Privacy Policy
How We Use Your Information
Advancing Our Mission
Member Services & Professional Development
- Processing and managing membership applications and renewals
- Providing access to member-exclusive resources and benefits
- Facilitating continuing education opportunities and CE credit tracking
- Organizing annual conventions and professional meetings
- Supporting career advancement through mentorship programs
- Connecting members for professional networking and collaboration
Advocacy & Research Initiatives
- Supporting policy initiatives to improve oral health equity
- Contributing to research on healthcare disparities (using aggregated, de-identified data)
- Advancing legislative and regulatory efforts
- Promoting diversity in dental education and practice
- Addressing systemic barriers in the dental profession
Professional Directory Services
- Maintaining searchable directories for member networking
- Helping communities find qualified minority dental professionals
- Supporting patient referrals and professional connections
- Facilitating academic recruitment efforts
- Enhancing visibility of diverse dental professionals
Communications & Engagement
- Sending newsletters, journal publications, and professional updates
- Notifying members about conventions, CE opportunities, and events
- Sharing advocacy alerts and policy developments
- Facilitating chapter and district communications
- Providing industry news and best practices
Community Outreach & Education
- Supporting public health initiatives and community screenings
- Promoting oral health awareness in underserved communities
- Highlighting contributions of minority dental professionals
- Encouraging minority youth to pursue dental careers
Member Portal & Account Data NEW
Our enhanced member portal provides secure access to exclusive resources and personalized services.
Account Management via MemberStack
We use MemberStack for secure account management and tier-based access control. This system manages your login credentials, membership status, and content permissions. MemberStack operates under its own privacy policy and security standards, which comply with industry best practices.
Membership Tiers & Access Levels
- Free Tier: Basic access to public resources and limited directory visibility
- Paid Member Tier: Full access to resources, directory, CE content, and member benefits
- Corporate Tier: Enhanced features for institutional partners ($5,000-$30,000 value)
What Data Is Stored in Your Member Portal
- Professional profile and practice information
- CE credit history and certificate downloads
- Event registration history and upcoming bookings
- Payment history and membership receipts
- Saved content preferences and bookmarks
- District/chapter affiliation and participation records
- Communication preferences and subscription settings
Data Integration & Workflows
Your member portal data integrates with several systems to provide seamless service:
Database & Backend Infrastructure
We use a secure, enterprise-grade PostgreSQL database system to store and manage member information. This database serves as the central hub for all member data, with automated triggers and functions that ensure real-time synchronization with external systems.
Real-Time Data Synchronization
When you register or update your profile, our system employs automated workflows that instantly sync your information across platforms:
- Database Triggers: Automated server-side processes that fire immediately when member data changes
- Edge Functions: Secure, serverless functions that handle authentication and API calls to external services
- OAuth 2.0 Authentication: Industry-standard secure authentication for API connections
- Encrypted Storage: All database connections and data transmission use encryption
Salesforce CRM Integration
Member data automatically syncs to Salesforce for relationship management through two methods:
Direct Integration (Primary Method): When you register or update your profile, database triggers activate serverless functions that authenticate with Salesforce using OAuth 2.0 and create or update your Contact record. This happens in real-time without any manual intervention.
Zapier Integration (Backup Method): As an alternative or redundant system, we can route data through Zapier's workflow automation platform, which provides visual workflow management and additional data transformation capabilities.
Data Flow Process
- Member Action: You register or update your profile through the portal
- Database Update: Your information is securely stored in our PostgreSQL database
- Trigger Activation: Automated database trigger detects the change
- Edge Function: Serverless function authenticates with external service (Salesforce)
- API Call: Secure API request sent with your data
- External Update: Your Contact record is created or updated in Salesforce
- Confirmation: System logs the successful sync
Integration Partners
- Typeform: Collects detailed information during registration and applications
- Stripe: Processes payments securely through tokenized payment APIs
- Salesforce CRM: Manages member relationships with real-time bidirectional sync
- Zapier (Optional): Provides workflow automation and system integration backup
- Google Drive: Stores member resources via secure API connections
- Mapbox: Powers interactive district map with geolocation services
Data Security in Transit
All integrations employ multiple security layers:
- SSL/TLS encryption for all API communications
- OAuth 2.0 authentication tokens (never storing passwords)
- Encrypted secrets management for API credentials
- Server-side only processing (no client-side sensitive data exposure)
- Admin-only access to integration management
- Automated logging and monitoring of all sync operations
Admin Approval Workflows
Free tier applications require administrative review to verify professional credentials. During this process:
- Your submission is stored securely in our database with "pending" status
- NDA staff receive automated notification of new applications
- Staff review credentials through secure admin portal
- Upon approval, database status updates trigger membership activation
- You receive email confirmation with portal access credentials
- Your approved profile automatically syncs to all connected systems
We typically complete reviews within 3-5 business days.
