Privacy Policy

Last updated: July 3, 2026

Privacy Policy Highlights

This summary is provided for convenience only and does not replace the full Policy below.

  • We collect information you give us directly (contact form, donations, newsletter, applications) and basic technical server logs. A cookie banner lets you control optional analytics cookies; strictly necessary cookies only remember your choice.
  • We never sell or share your personal information with third parties for their marketing purposes.
  • Payment card details for donations are handled by our third-party payment processor, not stored on our own servers.
  • You can request access to, correction of, or deletion of your personal information at any time by emailing [email protected].
  • This Policy applies only to information collected through this website — not to beneficiary or patient data handled in the field by AMA's local implementing partners.

Introduction

Alliance for Medical Access ("AMA," "we," "us," or "our") respects your privacy and is committed to protecting the personal information of everyone who interacts with us — including website visitors, donors, prospective partners, job applicants, volunteers, journalists, and members of the public at large.

This Privacy Policy ("Policy") explains, in clear and complete language, what information we collect through our website at amedicalaccess.org (the "Site"), why we collect it, the legal grounds on which we rely, how we use and safeguard it, how long we retain it, with whom it may be shared, and what rights you have over it. We have written this Policy to meet the standard of transparency that leading organizations apply to their own privacy practices, while remaining honest and specific about what AMA, as a mid-sized nonprofit consortium, actually does today.

By visiting or otherwise using the Site, you acknowledge that you have read and understood this Policy. If you do not agree with our practices as described here, we ask that you refrain from using the Site, or that you contact us directly so we can try to address your concerns.

This Policy is intended to be read together with any additional notices we may provide at the specific point of data collection (for example, next to a form field), which will always take precedence in case of any inconsistency for that specific interaction.

Who We Are

Alliance for Medical Access is a U.S. 501(c)(3) nonprofit organization (EIN 32-0841542), incorporated in the State of Wyoming, with its registered address at:

30 N Gould St, Ste N
Sheridan, WY 82801
United States of America

AMA operates as a consortium and fiscal sponsor advancing equitable healthcare access. AMA has established partner relationships in six countries — Nigeria, Kenya, the Democratic Republic of Congo, Burkina Faso, Togo, and South Sudan — and has identified Benin, Cameroon, Myanmar, and Nepal as expansion priorities for future consortium development. We design, fund, coordinate, and provide technical and administrative support to a network of vetted local implementing partner organizations. AMA itself does not maintain a direct clinical or field presence; program delivery on the ground is carried out by our local partners.

Our institutional governance is overseen by our Board of Directors, which holds ultimate responsibility for AMA's compliance framework, including this Policy. AMA maintains a broader internal governance framework — covering areas such as data protection, IT security, incident management, child and vulnerable-adult protection, and financial management — of which this public-facing website Policy forms one part.

For the purposes of applicable data protection laws, AMA is the Data Controller (or, under some U.S. state laws, the "Business") with respect to the personal information described in this Policy, unless otherwise stated.

Scope of This Policy

This Policy applies to personal information collected through the Site, including through our contact form, donation pages, newsletter subscription mechanism, and any online applications for volunteering, employment, or institutional partnership.

This Policy does not cover the following, which are governed separately:

  • Beneficiary, patient, or clinical data collected in the field. Health-related and program-related data concerning the individuals and communities served by AMA-supported programs is collected, held, and processed directly by our local implementing partner organizations, under their own institutional data protection obligations and the applicable law of the country in which they operate. Because AMA is a consortium and fiscal sponsor without direct field presence, AMA does not itself directly collect, store, or process such clinical or beneficiary-level data, and this Policy should not be read as describing the handling of that data. If you are a beneficiary or community member with questions about how a specific local partner handles your information, we encourage you to contact that partner directly; we are also happy to facilitate an introduction.
  • Third-party websites and services that may be linked from or integrated with the Site, including social media platforms and our payment processor's own hosted checkout pages, each of which maintains its own privacy policy (see Section 16).
  • Internal employment and personnel records of AMA's own staff, board members, consultants, and contractors, which are addressed by our internal Human Resources and Recruitment Policy and any individual employment or engagement agreements.
  • Information exchanged during grant, banking, and institutional due diligence processes through channels other than the Site (for example, direct email or dedicated grant portals), which are handled under the specific confidentiality terms applicable to those relationships.

