Loading...

About ATMIA
About ATMIA

Privacy Policy

Last Updated: August 17, 2026

(Supersedes Policy effective November 18, 2025)

The ATM Industry Association (ATMIA) (“we,” “our,” or “us”) is the leading non-profit trade association representing the global ATM industry. We are committed to protecting the privacy and security of our members, event participants, partners, and visitors (“you”).

This Privacy Policy explains how we collect, use, store, and safeguard your personal data in accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), and other applicable data protection laws.

1. Data Controller and Contact Information

ATM Industry Association (ATMIA)

PO Box 88433
Sioux Falls, SD
57109-8433
USA

Email for Privacy Requests: [email protected]
Phone: 800-475-0585 ext. 1704

If you have any questions about this policy or your rights, please contact us using the email address above.

2. Personal Data We Collect

Our overall policy is simple: If we collect information from you, we use it only for the purposes for which it was collected, and the limited purposes outlined below. We collect the following categories of data, which may be considered "Personal Information" under US laws:

Category of DataExamples of Data CollectedSource in Current ATMIA Policy
IdentifiersName, Home Address, Email address, Phone number, IP addressMembership, Events, Forms & Online Surveys
Professional/EmploymentJob title, Organization/Company name, Membership status and historyMembership, Events
Demographic InformationLocation, AgeMembership,  Forms & Online Surveys
Financial/TransactionalPayment details (processed securely), invoice and billing dataMembership, Events, Payments
Internet/Network ActivityBrowser type, operating system, referral domain, website usage analytics, data from cookiesAutomatic Collection
CommunicationEmails, inquiries, survey responses, newsletter subscription preferencesForms/Contacting
Event ParticipationRegistration details, attendance records, mobile app usage, speaker detailsEvents

We do not collect sensitive personal data unless explicitly required and consented to (e.g., accessibility requirements for an event).

3. How We Use Your Personal Data and Legal Basis

Purpose of UseLegal Basis (GDPR)Use in Current ATMIA Policy
Membership, Events & Service FulfillmentPerformance of a contractProcessing applications, renewals, member services, event registration, mobile app functionality
Organizational CommunicationsLegitimate InterestSending organizational updates, newsletters, and contacting the user
Website Operation & DiagnosticsLegitimate Interest; Consent (for non-essential cookies)Improving site performance, diagnosing server problems, and site administration
Billing & AccountingCompliance with legal obligationsProcessing payments and maintaining financial records
Aggregated SharingLegitimate InterestSharing non-personally identifiable data (like demographics) with affiliates or business partners on an aggregated basis

4. Sharing Your Personal Data

We have a firm commitment to privacy. We will not sell or disclose your personal data to any third party that is not an affiliate of ATMIA, and we will not share it for cross-context behavioral advertising (as defined by the CCPA/CPRA), except in the following circumstances:

  1. We first obtain your permission;
  2. We share it with agents or contractors who perform services on our behalf (e.g., payment processors, email service providers, IT support, website security/analytics providers) under contracts that restrict their use of your data to those services; or
  3. We are required by law to disclose it (e.g., in response to a court order or valid legal process).
  4. Your profile or contact information is made visible to other ATMIA members through the Member Directory or Member-to-Member Connections tool, based on the sharing preferences you set in your account. You can review or change these preferences at any time by logging into your member profile.

5. International Data Transfers (GDPR/EEA)

If you are visiting our Site from outside the United States, be aware that your information will be transferred to, stored, and processed in the United States where our servers are located and our central database is operated. By using our services, you consent to any transfer of this information.

When transferring personal data out of the European Economic Area (EEA), we ensure adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) or transfers to countries with adequacy decisions. You may request details on these safeguards by contacting us.

VendorServiceData Processed / Security
CloudflareWebsite Services (Firewall, DDos Protection, Bot Management, Rate Limiting, Analytics)

Data Processed: IP Address, browser information, request headers.

The processing of data is based on Standard Contract Clauses, which you can find here: https://www.cloudflare.com/cloudflare-customer-scc/.

