About Digital Privacy: PSU Web Privacy Notice

PSU computer lab

Introduction

This Privacy Notice describes our practices and procedures on the collection, use, and disclosure of your information when you use the Portland State University (PSU) main website (pdx.edu). This also pertains to other websites that we own and control unless otherwise indicated. By using our websites, you are consenting to our collection and use of information in accordance with this privacy notice.

On many PSU websites, we may also link to non-PSU websites which will have their own privacy practices. We encourage you to read their privacy notice as we are not responsible for the content or practices of those sites.

Our Privacy Notice explains: (1) what information we collect; (2) why we collect it; (3) how we use that information; (4) how we may share it; (5) the choices we offer, including how to access and update information; (6) and the measures we take to keep your information safe. Specifically, our Privacy Notice covers the following topics:

  1. Information We Collect
  2. How We Use Information We Collect
  3. Sale of Personal Information
  4. Our Legal Basis for Collecting Personal Data
  5. Information We Share
  6. Your Failure to Provide Personal Data
  7. Our Retention of Your Personal Data
  8. Your Rights and Choices
  9. Our Opt-in/Opt-out Policy
  10. Third Party Links
  11. International Transfer
  12. How We Protect Personal Data
  13. Children
  14. PSU Partners
  15. Changes to this Privacy Policy
  16. How to Contact Us

Please familiarize yourself with our privacy practices and let us know if you have any questions. By using the Sites, you signify your acceptance of this Privacy Policy. If you do not agree to this Privacy Notice, please do not use the Sites.

Irrespective of which country you live in, you authorize us to transfer, store, and use your information in the United States. In some countries, the privacy and data protection laws and rules regarding when government authorities may access data may vary from those in the country where you live. Learn more about our data transfer operations in the “International Transfer” section below. If you do not agree to the transfer, storage and use of your information in the United States, please do not use the Sites or Services.

If you have any questions or comments about this Privacy Policy, please submit a request to DPO@pdx.edu or visit the Helpdesk located here.

Information We Collect

We collect information, including personal data, to provide better services to all our Users. We use the term “Personal Data” to refer to any information that identifies or can be used to identify you. Common examples of Personal Data include: full name, email address, digital identity, such as a login name or handle, information about your device, and certain metadata.

“Sensitive Personal Data” refers to a smaller subset of Personal Data which is considered more sensitive to the individual, such as race and ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric information, physical or mental health information, medical insurance data, or sexual orientation.

When you use our Services, we collect Personal Data in the following ways:

1. Information You Give to Us
As you use the website you may choose to provide us with Personal Data about yourself, including your name, phone number, address, country of residence, and email address by completing forms on our website, such as when you request admission information. You may also choose to provide us with employment and education information when you apply for a job at PSU via our Site.

In some instances, you may elect to provide us with location and address information. You may also provide us with Personal Data about yourself when you report a problem or have a question about our site.

The Sites offer interactive and social features that permit you to submit content and communicate with us. You may provide Personal Data to us when you post information in these interactive and social features. Please note that your postings in some areas of the Sites may be publicly accessible or accessible to other Users.

2. Information We Obtain from Your Use of Our Site
We collect certain information automatically, such as your operating system version, browser type, and internet service provider. We also collect information about your interaction with the Site. When you use our Site, we automatically collect and store this information in service logs. This includes: details of how you used our Site; Internet protocol address; cookies that uniquely identify your browser, the referring web page and pages visited. We may also collect and process information about your actual location. The information we collect automatically is statistical data and may or may not include Personal Data.

3. Cookies and Similar Technologies
We use various technologies to collect and store information when you visit one of our sites, and this may include using cookies or similar technologies to identify your browser or device. Our third-party analytics partners include Google Analytics and similar partners.

