Effective Date: October 20, 2022
Mount St. Joseph University (the “University”) is committed to the privacy of its community and guests. This Privacy Policy explains the types of personal data the University collects and how that data is used.
Who You Can Contact About This Policy
For questions or actions related to this Policy, please contact the University’s Vice President of Compliance, Risk, and Legal Affairs/General Counsel, Paige Ellerman, at Paige.Ellerman@msj.edu.
Related Policies
This Policy is governed by the University’s “Terms of Use” which are incorporated herein by reference, including the limitations of liability set forth therein.
University students and employees are subject to additional standards regarding technology, website, and email usage, as set forth in the applicable University Employee Handbook, University Student Handbook, and other University internal policies and procedures (“Internal Policies”). As to University students and employees: (i) in the event of a conflict between those Internal Policies and this Policy, the Internal Policies shall prevail; and (ii) this Policy shall supplement, rather than replace, such Internal Policies.
How and What Information The University Collects
Information Voluntarily Provided
The University collects personal information that you voluntarily provide when you use the University’s website (“Website”) and related services, applications, and functionality (“Services”). The University also collects personal information from third parties whom you have directed to provide information to the University. For example, the University may collect personal and sensitive information about you in connection with your account on The Roar Store website such as your full name, mailing address, mobile number, and email address, account information such as a password or other information that helps us confirm that it is you accessing your account, and demographic or other information such as your gender, age or birthdate, zip code and information about your interests and preferences. We will also collect payment information (typically, credit card account information) if you choose to purchase products or services through the Services. And, when you make a purchase or otherwise transact with the University, whether online or offline, we will retain information regarding those purchases and transactions, including, but not limited to products purchased, location of purchase, and how frequently you make purchases. Any information combined with Personal Information will be treated as Personal Information.
Publicly Facing Technology Services
The University’s publicly facing technology services collect personal information you provide voluntarily, such as when completing applications and forms, sending emails, registering for classes or other programs, responding to surveys, and filing complaints.
Information Automatically Collected
The University collects certain information about you automatically which does not specifically identify you or contain personal information, when you use or interact with the Website and Services. For example, the University may collect your IP address, domain information, browser and operating system information, usage data (including the date and time you access the Website and Services), and location data.
Cookies and Tracking Features; Do-Not-Track Signals
Cookies are small pieces of data stored by a web browser on your local computer or mobile device, used to remember information about preferences and pages you have visited. By setting preferences in your browser, you can refuse to accept cookies, disable cookies, and remove cookies from your hard drive. The University collects your personal and other information through cookies and other tracking features, such as targeting cookies/marketing cookies, social media cookies, beacons/pixels/tags, click redirects, and social media plugins (through features such as a “Like” button, and widgets, such as a “Share” button). The University does not currently respond to Do-Not-Track browser signals or any other mechanism that automatically communicates your choice not to be tracked online.
How the University Uses Your Information
The University uses your personal information to administer and offer the Website and Services, to operate its programs, and to improve its practices and enhance user experiences with such Website and Services. In any event, the University processes your information in accordance with applicable law and as reasonably necessary in connection with its programs and services as a higher educational institution. Processing such personal data of its students, employees, applicants, research subjects, alumni, and others involved in the University’s programs and services may be done, without limitation, in connection with:
If you provided consent for the University to process your personal information, you may request to withdraw your consent at any time by contacting Paige.Ellerman@msj.edu. Withdrawing your consent will not affect the lawfulness of the processing before its withdrawal, nor when applicable law allows, will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent. Some data required to be held for legal or accreditation reporting purposes cannot be withdrawn. The University shall have a reasonable amount of time in which to review and implement your request. Withdrawing your consent or refusing to provide personal data that is required by the University may make it impossible for the University to provide certain services.
Sharing Personal Data
The University shares personal data with other parties when one or more of the following conditions apply:
In certain circumstances, the University may be required by law to disclose personal or other information provided to us through our Website or Services.
Statutory Compliance
The University complies with, when applicable: (i) the Family Educational Rights and Privacy Act (“FERPA”); (ii) the Health Insurance Portability and Accountability Act (“HIPAA”); (iii) the Jeanne Clery Disclosure of Campus Security Policy and Campus Crime Statistics Act (“Clery Act”); and (iv) other applicable laws. The University will disclose your personal information as it deems reasonably necessary to comply with the foregoing.
How Long the University Keeps Your Information
The University generally complies with its Records Retention and Document Destruction Policy, as the same may be updated from time to time by the University in its sole discretion.
Linking
The Website and related Services may link to third-party websites which are not controlled by the University or subject to this Policy. The University shall have no liability for your interactions with third party websites or any damages resulting therefrom.
GDPR provides broad privacy protections to individuals physically located in the European Economic Area (“EEA”) (“data subject(s)”). The following sections only apply when the University is subject to GDPR with respect to certain data, and only to the applicable data subject(s):
A. GDPR Lawful Bases for Processing Personal Data
The University must have a lawful basis to process a data subject’s personal data. The following lawful bases will apply to most processing activities:
B. GDPR Individual Rights of the Data Subject
Subject to all other applicable laws and regulations, including all laws of the United States and the State of Ohio, where legally applicable, certain data subjects have the following rights under the GDPR, when GDPR applies:
Under certain circumstances, the GDPR or other applicable laws may limit a data subject’s exercise of the above rights. To exercise the above rights, data subjects should contact Paige.Ellerman@msj.edu. Exercising these rights is not a guarantee of a requested outcome.
The University takes appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information it processes. However, despite safeguards and efforts to secure your information, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. To the maximum extent permitted by applicable law, the University cannot and does not promise or guarantee that unauthorized third parties will not be able to defeat its security and improperly collect, access, steal, or modify your information. Transmission of personal information to and from our Website Services is at your own risk, to the extent permitted by applicable law.
Amendments
The University may amend this Policy at any time and from time to time, in its sole discretion. All such amendments will be in effect as of the date such amended version is posted on the University’s Website.