Definitions

For clarity throughout this Policy, the following terms have the meanings set out below. Not every term is relevant to every visitor, but we include a fuller set of definitions in the interest of transparency and consistency with international practice.

  • "Personal Data" / "Personal Information" — any information relating to an identified or identifiable natural person, such as a name, email address, telephone number, billing address, or online identifier.
  • "Special Category Data" / "Sensitive Personal Information" — personal data revealing racial or ethnic origin, religious or philosophical beliefs, health information, sexual orientation, biometric or genetic data, or similar categories entitled to heightened protection under applicable law. AMA does not knowingly collect Sensitive Personal Information from Site visitors through the Site itself.
  • "Processing" — any operation performed on personal data, whether or not by automated means, including collection, recording, storage, use, disclosure, or deletion.
  • "Data Controller" / "Business" — the entity that determines the purposes and means of processing personal data. AMA is the Data Controller for the data described in this Policy.
  • "Data Processor" / "Service Provider" — a third party that processes personal data on behalf of, and under the instructions of, the Data Controller.
  • "Consent" — a freely given, specific, informed, and unambiguous indication of your wishes, by which you signify agreement to the processing of your personal data.
  • "Legitimate Interest" — a lawful basis for processing that relies on AMA's or a third party's legitimate business or organizational interest, balanced against your own rights and freedoms.
  • "Sale" (as defined under U.S. state privacy laws such as the CCPA) — generally, the exchange of personal information for monetary or other valuable consideration. AMA does not sell personal information.
  • "Sharing" (as defined under the CCPA/CPRA) — generally, disclosing personal information for cross-context behavioral advertising. AMA does not share personal information for this purpose.
  • "Cookie" — a small text file placed on your device by a website to store information about your visit or preferences (see Section 9).
  • "Profiling" — automated processing of personal data to evaluate certain personal aspects, such as behavior, interests, or preferences.
  • "Pseudonymization" — processing personal data such that it can no longer be attributed to a specific person without additional information kept separately and securely.
  • "Site" — the website located at amedicalaccess.org and any subdomains thereof.
  • "You" / "User" / "Data Subject" — any individual who visits, browses, or otherwise interacts with the Site.

Information We Collect

We collect information in three principal ways: information you provide to us directly, information collected automatically through your use of the Site, and, occasionally, information we receive from other sources.

Information You Provide Directly

Contact Form. When you use our contact form, we collect your name, email address, and the content of your message, along with any other information you voluntarily choose to include.

Donations. When you make a donation through the Site, we collect the information necessary to process and acknowledge your contribution, which may include your name, email address, billing address, donation amount, and whether the gift is one-time or recurring. Payment card and bank account details are collected and processed directly by our third-party payment processor; AMA does not store full payment card numbers on its own servers. If you would like this Policy to name our current payment processor explicitly, we are glad to update this section accordingly.

Newsletter Subscription. If you subscribe to our newsletter or mailing list, we collect your email address and, where provided, your name, in order to send you updates about AMA's work. You may unsubscribe at any time using the link included in every email we send, or by contacting us directly.

Volunteer, Employment, and Partnership Applications. If you apply to volunteer with AMA, apply for a position, or reach out regarding a potential institutional partnership, we collect the information you submit, which may include your name, contact details, resume or curriculum vitae, cover letter, areas of expertise, and any references, writing samples, or supporting documents you choose to share.

Grant, Donor, and Institutional Correspondence. If you represent a foundation, grant-making body, financial institution, or partner organization and correspond with us regarding funding, due diligence, or collaboration, we retain that correspondence and any supporting documents exchanged, for legitimate recordkeeping, audit, and compliance purposes.

Event or Survey Participation. If AMA invites you to complete a survey, register for a webinar, or take part in a similar activity connected to the Site, we will collect the information you provide as part of that specific activity and will describe any additional processing at the point of collection.

Categories of Personal Information (Summary Table)

The table below summarizes the categories of personal information we may collect through the Site, consistent with the categories referenced in some U.S. state privacy laws.

