top of page
shutterstock_92147020.jpg

PRIVACY POLICY

March 24, 2025


INTRODUCTION
At National Flood Association (“NFA”), we care about the privacy of your data and are committed to protecting it. Our Privacy Policy (“Policy”) is intended to help you understand what Information we collect, maintain, or process, why we collect, maintain, or process it, what we do with your Information, and how you can update, manage, export, or delete your Information. Throughout this Privacy Policy, when we write “NFA,” “we,” “us,” or “our,” we’re referring to the National Flood Association, a Colorado nonprofit organization.
As part of our services, we utilize a third-party software provider (“Software Provider”) to deliver the mobile application (“App”) and related services to users (collectively, “Services”). While we manage user interactions and data collection through our Services, certain technical data and analytics may also be processed by our Software Provider to ensure the functionality, security, and improvement of the Services.


SCOPE
This Policy applies to the information obtained or processed by us through your use of our Services (“Information”) as described in this Policy. Any capitalized terms not defined herein shall have the meaning ascribed to them in the Terms of Service.


INFORMATION NFA COLLECTS, MAINTAINS, OR PROCESSES

 

Information collected, maintained, and processed.
When you interact with our Services, we may collect, maintain, or process Information that, alone or in combination with other data, could be used to identify you (“Personal Data”). Some of the Information we collect, maintain, or process is stored in a manner that cannot be linked back to you (“Non-Personal Data”).
 
Information provided when you create an account.
In addition to the Information detailed below, NFA may collect, and process data related to your participation in NFA’s annual conference and other membership activities. This may include event registration details, session attendance, preferences, survey responses, and other engagement metrics to improve member experiences.

  • Username, Password, E-mail Address, and Contact Preferences. When you create an account or log in to your account(s) that is associated with NFA’s Services, you are providing us with certain Personal Data, which may include your username, password, e-mail address, phone number, or other contact Information. Additionally, your organization, of which you are an Authorized User, may have also provided us with Personal Data that you previously provided to your organization.

  • Payment Information. Depending on how you use the Services, payment Information may be required to complete various transactions (membership, renewals, event registration, etc.). This Information is directly managed by a reputable third-party payment processing provider to enable any such transactions. NFA does not store or process your payment details directly.

  • User Content. We also collect, maintain, or process content you create, upload, or receive from others while using NFA’s Services. This includes things like messages you post or receive within, photos, documents, comments you make on discussion or wall threads, or other content or Information uploaded entered, or otherwise transmitted by you. If you engage in interactive features such as forums, networking tools, or event-specific discussions, we may collect data related to your participation to facilitate communication and enhance user experience.

 

 

 


Information collected automatically as you use our Services.
We automatically collect, maintain, or process certain Information about the devices you use to access NFA’s Services. The Information collected includes:

  • Location Information. This is the geographic area in which you are using your computer or mobile devices when interacting with NFA’s Services. NFA uses your location Information to provide a better user experience through notifications, event registration, or event check-in. Your location may be determined with varying degrees of accuracy by: (i) GPS, (ii) IP address, or (iii) Information about things near your device, such as Wi-Fi access points, cell towers, or Bluetooth devices. Our ability to collect location data depends in part on your device and account settings. If you enable location services, NFA may collect real-time location data for purposes such as personalized event recommendations, on-site navigation, and proximity-based networking.

  • Log Data. Our servers automatically collect data when you access the Services. That data is recorded into log files. This log data may include the IP address, date and time of use, Information about your browser configuration, Information about your mobile device configuration, and cookie data. Our Software Provider may also collect and use the Information collected for analytics and to improve the Services.

  • Usage Information. This Information informs us about how you use our Services. As an example, we will collect Information about user access to specific content within the Services. We use this Information to better understand how users use our Services. Our Software Provider may also collect and use the Information for analytics and to improvement of the Services.

