Security standard expected of all people working with the Racine Play Foundation.
Private Storage & No Public Access
All data is stored in a private data store with restricted network endpoints. There is no public access to storage resources, and all access is authenticated and authorized.
Role-Based Access
Staff, coaches, directors, and volunteers are assigned only the access required for their role. Admin functions are restricted to directors and managers.
Encryption in Transit & at Rest
Data is encrypted in transit using TLS and at rest through platform-managed encryption. Sensitive configuration is managed securely and not exposed publicly.
Data Retention & Deletion
We retain information only as long as needed for active program operations, required reporting, and applicable legal obligations. When data is no longer needed, it is deleted securely through overwrite, cryptographic erasure, or physical destruction, as appropriate to the storage medium.
Auditing & Accountability
Key actions are logged and reviewable. Staff are accountable for how they access, use, and share information.
Incident Response
We maintain a simple incident response process: detect, contain, notify, and remediate. Leadership and affected parties are informed promptly when something goes wrong.
Security & Confidentiality Agreement
All staff, volunteers, and partners must understand and accept these obligations before accessing foundation systems or data.
1. Confidentiality
You will treat all non-public information — especially youth and family data — as confidential. Do not share, post, or discuss internal records outside of foundation business.
2. Acceptable Use
Use foundation systems and data only for authorized program and administrative purposes. Do not access records for personal curiosity or unrelated purposes.
3. Protection of Youth Data
Because we serve minors, extra care applies. Do not publish photos, names, or identifying details without signed parental consent and manager approval.
4. Access & Authentication
Use only your assigned account. Never share credentials. Log out when finished and report lost or compromised access immediately.
5. Reporting Concerns
Report suspected misuse, data loss, or security concerns to a director or manager right away. Do not attempt to investigate or conceal incidents yourself.
6. Consequences
Violations may result in loss of access, removal from programs, and, where required, notification to affected parties or authorities.
All users must formally accept this agreement before access is granted. Acceptance is logged with the date and agreement version.