  {"id":220,"date":"2018-05-09T10:36:00","date_gmt":"2018-05-09T10:36:00","guid":{"rendered":"https:\/\/www.stmarytx.edu\/policies\/?post_type=ucommp&#038;p=220"},"modified":"2025-10-30T16:34:58","modified_gmt":"2025-10-30T16:34:58","slug":"privacy-policy","status":"publish","type":"university-communica","link":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/","title":{"rendered":"Privacy Policy"},"content":{"rendered":"\n<p>ÁñÁ«ÊÓÆµ&#8217;s University (&#8220;ÁñÁ«ÊÓÆµ&#8217;s,&#8221; &#8220;we,&#8221; &#8220;us,&#8221; &#8220;our&#8221;) respects your privacy. This Privacy Policy explains how we collect, use,&nbsp;disclose, and protect personal information obtained through our websites (including subdomains), services, applications, and related communications. By using our sites or services, you agree to this Policy.&nbsp;<\/p>\n\n\n\n<p>This Policy applies to personal information collected from visitors to our public websites (e.g., stmarytx.edu and related subdomains), applicants, students, faculty, staff, alumni, donors, and other third parties who interact with us online or through our services. It does not replace specialized notices (for example, employee privacy notices or HIPAA notices) when applicable.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Information We Collect<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Information you provide<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Contact details (name, email, postal address, phone)&nbsp;<\/li>\n\n\n\n<li>Academic and application information (for applicants\/students)&nbsp;<\/li>\n\n\n\n<li>Employment and payroll information (for employees)&nbsp;<\/li>\n\n\n\n<li>Payment information&nbsp;submitted&nbsp;to authorized payment processors&nbsp;<\/li>\n\n\n\n<li>Communications with us (emails, chat transcripts)&nbsp;<\/li>\n\n\n\n<li>Other information you choose to provide&nbsp;<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Information collected automatically<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Technical information (IP address, browser, device, OS, pages viewed, referring URLs)&nbsp;<\/li>\n\n\n\n<li>Cookies, tracking pixels, and similar technologies (see&nbsp;Cookies, Ad Trackers, and Remarketing)&nbsp;<\/li>\n\n\n\n<li>Analytics and performance data&nbsp;<\/li>\n\n\n\n<li>Interaction data captured by session recording or form-saving features (see&nbsp;Cookies, Ad Trackers, and Remarketing)&nbsp;<\/li>\n<\/ul>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Tracking and Monitoring Technologies<\/h2>\n\n\n\n<p><strong>We use a range of tracking technologies for analytics, accessibility, security, marketing, and student services.<\/strong>&nbsp;These may include, but are not limited to:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Tracking pixels\/web beacons<\/strong>&nbsp;(e.g., Facebook Pixel, TikTok Pixel, Snap Pixel, and similar).&nbsp;<\/li>\n\n\n\n<li><strong>Session recording\/session replay<\/strong>&nbsp;(e.g., Microsoft Clarity,&nbsp;FullStory) to understand user journeys and improve our sites.&nbsp;<\/li>\n\n\n\n<li><strong>Keystroke \/ form-saving capture<\/strong>&nbsp;(only where necessary and with safeguards) to preserve form state and improve user experience.&nbsp;<\/li>\n\n\n\n<li><strong>Chat technologies<\/strong>&nbsp;(chatbots, live chat, Zoom embeds,&nbsp;Botpress)&nbsp;to provide&nbsp;help and schedule services.&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><strong>Purpose:&nbsp;<\/strong>Improve site usability, security monitoring, fraud detection, analytics, and legitimate institutional operations (admissions outreach, alumni engagement, etc.).&nbsp;<\/p>\n\n\n\n<p><strong>Data collected:<\/strong>&nbsp;Page interactions, clicks, scrolls, timestamps, form fields (including partially entered content), and limited device\/browser metadata.&nbsp;<\/p>\n\n\n\n<p><strong>Legal basis\/consent:<\/strong>&nbsp;Where required by&nbsp;law&nbsp;we will obtain user consent prior to placing or reading non-essential cookies or deploying tracking that collects personal data. For visitors in&nbsp;jurisdictions&nbsp;with opt-in requirements (e.g., GDPR for EU\/EEA residents), we will&nbsp;require&nbsp;affirmative consent prior to&nbsp;setting&nbsp;those trackers.&nbsp;<\/p>\n\n\n\n<p><strong>Tracker Inventory:&nbsp;<\/strong>A complete list of all pixels, tags, and session-replay scripts by subdomain is maintained &nbsp;Appendix A&nbsp;and updated regularly.