  • Device Information. Device data is from your computer or mobile device, such as the type of hardware and software you are using, as well as unique device identifiers for devices that are using NFA’s Services. Our Software Provider may also collect and use the Information for analytics and to improvement of the Services.

  • Cookies. Cookies are small files stored in your device and used by web browsers to deliver personalized content and remember logins and account settings. NFA uses cookies and similar technologies to collect usage and analytic data that helps us to continue providing the App and Services to you. By using NFA’s Services, you consent to the use of cookies unless you opt out via the opt out setting or our cookie management tool.

 

How does NFA use my Information?
NFA uses the Information we collect, maintain, or process for the following purposes:
 

  • Enhance Your Experience. We use your Information to enhance your experience with our annual conference and membership activities, including sending event- related communications, facilitating networking opportunities, and providing personalized content.

  • Provide Services. We use your Information to administer our Services, authenticate users for security purposes, provide personalized features and access, process transactions, display user content associated with your account, and update your Information in the database of your organization of which you are an Authorized User.

  • Maintain & Improve Services. We use your Information to ensure that our Services are working as intended (e.g., tracking outages or troubleshooting issues that you or your organization report to us). Our Software Provider may also analyze usage data to identify the most utilized features and make improvements to the Services accordingly.

 

Does NFA review user generated content?
NFA does not monitor or view your user generated content stored in or transferred through our Services. However, such user generated content may be viewed under the following circumstances:

  • In order to respond to a request for user support;

  • In order to protect the rights, property, or personal safety of NFA and its users; or

  • To comply with our legal obligations, such as responding to warrants, court orders, or other legal processes.


INFORMATION ACCESS AND DISCLOSURE

 

Does NFA share Information?
NFA only discloses your Information to third parties under the following circumstances:

  • When NFA uses service providers who assist us in meeting business operation needs, including hosting, delivering, or improving our App or Services. We also use service providers for specific services and functions, including email communication, customer support services, payment processing, cloud storage, and analytics. These service providers have access, process, or store your Information to the extent necessary to perform their duties to us;

  • When NFA has your explicit consent to share your Information; or

  • When NFA determines that the access, preservation, or disclosure of your Information is required by law to protect the rights, property, or personal safety of NFA and users of our Services, or to respond to lawful requests by public authorities, including national security or law enforcement requests.

 

NFA does not sell or rent your Information.


Third-Party Applications and Plugins.
Depending on your use of our Services, third parties such as Zendesk, Google, Pardot, or Access Development may process your Information. Accordingly, please refer to Zendesk’s privacy policy, Google’s privacy policy, Pardot’s privacy policy, and Access Development’s privacy policy. You should keep in mind that no Internet transmission is ever completely secure or error-free. In particular, e-mail sent to or from this Website may not be secure.

 

Additionally, you may choose to use the services of a third-party payment processor or payment gateway to process payments within our Services. In the event that you have made such a choice, your Information may be transferred to such third-party payment processor or payment gateway in order to facilitate any payments or transactions made through our Services.


Communications from NFA.
NFA may occasionally contact you with Information related to events, activities, and membership announcements. In the event you wish to opt out of such communications, you may do so by clicking the “unsubscribe” link found within NFA emails. Please note that you may continue to receive transactional communications related to our Services even if you unsubscribe from NFA’s promotional communications.
 
By using NFA’s Services, you agree to receive essential communications, including account notifications, security alerts, and updates related to NFA’s events and membership programs.


Will NFA ever make any of my Information or user generated content public?
No. NFA will not share your Information or user generated content except in the limited circumstances described in the “Does NFA share my Information?” section above.


Does NFA collect, maintain, or process Information from children?
Our Services are not intended for children under 13 years of age. No one under age 13 may provide any Information to or on the NFA App or Services. NFA does not knowingly collect, maintain, or process Personal Information from children under the age of 13. If NFA determines that we have collected, maintained, or processed Personal Information from a child younger than 13, we will take reasonable measures to remove that Information from our systems. If you are under the age of 13, please do not submit any Personal Information through our Services. NFA encourages parents and legal guardians to monitor their children’s Internet usage and to help enforce this Policy by instructing their children never to provide Personal Information through our Services without the parents’ or guardians’ permission.


