FRATERNALWEB PRIVACY POLICY Effective date: September 2, 2026 Version: 2026-09-02 0. THE COMPANY; OUR PRIVACY OFFICER 0.1 "Company," "we," "us," and "our" mean FraternalWeb Limited, a corporation existing under the laws of the Province of Ontario, Canada, with a mailing address of Office 911, 145 1/2 Church St, Unit 5, Toronto, ON M5B 1Y4, Canada (Ontario Corporation Number 1001724366). 0.2 Privacy Officer. The Company has designated an individual who is accountable for the Company's compliance with this Policy and with applicable privacy legislation. That individual holds the office below, and their name will be provided on request: The Privacy Officer FraternalWeb Limited Office 911, 145 1/2 Church St, Unit 5, Toronto, ON M5B 1Y4, Canada privacy@frweb.org 0.3 All privacy questions, access and correction requests, consent withdrawals, and privacy complaints should be sent to privacy@frweb.org. Other Company addresses (help@frweb.org for support and info@frweb.org for general enquiries) are monitored, and a privacy request received at either will be routed to the Privacy Officer, but using privacy@frweb.org will be faster and starts the response clock described in Section 15 without delay. 1. SCOPE OF THIS POLICY; WHO IT APPLIES TO; DEFINITIONS 1.1 This Privacy Policy explains how the Company collects, uses, discloses, and protects information in connection with the FraternalWeb platform, including frweb.org and every Chapter subdomain of frweb.org (collectively, the "Service"). It should be read together with our Terms of Service. 1.2 Four groups of people are described in this Policy, and different parts apply to each: (a) Chapters and their Administrators -- the organizations that subscribe to the Service and the individuals who run their Backends. Sections 2, 5.1, 9, 10, 11, 13, 14, and 15 are most relevant to you. (b) Members -- individuals with their own member accounts. Section 3 is written specifically for you. (c) Event registrants, form submitters, and newsletter subscribers who are not Members. Section 4 is written specifically for you. (d) Visitors to a public Tenant Site who do not submit anything. Section 4.5 is written specifically for you. 1.3 Definitions. This Policy uses the same defined terms as our Terms of Service. In particular: (a) "Chapter" means any lodge, council, chapter, fraternal or civic organization, or other entity that registers to operate a Tenant Site and Backend on the Service. (b) "Administrator" means whichever individual(s) currently hold administrator-level access to a Chapter's Backend. (c) "Member" means an individual who completes the Service's own account signup process (typically using an invite link provided by a Chapter) to obtain access to that Chapter's Backend as an individual member. (d) "Personal Information" means information about an identifiable individual. (e) "PIPEDA" means the Personal Information Protection and Electronic Documents Act (Canada), together with its regulations, as amended or replaced. 1.4 A Chapter's acceptance of this Policy is an organizational commitment made through whoever currently serves as its Administrator, in the same manner described in Section 1.6 of the Terms of Service. 1.5 What this Policy does not cover. This Policy does not cover: (a) a Chapter's own privacy practices outside the Service, including the paper, spreadsheet, or other records it keeps independently; (b) third-party websites or services that a Chapter links to or embeds on its Tenant Site; or (c) the practices of the third-party providers listed in Section 9.2, each of which is governed by its own privacy policy. 2. OUR ROLE, AND A CHAPTER'S ROLE, REGARDING PERSONAL INFORMATION 2.1 Two different kinds of decision. The Service has a fixed set of built-in categories for tracking a Chapter's members and related individuals -- currently including name, email address, phone number, role or office assignments, degree or rank progression history, dues and payment status/history, and event RSVPs, among others described in Section 5. These categories, and how the Service's own features process them (for example, how a "mark dues paid" action is recorded, or how a degree-advancement entry appears in a member's history), are designed and controlled by the Company as part of the Service's feature set. A Chapter cannot add, remove, or redefine these categories, and every Chapter's Backend uses the same fixed fields. 2.2 Within those fixed categories, a Chapter's Administrator(s) -- and anyone else the Chapter grants a relevant permission to -- decide which specific individuals to add as members (or event attendees or newsletter subscribers), and what specific values to enter, update, or remove for them: for example, that a particular person's dues are now paid, that a particular person advanced to a new degree, or that a particular person holds a particular role. Some fields, such as a Member's own name or phone number, may also be updated directly by that Member within their own account. In most cases this information mirrors records a Chapter already keeps independently of the Service (such as its own paper or spreadsheet dues ledger); the Service is, in substance, digitizing and mirroring that Chapter's own recordkeeping. 