The technologies we use for this automatic data collection may include:

Cookies. A cookie is a small file placed on the hard drive of your computer. You may refuse to accept browser cookies by activating the appropriate setting on your browser. However, if you select this setting you may be unable to access certain parts of our services. Unless you have adjusted your browser setting so that it will refuse cookies, our system will issue cookies when you direct your browser to our services. We use both persistent and session cookies for the purposes set out below:

  • Necessary / Essential Cookies (Session Cookies)
    Administered by: PSU
    Purpose: These cookies are essential to provide you with services available through the website and to enable you to use some of its features. They help to authenticate users and prevent fraudulent use of user accounts. Without these cookies, the services that you have asked for cannot be provided, and we only use these cookies to provide you with those services.
  • Functionality Cookies (Persistent Cookies)
    Administered by: PSU
    Purpose: These cookies allow us to remember choices you make when you use the website, such as remembering your login details or language preference. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you use the website.
  • Tracking and Performance Cookies (Persistent Cookies)
    Administered by: Third-Parties
    Purpose: These cookies are used to track information about traffic to the website and how users use the website. The information gathered via these cookies may directly or indirectly identify you as an individual visitor. This is because the information collected is typically linked to a pseudonymous identifier associated with the device you use to access the website. We may also use these cookies to test new advertisements, pages, features, or new functionality of the website to see how our users react to them.

Web Beacons. Pages of our services or our e-mails may contain small electronic files known as web beacons (also referred to as clear gifs, pixel tags and single-pixel gifs) that permit us, for example, to count Users who have visited those pages or opened an e-mail and for other related website statistics (for example, recording the popularity of certain website content and verifying system and server integrity).

Clickstream Data. Clickstream data is information collected by our computers when you request Web pages from the Sites. Clickstream data may include information such as the page served, the time spent viewing the page, source of the request, type of browser making the request, the preceding page viewed and similar information. Clickstream data permits us to analyze how visitors arrive at the Sites, what type of content is popular, what type of visitors in the aggregate are interested in particular kinds of content on the Sites.

Types of data Collected

PSU may ask you to provide certain personally identifiable information (PII). PII may include, but is not limited to:
 

  • Full Name
  • Email
  • Address
  • Telephone
  • Age, Date of Birth
  • Legal Sex
  • Veteran Status
  • Race/Ethnicity
  • PSU ID number
  • Social Security Number
  • Social network account information

 

How We Use Information We Collect

We use your Personal Data in ways that are compatible with the purposes for which it was collected or authorized by you, including for the following purposes:
 

  1. To present, operate or improve the Site and Services, including analysis of Site activity;
  2. To manage your account (The personal data you provide can give you access to different functionalities of the website that are available to you as a registered user.);
  3. To inform you about PSU programs and activates;
  4. To authorize access to our Sites and Services;
  5. To administer content or other Site features;
  6. To communicate about, and administer your participation in programs and activities and to deliver pertinent emails;
  7. To improve our Site;
  8. To secure our Site, including to authenticate Users;
  9. To use statistical information that we collect in any way permitted by law, including from third parties;
  10. To respond to and support Users regarding their use of the Sites;
  11. To comply with all applicable legal requirements;
  12. To perform data analysis and testing;
  13. To investigate possible fraud or other violations of our or this Privacy Policy and/or attempts to harm our Users;
  14. To resolve disputes;
  15. To otherwise fulfill the purpose for which the information was provided.

 

We use the information we collect from our Sites to provide, maintain, and improve them, to develop new programs, and to protect our institution and our Users.

We use information collected from cookies and other technologies, to improve your User experience and the overall quality of our Site. We may use your Personal Data to see which web pages you visit at our Site, which web site you visited before coming to our Site, and where you go after you leave our Site. We can then develop statistics that help us understand how our visitors use our Site and how to improve it.

We will ask for your consent before using information for a purpose other than those set out in this Privacy Policy.

Sale of Personal Information

In the preceding twelve (12) months, we have not sold any Personal Information.

