CHEST Foundation reserves the right to make changes to this Policy at any time; in such case, CHEST Foundation will post a notice that this Policy has been modified by revising the “Last Reviewed” date at the bottom of this Policy.
CHEST Foundation does not knowingly collect or use any personal information from any person under the age of 18. If you are under the age of 18, please do not access or use CHEST Foundation websites. If CHEST Foundation becomes aware that our systems have collected any personal information from persons under the age of 18, CHEST Foundation will delete that data from our systems.
What information does CHEST Foundation collect?
CHEST Foundation collects two types of information: (1) non-personally identifiable information for everyone who visits its websites; and (2) personally identifiable information for donors, registered website users, and anyone who purchases products, events, and services, or requests information.
Non-personally identifiable information
Users who do not desire the functionality offered by cookies may disable cookie functionality in their browsers or through settings on their devices; however, users who do so may not be able to use some features of CHEST Foundation websites. For example, a registered user must have cookies enabled in order to access the registered-user sections of CHEST Foundation websites.
CHEST Foundation may share aggregated or anonymous information that cannot identify you with third parties.
For system administration and troubleshooting, CHEST Foundation also logs the originating internet protocol (IP) address, the browser and operating system used, and information about individual use, such as time and date of visits, duration of sessions, and other similar usage or system data.
Personally, identifiable information
In addition to the non-personally identifiable information listed above, CHEST Foundation records the user’s name and ID number for all registered users (ie, users who have logged into a password-protected area of a CHEST Foundation website). In the course of using CHEST Foundation websites, a user may be asked to provide personally identifiable information (eg, name, address, zip code, email address, telephone number, fax number, credit card payment information, etc) in order to make a donation or register for an event, participate in a CHEST Foundation activity, subscribe to a publication, request information, or otherwise interact with CHEST Foundation. In addition, users may be asked to update their contact information.
CHEST Foundation also collects email addresses voluntarily provided via donation forms, event registrations, donor surveys, downloads of certain materials, email communication sign-ups, and comments made in discussion threads on CHEST Foundation websites.
Important note for CHEST Foundation donors and constituents: CHEST Foundation also maintains a CRM database. The information in this database (eg, National Provider Identifier [NPI] numbers; demographic information, such as education and specialty) is drawn from donation payment forms, applications, product orders, continuing medical education (CME) reporting, public databases, donor surveys, and other correspondence between CHEST Foundation and its donors and constituents.
CHEST Foundation does not disclose the credit card account information or activity of its donors. When donors pay using credit cards, CHEST Foundation submits this information encrypted to obtain payment from the appropriate clearing house. Credit card numbers are never stored in CHEST Foundation databases. CHEST Foundation auto-pay via credit card uses token technology, and credit card numbers are not stored.
How does CHEST Foundation use information collected?
CHEST Foundation uses the information it collects to better serve donors, constituents, and visitors to CHEST Foundation websites in the following ways:
CHEST Foundation services and products
CHEST Foundation uses information collected to improve its web content, to respond to visitor needs and preferences, and to develop new products and services. For example, CHEST Foundation will combine non-personally identifiable information (eg, data stored in cookies, user’s IP address) with personally identifiable information (eg, user’s name, ID, email address) to offer content that may be of specific interest to the user.
Disclosure to third parties
If CHEST Foundation discloses personally identifiable information to contracted third parties, CHEST Foundation requires that these providers agree to keep confidential all such information and to use it only for the purposes designated by CHEST Foundation. CHEST Foundation will only disclose personally identifiable information to contracted third parties that provide sufficient guarantees in respect of the technical and organizational security measures governing the processing to be carried out and that demonstrate a commitment to compliance with those measures. The information used by any contracted third party will be preapproved by CHEST Foundation.
CHEST Foundation may make personally identifiable information available to contracted third parties in connection with CHEST Foundation programs and events or for other purposes that might be of interest to you as a CHEST Foundation constituent.
CHEST Foundation may make personally identifiable information available to contracted third parties that offer their own products or services deemed of potential interest to donors and constituents of CHEST Foundation. For example:
- Mailing purposes to CHEST Foundation donors and members about the Foundation
- Mailing invitation to CHEST Foundation donor-only event
- Contractors of CHEST Foundation who work on behalf of the Foundation for donor engagement
CHEST Foundation may make personally identifiable information available to our partners and sponsors when you request access to their offerings, benefits, communications, or content.
CHEST Foundation may make personally identifiable information available to our third-party contractors and payment processors who perform services for us in connection with the websites, or to complete or confirm a transaction or series of transactions that you conduct with us.
CHEST Foundation may make personally identifiable information available to service providers or suppliers when the information enables that party to perform business, professional, or technical support for us.
Links to other websites and social media
CHEST Foundation websites include the ability to link to social media channels and social channel websites. As a result, CHEST Foundation receives information about users when they choose to post or otherwise share information about CHEST Foundation on these social platforms. CHEST Foundation may leverage that information in various ways, including enhance user experience with CHEST Foundation websites or to communicate with users about CHEST Foundation offerings and activities.
