Privacy and Security
We take the privacy and security of our members' information seriously. As a non-profit organization, we have implemented multiple layers of protection to safeguard your data while maintaining transparency about our capabilities and limitations.
Security Measures We've Implemented
Password Security: All user passwords are encrypted using industry-standard encryption algorithms. Your password is never stored in plain text, ensuring that even our administrators cannot view your actual password.
Multi-Factor Authentication (MFA): We offer two-factor authentication to add an extra layer of security to your account. When enabled, you'll need to provide a second form of verification in addition to your password when logging in.
Account Lockout Protection: To prevent unauthorized access attempts, accounts are automatically locked for a limited time period after multiple unsuccessful login attempts. This protects your account from brute-force attacks.
Account/Membership Validation: New accounts undergo a validation process to ensure legitimacy and prevent fraudulent registrations, helping maintain a secure community environment.
Network and Infrastructure Security
HTTPS & TLS Encryption: All data transmitted between your browser and our servers is encrypted using HTTPS with Transport Layer Security (TLS). This ensures that your information cannot be intercepted during transmission.
DDoS and Cyber Attack Prevention: We utilise Cloudflare's security infrastructure to protect our portal from Distributed Denial of Service (DDoS) attacks and other common cyber threats, ensuring consistent availability and performance.
Role-Based Access Control (RBAC): Our system implements role-based access controls, meaning members and administrators only have access to the information and features necessary for their specific roles. This minimises potential exposure of sensitive data.
Privacy Practices
Data Collection and Use: We collect only the information necessary to provide membership services and maintain our portal. Your personal information is used exclusively for:
- Account management and authentication
- Providing membership benefits and services
- Communicating important organisational updates
- Complying with legal obligations
Data Sharing: We don't sell or share your personal information with third parties for marketing purposes.
Data Retention: We retain your personal information only for as long as necessary to provide services or as required by law. Members may request account deletion at any time.
Important Limitations and Transparency
Our Commitment Despite Resource Constraints:
As a non-profit organization operating with limited funding and resources, we want to be transparent about our security capabilities:
What We Do:- Implement industry-standard security practices within our means
- Regularly update our systems and apply security patches
- Monitor for suspicious activity and respond to security incidents
- Continuously evaluate and improve our security measures
Our Limitations:
- We may not have access to enterprise-level security tools available to larger organizations
- Our security infrastructure is maintained by a small team or volunteers
- We cannot guarantee absolute protection against all potential security threats
- Response times to security incidents may be longer than commercial organizations
No Guarantee of Absolute Security: While we implement reasonable security measures and make every effort to protect your information, no system can be 100% secure. We cannot guarantee that unauthorised access, hacking, data loss, or other breaches will never occur. By using our portal, you acknowledge and accept these inherent risks.
Your Role in Security
You can help protect your account by:
- Creating strong, unique passwords
- Enabling multi-factor authentication
- Never sharing your login credentials
- Logging out after using shared or public computers
- Reporting suspicious activity immediately
- Keeping your contact information up to date
Reporting Security Concerns
If you discover a security vulnerability or suspect unauthorised access to your account, please contact us immediately at [[email protected]].
