Privacy Policy

1. Who We Are

The Trinidad & Tobago Medical Association (T&TMA) is a registered medical professional body operating in the Republic of Trinidad & Tobago. Our website is located at https://tntmedical.com.

For data protection purposes, T&TMA acts as the Data Controller under the Trinidad & Tobago Data Protection Act 2011 (Act No. 13 of 2011).

Contact for privacy matters: medassoc@tntmedical.com

2. What Personal Data We Collect

When you register for an event or purchase through our website, we collect the following:

  • Full name
  • Email address
  • Phone number (optional)
  • Country of residence
  • T&TMA membership number
  • Occupation and place of work
  • Event preferences (meal, CME certificate delivery)
  • Payment transaction reference number and amount (we do NOT store card numbers)

We also collect the following automatically when you visit the site:

  • IP address and browser type (for security and analytics purposes)
  • Cookie data (see Section 6 — Cookie Policy)

3. Why We Collect This Data (Legal Basis)

Data TypePurposeLegal Basis (T&T DPA 2011)
Name, email, membership no.Process event registration and issue CME certificateContract performance / Consent
Occupation, place of workVerify membership tier; AACME certificate accuracyLegitimate interest / Consent
Payment transaction referenceFinancial record-keeping and auditLegal obligation (financial records)
Email (for newsletters)Send T&TMA updates and announcementsConsent (opt-in only)
IP address / browserWebsite security and fraud preventionLegitimate interest

4. Payment Processing — Fygaro / First Atlantic Commerce

All card payment processing is handled by Fygaro, operated by First Atlantic Commerce (FAC). Fygaro is a PCI DSS-certified payment gateway. When you click ‘Proceed to secure payment’, you are redirected to Fygaro’s hosted payment page.

T&TMA does NOT:

  • See, capture, or store your credit or debit card number
  • Store CVV/CVC security codes
  • Have access to full card details at any stage

T&TMA DOES store:

  • Your name, email, and order reference number (for receipting purposes)
  • The transaction amount and date

Fygaro’s privacy policy is available at: https://www.fygaro.com/en/privacy-policy

5. Data Hosting — GoDaddy

This website is hosted on GoDaddy servers, which are located in the United States of America. By submitting your personal information on this website, you acknowledge that your data may be transferred to and processed in the United States.

GoDaddy maintains appropriate technical and organisational security measures. Their privacy policy and data processing agreement are available at https://www.godaddy.com/legal/agreements/privacy-policy.

6. Cookie Policy

This website uses cookies. A cookie is a small text file stored on your device. We use the following categories:

CategoryPurposeCan be declined?
NecessaryWooCommerce cart, session, login — required for site to functionNo
AnalyticsGoogle Analytics — website usage statisticsYes
MarketingThird-party advertising or retargeting (if applicable)Yes

You can manage your cookie preferences at any time via the cookie consent banner. Your preferences are logged by CookieYes for compliance purposes.

7. How Long We Keep Your Data

  • Active member accounts: retained while membership is active + 2 years
  • Completed order/registration records: retained for 3 years (CME records and financial audit requirements)
  • Pending or abandoned orders: deleted after 30 days
  • Marketing consent and email lists: retained until you unsubscribe
  • Cookie consent logs: retained for 3 years

8. Your Rights Under the T&T Data Protection Act 2011

You have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate personal information
  • Request deletion of your personal data (subject to legal retention requirements)
  • Withdraw consent at any time (where consent is the legal basis)
  • Lodge a complaint with the Office of the Information Commissioner of Trinidad & Tobago

To exercise any of these rights, email: medassoc@tntmedical.com with the subject line ‘Data Protection Request’. We will respond within 30 days.

9. Data Security

We implement the following security measures to protect your data:

  • HTTPS/TLS encryption on all pages of the website
  • Two-factor authentication (2FA) required for all WordPress administrator accounts
  • Regular WordPress core, theme, and plugin updates
  • Automated encrypted website backups
  • Access to the WordPress admin panel is restricted to named administrators

10. Changes to This Policy

We may update this Privacy Policy from time to time. The current version will always be available at https://tntmedical.com/privacy-policy. Material changes will be notified by a notice on the website homepage.

Back to top button