PRIVACY POLICY CR-7 (1)

Part A Overview
Affordable Housing Experts LLC is committed to protecting employees, partners, vendors and the company from illegal or damaging actions by individuals, either knowingly or unknowingly. When addressing issues proactively and using correct judgment, it will help set us apart from competitors.

Affordable Housing Experts LLC will not tolerate any wrongdoing or impropriety at any time. Affordable Housing Experts LLC will take appropriate measures and act quickly in correcting the issue if the ethical code is broken.

Scope
This Privacy Policy applies to all individuals who use our services, visit our website, or interact with us through various mediums (“Users”).
The policy applies to all personal data collected by Affordable Housing Experts LLC, whether online or offline, including but not limited to data collected through our website, mobile applications, via phone or email interactions, or during in-person meetings.
This policy also covers personal data we may receive from our partners and third-party providers.
Our Privacy Policy does not extend to external websites or services linked to our website or referred to in our communications. We encourage our users to read the privacy statements of these third-party entities before providing them with any personal information.
All employees, contractors, partners, and anyone directly associated with Affordable Housing Experts LLC must adhere to this policy. Non-compliance may result in disciplinary measures, up to and including termination of employment or contract.
Affordable Housing Experts LLC reserves the right to amend this policy at any time. The revised policy will apply from the date of publication on our website. We encourage our users to regularly review this policy to stay informed about how we are protecting their personal data.

IDENTIFY-P (ID-P)

Data We Collect
We collect personal information you voluntarily provide to us when you use our services, including but not limited to: name, email address, phone number, payment information, and other related personal details. We also automatically collect data when you use our services, such as IP addresses, device information, log information, and usage data.

Purpose of Data Collection
We collect and process your personal data to deliver services, enhance your user experience, and comply with legal obligations.

GOVERN-P (GV-P)

Roles and Responsibilities
Our organization, employees, and trusted third-party providers comply with this privacy policy and related procedures, ensuring the protection of your personal data. Our Data Protection Officer (DPO) is responsible for overseeing these compliance efforts.

CONTROL-P (CT-P)

Data Access and Accuracy
We provide mechanisms for you to review, correct, or delete your personal data, ensuring data accuracy and completeness.

Data Security
We employ state-of-the-art technical and organizational measures to secure your personal data from unauthorized access, alteration, disclosure, or destruction. These include encryption, secure servers, and physical security measures.

COMMUNICATE-P (CM-P)

Data Sharing
We do not sell, rent, or otherwise share your personal data to third parties for their marketing purposes without your explicit consent. We may disclose your personal data to third parties who perform services on our behalf or as required by law.

Data Breach Notification
In the event of a data breach, we will notify the affected individuals and the appropriate authorities as required by law, detailing the nature and scope of the breach, the measures taken, and how to protect themselves further.

PROTECT-P (PR-P)

Data Retention and Deletion
We retain your personal data for as long as necessary to provide our services, comply with legal obligations, or resolve disputes. After this, we securely delete or anonymize your personal data.

International Data Transfers
When we transfer your personal data internationally, we ensure that the recipient countries have adequate data protection laws or that we have appropriate safeguards in place, in accordance with applicable law.

Changes to this Policy
We may update our privacy policy from time to time. We will notify you of any significant changes.

Executive Commitment to Privacy

At Affordable Housing Experts LLC, our leadership team is fully committed to ensuring the privacy of our users’ personal data. This commitment is embedded in every level of our organization and guides our decisions and operations.

  1. Leadership Involvement: Our senior leadership plays an active role in setting our privacy goals, establishing policies, and allocating resources necessary for effective privacy management.

  2. Roles and Responsibilities: Our leadership team has appointed a Data Protection Officer (DPO) to oversee the organization’s privacy program.

  3. Culture of Privacy: Our management promotes a culture that respects privacy.

  4. Training and Education: Our management ensures all staff undergo regular training on privacy principles.

  5. Review and Improvement: Leadership regularly reviews the effectiveness of our privacy program.

  6. Stakeholder Engagement: We actively engage with stakeholders to understand privacy expectations.

Procedure for Identifying, Assessing, and Treating Privacy Risks and Opportunities

  1. Identifying Privacy Risks and Opportunities: Through data mapping, PIAs, audits, feedback, and monitoring industry trends.

  2. Assessing Privacy Risks and Opportunities: Based on potential impact and likelihood, considering type of data and existing controls.

  3. Treating Privacy Risks and Opportunities: Developing action plans (avoidance, reduction, sharing, acceptance).

  4. Monitoring and Review: Tracking progress, reassessing, and reporting findings to leadership.

  5. Documentation: Keeping records of all steps for internal and external review.

Policy and Procedure for Internal and External Communications

Policy: Affordable Housing Experts LLC is committed to open, transparent, and timely communication about our privacy program.

Internal Communications:

Regular updates via meetings, newsletters, or intranet

Training for all staff

Queries directed to the DPO

External Communications:

Privacy policy publicly available on our website

Stakeholder queries directed to DPO

Data breach notifications as required by law

Media inquiries managed by PR team in coordination with DPO

Procedure for Handling Privacy Program Documentation

  1. Creation and Approval: All documents reviewed and approved by the DPO.

  2. Storage and Access: Secure, centralized document management with role-based access.

  3. Version Control: Version history maintained with dates and change logs.

  4. Review and Update: Annual reviews or when significant changes occur.

  5. Disposal: Secure shredding or electronic deletion when no longer needed.

  6. Audit: Regular audits to ensure compliance.

  7. Training: Staff trained on documentation procedures.

References:

https://www.nist.gov/privacy-framework/privacy-framework

https://doi.org/10.6028/NIST.CSWP.01162020