CANADIAN FRIENDS OF SUFI ARTS, CULTURE AND KNOWLEDGE
PRIVACY POLICY
Revised and Approved April 21, 2023
A. Introduction
About Canadian Friends of Sufi Arts, Culture and Knowledge
Canadian Friends of Sufi Arts, Culture and Knowledge (“CFSACK”) (also “we”, “our” or “us”) is a Canadian not for profit corporation dedicated to advancing education by increasing the public's knowledge and appreciation of Sufi history, art and culture through museum, art and interactive exhibits, lectures, conferences, performances, classes, seminars, workshops and events for the public.
Our Commitment
CFSACK is committed to protecting the privacy of our employees, donors, participants and other stakeholders. CFSACK is accountable for and transparent in how it treats your Personal Information. CFSACK does not sell, rent or trade our mailing lists or other Personal Information.
​
What is Personal Information?
Personal Information is information about an identifiable individual, including any information about you or that can be used to identify you. For the purposes of this Privacy Policy, Personal Information means any information provided to or collected by CFSACK about an identifiable individual regardless of how the information is collected.
However, Personal Information does not include business contact information, including name, job title or position, work address, work e-mail addresses, work telephone and work facsimile numbers that are collected, used or disclosed solely for the purpose of communicating with a person in relation to their employment or profession.
Scope of this Privacy Policy
This Privacy Policy applies to any Personal Information provided to or collected by CFSACK through its website www.cfsack.org (the “Website”), by email, facsimile, postal mail, hand delivered, verbally or any other means.
Purpose of this Privacy Policy
The purpose of this Privacy Policy is to give you information about what Personal Information CFSACK collects from you, why it collects it and how it uses it, as well as what happens if you choose not to disclose certain Personal Information to CFSACK. We are committed to protecting personal information in accordance with British Columbia’s Personal Information Protection Act (“PIPA”). CFSACK will only collect, use and disclose your personal information in accordance with this Privacy Policy.
Please read this document carefully.
​
B. How CFSACK Collects Personal Information
CFSACK may collect Personal Information in different ways in the course of our normal operations and providing our services, including:
-
Direct interactions – You may voluntarily provide us with Personal Information by making a donation to us; registering to attend a CFSACK event or participate in a CFSACK program; purchasing items and arranging for delivery; requesting information to be sent to you; agreeing to receive emails from us; subscribing for our publications; filling out forms or signing documents; applying for a job posting; paying accounts or other amounts to us; posting comments on the Website; or communicating with us face to face, over the telephone, by mail, by email, by text, through social media or through other means.
-
Automated interactions – when you use the Website we may automatically collect technical data about your equipment and browsing history using cookies and similar technologies (See E below for more information).
-
Third-party interactions – if you make a donation directly to CFSACK by way of Interac e-transfer, we will only collect the Personal Information that you choose to provide in the comments box. If you make a donation to CFSACK through the donorbox webform, we will receive only the Personal Information that you voluntarily provide to us. We may receive information about you from other third parties such as the Museum, our international colleagues such as American Friends of Sufi Arts, Culture and Knowledge, information or service providers, publicly available records or other professionals in connection with the delivery of our membership, benefits and other services.
C. What Personal Information is Collected by CFSACK
The Personal Information it may collect could include:
-
Personal identifiers such as your name, date of birth and gender;
-
Contact information such as your mailing address, telephone number and email address;
-
Employee records, including employment history and background checks for employees;
-
Website account information such as your log-in, user name, password information and other security information;
-
Event and program information;
-
Images, including photographs and videos;
-
Your Website profile including all photos, posts, videos and other content;
-
Information about your device such as your IP address, location or provider and your usage information and browsing history (see below for more information);
-
Information about your interactions with our content on third-party sites or platforms, such as Facebook, Instagram, LinkedIn and Twitter;
-
Communications such as letters, emails and digital communications that we send to you or that you send to us;
-
Personal Information you give us that we did not request (such as Personal Information you voluntarily put into an email to us or in a comments box on the Website).
D. Our Guiding Principles
​
1. Accountability:
CFSACK is responsible for Personal Information under our control. If you have any questions about this Privacy Policy, including how to exercise your legal rights, or if you would like specific information about how we manage Personal Information, please contact us at:
-
Canadian Friends of Sufi Arts, Culture and Knowledge - info@cfsack.org
2. Identifying Purposes:
CFSACK identifies the purposes for which Personal Information is collected at or before the time the information is collected.
We use the Personal Information we collect to manage our operations and for various purposes associated with the programs and services we provide. We collect, use, and disclose Personal Information only for purposes that a reasonable person would consider appropriate in the circumstances.
