Data Protection & Privacy Rights

Your privacy rights under GDPR (EU/EEA/UK) and U.S. state privacy laws, and how the Sculpting Choices Autism Foundation processes and protects your personal data.

Last updated: October 1, 2026

Our Privacy Commitment

Sculpting Choices Autism Foundation, Inc. (“the Foundation,” “we,” “us”) is committed to protecting the privacy and personal data of all users of the SCAIP™ platform. This notice describes your rights under both the EU General Data Protection Regulation (Regulation (EU) 2016/679) — for individuals in the European Economic Area (EEA), the United Kingdom, and Switzerland — and under U.S. state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), and Connecticut Data Privacy Act (CTDPA), where applicable.

Data Controller

The Foundation is the data controller for personal data processed through the SCAIP™ platform:

Sculpting Choices Autism Foundation, Inc.

1305 Hardeman Ave, Suite 200

Macon, GA 31201, USA

president@sculptingchoicesfoundation.org

478-777-0729

Data Protection Officer

Our Data Protection Officer (DPO) oversees GDPR compliance and is your point of contact for data protection matters:

[DPO Name — to be appointed]

A Data Protection Officer will be formally designated before processing personal data of EU/EEA residents at scale.

dpo@sculptingchoicesfoundation.org

Legal Basis

Lawful Basis for Processing

We only process your personal data when we have a valid legal basis under GDPR Article 6.

Consent

You have given clear consent for us to process your personal data for a specific purpose (e.g., newsletter sign-up, event registration).

Contract

Processing is necessary to provide a service you requested (e.g., account creation, donation processing, messaging).

Legal Obligation

We must process data to comply with a legal or regulatory obligation (e.g., financial record-keeping, nonprofit reporting).

Legitimate Interests

Processing is necessary for our legitimate interests (e.g., platform security, fraud prevention) and does not override your rights.

What We Process

Categories of Personal Data

The types of personal data we process, why, and how long we keep it.

Identity Data

Examples

Name, email address, account type, organization name

Purpose

Account creation, authentication, role-based access

Retention

Duration of account + 30 days post-deletion request

Profile & Family Data

Examples

Client/child name, date of birth, diagnosis status, roadmap notes

Purpose

Enabling family roadmap, client profile management

Retention

Until user deletes the record or requests erasure

Communication Data

Examples

Secure messages, referrals, contact form submissions

Purpose

Facilitating secure messaging and inter-organization referrals

Retention

Duration of account; deletable by the user at any time

Usage & Technical Data

Examples

Analytics events, IP address, browser type, page views

Purpose

Platform improvement, security monitoring, troubleshooting

Retention

Aggregated indefinitely; individual records up to 24 months

Financial Data

Examples

Donation amount, transaction reference, receipt details

Purpose

Processing donations and issuing tax receipts

Retention

7 years per IRS nonprofit record-keeping requirements

Cookie & Tracking Data

Examples

Session ID, consent preferences, analytics identifiers

Purpose

Maintaining sessions and measuring platform usage

Retention

Session cookies expire on close; consent stored 12 months

Your Rights

Your Rights Under GDPR

Eight fundamental rights — here is what each one means for you.

Right of Access (Art. 15)

You can request a copy of the personal data we hold about you and information about how it is processed.

Right to Rectification (Art. 16)

You can ask us to correct inaccurate or incomplete personal data. Account holders can edit most information directly in their dashboard.

Right to Erasure (Art. 17)

Also known as the 'right to be forgotten.' You can request deletion of your personal data, subject to legal retention obligations.

Right to Restriction (Art. 18)

You can request that we restrict processing of your data temporarily — for example, while a correction request is being reviewed.

Right to Data Portability (Art. 20)

You can receive your personal data in a structured, machine-readable format and transmit it to another service provider.

Right to Object (Art. 21)

You can object to processing based on legitimate interests or for direct marketing. We will stop unless we have compelling grounds.

Rights Regarding Automated Decisions (Art. 22)

You have the right not to be subject to decisions based solely on automated processing that significantly affect you.

Right to Lodge a Complaint (Art. 77)

You can lodge a complaint with your local data protection supervisory authority if you believe your rights have been violated.

U.S. State Rights

Your Rights Under U.S. State Privacy Laws

If you are a U.S. resident, state privacy laws may give you the following rights. Most state laws exempt nonprofit organizations, but we honor these rights voluntarily as a best practice.

Right to Know / Access

You can request a copy of the personal data we collect about you, the categories of data, the purposes for processing, and the third parties with whom we share it (CCPA §1798.110, VCDPA §59.1-578).

Right to Delete

You can request deletion of personal data we hold about you, subject to legal retention obligations (CCPA §1798.105).

Right to Correct

You can request correction of inaccurate personal data. Account holders can edit most information directly in their dashboard (CPRA §1798.106, VCDPA §59.1-579).

Right to Opt-Out of Sale or Sharing

You can direct us not to “sell” or “share” your personal data for cross-context behavioral advertising or other targeted purposes (CCPA §1798.120, CPRA §1798.140).

Right to Opt-Out of Targeted Advertising

You can opt out of the processing of your personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects (VCDPA, CPA, CTDPA).

Right to Limit Use of Sensitive Data

You can limit the use of sensitive personal data (such as health data) to what is necessary to provide the service or as otherwise permitted (CPRA §1798.121).

Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights — you will not receive a different level of service or be charged a different price (CCPA §1798.125).

Right to Appeal

If we decline to act on your request, you may appeal our decision within a reasonable period. You also have the right to contact your state Attorney General (VCDPA §59.1-580, CPA, CTDPA).

Cross-Border

International Data Transfers

Your data may be processed outside the EEA — here is how we protect it.

Transfer Safeguards

  • Data is hosted on cloud infrastructure located in the United States.
  • Where data is transferred outside the EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
  • We only share data with processors who provide adequate safeguards and have signed appropriate data processing agreements.
  • You will be notified of any material changes to our data transfer arrangements.
Take Action

Exercise Your Rights — EU & U.S.

Submit a privacy rights request under GDPR or U.S. state law. We will respond within 30 days (GDPR) or 45 days (CCPA), as required by applicable law.

We will verify your identity before disclosing or modifying personal data. You do not need to provide a reason for most requests. Under GDPR, there is no fee unless the request is manifestly unfounded or excessive. Under CCPA, we will not charge a fee and will respond within 45 days. Authorized agents may submit requests on behalf of a consumer with written permission.

Managing Cookies

You can manage your cookie preferences at any time. The consent banner appears on your first visit; once you have made a choice, you can reset your preferences by clearing your browser's local storage for this site, which will show the banner again.

Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local data protection supervisory authority. In the EU, each member state has its own authority — find yours at edpb.europa.eu. If you are a U.S. resident, you may contact your state Attorney General’s office. We encourage you to contact us first so we can address your concerns directly.

Important Notice

This Data Protection notice is provided for transparency and is not a substitute for formal legal or compliance counsel. The Foundation is a U.S.-based nonprofit organization; GDPR applies to the extent we process personal data of individuals in the EEA, UK, or Switzerland. Most U.S. state privacy laws exempt nonprofit organizations, but we honor consumer rights voluntarily as a best practice. This document will be reviewed by legal counsel before formal adoption.