Your Rights and Choices
Membership Directory Control
Profile Visibility Options
- Public Directory Listing: Choose what information appears in public searches
- Member-Only Visibility: Restrict your profile to NDA members only
- Complete Opt-Out: Remove yourself from directories while maintaining membership
- Enhanced Profiles: Add photos, specializations, and additional practice details
Access directory settings through your member portal account preferences.
Communications Preferences
Email Subscriptions
Control which types of communications you receive:
- Monthly newsletters and journal publications
- Event announcements and convention updates
- CE course opportunities and professional development
- Advocacy alerts and policy updates
- District and chapter communications
- Partner offers and industry news
How to Update: Use the preference center link in any email, contact our office, or update settings in your member portal. Note that certain membership-related communications (payment confirmations, convention registrations) cannot be opted out of while maintaining active membership.
Data Access and Control
Your Data Rights
- Access: Request copies of your personal information we maintain
- Corrections: Update or correct inaccurate information
- Portability: Obtain your data in a portable format for transfer
- Deletion: Request deletion of non-essential personal information
- Restriction: Limit how we process certain types of data
Important Notes on Data Deletion
While we honor data deletion requests, some information must be retained for:
- Active membership records and benefits administration
- Financial transaction history and tax compliance
- CE credit reporting to state dental boards
- Legal and regulatory requirements
- Fraud prevention and security purposes
We will clearly explain what can and cannot be deleted when processing your request.
How to Exercise Your Rights
Submit data rights requests by:
- Emailing info@ndaonline.org with subject "Privacy Request"
- Calling (202) 885-9492 and asking for the Privacy Officer
- Mailing written requests to our Washington, DC office
We will verify your identity and respond within 30 days. Complex requests may require additional time.
Account Management
- Login Credentials: Maintain secure passwords through your member portal
- Profile Updates: Keep professional information current for accurate directory listings
- Membership Tier Changes: Upgrade or modify membership level as needed
- Account Closure: Request account deactivation (membership termination)
Data Security and Protection
Protecting your personal and professional information is a top priority for the NDA.
Technical Safeguards
Infrastructure Security
- Encryption: Industry-standard SSL/TLS encryption for all data transmission
- Secure Hosting: Enterprise-grade hosting through Webflow and trusted cloud providers
- Database Protection: Encrypted data storage with access controls and monitoring
- Payment Security: PCI-compliant processing through Stripe (we never store full payment card details)
- Regular Updates: Maintaining current security patches and system monitoring
- Backup Systems: Secure data backup and recovery procedures
Organizational Safeguards
Access Controls
- Limiting data access to authorized personnel with legitimate business needs
- Multi-factor authentication for administrative systems
- Role-based permissions for staff and chapter administrators
- Regular access reviews and credential management
Staff Training & Policies
- Privacy and security training for all NDA staff and volunteers
- Clear data handling policies and procedures
- Confidentiality agreements with service providers
- Regular privacy and security awareness updates
Vendor Management
- Requiring privacy and security commitments from all service providers
- Data processing agreements with third-party vendors
- Regular vendor security assessments
- Limiting data sharing to only what's necessary
Incident Response
In the unlikely event of a data security incident:
- We maintain documented incident response procedures
- Affected members will be notified promptly as required by law
- We will provide guidance on protective measures you can take
- Investigations will be conducted to prevent future incidents
Your Role in Security
Best Practices for Members
- Use strong, unique passwords for your member portal account
- Never share your login credentials with others
- Log out of the member portal when using shared computers
- Keep your contact information current for security notifications
- Report suspicious emails or communications claiming to be from NDA
- Review your account activity regularly for unauthorized access
Payment Processing & Financial Data
Stripe Payment Integration
All payment processing for memberships, event registrations, and donations is handled securely through Stripe, a PCI-DSS compliant payment processor.