2.3 How this works under PIPEDA. PIPEDA does not divide the world into "controllers" and "processors." Instead, it holds an organization accountable for Personal Information in its possession or custody, including information the organization transfers to a third party for processing on its behalf, and requires the organization to use contractual or other means to ensure a comparable level of protection while the information is being processed by that third party. Applying that framework: (a) Your Chapter is the organization accountable to you for the membership information it keeps about you. It decides to record you, decides what to record, decides why, and is responsible for having a lawful basis and any required consent for doing so. It remains accountable for that information even though it is stored on our Service. (b) The Company holds and processes that information on your Chapter's behalf, for the sole purpose of providing and supporting the Service. We do not sell it, rent it, trade it, or use it for our own marketing, advertising, profiling, or artificial-intelligence training purposes. (c) The Company is separately accountable, in its own right, for: the Personal Information we collect directly from Chapters and Administrators for billing, account administration, support, and security; the technical and usage information described in Section 5.6; the design of the Service's fixed data categories and built-in processing logic; and the safeguards described in Section 11. 2.4 Practical effect. This division determines who you should approach for what. Requests to change what your Chapter records about you -- your dues status, your degree or rank history, your offices, whether you are listed at all -- go to your Chapter, because those are your Chapter's decisions and its records. Requests about how the Service itself handles information, about our safeguards, or about information we hold in our own right, come to us at privacy@frweb.org. Section 15 explains how we handle a request that reaches us but belongs with your Chapter. 2.5 A note on other legal regimes. The description above is written to PIPEDA. If a different framework applies to a particular Chapter or a particular individual -- for example Quebec's private-sector privacy law, or a law outside Canada that uses controller/processor concepts -- the allocation of legal roles under that framework may be characterized differently. Section 18 addresses this. A Chapter subject to such a framework should obtain its own advice. 3. PRIVACY NOTICE FOR INDIVIDUAL MEMBERS 3.1 This Section 3 is addressed specifically to Members -- individuals who complete the Service's own account signup (typically using an invite link from a Chapter) to access a Chapter's Backend. It summarizes, in one place, what Personal Information about you the Service processes and the choices and rights available to you. It supplements, and does not replace, the rest of this Policy. 3.2 What is processed about you. As described more fully in Section 2 and Section 5, the Service processes Personal Information about you that your Chapter's Administrator(s) enter or maintain using the Service's fixed built-in fields (such as your name, email address, role/office history, degree or progression history, and dues/payment records), together with information you provide directly when creating or using your own account (such as your login credentials, and any profile fields -- like your name or phone number -- that you are permitted to edit yourself), and technical and usage information described in Section 5.6. 3.3 Why it is processed. Your information is processed to operate the member portal for you and your Chapter: to authenticate your sign-in, display your own membership records to you, let your Chapter's Administrator(s) maintain accurate records (such as dues status, degree/rank, or role), process event RSVPs, and send you transactional communications like invite links, sign-in links, and notices from your Chapter. Section 6 sets out the full list of purposes. 3.4 Your consent. By completing your account signup, you consent to the Company processing your Personal Information as described in this Policy, for the purpose of providing you and your Chapter with access to the Service. Section 7 explains the form your consent takes and how you can withdraw it. You are not asked to, and do not need to, agree to any billing or commercial terms -- those apply only to your Chapter, as explained in Section 8 of the Terms of Service. 3.5 Who can see your information. Within your Chapter's Backend, your information is visible to your Chapter's Administrator(s) and to any other person your Chapter has granted a permission level that includes access to member records. Your Chapter -- not the Company -- decides who those people are. Your Chapter may also choose to publish some information (for example, an officer's name and contact details) on its public Tenant Site; if you hold an office and do not wish to be listed publicly, raise that with your Chapter. Company personnel may access your information only as described in Section 11.3. 