Privacy Policy for WhaleFest Monterey
1. Introduction
WhaleFest Monterey (“we,” “us,” “our”) is strongly committed to protecting and respecting your privacy. This Privacy Policy outlines how we collect, use, store, and share your personal data in connection with your use of our website at whalefestmonterey.com (“Site”) and our services. We process your personal data with the highest priority for security, transparency, and in full compliance with applicable data protection laws, including the General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act (“CCPA”).
By using our Site or services, you agree to the practices described in this Privacy Policy.
2. Scope of Policy and Role of Data Controller
This policy applies to personal data collected through the use of whalefestmonterey.com and any related services or communications. For the purpose of applicable data protection laws, WhaleFest Monterey is the “data controller” of your personal data. As a data controller, we determine the purposes and means of processing your personal information.
3. Categories of Data We Process
We may collect and process the following categories of personal data:
3.1 Usage Data
Includes information such as your browser type, IP address, device identifiers, time zone, language preferences, pages visited, duration of visits, click-stream data, and other related diagnostic data gathered from your interaction with the Site.
3.2 Account Data
Includes your full name, billing and shipping addresses, email address, and telephone number, typically provided when you create an account or engage with our services.
3.3 Profile Data
Includes information such as your preferences, event participation history, survey responses, and any purchases made through the Site.
3.4 Communication Data
Includes information from your interactions with us through email or the contact form, including inquiries, support requests, and feedback.
3.5 Technical Data
Includes details about the devices you use to access the Site such as operating system, hardware models, browser versions, and system configuration.
3.6 Transaction Data
Includes details related to any donations or purchases you may complete through the Site, such as payment method, billing details, and delivery confirmations. We do not store full credit card information.
3.7 Preference Data
Includes your communication preferences, marketing consents, interests in specific events or products, and preferred modes of contact.
4. Legal Bases for Processing Personal Data
Under data protection law, we rely on one or more of the following legal bases to lawfully process your personal data:
– Consent: Where you provide your clear and informed consent for specific processing (e.g., subscribing to newsletters).
– Contract: Where processing is necessary for the performance of a contract with you (e.g., ticket purchases).
– Legal Obligation: Where processing is required to comply with applicable laws or obligations.
– Legitimate Interests: Where necessary for our legitimate interests (e.g., improving the Site, preventing fraud), unless overridden by your fundamental rights and freedoms.
5. Your Data Protection Rights
In accordance with GDPR and CCPA, you have the following rights over your personal information:
– Right to Access: You may request access to the personal data we hold about you.
– Right to Rectification: You may request that we correct any inaccurate or incomplete information.
– Right to Erasure: You have the right to request deletion of your data under certain conditions (“right to be forgotten”).
– Right to Restriction: You may request that we restrict the processing of your personal data.
– Right to Data Portability: You can request that your data be provided in a structured, commonly used, and machine-readable format for transfer to another service provider.
– Right to Object: You may object to certain types of processing, such as direct marketing.
– Right to Opt-Out (CCPA): California residents have the right to opt out of the sale of their personal data and to request a disclosure of what data was collected, used, and shared.
To exercise any of these rights, please contact us at [email protected].
6. Security Measures
We employ a variety of technical and organizational measures to safeguard your personal data, including:
– End-to-end encryption of sensitive data during transmission.
– Restricted access to personal data only to authorized personnel under a duty of confidentiality.
– Regular data backups and secure storage solutions.
– Staff training programs focused on data protection and privacy compliance.
7. International Transfers
Your personal data may be transferred to and processed outside of your country of residence, including in countries that may not offer the same level of data protection. Where applicable, we implement Standard Contractual Clauses or rely on other legal mechanisms approved under GDPR to ensure lawful international data transfers.
8. Data Retention
We retain your personal data only as long as necessary for the purposes set out in this Privacy Policy, unless a longer retention period is required by applicable law. Data retention periods vary depending on the category:
– Usage Data: up to 26 months
– Account and Profile Data: for the duration of your account + 6 years for audit purposes
– Communication Data: for 2 years following last interaction
– Transaction Data: retained for legally required financial record-keeping (7 years)
– Preference Data: until you withdraw consent or unsubscribe
9. Cookie Policy
We use cookies and similar tracking technologies to enhance your experience on whalefestmonterey.com. These include:
– Essential Cookies: Required for the Site to function properly (e.g., session cookies).
– Functional Cookies: Enable personalization such as remembering preferences.
– Analytics Cookies: Help us understand user interaction to improve the Site (e.g., Google Analytics).
– Performance Cookies: Optimize website speed and server response.
10. Cookie Management and Compliance
Upon accessing the Site, you will be prompted to accept or customize your cookie preferences. You may update or withdraw your consent at any time through the cookie settings panel or by adjusting your browser settings. Our cookie practices comply with GDPR and CCPA requirements, offering opt-in mechanisms for non-essential cookies and providing clear disclosures regarding data use.
11. Protection of Children’s Privacy
Our Site is not intended for or directed to children under the age of 13. We do not knowingly collect or solicit personal data from anyone under 13. If we learn that we have collected such data inadvertently, we will take prompt steps to delete such information from our records. Parents or guardians who believe that their child has provided personal information should contact us immediately at [email protected].
12. Policy Updates and Notices
We may update this Privacy Policy to reflect changes in legal obligations, our practices, or the Site’s functionality. Any changes will be communicated via notice on the Site and/or emailed to users where legally required. Continued use of the Site after such notifications indicates your acceptance of the revised policy.
13. Contact Information
If you have any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us at:
WhaleFest Monterey
Email: [email protected]
Website: whalefestmonterey.com
We are committed to compliance with all applicable privacy laws and will strive to maintain transparency, accountability, and user trust. Please reach out to us with any inquiries or requests regarding your personal data and privacy rights.