Our Legal Basis for Collecting Personal Data

Whenever we collect Personal Data from you, we may do so on the following legal bases:

  1. Your consent to such collection and use;
  2. Out of necessity for the performance of an agreement between us and you, such as your enrolment at PSU;
  3. Our legitimate business interest, including but not limited to the following circumstances where collecting or using Personal Data is necessary for:
    • Intra-organization transfers for administrative purposes;
    • Site development and enhancement, where the processing enables PSU to enhance, modify, personalize, or otherwise improve our services and communications for the benefit of our Users, and to better understand how people interact with our Sites;
    • Communications and marketing, including processing data for direct marketing purposes, and subject to your opt-in for these purposes, and to determine the effectiveness of our promotional campaigns and advertising;
    • Fraud detection and prevention;
    • Enhancement of our cybersecurity, including improving the security of our network and information systems; and
    • General operations and diligence;

Provided that, in each circumstance, we will weigh the necessity of our processing for the purpose against your privacy and confidentiality interests, including taking into account your reasonable expectations, the impact of processing, and any safeguards which are or could be put in place. In all circumstances, we will limit such processing for our legitimate business interest to what is necessary for its purposes.

Information We Share

We do not share personal data with companies, organizations and individuals outside of PSU unless one of the following circumstances applies:

  • With your consent. We will share Personal Data with companies, organizations or individuals outside of PSU when we have your consent to do so.
  • For external processing. >We provide personal information to our affiliates or other trusted businesses or partners to process it for us, based on our instructions and in compliance with our Privacy Policy and any other appropriate confidentiality and security measures. These third parties include marketing partners, third party hosted services providers, and similar partners. It is our policy to only share Personal Data with contractors, service providers and other third parties who are bound by contractual obligations to keep Personal Data confidential and use it only for the purposes for which we disclose it to them.
  • For Legal Reasons.We will share Personal Data with companies, organizations or individuals outside of PSU if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to:
     

    • meet any applicable law, regulation, legal process or enforceable governmental request.
    • detect, prevent, or otherwise address fraud, security or technical issues.
    • protect against harm to the rights, property or safety of PSU, our Users or the public as required or permitted by law.

    We attempt to notify Users about legal demands for their Personal Data when appropriate in our judgment, unless prohibited by law or court order or when the request is an emergency. We may dispute such demands when we believe, in our discretion, that the requests are over-broad, vague or lack proper authority, but we do not promise to challenge every demand.

  • Non-Personal and Aggregate Site Use Information. PSU may compile and share your information in aggregated form (i.e., in a manner that would not personally identify you) or in de-identified form so that it cannot reasonably be used to identify an individual (“De-Identified Information”). We may disclose such de-identified information publicly and to third parties, or to PSU Partners under agreement with us.

We may disclose your Personal Information for legal reasons. Specifically, we will share Personal Information with companies, organizations or individuals outside of PSU if we have a good-faith belief that access, use, preservation or disclosure of the information is reasonably necessary to:

  • Fufill any purpose for which you provide it;
  • Meet any applicable law, regulation, legal process or enforceable governmental request;
  • Enforce applicable Terms of Use, including investigation of potential violations;
  • Detect, prevent, or otherwise address fraud, security or technical issues;
  • Protect against harm to the rights, property, assets or safety of PSU, our customers or the public, content found on the Services, or to protect the Services from unauthorized use or misuse, as required or permitted by law;
  • Facilitate a business transfer, such as to a buyer or other successor in the event of merger, acquisition, consolidation, divestiture, change in control, dissolution or other sale or transfer of some or all of PSU's assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which Personal Information held by PSU about its customers and users will be among the assets to be transferred, and any such successor may use your information for the same purposes set forth in the Privacy Policy.
  • For any other purpose disclosed when you provide the information; and,
  • When we obtain your consent to do so.
  • We attempt to notify you about legal demands for your Personal Information when appropriate in our judgment, unless prohibited by law or court order or when the request is an emergency. We may dispute such demands when we believe, in our discretion, that the requests are over-broad, vague or lack proper authority, but we do not promise to challenge every demand.