The main purposes for which we generally use Personal Information are:
-
To manage, oversee and administer our operations, programs, services and activities;
-
For accounting purposes
-
To maintain and manage relationships and provide customer service;
-
To answer questions and to respond to inquiries;
-
To track communications with volunteers, donors and other stakeholders;
-
To organize, promote and provide programs, workshops and other events;
-
To raise awareness of our programs and services;
-
To monitor the quality of our programs and services and the needs of our stakeholders so that we can improve our programs and services;
-
To provide, administer and protect the Website including troubleshooting, data analysis, maintenance and network security;
-
To deliver relevant Website content and to provide associated functionality such as technical support and password reminders;
-
To identify and authenticate you in our information system and network;
-
To send you informational or promotional communications (in compliance with Canada's Anti-Spam Legislation);
-
To record whether you have registered for events or subscribed to or unsubscribed from any of our mailing lists or publications;
-
To disclose or share your Personal Information when required to comply with legal or regulatory requirements;
-
To prevent and detect fraud and other crimes;
-
To protect our rights, property or safety or that of our employees, contractors, consultants or any other person;
-
For other purposes that we have told you about and for which you have given us your consent;
-
To fulfill other purposes permitted or required by law.
CFSACK does not collect more Personal Information than we need to achieve these purposes.
3. Consent:
We only collect, use and disclose Personal Information with your knowledge and consent. Your consent may be expressed orally, electronically or in writing or it may be implied. CFSACK is committed to obtaining meaningful consent, using clear explanations in plain language, to make sure that our consent processes are understandable and user friendly.
You have the right at any time to withdraw or cancel your consent to the collection, use or disclosure of your Personal Information by contacting CFSACK at info@cfsack.org. Withdrawals of consent only take effect from the date of cancellation. They cannot be retroactive. We will let you know if your withdrawal could have any consequences, such as CFSACK being unable to provide you with goods or services.
4. Collecting Personal Information:
CFSACK will only collect personal information for the purposes identified in this Privacy Policy. If we want to collect information for a different purpose, we will tell you what that purpose is in writing and obtain your consent.
We will not collect, use or disclose more Personal Information than is reasonably necessary to meet the identified purposes. We will limit our collection of Personal Information to that which is necessary for the purposes identified by CFSACK. We collect Personal Information only by fair and lawful means.
5. Limiting Use, Disclosure and Retention of Personal Information:
CFSACK will only use or disclose Personal Information for the purposes for which it was collected, unless we have your consent to use it for a different purpose or if CFSACK is required by law. If we want to use or disclose your Personal Information for a new purpose, we will advise you of this purpose in writing and obtain your consent.
We keep Personal Information only as long as necessary to achieve the purposes for which it was collected although we may retain certain Personal Information indefinitely if CFSACK is required to do so by Canada Revenue Agency or by our insurers. If you have made a request to access Personal Information, we will keep that Personal Information for as long as is necessary to allow you to fully seek any remedies (exhaust any recourse) that you may have under federal and provincial legislation.
CFSACK does not disclose or share Personal Information more widely than is necessary to achieve the purposes for which it was collected.
We may share Personal Information with the parties set out below for the following purposes:
-
The Museum, in connection with matters affecting our programs and events;
-
To our American sister organization, AFSACK, in connection with matters affecting the Museum and/or for joint programs and events;
-
Third-party service providers, such as those who provide us with group benefits, insurance, IT and system administration services, payment processing services such as Stripe and PayPal, e-commerce, telemarketing services, direct mail services and database management services;
-
Professional advisors, such as lawyers, auditors, bankers and insurers who provide us with legal, accounting, auditing, banking and insurance services;
-
Government, regulatory authorities, law enforcement, dispute resolution bodies, courts and similar entities to comply with any legal or regulatory obligation, to detect and prevent crimes or to assert or defend legal rights and interests;
-
Any persons or entities where we have a legitimate business reason for doing so, such as to manage risk, to process payments to you or to someone on your behalf or to perform or carry out the terms of any contract between us;
-
To the transferee if we transfer, sell or dispose of all or substantially all of our assets or operations;
-
To anyone we reasonably believe is your agent;
-
To other third parties if we have told you about them and you have given us your consent.
6. Ensuring Accuracy of Personal Information:
CFSACK has adequate processes and safeguards in place to keep Personal Information as accurate, complete, and up-to-date as is necessary for the purposes for which it is to be used. We will not routinely update Personal Information, unless such a process is necessary to fulfil the purposes for which the Personal Information was collected. To change or modify any Personal Information previously provided to CFSACK, contact us at info@cfscack.org.
