Privacy Policy

Language: Português 简体中文 繁體中文

Last updated: June 17, 2026

1. Introduction

Sociocracy For All Network (“SoFAN,” “we,” “our,” or “us”) is committed to protecting the personal data of everyone who interacts with our organization. This Privacy Policy explains what personal data we collect, why we collect it, how we use and store it, and what rights you have in relation to your data.

This policy applies to all services offered by SoFAN, including our newsletter, membership programs, the Professional Partner program, training offerings, our online learning platform, Communities of Practice, consulting, publications, events, volunteer and staff relationships, internal coordination, networking introductions, and donation processing.

We comply with the EU General Data Protection Regulation (GDPR) and applicable data protection laws.

2. Who We Are (Data Controller)

The data controller responsible for your personal data is:

Sociocracy For All Registered Address: 120 Pulpit Hill Rd., Unit 8, Amherst, MA 01002, [email protected], www.sociocracyforall.org

If you have any questions about this policy or wish to exercise your rights, please contact us at the address above.

3. Legal Bases for Processing

We process personal data only when we have a lawful basis to do so. The legal bases we rely on are:

  • Consent — you have given us clear, specific consent to process your data for a stated purpose (e.g., subscribing to our newsletter, registering for a webinar or conference, joining a Community of Practice, or agreeing to be introduced to others in the network).
  • Contract — processing is necessary to fulfill a contract with you (e.g., processing a membership, a Professional Partner agreement, an Academy enrollment, fulfilling an order, or engaging you as staff or a contractor).
  • Legal obligation — processing is required by law (e.g., retaining financial records for tax purposes).
  • Legitimate interests — processing is necessary for our legitimate organizational interests, where those interests are not overridden by your rights (e.g., coordinating internal meetings).

4. What We Collect and Why

4.1 Newsletter

Data collected: name, email address. Purpose: to send our regular newsletter with news, resources, and updates about sociocracy and SoFAN. Legal basis: Consent, given by checking the opt-in box on our newsletter signup form. Consent is recorded by date in our system. You may withdraw consent at any time by clicking the unsubscribe link in any email or by contacting us directly. Retention: retained for as long as you remain subscribed. Upon withdrawal of consent, your data is deleted within 30 days. We will confirm deletion to you in writing upon request.

4.2 Network Membership

Data collected: name, email address, mailing address and telephone number where provided, and payment/banking details where a membership fee applies (processed via our payment processor). Purpose: to administer your membership, provide access to network resources, and send relevant updates. We share your name and email with other members so members can communicate with one another. Legal basis: Contract, governed by our membership terms. Retention: retained for the duration of your membership. On termination, your data is removed from active member systems within 30 days; financial records are retained for the statutory period required by law (commonly 6–10 years).

4.3 Professional Partner Program

Data collected: name, email address, mailing address and telephone number where provided, professional biography, photo or other profile information as provided, and payment details where applicable (processed via our payment processor). Purpose: to administer your partnership agreement and list your profile publicly on our website. We share your name and email with other Professional Partners so you can communicate with one another. With your separate consent, we also share your profile with potential clients and students — this is a distinct purpose from the core partnership and is recorded separately. Legal basis: Contract (core partnership); Consent (profile info and sharing with clients/students). Retention: retained while the Professional Partner relationship is active. Profile data is removed from our website within 30 days of termination (a 30-day notice period applies under the Professional Partner Agreement); financial records are retained per legal obligation.

4.4 Webinars

Data collected: name, email address, and — where the webinar is paid — telephone number where provided and payment details (processed via our payment processor). Purpose: to process your registration and deliver the webinar. We share your name and email with other webinar participants so you can communicate with one another. Legal basis: Consent. Retention: registration data is retained for the event plus a reasonable follow-up window (usually one month), then removed. Where the webinar is recorded, the recording is kept indefinitely as a resource — see Section 4.15 for how recording consent itself is handled.

4.5 Conferences and Events

Data collected: name, email address, and — where the event is paid — telephone number where provided and payment details (processed via our payment processor). Purpose: to process registration, deliver event logistics, and give access to recordings afterward. We share your name and email with other conference attendees so you can communicate with one another. Legal basis: Consent. Retention: retained for the duration of the event and for the period recordings remain available, then deleted. Financial records are retained per legal obligation.

