Updated: May 24, 2018

C40 Cities Climate Leadership Group, Inc. and its Affiliates (collectively, “we” “us” or “C40”) are committed to protecting and respecting the privacy of the individuals who help us fulfil our charitable mission. Our Affiliates are:

  • C40 Cities Climate Leadership UK, a charity registered in England and Wales with company number 10401717 and charity number 1173124 whose registered office is at 3 Queen Victoria Street, London, EC4N 4TQ, UK.
  • C40 Cities Climate Leadership South Africa NPC, a Non Profit Company registered in South Africa with a company number of 2017/243962/08 whose registered office is at Traduna House, 118 Jorissen Street, Braamfontein, 2001 Gauteng, South Africa.

Each of these Affiliates may be data controllers of your personal information and it may be shared internally between these Affiliates to achieve the purposes set out below.

Please read the following carefully to understand how C40 uses your personal information and for information about your privacy rights.

This Privacy Notice applies to C40.org and any other C40 sites, forms, or services, in addition to any event attendance or general interactions with C40 or its representatives (collectively “ C40 Services ”).

What personal information do we collect and process?

The personal information we may collect includes name, email address, employer, job title, business address, telephone number, location or any additional information you elect to provide directly to us.

In providing C40 Services, we may also log technical information such as you Internet Protocol (IP) address, browser type, cookie information, access times and device type.

How do we collect personal information?

We obtain personal information from when you provide it directly to us, for example when you engage with our staff, fill in a form on our website, or use C40 Services. We also obtain personal information indirectly from you when you visit our websites, including technical information about your device and browsing such as IP address and your interactions with the sites, and via cookies.

We may also receive information about you from third parties , for example from one of our member cities (see www.c40.org/cities ), partner organizations, or from individuals or third party organisations who share our charitable interests and may introduce you to us.

We may collect your information from publicly available sources, such as your organisation’s or employer’s website (for example, your business contact details including your email address). Depending on your privacy settings for social media services, we may access information from those accounts or services, including from LinkedIn, Facebook, Instagram and Twitter.

In general, we may combine your personal information from these different sources to use in accordance with purposes listed in this Privacy Notice.

How and why do we use this personal information?

We may use your personal information in a number of ways, including:

  • to promote C40’s charitable and educational mission (including to hold a list of relevant city contacts and to communicate with and network with and between them in pursuit of our mission);
  • to provide you with services or information that you have requested and to communicate with you in general;
  • to facilitate your, or your organization’s, participation in C40’s network or one of our programs and/ or events – and to administer those programs and events;
  • to provide you with information about our charitable activities, including C40 and third party events, work and other services related to our charitable and educational mission that we think may be of interest to you.
  • to analyse and improve our work, including our services and activities and to report on the impact and effectiveness of our work.
  • for administration purposes including to create an account for you if you register with us; to notify you about changes to C40 Services; to keep C40 Services safe and secure; and to ensure that content is presented in the most effective manner.
  • for company administration purposes including to satisfy legal obligations which are binding on us (e.g. in relation to tax and law enforcement bodies), for the prevention of fraud or misuse of services, and for the establishment, defence and/ or enforcement of legal claims.
  • We may provide you separately with specific further information about our use of your personal information (for example if you apply to work at C40). Also, if we anticipate processing your information in a way that could reasonably be considered outside of what of what you could reasonably expect, then we will notify you in advance, obtain your consent, where appropriate, or refrain from processing your information in the new way.

What is our lawful basis for using your personal information?

The General Data Protection Regulation (GDPR), where it applies to our activities, requires us to rely on one or more lawful basis to process your personal information. The following are relevant to us:

  • Where you give consent (for example, to receive our newsletter).
  • We have entered into a contractual arrangement or taken steps at your request prior to entering into one (with you).
  • Where necessary to comply with a legal obligation to which we are subject.
  • Where there is a legitimate interest in us doing so provided our use is fair, balanced and does not unduly impact your rights and freedoms – in general, C40’s legitimate interests are aimed at furthering our charitable and educational mission (for example, company governance and reporting, delivering services and programs, and networking and campaigning).

Do we share your personal information with anyone else?

