We are committed to protecting your privacy

Updated May 1, 2019

Overview

Kennedy Krieger Institute (“Kennedy Krieger,” or “the Institute”) is committed to protecting the privacy and security of the personal information we receive or collect from you. We also believe in transparency and are committed to informing you about how we treat your personal information.

Kennedy Krieger has prepared this Privacy Policy (the "Policy"), together with any documents referenced therein, to inform you ("you", "your" or "user") of our practices regarding personal information that we collect, use, and share regarding our websites, and other online services provided by us and our affiliates. The Policy also describes certain rights and options that you have with regard to your personal information.

This Policy covers all personal information collected through website URLs, web applications, and mobile applications (collectively the "Sites").

This Policy does not apply to information you may provide to us offline or through means other than through these Websites.

Please read this Privacy Policy carefully to understand how we treat your personal information and what choices and rights you have in this regard. If you do not agree with the terms and conditions of this Policy, you should not access or use our sites or our online services.

Who Is Responsible For Your Personal Information?

Kennedy Krieger is responsible for the personal information you provide through our Sites. Kennedy Krieger includes Kennedy Krieger Institute, Kennedy Krieger Foundation, Kennedy Krieger Children’s Hospital, Kennedy Krieger School Programs, Parents and Children Together (PACT), etc. (collectively, “Kennedy Krieger”, “the Institute” or "we", "us", "our").

If you are a user in in the European Union (the "EU") or European Economic Area ("EEA"), Kennedy Krieger will be the controller of the personal information we collect for purposes of the E.U. General Data Protection Regulation, 2016/679 (the "GDPR").

What Personal Information Do We Collect and Why

We may collect and process the following personal information from you for the following purposes:

Category

Types of Data and Purpose

Contact Information

When you visit our Site(s) or ask for services, we may ask you for your name, address, telephone number, email address or other contact details in order to respond to your requests or inquiries.

Donor Account Information

When you create an account, we collect your contact information, other identity information (e.g., age, date of birth, photo), other demographic information (location), username and password, and other registration information, including payment information. This information is necessary to enable us to provide you the account you have requested and to maintain the account and your profile. You may update your account information by editing the information associated with your account.

Event Registration Information

When you register for an event hosted by us, we collect your contact information and other details necessary for processing the registration, including payment information.

Business Information

When you seek services from us in the course of contractual or customer relationships between you, your organization and Kennedy Krieger, we may collect contact information and other personal information in order to provide you with the services you have requested.

Financial and Payment Information

When you purchase goods or services from or donate funds to Kennedy Krieger, we may collect your bank account and other data necessary to process payments, including credit card numbers, security codes, expiration dates, and other related billing information.

Location Information

When you use our Sites, we may collect information about your use of our Sites and services for advertising, analytics, to serve content and to protect our Sites and services. Location information collected may include your Internet Protocol (IP) address, internet tags, GPS, Wi-Fi, cellular technology, Radio-frequency identification (RFID), Bluetooth or other beacon technology or other similar location-tracking technologies.

Cookies

When you visit our Sites, we may collect cookies and use similar technologies to, among other things, provide you with a more personal and interactive experience on our Sites, to improve our marketing efforts, and for usage analytics for our Sites (e.g., page response times, download errors, length of visit, webpages visited, etc.). Please see our Cookies and Similar Technologies Policy for more information. If you choose to disable cookies and similar technologies, some areas and features of our Sites may not work properly.

Automated Information

When you visit our Sites, we automatically collect information from your browser or your mobile device, such as Internet Protocol (IP) address or unique device identifier, cookies and data about which pages you visit in order to allow to operate and provide our Sites and our services. This information is used to protect our Sites and services and to keep our Sites secure, to analyze and improve our Sites and services and understand how our Sites work for users, and to provide advertising to you and a more personalized experience for our users. To learn more about our collection of technical data, please visit our Cookies and Similar Technologies Policy.

Email Interconnectivity

If you receive email communications from us, we may use certain tools to capture data related to when you open our message, click on any links or banners it contains and make purchases. We use this information to enhance our marketing efforts.

Employment

If you apply for a job, or become an employee, we collect personal information necessary to process your application or employment. This may include, among other things, your contact information, your social security number, employment history, etc.

Feedback / Support / Inquiries

If you provide us with feedback or contact us for support or ask us questions, we will collect your name, email address, other contact information and other information needed to respond to your feedback, request for support, or answer your question.

Mailing List

When you sign up for one of our mailing lists, we collect your contact information, including your email address and postal address.

Order Placement

When you place an order with or purchase goods or services from us, we collect your name, billing address, shipping address, email address, and contact details, shipping preferences, and payment information.

Sensitive Personal Information

When necessary in order to respond to your requests for services or employment, we may collect information regarding your racial or ethnic origin, biometric data, health information, financial information. Kennedy Krieger will collect this sensitive personal information with your express consent or as otherwise permitted by applicable law.

In addition to the information that we collect from you directly, we may also receive information about you from other sources, including third parties, business partners, our affiliates, or publicly available sources.

How Will We Use Your Personal Information?