DATA STORAGE, TRANSFER, RETENTION, AND DELETION

 

How is my Information stored?
Information submitted to NFA will be transferred to, processed, and stored in the United States unless otherwise required by law. When you use our Services, Information and user generated content may be stored locally on that device and synced with NFA’s servers. If you post or transfer any Information to or through our App, you are agreeing to such Information, including any Personal Data or user generated content, being hosted, and accessed in the United States. Furthermore, some technical data may also be processed by our Software Provider for operational purposes.


How secure is my Information?
NFA is committed to protecting the security of your Information and takes reasonable precautions to protect it. However, data transmissions over the Internet, whether wired or wireless, cannot be guaranteed to be 100% secure. As a result, NFA cannot ensure with 100% certainty the security of Information you transmit to us, including Personal Data or user generated content. Accordingly, you acknowledge and agree that you do so at your own risk.
In order to minimize the security risk to your Information, NFA and our Software Provider use industry-standard encryption to protect your data in transit. This is commonly referred to as transport layer security (“TLS”) or secure socket layer (“SSL”) technology.
The security of the data stored locally in our App installed on your devices requires that you make use of the security features of your device. We recommend that you take the appropriate steps to secure all devices that you use in connection with our Services.
In the event NFA learns of a security breach, NFA will attempt to notify you and provide Information on protective steps, if available, through our Services. Additionally, we may attempt to contact you through the email address that you have provided to us. Depending on where you live, you may have a legal right to receive such notices in writing.


Deleting your Information from NFA.
NFA allows you to delete your Information that is in our possession. To request that we delete your Information, please send an email to our support team at webmaster@nfaflood.com. Once we have verified your identity, we will be happy to assist in deleting your Information. Additionally, please note that you must delete our App from your device(s) in order complete the deletion process.
Please keep in mind that our deletion of your Information does not delete the Information that was collected by your organization. You will need to contact your organization directly if you wish to have your Information deleted from their records.


How long is my Information retained?
Although you can delete your Information at any time by deleting your account as described above, NFA may keep some of your Information for as long as reasonably necessary for our legitimate business interests, including fraud detection and prevention or to comply with our legal obligations including tax, legal reporting, and auditing obligations.
 
What happens if NFA (or my organization) deletes my account?
In the event NFA or your organization deletes your account, then you may contact NFA or your organization to request deletion of your data. NFA will evaluate such requests on a case- by-case basis, pursuant to our legal obligations.


Your State Privacy Rights.
State consumer privacy laws may provide their residents with additional rights regarding our use of their Personal Information.
California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia provide (now or in the future) their state residents with some variation of rights to:

  • Confirm whether we process their Personal Information.

  • Access and delete certain Personal Information.

  • Correct inaccuracies in their Personal Information, taking into account the Information’s nature processing purpose.

  • Data portability.

  • Opt-out of personal data processing for:

    • targeted advertising;

    • sales; or

    • profiling in furtherance of decisions that produce legal or similarly significant effects.

  • Either limit (opt-out of) or require consent to process sensitive personal data.

 

The exact scope of these rights may vary by state. To exercise any of these rights please email us at webmaster@NFAflood.com


Notice to California Residents.
We comply with the California Consumer Privacy Act (“CCPA”). If you are a resident of California, you have following additional rights available to you, including:
 
The right to access your Personal Information;

  • The right to obtain your Personal Information in a portable format;

  • The right to have your Personal Information deleted from our databases; and

  • The right to refuse us the right to sell your Personal Information;

 

If you would like to make any requests under the CCPA, please email us at info webmaster@nfaflood.com.

 

California law permits users of our Services who are California residents to request certain Information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please write to us at:

 

Email: webmaster@nfaflood.com

 

Our Services collect Information that identifies, relates to, describes, references, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or device.

