Revised June 11, 2021 (Added CCPA Compliance section)

Introduction

When you entrust your personal information to a web site, you expect the operators of that site to demonstrate that they have earned your trust. Maintaining your privacy and the security of your personal information is our highest priority.

This Privacy Policy explains how Gembrook Systems, LLC (“Gembrook”) d/b/a ClubExpress (“ClubExpress”), an Illinois Limited Liability Company, collects, stores, uses, and discloses information about you. Our customer is Association of Seniors of Indian Origin, which has signed up and paid for the ClubExpress service.

We offer our services to membership-based organizations (clubs and associations) to help them run their operations, including their website, events, finances, and communications. These operations include the collection, storage, and processing of data on current and expired members of each organization, as well as non-members who add themselves to the organization’s database by completing an Add-Me form, registering for an event, making a donation, volunteering, or other means, including being added manually by an administrator of the organization (for example, if you’re a member of the Press or a local government or public safety official).

Association of Seniors of Indian Origin and ClubExpress are committed to meeting and exceeding all relevant international, federal, and state laws and industry guidelines regarding your personal information and how it is protected.

Please note that privacy laws differ widely between countries and, within countries, between states and smaller jurisdictions. Because a club or association using ClubExpress may be located anywhere in the world and may have members or non-members from anywhere, and because their website may be accessed from anywhere in the world, ClubExpress will follow the strictest possible rules. This Privacy Policy has been updated in accordance with the requirements of the European Union’s General Data Protection Regulations (“GDPR”) and similar UK regulations.

In the context of the GDPR and similar UK regulations, Association of Seniors of Indian Origin shall be considered to be the Data Controller and Gembrook shall be considered to be the Data Processor.

Gembrook is based in the United States and our servers are hosted in the US. No matter where you are located, you consent to the transferring to, and processing of, your information in the US.

This Privacy Policy applies only to this website and the functionality and services provided by ClubExpress. This website may contain links to other websites not controlled by Association of Seniors of Indian Origin or by Gembrook, and the policies and procedures described herein do not apply to these other websites.

Note also that privacy laws and regulations are continually evolving and this Privacy Policy may be modified at any time to account for new and stricter provisions. Your continued membership in Association of Seniors of Indian Origin and/or your continued use of this website, whether as a member or non-member, confirms your agreement to abide by the provisions of the current Privacy Policy. As described below, you also have the right and ability at any time to resign from the organization and to have your personal information removed from its databases.

What We Collect and How We Use It

This site stores personal information about you, including your name, contact information (addresses, phone numbers, email address, work information, etc.), demographic data (date of birth, gender, etc.), and, for members only, a user name and password to allow you to log in and access member-only content. Depending on which functions have been enabled by Association of Seniors of Indian Origin, it may also collect, store, and display other information, including but not limited to:

  • Your original membership sign-up and subsequent renewals
  • Your event registrations
  • Your donations
  • Your online payments and payment history
  • Biographic and other information specifically to share with other members
  • Business information specifically to share with the public
  • Links to your social networking accounts for the purposes of sharing club or association information with others in your networks
  • Information posted in online discussion forums and surveys
  • Volunteering and committee assignments
  • Downloading of documents and photos from the website
  • Uploading of documents and photos to the website
  • Completing custom forms for specific club or association purposes
  • Posting classified ads or available jobs
  • Maintaining your certifications and continuing education training
  • Purchasing products through an E-commerce storefront
  • Registering for interest groups
  • Whether you have opened emails sent to you from the platform

This information is provided by you as you interact with the website and its various screens and dialogs. Some information is required by your club or association in order to maintain accurate and complete records, for legal protections, or to allow the organization to provide its services to you. Other information is optional or dependent on your participation in specific activities or programs.

Association of Seniors of Indian Origin uses this information to run the club or association, to provide services for members, to maintain accurate and complete financial records, to fulfill its legal obligations in accordance with laws pertaining to non-profits, to promote the club or association in the general community, to strengthen and grow the organization, to communicate with you about news and activities, and to advocate for issues that are important to members.

Within this website, only authorized administrators appointed by Association of Seniors of Indian Origin have access to personal information on members. ClubExpress cannot control who these administrators are or what they do with this information. However, our agreement with Association of Seniors of Indian Origin strongly discourages organizations from selling or trading personal data to third parties, but if they do so, you always have the ability to opt-out from such lists.

ClubExpress may collect and access personal information when you contact our Customer Support team by email or phone to get help with using the features of this website. ClubExpress does not otherwise collect personal information for its own purposes. All personal information is collected on behalf of the clubs or associations that have signed up to use the ClubExpress platform.

