Privacy and Security Effective Date: MARCH 15, 2024 This Privacy Notice (“Notice”) explains how the YMCA Retirement Fund (“Fund”, “we”, “us” or “our”) collects, uses, discloses, and protects personal information. The Fund collects your personal information in a variety of ways. Examples include interactions involving a product or service you obtain from us; when you visit our website and/or our mobile app; when you use our IVA; and when you contact our customer service department. “Personal information” means information that (either in isolation or in combination with other available information) enables you to be identified as an individual or recognized directly or indirectly. It would not include aggregate or de-identified information or various types of publicly available information. Examples of “personal information” include the following: Name Date of birth Marital status Mailing address Email address Phone numbers Social security number Biometric identifiers (voiceprint; fingerprint; facial recognition) Beneficiary information Passwords Answers to security questions IP addresses Customer service recordings Bank account information Personal information will be used to access your records, for you to use our website, mobile app and IVA or for purposes described to you at the point of collection (collectively “Services”). Please be aware that although we have implemented reasonable security measures and technologies in an effort to safeguard personal information, such as the use of two-factor authentication, we cannot guarantee that personal information, during transmission or while stored on our systems, will be kept confidential from unauthorized users or hackers or during an unanticipated system outage. The Fund collects general information about visitors in order to analyze visitors’ interests and improve this site. The Fund will not knowingly give, sell, or transfer any personal information to a third party. No attempts are made to identify individual visitors unless illegal behavior is suspected. The Fund and its service providers monitor network traffic to identify unauthorized attempts to upload or change information or damage this site. The Fund may enable “cookies” on our website and mobile app. You may disable the use of cookies by modifying your browser settings. Occasionally the Fund will email or text you notices about your account and programs available to you. Some programs will be accessible on the Fund’s website and/or mobile app or on third party websites. If you do not wish to receive these notices, you may unsubscribe at any time by replying to our email message and typing “unsubscribe” in the subject line or by replying to our text message and typing “stop.” We may revise this Notice. If we make material changes, we will notify you as required by law. USE OF YOUR PERSONAL INFORMATION We may use the information that we collect or receive about you for various purposes. a. To Provide You With Our Services. We use your information to provide you Services with respect to the Fund. Your information may be available or provided to third-party service providers that provide services on behalf of the Fund. b. To Maintain, Improve, and Personalize Our Services. We use your information for our everyday business operations such as auditing, administration, and analytics. Your information may also be used to improve our Services or to personalize your Services. c. To Communicate with You. We use your information to communicate with you. We may also contact you with offerings or other communications that may be of interest to you. If we send you marketing emails, each email will contain instructions permitting you to “opt-out” of receiving future marketing or other communications. d. For Security Purposes. Keeping your Account safe requires us to process your personal information. We use such information to combat spam, malware, malicious activities, and security risks; improve and enforce our security measures; and monitor and verify your identity so that unauthorized users do not gain access to your information. e. To Maintain Legal and Regulatory Compliance. Our Services are subject to certain laws and regulations which may require us to process your personal information. f. For Our Business Purposes. We may use your information for any other purpose disclosed to you at the time we collect or receive the information, or otherwise with your consent. We may share your information with our affiliates (entities that control or are under the control of the Fund) for business purposes. CONTACT US FOR QUESTIONS OR INFORMATION If you have any questions or concerns relating to this Notice or our privacy practices please contact us. YMCA Retirement Fund 120 Broadway New York, NY 10271 TWO-FACTOR AUTHENTICATION TERMS AND CONDITIONS By logging into your account on yretirement.org, you agree to the YMCA Retirement Fund Two-Factor Authentication Terms and Conditions (“2FA Terms”). You authorize the Fund to communicate with you (directly or through a third-party) by email, text, and/or voice call (as you have selected), to provide you with a single-use verification code to log into your account on yretirement.org. You are responsible for any message or data charges that you incur through the use of 2FA. In addition, you are responsible for timely updating any phone number(s) and email address(es) that you have on file with the Fund. The email, text, or voice call that delivers your verification code is initiated when you log into your account on yretirement.org. If you receive a verification code at any other time or have questions about the security of the verification code that you receive, please immediately contact the Customer Service Department via Live Chat or call us directly at 800-RET-YMCA (800-738-9622), Monday through Friday from 9:00am to 5:00pm ET. If you wish to change the method (email, text, or voice call) that you elected for receiving verification codes, log into your account on yretirement.org, go to your Personal Information screen, and update your 2FA “Pick Your Delivery Method” election. The Fund may revise the 2FA Terms. By logging into your account on yretirement.org after such posting, you agree to the current 2FA Terms.