 

We do not resell Personal Information that we collect from any consumer.

 

We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:

  • Deny you goods or services.

  • Charge you different prices or rates for goods or services.

  • Provide you a different level or quality of goods or services.

  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

 

However, we may offer, and you may consent to receive certain incentives permitted by the CCPA. Any CCPA-permitted incentive we offer will reasonably relate to your Personal Information ’s value and contain written terms that describe the program’s material aspects. You may revoke your consent to participate or receive such financial incentive at any time.

You have the right to request that we disclose certain Information to you about our collection and use of your Personal Information over the past 12 months. Once we receive and confirm your verifiable consumer request, we will disclose to you: (A) the categories of Personal Information we collected about you; (B) the categories of sources for the Personal Information we collected about you; (C) our business or commercial purpose for collecting or selling that Personal Information ; (D) the categories of third parties with whom we share that Personal Information ; (E) the specific pieces of Personal Information we collected about you (also called a data portability request). If we disclosed your Personal Information for a business purpose, we will provide you with a list disclosing such disclosures, identifying the Personal Information categories that each category of recipient obtained.

 

You have the right to request that we delete any of your own Personal Information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your Personal Information from our records, unless an exception applies.

 

An exception to your request may apply if retaining the Information is necessary for us or our Software Provider to:

  • Complete the transaction for which we collected the Personal Information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform our contract with you.

  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.

  • Debug products to identify and repair errors that impair existing intended uses of Information.

  • Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.

  • Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 etc.).

  • Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the Information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.

  • Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.

  • Comply with a legal obligation.

  • Make other internal and lawful uses of that Information that are compatible with the context in which you provided such Information.

 

Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a verifiable consumer request related to your Personal Information. You may also make a verifiable consumer request on behalf of your minor child. You may only make a verifiable consumer request for access or data portability twice within a 12-month period. The verifiable consumer request must: (A) provide sufficient Information that allows us to reasonably verify you are the person about whom we collected Personal Information or an authorized representative; and (B) describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it. We cannot respond to your request or provide you with Personal Information if we cannot verify your identity or authority to make the request and confirm the Personal Information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use Personal Information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.

 

We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to ninety (90) days), we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option. Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your Personal Information that is readily usable and should allow you to transmit the Information from one entity to another entity without hindrance. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.


NFA and the General Data Protection Regulation (“GDPR”)

NFA uses, processes, and stores Personal Data, including those listed in the “Information collected, maintained, and processed.” section above, as necessary to perform our obligations to you or your organization, and based on our legitimate interests in order to provide the various services through our Services. NFA relies on your consent to process
 
Personal Data, to send promotional communications, and to place cookies on your devices. In some cases, NFA may process Personal Data pursuant to legal obligations or to protect your vital interests form those of another person.


Role as a Data Controller and Data Processor
Under the GDPR, NFA acts as a “Data Controller” and as a “Data Processor.” As a Data Controller, NFA is responsible for safeguarding the data of our customers as they interact directly with our Services. As a Data Processor, NFA is responsible for safeguarding the data of our partners’ and customers’ users as it flows through our system.

 

If you have other questions or do not have a NFA account, feel free to contact us by reaching out to our support team at webmaster@nfaflood.com.


WILL OUR PRIVACY POLICY EVER CHANGE?

As NFA continues to grow, we may need to update this Policy in order to keep pace with changes in our Services, our business, and laws applicable to us and you. NFA will, however, always maintain our commitment to respect your privacy. We will notify you of any material changes that impact your rights under this Policy by email (to your most recently provided email address) or post any other revisions to this Policy, along with their effective date, in an easy-to-find area of the App, so we recommend that you periodically check to stay informed of any changes. Please note that your continued use of the App and our Services after any update constitutes acceptance and consent to be bound by the revised Policy. If you disagree with any changes in this Policy and do not wish your Information to be subject to it, you will need to delete your NFA account and our App from your devices
 

bottom of page