For more information on Cloudflare, please visit the privacy policy at: https://www.cloudflare.com/cloudflare-customer-dpa/.

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/5666.

Authorize.netCredit Card Processing

Data Processed: Credit Card Number, CID, Expiration Date, Company Name, Shipping/Billing Address, IP Address.

We do not store credit card data on our servers. All data required for transactions is transmitted securely and stored by Authorize.net. You may find their privacy notice link(s) here: https://www.authorize.net/content/dam/anet-redesign/documents/authorizenet-dpa.pdf and https://www.authorize.net/en-us/about-us/terms.html.

Constant ContactEmails

Data Processed: Name, Email Address, Subscription Preferences, Engagement Data.

The processing of data is based on Standard Contractual Clauses which can be found here: https://www.constantcontact.com/legal/data-processing-addendum

The company is certified in accordance with the “EU-US Data Privacy Framework” (DPF). The DPF is an agreement between the European Union and the US, which is intended to ensure compliance with European data protection standards for data processing in the US. Every company certified under the DPF is obliged to comply with these data protection standards. For more information, please contact the provider under the following link: https://www.dataprivacyframework.gov/participant/4423.

ChatlingAI Chatbot (website Q&A assistant)

Data Processed: The questions and information you type into the chatbot, along with limited technical data (e.g., IP address) needed to operate the chat session.

Chatling acts as a data processor and relies on its own sub-processors — including cloud hosting and AI-model providers (e.g., OpenAI, Anthropic, Google, Mistral) — to generate responses. A current list of Chatling's sub-processors is available here: https://chatling.ai/eu-data-protection
Chatling offers a GDPR-compliant Data Processing Agreement incorporating Standard Contractual Clauses: https://chatling.ai/dpa
Chatling's Privacy Policy: https://chatling.ai/privacy-policy

6. Data Retention

We retain your information for as long as your account is active or as needed to provide you with access to our services. We will retain and use your information as necessary to:

  • Comply with our legal obligations (e.g., financial records kept for 7 years).
  • Resolve disputes and enforce our agreements.

We maintain one or more databases to store your personal data and may keep such information for historical reference or legal compliance based on the timeframes below, or until you exercise your right to request deletion.

  • Membership Information: Retained for the duration of membership + 7 years for historical reference and legitimate interest
  • Event Registrations: Retained for 7 years for historical reference and legitimate interest
  • Form Submissions: Kept for 3 years for historical reference and legitimate interest
  • Financial Records: Kept for 7 years to comply with US and international tax and accounting laws
  • Marketing Data: Retained until you withdraw consent (e.g., unsubscribe from a newsletter)
  • Cookies & Website Analytics Data: Up to 26 months from collection, consistent with our cookie settings, after which it is deleted or aggregated

7. Your Rights Under GDPR (EEA Residents)

If you are a resident of the EEA, you have the following rights regarding your personal data:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten"): Request deletion of your data
  • Right to restrict processing: Limit how your data is used
  • Right to data portability: Obtain your data in a transferable format
  • Right to object: Object to processing based on legitimate interests or direct marketing
  • Right to withdraw consent: Withdraw consent at any time for data processing based on consent

8. Your Rights Under US Privacy Laws

If you are a resident of California (CCPA/CPRA) or Texas (TDPSA), you have the following rights concerning your Personal Information:

  • Right to Know: Request disclosure of the categories and specific pieces of information collected
  • Right to Delete: Request the deletion of your personal information, subject to certain exceptions
  • Right to Correct: Request the correction of inaccurate personal information
  • Right to Opt-Out of Sale/Sharing: ATMIA does not sell your information and any sharing to other members is based on your preferences set in your account. To our knowledge any 3rd party service we use does not sell personal information or share it for cross-context behavioral advertising. If you would still like to submit an opt-out request, or if you have questions about a specific third-party tool used on our Site, contact us using the details in Section 1.
  • Right to Non-Discrimination: The right not to receive discriminatory treatment

To exercise your rights under GDPR, CCPA, or TDPSA, please submit a request to our Privacy Contact at: [email protected].

