01Who We Are
IFO4 Inc. is a Delaware non-profit corporation and the controller of personal information processed under this Policy. IFO4 operates a suite of professional-development products for the Financial Operations discipline, including the UNUM cost calculator, IFO4 Social, the IFO4 Community, professional certifications, learning programs, research publications, and events.
02U.S. Privacy Laws This Policy Addresses
This Policy explains your rights and IFO4's obligations under applicable U.S. federal and state privacy laws, including:
- California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA);
- Virginia Consumer Data Protection Act (VCDPA);
- Colorado Privacy Act (CPA);
- Connecticut Data Privacy Act (CTDPA);
- Utah Consumer Privacy Act (UCPA);
- Texas Data Privacy and Security Act (TDPSA);
- Oregon, Montana, Tennessee, Iowa, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Kentucky, and Rhode Island comprehensive state privacy laws, and other analogous statutes as they become effective;
- Illinois Biometric Information Privacy Act (BIPA), applicable to on-device exam processing;
- Children's Online Privacy Protection Act (COPPA). IFO4 does not knowingly serve anyone under 18;
- Health Insurance Portability and Accountability Act (HIPAA), only where IFO4 is engaged as a Business Associate under a BAA;
- Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, where applicable to financial-services customers;
- Federal Trade Commission Act § 5 prohibitions on unfair and deceptive acts.
03What Information We Collect
The sub-sections below describe the categories of information IFO4 collects, organized by product area. Only information necessary to operate the relevant Service is collected.
3.1 Universal Account and Identity Data
- Name, email address, password hash, phone number (if provided), username, avatar, profile bio.
- Role, employer, country, time zone, and any self-declared professional credentials.
- IP address, user-agent, device fingerprint (hashed), and session telemetry for security and fraud prevention.
- Communication preferences and consent records.
3.2 UNUM: Cost Calculator
- Scenario inputs you submit to UNUM (for example: cloud provider, region, commitment model, usage profile).
- Saved UNUM drafts and named scenarios, if you choose to save them to your account.
- UNUM does not collect or process your actual cloud-billing data. It operates on self-supplied estimates and public list prices.
3.4 Certification and Examination Data
- Registration and identity-verification records, exam attempts, scores, and credential status.
- Anonymized integrity-event flags and confidence scores from the on-device exam-integrity system. No photos, video footage, or raw biometric data leave your device.
- Appeals, human-review requests, and any correspondence you send about a decision.
3.5 Learning and Education Data
- Course enrollments, lesson progress, quiz attempts, bookmarks, and notes.
- Study-coach chat transcripts (server-side logs retained only for abuse prevention and quality).
3.6 Events, Summit, and Mentorship
- RSVP and attendance records for IFO4 events, including the Community Call and Summit.
- Mentor / mentee pairings, coffee-chat scheduling metadata, and session notes you voluntarily save.
3.7 Careers and Research Data
- Job postings, applications, endorsements, and profile data you elect to share with employers.
- Research submissions, peer-review status, and citations.
04How and Why We Use Your Information
IFO4 processes the categories of information above for the following purposes, each tied to a lawful basis recognized under applicable U.S. law:
- Providing the Services (contract). Running the Platform, UNUM, certifications, learning, events, and community features.
- Security and fraud prevention (legitimate interest). Account-lockout, anomaly detection, abuse reporting, law-enforcement response.
- Customer support (contract). Answering questions, honoring appeals, running human review.
- Product improvement and analytics (legitimate interest). Aggregated, privacy-preserving analytics only. IFO4 does not sell personal information.
- Communications (consent + legitimate interest). Transactional emails, event reminders, newsletters you opt in to.
- Legal compliance (legal obligation). Tax, accounting, professional-body reporting, response to valid legal process.
06How Long We Keep Information
IFO4 retains personal information only as long as reasonably necessary to provide the Services and to satisfy legal, accounting, and legitimate-business purposes. Typical retention periods include:
- Account and profile data: while your account is active, plus two (2) years after closure.
- Exam records and credential status: seven (7) years for audit and verification.
- Financial records: seven (7) years as required by U.S. tax and accounting standards.
- Support and dispute records: the limitation period of any potentially applicable claim.
- Security logs: twelve (12) months rolling, aggregated and de-identified thereafter.
07Your Rights
Depending on your state of residence, you may have the rights listed below. IFO4 honors these rights for all U.S. residents where granted by applicable state law, and in many cases extends them voluntarily to all U.S. users.
- Right to know: what personal information IFO4 has about you and how it is used.
- Right to access: a copy of your personal information in a portable format.
- Right to correct: inaccuracies in your personal information.
- Right to delete: your personal information, subject to legal-retention exceptions.
- Right to opt out: of any sale or cross-context behavioral advertising (which IFO4 does not engage in).
- Right to limit: the use of sensitive personal information (which IFO4 honors even though it does not use sensitive information for unrelated purposes).
- Right to non-discrimination: you will not be treated differently for exercising any of these rights.
- Right to appeal: any denial of a rights request, via privacy@ifo4.org.
Submit requests via privacy@ifo4.org. IFO4 will verify your identity and respond within the timeframe required by applicable law, typically 45 days.
08Security Measures
- TLS 1.2+ in transit; AES-256 at rest for sensitive fields.
- Role-based access controls, principle of least privilege, and quarterly access reviews.
- Multi-factor authentication available for all accounts; required for IFO4 staff.
- Automated dependency scanning, secrets scanning, and vulnerability patching.
- Audit logging of privileged actions. Audit log is retained and monitored for anomalies.
- Annual security review. IFO4 will publish its formal Trust Center documentation when available.
09Data Breach Notification
If IFO4 determines that a security breach has affected your unencrypted personal information, IFO4 will notify you and relevant authorities consistent with applicable U.S. federal and state breach-notification laws.
10Children's Privacy
IFO4 services are intended exclusively for professionals aged eighteen (18) or older. IFO4 does not knowingly collect, solicit, or process personal information from anyone under 18 and does not direct any Service to children. If IFO4 becomes aware that personal information has been collected from a minor, IFO4 will delete that information promptly and terminate the associated account. If you believe a minor has registered, contact privacy@ifo4.org immediately.
12Third-Party Sites, Links, and Integrations
The Services may link to or integrate with third-party websites, platforms, and tools. IFO4 does not control and is not responsible for the privacy practices of third parties. Reviewing the privacy policies of those third parties before providing personal information to them is your responsibility.
13California "Shine the Light"
California residents may request once per calendar year a list of third parties to whom IFO4 has disclosed personal information for direct-marketing purposes, if any, in the preceding calendar year. As stated above, IFO4 does not share personal information with third parties for their direct-marketing purposes. Requests may be sent to privacy@ifo4.org.
14Changes to This Policy
IFO4 may update this Policy from time to time. Material changes will be communicated at least thirty (30) days in advance by email to your registered address and through an in-platform notification. Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
15Contact
- Privacy questions and requests: privacy@ifo4.org
- Data-rights appeals: privacy@ifo4.org
- Security concerns: security@ifo4.org
- Postal: IFO4 Inc., Delaware, United States
Questions about this document can be sent to privacy@ifo4.org.
IFO4 Inc., a Delaware non-profit corporation. Effective April 2026. v4.2.
3.3 IFO4 Social and IFO4 Community