In addition to the uses described above, Kennedy Krieger uses the personal information collected in an effort to improve your experience on our Sites, to provide services to you, and to communicate with you about the information you have requested. The Institute may also use personal information to help target specific offers to you and to help us develop and improve our Sites and services. Additionally, we may use your personal information in the following ways:

  • To provide you with services you have requested and to manage our relationship with you, including administering your account, processing payments, accounting, auditing, billing and collection and taking other steps necessary to the performance of our business relationship with you;
  • To present and improve Site contact and functionality;
  • To determine user interests, needs and preferences;
  • To provide notice of changes to our Sites or the services we offer or provide through it;
  • To conduct research and analysis;
  • To develop new products and services;
  • To manage and maintain the security of our Sites and services;
  • To market our services to you. We will only provide you with marketing-related information after you have, where legally required to do so, opted in to receive those communications and having provided you with the opportunity to opt-out of such communications at any time. We do not sell or distribute this information to third parties or use it for any other purpose.
  • For complying with our legal and compliance obligations, including maintaining records, performing compliance audits, etc.
  • For insurance purposes;
  • To exercise and defend our legal rights, or to comply with court orders;
  • For any other purpose related to and/or ancillary to any of the purposes and uses described in this Policy for which your personal information was provided to us;
  • In any other way we may describe when you provide the information; and
  • For any other purpose to which you have consented.

We may process (collect, organize, use, transmit, store or remove) your personal information in connection with any of the purposes and uses set out in this Policy on one or more of the following legal grounds:

  • because it is necessary for us to do so to perform the services you have requested, to comply with your instructions or other contractual obligations between you and Kennedy Krieger;
  • to comply with our legal obligations as well as to keep records of our compliance processes;
  • because our legitimate interests, or those of a third-party recipient of your personal information, makes the processing necessary, provided those interests are not overridden by your interests or fundamental rights and freedoms;
  • because you have chosen to publish or display your personal information on a public area of our Sites, such as blog or comment area;
  • because it is necessary to protect your vital interests;
  • because it is necessary in the public interest; or
  • because you have expressly given us your consent to process your personal information in a particular manner.

Disclosure Of Your Personal Information

We may share your personal information in the following contexts:

Category

Disclosure Contexts

Subsidiaries and Acquisitions

We may share your personal information with our corporate subsidiaries and affiliates. If another company acquires Kennedy Krieger, we will share your personal information with that company.

Disclosures With Your Consent

We may ask if you would like us to share your personal information with other unaffiliated third parties who are not described elsewhere in this Policy. We will only disclose your personal information in this context with your consent.

Disclosures Without Your Consent

We may disclose your personal information in response to subpoenas, warrants, court orders or other legal process, or to comply with relevant laws. We may also share your personal information in order to establish or exercise our legal rights, to defend against a legal claim, to investigate, prevent, or take action regarding possible illegal activities, suspected fraud, safety of person or property or a violation of our Terms of Use, or to comply with your request for shipment of items ordered from us to the provision of services by a third-party.

Public

Some areas of our Sites provide the opportunity to post comments, or reviews, in a public forum. If you decide to submit your personal information in these areas, you do so at your own risk and acknowledge that the information will be publically-available.

Directories

You may consent through account or conference/seminar registrations to having your contact information shared with other account holders or conference/seminar registrants.

Third Parties

Kennedy Krieger may provide personal information about you to third parties that offer products and services specifically requested by you.

Service Providers

Kennedy Krieger may share your personal information with our service providers. Among other things, service providers may help us to administer our Sites, support our provision of services requested by you, provide technical support, send marketing, promotions and communications to you about our service, payment processing and other legitimate purposes permitted by law.

 

How Long Do We Store Your Personal Information?

Kennedy Krieger will retain your personal information as needed to fulfill the purposes for which it was collected. The Institute will retain and use your personal information as long as necessary to comply with our business requirements, legal obligations, resolve disputes, protect our assets, provide our services, and enforce our agreements.

When we no longer have a purpose to retain your personal information, we will securely destroy your personal information in accordance with applicable law and our policies.

Security Of Your Personal Information

Kennedy Krieger has put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized manner, altered or disclosed. While our security measures seek to protect your personal information in our possession, no security system is perfect and the Institute cannot promise that your personal information will remain absolutely secure in all circumstances.

The safety and security of your personal information also depends on you. Where you use a password for access to restricted parts of our Sites, you are responsible for keeping the password confidential. Do not share your password with anyone. If you are concerned about sharing protected health information, please call us, and do not enter the information into a form or anywhere else on the our Sites or any social media channels.

If a security breach causes an unauthorized intrusion into our Sites or systems that compromises your data, we will notify you and any applicable regulator when we are required to do so by applicable law.

Updating Your Personal Information

If the personal information you have provided to us changes, please let us know. For instance, if your email changes, if you wish to cancel any request you have made of us, or if you become aware of inaccurate personal information about you, contact us to update your information. You may also edit your account details if you have a user account through our Sites.

We are not responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.

Your Rights To Access And Control Your Personal Information

Please use the Contact Us details at the end of this Policy to exercise your rights and choices under this Policy.

Right of Access. If required by law (e.g., under the GDPR), upon request, we will grant reasonable access to the personal information that we hold about you.