CategoryExamplesSourceCollected?
IdentifiersName, email address, IP addressYou, directly; automaticallyYes
Contact informationMailing address, phone numberYou, directlyYes, if provided
Financial / payment informationBilling address, donation amount, payment card dataYou, directly; payment processorYes (card data handled by processor)
Professional / employment informationResume, cover letter, work historyYou, directlyYes, for applicants
Internet or network activityLog data, browser type, pages visitedAutomaticallyYes (baseline logs only)
Commercial informationDonation historyYou, directlyYes, for donors
Geolocation data (general, non-precise)Country or region inferred from IP addressAutomaticallyLimited
Precise geolocationGPS coordinatesNo, not collected
Biometric informationFingerprints, facial recognition dataNo, not collected
Health informationMedical or health recordsNo, not collected through the Site
Government identifiersSocial Security Number, passport numberNo, not collected through the Site
Sensitive Personal InformationRacial/ethnic origin, religious beliefs, sexual orientationNo, not knowingly collected

Information Collected Automatically

Log and Device Data. Like virtually all websites, our web server automatically records certain technical information whenever you visit the Site, typically including your IP address, browser type and version, operating system, device type, referring and exit pages, and the date and time of your visit. This information is used for security, troubleshooting, and to keep the Site functioning correctly; it is not used to build individual marketing profiles.

Cookies and Similar Technologies. As described in detail in Section 9, AMA uses only a strictly necessary cookie by default. Google Analytics (an analytics cookie) activates only if you explicitly consent to it through the cookie banner; AMA does not deploy web beacons, pixel tags, or advertising technologies on the Site beyond that.

Information from Other Sources

On occasion, we may receive limited information about you from third parties — for example, if a partner organization, Rotary club, or peer nonprofit introduces us to a prospective donor or collaborator, or if publicly available information (such as a foundation's own website) helps us verify the details of an institutional partner during due diligence. We use such information only for the legitimate purposes described in this Policy.

Information We Do Not Collect

For clarity, and consistent with the table above, AMA does not knowingly collect through the Site: government identification numbers, precise geolocation data, biometric identifiers, health or medical information about Site visitors, or Special Category/Sensitive Personal Information. If you include such information voluntarily in a free-text field (for example, in a message to us), we will handle it with heightened care and delete it once it is no longer needed for the purpose for which it was shared.

Notice at Collection Summary

For visitors in jurisdictions that require a consolidated "notice at collection," the table below summarizes, at a glance, what we collect at each point of interaction, the purpose, and the applicable retention approach (cross-referencing Sections 7 and 10 for full detail).

Point of CollectionCategories CollectedPurposeRetention
Contact formIdentifiers, contact informationRespond to inquiriesSee Section 10
DonationIdentifiers, financial/payment informationProcess donation, complianceSee Section 10
Newsletter sign-upIdentifiers (email)Send communicationsUntil unsubscribe
Application formsIdentifiers, professional informationEvaluate applicationSee Section 10
Automatic (all visitors)Internet/network activity (log data)Security, functionalityLimited rolling period

How We Use Your Information

We use the personal information described above for the following purposes:

  1. Responding to inquiries. To respond to your questions, requests, and correspondence submitted through the contact form or by email, and to route your message to the appropriate team member within AMA.
  2. Processing donations. To process, acknowledge, and issue receipts for donations, to set up and manage recurring gifts where applicable, and to maintain the financial records necessary for nonprofit compliance and audit purposes.
  3. Sending communications. To send newsletters and organizational updates to subscribers who have opted in, and to respond to specific requests for information about our programs, governance, or impact.
  4. Evaluating applications. To review, correspond about, and respond to volunteer, employment, and institutional partnership applications, including verifying qualifications and contacting references where you have provided them.
  5. Managing institutional relationships. To communicate with current and prospective institutional partners, donors, and grant-making bodies, including during due diligence, reporting, and compliance processes tied to specific funding relationships.
  6. Recordkeeping and compliance. To maintain accurate financial and administrative records, including for audit, tax, and nonprofit regulatory compliance purposes, consistent with our internal Financial Management and Procurement Policy.
  7. Operating and improving the Site. To operate, maintain, secure, and improve the Site and its content, and to understand at a general, aggregate level how the Site is used, without building individual behavioral profiles.
  8. Security and fraud prevention. To detect, investigate, and prevent fraud, abuse, unauthorized access, or other security incidents affecting the Site or AMA's systems.
  9. Legal compliance. To comply with applicable laws, regulations, and legal process, and to establish, exercise, or defend legal claims where necessary.
  10. Mission delivery. To pursue AMA's charitable mission and to communicate our programmatic impact to stakeholders, donors, and the public, including through impact reports and updates that may reference aggregate, non-identifying donation statistics.