<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Cookies, Ad Trackers, and Remarketing<\/h2>\n\n\n\n<p>We use cookies and similar technologies to personalize content, provide social media features, and analyze traffic. Cookies are classified as necessary (required&nbsp;for site functionality), performance,&nbsp;functional, or advertising\/marketing.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Third-party cookies and ad trackers:<\/strong>\u00a0We use third-party services (e.g., google-analytics.com, doubleclick.net, facebook.com, tiktok.com) for analytics and advertising purposes, including remarketing and cross-site behavioral advertising.\u00a0<\/li>\n\n\n\n<li><strong>Do Not Sell or Share\/CPRA:<\/strong>&nbsp;If you are a California resident, you may exercise your right to opt-out of the sale or sharing of your personal information by using the&nbsp;<strong>&#8220;Do Not Sell or Share My Personal Information&#8221;<\/strong>&nbsp;link on our homepage.&nbsp;(https:\/\/www.stmarytx.edu\/do-not-sell).&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><strong>How to manage cookies:<\/strong>&nbsp;Our cookie\/consent management tool allows you to accept or decline&nbsp;our&nbsp;cookies. You may also set browser-level preferences (note: blocking certain cookies may affect functionality).&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Session Recording, Keystroke Capture, and Chat \u2014 Special Notice&nbsp;<\/h2>\n\n\n\n<p>Some of our sites may use session recording and keystroke preservation to help troubleshoot forms or to improve&nbsp;user experience.&nbsp;We&nbsp;<strong>do not<\/strong>&nbsp;use these mechanisms to capture sensitive fields (e.g., full payment card numbers, complete social security numbers, or protected health information),&nbsp;and&nbsp;we will&nbsp;endeavor&nbsp;to mask fields that may&nbsp;contain&nbsp;such data.&nbsp;<\/p>\n\n\n\n<p><strong>When session recording or keystroke capture is active on a page that could collect PHI or other&nbsp;highly sensitive&nbsp;data, that functionality will be disabled or opt-in will be&nbsp;required.<\/strong><\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Third-Party Sharing and Disclosures<\/h2>\n\n\n\n<p>We may share personal data&nbsp;with&nbsp;vendors and service providers (e.g., analytics, cloud hosting, payment processors), academic partners, government\/regulatory bodies when required, and other parties consistent with the purposes described here.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Third-party links and embedded content:<\/strong>&nbsp;Our sites may&nbsp;contain&nbsp;links or embedded content (maps, videos, social widgets) that are controlled by third parties. We are not responsible for&nbsp;third-party&nbsp;privacy practices.&nbsp;<\/li>\n\n\n\n<li><strong>Vendor contracts:<\/strong>&nbsp;Where required by law (e.g., California, Colorado, Virginia), we require vendors to adhere to privacy obligations consistent with this Policy.&nbsp;<\/li>\n<\/ul>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Sensitive Data and Special Categories<\/h2>\n\n\n\n<p>We avoid collecting sensitive personal information (e.g., biometric data, genetic data, precise geolocation, health\/medical information) via public websites. If we must collect such data for a legitimate business purpose, we will:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Disclose the collection and the reason for it,&nbsp;<\/li>\n\n\n\n<li>Obtain affirmative opt-in consent where required by law,&nbsp;and&nbsp;<\/li>\n\n\n\n<li>Put&nbsp;appropriate safeguards&nbsp;in place (data minimization, retention limits, encryption).&nbsp;<\/li>\n<\/ul>\n\n\n\n<p><strong>HIPAA \/ Health Data:<\/strong>&nbsp;If you provide health or medical information in contexts where HIPAA applies (covered entity or business associate), separate Notices of Privacy Practices and BAA agreements will apply.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Children\u2019s Privacy<\/h2>\n\n\n\n<p>Our services are not targeted&nbsp;at&nbsp;children under 13. If we discover that a child under 13 has provided personal information without parental consent, we will take reasonable steps to&nbsp;delete&nbsp;such data. If any of our programs or offerings are aimed at children, we will provide specific notices and obtain parental consent consistent with COPPA or applicable local law.