Membership Privacy Supplement
How WorkOnward Foundation handles membership application, review, payment, renewal, and conduct-related personal information.
Version
draft-v1
Status
Draft pending adoption
Sections
10
These pages are intended to show the operating framework for WorkOnward membership as it is being formalized. They are public for transparency, but not yet final.
Draft pending legal review
Scope of this Privacy Supplement
This Privacy Supplement applies to information collected for the WorkOnward Foundation membership program, including applications, supporter submissions, nomination materials, payments, renewals, status tracking, appeals, and conduct matters.
It supplements the Foundation's broader site privacy practices by describing membership-specific handling of personal and professional information used to operate the membership program.
Categories of Information We Collect
The Foundation may collect identity and contact information, professional background, educational history, employment information, application statements, supporter details, uploaded documents, payment status, member IDs, correspondence, and records relating to conduct or appeals.
We may also collect metadata reasonably necessary to operate the service, such as timestamps, token usage status, IP-related security logs, file metadata, and internal workflow notes created during review.
Sensitive information should not be included unless it is necessary for the request being made, such as an accommodation request or hardship explanation.
Sources of Information
Most membership information comes directly from the applicant, member, supporter, nominator, or other participant submitting it to the Foundation.
Additional information may arise from payment processors, internal reviewers, interviews, complaint reporting, publicly available professional sources cited by the participant, or records created during membership administration.
How We Use Membership Information
The Foundation uses membership information to assess eligibility, verify supporter responses, communicate about status, process payments, administer renewals, issue decisions, maintain records, support governance, investigate complaints, and protect the integrity of the program.
We may also use information to improve process design, monitor access and fairness patterns in aggregate, respond to legal obligations, and defend the Foundation against fraud, abuse, or disputes.
We do not collect membership information for resale, and we do not treat application materials as public by default.
Legal and Operational Bases for Handling Information
We handle information because it is necessary to review requests made by participants, operate the membership program, maintain security, comply with legal obligations, protect legitimate organisational interests, and honour participant choices such as accommodation requests or renewal actions.
Where a participant volunteers optional information, the Foundation will use that information only to the extent reasonably connected to the request or program function for which it was provided.
Disclosures, Service Providers, and Internal Access
Membership information may be shared internally with Foundation personnel, reviewers, committee participants, or authorised contractors who need access for legitimate membership functions and who are expected to respect confidentiality.
We may use third-party processors and infrastructure providers for email delivery, database hosting, secure file handling, captcha verification, and payment processing. These providers receive only the information reasonably necessary for the relevant service.
We may disclose information where required by law, to respond to legal process, to investigate fraud or abuse, or to protect the rights, safety, and operations of the Foundation and its participants.
Retention and Deletion
The Foundation retains membership records for as long as reasonably necessary to administer membership, maintain historical records, handle renewals, support governance, address disputes, and comply with legal, accounting, or risk-management obligations.
Retention periods may differ for active member records, declined applications, payment records, supporter responses, and conduct files. Some records may be archived rather than deleted immediately when no longer needed for day-to-day operations.
Deletion requests will be considered in light of legal duties, recordkeeping needs, active disputes, and the Foundation's need to preserve the integrity of prior membership decisions.
Security and Confidentiality Measures
The Foundation uses administrative, technical, and organisational safeguards appropriate to the nature of the information and the size of the program. These may include role-based access limits, tokenised links, secure file handling, and restricted admin workflows.
No system is perfectly secure. Participants should use current contact details, protect their own email access, and avoid sharing private status links or membership tokens with others.
Participant Rights and Requests
Participants may request access to or correction of their membership information, ask questions about retention or handling, withdraw from the process, or raise concerns about privacy practices subject to legal and operational constraints.
Some requests may be limited where disclosure would expose another person's confidential submission, compromise an ongoing investigation, or undermine the integrity of a review process.
International Use, Contact, and Updates
The Foundation operates from the United States and stores or processes membership information through systems chosen to support the program. Participants outside the United States should be aware that their information may be handled in the United States or other jurisdictions used by service providers.
Questions about membership privacy may be directed to the Foundation through the published membership contact channels. The Foundation may update this supplement as the program evolves, and updated versions will be published with a revised version label where appropriate.