3.6 Your choices and rights. You may review or correct certain information yourself within your account (such as your name or phone number, where the Service allows self-editing). For information your Chapter's Administrator(s) control (such as your dues or degree records), contact your Chapter's Administrator. To exercise the access and correction rights described in Section 15, or to complain about our handling of your information under Section 16, contact privacy@frweb.org. If you no longer wish to use the member portal, you may ask your Chapter's Administrator to remove your account access; the underlying membership records may still be retained by your Chapter as its own organizational records, independent of the Service, in the same way a paper ledger would be. 3.7 No commercial relationship. You are not a customer of the Company and have no billing relationship with us. Our processing of your Personal Information is not conditioned on any payment from you, and nothing in this Policy creates such an obligation. 4. PRIVACY NOTICE FOR EVENT REGISTRANTS, FORM SUBMITTERS, SUBSCRIBERS, AND PUBLIC VISITORS 4.1 This Section 4 is addressed to people who interact with a public Tenant Site without holding a member account. 4.2 If you register for an event or submit a form. A Chapter may enable public RSVP forms, contact forms, or other forms on its Tenant Site. We collect what you voluntarily submit -- typically your name, email address, and any information the form asks for -- and make it available to the Chapter that operates that Tenant Site, for the purpose of fulfilling your request (for example, confirming your RSVP or replying to your enquiry). The Chapter, not the Company, decides what its forms ask for, how long it keeps your submission, and what it does with it afterwards. If you want your submission deleted, contact the Chapter first; see Section 15.4 if you cannot reach it. 4.3 If you subscribe to a newsletter. See Section 8, which explains how subscription and unsubscribing work, and who is legally the sender of the messages you receive. 4.4 Submitting a form or subscribing does not create a member account, does not give you access to any Chapter's Backend, and does not make you a member of any Chapter. 4.5 If you are just browsing. Visiting a public Tenant Site does not require you to provide any Personal Information. We automatically collect the technical and usage information described in Section 5.6 for security, abuse prevention, and troubleshooting. Public Tenant Sites use only the strictly necessary cookies described in Section 5.7, and we do not use advertising or cross-site tracking cookies. A Chapter may embed third-party content (such as a map, video, or calendar) on its Tenant Site, and that third party may collect information about you under its own privacy policy, over which we have no control. 5. INFORMATION WE COLLECT 5.1 Account and Chapter information. When a Chapter is registered, we collect the Chapter's name, chapter/lodge number (if applicable), organization type, mailing address, chosen subdomain, and the registering Administrator's name and email address. 5.2 Individual member information. Administrators may enter information about their Chapter's own members, which can include: name (and pre-/post-nominals), email address, phone number, role and office history, degree or progression history, dues and financial ledger records, and event RSVPs. Authentication information is also held: a member-selected password (stored only as a one-way cryptographic hash, never in readable form) or, if the member signs in with Google, an OAuth identifier -- we never see or store a Google account password. See Section 2 for how responsibility for this information is divided between the Company and your Chapter. 5.3 What the Service is not designed to hold. The Service's fixed data categories are not designed for, and Chapters are contractually prohibited by Section 9.3 of the Terms of Service from entering, health or medical information, government identification or social insurance numbers, financial account or payment card numbers, biometric information, precise geolocation, or criminal history. If you become aware that such information has been entered about you, tell your Chapter and let us know at privacy@frweb.org. 5.4 Content uploaded to the Service. Files, photographs, newsletters, event listings, correspondence, and form responses uploaded through a Chapter's Backend or public forms. Content may incidentally contain Personal Information -- a group photograph, a set of meeting minutes, a scanned letter -- and the Chapter that uploads it is responsible for having the right to do so. 5.5 Payment information. Subscription payments are handled directly by our payment processor, Stripe, Inc. We do not receive or store your full payment card number. We do retain a Stripe-assigned customer identifier and invoice and payment status information for billing and account administration. Only Chapters make payments; Members do not. 5.6 Technical and usage information. IP address, browser and device information, requested URLs, access timestamps, referring page, error and diagnostic records, email delivery and bounce records, and similar log data, collected automatically for security, fraud prevention, rate-limiting, deliverability, and troubleshooting purposes. Server and application logs are retained for approximately 90 days and then deleted or aggregated, except where a longer period is needed to investigate a specific security or abuse incident. 