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">User Rights and Choices&nbsp;<\/h2>\n\n\n\n<p>Depending on where you live, you may have&nbsp;the right&nbsp;to access, correct,&nbsp;delete, restrict, or port your personal information. Examples include rights under the GDPR, CPRA, and other state laws.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>California residents:<\/strong>&nbsp;Rights&nbsp;to access,&nbsp;delete, correct, opt-out of sale\/sharing (Do Not Sell or Share), and&nbsp;nondiscrimination&nbsp;for exercising rights.&nbsp;&nbsp;<\/li>\n\n\n\n<li><strong>GPC and DNT:<\/strong>\u00a0We will recognize Global Privacy Control (GPC) signals where legally required and will describe how users can exercise choice via our privacy controls. Do Not Track (DNT) signals are honored\u00a0in accordance with\u00a0applicable law.\u00a0<\/li>\n<\/ul>\n\n\n\n<p><strong>How to exercise rights:\u00a0<\/strong>See\u00a0Contact and Exercising Rights\u00a0below for contact details and instructions. We will verify requests consistent with applicable\u00a0aws.\u00a0<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Data Retention&nbsp;<\/h2>\n\n\n\n<p>We&nbsp;retain&nbsp;personal information only as long as necessary for the purposes described and to satisfy legal, accounting, or reporting requirements. We&nbsp;maintain&nbsp;retention categories (e.g., admissions records, alumni data, web analytics) and approximate retention periods as outlined in&nbsp;Appendix B.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Data Transfers and Residency\u00a0<\/h2>\n\n\n\n<p>Personal information may be processed in the United States and other countries. Where international transfers occur, we will adopt&nbsp;appropriate safeguards&nbsp;(e.g., Standard Contractual&nbsp;Clauses, contractual protections). If you are an EU\/EEA resident, we will provide mechanisms to exercise GDPR rights and information about data transfers.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Security&nbsp;<\/h2>\n\n\n\n<p>We&nbsp;maintain&nbsp;administrative, technical, and physical safeguards designed to protect personal information. While we use industry-standard controls (encryption in transit and at rest where&nbsp;appropriate, access controls), no system is completely secure. We will notify affected parties and regulators as required by law&nbsp;in the event of&nbsp;a breach.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">AI, ML, and Automated Decision-Making&nbsp;<\/h2>\n\n\n\n<p>If we use artificial intelligence, machine learning, or automated decision tools that process personal information, we will&nbsp;disclose&nbsp;the purposes and the categories of data used. We commit to fairness, regular audits, and safeguards (anonymization&nbsp;and&nbsp;pseudonymization) where&nbsp;feasible.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Changes to This Policy<\/h2>\n\n\n\n<p>We may&nbsp;periodically&nbsp;update&nbsp;this&nbsp;Policy.&nbsp;If changes are&nbsp;substantial, we will provide notice on the website and adjust&nbsp;the effective date at the top of this document&nbsp;accordingly.&nbsp;<\/p>\n\n\n\n<div style=\"height:25px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Contact and Exercising Rights&nbsp;<\/h2>\n\n\n\n<p>For privacy inquiries or to exercise your rights with respect to our privacy practices or this Policy, or to update your information, contact us:&nbsp;<br><strong>Email:<\/strong>&nbsp;<a href=\"mailto:privacy@stmarytx.edu\" target=\"_blank\" rel=\"noreferrer noopener\">privacy@stmarytx.edu<\/a>&nbsp;<br><strong>Mail:<\/strong>&nbsp;<br>ÁñÁ«ÊÓÆµ&#8217;s University&nbsp;<br>Office of University Marketing and Communications, Box 75&nbsp;<br>One Camino Santa Maria&nbsp;<br>San Antonio, TX 78228&nbsp;<br><strong>California Residents:&nbsp;<\/strong>To&nbsp;submit&nbsp;requests related to the CPRA, use our&nbsp;<a href=\"https:\/\/www.stmarytx.edu\/do-not-sell\" target=\"_blank\" rel=\"noreferrer noopener\">Do Not Sell or Share link<\/a>&nbsp;or email&nbsp;<a href=\"mailto:privacy@stmarytx.edu\" target=\"_blank\" rel=\"noreferrer noopener\">privacy@stmarytx.edu<\/a>&nbsp;with subject line:&nbsp;<strong>CA PRIVACY REQUEST<\/strong>.