Privacy Policy

Welcome to the Supply Trace Research Pilot. The Supply Trace Research Pilot is a project at Northeastern University. Northeastern University is committed to delivering information services that recognize and respect your concerns about privacy. We have developed this Data Privacy Policy that outlines our privacy practices on how we process, collect, use and share your personal information, as well as your privacy rights under certain privacy laws. Please review this Policy carefully, as there may have been changes to the Policy since you last visited the website.

Northeastern University (“Northeastern,” “us,” or “we”) is committed to protecting the privacy and security of all confidential information when you access, use, or interact with us via the Supply Trace Research Pilot website (the “Site”), the Supply Trace Research Pilot Platform (the “Platform”), marketing communications, and confidential information we process in order to provide services to our users. We receive limited confidential information from our users. This notice explains our practices with regard to the confidential information we receive from our users as a Data Processor.

This Privacy Policy does not apply to data that is not personal, which includes anonymous and aggregated data, or information related to our job candidates.  

This Privacy Policy is intended to apply to the extent we processes your data as a data controller. It is not intended to apply when Northeastern processes your data as a data processor on behalf of our customers. It also does not apply to information that has been aggregated, de-identified, or pseudonymized.  

  1. Information We Collect

We collect “personal data,” which means information relating to an individual who can be identified, directly or indirectly, by reference to an identifier, such as a name, identification number, location data, or an online identifier.

1.1 Information Collected from You

The types of information we collect about you depends on your use of our products, services and the ways that you interact with us, and obtain from third parties. This may include information about:

1.2 Special Categories of Personal Data

We do not intentionally collect special categories of personal data which includes sensitive information such as:

You are not required to provide, nor should you disclose this information as we do not intend to process sensitive information. However, if you do disclose, you acknowledge that you consent to our collecting and processing of these special categories of data.

  1. How We Collect Your Personal Data

The types of personal data we collect about you depends upon your use of our products and services and the ways that you interact with us.

2.1 Personal Data Collected Directly from You

We ask for and collect personal data from you in the following instances:

If you provide personal data relating to another individual, you represent that you have the authority to do so, and where required, you represent that you have obtained the necessary consent to share such data. You acknowledge that the personal data of the other individual may be used in accordance with this Privacy Policy.

If you believe your personal data has improperly been provided to us, or if you want to exercise your rights relating to your personal data, please contact us through the Contact Us form.

2.2 Personal Data Collected from Others

We may collect your personal data from other sources such as publicly available information and third-party sources that we purchase personal data from. The third-party sources may change over time and may include:

The personal data may include identifiers, professional or employment related information, education information, commercial information, visual information, internet activity information, social media profiles, and inferences about preferences and behaviors. We may combine information from other sources with the personal data provided by you.

This data helps us keep our records updated, identify new customers, and create tailored advertising for products and services that may be of interest to you.

  1. Device and Usage Data We Process

We use information gathering tools such as cookies, web beacons, pixels, and similar technology to automatically collect information that might contain your personal data when you use our websites and services or interact with emails we send you.

3.1 Automatic collection.

Most websites automatically collect data about you when you visit the site. This information may include:

We use this information to analyze overall trends, help us improve our websites, offer a personalized experience for website users, and secure and maintain our websites.

We also automatically collect information as part of your use of our products and services. This information may include:

We use this information to maintain the security of our websites and our products and services, provide necessary functionality, improve the performance of services, assess and improve customer and user experience, validate that you are an authorized user, review compliance with usage terms, identify future opportunities for service development, assess capacity needs and requirements, and identify customer opportunities.

Device and usage data is primarily used to identify the unique uses of our websites instead of identifying specific individuals unless identity is required for security purposes or to provide services to the individual.

3.2 Tracking Technologies

Our websites, online services, interactive applications, email messages, and advertisements may use tracking technologies such as web beacons, pixels, tags, and cookies to help us tailor your experience, better understand your preferences, tell us which parts of our websites you have visited, and facilitate and measure the effectiveness of our interest-based advertisements and web services, and gather information about the use of our websites and the interactions with our emails.

