This Privacy Policy explains how IAF ("we", "us" or "our") collects, uses, stores and protects personal information of its applicants, members, partners, visitors and stakeholders.
Last Updated: August 25, 2025This Privacy Policy applies to the iafcom website, membership pre‑application forms, member portal interactions, newsletters, events registration, technical committees and any digital services operated directly by IAF. Where third‑party systems are used (e.g. secure payment processors, webinar platforms), their own privacy notices also apply.
We do not collect: unnecessary personal profiling data, marketing demographics purchased from brokers, or special categories of data unless explicitly provided for accreditation justification.
Data is obtained directly from you (forms, email, portal, events), automatically through essential technical logs, or indirectly where an organisation nominates you as a representative (with your knowledge). We do not use covert tracking scripts or third‑party advertising beacons.
We limit sharing to what is operationally required:
We do not sell personal data or provide member lists to advertising networks.
Personal data is retained only for the lifecycle necessary to evaluate, establish, maintain or document membership and related activities, after which it is securely deleted or anonymised. Core governance records may be archived for statutory or audit obligations.
Controls include role‑based access, encryption at rest for infrastructure‑level storage, TLS for transport, integrity monitoring, least‑privilege principles, and periodic security reviews. While no system is infallible, we continuously enhance resilience against emerging threats.
Data may be processed in jurisdictions where our secure hosting or processors operate. Where required, standard contractual safeguards or equivalent mechanisms are applied to protect cross‑border transfers.
Depending on jurisdiction, you may request: access, rectification, deletion, restriction, objection, portability and withdrawal of consent (where relied upon). We will respond in a reasonable timeframe subject to verification.
This site is not directed to children under 16. We do not knowingly process data of minors without appropriate guardian consent where legally necessary.
Material changes will be posted on this page with a revised "Last Updated" date. Where required, we will notify active members via email or portal notices.
To exercise rights or ask questions about this policy, contact:
Email: [email protected] (example)
Subject: Privacy Request / Inquiry