&nbsp;<\/p>\n\n\n\n<div style=\"height:35px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Appendix A&nbsp;\u2014 Known tracking and third-party technologies&nbsp;<\/h2>\n\n\n\n<p>The following is a current inventory of tracking technologies, pixels, tags, and third-party scripts deployed across ÁñÁ«ÊÓÆµ&#8217;s University web properties. This list is updated regularly and reconciled with our tag management system.&nbsp;<\/p>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>View List<\/summary>\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Technology\/Vendor<\/strong><\/td><td><strong>Domain(s)&nbsp;<\/strong><\/td><td><strong>Purpose&nbsp;<\/strong><\/td><td><strong>Data Retention&nbsp;<\/strong><\/td><td><strong>Vendor Privacy Policy&nbsp;<\/strong><\/td><\/tr><tr><td><strong>Google Analytics&nbsp;<\/strong><\/td><td>google-analytics.com, googletagmanager.com&nbsp;<\/td><td>Analytics, performance monitoring&nbsp;<\/td><td>26 months (adjustable)&nbsp;<\/td><td><a href=\"https:\/\/policies.google.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>DoubleClick&nbsp;<\/strong><\/td><td>doubleclick.net&nbsp;<\/td><td>Advertising, remarketing&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/policies.google.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>Facebook Pixel&nbsp;<\/strong><\/td><td>facebook.com, facebook.net&nbsp;<\/td><td>Analytics, advertising, remarketing&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.facebook.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong><strong>Reddit Pixel<\/strong>&nbsp;<\/strong><\/td><td>reddit.com&nbsp;<\/td><td>Analytics, advertising, remarketing&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.reddit.com\/policies\/privacy-policy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>TikTok Pixel&nbsp;<\/strong><\/td><td>tiktok.com&nbsp;<\/td><td>Analytics, advertising&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.tiktok.com\/legal\/privacy-policy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>Snap Pixel&nbsp;<\/strong><\/td><td>snapchat.com&nbsp;<\/td><td>Analytics, advertising&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.snap.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong><strong><strong><strong>AppNexus<\/strong>&nbsp;<\/strong><\/strong><\/strong><\/td><td>appnexustech.com<\/td><td>Analytics, remarketing&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/appnexustech.com\/privacy-policy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a><\/td><\/tr><tr><td><strong>Monsido<\/strong><\/td><td>monsido.com&nbsp;<\/td><td>Accessibility monitoring&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/monsido.com\/privacy-policy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a><\/td><\/tr><tr><td><strong>Hotjar&nbsp;<\/strong><\/td><td>hotjar.com&nbsp;<\/td><td>Session recording, heatmaps&nbsp;<\/td><td>365 days&nbsp;<\/td><td><a href=\"https:\/\/www.hotjar.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>FullStory&nbsp;<\/strong><br><strong>&nbsp;<\/strong><\/td><td>fullstory.com&nbsp;<\/td><td>Session recording, UX analysis&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.fullstory.com\/legal\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>Microsoft Clarity&nbsp;<\/strong><\/td><td>clarity.ms&nbsp;<\/td><td>Session replay, analytics&nbsp;<\/td><td>90 days&nbsp;<\/td><td><a href=\"https:\/\/privacy.microsoft.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>Pendo&nbsp;<\/strong><\/td><td>pendo.io&nbsp;<\/td><td>Product analytics&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.pendo.io\/privacy-policy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>Botpress<\/strong><\/td><td>botpress.com&nbsp;<\/td><td>Chatbot <\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/botpress.