Web beacons and pixels are used on our websites and in our emails to help deliver cookies, gather usage and performance data, and operate and improve our websites and marketing emails.

Cookies are alphanumeric identifiers that are stored on your device’s local storage through your web browser for recordkeeping purposes. Some cookies allow us to make it easier for you to navigate our websites and services, improve and customize your browsing experience, and infer your browsing preferences, while others are used to enable a faster log-in process or allow us to track your online activities over time and across our webpages.

We use both session-based and persistent cookies.

There are three categories of cookies: required and functional, analytics and customization, and advertising:

3.3 Disabling Cookies on Your Browser

You can opt out from the collection of non-essential device and usage data on your web browser. Depending on your personal preferences, you can edit your browser options by using the “Help” function in your browser toolbar. You can prevent your computer from accepting new cookies, have the browser notify you when you receive a new cookie, or disable all cookies. However, it is important to note that if you block or delete cookies that we use on our websites, you will still be able to browse certain areas of the websites, but some features may not function properly.

3.4 Flash Local Storage Objects

We may use Flash Local Storage Objects (Flash LSOs) to store your website preferences and to personalize your visit. Flash LSOs are different than browser cookies because of the amount and type of data stored. Typically, you cannot control, delete, or disable acceptance of all Flash LSOs through your web browser.

For more information about Flash LSOs and to learn how to manage your settings for Flash LSOs, go to the Adobe Flash Player Help Page.

3.5 Invisible Images

Invisible Images are tiny graphics with a unique identifier, similar in function to cookies. In contrast to cookies, which are stored on your device’s local storage, these images are embedded invisibly on web and application pages.

We may use invisible images, which are also known as web beacons, web bugs, or pixel tags in connection with our websites and service offerings to, among other things, track the activities of website visitors and application users, help us manage content, and compile statistics about website usage.

We, and our third-party service providers, also use invisible images in HTML emails to our customers to help us track email response rates, identify when our emails are viewed, and to track whether our emails are forwarded.

3.6 Behavioral or Interest Based Advertising

We, and our third-party service providers, may use information about your visit to our websites, such as pages you visit, items you view, and your responses to our advertisements and emails. This information allows us to make the advertisements you see more relevant to you. To update your preferences, you may send a notice through the Contact Us form to “unsubscribe” to any email marketing communication that is sent to you.

It may take up to ten (10) business days for your email preferences to take effect.

You may also visit the opt out pages to opt out of many third-party advertising networks through various trade association websites such as:

However, using these opt out pages does not mean that you will no longer receive advertising through our websites or services, or on other third-party websites.

3.7 Third Party Advertising Networks

From time to time, we may give unaffiliated network advertisers information, including your personal data. These network advertisers provide advertisements on our websites, applications, and on other parties’ websites and media, such as social networking platforms.

Our shared use of your personal data with these network advertisers enables us to offer the products and services that will be of most interest to you. Non-affiliated ad network providers, network advertisers, sponsors, and/or traffic measurement services may use cookies, JavaScript, web beacons, Flash LSOs, and other tracking technologies to measure the effectiveness of their advertisements and to personalize advertising content to you. Other parties’ cookies and technologies are governed by each company’s specific privacy policy, and not by this Privacy Policy.

When we work with third party advertising networks, we require them to restrict their data processing to only what is necessary to provide us with the advertising services we request.

Website users located in the United States may learn more about opting out and opt out of many third-party advertising networks through various trade association websites such as:

However, it does not mean that you will no longer receive advertising through our websites, services, or on other third-party websites.

3.8 Cross Device Use

We, and our third-party service providers, including Google, may use the information that we collect about you, whether directly from our website, from our mobile applications, through your device, or from a third party, to help us and our third-party service providers identify other devices that you use, such as a mobile phone, tablet, or other computer.

We, and our third-party service providers may also utilize the cross-device use information we learn about you to serve targeted advertising on your devices and to send you emails.