5.7 Cookies. We use cookies that are strictly necessary to operate the Service, and no others. We do not use advertising, analytics, or cross-site tracking cookies, and we do not present a cookie consent banner, because every cookie we set is strictly necessary to deliver a service you have requested. The cookies we set are: (a) a session cookie, which keeps you signed in to your account; (b) a security token, which protects forms against cross-site request forgery; and (c) a sign-in recognition cookie, which holds a random value that lets us tell whether your account has been used to sign in from that browser before. Because signing in uses a link sent to your email address rather than a password, telling you about a sign-in from a browser we do not recognize is how you would learn that someone else has obtained access to your email account. This cookie is not a credential and grants no access on its own: presenting it tells us only that the browser is familiar, and its sole effect is that we do not send you that notification. You can block or delete these cookies through your browser. Without (a) and (b) the Service will not function correctly; blocking (c) means only that you will be notified each time you sign in. 5.8 Correspondence. If you contact us at any address ending in @frweb.org, we keep a record of that correspondence, including your address and the content of your message, so that we can respond, maintain a support history, and resolve disputes. 6. WHY WE USE INFORMATION (PURPOSES) 6.1 We identify our purposes here rather than collecting information first and deciding later. We use the information described in Section 5 to: (a) provide, operate, and maintain the Service, including hosting public Tenant Sites and operating Chapter Backends; (b) authenticate sign-ins and enforce account permissions; (c) process subscription payments and manage billing, invoicing, renewals, collections, and tax and accounting records; (d) send transactional and service communications -- invite links, sign-in links, RSVP confirmations, billing notices, security alerts, outage notices, and notices about changes to this Policy or the Terms of Service; (e) transmit newsletters and other messages that a Chapter chooses to send to its own recipients, as described in Section 8; (f) provide customer support and respond to correspondence; (g) detect, prevent, and investigate fraud, abuse, spam, and security incidents, including automated malware scanning of uploaded files, rate-limiting, and log review; (h) comply with legal obligations and respond to lawful demands; and (i) troubleshoot, debug, maintain, and improve the Service. 6.2 If we intend to use Personal Information for a purpose not listed above and not compatible with the purpose for which it was collected, we will identify that new purpose and obtain consent before doing so. 6.3 We do not use Personal Information held on the Service to train machine-learning or artificial-intelligence models, and we do not disclose it to any third party for that purpose. 6.4 We collect only the information necessary for the purposes above. We do not require a Member to provide information beyond what is needed to operate the member portal, and we do not condition access on consent to any unnecessary collection. 7. CONSENT 7.1 Form of consent. Where the law requires consent, we rely on: (a) express consent, given by an affirmative act -- for example, completing account signup after being presented with this Policy, submitting a form, or subscribing to a newsletter; and (b) implied consent, where the purpose is obvious from the circumstances and a reasonable person would expect it -- for example, using the email address you supply to send you the RSVP confirmation you asked for. 7.2 We do not use pre-checked boxes to obtain consent, and we do not bundle consent to unrelated processing into acceptance of the Terms of Service. 7.3 Withdrawing consent. You may withdraw your consent to processing that depends on consent, at any time, by writing to privacy@frweb.org or, where the processing is your Chapter's, by contacting your Chapter. We will tell you what withdrawal will mean before we act on it. 7.4 Consequences of withdrawal. Some processing is necessary to operate an account at all -- authentication, security logging, and storing the records that make up the member portal. If you withdraw consent to that processing, we cannot continue to provide you with an account, and your access will end. Withdrawing consent to receive newsletters does not affect your account. Withdrawal is not retroactive, and does not require us to delete records we are required or permitted by law to retain, such as billing records. 7.5 A Chapter cannot give consent on your behalf for purposes outside its own membership recordkeeping, and nothing in a Chapter's acceptance of this Policy constitutes your personal consent to anything beyond that. 8. NEWSLETTERS, BULK EMAIL, AND YOUR SUBSCRIPTION CHOICES 8.1 Who is sending. When you receive a newsletter, bulletin, event invitation, or similar bulk message that originated from a Chapter's Backend, the Chapter is the sender. The Company operates the technical means of transmission on the Chapter's behalf. We do not write, review, approve, or select the recipients of those messages, and we do not use any Chapter's recipient list for our own purposes or share it with any other Chapter. 