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a><\/td><\/tr><tr><td><strong>Zoom&nbsp;<\/strong><\/td><td>zoom.us&nbsp;<\/td><td>Embedded meeting links&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/zoom.us\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong><strong>Gravity Forms<\/strong>&nbsp;<\/strong><\/td><td>gravityforms.com&nbsp;<\/td><td>Manage&nbsp;Forms&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/www.gravityforms.com\/privacy\/\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><tr><td><strong>Swiftype&nbsp;<\/strong><\/td><td>swiftype.com&nbsp;<\/td><td>Site Search&nbsp;<\/td><td>Varies&nbsp;<\/td><td><a href=\"https:\/\/swiftype.com\/privacy\" target=\"_blank\" rel=\"noreferrer noopener\">Link<\/a>&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n<\/details>\n\n\n\n<div style=\"height:35px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Appendix B&nbsp;\u2014 Data Retention Schedule<\/h2>\n\n\n\n<p>ÁñÁ«ÊÓÆµ&#8217;s University&nbsp;maintains&nbsp;the following general retention periods for personal information collected through our websites and services:&nbsp;<\/p>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>View List<\/summary>\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Data Category&nbsp;<\/strong><\/td><td><strong>Description&nbsp;<\/strong><\/td><td><strong>Retention Period&nbsp;<\/strong><\/td><td><strong>Legal\/Regulatory Basis&nbsp;<\/strong><\/td><\/tr><tr><td><strong>Admissions Records&nbsp;<\/strong><\/td><td>Applications, test scores, supporting documents&nbsp;<\/td><td>7 years after decision&nbsp;<\/td><td>FERPA, institutional policy&nbsp;<\/td><\/tr><tr><td><strong>Student Records&nbsp;<\/strong><\/td><td>Academic records, enrollment data&nbsp;<\/td><td>Permanent (transcripts); 5 years after graduation (other records)&nbsp;<\/td><td>FERPA, accreditation requirements&nbsp;<\/td><\/tr><tr><td><strong>Alumni Engagement Data&nbsp;<\/strong><\/td><td>Contact information, giving history, event participation&nbsp;<\/td><td>Indefinite with opt-out capability&nbsp;<\/td><td>Legitimate institutional interest&nbsp;<\/td><\/tr><tr><td><strong>Web Analytics&nbsp;<\/strong><\/td><td>Page views, session data, anonymized user behavior&nbsp;<\/td><td>26 months (adjustable per tool)&nbsp;<\/td><td>Data minimization&nbsp;<\/td><\/tr><tr><td><strong>Marketing Lists&nbsp;<\/strong><\/td><td>Email addresses, contact preferences&nbsp;<\/td><td>Until opt-out or 3 years of inactivity&nbsp;<\/td><td>CAN-SPAM, institutional policy&nbsp;<\/td><\/tr><tr><td><strong>Employee Records&nbsp;<\/strong><\/td><td>HR data, payroll, benefits&nbsp;<\/td><td>7 years after separation&nbsp;<\/td><td>IRS, state employment law&nbsp;<\/td><\/tr><tr><td><strong>Donor Records&nbsp;<\/strong><\/td><td>Contribution history, contact information&nbsp;<\/td><td>7 years (financial); indefinite (recognition)&nbsp;<\/td><td>IRS, institutional policy&nbsp;<\/td><\/tr><tr><td><strong>Support\/Help Desk Tickets&nbsp;<\/strong><\/td><td>Chat logs, email correspondence&nbsp;<\/td><td>3 years&nbsp;<\/td><td>Customer service, legal holds&nbsp;<\/td><\/tr><tr><td><strong>Cookie\/Tracker Data&nbsp;<\/strong><\/td><td>Behavioral data from advertising pixels&nbsp;<\/td><td>12-26 months&nbsp;depending on vendor&nbsp;<\/td><td>GDPR, CPRA&nbsp;<\/td><\/tr><tr><td><strong><strong>Security Logs&nbsp;<\/strong><\/strong><\/td><td>Access logs, authentication attempts&nbsp;<\/td><td>90 days&nbsp;to 1 year&nbsp;<\/td><td>Cybersecurity policy&nbsp;<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p><strong>Note:<\/strong>&nbsp;Retention periods may be extended for legal holds, litigation, investigations, or regulatory inquiries. Individuals may request early deletion of their data subject to legal and operational constraints.&nbsp;&nbsp;<\/p>\n\n\n\n<p>This schedule is reviewed annually by the Data Governance Committee.&nbsp;<\/p>\n<\/details>\n\n\n\n<div style=\"height:35px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Definitions&nbsp;<\/h2>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Regulatory and Legal Acronyms\u00a0<\/summary>\n<p><strong>BAA (Business Associate Agreement)<\/strong>&nbsp;<br>A written agreement between a HIPAA covered entity and a business associate that ensures the protection of Protected Health Information (PHI).&nbsp;<\/p>\n\n\n\n<p><strong>BIPA (Biometric Information Privacy Act)<\/strong>&nbsp;<br>Illinois state law regulating the collection, use, and storage of biometric identifiers and biometric information.&nbsp;<\/p>\n\n\n\n<p><strong>COPPA (Children&#8217;s Online Privacy Protection Act)<\/strong>&nbsp;<br>Federal law protecting the privacy of children under 13 by requiring parental consent for collection of personal information from minors.&nbsp;<\/p>\n\n\n\n<p><strong>CPRA (California Privacy Rights Act)<\/strong>&nbsp;<br>California&#8217;s comprehensive consumer privacy law, amending and expanding the CCPA, effective January 1, 2023.