​
7. Securing Personal Information:
We will take reasonable steps to keep Personal Information in both paper and electronic format protected against loss, theft, snooping, hacking or people collecting, disclosing, copying, using or changing it without authorization. We use security safeguards appropriate to the sensitivity of the information. Our methods of protection include:
-
Physical measures - such as areas of restricted access and locked filing cabinets;
-
Organizational measures - such as security policies and procedures, employee training on privacy issues, security clearances and limiting access on a "need-to-know" basis;
-
Technological measures - such as passwords, encryption, audits as well as strong data security software and systems to protect the Personal Information in CFSACK’s custody from hackers and malicious intruders. Our software is routinely updated to maximize protection of Personal Information;
CFSACK makes all employees, volunteers as well as third-party service providers aware of the importance of maintaining the privacy and security of Personal Information. All CFSACK employees and volunteers must sign a confidentiality agreement.
We securely destroy Personal information so that reconstruction is not reasonably possible. This prevents unauthorized parties from gaining access to the Personal Information.
While CFSACK is committed to protecting your Personal Information, our security practices and technology measures cannot guarantee absolute security of Personal Information and we cannot ensure or warrant the security of any information you provide to us. You can reduce risk to your own Personal Information by using strong passwords, keeping your passwords confidential and following other Personal Information security best practices.
a) Third Party Processors
We use Stripe and PayPal to process payment data.
You can access Stripe’s security policies at https://stripe.com/docs/security. You can read Stripe’s privacy policy at https://stripe.com/en-ca/privacy.
You can access more information about PayPal’s security standards at https://www.paypal.com/ca/business/security/pci-compliance. You can read PayPal’s privacy policy at https://www.paypal.com/webapps/mpp/ua/privacy-full.
​
We use Donorbox to process donor information.
Donorbox is an online fundraising software that allows not for profit organizations like CFSACK to receive donations over the Internet. You can access more information about Donorbox’s security safeguards at https://donorbox.org/security and at https://donorbox.zendesk.com/hc/en-us/articles/360020293212-How-does-Donorbox-keep-payment-data-secure-. You can read Dropbox’s privacy policy at https://www.dropbox.com/privacy#:~:text=We%20may%20disclose%20your%20information,abuse%20of%20Dropbox%20or%20our.
8. Openness:
CFSACK will make available to individuals specific information about our policies and practices relating to the management of Personal Information, including by posting this Privacy Policy on the Website. If you have any questions about this Privacy Policy, including how to exercise your legal rights, or if you would like specific information about how we manage Personal Information, please contact us at info@cfsack.org.
9. Individual Access:
If you make a request to us, we will inform you of the existence, use, and disclosure of your Personal Information and we will give you access to your Personal Information, subject to limited exceptions under PIPA. We will respond to your request within the time periods provided for under PIPA.
You can challenge the accuracy and completeness of the Personal Information and have it changed or corrected as appropriate if there is an error or omission by contacting usthe Privacy Officer. We will respond to your request within the time periods provided for under PIPA. If we identify a gap in compliance, we will take appropriate steps to remedy the situation, including changing our policies and practices if necessary.
10. Questions and Complaints:
Any complaints, concerns or questions regarding CFSACK’s compliance should be directed in writing to us at info@cfsack.org. If we are unable to resolve the concern, you may also write to the Information and Privacy Commissioner of British Columbia.
E. Information Collected Through Technology and Social Media
When you visit the Website, we may automatically collect information about your equipment and browsing history using cookies, server log files and other similar mechanisms. By using the Website, you consent to the use of cookies in accordance with this Privacy Policy.
A cookie is a small text file that is placed on your device when you visit a Website and can last either for the duration of your visit (a “session cookie”) or for repeat visits (a “persistent cookie”). We use the word “cookie” in this Privacy Policy to refer to all files that collect information in this manner.
Some of the cookies we use may be necessary for security purposes, to authenticate you and enable you to use the Website. Other cookies may not be essential but may make it easier for you to use the Website (such as by identifying you, remembering your preferences and helping you navigate the Website). Some cookies are used to help us analyze the use and performance of the Website, as well as for advertising or tracking purposes, including allowing our advertising partners to track and analyze your behaviour on the Website and across the internet (e.g. Wix and Google Analytics, which track Website usage and traffic)
We collect the following types of information through cookies:
-
your IP address;
-
your approximate geographic location;
-
the type of operating system you are using (e.g., Windows or Mac);
-
the type of device you are using;
-
the type of browser you are using;
-
the domain name from which you reached the Website;
-
which pages you visit on the Website;
-
the frequency, date and time of your visits to the Website.
In addition to the identified purposes described in this Privacy Policy, we collect and may share this information with our service providers and agents for the purpose of understanding how visitors use the Website, to improve the functionality and content of the Website and to improve your interaction with the Website by making it easier for you to get back to the pages you have looked at the next time you visit.