4.6 Academy and Long-Format Training Programs

Data collected: name, email address, mailing address, certification level, and payment information including bank details where applicable (processed via our payment processor where possible; we recommend not storing raw bank details ourselves). Purpose: to administer your training enrollment, support certification, and fulfill financial record-keeping obligations. We share your name and email with other academy students so you can communicate with one another. Legal basis: Contract (governed by a signed enrollment agreement); Legal Obligation (financial records, where payment is made). Retention: course/contact data is retained for the duration of the training and removed one year after training ends if you do not pursue further certification. Certification records are retained for 3 years to support verification. Financial records are retained per applicable law (typically 6–10 years).

4.7 Sutra Learning Platform

Data collected: name, email address, and learning activity (such as course progress and contributions to course discussions or community spaces hosted on the platform). Purpose: to give you access to trainings and community spaces delivered through the Sutra platform. Legal basis: Contract (platform access tied to the underlying service — training, Professional Partner program, or membership). Retention: account and activity data are retained while your account is active. On account closure or a deletion request, your data is removed within 30 days. Sutra hosts this data on our behalf as a processor (see Section 5); we maintain a signed DPA with Sutra and have confirmed their hosting location for cross-border transfer purposes.

4.8 Communities of Practice

Data collected: name, email address. Purpose: to invite you to the Community of Practice that matches your interest and to coordinate those sessions. We share your name and email with other members of the Community of Practice so you can communicate with one another. Legal basis: Consent. Retention: retained while you remain part of the relevant Community of Practice. You may withdraw consent or ask to be removed at any time; your name and email are removed within 30 days of your departure.

4.9 Consulting

Data collected: name, email address, mailing address, and payment details (processed via our payment processor). Purpose: to deliver consulting services and process payment. Legal basis: Contract; Legal Obligation (financial records). Retention: retained for the duration of the engagement. Bank/payment details are removed after the transaction completes; financial records are retained per applicable law. Other contact data is deleted within 30 days of a deletion request, unless you have separately opted into Consent to Network.

4.10 Books and Publications

Data collected: name, email address, delivery address, and payment details (processed via our payment processor). Purpose: to process and fulfill your order and to meet financial record-keeping obligations. We may share your delivery details with a shipping provider for physical copies. Legal basis: Contract (order processing); Legal Obligation (financial records). Retention: order data is retained until the order is fulfilled and any return period has passed, then removed. Financial records are retained per applicable law.

4.11 Donations

Data collected: name, email address, mailing address, and payment/banking details (processed via our payment processor). Purpose: to process your donation, issue receipts, maintain financial records, and maintain our relationship with donors. Legal basis: Consent (general, unrestricted donations); Contract (restricted/designated donations); Legal Obligation (financial records and receipts). Retention: donor relationship data is retained year-to-year to support communication and issue annual receipts. Financial records are retained per applicable law (commonly 7 years). You may withdraw consent or object to relationship communications at any time.

4.12 Staff and Contractors

Data collected: name, email address, telephone/messaging handle, bank account and bank address, home or mailing address, experience and certification level, and photo or video where applicable. (We do not use WhatsApp for organizational communication due to unresolved data protection agreement complications.) Purpose: to communicate, process payments, verify identity and qualifications, and, where agreed, represent you on our website. Legal basis: Contract; Legal Obligation (for paid staff/contractors, financial records). Retention: financial and identity records are retained for the period required by law following termination of the contract (typically 7 years). Public profile data (e.g., facilitator listing) is removed from the website and internal systems (e.g., Peerdom, Google Groups) within 30 days of departure, unless you continue in another role that requires it (e.g., as a Professional Partner), in which case that data is retained under the separate Professional Partner service.

4.13 Internal Meetings

Data collected: name, email address, and telephone or messaging handle where provided. Purpose: to invite participants to internal meetings and coordinate scheduling. Legal basis: Legitimate Interest. Retention: retained while you are part of the relevant group or role; removed when you leave or on objection. Where we coordinate through third-party messaging or project apps (e.g., Slack, Asana, ClickUp), those apps act as separate processors (see Section 5).

4.14 Consent to Network

Data collected: name, email address, and — where you provide them — telephone number, mailing address, and information about your interests. Purpose: where useful, to connect you with peers, consultants, or trainers in the network. Legal basis: Consent, given through our “Consent to Network” form. Consent is recorded by date. Retention: retained until you withdraw consent. On withdrawal or a deletion request, your data is deleted within 30 days; we confirm what was deleted and notify any active referrals within 30 days.

