top of page

Privacy Policy

SILVER BUDDY PROGRAM, INC.

DATA AND PRIVACY POLICY

How Silver Buddy Program collects, uses, and protects information

This Policy explains how Silver Buddy Program, Inc. (the “Silver Buddy Program” or the “Program”) collects, uses, protects, retains, and shares information about the people we serve and the people who serve with us. It applies to every director, officer, employee, volunteer, and contractor who handles Program information (each a “User”). The Program is not a HIPAA-covered entity and does not provide healthcare, but it handles sensitive personal information and treats it with care.

The Board designates a Data and Privacy Officer, who oversees this Policy, answers questions, coordinates the response to any incident, and reviews the Policy at least once a year. Until the Board designates otherwise, the Data and Privacy Officer is the [Secretary / designated officer]. Every User is responsible for reading this Policy and following it, and for reporting any suspected problem immediately to the Data and Privacy Officer.

In running the program, the Program handles information such as: senior participants’ contact details and limited notes about their participation and home access; volunteers’ contact details, application information, and background-check results; location/pin date for a limited period of time; loneliness surveys; and general program records such as visit logs. Some of this is “Sensitive Information,” meaning information that could identify a person or cause harm if disclosed, including background-check results and any notes touching on a participant’s health or safety.

The Program follows three simple rules for all information:

  • Need to know. Users may access only the information they need to do their program role.

  • Least access. We give the minimum access necessary, and we remove access promptly when a role ends.

  • Purpose limits. Information is used only for the program purpose it was collected for, not for any personal or unrelated use.

Every User agrees to the following practical safeguards:

  • Use strong, unique passwords and enable multi-factor authentication on Program accounts. Never share accounts or passwords.

  • Use only Program-approved tools (for example, the Program’s email and shared drive) for program information. Do not store program information in personal email or personal cloud accounts.

  • Lock your screen or device when unattended, and keep devices updated and protected with current security software.

  • In any shared visit log or roster, identify participants by an ID or first name and last initial rather than full personal detail, and do not record a participant’s detailed health information.

  • Do not disclose participant or volunteer information to anyone outside the Program except as Section 7 allows.

 

Background-check results are Sensitive Information obtained through a consumer reporting agency and are subject to the federal Fair Credit Reporting Act. We collect them only with the volunteer’s written authorization, use them only to evaluate suitability for service, restrict access to the Data and Privacy Officer and those who must see them, store them separately from general files, and dispose of them securely when no longer needed. If a report may lead us to decline or end a placement, we follow the FCRA’s notice steps.

 

Users keep participant and volunteer information confidential during and after their service. The Program shares information only: as required by law; to protect someone’s safety, including reporting suspected abuse, neglect, or exploitation; with the individual’s consent; or in an emergency, in which case we contact 911 and, where relevant, community or facility staff. We do not sell or rent personal information, and we do not use it for advertising.

 

The Program keeps information only as long as it is needed for the program, for legitimate recordkeeping, or as the law requires, and then disposes of it securely. Paper records are shredded, and electronic records are permanently deleted or wiped. The Data and Privacy Officer sets simple retention periods and reviews them yearly.

 

The Program uses outside services, such as its background-check provider and cloud-based email and file storage. We choose reputable providers that offer appropriate security, and we limit the information we share with them to what the service requires.

 

Any User who suspects that information has been lost, stolen, or exposed must notify the Data and Privacy Officer immediately. The Data and Privacy Officer will promptly (a) contain the problem and cut off further access, (b) assess what information was involved and who is affected, (c) notify affected individuals and any authorities where required by Georgia’s breach-notification law and other applicable law, engaging legal counsel as needed, and (d) document the incident and any steps taken to prevent a recurrence.

 

Following this Policy is a condition of serving with the Program. A User who does not follow it may lose access to Program information and may have their role or service ended. The Data and Privacy Officer may update this Policy from time to time and will share material changes with Users.

bottom of page