To opt out of cross device use, you may opt out of third-party advertising (see Section 3.7). However, if you opt out of these advertising cookies, your opt out will be specific to the web browser, application, or device from which you accessed the opt out. If you use multiple devices or web browsers, you will need to opt out of each device and each browser on each device that you use.

3.9 Do Not Track Option

Some internet browsers offer a “Do Not Track” option that allows you to tell websites that you do not want your online activities tracked. There is currently no industry common standard, therefore, we do recognize these Do Not Track signals on our websites. We take privacy and your preferences seriously and will continue to monitor Do Not Track developments and the adoption of a standard.

However, you may disable certain tracking by sending a notice to the Contact Us form or disabling cookies on your browser (see Section 3.3), or by opting out of advertising (see Sections 3.6 and 3.7).

3.10 Social Media

We are responsible for the content we publish using social media platforms, but we are not responsible for managing the social media platforms or the data they collect and process. Our websites have social media sharing plugins. These widgets may allow you to post information about your activities on our websites on outside platforms and social networks. You may also be able to like or share information we have posted on our websites or our branded social media pages. If the social media pages are hosted by the individual platforms and you click through to the site from our websites, the platform may receive information showing that you visited our websites. If you are logged into the social media site at the time you click through, the social media site may be able to link your visit to our websites with your social media profile.

3.11 Telephony Information

If you use features of our services on your mobile device, we may collect telephony log information, including phone numbers, time and date of the calls, duration of the call, SMS routing information. We may collect device event information, such as system activity, hardware settings, and browser language. We may also collect location information through GPS, IP address, WiFi access points and cell towers, and other sensors that provide us with information on nearby devices.

  1. Purposes and Legal Bases for Processing Personal Data

We collect and process your personal data for the following purposes:

Where required by law, we will obtain your prior consent to use and process your personal data, or we will rely on another authorized legal basis, such as performing a contract or having a legitimate interest.

  1. Who Do We Share Your Personal Data With?

We may share your personal data with our business partners, which include:

  1. International Transfers of Personal Data

We may collect, transfer, and store your personal data in the United States. We may also collect, transfer, and store your personal data in other countries. This includes countries outside the European Economic Area (EEA) and countries with laws that have not been determined to provide an adequate level of protection under the laws of the European Union (EU) or other jurisdictions.

This means that your personal data may be processed outside your jurisdiction in countries that are not subject to an adequacy decision of the European Commission on the basis of Article 45 of Regulation (EU) 2016/679 (GDPR) or regulatory authority. However, we will ensure that your personal data is subject to an adequate level of protection and security by entering into appropriate agreements, including the UK standard contractual clauses and the EU standard contractual clauses, or an alternative mechanism for the transfer of your personal data.

  1. Children’s Data

Our websites, products, and services are not for children. We do not knowingly collect and process personal data of children under the age of sixteen (16). If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us through the Contact Us form. and we will take the necessary steps to delete their personal data from our systems.

  1. Data Retention

We will retain your information no longer than is necessary for the Supply Trace Research Pilot’s purposes. We will retain your personal data for different periods of time depending on the category of personal data it is collected for. Some personal data may be deleted automatically, and some will be retained longer consistent with the original purpose for collecting it, for as long as required to fulfill our obligations, or as required by law.

When the retention period expires, we will delete your personal data. If there is any data that cannot be completely deleted for technical reasons, we will implement appropriate measures to prevent any further processing of such data.

  1. Your Rights

You may have certain rights relating to your personal data, subject to data protection laws. These rights may include:

We do not currently use automated decision making on our websites or in our services.

9.1 How to Exercise Your Rights

To exercise your rights, please contact us at through the Contact Us form.

Your personal data may be processed by us when we respond to these rights. We attempt to respond to all legitimate requests within thirty (30) days, unless otherwise required by law, and will contact you if we need additional information in order to honor your request or verify your identity. At times, it will take longer than thirty (30) days, considering the number and the complexity of the requests we receive. We will contact you if we need additional time to fulfill your request.

