Legal basis for collecting and processing your personal and non-personal data
When you load a page on choirschoo.org, data is collected for the technical operation of the website, such as security protocols looking for malicious activity that could lead to defacement or a data breach. We thereby have a legitimate interest in monitoring the site’s performance in order to provide a positive experience for visitors. The legal basis for other data collection, such as names and email addresses you submit when requesting more information or starting the application process, is based on the consent you provide when you elect to use a contact form or initiate another direct interaction.
We Collect Your Personal Data in the Following Ways
Automatic Collection
We automatically receive information from your web browser or mobile device. This information may include the name of the website from which you entered our website, if any, as well as the name of the website you’ll visit when you leave our website, your Internet service provider’s name, your web browser type, the type of mobile device, your computer operating system, and data about your browsing activity when using our website. We use all this information to analyze trends among our users to help improve our website. From time to time, Saint Thomas Choir School may release non-personally-identifying information in the aggregate, e.g., by publishing a report on trends in the usage of its website.
Contact Forms
The contact form asks for your consent to transmit personal data such as your email address and name in order to facilitate communication. That data is stored in our database and may also be sent to the appropriate staff member as email using Simple Mail Transfer Protocol (SMTP). Our own SMTP servers are protected by TLS (sometimes known as SSL) meaning that the email content is encrypted using SHA-2, 256-bit cryptography before being sent across the internet. The email content is then decrypted by our local computers and devices. However, not all mail servers are secured in such a way. Therefore, we would suggest that you always consider email as an insecure medium and not include confidential or sensitive information within an email.
Concluded conversations will be deleted from those inboxes after 60 days. None of this personal information will be used for marketing purposes.
Analytics
Our website uses Google Analytics to collect information about the use of our website, but not to collect any personal data. When you load the site, your IP address is anonymized so that it cannot be used to trace you as an individual while still allowing us gather information about how users interact with our site. Google Analytics will still place cookies on your computer to track metrics like visit duration, but it does so without including personal information.
All activity falls within the bounds of the Google Analytics Terms of Service. For more information on how Google collects and processes your data, visit https://www.google.com/policies/privacy/partners/. Or to opt-out of Google Analytics across all websites, consider using the tool at https://tools.google.com/dlpage/gaoptout
Security
We use security plugins like Wordfence to prevent hacks, break-ins, etc. Those plugins necessarily look at your IP address to ensure that you’re not engaged in malicious activity, as well as block IP addresses as that violate security rules. Wordfence does analyze the activity of IP addresses to look for larger security trends and risks across the internet, and as such we consider Wordfence and their parent company, Defiant, Inc., to be a third party data processor. Contact us if you need the data they process to be removed.