&nbsp;<\/p>\n\n\n\n<p><strong>EU\/EEA (European Union\/European Economic Area)<\/strong>&nbsp;<br>The 27 member states of the European Union plus Iceland, Liechtenstein, and Norway, where GDPR applies.&nbsp;<\/p>\n\n\n\n<p><strong>FERPA (Family Educational Rights and Privacy Act)<\/strong>&nbsp;<br>Federal law protecting the privacy of student education records.&nbsp;<\/p>\n\n\n\n<p><strong>GDPR (General Data Protection Regulation)<\/strong>&nbsp;<br>European Union regulation governing data protection and privacy for individuals within the EU\/EEA.&nbsp;<\/p>\n\n\n\n<p><strong>GINA (Genetic Information Nondiscrimination Act)<\/strong>&nbsp;<br>Federal law prohibiting discrimination based on genetic information in health insurance and employment.&nbsp;<\/p>\n\n\n\n<p><strong>GIPA (Genetic Information Privacy Act)<\/strong>&nbsp;<br>State-level laws regulating the collection and use of genetic information.&nbsp;<\/p>\n\n\n\n<p><strong>HIPAA (Health Insurance Portability and Accountability Act)<\/strong>&nbsp;<br>Federal law&nbsp;establishing&nbsp;privacy and security standards for Protected Health Information in healthcare contexts.&nbsp;<\/p>\n\n\n\n<p><strong>SCCs (Standard Contractual Clauses)<\/strong>&nbsp;<br>EU-approved contractual terms for lawful international data transfers outside the EU\/EEA.&nbsp;<\/p>\n\n\n\n<p><strong>Technical Acronyms<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>CMP (Consent Management Platform)<\/strong>&nbsp;<br>A system or tool (e.g.,&nbsp;OneTrust, Osano) that manages user consent for cookies, trackers, and other data collection practices.&nbsp;<\/p>\n\n\n\n<p><strong>DNT (Do Not Track)<\/strong>&nbsp;<br>A web browser setting that requests websites not&nbsp;track&nbsp;the user&#8217;s browsing activity.&nbsp;<\/p>\n\n\n\n<p><strong>GPC (Global Privacy Control)<\/strong>&nbsp;<br>A web browser signal that communicates a user&#8217;s privacy preferences (such as opting out of data sharing). Businesses&nbsp;are required to&nbsp;honor this in certain&nbsp;jurisdictions.&nbsp;<\/p>\n\n\n\n<p><strong>GTM (Google Tag Manager)<\/strong>&nbsp;<br>Google&#8217;s tag management system that allows organizations to manage and deploy marketing tags (snippets of code or tracking pixels) on their websites.&nbsp;<\/p>\n\n\n\n<p><strong>PHI (Protected Health Information)<\/strong>&nbsp;<br>Individually identifiable health information transmitted or&nbsp;maintained&nbsp;in any form or medium by a HIPAA covered entity or business associate.&nbsp;<\/p>\n\n\n\n<p><strong>UX (User Experience)<\/strong>&nbsp;<br>The overall experience a person has when interacting with a website, application, or digital service, encompassing usability, design, and functionality.&nbsp;<\/p>\n\n\n\n<p><strong>Key Privacy Terms<\/strong>&nbsp;<\/p>\n\n\n\n<p><strong>AI (Artificial Intelligence) and ML (Machine Learning)<\/strong>&nbsp;<br>Technologies that use algorithms to analyze data, make predictions, or automate decisions. If trained&nbsp;on&nbsp;personal information, transparency and&nbsp;fairness&nbsp;obligations apply.&nbsp;<\/p>\n\n\n\n<p><strong>Anonymization<\/strong>&nbsp;<br>The process of removing or altering personal information so that individuals can no longer be&nbsp;identified, either directly or indirectly. Anonymized data is no longer considered personal information under most privacy laws.&nbsp;<\/p>\n\n\n\n<p><strong>Biometric Information<\/strong>&nbsp;<br>Data based on unique biological traits (e.g., fingerprints, facial recognition, voice patterns) used to&nbsp;identify&nbsp;an individual. Protected by laws like Illinois BIPA.&nbsp;<\/p>\n\n\n\n<p><strong>Chat Technologies<\/strong>&nbsp;<br>Embedded live chat or chatbot tools (e.g., Zoom integrations,&nbsp;Botpress) that allow real-time communication. Conversations may be&nbsp;logged&nbsp;or shared with third-party providers.&nbsp;<\/p>\n\n\n\n<p><strong>Consumer Health Data<\/strong>&nbsp;<br>Information relating to an individual&#8217;s health status or health-related behavior. May be subject to the Washington My Health My Data Act and similar state laws.&nbsp;<\/p>\n\n\n\n<p><strong>Cookies<\/strong>&nbsp;<br>Small text files stored on a user&#8217;s browser to remember preferences, support website functionality, and track browsing behavior. Includes first-party cookies (set by stmarytx.edu) and third-party cookies (set by external services such as analytics or advertisers).