We do not use your personal information to serve targeted advertising, and we do not sell your information (see Section 8). We also do not use your information for any purpose that is materially different from those described above without providing you notice and, where required, obtaining your consent.

How We Share Your Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes, and we do not "share" personal information for cross-context behavioral advertising as defined under the CCPA/CPRA. We may disclose information in the limited circumstances described below.

Categories of Recipients

Recipient CategoryPurposeExample
Hosting and infrastructure providersTo operate the SiteOur web hosting provider
Payment processorsTo process donationsThird-party payment processor
Email service providersTo send newsletters and respond to inquiriesEmail delivery platform
Professional advisorsFinancial, legal, and compliance adviceAuditors, accountants, legal counsel
Regulators and legal authoritiesLegal complianceTax authorities, courts, law enforcement, where legally required
Successor entitiesBusiness continuityIn the event of a merger or reorganization

Service Providers. We share information with trusted service providers who perform functions on our behalf, such as website hosting, email delivery, and payment processing. These providers are contractually bound to protect your information and to use it only for the purposes we specify, consistent with applicable "service provider" or "processor" requirements under relevant law.

Payment Processors. Donation-related payment information is shared with our third-party payment processor solely to complete and confirm your transaction.

Professional Advisors. We may share information with our auditors, accountants, or legal counsel where necessary for financial reporting, compliance, or legal advice.

Legal and Regulatory Disclosures. We may disclose information where required by law, regulation, legal process, or governmental request, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of AMA, our partners, our donors, or the public.

Business or Organizational Changes. In the unlikely event of a merger, reorganization, or transfer of AMA's operations, personal information may be transferred as part of that transaction, subject to the protections of this Policy.

With Your Consent. We may share information for any other specific purpose with your explicit consent.

Local Implementing Partners. As described in Section 3, AMA does not, as a matter of course, transfer website-collected personal data (such as donor or newsletter information) to field-level implementing partners. Any exchange of personal data with a partner organization is governed by a separate data-sharing agreement and limited to what is strictly necessary for a specific, defined purpose.

Cookies and Tracking Technologies

Current Status

The Site uses a cookie consent banner that lets you choose which categories of cookies to allow. Strictly necessary cookies (used solely to remember your cookie preference) are always active and require no consent, consistent with standard guidance under the GDPR and U.S. state privacy laws. Analytics cookies (Google Analytics) are optional and off by default — they only activate if you explicitly accept them through the banner or your preferences, and you can withdraw that consent at any time. AMA does not use any advertising or cross-site tracking technology on the Site. The only other technical data collected is the baseline server log data described in Section 5.3, generated automatically by standard web server software and necessary for security and functionality.

What Are Cookies?

Cookies are small text files placed on your device by a website. Session cookies are temporary and are deleted when you close your browser. Persistent cookies remain on your device for a set period, or until you delete them. First-party cookies are set by the website you are visiting; third-party cookies are set by a domain other than the one you are visiting (for example, an analytics or advertising provider).

Categories of Cookies We May Use in the Future

Should AMA introduce cookies or similar technologies in the future, they would generally fall into the following categories. This section, along with an on-Site cookie consent banner, will be updated accordingly before any such technology is deployed.

CategoryPurposeCan Be Disabled?
Strictly NecessaryRequired for core Site functionality, such as security and load balancingNo
FunctionalRemember preferences, such as language, to improve your experienceYes
AnalyticsHelp us understand, in aggregate, how visitors use the SiteYes
Marketing / AdvertisingMeasure the effectiveness of outreach campaignsYes (not currently used)

Managing Cookies Through Your Browser

Because analytics cookies are optional and off by default, no action is required on your part unless you want to change a preference you already set via the banner. For your general privacy hygiene across the web, most browsers also allow you to view, block, or delete cookies through their settings:

  • Google Chrome: Settings → Privacy and security → Cookies and other site data
  • Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Apple Safari: Preferences → Privacy → Manage Website Data
  • Microsoft Edge: Settings → Cookies and site permissions

Data Retention

We retain personal information only for as long as reasonably necessary to fulfill the purposes described in this Policy, including to satisfy any applicable legal, accounting, or reporting obligations.