This website also collects information when you log in and as you navigate around the site, using standard Internet technologies (such as IP addresses, log files, access dates and times, language and other formats, session cookies, pixel tags, other tracking technologies, and reading your computer or mobile device type, operating system, browser version, etc.) We use this information for the following purposes:

  • To provide and maintain our service
  • To help us improve our products and services
  • To manage the performance of our platform
  • To perform accounting and billing activities

For the following security and data protection purposes:

  • To detect, investigate and prevent fraudulent use of the platform
  • To detect, investigate and prevent abuse and other illegal activities
  • To detect, investigate and block security breaches
  • To protect the rights, intellectual and physical property of Gembrook
  • To protect the rights and intellectual property of others
  • To provide you with a safe online environment
  • To manage and resolve legal claims
  • To protect and enforce our legal rights

Your club or association may enable a ClubExpress module that provides discussion forums. Please remember that any information disclosed in these forums may become public. You should exercise caution regarding personal information when you write messages in a public discussion forum.

Your club or association may enable a ClubExpress module that allows a third party, from an external website, to verify your membership in Association of Seniors of Indian Origin using a special interface and by providing credentials that you have supplied to that party. Your use of their website and the provision of these credentials is governed by their Privacy Policy. In providing them with your credentials for this website, you have consented to allow them to use this data to verify your membership status.

Using the ClubExpress Mobile App

Your organization may also enable a ClubExpress mobile app that provides special functions for members using mobile devices such as smartphones and tablets, running on both iOS and Android. When you download the mobile app for your club and device, we may request permission to use various features on your mobile device:

  • Calendar – We request access to your calendar so that we can add/edit events on your device. Calendar events are only added when you touch the “add event” icon. We never automatically add or edit events without user interaction.
  • Location – We request permission to access your device location for the “Meets” functionality. Your location is stored on our servers when you tap “Update my position” and displayed to other users for a set time before it is hidden automatically. We do not retain this data or share it with third parties.
  • Microphone – We request access to your microphone only for a general media permission request; no audio is stored or recorded.
  • Phone – When you tap a phone number, your device’s dialer is preloaded with the number. We do not store or retain phone logs or numbers.
  • Contact Logs – We do not request or keep any contact log data.
  • Notifications – Permissions are requested to send you notifications when a new message is posted to a chat channel.
  • Storage – We request access to device storage to save or display files only when you initiate a download; files are not automatically sent to your device.
  • Carrier/Network Information – We do not share or keep any carrier or network information.
  • Camera – Access to your device camera is requested only when adding a photo to a chat message.
  • Cookies – Session cookies are used to keep you logged in while using the mobile app and disappear when you log out. We do not store persistent session or financial data in cookies.

What is our Legal Basis for Collecting and Processing this Information

Association of Seniors of Indian Origin is the controller of this data. It collects and stores your personal information in order to manage your membership and/or your participation in the organization’s activities. Clear indications of your intent include:

  • Paying a membership fee to join or renew
  • Registering for an event
  • Making a donation
  • Purchasing a product from the organization’s storefront
  • Requesting to be added to the mailing list
  • Logging in as a paid member to participate in activities

You also have the right to cancel this relationship at any time and have your data removed from the website and its repositories, subject to record-keeping requirements.

ClubExpress acts as the Data Processor for this data, under a legal agreement with Association of Seniors of Indian Origin to maintain and process the data securely.

Sharing of Information

Information about you will only be shared based on the provisions of this Privacy Policy.

The ClubExpress platform is designed to allow clubs and associations to run their operations online, including public promotion. An organization may choose to make certain user information (typically your name and, in some cases, contact details) visible on its public website. This information may include:

  • Membership in a committee, interest group, or chapter
  • Event registration
  • Volunteering activity registration
  • Uploaded photos
  • Participation in a Member or Business Directory

Members who log in may see more detailed information about other members, depending on the website’s configuration. We recommend reviewing your organization’s sharing settings if you have concerns.

Organizations can also define roles such as “Administrators” (with full data access) and “Coordinators” (with limited rights). Additionally, data may be shared with vendors assisting in operations, but only to the extent necessary and under strict contractual obligations.

What ClubExpress Will Not Do

Neither ClubExpress nor club officers have direct access to your password or credit card information. This data is encrypted using state-of-the-art technologies and cannot be directly accessed. In the event of a forgotten password, a reset can be initiated by Association of Seniors of Indian Origin or ClubExpress.

You can opt not to store your credit card information. If you do, you will need to re-enter it for each transaction. Once a card is authorized, only the first 4 and last 4 digits are retained per PCI regulations.

ClubExpress will not contact you about new features or products unless you are an official club contact, and we do not send unsolicited email.

Your name and contact information will not be sold or shared with third parties for marketing or revenue purposes, except as necessary (e.g., for processing a credit card transaction).

Aggregate statistics may be generated, but these will not include individually identifiable data.

Note that data from different organizations remains separate, even if you belong to more than one.

Other Things We Do To Protect You

ClubExpress’s servers are hosted in a secure data center behind a firewall with physical access limited to authorized personnel. Service packs and security updates are promptly installed and data is backed up nightly. Confidential data is transmitted using SSL/TLS encryption, and our SSL Certificates are issued by Comodo.