8.2 Consent to receive. Each Chapter is required by Section 7 of the Terms of Service to send only to people who have asked to receive its messages, or with whom it has a relationship that gives rise to implied consent under Canada's Anti-Spam Legislation, and is prohibited from using purchased, rented, traded, harvested, or scraped address lists. Each Chapter is responsible for keeping its own records of the consent it relies on. 8.3 Unsubscribing. Every bulk message sent through the Service must contain an unsubscribe mechanism. Using it removes you from that Chapter's list. Unsubscribing from one Chapter's newsletter does not unsubscribe you from another Chapter's, because each Chapter maintains its own separate list. Unsubscribing also does not stop transactional messages that are necessary to operate your account, such as password resets and security notices; to stop those, you must close your account. 8.4 Suppression. When you unsubscribe, we record that fact so the Service can prevent further sending to you, and we retain that record for as long as necessary to keep honouring your choice. This is one of the few cases where retaining your email address after you ask to be left alone is the privacy-protective outcome: without it, we could not reliably stop the next message. 8.5 If you keep receiving unwanted messages. Contact the Chapter first, using the contact information the message is required to contain. If that does not work, write to privacy@frweb.org with a copy of the message. We investigate complaints of this kind and can suspend a Chapter's sending ability under Section 7.8 of the Terms of Service. 8.6 The Company's own messages. We send Chapters and Administrators transactional and service messages about their accounts. We do not send marketing email to Members, and we do not add anyone to a marketing list as a result of using the Service. 9. HOW WE SHARE INFORMATION 9.1 We do not sell Personal Information, and we do not share Personal Information with third parties for their own independent marketing purposes. 9.2 We use the following categories of third-party service providers, solely as necessary to operate the Service. Each is bound by its own privacy policy, and each is required to provide a level of protection comparable to that described in this Policy while information is in its custody: - Stripe, Inc. -- payment processing and billing. Receives the Chapter's billing contact details and payment credentials, which it collects directly. Processes in the United States and elsewhere. - Google LLC -- optional "Sign in with Google" authentication, and Google Search Console for public Tenant Site indexing. Receives an account identifier for members who choose Google sign-in. Processes in the United States and elsewhere. - Email delivery infrastructure -- to transmit transactional messages and Chapter newsletters. Receives recipient addresses, message content, and delivery metadata. - Malware scanning -- to scan files uploaded to the Service. May receive file contents or cryptographic hashes of files. - Canadian Centre for Child Protection Inc. ("C3P"), operator of Project Arachnid -- to detect child sexual abuse material and harmful-abusive material of children. Images and videos uploaded to the Service are transmitted to C3P's "Shield" service and compared against its classified hash list. C3P is a registered Canadian charity; under its own terms it may retain, use, and share submitted media in furtherance of that purpose, including with organizations outside Canada that assist it in classifying such material. See Section 10.2. - Professional advisors (accounting, legal) and, where necessary, insurers -- may receive information relevant to a specific engagement or claim. 9.3 Between Chapters. We do not share one Chapter's information with another Chapter. Each Chapter's data is logically separated within the Service. 9.4 Legal disclosures. We may disclose information if required to do so by law, subpoena, court order, or other legal process, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public, or to investigate suspected fraud, abuse, or a violation of the Terms of Service. Where we are legally permitted to do so, we will notify the affected Chapter before disclosing information in response to a legal demand. 9.5 Business transfers. If the Company is involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to this Policy or a successor policy of at least equivalent protection, and subject to applicable law. 9.6 Aggregate and de-identified information. We may create and use aggregate or de-identified statistics that cannot reasonably be used to identify any individual -- for example, the total number of Chapters using a feature. This is not Personal Information and is not restricted by this Policy. 10. WHERE INFORMATION IS STORED; CROSS-BORDER PROCESSING 10.1 The Service's primary infrastructure -- the application servers and databases holding Chapter Backends, Member records, and uploaded files -- is operated by the Company and located in Canada. 