American Supplement Association

Privacy Policy

This Privacy Policy explains how the American Supplement Association collects, uses, discloses, retains, and protects personal information in connection with its websites, membership, communications, events, education, committees, applications, awards, registries, and related services.

This Privacy Policy explains how the American Supplement Association collects, uses, discloses, retains, and protects personal information in connection with its websites, membership, communications, events, education, committees, applications, awards, registries, and related services.

Effective date and last updated date: Display from the approved legal record.

Scope

This Policy applies when ASA determines the purposes and means of processing personal information through the services it identifies. A separate notice or agreement may apply to employees, contractors, research participants, specific events, or another activity. When a more specific notice conflicts with this Policy for the stated activity, the more specific notice controls.

External websites and services have their own privacy practices.

Information ASA collects

Depending on the relationship and service, ASA may collect:

Identity and contact information

Name, professional title, organization, business address, email, phone, signature, account identifiers, and communication preferences.

Organization and membership information

Legal entity, trade names, jurisdiction, ownership or control information relevant to eligibility, business roles, websites, representatives, category, dues, directory choices, Code reaffirmation, and application or status records.

Account and authentication information

Login identifiers, credential-management data, multifactor settings, roles, permissions, authentication events, device or session information, and security logs. ASA should not store a readable password.

Transaction and registration information

Membership billing, event or education registration, invoicing, payment status, attendance, completion, cancellations, and support. Payment-card data should be handled by the approved payment provider rather than stored by ASA except for limited transaction references.

Professional and participation information

Qualifications, biographies, photographs, committee and event participation, faculty or reviewer roles, contributions, disclosures, conflicts, affiliations, attendance, and professional interests.

Policy, scientific, and publication information

Comments, sources, authorship, peer review, research or technical contributions, disclosures, corrections, and communications connected to ASA work.

NutraFormula application information

Applicant identity and authority, professional contacts, formula and evidence records, reviewer communications, disclosures, decision records, public registry fields, change notices, and mark-use records. These submissions can include confidential business information and are subject to additional application terms and access controls.

Concern and integrity information

Reports, supporting records, reporter contact or anonymity choice, affected parties, correspondence, review steps, conflicts, findings, outcomes, and preservation records. Reports should not include unnecessary personal or health information.

Website and technical information

IP address, browser, device, pages, links, search terms, referring source, approximate region derived from IP, timestamps, cookie or similar-technology identifiers, errors, and security events.

Communications

Messages, support requests, survey responses, recorded consent, and interactions with ASA channels. ASA records a call or virtual session only with the notice or permission required for the activity.

Sources

ASA may receive information:

  • directly from the person or organization;
  • from an authorized organization representative;
  • from event, education, application, payment, email, hosting, security, or other service providers;
  • from public government, corporate, professional, scientific, or media records;
  • from members, reviewers, speakers, partners, or other participants acting within an authorized process;
  • through website and account use.

How ASA uses information

ASA may use personal information to:

  • respond to inquiries and provide requested services;
  • review and administer membership;
  • authenticate accounts and control access;
  • deliver member, committee, policy, regulatory, education, event, and publication functions;
  • process transactions and maintain financial records;
  • manage communications and preferences;
  • evaluate applications and administer NutraFormula Awards;
  • publish consented leadership, member, author, faculty, or registry records;
  • receive and review concerns, correct records, and enforce terms or policies;
  • operate, measure, maintain, secure, and improve services;
  • meet legal, tax, governance, contractual, insurance, audit, safety, and records obligations;
  • establish, exercise, or defend legal claims;
  • create de-identified or aggregated information subject to reasonable safeguards.

Where law requires a legal basis, ASA identifies the applicable basis in the activity notice, such as consent, contract, legitimate interests, or legal obligation.