Your Failure to Provide Personal Data

Your provision of Personal Data is required in order to use certain parts of our Site and our programs. If you fail to provide such Personal Data, you may not be able to access and use our Site and/or our programs, or parts of our Site and/or our programs.

Our Retention of Your Personal Data

We may retain your Personal Data for a period of time consistent with the original purpose for collection. For example, we keep your Personal Data for no longer than reasonably necessary for your use of our Site and Services and for a reasonable period of time afterward. We also may retain your Personal Data during the period of time needed for us to pursue our legitimate business interests, conduct audits, comply with our legal obligations, resolve disputes and enforce our agreements.

We retain your Personal Data even after your relationship with us ends if reasonably necessary to comply with our legal obligations (including law enforcement requests), attest to any degree, honor, or certification bestowed by the institution, meet regulatory requirements, resolve disputes, maintain security, prevent fraud and abuse, or fulfill your request to “unsubscribe” from further messages from us.

Your Privacy Rights and Choices

You may have certain rights relating to your Personal Information, subject to local data protection law. Whenever you use our Site, we aim to provide you with choices about how we use your Personal Data. We also aim to provide you with access to your Personal Data. If that information is wrong, we strive to give you ways to update it quickly or to delete it – unless we have to keep that information for legitimate business or legal purposes. Subject to applicable law, you may obtain a copy of personal information we maintain about you, or you may update or correct inaccuracies in that information by contacting us. To help protect your privacy and maintain security, we will take steps to verify your identity before granting you access to the information. In addition, if you believe that personal information we maintain about you is inaccurate, subject to applicable law, you may have the right to request that we correct or amend the information by contacting us as indicated in the How to Contact Us section below.

Notification of Rights Under FERPA

PSU complies with The Family Educational Rights and Privacy Act (FERPA) and will not disclose student data without a court order or other exemption as outlined in the section 3.0 of the Student Records and Privacy Policy.

Privacy Rights Specific to European Union Residents

Some data protection laws, including the European Union’s General Data Protection Regulation (“GDPR”), corresponding legislation in Switzerland and in the United Kingdom, and some U.S. state laws, provide you with certain rights in connection with Personal Data you have shared with us. If you are resident in the European Economic Area, you may have the following rights:

  1. The right to be informed. You are entitled to be informed of the use of your Personal Data. This Privacy Policy provides such information to you.
  2. The right of access. You have the right to request a copy of your Personal Data which we hold about you.
  3. The right of correction. You have the right to request correction or changes of your Personal Data if it is found to be inaccurate or out of date.
  4. The right to be forgotten. You have the right to request us, at any time, to delete your Personal Data from our servers and to erase your Personal Data when it is no longer necessary for us to retain such data. Note, however, that deletion of your Personal Data will likely impact your ability to use our services.
  5. The right to object (opt-out). You have the right to opt-out of certain uses of your Personal Data at any time.
  6. The right to data portability. You have the right to a “portable” copy of your Personal Data that you have submitted to us. Generally, this means your right to request that we move, copy or transmit your Personal Data stored on our servers / IT environment to another service provider’s servers / IT environment.
  7. The right to refuse to be subjected to automated decision making, including profiling. You have the right not to be subject to a decision and insist on human intervention if the decision is based on automated processing and produces a legal effect or a similarly significant effect on you.
  8. The right to lodge a complaint with a supervisory authority.

You may also have the right to make a GDPR complaint to the relevant Supervisory Authority. A list of Supervisory Authorities is available here: http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.

If you need further assistance regarding your rights, please contact us using the contact information provided below and we will consider your request in accordance with applicable law. To make these requests, you may contact us using the contact information below, and we will consider your request in accordance with applicable laws. For your protection, we may need to verify your identity before responding to your request. We may respond to your request by letter, email, telephone or any other suitable method. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.

