diff --git a/ws/templates/privacy/home.html b/ws/templates/privacy/home.html index 74cbd769..c0b06fcc 100644 --- a/ws/templates/privacy/home.html +++ b/ws/templates/privacy/home.html @@ -14,10 +14,13 @@
- At MITOC, we take privacy very seriously. +
+ MITOC is committed to supporting the privacy of all who participate in the club. + This Privacy Statement explains how we handle and use the personal information we collect about anyone who uses this site.
+We strive to collect the least amount of information necessary and give you control over how that data is used. @@ -30,7 +33,26 @@
+ While specific information may vary for particular individuals, we may collect, + use, store and transfer different kinds of personal information about you. + We collect your name, email address, emergency contact information. We also collect + a record of which trips you sign up for, as well as a record of which you + participate on. You have the option to also supply information about your + car, any emergency information you wish to share with leaders. +
++ You can manage the data you share + and/or download data MITOC stores about you. +
+ ++ The personal information we collect is generally supplied by you when using this site. +
+ +We place a very small cookie in your browser when you use this site. The cookie is used only to manage your session. This cookie keeps you logged @@ -45,12 +67,15 @@
Related: Personal Information, Privacy
++ We use your personal information for a number of legitimate purposes all in support of the Institute and its mission. +
+When you attend a MITOC trip, we supply trip leaders with the details of any MITOC items that you may have rented from the office. @@ -77,10 +102,15 @@
+ If you have concerns about any of these purposes, or how we communicate with you, please contact us. + We will always respect a request by you to stop processing your personal information (subject to our legal obligations). +
-+ By using this site, you share some information with the following companies/services: +
@@ -90,7 +120,8 @@
+ MIT uses risk-assessed administrative, technical and physical security + measures to protect your personal information. Your information lives in + a Postgres database (behind a Virtual Private Cloud) administered by + Amazon Web Services. Direct database access is restricted to MITOC's + elected webmasters. +
+ ++ We automatically remove all participant-supplied medical information + after 6 months of activity. You can remove most profile information at + any time. Legal waivers, any monetary payments to the club, and + any participation on past trips are retained indefinitely. +
+ ++ You have the right in certain circumstances to (1) access your personal + information; (2) to correct or erase information; (3) restrict processing; and + (4) object to communications, direct marketing, or profiling. To the extent + applicable, the EEA’s General Data Protection Regulation (GDPR) provides + further information about your rights. You also have the right to lodge + complaints with your national or regional data protection authority. +
+ ++ If you are inclined to exercise these rights, we request an opportunity + to discuss with you any concerns you may have. To protect the personal + information we hold, we may also request further information to verify + your identity when exercising these rights. Upon a request to erase + information, we will maintain a core set of personal data to ensure we do + not contact you inadvertently in the future, as well as any information + necessary for MIT archival purposes. We may also need to retain some + financial information for legal purposes, including US IRS compliance. In + the event of an actual or threatened legal claim, we may retain your + information for purposes of establishing, defending against or exercising + our rights with respect to such claim. +
+ ++ By providing information directly to MIT, you consent to the transfer of + your personal information outside of the European Economic Area to the + United States. You understand that the current laws and regulations of + the United States may not provide the same level of protection as the + data and privacy laws and regulations of the EEA. +
+ ++ You are under no statutory or contractual obligation to provide any + personal data to us. The controller for your personal information is MIT. +
+ ++ If you are in the EEA or UK and wish to assert any of your applicable GDPR + rights, please contact dataprotection@mit.edu. + You may also contact MIT’s representatives listed below: +
+ ++ J-PAL Europe: + 48 Boulevard Jourdan, 75014 Paris, France +
+ + ++ MIT Press UK: + 71 Queen Victoria Street, London, United Kingdom, EC4V 4BE +
+ ++ We may change this Privacy Statement from time to time. If we make any + significant changes in the way we treat your personal information we will + make this clear on our MIT websites or by contacting you directly. +
+