Data Privacy and Personal Information Protection Policy
Effective Date
2/20/2025
Approved By
Board of Directors, KMT2C Foundation
Next Review Date
2/20/2027
1. Purpose
The purpose of this Data Privacy and Personal Information Protection Policy (“Policy”) is to establish principles and requirements governing the collection, use, retention, protection, and deletion of personal information by KMT2C Foundation (“the Foundation”). This Policy reflects the Foundation’s commitment to ethical data practices and compliance with applicable privacy laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
2. Scope
This Policy applies to:
This Policy covers personal information collected through websites, forms, email communications, and other engagement channels operated by the Foundation.
3. Definitions
4. Data Minimization and Categories of Information Collected
The Foundation adheres to principles of data minimization and purpose limitation.
4.1 Categories of Personal Information Collected
The Foundation collects only the following categories of personal information:
The Foundation does not collect genetic data, health data, biometric data, financial information, precise geolocation data, or government-issued identifiers through general communications or public-facing forms.
5. Purpose of Processing
Personal information is processed solely for purposes aligned with the Foundation’s non-profit mission, including:
The Foundation does not sell or share personal information for commercial purposes or targeted advertising.
6. Legal Basis for Processing
6.1 GDPR Lawful Bases
Where GDPR applies, the Foundation processes personal data based on one or more of the following lawful bases:
7. Data Sharing and Disclosure
The Foundation does not sell or share personal information within the meaning of the CCPA/CPRA.
Personal information may be disclosed only:
8. Data Retention and Deletion
Personal information shall be retained only for as long as reasonably necessary to fulfill the purposes outlined in this Policy or as required by law.
Deletion Requests
Requests for deletion must be submitted in writing to:
9. Individual Privacy Rights
9.1 GDPR Rights
Where applicable, individuals have the right to:
9.2 CCPA/CPRA Rights (California Residents)
California residents have the right to:
The Foundation does not collect sensitive personal information as defined by the CPRA.
10. Information Security
The Foundation shall implement reasonable administrative, technical, and organizational safeguards designed to protect personal information from unauthorized access, disclosure, alteration, or destruction.
11. Children’s Privacy
The Foundation does not knowingly collect personal information from children under the age of 13, or under 16 where required by applicable law. Any such information identified will be promptly deleted.
12. International Data Transfers
Where personal information is transferred across national borders, the Foundation will take reasonable steps to ensure appropriate safeguards are in place in accordance with applicable data protection laws.
13. Governance and Oversight
The Board of Directors has oversight responsibility for this Policy. Management is responsible for implementation, training, and compliance.
This Policy shall be reviewed periodically and updated as necessary to reflect legal, regulatory, or operational changes.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.