Exercising Your Rights

To exercise your rights, you can:
 

  1. Submit a request via our portal at https://portlandstate.atlassian.net/servicedesk/customer/portal/2/create/163
  2. Send an email to DPO@pdx.edu

 

Our Response to Your Request

Upon receiving your request, we will confirm receipt of your request by [sending you an email/confirming receipt via our online portal/sending a message to your online account]. To help protect your privacy and maintain security, we may take steps to verify your identity before granting you access to the information. In some instances, such as a request to delete personal information, we may first separately confirm that you would like for us to in fact delete your personal information before acting on your request.

We will respond to your request within thirty (30) days. If we require more time, we will inform you of the reason and extension period in writing. If you have an account with us, we will deliver our written response to that account.If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.

In some cases our ability to uphold these rights for you may depend upon our obligations to process Personal Information for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, listed below, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.

In some cases our ability to uphold these rights for you may depend upon our obligations to process personal information for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services or program you have requested. Where this is the case, we will inform you of specific details in response to your request.

Third Party Links

The Sites may contain links to webpages operated by parties other than PSU. We do not control such websites and are not responsible for their contents or the privacy policies or other practices of such websites. Our inclusion of links to such websites does not imply any endorsement of the material on such websites or any association with their operators. Further, it is up to the User to take precautions to ensure that whatever links the User selects or software the User downloads (whether from this Site or other websites) is free of such items as viruses, worms, trojan horses, defects and other items of a destructive nature. These websites and services may have their own privacy policies, which the User will be subject to upon linking to the third party's website. PSU strongly recommends that each User review the third party's terms and policies.

International Transfer

We are committed to complying with applicable laws, regulations and mandatory government standards regarding the protection of Personal Data.

Personal Data and any additional information submitted may be used globally in connection with enrolment, employment, operational processes within PSU, or communicating with our PSU Partners. Therefore, Personal Data may be transferred to such entities worldwide, where it will be processed in accordance with this Privacy Policy and laws that are applicable in each country. Countries where we process data may have laws which are different, and potentially not as protective, as the laws of your own country.

If we transfer your Personal Data out of your jurisdiction, we will implement suitable safeguards and rely on legally-provided mechanisms to lawfully transfer data across borders to ensure that your Personal Data is protected.

How We Protect Personal Data

PSU maintains administrative, technical and physical safeguards designed to protect the User's Personal Data and information against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use. We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account technological reality, cost, the scope, context and purposes of processing weighted against the severity and likelihood that the processing could threaten individual rights and freedoms. For example, we restrict access to personal information to PSU employees, contractors, business partners and agents who need to know that information as part of their function. These individuals are bound by confidentiality obligations and may be subject to discipline, including termination and criminal prosecution, if they fail to meet these obligations. We use commercially reasonable security measures such as encryption, firewalls, and Secure Socket Layer software (SSL) or hypertext transfer protocol secure (HTTPS) to protect Personal Data. Please contact theOffice of Information and Technology (OIT)for more information.

Children

The Site is not intended for use by children. We do not intentionally gather Personal Data about visitors who are under the age of 16. If a child has provided us with Personal Data, a parent or guardian of that child may contact us to have the information deleted from our records. If you believe that we might have any information from a child under age 16 in the applicable jurisdiction, please contact us at DPO@psx.edu. If we learn that we have inadvertently collected the personal information of a child under 16, or equivalent minimum age depending on jurisdiction, we will take steps to delete the information as soon as possible.

Changes to this Privacy Policy

Our Privacy Policy may change from time to time. We will not reduce your rights under this Privacy Policy without your explicit consent. We will post any privacy policy changes on this page and, if the changes are significant, we will provide a more prominent notice (including, for certain services or programs, email notification or privacy policy changes). We will also keep prior versions of this Privacy Policy in an archive for your review.

How to Contact Us

If you have any specific questions about this Privacy Policy, you can contact us via email or phone or by writing to us at the address below:

Send e-mail to: DPO@PDX.edu

Send mail to our address:
Portland State University
Attn: Privacy Policy Inquiry
1825 SW Broadway
Portland, OR 97201, U.S.A

Effective Date: August 1, 2020
Last Updated: January 31, 2024