Version 1.0 · Effective 25 September 2026 · Made under clause 4.1.8 of the SCPMI Charter

Privacy and Cookie Notice

01.

Who we are

The Supply Chain and Procurement Management Institute, registered in the Commonwealth of Massachusetts, United States, at 3 Bayberry Avenue, Provincetown, Massachusetts 02657. We are the controller of the personal data described here.

For anything in this notice, write to info@scpmi.org.

02.

What this notice covers

How we collect, use, share and protect personal data when you join SCPMI, use the community, take a course, take an assessment, attend an event or visit our website.

It applies wherever you are. Where local law gives you more than this notice does, that law applies.

03.

What we collect

You give us

Name, as it appears on your government-issued identification. Personal email address. Mobile number. Work email address, if you choose. Password. Your industries and areas of professional interest. Your membership category. How you found us. Your preferred contact frequency. Your employer and job title. Anything you put in your profile.

You create

Posts, comments, questions, answers, documents and other contributions to the community. Course enrollments and progress. Assessment attempts and results. Event registrations and attendance.

We collect automatically

Device and browser information. IP address. Pages viewed and features used. Approximate location derived from IP address. Cookies and similar technologies, as described at section 12.

We collect from others

Employer or domain verification from public sources. Partner attribution, where an accredited partner introduced you. Identity verification data from a proctoring provider, where you take an assessment. Screening results from sanctions and restricted party list providers.

Special category data

Where you register for an event, we may ask about accessibility requirements or dietary requirements. In the European Economic Area and the United Kingdom, some of this is health data. We ask for it only where it is needed to run the event, we rely on your explicit consent, we share it only with the venue or caterer for that purpose, and we delete it within thirty days of the event.

04.

Why we use it, and on what basis

To provide what you signed up for. We create and run your account and send the messages it needs. We deliver the courses, assessments and credentials you enroll in. For both, we rely on performance of a contract.

To run the community. We operate and moderate it to keep it useful and safe. We rely on performance of a contract, and on our legitimate interest.

To keep credentials meaningful. We verify your identity when you take an assessment, relying on performance of a contract and on our legitimate interest in credentials that mean something. We verify the employer you claim, relying on our legitimate interest in the integrity of a practitioner community. We protect against fraud and credential misuse, relying on our legitimate interest and on legal obligation.

To improve the service and serve the profession. We develop and improve our automated and machine learning systems. We produce aggregated benchmarks, indices and research, using only anonymized aggregates that cannot be re-identified. For both, we rely on our legitimate interest.

Where you have agreed. We personalize what you see when you choose industries and interests to follow. We send professional and community communications, with the consent you give at signup. We publish your credential on a public register so an employer can verify it, with the consent you give at certification. We record events and use the material for communications and marketing, with the consent you give at event registration. You may withdraw any of these consents at any time.

Where you have given explicit consent. We handle accessibility and dietary requirements at events, only to run the event.

Where the law requires it. We screen against sanctions and restricted party lists, relying on legal obligation and on our legitimate interest. We meet our legal, tax and regulatory obligations.

Where we rely on legitimate interest, we have considered your rights and concluded that ours does not override them. You may object, and section 9 explains how.

05.

Your profile, and what is public

Visible to other members. Your name, your professional title and employer, your industries and interests, your membership category, your contributions, and any credential you hold.

Visible to anyone. Your name, the credential you hold, whether it is active or not active, and its validity dates, where you appear on a public verification register. And any contribution the Institute publishes outside the community, with attribution.

Never public. Your email addresses, your mobile number, your password, your assessment attempts and results other than the fact of a credential earned, and your account activity.

You may ask to be removed from a public register. A credential that is not on the register cannot be independently verified.

06.

Who we share it with

Service providers, who process data on our instructions and only for our purposes. These include hosting and infrastructure, the learning platform, the community platform, email delivery, examination proctoring and identity verification, payment processing, and analytics.

Accredited partners, where a partner introduced you or delivers a program you have enrolled in, limited to what is needed for that purpose.

Employers, where your organization has purchased on your behalf, limited to enrollment and completion status.

Anyone, with respect to the public register described at section 5.

Authorities, where we are required by law.