10.2 Certain third-party providers listed in Section 9.2, notably Stripe and Google, process information in the United States and potentially in other countries. In addition, images and videos uploaded to the Service are sent to the Canadian Centre for Child Protection (Project Arachnid Shield) for child-protection screening. C3P is located in Canada, but its screening may process media on servers in the European Economic Area, and media that matches its hash list may be made available to child-protection organizations it works with in other countries, including outside Canada and the EEA. 10.3 What that means. While Personal Information is in a foreign jurisdiction, it is subject to the laws of that jurisdiction, and may be accessible to the courts, law enforcement agencies, regulators, and national security authorities of that jurisdiction, in some cases without notice to you and without any right of challenge available to you under Canadian law. We provide this notice so that you can make an informed decision; using the Service means accepting that this is the case for the categories of information described in Section 9.2. 10.4 If we change hosting or service providers in a way that moves Personal Information to a different country, we will update this Policy and, where the change is material, notify Chapters in accordance with Section 19. 11. SAFEGUARDS 11.1 We protect Personal Information with safeguards appropriate to its sensitivity. Our current measures include: (a) encryption of sensitive data at rest, with per-Chapter separation of uploaded files; (b) encryption of data in transit using HTTPS/TLS; (c) passwordless authentication: the Service does not use, set, or store member passwords at all. Members sign in either with a single-use link sent to their email address, which expires shortly after it is issued, or with Google. There is therefore no member password for us to store, for you to reuse, or for an attacker to steal from us; (d) logical separation of each Chapter's data, so that one Chapter's Backend cannot access another's; (e) role-based permissions within each Chapter's Backend; (f) automated malware scanning of uploaded files; (g) rate-limiting and logging to detect and slow abuse; and (h) restriction of administrative access to authorized Company personnel. 11.2 We review these measures periodically and may change them as our assessment of appropriate safeguards evolves. This Section describes our practices; it is not a warranty. No method of electronic storage or transmission is completely secure, and we cannot guarantee that unauthorized access, disclosure, alteration, loss, corruption, or destruction of data will never occur. The allocation of legal liability for such events is addressed in Sections 15 and 16 of the Terms of Service, not in this Policy. 11.3 Company access to your information. Company personnel access Chapter and Member information only where necessary to operate, secure, support, or troubleshoot the Service -- for example, to investigate a support request, respond to a security incident, or perform a database migration -- and are bound by confidentiality obligations. We do not browse Chapter data for any other reason. 11.4 Backups. We perform backups of Service data on an approximately hourly basis as a matter of operational practice. Backups contain Personal Information and are protected by the measures in Section 11.1. Because backups are periodic rather than continuous, and because backup media are overwritten or expire on their own cycle, deleted information may persist in backups for a limited period after deletion from the live Service; see Section 13.5. The status of our backup process as an operational measure rather than a commitment is addressed in Section 11 of the Terms of Service. 11.5 Your part in security. Much of the security of your information depends on you. Because sign-in is passwordless, THE SECURITY OF YOUR EMAIL ACCOUNT IS THE SECURITY OF YOUR FRWEB ACCOUNT: anyone who can read your email can request a sign-in link and use it. Keep that mailbox under your sole control, secure it with a strong unique password and multi-factor authentication with your email provider, do not share your account or forward sign-in links to anyone, sign out on shared devices, and tell us promptly if you think your email account or your frweb account has been compromised. Section 3 of the Terms of Service sets out these obligations in full. 12. ACCURACY 12.1 Personal Information should be as accurate, complete, and current as is necessary for the purposes for which it is used. Inaccurate membership records can have real consequences -- a member wrongly shown as in arrears, or a degree or office record that is wrong. 12.2 Most of the substantive records about you are entered and maintained by your Chapter, and your Chapter is responsible for keeping them accurate. Where the Service permits you to edit your own fields, you are responsible for keeping those current. 12.3 We do not routinely update Personal Information on our own initiative, because doing so would mean second-guessing a Chapter's records. If you tell us information we hold in our own right is inaccurate, we will correct it. If you tell us information your Chapter holds is inaccurate, Section 15.4 applies. 13. RETENTION AND DELETION 13.1 We keep Personal Information only as long as necessary for the purposes identified in Section 6, or as required by law. 13.2 Active Chapters. We retain Chapter and Member information for as long as the Chapter's account remains active. 13.3 Inactive Chapters. If a Chapter's account becomes inactive due to non-payment and remains inactive for a further period (currently expected to be approximately one additional week), we may permanently delete the Chapter's Tenant Site, Backend data, uploaded files, and associated member information, as described in Section 17 of the Terms of Service. Chapters are strongly encouraged to maintain their own current export copies at all times. 