While we employ various technical and operational measures to protect your data, no method of electronic storage or transfer is 100% secure. Email communications may not be secure, so please exercise caution with sensitive information.

Data Retention Policy

Association of Seniors of Indian Origin maintains records of its operations, including memberships, events, and fundraising. ClubExpress will retain your information as long as you are an active or expired member or have participated as a non-member, for reasons including:

  • Enabling use of the ClubExpress platform
  • Allowing you to review and update your information
  • Opting out of communications or requesting deletion
  • Respecting your communication preferences
  • Maintaining accurate records and financial data
  • Understanding platform usage and preventing abuse
  • Complying with legal and financial requirements

Note that data may persist in exported formats for backup or analysis, and deletion or correction requests will be forwarded to the organization for exported data.

Your Rights and Options

If you are a member, you can log in to view and update your personal data, transaction history, event registrations, and more. You can also change your privacy settings (e.g., opting out of announcements or third-party lists).

Non-members can view and update any personal data stored in the platform and adjust their privacy settings via a request submitted through the Contact Us page.

Both members and non-members have the right to request deletion of their personal data. For members, this effectively resigns your membership. Requests may be submitted through your Profile screen, the email Opt-Out screen, or via email to the designated Data Privacy Officer (DPO).

You may also object to processing, request a restriction on processing, or withdraw consent for future processing. Such requests will be treated as deletion requests and cannot be applied retroactively.

Requests will be logged and processed within 30 days, with data flagged for deletion within 7 days if accepted. Data with a compelling business reason (such as payment records) will be anonymized instead of deleted.

You also have the right to file a complaint with your local Data Protection Authority (“DPA”).

Privacy Shield

ClubExpress complies with the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks as established by the U.S. Department of Commerce. ClubExpress certifies that it adheres to the Privacy Shield Principles. In the event of any conflict between this Privacy Policy and the Privacy Shield Principles, the latter will govern. For more information and certification details, please visit PrivacyShield.gov.

ClubExpress commits to resolving complaints about our collection or use of your personal information under the Privacy Shield. Binding arbitration may be invoked if other dispute resolution methods are exhausted, and onward transfers of personal data adhere to Privacy Shield requirements.

The Federal Trade Commission (FTC) has jurisdiction over ClubExpress’s compliance with Privacy Shield.

Privacy Provisions for Customers and Members located in the UK

Following Brexit, UK individuals and subjects located elsewhere are no longer covered by the EU’s GDPR and Privacy Shield. However, Association of Seniors of Indian Origin and ClubExpress warrant that personal data will continue to be processed in accordance with applicable data protection laws, with security measures in place to prevent unauthorized disclosure or loss.

If sub-processors (such as merchant processors) are involved, they too will be bound by these provisions. In the event of termination, ClubExpress will maintain confidentiality and cease active processing while retaining necessary security measures. UK subjects with complaints should contact ClubExpress using the information provided below.

Compliance with CA Consumer Privacy Act (CCPA)

The CCPA provides California residents with specific rights regarding their personal information. Within the context of the CCPA, ClubExpress acts as a “Service Provider” processing personal data on behalf of Association of Seniors of Indian Origin. We do not sell, trade, or share your personal data with third parties (except as needed for business operations, such as credit card processing) and do not claim ownership over your data.

ClubExpress and Association of Seniors of Indian Origin may collect the following types of Personal Information:

  • Your name, nickname, postal address, phone numbers, email address, website, spouse and family information, work information, and emergency contact information.
  • Membership-specific information such as qualifications, education, interests, and affiliations.
  • Geolocation data.
  • Participation in club activities, including event registrations, volunteering, downloads, page views, chat and forum participation, emails, texts, certifications, and storefront purchases.
  • Activity on the Association of Seniors of Indian Origin website.

Trusted third parties may be engaged for functions such as hosting, database management, credit card processing, and direct marketing, with strict obligations to maintain data privacy and security.

You have the right to see what Personal Information has been collected about you and how it is used. Members can log in to view and update their Profile, while non-members may submit a request via the Contact Us page. Verification of identity may be required, and information will be provided within 45 days.

You also have the right to know:

  • The categories of personal information collected
  • The sources of this information
  • The business purpose for its collection
  • Whether it has been shared with any third parties

You have the right to request deletion of your personal information (see “Your Rights and Options” above) and the right of non-discrimination in the exercise of your CCPA rights.

Other Provisions

This website is not intended for unsupervised access by children under the age of 13. We do not knowingly collect information from children, and we encourage parents to discuss safe internet practices with their children.

If you have questions, comments, or concerns regarding this Privacy Policy, please contact our Data Protection Officer at:

ClubExpress
1213 W. Morehead Street, Suite 500
Charlotte, NC 28208
Phone: 1-866-HLP-CLUB (457-2582)
Email: privacy@clubexpress.com