GDPR & Data Protection

360Alumni is committed to protecting personal data and supporting our clients’ compliance with the General Data Protection Regulation (GDPR).

When an organization uses 360Alumni to manage personal data on behalf of its alumni or other constituents, the client generally acts as the data controller and 360Alumni acts as the data processor. 360Alumni processes personal data on behalf of and according to the instructions of our clients.

360Alumni provides technical, organizational, and product safeguards designed to support GDPR requirements, including data security, access controls, individual privacy controls, data access and portability, correction, deletion, and communication preference management.

The information below describes how 360Alumni supports our clients’ GDPR compliance. It is provided for informational purposes and is not legal advice.

Our clients determine what personal data is maintained in 360Alumni and the purposes for which it is processed. 360Alumni processes that data to provide and support our services in accordance with our agreements and documented client instructions.

Our Data Processing Agreement (DPA) establishes the respective responsibilities of the client as data controller and 360Alumni as data processor and addresses security, confidentiality, data subject requests, subprocessors, international data transfers, data deletion, and audit rights.

360Alumni maintains technical and organizational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access.

Our security practices include:

  • Authentication and authorization controls
  • Role-based and permission-based access to data and administrative functionality
  • Encryption of data in transit
  • Network and application security controls
  • Web application firewall protection
  • Logging, monitoring, and incident response procedures
  • Vulnerability management, security testing, and penetration testing
  • Backup, replication, and availability protections
  • Access controls for 360Alumni personnel
  • Confidentiality obligations for personnel authorized to process personal data

Additional information about our security practices and safeguards is available upon request.

360Alumni provides tools and support to help clients respond to individuals exercising their rights under GDPR.

Authorized administrators can export personal data maintained in 360Alumni. 360Alumni also provides  assistance to clients when additional information or assistance is needed to respond to an authorized data subject request.

Users can update much of their own profile information directly within 360Alumni, and authorized administrators can update information on behalf of constituents. This enables inaccurate or incomplete information to be corrected.

360Alumni supports clients in responding to authorized requests for deletion of personal data. Where certain records must be retained for legitimate business, financial, contractual, or legal purposes, identifying information may be anonymized where appropriate.

Following the termination or expiration of a client’s agreement, personal data is deleted or returned in accordance with the applicable agreement, DPA, and legal requirements.

360Alumni provides granular privacy controls that allow users to manage the visibility of their information. Users can also manage applicable email and notification preferences within the platform.

As data controller, each client is responsible for determining the appropriate lawful basis for its processing activities and for obtaining consent where consent is the applicable lawful basis.

360Alumni provides configurable profile fields, communication preferences, privacy settings, and other tools that clients can use as part of their data protection processes.

Clients determine which communications they send through 360Alumni and are responsible for ensuring that their communications and processing activities are consistent with applicable legal requirements and their own privacy policies.

Clients determine what constituent information they collect and maintain within 360Alumni. The platform can be configured to reflect an organization’s data requirements, allowing clients to collect information appropriate to their alumni engagement programs rather than requiring a fixed set of personal information.

Users can also maintain and update their own information, helping organizations keep constituent data current and accurate.

360Alumni uses selected third-party service providers to support the operation and delivery of our services.

Subprocessors that process personal data on behalf of 360Alumni are subject to applicable contractual and data protection obligations. 360Alumni remains responsible for the performance of its subprocessors as provided in our DPA.

Our current list of subprocessors is available as part of our Data Processing Agreement, and additional information is available upon request.

360Alumni is based in the United States, and personal data processed through our services may be transferred to and processed in the United States and other countries in which our subprocessors operate.

For personal data subject to GDPR, 360Alumni maintains contractual and organizational measures designed to support lawful international transfers in accordance with applicable data protection requirements.

Additional information about international data transfers and applicable safeguards is provided in our Data Processing Agreement.

360Alumni maintains procedures for identifying, investigating, and responding to security incidents involving personal data.

If 360Alumni becomes aware of a personal data breach affecting client personal data, we notify the affected client in accordance with the requirements and timeframes established in our Data Processing Agreement and provide reasonable assistance to support the client’s applicable notification obligations.

Clients control the constituent records maintained within their 360Alumni communities and can request deletion of personal data when it is no longer required.

360Alumni may retain certain information when necessary to meet contractual, security, financial, or legal obligations. Where appropriate, personal information may be anonymized while required non-personal records are retained.

Upon termination or expiration of services, client personal data is handled in accordance with our Data Processing Agreement and applicable legal requirements.

360Alumni uses cookies and similar technologies to provide, secure, and improve our services. Additional information about the cookies and similar technologies used by 360Alumni and the choices available to users is provided in our Cookie Notice.

360Alumni offers a Data Processing Agreement (DPA) to clients subject to GDPR and other applicable data protection requirements.

The DPA addresses:

  • The roles and responsibilities of 360Alumni and our clients
  • Processing of personal data
  • Technical and organizational security measures
  • Confidentiality
  • Data subject requests
  • Personal data breaches
  • Subprocessors
  • International data transfers
  • Data return and deletion
  • Audit and compliance rights

We are happy to work with clients and prospective clients conducting privacy, security, or vendor due diligence and can provide additional information about our privacy and security practices upon request.

For our Data Processing Agreement or additional information about 360Alumni’s data protection practices, please contact support@360alumni.com.