13.4 Categories with their own retention periods: - Billing and payment records: retained for the period required by Canadian tax and corporate law, currently six (6) years from the end of the relevant fiscal period, even after an account closes. - Server and application logs: approximately 90 days, as described in Section 5.6. - Correspondence with us: two (2) years from the last message in the thread, unless it relates to an ongoing matter. - Unsubscribe and suppression records: retained indefinitely, for the reason given in Section 8.4. - Breach records: at least twenty-four (24) months, as required by law; see Section 14.4. 13.5 Residual copies. After deletion from the live Service, information may persist in backup media, logs, or caches for a limited period until those media are overwritten or expire in the ordinary course. We do not extract individual records from backup media on request. Residual copies remain protected by Section 11 and are not restored into the live Service except as part of a general restoration. 13.6 Requesting deletion. You may request deletion of Personal Information by contacting your Chapter's Administrator or by emailing privacy@frweb.org. We will respond as described in Section 15, subject to any retention we are required or permitted to maintain by law or for legitimate purposes such as billing records, fraud prevention, or the suppression records in Section 8.4. 14. IF THERE IS A BREACH 14.1 A breach of security safeguards means the loss of, unauthorized access to, or unauthorized disclosure of Personal Information resulting from a failure of our safeguards or from their absence. 14.2 If we become aware of a breach affecting a Chapter's information, we will notify that Chapter's Administrator(s) without undue delay after confirming it, and give them the information reasonably available to us about what happened, what categories of information were involved, and what we have done in response. 14.3 Determining whether individuals must be notified. Because your Chapter is the organization accountable to you for its membership records (Section 2.3), your Chapter is responsible for assessing whether a breach creates a real risk of significant harm to any individual, and for making any resulting report to the regulator, any notification to affected individuals, and any notification to other organizations that could reduce the risk. We will assist with that assessment. Where a breach affects information for which the Company is accountable in its own right, or where the law places the reporting obligation on us, we will report and notify as the law requires. 14.4 Records. We maintain a record of every breach of security safeguards involving Personal Information under our control, whether or not it triggers a notification requirement, and retain that record for at least twenty-four (24) months. We will make those records available to the regulator on request. 14.5 What notification will contain. Where we notify you directly, we will describe the circumstances, the day or period it occurred, the Personal Information involved, what we have done to reduce the risk of harm, what you can do to reduce your own risk, and how to contact us for more information. 14.6 Notifying us. If you believe your account has been compromised, or you can see information belonging to someone else, tell us immediately at privacy@frweb.org or help@frweb.org, and do not access or copy information that is not yours. 15. YOUR RIGHTS: ACCESS, CORRECTION, AND HOW TO EXERCISE THEM 15.1 Subject to applicable law, you may: ask whether we hold Personal Information about you; ask for access to it and for an account of how it has been used and to whom it has been disclosed; ask that it be corrected if it is inaccurate or incomplete; ask that it be deleted, subject to Section 13; and withdraw consent, subject to Section 7. 15.2 Making a request. Write to privacy@frweb.org. Tell us what you are looking for, and enough detail to locate it. We may ask you to verify your identity before we disclose anything -- this protects you, and we will ask only for what is needed to confirm you are who you say you are. 15.3 Our response. We will respond no later than thirty (30) days after we receive your request. If we need more time -- because meeting that deadline would unreasonably interfere with our operations, or because we need to consult or convert information into another format -- we will tell you within the original thirty days that we are extending, why, and by how long, and we will tell you that you may complain to the regulator about the extension. Access is normally provided free of charge; if a request would involve more than minimal cost, we will tell you the estimated cost in advance and proceed only if you confirm. 15.4 Requests that belong with your Chapter. If your request concerns records your Chapter controls -- your dues, your degree or office history, whether your Chapter records you at all -- we will refer you to your Chapter and let your Chapter know you have asked, unless the law directs otherwise. Your Chapter is responsible for responding within the time the law allows. If your Chapter does not respond, or cannot fulfil the request using the Service's own features, tell us and we will provide reasonable assistance. 