9. Opting Out of Communications and Targeted Advertising

A. Opting Out of Communications

  • Mailings: Users may opt-out of future mailings using the unsubscribe link or contacting us.
  • Account Removal/Correction: Contact us at [email protected] or visit your member profile to correct or remove information.

B. Opting Out of Targeted Advertising

You may opt out of receiving targeted ads through the following industry tools:

We also honor Global Privacy Control (GPC) signals as a valid opt-out-of-sale/sharing request for browsers where GPC is enabled, in accordance with the CCPA/CPRA.

10. Cookies

We use cookies to make our website easier to use and to deliver a personalized experience. You may modify browser settings to accept, notify, or reject cookies, but rejecting cookies may prevent you from utilizing certain services. By default only functional cookies are accepted on this website. Preferences can be changed at any time by clicking the cookie icon in the lower left of the page.

11. Mobile Application Disclosure

The ATMIA Conference mobile app uses personal information after login to provide functionality like My Agenda, My Exhibitors, Game Center Leaderboard, and sharing Attendee Details (email, phone, photo) based on user settings. ATMIA tracks app usage on a de-identified basis, using device and usage identifiers rather than your name or contact details..

12. SMS Messaging

ATMIA allows US residents to sign up to receive SMS messages. Message content and frequency vary. View the Terms of Use for complete details.

13. AI Chatbot

Our website uses an AI-powered chatbot, provided by Chatling, to help answer questions from visitors and members. When you use the chatbot, the questions and information you type are processed by Chatling and, in turn, by the AI model providers Chatling relies on to generate a response, in order to produce an answer for you. Chatling acts as a data processor on our behalf under a Data Processing Agreement incorporating Standard Contractual Clauses.

We do not knowingly use the chatbot to collect sensitive personal information, and we recommend you avoid entering sensitive details — such as payment card numbers, government ID numbers, or health information — into the chat window. Your chatbot inputs are not used to train Chatling's or its underlying AI providers' models. Chat transcripts may be retained for a limited period to operate and improve the chatbot, consistent with the retention practices described in Section 6, and to allow our staff to follow up on unanswered questions.

For more information on how Chatling processes data on our behalf, see its EU Data Protection page (https://chatling.ai/eu-data-protection) and Privacy Policy (https://chatling.ai/privacy-policy).

14. Children’s Privacy

ATMIA’s websites and services are not directed to or intended for children under the age of 13, and ATMIA does not knowingly collect personal information from children under the age of 13. If we learn that we have inadvertently collected personal information from a child under the age of 13, we will take reasonable steps to delete that information from our records.

A parent or legal guardian who believes that a child under the age of 13 has provided personal information to ATMIA may request deletion of that information by contacting us at [email protected]. The request should include sufficient information to allow us to identify the child’s information and the circumstances under which it may have been provided. We may request additional information as reasonably necessary to verify the identity and authority of the parent or legal guardian and to locate the information.

Upon verification of the request, ATMIA will take reasonable steps to locate and delete the child’s personal information from its systems, subject to any information that must be retained to comply with applicable legal, regulatory, security, or recordkeeping requirements. We will notify the requesting parent or legal guardian when the deletion request has been addressed.

15. Security Measures

While no method of transmission or storage is 100% secure, we take reasonable steps designed to protect your personal information, including:

  • Encrypted communications (SSL/TLS)
  • Access controls and authentication
  • Secure data storage and backup procedures

If you become aware of a security incident involving your information, please contact us using the details in Section 1.

16. Changes to This Policy

This statement may change over time—please review it periodically. We will update the “Last Updated” date at the top of the policy accordingly.

17. Contact Us

If you have any questions about this privacy statement, the practices of this site, or your dealings with this Web site, you can email ATMIA at: [email protected].


In This Section
Special Offer Image

Global Sponsors

Sponsorship Information