A successor, on a sale, merger, reorganization or change of control, provided the successor is bound by terms no less protective of you. We will tell you before your data is transferred to a successor. A transfer of this kind is not a sale of personal data.

We do not sell personal data.

07.

International transfer

The Institute operates from the United States, with delivery and support functions in the United Arab Emirates and India, and members worldwide. Your data will be transferred outside the country in which you live.

Where data leaves the European Economic Area or the United Kingdom, we rely on Standard Contractual Clauses approved by the European Commission, on the UK International Data Transfer Addendum where applicable, and on adequacy decisions where one exists. You may ask us for details of the safeguards that apply.

08.

How long we keep it

Your account and profile, for as long as you are a member and for two years afterward.

Your contributions to the community, indefinitely, because a discussion loses its value if it is dismantled. They remain attributed unless you ask us to anonymize them.

Your credential record, indefinitely, so that a credential you earned remains verifiable. This is why we hold it, and it is the reason we cannot delete it on request.

Assessment records, for the period set out in the Certification Standards.

Financial records, for the period required by law.

Marketing preferences, including a record that you have opted out. This is a suppression record holding only what we need to honor your choice, kept for as long as it is needed for that purpose.

09.

Your rights

Subject to local law, you may:

Access the personal data we hold about you. Correct it where it is wrong. Delete it, where we have no continuing basis to keep it. Restrict or object to our processing, including processing based on legitimate interest. Port the data you gave us, in a machine-readable form. Withdraw consent at any time, without affecting what we did before you withdrew it.

Where you ask us to delete your data, we will do so except where we must keep it: your credential record, so the credential remains verifiable; financial and tax records; and anything we need to defend a legal claim. We will tell you what we have kept and why.

Contributions you have made to the community remain, under the license in the Membership Terms. We will anonymize your authorship on request.

To exercise a right, write to info@scpmi.org. We respond within one month, and may extend that by two months where a request is complex, telling you why. Where a request is manifestly unfounded or excessive, or repeats an earlier one, we may charge a reasonable fee or decline it, and we will explain our reasoning. We may ask you to verify your identity before we act.

If you are not satisfied, you may complain to your data protection authority.

10.

If you are in the United States

Depending on where you live, you may have the right to know what personal data we collect and why, to obtain a copy, to correct it, to delete it, to opt out of its sale or sharing, to opt out of targeted advertising, and not to be discriminated against for exercising those rights.

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We do not use it for targeted advertising and we permit no third-party advertising on our platform.

To exercise a right, write to info@scpmi.org. You may use an authorized agent, and we may ask for proof of that authority. If we decline a request, you may appeal by writing to the same address.

11.

Automated decisions

We use automated systems to triage community content, to detect fraud and credential misuse, to screen against sanctions and restricted party lists, and to support proctoring during assessment.

No decision adverse to you is made by automated means alone. Where an automated system flags something, a qualified person reviews it before any action is taken. You may ask for the reasoning, and you may contest the outcome. This reflects clause 5.2.7 of the Charter.

12.

Cookies

Essential cookies keep you signed in, keep the service secure and remember your consent choices. They are always on.

Analytics cookies tell us how the service is used, so we can improve it.

Preference cookies remember your settings.

We ask before setting anything other than essential cookies, and you may change your choices at any time through the cookie settings on our website. We do not use advertising cookies and we do not permit third-party advertising on our platform.

13.

Security

We hold personal data on secured infrastructure, encrypt it in transit and at rest, restrict access to those who need it, and log access to credential and assessment records.

We notify the relevant supervisory authority of a personal data breach within the period the law prescribes, and we notify you directly where the risk to you is high.

14.

Children

SCPMI is for professionals and for students preparing to enter the profession. Our services are not directed at anyone under sixteen, and we do not knowingly collect their data. Where we learn that we have, we delete it.

15.

Changes to this notice

  • 15.1 We may amend this notice. A change that is not material takes effect when it is published.

  • 15.2 Where a change is material, we give thirty days' notice by email or by notification within the service before it takes effect. We determine, acting reasonably, whether a change is material.

  • 15.3 Continued use of our services after the effective date is acceptance of the change. Where the law requires fresh consent, we ask for it, and processing carried out before the change remains valid.

  • 15.4 Every version is numbered, dated and archived. The version in force is published on our website. A previous version is available on request.