Data CategoryTypical Retention Period
Contact form submissionsDuration of inquiry, plus a reasonable period for recordkeeping, then periodically reviewed for deletion
Donation and payment recordsAs required by applicable financial recordkeeping and nonprofit compliance rules (commonly several years)
Newsletter subscriber informationUntil you unsubscribe or request deletion
Volunteer, employment, and partnership applicationsDuration of the evaluation process, plus a reasonable period afterward in case related opportunities arise
Institutional/grant correspondenceDuration of the relationship, plus applicable recordkeeping requirements
Server log dataA limited rolling period sufficient for security and troubleshooting purposes

When personal information is no longer needed, we securely delete, anonymize, or archive it in accordance with our internal data retention practices.

Data Security

We take the security of your personal information seriously and apply reasonable technical and organizational measures designed to protect it, including:

  • Encryption in transit. The Site uses HTTPS/TLS encryption to protect information transmitted between your browser and our servers.
  • Access control. Access to personal information is restricted to personnel and service providers who need it to perform their functions, on a need-to-know basis.
  • Confidentiality obligations. Staff, board members, consultants, and volunteers with access to personal information are bound by confidentiality obligations as a condition of their engagement with AMA.
  • Vendor oversight. Third-party service providers who process personal data on our behalf are selected with reasonable care and are contractually required to maintain appropriate security safeguards.
  • Internal governance. This Policy operates alongside AMA's broader internal IT Security and Incident Management frameworks, which govern access management, authentication, and incident response for AMA's systems generally.
  • Personnel awareness. Personnel with access to personal information are made aware of their confidentiality and data protection obligations as part of their onboarding with AMA.
  • Periodic review. This Policy, and the practical safeguards described in it, are reviewed periodically — and no less than every two years — to ensure they remain appropriate as the Site and AMA's activities evolve.
  • Proportionality. Because AMA collects a limited set of personal information through the Site (as described in Section 5), our security measures are designed to be proportionate to the actual sensitivity and volume of that information, consistent with recognized "privacy by design" principles.

No method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security. If you have reason to believe your interaction with the Site is no longer secure, please contact us immediately using the details in Section 24.

International Data Transfers

AMA is based in the United States, and personal information collected through the Site is generally processed and stored on servers located in the United States. If you are accessing the Site from outside the United States — including from the EEA, the UK, or from any of the countries where AMA's programs operate — please be aware that your information will be transferred to, and processed in, the United States, which may have data protection laws different from those of your country of residence.

Where AMA engages service providers located outside the United States, or where otherwise required by applicable law, we take reasonable steps to ensure an adequate level of protection for your personal information, including through contractual safeguards such as standard contractual clauses, where applicable.

We periodically review the location and safeguards of our service providers as part of our vendor oversight practices described in Section 11. If AMA's use of international sub-processors changes materially, we will update this section to reflect the relevant safeguards in place at that time.

Your Privacy Rights

We aim to offer meaningful, consistent privacy rights and choices to all visitors to the Site, regardless of where you are located, while noting the specific legal frameworks that formally apply in certain jurisdictions.

General Rights for All Users

Subject to applicable law and certain exceptions, you may have the right to:

  • Right to be informed — to know, through this Policy, what personal information we collect and why.
  • Right of access — to request confirmation of whether we process your personal information, and to obtain a copy of it.
  • Right to rectification — to request correction of inaccurate or incomplete information.
  • Right to erasure — to request deletion of your personal information, subject to certain exceptions (for example, financial recordkeeping obligations).
  • Right to restrict processing — to request that we limit how we use your information in certain circumstances.
  • Right to data portability — to receive a copy of certain information you have provided to us in a structured, commonly used, machine-readable format.
  • Right to object — to object to processing based on legitimate interest, including for direct marketing purposes.
  • Right to withdraw consent — at any time, where processing is based on consent.
  • Rights related to automated decision-making — see Section 17; AMA does not engage in automated decision-making with legal or similarly significant effects.

European Economic Area and United Kingdom Residents

If the General Data Protection Regulation (GDPR) or UK GDPR applies to you, you have the rights described in Section 13.1 in full, as a matter of law, and you also have the right to lodge a complaint with your local supervisory authority (see Section 22).

