or we launch a new kind of program or partnership. A Privacy Lead appointed by the Board is your day-to-day point of contact. When we make meaningful changes, we will update the date at the top of this page and, where appropriate, let members and volunteers know directly.
Contact Us
Questions, concerns or requests about your personal data are always welcome.
Privacy Lead, EMCC USA, Inc.
Email: info@emccusa.org
Website: www.emccusa.org
If you are in the European Union, you may also contact EMCC Global at privacy@emccglobal.org or your local data protection authority. If you are in the United States, you may also contact the Attorney General of your state.