How Payment Data Is Handled
- Direct Processing: Payment card information goes directly to Stripe, not NDA servers
- Token-Based Security: We store only payment tokens, never full card numbers
- PCI Compliance: Stripe maintains full PCI-DSS Level 1 certification
- Fraud Protection: Advanced fraud detection and prevention systems
- Secure Connections: All payment pages use 256-bit SSL encryption
What Financial Information We Retain
For membership administration and tax compliance, we maintain:
- Transaction dates and amounts
- Payment method type (last 4 digits only)
- Membership dues payment history
- Event registration payment records
- Donation receipts and acknowledgments
- Refund and adjustment history
Financial Data Retention
Financial records are retained for a minimum of 7 years to comply with:
- IRS tax requirements for non-profit organizations
- State and federal financial record-keeping laws
- Audit and compliance obligations
Refund and Cancellation Policies
Refund eligibility varies by purchase type:
- Memberships: Refund policies outlined in membership terms
- Convention Registration: Cancellation deadlines in event terms
- Donations: Generally non-refundable (tax receipts issued)
Contact info@ndaonline.org for refund requests with transaction details.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. We are committed to transparency in how we notify members of changes.
How We Notify You
Update Notification Process
- Email Notice: Advance notice of significant changes via email to all members
- Website Updates: Current version posted prominently on ndaonline.org
- Portal Alerts: In-app notifications within the member portal
- Effective Dates: Clear indication of when changes take effect
- Version Archive: Previous policy versions available for reference
What Constitutes a "Significant" Change
We will provide advance notice and, where appropriate, seek consent for changes that:
- Expand the types of personal information we collect
- Change how we use sensitive professional data
- Introduce new categories of third-party data sharing
- Reduce your privacy rights or control options
- Fundamentally alter our data protection practices
Your Acceptance of Changes
By continuing to use our services after changes take effect, you accept the updated Privacy Policy. If you disagree with changes, you may:
- Contact us to discuss your concerns
- Opt out of new data uses where possible
- Request account closure if changes are unacceptable
Review and Audit Schedule
The NDA conducts regular privacy practice reviews:
- Annual Review: Comprehensive policy and practice assessment
- Technology Updates: Reviews when implementing new systems
- Legal Changes: Updates to comply with new privacy regulations
- Incident Reviews: Policy adjustments following any security incidents
Version Information
Current Version: 2.0
Effective Date: December 10, 2025
Last Revised: December 10, 2025
Previous Version: Dated September 11, 2025
Major Changes in This Version:
- Enhanced member portal and digital services information
- Expanded data security and protection details
- Clarified payment processing procedures
- Updated service provider information
- Added comprehensive user rights explanations
Questions, Concerns, and Complaints
How to Contact Us
Privacy Inquiries
Email: privacy@ndaonline.org
Subject: Privacy Question
Phone: (202) 885-9492
Ask for the Privacy Officer
Mail:
National Dental Association
Attn: Privacy Officer
3517 16th Street, NW
Washington, DC 20010
Resolution Process
When you contact us with a privacy concern:
- Acknowledgment: We will acknowledge receipt within 2 business days
- Investigation: We will thoroughly investigate your concern
- Response: You will receive a detailed response within 30 days
- Resolution: We will work with you to address your concerns satisfactorily
- Escalation: If unsatisfied, you may request review by NDA leadership
Regulatory Complaints
While we hope to resolve any concerns directly, you have the right to file complaints with relevant regulatory authorities:
- U.S. Members: Federal Trade Commission (FTC) or state attorney general
- International Members: Your local data protection authority
Documentation
When contacting us about privacy issues, please provide:
- Your name and membership number (if applicable)
- Contact information for follow-up
- Detailed description of your concern
- Relevant dates, documents, or correspondence
- Your desired resolution
Professional Ethics and Confidentiality
As a professional organization serving healthcare providers, we understand the critical importance of confidentiality and ethical data handling. Our privacy practices align with:
- Dental Professional Ethics: ADA Code of Professional Conduct and confidentiality principles
- Healthcare Privacy: HIPAA principles where applicable to health information
- Professional Development: Supporting career advancement while protecting professional reputation
- Community Trust: Maintaining the trust of communities we serve
Acknowledgment and Acceptance
By Using Our Services
By accessing the NDA website, member portal, and related services, you acknowledge that you have read and understood this Privacy Policy. For NDA members, this policy supplements but does not replace the privacy provisions in your membership agreement.
Our Commitment to You
The National Dental Association is committed to protecting your privacy while advancing oral health equity and supporting the professional development of minority dental professionals. For over 112 years, we have served our community with integrity and excellence, and this commitment extends to how we protect and use your