You have choices when it comes to cookies. All major browsers allow you to disable cookies. If you do not want information collected through the use of cookies, you can disable cookies by changing the setting of your Internet browser. If you disable cookies, you may be unable to use or access some features on the Website.
The Website may also provide links to third party internet sites. Clicking on those links may allow third parties to collect or share information about you. We cannot control these third-party sites and CFSACK is not responsible for the actions or policies of such third parties. You should check the privacy policies of third parties when visiting their internet sites or when providing any Personal Information to them.
For example, we use Stripe and PayPal as our payment process providers. You can read Stripe’s privacy policy at https://stripe.com/en-ca/privacy. You can read PayPal’s privacy policy at https://www.paypal.com/webapps/mpp/ua/privacy-full.
We use Donorbox to process donor information. You can read Dropbox’s privacy policy at https://www.dropbox.com/privacy#:~:text=We%20may%20disclose%20your%20information,abuse%20of%20Dropbox%20or%20our.
If you make a donation directly to CFSACK by way of interac e-transfer, we will only collect the Personal Information that you choose to provide in the comments box.
We may collect Personal Information when you interact with our content on third-party sites or platforms, such as Facebook, Instagram, You Tube and Vimeo. This may include data such as comments or feedback, "likes" or shares, profile data or the fact that you viewed or interacted with our content. If you voluntarily post or submit any information on these platforms, your Personal Information may be automatically included in the posting and may be collected and used by others.
F. Protecting the Privacy of Children and Youth
We understand that Personal Information relating to children and youth is particularly sensitive, especially the younger they are. Consistent with the position of the Office of the Privacy Commissioner of Canada, we will not knowingly collect Personal Information from children under the age of 13 unless we have the consent of their parents or guardians. We collect the minimum amount of Personal Information of children and youth necessary to achieve our purposes.
If you are a child or youth, you should review this Privacy Policy with your parents or guardians to make sure that you understand and consent to everything in it. IF YOU ARE UNDER THE AGE OF 13, you must not access the Website or provide us with any Personal Information unless your parent or guardian has consented. If we discover that we have collected Personal Information from a child under the AGE OF 13 without parental consent, we will delete that Personal Information.
G. Compliance with Canada’s Anti-Spam Legislation
CFSACK complies with the requirements of Canada’s Anti-Spam Legislation (“CASL”), as amended from time to time at all times, including when: sending emails or texts from a CFSACK account, email address or domain name, obtaining consent from recipients to send emails or texts, managing and responding to requests to unsubscribe and documenting and retaining records of consent. CFSACK does not send commercial electronic messages (“CEMs”) to any person unless it has express or implied consent from the recipient, the CEM includes identification and contact information for the sender and the CEM has an unsubscribe mechanism. To ensure compliance with CASL, CFSACK has written policies and procedures, updates its volunteers and staff regarding CASL requirements and keeps records of consents and requests to unsubscribe. Complaints regarding the sending of CEMs and requests to unsubscribe from CEMs should be directed to us at info@cfsack.org.
​
H. Other jurisdictions
Some or all of the Personal Information we collect may be transferred to third-party service providers in the course of our normal operations or activities including, without limitation, being stored on servers in cloud-based environments or transferred through other technological measures to trusted third parties to assist us in serving you. Some of our service providers are located outside of Canada and therefore Personal Information may be stored or processed in jurisdictions outside of Canada. As a result, this information may be subject to access requests from governments, courts, or law enforcement in those jurisdictions according to laws in those jurisdictions.
In addition to the rights listed in this Privacy Policy, other jurisdictions, including but not limited to the European Union (“EU”), grant other rights with respect to Personal Information. If you reside in the EU, these rights include the rights to access your Personal Information; to have us erase it; to obtain and reuse it for your own purposes and to restrict its processing. There may be certain limitations on or exceptions to these rights. If you are an EU resident, you understand that we may have to process or store your Personal Information outside of the EU. We use contracts with third party service providers and other mechanisms to protect your Personal Information in accordance with this Privacy Policy and applicable law.
If you have any questions or concerns about our privacy practices or procedures in relation to other jurisdictions, or to exercise any of your rights under the applicable law of other jurisdictions, please contact us at info@cfsack.org. We will let you know if there are any limitations or exceptions that apply.
I. Changes to Privacy Policy
We will update this Privacy Policy from time to time in response to developments and changes in privacy law or to reflect technological changes or new functionalities.
When we post changes to this Privacy Policy on the Website, we will change the “last updated” date at the top of this Privacy Policy. If possible, we will post notices of significant changes before they take place. Please refer to the latest update date above to know when we last updated this Privacy Policy.
​
​