15.5 When we may refuse. We may refuse access in the limited circumstances the law allows -- for example, where disclosing your information would reveal Personal Information about another identifiable individual and that information cannot be severed, where the information is protected by solicitor-client privilege, where it contains confidential commercial information, where disclosure could threaten the life or security of another individual, or where it was generated in the course of a formal dispute resolution process. If we refuse, we will tell you in writing, give our reasons, identify the provision we are relying on, and tell you how to complain under Section 16. 16. COMPLAINTS AND CHALLENGING OUR COMPLIANCE 16.1 You may challenge our compliance with this Policy or with applicable privacy law. Write to the Privacy Officer at privacy@frweb.org, describing your concern. You do not need to use any particular form or wording. 16.2 We will acknowledge your complaint, investigate it, and respond in writing with the outcome and the reasons for it. We aim to complete this within thirty (30) days, and will tell you if it will take longer. If your complaint is justified, we will take appropriate measures, including correcting our practices and, where necessary, amending this Policy. 16.3 If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada. The OPC generally expects you to raise your concern with the organization first, which is why Section 16.1 comes before this step. Office of the Privacy Commissioner of Canada 30 Victoria Street, Gatineau, Quebec K1A 1H3 1-800-282-1376 www.priv.gc.ca 16.4 Depending on where you live, a provincial privacy regulator may also have jurisdiction over your complaint; see Section 18. 16.5 A complaint about your Chapter's own handling of your information -- what it records, who it shares it with, whether it will correct a record -- is a complaint about your Chapter, and should be directed to your Chapter and, if unresolved, to the appropriate regulator for that Chapter. 17. CHILDREN'S PRIVACY 17.1 The Service is intended for use by adults and is not directed at children. We do not knowingly collect Personal Information directly from individuals under the age of 18 for the purpose of creating an account. 17.2 If we become aware that an individual under 18 has created an account, we may terminate that account and delete the associated information. 17.3 Section 19 of the Terms of Service addresses Member Data a Chapter may enter about an individual under 18, such as historical or honorary records. A Chapter is solely responsible for having the legal right and any required consent -- including, where applicable, that of a parent or guardian -- before entering such information. 17.4 If you are a parent or guardian and believe information about your child has been entered into the Service, contact the Chapter and write to us at privacy@frweb.org. 18. PRIVACY LAWS OTHER THAN PIPEDA 18.1 This Policy is written to PIPEDA, the federal Canadian private-sector privacy law that applies to the Company. 18.2 Alberta, British Columbia, and Quebec have their own private-sector privacy legislation, and Quebec's in particular imposes requirements that differ from PIPEDA in substance, not just in wording. A Chapter located in one of those provinces, or recording information about individuals located there, is responsible for identifying and meeting any additional requirements that apply to it. 18.3 The Service is not designed or represented as compliant with the privacy law of any jurisdiction outside Canada. A Chapter operating outside Canada, or recording information about individuals outside Canada, is responsible for determining whether it may lawfully use the Service for that purpose. 18.4 Canadian federal privacy law is currently under legislative review, and the framework that applies to the Company may change. If it does, we will update this Policy under Section 19. 19. CHANGES TO THIS POLICY 19.1 We may update this Privacy Policy from time to time. The "Effective date" and "Version" at the top indicate when it was last revised. 19.2 Material changes -- particularly any change to the purposes for which we use Personal Information, the categories of third parties we share it with, or where it is stored -- will be communicated by reasonable means, such as email to Administrators or a notice on the Service, before they take effect. Where a change requires consent under applicable law, we will obtain it rather than rely on notice. 19.3 Where the Company requires affirmative re-acceptance of a revised version before continued use, a Chapter's re-acceptance is completed by whoever currently serves as its Administrator, consistent with Section 1.4 above and Section 1.6 of the Terms of Service. 19.4 We keep prior versions of this Policy and will provide a copy of the version in effect on a particular date on request to privacy@frweb.org. 20. CONTACT US Privacy questions, access and correction requests, consent withdrawals, and complaints: Privacy Officer FraternalWeb Limited privacy@frweb.org Office 911, 145 1/2 Church St, Unit 5, Toronto, ON M5B 1Y4, Canada Technical support: help@frweb.org General enquiries: info@frweb.org