We provide your information to our contractors, suppliers and partners who provide services on our behalf, or with whom we collaborate, to the extent necessary to enable us to provide you C40 Services – provided we are satisfied that they provide sufficient guarantees in respect of safeguarding your personal information and privacy rights, and that we have in place an appropriate agreement with them.

We may also share your information between our Affiliates (described in the introduction to this Notice), in accordance with applicable data protection law and where appropriate to deliver our charitable mission and C40 Services.

We may also need to disclose your information to local authorities or law enforcement agencies, if required to do so by law, or as expressly permitted under relevant data protection regulations. If we merge or undergo a reorganisation, in doing so we may acquire or transfer personal information as part of that transaction but your personal information would continue to be used for the same purposes.

International Transfers

As an international organization, we will occasionally need to transfer data outside the European Economic Area – including between C40’s Affiliates and branch offices but also when we use suppliers and engage with other third parties based outside the European Economic Area. Please note that some countries outside of the EEA may have a lower standard of protection for personal information, including lower security requirements and fewer rights for individuals. In these instances, adequate safeguards, such as European Commission-approved contractual clauses and technical measures, have been put in place to adequately protect personal information.

Security

C40 is committed to keeping your personal information safe and secure. We take appropriate and proportionate measures to ensure that your personal information is kept secure and to prevent its loss, destruction and misuse. We use strict procedure and security features, such as encryption, permission controls, and audit logging, to ensure your data is handled securely. However, you should be aware that the transfer of information over the Internet is not entirely secure and although we will do our best to protect your personal data we cannot guarantee the security or integrity of any personal information which is transferred online from or to you.

Cookies

Our website uses cookies to distinguish you from other users of our website. This helps us to provide you with a good experience when you browse our website and also allows us to improve our site.

Your privacy rights and choices

If we rely on your consent to use your personal information (for example if you sign up for one of our newsletters and consent to us providing you with marketing information), you can withdraw that consent (including the right to ‘opt–out’ of our using your information for marketing purposes generally) at any time by emailing privacy@c40.org or by clicking “Unsubscribe” at the bottom of any marketing email.

You also have the following rights:

  • To request from us access to (including a copy of) your personal information.
  • To ask us to update your personal information if it is inaccurate (and you can ask us to check if you are unsure)
  • To ask us to delete your personal information in some cases.
  • To ask us to restrict processing, if there is disagreement about its accuracy or legitimate usage.
  • To object to processing where we are (i) relying on the basis of legitimate interests, or (ii) using your personal information for direct marketing or (iii) using your personal information for statistical purposes.
  • To data portability in certain circumstances - where we are processing your personal information (i) on the basis of your consent, (ii) because the processing is necessary for the performance of a contract with you or to take steps at your request prior to entering into a contract, and the processing is carried out by automated means, you may ask us to provide it to you or another service provider in a machine-readable format.

To exercise your rights, email privacy@c40.org. Please note that these rights are subject to exemptions and may only apply in limited circumstances. We may also ask for additional information to confirm your identity and for security purposes before we are able to comply.

If your data is subject to the GDPR, you have the right to lodge a complaint to the Supervisory Authority in your country, if you believe that we have not complied with the requirements of the GDPR with regards to your personal information (in the UK, for example, this would be the Information Commissioner’s Office, or ICO – www.ico.org.uk/global/contact-us ).

How long will we keep your personal information?

In general terms, we will retain your information for as long as necessary to fulfil the purposes for which it was collected and/ or it is used. However, if before that date (i) your personal information is no longer required in connection with such purpose(s), (ii) we are no longer lawfully entitled to process it or (iii) you validly exercise your right of deletion (please see section 10 above), we will remove it from our records at the relevant time.

Where required, in some cases we will keep personal information at least as long as necessary to comply with relevant regulatory or statutory requirements. We will also retain information, when and as long as necessary, to resolve legal disputes.

Changes to this notice

Any changes we may make to this Privacy Notice in the future will be posted on this page and, where appropriate, notified to you by e-mail. Please check back frequently to see any updates or changes to our Privacy Notice.

Contact Us

Any questions about this Privacy Notice or the ways in which your information is being used should be addressed to privacy@c40.org or ATTN: C40 Legal Department, 120 Park Ave, Floor 23, New York, NY 10017.