&nbsp;<\/p>\n\n\n\n<p><strong>Covered Entity<\/strong>&nbsp;<br>Under HIPAA, a health plan, healthcare clearinghouse, or healthcare provider that transmits health information in electronic form.&nbsp;<\/p>\n\n\n\n<p><strong>Business Associate<\/strong>&nbsp;<br>Under HIPAA, a person or entity that performs functions or activities on behalf of, or provides services to, a covered entity that&nbsp;involve&nbsp;access to Protected Health Information.&nbsp;<\/p>\n\n\n\n<p><strong>Cross-Site Behavioral Advertising<\/strong>&nbsp;<br>The practice of tracking users across multiple websites to deliver targeted advertisements based on their browsing history and behavior.&nbsp;<\/p>\n\n\n\n<p><strong>Data Minimization<\/strong>&nbsp;<br>A privacy principle&nbsp;requiring&nbsp;that only the&nbsp;minimum&nbsp;amount of personal data necessary for a specific purpose be collected and processed.&nbsp;<\/p>\n\n\n\n<p><strong>Data Residency and Transfers<\/strong>\u00a0<br>Rules and practices\u00a0regarding\u00a0where data is stored and whether it is transferred internationally. Includes safeguards like Standard Contractual Clauses (SCCs).\u00a0<\/p>\n\n\n\n<p><strong>Data Retention<\/strong>&nbsp;<br>The&nbsp;period of time&nbsp;for which the University stores personal information before deletion or anonymization.&nbsp;<\/p>\n\n\n\n<p><strong>Do Not Sell or Share My Personal Information<\/strong>&nbsp;<br>A user right, particularly under California&#8217;s CPRA, requiring organizations to&nbsp;provide&nbsp;a clear opt-out mechanism for selling or sharing personal data with third parties.&nbsp;<\/p>\n\n\n\n<p><strong>Genetic Information<\/strong>&nbsp;<br>Data derived from an individual&#8217;s DNA or genetic testing, regulated by GINA and state privacy laws (e.g., GIPA).&nbsp;<\/p>\n\n\n\n<p><strong>Keystroke Capture (Form Preservation)<\/strong>&nbsp;<br>Technology that can capture text as it is entered into online forms to improve functionality or prevent data loss. Sensitive fields (like SSNs or payment details) are excluded.&nbsp;<\/p>\n\n\n\n<p><strong>Non-Discrimination<\/strong>&nbsp;<br>The legal requirement that organizations may not deny goods or services, charge different prices, or provide a different level of quality to consumers who exercise their privacy rights.&nbsp;<\/p>\n\n\n\n<p><strong>Personal Information<\/strong>&nbsp;<br>Any information that&nbsp;identifies, relates to, describes, or could&nbsp;reasonably be&nbsp;linked with an individual, including names, contact details, account information, and digital identifiers.&nbsp;<\/p>\n\n\n\n<p><strong>Pseudonymization<\/strong>&nbsp;<br>The processing of personal data in such a way that it can no longer be attributed to a specific individual without the use of&nbsp;additional&nbsp;information, which is kept separately and subject to technical and organizational measures.&nbsp;<\/p>\n\n\n\n<p><strong>Remarketing (Retargeting)<\/strong>&nbsp;<br>The practice of using analytics and cookie data to display targeted ads to users as they browse other websites.&nbsp;<\/p>\n\n\n\n<p><strong>Sensitive Personal Information<\/strong>&nbsp;<br>Special categories of personal data that may&nbsp;include:&nbsp;Social Security numbers, financial information, biometric data, genetic data, precise geolocation, or Protected Health Information (PHI).&nbsp;<\/p>\n\n\n\n<p><strong>Session Recording (Session Replay)<\/strong>&nbsp;<br>Technology that records user interactions on a website (mouse clicks, scrolling, navigation) to understand user experience. May also include&nbsp;form&nbsp;interactions.&nbsp;<\/p>\n\n\n\n<p><strong>Third-Party Cookies and Ad Trackers<\/strong>\u00a0<br>Cookies or scripts placed by third parties that collect user behavior for analytics, targeted advertising, or cross-site remarketing.\u00a0<\/p>\n\n\n\n<p><strong>Tracking Pixel (Web Beacon)<\/strong>&nbsp;<br>A small, often invisible, image or code snippet embedded in a webpage or email used to track user activity, measure engagement, and support remarketing campaigns.