CHEST Foundation may use outside marketing companies to place and monitor advertisements or links on CHEST Foundation websites and on other websites. These companies may use non-personally identifiable information (eg, links clicked during a visit, browser type, time and date, subject of advertisements clicked or scrolled over) and personally identifiable information (eg, NPI number) during user visits to CHEST Foundation websites and other websites in order to provide advertisements about products and services likely to be of interest to users.
Protection of your data
CHEST Foundation has significant protections in place to ensure the privacy of your personal information. The CHEST Foundation donor database is implemented and designed to protect personal information. Individuals are asked to provide only the minimum information necessary when making a donation or registering for an event. Multiple layers of physical, administrative, and electronic protections are in place to protect all information from unauthorized use, access, or malicious activity. Personnel procedures and processes have been developed with an emphasis on privacy.
The CHEST Foundation system is audited by independent third parties. Effective donor privacy and security are top priorities as part of our overall mission to provide our services to constituents.
Once someone voluntarily provides an email address, CHEST Foundation uses that information to email that person with questions, transaction follow-up, promotions, and communications. CHEST Foundation collects data to track the effectiveness of emails, which enables CHEST Foundation to better serve its audiences.
As noted earlier, there are instances in which CHEST Foundation will share email addresses of its donors or constituents with outside service providers who are under an obligation of confidentiality and restricted use. Release of email addresses is governed under strict contractual licensing guidelines and can only be used for specific purposes.
All CHEST Foundation marketing emails and those of third parties include a link for unsubscribing. CHEST Foundation will apply any unsubscribe request as quickly as possible. However, because there may be email campaigns already in progress, some messages may still be sent until the opt-out request can be fully processed. Once the opt-out is processed by CHEST Foundation and all of its partners, that email address will no longer receive marketing or promotional emails from CHEST Foundation. Email addresses are still used in support of specific transactions (eg, membership renewal notice, order confirmation).
Donors, constituents, and registered website users may choose not to have information released from CHEST Foundation. This is done by requesting that CHEST Foundation designate a record as “no contact.” The “no contact” status of a record ensures that information will not be licensed for purposes of marketing via email, mail, or phone. To opt-out via “no contact” designation, contact the CHEST Foundation Help Team at 800/343-2227 or email firstname.lastname@example.org.
Market research opt-out
From time-to-time, CHEST Foundation users may be invited to participate in surveys, focus groups, and/or research panels. Participant contact information, including name, phone number, address, and email address, may be used by CHEST Foundation to carry out the survey or communicate about the survey, focus groups, and/or research panels and to provide incentives for participation. Participation in any type of research is completely voluntary. If you prefer not to be contacted to participate in future surveys, focus groups, panels, etc, call the CHEST Foundation Help Team at 800/343-2227 or email HelpTeam@CHEST Foundationnet.org.
CHEST Foundation has agreements with other organizations that offer products and services through CHEST Foundation websites or third-party agreements. When the user interacts with these organizations on their organizations’ websites, whether as a result of following links from a CHEST Foundation website, within a CHEST Foundation email, or otherwise, different rules and privacy policies may apply. Since CHEST Foundation does not control the collection of information or the use of information collected via these other organization websites, CHEST Foundation is not responsible for their privacy practices, security, or content.
Visiting or accessing CHEST Foundation websites from outside the United States
By visiting or accessing CHEST Foundation’s websites, becoming a donor, or otherwise voluntarily submitting information to CHEST Foundation from outside of the United States, information that CHEST Foundation collects will be transferred to servers inside the United States, which may involve the transfer of information out of countries located in the European Economic Area. By allowing CHEST Foundation to collect information about you, you consent to such transfer and processing of your data.
European resident privacy rights
In regards to the EU General Data Protection Regulation 2016/679 (“GDPR”), the “data controller” is the CHEST Foundation, registered in Illinois, USA, with a registered address at 2595 Patriot Blvd, Glenview, IL 60026, USA.
For residents of the European Union and European Economic Area (the “EU”): You have the right to ask us not to process your personal information for marketing purposes. We will usually inform you (before collecting your personal information) if we intend to use your personal information for such purposes or if we intend to disclose your information to any third party for such purposes. You can exercise your right to prevent such processing by checking certain boxes on the forms we use to collect your personal information. You can also exercise the right by contacting us by one of the methods in Contact Us section.
Under GDPR, in certain circumstances, you have the right to (a) request access to any personal information we hold about you and related information; (b) obtain without undue delay the rectification of any inaccurate personal information,; (c) request that your personal information is deleted provided the personal information is not required by CHEST Foundation for compliance with a legal obligation under European or Member State law or for the establishment, exercise, or defense of a legal claim; (d) prevent or restrict processing of your personal information, except to the extent processing is required for the establishment, exercise, or defense of legal claims; and (e) request transfer of your personal information directly to a third party where this is technically feasible.