Accuracy. Our goal is to keep your personal information accurate, current and complete. Please contact us if you believe your information is not accurate or changes.

Right to Object. In certain circumstances, as permitted under applicable law, you have the right to object to processing of your personal information and to ask us to erase or restrict our use of your personal information. If you would like us to stop using your personal information, please contact us and we will let you know if are able to agree to your request.

Right to Erasure and Deletion of Your Personal Information. You may have a legal right (for instance, if you are located in the EU or EEA under the GDPR) to request that we delete your personal information when it is no longer necessary for the purposes for which it was collected, or when, among other things, your personal information has been unlawfully processed. All deletion requests should be sent to the address noted in the Contact Us section of this Policy.

We may decide to delete your personal information if we believe it is incomplete, inaccurate or that our continued storage of your personal information is contrary to our legal obligations or business objectives. When we delete personal information, it will be removed from our active servers and databases and our Sites, but it may remain in our archives when it is not practical or possible to delete it. We may also retain your personal information as needed to comply with our legal obligations, resolve disputes, or enforce any agreements.

Right to Withdraw Consent. If you have provided your consent to the collection, processing and transfer of your personal information, you have the right to fully or partially withdraw your consent. To withdraw your consent, please notify us using the information in the Contact Us section of this Policy and you may follow opt-out links on any marketing communications sent to you.

Once we have received notice that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there are compelling legitimate grounds for further processing that override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

Withdrawal of consent to receive marketing communications will not affect the processing of personal information for the provision of our services.

Right to Complain. If you believe that your rights relating to your personal information have been violated, you have a right to lodge a complaint with the applicable enforcement authority, or seek a remedy through the courts. You may also lodge a complaint with us by contacting us using the information provided in the Contact Us section of this Policy.

Online Tracking. We do not currently recognize browser settings or signals of tracking preferences, which may include "Do Not Track" instructions.

California Residents. California residents may be entitled to ask us for a notice describing what categories of personal information (if any) we share with third parties or affiliates for those parties to use for direct marketing. If you are a California resident and would like a copy of such notice, please submit a written request to us using the information in the "Contact Us" section of this Policy.

European Union or European Economic Area Residents. If you are located in the EU or EEA and believe we have not processed your personal information in accordance with applicable provisions of the EU GDPR, you may lodge a complaint with your local data protection or supervisory authority.

Cross Border Transfers of Personal Information

Kennedy Krieger is located and established in the United States and therefore, your personal information may be transferred to, stored or processed in the United States. While the data protection, privacy and other laws of the United States might not be as comprehensive as those in your country, we take necessary and appropriate steps to protect the security and privacy of your personal information. By using our Sites or requesting services from us, you understand and consent to the collection, storage, processing and transfer of your personal information to our facilities in the United States and those third parties with whom we share it as described in this Policy.

Residents of the EU / EEA. We rely on recognized legal bases to lawfully conduct cross-border transfers of personal information outside of the European Union (EU) and European Economic Area (EEA), such as your express informed consent (as noted above), when transfer is necessary for us to deliver services pursuant to an agreement or contract for services between Kennedy Krieger and you, or when the transfer is subject to safeguards that assure the protection of your personal information, such as the European Commission's approved standard contractual clauses.

Links To Other Sites

Our Site may contain links to, and media and other content from, third party websites. These links are to external websites and third parties with which we have no relationship. If you click on an embedded third-party link, you will be redirected away from our Site to the external third-party website. You can check the URL to confirm that you have left our Site.

Kennedy Krieger cannot and does not (i) guarantee the adequacy of privacy, security, practice content or media provided by third parties or their websites, (ii) control third parties' independent collection or use or your personal information, or (iii) endorse any third party information, products, services or websites that may be reached through embedded links on our Sites.

Any personal information provided by you or automatically collected from you by a third party will be governed by that party's privacy policy and terms of use.

Children

The Children's Online Privacy Protection Act ("COPPA"), as well as other data privacy regulations, restrict the collection, use, or disclosure of personal information from and about children on the internet. Our Site and the services are not directed to children aged 16 or younger, nor is information knowingly collected from children under the age of 16. No one under the age of 16 may access, browse, or use our Sites or provide any information to or on our Sites. If you are under 16, please do not use or provide any information on our Sites. If we learn that we have collected or received personal information from a child under the age of 16 without a parent's or legal guardian's consent, we will take steps to stop collecting that information and delete it.

For more information about COPPA, please visit the Federal Trade Commission's website.

Changes To Our Privacy Policy

We reserve the right to update and change this Policy from time to time in order to reflect any changes to the way in which we treat your personal information or in response to changes in law. We will post any changes we make to this Policy on this page. If we make material changes to how we treat your personal information, we will notify you through a notice on the website home page or through email communication, when appropriate. The date this Policy was last revised is identified at the top of this Policy.

Contact Details

If you have questions or comments about this Policy, wish to access personal information we hold about you; believe the personal information we have about you is incorrect, or wish to lodge a complaint with us about how we have handled your personal information, please contact us through our website feedback form or email us at webmaster@kennedykrieger.org.