&nbsp;<\/p>\n<\/details>\n","protected":false},"featured_media":0,"parent":0,"menu_order":0,"template":"","class_list":["post-220","university-communica","type-university-communica","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Privacy Policy - Policy Library<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Privacy Policy - Policy Library\" \/>\n<meta property=\"og:description\" content=\"ÁñÁ«ÊÓÆµ&#8217;s University (&#8220;ÁñÁ«ÊÓÆµ&#8217;s,&#8221; &#8220;we,&#8221; &#8220;us,&#8221; &#8220;our&#8221;) respects your privacy. This Privacy Policy explains how we collect, use,&nbsp;disclose, and protect personal information obtained through our websites (including subdomains), services, applications, and related communications. By using our sites or services, you agree to this Policy.&nbsp; This Policy applies to personal information collected from visitors to [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"Policy Library\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-30T16:34:58+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/university-communica\\\/privacy-policy\\\/\",\"url\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/university-communica\\\/privacy-policy\\\/\",\"name\":\"Privacy Policy - Policy Library\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/#website\"},\"datePublished\":\"2018-05-09T10:36:00+00:00\",\"dateModified\":\"2025-10-30T16:34:58+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/university-communica\\\/privacy-policy\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/university-communica\\\/privacy-policy\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/university-communica\\\/privacy-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"University Communications\",\"item\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/university-communica\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Privacy Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/#website\",\"url\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/\",\"name\":\"Policy Library\",\"description\":\"Official policies of ÁñÁ«ÊÓÆµ&#039;s University\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.stmarytx.edu\\\/policies\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Privacy Policy - Policy Library","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/","og_locale":"en_US","og_type":"article","og_title":"Privacy Policy - Policy Library","og_description":"ÁñÁ«ÊÓÆµ&#8217;s University (&#8220;ÁñÁ«ÊÓÆµ&#8217;s,&#8221; &#8220;we,&#8221; &#8220;us,&#8221; &#8220;our&#8221;) respects your privacy. This Privacy Policy explains how we collect, use,&nbsp;disclose, and protect personal information obtained through our websites (including subdomains), services, applications, and related communications. By using our sites or services, you agree to this Policy.&nbsp; This Policy applies to personal information collected from visitors to [&hellip;]","og_url":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/","og_site_name":"Policy Library","article_modified_time":"2025-10-30T16:34:58+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/","url":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/","name":"Privacy Policy - Policy Library","isPartOf":{"@id":"https:\/\/www.stmarytx.edu\/policies\/#website"},"datePublished":"2018-05-09T10:36:00+00:00","dateModified":"2025-10-30T16:34:58+00:00","breadcrumb":{"@id":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/privacy-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.stmarytx.edu\/policies\/"},{"@type":"ListItem","position":2,"name":"University Communications","item":"https:\/\/www.stmarytx.edu\/policies\/university-communica\/"},{"@type":"ListItem","position":3,"name":"Privacy Policy"}]},{"@type":"WebSite","@id":"https:\/\/www.stmarytx.edu\/policies\/#website","url":"https:\/\/www.stmarytx.edu\/policies\/","name":"Policy Library","description":"Official policies of ÁñÁ«ÊÓÆµ&#039;s University","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.stmarytx.edu\/policies\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/www.stmarytx.edu\/policies\/wp-json\/wp\/v2\/university-communica\/220","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.stmarytx.edu\/policies\/wp-json\/wp\/v2\/university-communica"}],"about":[{"href":"https:\/\/www.stmarytx.edu\/policies\/wp-json\/wp\/v2\/types\/university-communica"}],"version-history":[{"count":0,"href":"https:\/\/www.stmarytx.edu\/policies\/wp-json\/wp\/v2\/university-communica\/220\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.stmarytx.edu\/policies\/wp-json\/wp\/v2\/media?parent=220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}