California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), gives you the following rights:

  • Right to Know — the categories and specific pieces of personal information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties with whom it is disclosed.
  • Right to Delete — to request deletion of personal information we have collected from you, subject to certain exceptions.
  • Right to Correct — to request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/SharingAMA does not sell or share personal information as those terms are defined under the CCPA/CPRA, so no opt-out mechanism is required; if this changes, we will provide a "Do Not Sell or Share My Personal Information" mechanism.
  • Right to Limit Use of Sensitive Personal Information — AMA does not use Sensitive Personal Information for purposes requiring this right to be exercised.
  • Right to Non-Discrimination — we will not discriminate against you for exercising any of your CCPA/CPRA rights.
  • Right to Appeal — if we deny your request, you may appeal by replying to our decision; see Section 13.5.

California's "Shine the Light" law (Civil Code Section 1798.83) separately allows California residents to request information about disclosures of personal information to third parties for their own direct marketing purposes. AMA does not disclose personal information to third parties for their own direct marketing purposes.

Nevada Residents

Nevada law (NRS 603A) gives Nevada residents the right to opt out of the "sale" of certain personal information. AMA does not sell personal information as defined under Nevada law, so no opt-out mechanism is required. You may still submit a request through the contact details in Section 13.5, and we will confirm our practices in writing.

Other U.S. State Privacy Rights

Residents of other U.S. states with comprehensive consumer privacy laws — including, among others, Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA) — may have rights broadly similar to those described in Sections 13.1 and 13.3, including rights to access, correct, delete, and obtain a portable copy of personal information, and to opt out of certain processing (such as targeted advertising, the sale of personal information, or certain profiling). AMA extends the substance of these rights to residents of those states in the same manner described in this Section 13, regardless of the precise state of residence, and most such laws also provide a right to appeal an adverse decision on a request, which we honor as described below.

How to Exercise Your Rights

To exercise any of the rights described in this Section 13, please contact us at [email protected]. We may need to verify your identity before fulfilling your request, using information proportionate to the sensitivity of the request. We aim to respond to legitimate requests within thirty (30) days, or within any shorter period required by applicable law; where a request is complex, we may reasonably extend this period, and we will inform you if we do so, together with the reason for the extension. There is generally no fee to submit a request, unless it is manifestly unfounded or excessive, in which case we will explain why before proceeding. If we deny a request, we will explain why and, where required by applicable state law, explain how you may appeal that decision.

Authorized Agents

You may designate an authorized agent to submit a privacy request on your behalf. We may require proof of the agent's written authorization and may still require you to verify your own identity directly with us.

Children's Privacy

The Site is not directed to children, and we do not knowingly collect personal information from children under the age of 13 (or the relevant minimum age in your jurisdiction, such as 16 in certain contexts under the GDPR) without appropriate parental or guardian consent. If we become aware that we have inadvertently collected personal information from a child in violation of this Policy, we will take reasonable steps to delete that information promptly. If you believe a child has provided us with personal information through the Site, please contact us using the details in Section 24 so that we can investigate and, where appropriate, delete the information.

Do Not Track and Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) signal, and some jurisdictions recognize a "Global Privacy Control" (GPC) signal as a valid opt-out preference. Because AMA does not use advertising or cross-site tracking technology, and analytics cookies are already opt-in only, these signals do not currently change how the Site behaves. If AMA introduces any processing subject to an opt-out right under Section 13 in the future, we will honor a valid GPC signal as an opt-out preference where legally required to do so.

Automated Decision-Making

AMA does not use your personal information to make decisions based solely on automated processing (including profiling) that would produce legal effects concerning you or similarly significantly affect you. Any evaluation of applications (volunteer, employment, or partnership) involves human review.

Data Breach Notification

A data breach refers to any accidental, unauthorized, or unlawful destruction, loss, alteration, or disclosure of personal information processed through the Site. In the event of a breach affecting your personal information, AMA will:

  1. Contain and assess. Take immediate steps to contain the incident and assess its scope and cause.
  2. Evaluate risk. Evaluate the potential risk to affected individuals.
  3. Notify where required. Where required by applicable law, notify affected individuals and relevant regulatory authorities without undue delay, and in any event within seventy-two (72) hours of becoming aware of a breach that poses a significant risk, or as otherwise required by the applicable law of the affected individual's jurisdiction.
  4. Remediate. Take reasonable steps to prevent recurrence, consistent with our internal Incident Management and Business Continuity framework.