When ASA discloses information

ASA may disclose personal information:

To service providers

Providers that support hosting, content management, authentication, email, meetings, event registration, payment, accounting, membership administration, applicant evidence storage, analytics, security, accessibility, and professional services. They receive information for defined services under appropriate terms.

Within member or program functions

Authorized organization administrators may manage their representatives. Committee, event, author, applicant, and reviewer information may be shared with participants when necessary and disclosed in accordance with the relevant notice.

In public records

ASA may publish approved leadership, staff, advisor, author, faculty, member-directory, policy, event, or award-registry information. Public fields and consent or authority should be clear before publication.

For legal, safety, and integrity purposes

ASA may disclose information when reasonably necessary to comply with law or process; respond to an authority; protect rights, safety, security, records, or services; investigate misuse; conduct fair review; enforce agreements; or address an emergency.

In an organizational transaction

Information may be transferred as part of a merger, reorganization, financing, asset transfer, or similar event subject to appropriate notice and protection.

ASA does not sell personal information for money. ASA does not use personal information for cross-context behavioral advertising. ASA must change this statement and provide legally required choices before adopting a materially different practice.

Cookies and similar technologies

ASA may use technologies necessary for security, authentication, preferences, forms, and service operation. Optional analytics or media technologies should load only according to the notice and choice required by applicable law. The cookie control identifies categories, purposes, providers, and duration.

Browser signals are handled according to ASA’s implemented control and applicable law. Blocking some necessary technologies can affect service functions.

Communications

Users can manage optional email choices through Communication Preferences and the link in eligible messages. ASA may still send messages needed for an account, transaction, event, governance duty, security, legal obligation, or requested service.

Manage communication preferences

Data retention

ASA retains personal information for the period reasonably necessary for the purpose, legal and tax obligations, governance records, contracts, disputes, security, safety, program integrity, and applicable limitation periods. Retention differs by record type. When retention ends, ASA deletes, de-identifies, or securely disposes of information subject to backup cycles and legal holds.

The internal records schedule controls exact periods. ASA should disclose a more specific period in an application or activity notice when it materially affects the person’s decision.

Security

ASA uses administrative, technical, and physical safeguards appropriate to the information and service, including role-based access, secure transfer, multifactor authentication for sensitive administrative roles, logging, backup, and incident procedures where implemented. No system can guarantee absolute security.

Do not send passwords, authentication codes, payment-card data, confidential formula evidence, or sensitive personal information through a general contact form.

International access and transfers

ASA is based in the United States. Information may be processed in the United States and other locations used by approved providers or reviewers. Where required, ASA uses an appropriate transfer mechanism and activity-specific notice. Applicants should review cross-border terms before submitting restricted evidence.

Children

ASA services are directed to professionals and organizations and are not intended for children under 13. ASA does not knowingly collect personal information directly from a child under 13 through general services. If a child’s information was submitted improperly, contact ASA for review. A program intended for minors requires a separate approved notice and safeguards before operation.

Privacy rights and choices

Depending on location and relationship, a person may have the right to request access, correction, deletion, restriction, portability, withdrawal of consent, or review of certain processing; object to some uses; or appeal a privacy decision. Rights can be limited by identity verification, legal obligations, privilege, safety, freedom of expression, records integrity, or another lawful exception.

ASA will not unlawfully discriminate against a person for exercising a privacy right.

Submit a privacy request

State the relationship with ASA, request, relevant account or record, jurisdiction, and preferred contact. ASA verifies identity and authority proportionately. An agent may need to show authorization.

Submit a privacy request

Do not send identity documents until ASA provides the secure method.

Changes to this Policy

ASA posts the effective and updated dates. If a change materially affects how existing information is used, ASA provides notice and choice where required. Prior versions are retained when necessary to understand the applicable terms.

Contact

Privacy questions and requests use ASA’s designated privacy route. Formal legal notices use the method in the Terms of Use.

Contact the privacy function

Exercise a privacy choice

Submit a privacy request

For optional email, manage communication preferences.