4.15 Recordings, Photographs, and Transcripts

Recordings, screenshots, photographs, chat logs with names, and transcripts are considered personal data under GDPR when they can be used to identify an individual. Data collected: video, audio, image, or text data that may identify participants. Purpose: to document sessions for internal review, training purposes, or shared learning resources, where consent has been obtained. Legal basis: Consent, obtained separately from all identifiable participants before recording begins. Zoom’s built-in consent notification does not replace our obligation to obtain and record explicit consent. Retention: the general default is 90 days, unless intentionally archived. Exception: webinar recordings are retained indefinitely as a standing resource (see Section 4.4). Participants may withdraw consent and request deletion at any time; deletion is completed within 30 days.

5. Data Processors

We use the following third-party data processors to store and process personal data on our behalf. Each processor is contractually required to protect your data in accordance with GDPR.

ProcessorPurposeData Protection Reference
GroundhoggCRM and email marketing (consent records, contact management)https://groundhogg.io/privacy
Google WorkspaceEmail, document storage, forms, and video meetingshttps://policies.google.com/privacy
ZoomVideo conferencing and session recordingshttps://zoom.us/privacy
QuickBooks (Intuit)Financial recordkeeping for paid transactions and donationshttps://intuit.com/privacy
SutraOnline learning platform for training programs and community spaceshttps://sutra.co/dpa
Digital OceanCloud hosting infrastructure for our website and self-hosted systems (e.g., Groundhogg)https://www.digitalocean.com/legal/privacy-policy
WooCommerceE-commerce processing for memberships, training, events, publications, and donationshttps://automattic.com/privacy/
AsanaProject and task management (may contain names and email addresses of staff, volunteers, clients, and collaborators)https://asana.com/terms/data-processing
SlackInternal team communication (may contain names and contact info of staff and volunteers)https://slack.com/trust/privacy/privacy-policy
ClickUpInternal project coordination (may contain names and contact info of staff and volunteers)https://clickup.com/terms/privacy
Shipping provider (for physical books/publications)Delivery of physical orders
Stripe / PayPal (Payment Processors)Processing payments for memberships, training, events, publications, donations, and consultinghttps://stripe.com/en-mx/privacyhttps://www.paypal.com/us/legalhub/paypal/privacy-full

We maintain signed Data Processing Agreements with each processor. These documents are stored internally and are available upon request.

Note: WhatsApp is not used as an organizational communication or data-storage tool due to unresolved GDPR/DPA concerns for organizational use.

6. Your Rights

Under GDPR, you have the following rights in relation to your personal data:

  • Right of access — you may request a copy of the personal data we hold about you.
  • Right to rectification — you may request correction of inaccurate or incomplete data.
  • Right to erasure — you may request deletion of your personal data (“right to be forgotten”), subject to legal retention obligations.
  • Right to restrict processing — you may request that we limit how we use your data in certain circumstances.
  • Right to data portability — you may request your data in a structured, machine-readable format.
  • Right to object — you may object to processing based on legitimate interests.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us using the details in Section 2. We will respond within 30 days. We may need to verify your identity before fulfilling a request.

If you believe your rights have not been respected, you have the right to lodge a complaint with your national data protection authority.

7. Data Security

We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or disclosure. These measures include:

  • Access controls limiting who within SoFAN can view personal data for each service.
  • Use of secure, GDPR-compliant third-party processors (see Section 5).
  • Regular review of retained data to identify and delete records that are no longer needed.

Despite these measures, no transmission of data over the internet is completely secure. If you believe your data has been compromised, please contact us immediately.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, or as required by law. Specific retention periods are set out in Section 4 for each service.

When data is deleted, we remove it from all active systems within 30 days of the deletion trigger (withdrawal of consent, end of contract, or data subject request). We maintain a log of deletions for accountability purposes.

Financial records are subject to legal minimum retention periods that vary by jurisdiction. We cannot delete financial records before the legally required period has elapsed, but we will restrict their use to legal compliance purposes only.

9. Cookies and Website Data

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of all cookies our site uses.

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.

Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Analytics”.
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category “Functional”.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Necessary”.
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Other”.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category “Performance”.
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
wp_woocommerce_session_SessionThis cookie is set by WooCommerce to store and maintain shopping cart contents and session state while browsing the store.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedback, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify relevant contacts by email and update the “Last updated” date at the top of this document. We encourage you to review this policy periodically.

Where a change affects the basis on which we process your data, we will seek fresh consent where required.

11. Contact Us

For questions about this policy, to exercise your rights, or to report a privacy concern, please contact:

Privacy Contact — Sociocracy For All Privacy Officer, [email protected];  120 Pulpit Hill Rd., Unit 8, Amherst, MA 01002

We aim to respond to all privacy-related inquiries within 5 business days and will resolve all data subject requests within 30 days.