Effective Date: May 27, 2021
The MITRE Corporation (“MITRE”) respects the privacy of its website users.
Information Collected from Web Traffic Reporting Tools
When you visit the Site, the website server logs basic information about each visit. MITRE processes this information monthly via an automated software tool to identify any Site performance issues, popular sections and content, and other important Site characteristics. This information does not identify you personally. This information is used only as a source of anonymous statistical information. MITRE may internally store such information, or it may be included in databases owned and maintained by our third-party service providers.
Do Not Track Signals
MITRE also uses Google Analytics and Google Tag Manager, which are third-party software services, to capture and analyze Site usage information. This service supplies MITRE with additional non-personally identifiable information about Site users to help us create content that our users may find useful. Users that wish to have their non-personally identifiable information not collected by means of their visit to the MITRE Site have the option to opt-out of the Google Analytics tracking service via this link https://tools.google.com/dlpage/gaoptout/.
Cookies and other passive information collection technologies enable MITRE to compile aggregate statistics concerning use of the Site, analyze trends, advance security of the Site, deliver content, and otherwise administer and improve the Site.
A. Information Collected
MITRE may obtain personal information about you, such as your name, address, demographic data, authentication credentials, email and phone number, when you submit such information to MITRE for queries regarding our services and/or visit the Site. “Personal Information” means information that identifies you or could reasonably be used to identify you.
MITRE may also collect other information about your visits to our Site without you actively submitting such information. This information may include, for example: your browser type and language, your operating system, device type, access time, your Internet Protocol (IP) address, the URLs of websites you visited before and after visiting our Site, the web search that landed you on our Site, and the links you click on within our Site.
B. Use of Personal Information
MITRE may use your Personal Information to improve the Site, notify you about updates to the Site, and for internal business analysis or other business purposes consistent with our mission and to carry out other purposes that are disclosed to you and to which you consent as required under applicable law.
MITRE may share the Personal Information that you provide to us within the corporation and with third-party service providers to respond to your queries and we may use this information for marketing research, sales, support, and service-related purposes. MITRE will never transfer your Personal Information to any third-party for that third-party’s marketing purposes.
MITRE may share generic aggregate demographic information not linked to any Personal Information with our business partners, third-party service providers, and trusted affiliates. With the limited exceptions above, MITRE does not provide Personal Information to anyone outside of the corporation unless required by law to do so.
C. Legal Grounds for Processing of Your Personal Information.
The use of your Personal Information set out in B. above is permitted under applicable United States’ state laws. For Personal Information collected under the applicability of European, Australian, and Canadian specific data privacy regulations and laws, the legal grounds for use are as follows:
When you have consented for MITRE to use and collect your Personal Information, you will have been presented with an online consent form in relation to any such use and may withdraw your consent at any time by sending an email to: ACTPOC_Members@mitre.org.
Where necessary to enter into or perform our contract with you.
Where MITRE needs to use it to comply with our legal obligations.
Where MITRE uses it to achieve a legitimate interest and our reasons for using it outweigh any prejudice to your data protection rights, such as promoting MITRE’s services and tailoring news and communications for you as requested by you, or for detecting fraud and criminal activities.
MITRE may also transfer your Personal Information to a third party without your consent when justified by a legitimate interest, or if there is a contractual obligation to do so.
D. Updating, Restricting, Deleting, or Accessing of Personal Information
If you wish to correct, restrict, or delete inaccuracies with your Personal Information, or to request access in an usable electronic format, as legally required, to any Personal Information that MITRE obtains about you, please contact us at ACTPOC_Members@mitre.org.
However, in certain situations, MITRE may not be able to provide access to, restrict, or delete all of the Personal Information that it holds about you due to applicability of certain exemptions such as, safeguarding the public interest (e.g. the prevention or detection of a crime), maintaining our interests (e.g., legal privilege), and protecting the rights of third parties.
E. Compliance with Legal Requests
MITRE may be legally required to provide your Personal Information to law enforcement agencies, regulators, courts and third-party litigants in connection with civil or criminal proceedings or investigations anywhere in the world. Where permitted, we will direct any such request to you, or we may notify you before responding unless to do so would prejudice the prevention or detection of a crime.
F. Security of Personal Information
MITRE maintains physical, electronic and procedural safeguards designed to protect Personal Information. MITRE employs encryption technologies and user authentication procedures that are designed to keep your data secure. MITRE limits access to Personal Information to authorized personnel, contractors and business partners who need access to perform their responsibilities and are contractually required to keep your information secure.
G. Retention of Personal Information
MITRE retains your Personal Information only as long as is necessary and only for the purpose for which MITRE obtained the Personal Information. MITRE’s retention periods are based on business needs and once your Personal Information is no longer needed, it is either irreversibly anonymized, or securely destroyed.
Information Collected from Thirds-Party Software
Links to Other Sites
You will only receive emails, mailings, or app notifications from MITRE if you have requested or agreed to be on our correspondence list. If you are currently on our communications list and do not wish to receive further contact, simply email a request to ACTPOC_Members@mitre.org with the subject “Unsubscribe“.
Questions and Comments
Please feel free to send your privacy-related comments or questions to firstname.lastname@example.org. We will do our best to respond to all reasonable inquiries in a timely manner. For all other ACT@POC™ related questions and comments, please contact us at ACTPOC_Members@mitre.org.