Marketing Communications

If you subscribe to our newsletter, every marketing email we send will include a clear and functional mechanism to unsubscribe. We honor unsubscribe requests promptly and do not send further marketing communications after you opt out, other than transactional or administrative messages (for example, confirming that your unsubscribe request was processed). To the extent applicable, we intend for our marketing practices to be consistent with the U.S. CAN-SPAM Act, including accurate sender information and a valid physical postal address in our communications.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The "Last Updated" date at the top of this Policy indicates when it was most recently revised. Where changes are material, we will provide additional notice — for example, via a prominent notice on the Site or by email to newsletter subscribers — before the changes take effect. We encourage you to review this Policy periodically.

Governing Law

This Policy is governed by the laws of the State of Wyoming and applicable United States federal law, without regard to conflict-of-law principles, except to the extent that mandatory data protection laws of your own jurisdiction apply to our processing of your personal information, in which case those mandatory provisions will take precedence for the aspects of processing they govern.

Complaints and Supervisory Authorities

If you have concerns about how we handle your personal information, we encourage you to contact us first at [email protected] so that we can try to resolve the issue directly and promptly. In addition:

  • If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority.
  • If you are a California resident, you may also contact the California Attorney General's Office or the California Privacy Protection Agency.
  • If you are located in another U.S. state with a comprehensive privacy law, you may contact your state Attorney General's office, which typically holds enforcement authority under those laws.

Accessibility

AMA is committed to making our communications, including this Policy, accessible to everyone. If you require this Policy in an alternative format, or need assistance exercising any of the rights described herein due to a disability, please contact us at the details below, and we will make reasonable efforts to accommodate your request.

Supplemental Notices for Specific Audiences

For Donors. In addition to the general practices described above, donors should note that donation and payment information is used specifically to process your gift, issue a tax-deductible receipt where applicable, maintain the financial records required of a U.S. 501(c)(3) organization, and, where you have agreed, to keep you updated on how your contribution supports our programs. We do not publish individual donor names or donation amounts without your permission.

For Job and Volunteer Applicants. If you apply for a role with AMA, the information in your application (resume, cover letter, references, and any interview notes) is used solely to evaluate your candidacy and, if you are engaged, to establish your working relationship with AMA. Unsuccessful applications are retained for a limited period in case a related opportunity arises, after which they are deleted, unless you ask us to remove your information sooner.

For Institutional Partners and Grant-Makers. If you represent a foundation, financial institution, or partner organization, information exchanged during due diligence, onboarding, or reporting is used to establish and manage that institutional relationship, and is retained consistent with the recordkeeping obligations tied to that relationship (for example, grant compliance or Know-Your-Customer requirements imposed by a financial institution).

For Journalists and Media. If you contact us in a media or press capacity, we use your contact information solely to respond to your inquiry and, where relevant, to maintain a media contact list for future outreach, which you may opt out of at any time.

Frequently Asked Questions

Do you sell my personal information?

No. AMA does not sell, rent, or trade personal information to third parties for their own marketing purposes, and we do not "share" personal information for cross-context behavioral advertising as defined under U.S. state laws.

Do you use cookies or track me across the web?

Only a strictly necessary cookie that remembers your cookie preference is active by default. Optional analytics cookies (Google Analytics) only activate if you accept them via the cookie banner, and you can withdraw that consent at any time. We do not use advertising or cross-site tracking technology. See Section 9 for full detail.

Is my donation payment information safe?

Yes. Payment card and bank details are collected and processed directly by our third-party payment processor using its own secure infrastructure; AMA does not store your full card number on its own servers.

How do I unsubscribe from your newsletter?

Every newsletter email includes an unsubscribe link at the bottom. You can also email [email protected] and we will remove you promptly.

Can I ask you to delete my information?

Yes, subject to limited exceptions such as financial recordkeeping requirements. Email [email protected] and we will process your request, generally within 30 days.

Do you share my information with your field partners in Africa or Asia?

No, not as a matter of course. Website-collected personal data (such as donor or newsletter information) is not routinely transferred to field-level implementing partners. Any such exchange would require a specific data-sharing agreement and a defined, limited purpose.

