Stoneleigh-Burnham School Privacy Notice effective 5/25/18
Your personal data
“Personal data” means any information relating to an identifiable living person who can be directly or indirectly identified through that information. Stoneleigh-Burnham School processes personal data in accordance with Massachusetts regulations found at 201 C.M R. 17.00 et seq. (the “Regulations”), the Data Protection Act and the General Data Protection Regulation 2016/679 (the “GDPR”), and other applicable laws and regulations, including our Comprehensive Information Security Program (adopted April 2010) and our Document Retention Policy and Document Destruction Policy (adopted June 5, 2009).
Who are we?
Stoneleigh-Burnham School is the data controller, and any queries in relation to the handling of personal data may be submitted via email to firstname.lastname@example.org, via mail to attn: Data Officer, Stoneleigh-Burnham School, 574 Bernardston Road, Greenfield, MA 01301, or by filling out this webform.
Legal basis of processing
The data processing described in this notice is on the basis of GDPR Article 6(1)(f), the legitimate interests of Stoneleigh-Burnham School as Data Controller to:
- provide services to customers
- evaluate service delivery
- market to potential customers
- maintain network and information security
- meet our legal obligations
You have the following legal rights in respect of how Stoneleigh-Burnham School processes your personal data:
- To access the data about you that Stoneleigh-Burnham School holds
- To correct the details we hold
- To have data erased in certain circumstances
- To restrict the use Stoneleigh-Burnham School makes of your data in certain circumstances
- The right to object to processing, including the right to object to marketing
- To data portability in certain circumstances
- The right to complain to the GDPR supervisory authority (Information Commissioner’s Office)
Contact Stoneleigh-Burnham School using the details in the section “Who are we” above.
When do we collect your personal data?
Stoneleigh-Burnham School collects personal data in the following ways*:
- Directly from individuals who contact us via telephone, email, social media, post, website forms, or in person
- From schools or other partners that you have authorized to provide your data to us
- From teachers, advisors, and parents related to students’ academic performance at the School**
* Stoneleigh-Burnham School also collects and processes personal data from individuals who are employed by Stoneleigh-Burnham School, or who are contracted by Stoneleigh-Burnham School to carry out specific services; separate privacy notices are provided to those individuals detailing the context-specific processing of personal data.
** In such cases you will have authorized the provision of that data.
In accordance with the Children’s Online Privacy Protection Act of 1998 (“COPPA”), we do not knowingly collect any personal information from children under the age of 13 without the valid consent of a parent or guardian.
We may request your email address or mailing address on some of the forms contained on the site. Whenever we request the identity of a visitor, we will clearly indicate the purpose of the inquiry before the information is requested. Any Personal Information you share with us, including email or mailing addresses, is kept confidential. We maintain a strict “No-Spam” policy that means that we do not sell, rent, or otherwise give your email or mailing address to a third-party without your expressed permission.
How do we protect your data?
Stoneleigh-Burnham School takes all reasonable precautions and follows industry best practices to protect your personal information.
Data exchanged with our website and third-party providers is encrypted using SSL.
Service providers for our applications are all subject to security and data protection assessment.
Stoneleigh-Burnham School assesses the minimum period to store personal data, taking into account relevant laws, and has processes to ensure data is securely deleted or encrypted when there is no longer a reason to keep it for the purposes for which it was gathered.
Sharing your data
Third Party Services
Stoneleigh-Burnham School uses the following third-party services that may contain your personal data:
|Supplier / Service||Details||Location||Supplier Security and Privacy Information|
|Email, document management, collaboration tools, cloud platform, CRM||USA||Trust and Privacy information|
|Webhost.io||Web content storage and caching||USA||Security|
|Stripe||Payment processing||USA||Security and Data Protection|
|Google Analytics||Web activity tracking||Worldwide||Data Privacy and Security|
Cookies and usage tracking
We may use your IP (Internet Protocol) address to help diagnose problems with our server and to administer our website by identifying (1) which parts of our site are most heavily used, and (2) which portion of our audience comes from within the Stoneleigh-Burnham School network.
The school occasionally monitors search terms that users enter into the Stoneleigh-Burnham Search Engine, but this tracking is never associated with individual users or personal Information.
No personal information is shared with third parties [other than service providers in order to manage the Sites and analytic reporting software], nor is personal information shared with any third party for advertising or marketing purposes.
We reserve the right to modify this privacy notice at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.