Privacy Policy

Effective Date: May 27, 2021

The MITRE Corporation (“MITRE”) respects the privacy of its website users.

This Privacy Policy explains the types of information collected from website visitors or that you provide to MITRE through other means, such as MITRE applications, (collectively “Site”), and how MITRE uses, shares, protects, and retains that information; and the choices you are provided with respect to the use of this information. By visiting the Site, you understand and agree to terms outlined in this Privacy Policy.

Information Collected from Web Traffic Reporting Tools

When you visit the Site, the website server logs basic information about each visit. MITRE processes this information monthly via an automated software tool to identify any Site performance issues, popular sections and content, and other important Site characteristics. This information does not identify you personally. This information is used only as a source of anonymous statistical information. MITRE may internally store such information, or it may be included in databases owned and maintained by our third-party service providers.

Do Not Track Signals

MITRE employs cookies for collecting portions of this information. “Cookies” are data that may be sent to your web browser and stored on your computer. MITRE may use cookies and tracking technologies such as session Cookies, persistent Cookies, and/or web beacons. Most web browsers can be configured not to accept Cookies, or to notify you if Cookies are sent to you. Please be aware that some functionality of the Site relies on the use of Cookies may not be available should you choose to refuse all Cookies. If you wish not to have Cookies set during your visit to the Site, you can disable them in your web browser. The raw log data is retained for a minimum of ninety (90) days.

MITRE also uses Google Analytics and Google Tag Manager, which are third-party software services, to capture and analyze Site usage information. This service supplies MITRE with additional non-personally identifiable information about Site users to help us create content that our users may find useful. Users that wish to have their non-personally identifiable information not collected by means of their visit to the MITRE Site have the option to opt-out of the Google Analytics tracking service via this link https://tools.google.com/dlpage/gaoptout/.

Cookies and other passive information collection technologies enable MITRE to compile aggregate statistics concerning use of the Site, analyze trends, advance security of the Site, deliver content, and otherwise administer and improve the Site.

Personal Information

A. Information Collected

MITRE may obtain personal information about you, such as your name, address, demographic data, authentication credentials, email and phone number, when you submit such information to MITRE for queries regarding our services and/or visit the Site. “Personal Information” means information that identifies you or could reasonably be used to identify you.

MITRE may also collect other information about your visits to our Site without you actively submitting such information. This information may include, for example: your browser type and language, your operating system, device type, access time, your Internet Protocol (IP) address, the URLs of websites you visited before and after visiting our Site, the web search that landed you on our Site, and the links you click on within our Site.

B. Use of Personal Information

MITRE may use your Personal Information to improve the Site, notify you about updates to the Site, and for internal business analysis or other business purposes consistent with our mission and to carry out other purposes that are disclosed to you and to which you consent as required under applicable law.

MITRE may share the Personal Information that you provide to us within the corporation and with third-party service providers to respond to your queries and we may use this information for marketing research, sales, support, and service-related purposes. MITRE will never transfer your Personal Information to any third-party for that third-party’s marketing purposes.

MITRE may share generic aggregate demographic information not linked to any Personal Information with our business partners, third-party service providers, and trusted affiliates. With the limited exceptions above, MITRE does not provide Personal Information to anyone outside of the corporation unless required by law to do so.

C. Legal Grounds for Processing of Your Personal Information.

The use of your Personal Information set out in B. above is permitted under applicable United States’ state laws. For Personal Information collected under the applicability of European, Australian, and Canadian specific data privacy regulations and laws, the legal grounds for use are as follows:

When you have consented for MITRE to use and collect your Personal Information, you will have been presented with an online consent form in relation to any such use and may withdraw your consent at any time by sending an email to: ACTPOC_Members@mitre.org.

Where necessary to enter into or perform our contract with you.

Where MITRE needs to use it to comply with our legal obligations.

Where MITRE uses it to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights, such as promoting MITRE’s services and tailoring news and communications for you as requested by you, or for detecting fraud and criminal activities.

MITRE may also transfer your Personal Information to a third party without your consent when justified by a legitimate interest, or if there is a contractual obligation to do so.

D. Updating, Restricting, Deleting, or Accessing of Personal Information

If you wish to correct, restrict, or delete inaccuracies with your Personal Information, or to request access in an usable electronic format, as legally required, to any Personal Information that MITRE obtains about you, please contact us at ACTPOC_Members@mitre.org.

However, in certain situations, MITRE may not be able to provide access to, restrict, or delete all of the Personal Information that it holds about you due to applicability of certain exemptions such as, safeguarding the public interest (e.g. the prevention or detection of a crime), maintaining our interests (e.g., legal privilege), and protecting the rights of third parties.

E. Compliance with Legal Requests

MITRE may be legally required to provide your Personal Information to law enforcement agencies, regulators, courts and third-party litigants in connection with civil or criminal proceedings or investigations anywhere in the world. Where permitted, we will direct any such request to you, or we may notify you before responding unless to do so would prejudice the prevention or detection of a crime.

F. Security of Personal Information

MITRE maintains physical, electronic and procedural safeguards designed to protect Personal Information. MITRE employs encryption technologies and user authentication procedures that are designed to keep your data secure. MITRE limits access to Personal Information to authorized personnel, contractors and business partners who need access to perform their responsibilities and are contractually required to keep your information secure.

G. Retention of Personal Information

MITRE retains your Personal Information only as long as is necessary and only for the purpose for which MITRE obtained the Personal Information. MITRE’s retention periods are based on business needs and once your Personal Information is no longer needed, it is either irreversibly anonymized, or securely destroyed.

Information Collected from Thirds-Party Software

When you visit the MITRE Site, you may link to third-party software that links to another party’s website. MITRE does not collect any information that may be collected by that third party; however, information you supply to that third-party software may be collected and/or used by that party. For information about that third party’s privacy policy, please see their respective website.

Links to Other Sites

Though the MITRE Site may contain links to other websites, MITRE is not responsible for the content, links, or privacy on any of those websites. It is recommended that you review the privacy policy applicable to those websites before accessing them.

Communication Preferences

You will only receive emails, mailings, or app notifications from MITRE if you have requested or agreed to be on our correspondence list. If you are currently on our communications list and do not wish to receive further contact, simply email a request to ACTPOC_Members@mitre.org with the subject “Unsubscribe“.

Changes to Our Privacy Policy

The MITRE Site may change from time to time. As a result, at times it may be necessary for us to make changes to this Privacy Policy. Accordingly, MITRE reserves the right to update or modify this Privacy Policy from time to time. If MITRE makes any material changes to this Privacy Policy, they will be posted and MITRE will concurrently update the “Effective Date” of this Privacy Policy stated above. Please review this Privacy Policy periodically, and especially before you provide any information. Your continued use of the MITRE Site after any changes or revisions to this Privacy Policy shall indicate your agreement with the terms of such revised Privacy Policy.

Questions and Comments

Please feel free to send your privacy-related comments or questions to privacy@mitre.org. We will do our best to respond to all reasonable inquiries in a timely manner. For all other ACT@POC™ related questions and comments, please contact us at ACTPOC_Members@mitre.org.