Are you the same organization that holds patient or beneficiary medical records?

No. AMA is a consortium and fiscal sponsor without direct field presence. Patient and beneficiary data in our supported programs is collected and held by our local implementing partner organizations under their own obligations, not by AMA directly, and this Policy does not describe that data flow. See Section 3 for detail.

What happens if there is a data breach?

We will contain the incident, assess the risk, and — where required by law — notify affected individuals and relevant authorities within 72 hours of becoming aware of a breach that poses a significant risk. See Section 18.

I am located outside the United States. Does this Policy still protect me?

Yes. We apply the practices in this Policy to all visitors regardless of location, and we extend rights modeled on GDPR and U.S. state privacy laws to visitors generally, even where not strictly required by your local law. See Section 13.

What if I am a minor?

The Site is not directed at children, and we do not knowingly collect personal information from children under 13 without parental consent. See Section 14.

Do you use my information for automated decisions, like an algorithm deciding my job application?

No. AMA does not make decisions based solely on automated processing that would significantly affect you; application review always involves human judgment.

How long do you keep my information?

It depends on the type of information; see the retention table in Section 10. As a general rule, we keep information only as long as necessary for the purpose it was collected, or as required by law.

Who can I contact if I'm not satisfied with your response to my request?

You can escalate to AMA's Board of Directors via [email protected], and, depending on your location, you may also contact your local data protection authority, your state Attorney General's office, or the California Privacy Protection Agency. See Section 22.

Will you tell me if this Policy changes?

Yes. We will update the "Last Updated" date, and for material changes we will post a notice on the Site or notify newsletter subscribers by email before the changes take effect. See Section 20.

Can I get a copy of my data in a format I can transfer elsewhere?

Yes, where applicable, you may request a structured, machine-readable copy of information you have provided to us directly. See Section 13.1.

Do you respond to "Do Not Track" browser signals?

Because we do not currently track visitors beyond baseline security logs, DNT signals do not currently change Site behavior. We will honor Global Privacy Control signals as an opt-out where legally required if this changes. See Section 15.

Our Broader Governance and Policy Framework

This Privacy Policy operates as part of a wider institutional governance framework adopted by AMA's Board of Directors. While the policies below are primarily internal instruments — and, in some cases, contain operational detail that is not appropriate to publish in full for security reasons — we describe their general purpose here in the interest of transparency about how AMA governs itself.

Internal PolicyGeneral Purpose
Code of Conduct and Ethics PolicySets standards of integrity, professionalism, and ethical conduct expected of everyone acting on AMA's behalf.
Conflict of Interest PolicyEnsures that personal or financial interests do not improperly influence AMA's decisions.
Data Protection and Privacy PolicyEstablishes AMA's internal framework for handling sensitive information across its operations, of which this public Policy is the website-facing counterpart.
Child and Vulnerable Adult Protection PolicySets safeguarding standards to protect children and vulnerable adults connected to AMA-supported programs.
Inclusion, Equity, and Anti-Discrimination PolicyEstablishes AMA's commitment to non-discrimination and equitable treatment in all its activities.
Financial Management and Procurement PolicyGoverns financial controls, budgeting, and procurement integrity.
Human Resources and Recruitment PolicyGoverns fair and consistent employment and recruitment practices.
Inventory and Medical Logistics PolicyGoverns the responsible management of program-related supplies and logistics by implementing partners.
Field Security and Safety PolicyEstablishes safety standards to protect personnel and communities in program locations.
Incident Management and Business Continuity PolicyEstablishes AMA's approach to responding to and recovering from major operational disruptions, including data incidents.
IT Security and Cybersecurity PolicyEstablishes technical and organizational controls to protect AMA's digital systems, complementing Section 11 of this Policy.

AMA's Board of Directors reviews this governance framework on a periodic basis to ensure it remains current, proportionate, and aligned with AMA's actual operating model as a consortium and fiscal sponsor. This periodic review also considers consistency across policies, so that the way AMA describes its activities in one document — including this public-facing Policy — remains aligned with how it describes them elsewhere, including in program materials, funding applications, and institutional due diligence submissions.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Alliance for Medical Access

30 N Gould St, Ste N
Sheridan, WY 82801, USA

[email protected]