Some authorized users may update their settings and profiles by logging into their accounts.

Please be aware that your request does not guarantee complete access or comprehensive removal as the law may not permit or require removal in certain circumstances.

9.2 Your Rights in Customer Data

We may process your personal data if submitted by or for a customer of our products and services. We are the processor on behalf of our customer, who is the controller. We are not responsible for and have no control over the privacy and data security practices of our customers, which may differ from those in our Privacy Policy.

If your data has been submitted to us by or on behalf of a customer and you wish to exercise any rights you have over your personal data under the applicable data protection laws, please inquire directly with our customer.

We may only access your personal data based upon our customer’s instructions. If you wish to make your request to exercise your rights with us, please provide us the name of the customer who submitted your data to us. We will refer the request to that customer and provide any support they need to respond to your request within a reasonable time.

9.3 Your Preferences for Email and SMS Communications

You have choices about how we reach you with marketing offers and about other uses of your information. To update your preferences, you can:

Please be aware that it may take up to 10 business days for your email preferences to take effect.

Opting out of marketing communications will not opt you out of receiving important business communications related to your current relationship with us, such as information about your products or services, event registrations, service announcements, or security information.

  1. How we Secure Your Personal Data

We take appropriate organizational, technical, and physical measures to help safeguard against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure of, or access to, the personal data we collect and process. The way we do this includes:

We follow generally accepted standards to protect your personal data. However, no method of collection, storage, or transmission is 100% secure. You are solely responsible for protecting your password, limiting access to your devices, and signing out of websites after your sessions.

We encourage you to keep any passwords you use confidential and to be careful to avoid “phishing” scams where someone may send you an email that appears to be from the Supply Trace Research Pilot asking for your personal information. The Supply Trace Research Pilot will not request your ID or password through email.

  1. Linked Sites

For your convenience, there may be hyperlinks on our websites that link to other websites. We are not responsible for, and this Privacy Policy does not apply to the privacy practices of any linked websites or of any companies that we do not own or control. The website links may collect information in addition to the information we collect.

We do not endorse any of these linked websites, their products, services, or any of the content on their websites. We encourage you to seek and read the Privacy Policy of each linked website that you visit to understand how the information that is collected about you is used and protected.

  1. California Consumer Privacy Act Disclosures

The California Consumer Privacy Act (CCPA) requires businesses to disclose whether they sell personal data, which the CCPA calls “personal information.” For the purposes of this Section 12, “personal data” includes all “personal information” as defined by the CCPA.

As a business covered by the CCPA, we do not sell personal data for monetary consideration. We may share personal data with others or allow them to collect personal data from our websites or services if they are affiliates, third parties authorized by us, or business partners who have agreed to our contractual requirements regarding retention, use, and disclosure of personal data, or if you use our products or services to interact with third parties or direct us to disclose your personal data to third parties.

If there is any conflict between this Section 12 and the rest of our Privacy Policy, the terms of Section 12 shall prevail as to the personal data of California residents that is subject to the CCPA.

12.1 Categories of Personal Data Disclosed

The CCPA requires us to detail the categories of personal data that we disclose for certain business purposes. In the preceding twelve (12) months, we may have collected the following categories of personal data listed:

12.2 Business Purposes

In the preceding twelve (12) months, we may have collected and processed your personal data for various business purposes, including:

In the preceding twelve (12) months, we may have shared your personal data with our affiliates, vendors, and suppliers that provide services on our behalf, and other third parties such as business partners, advertising networks, internet service providers, data analytics providers, operating systems and platforms, providers of identity verification services, regulatory bodies, and government authorities.

12.3 CCPA Rights

California’s laws grant state residents certain rights under certain circumstances in relation to their personal data:

The information may be delivered by mail or electronically. If it is provided electronically, it will be portable and in a readily usable format so you can transmit the information to another entity or person.

12.4 How We Handle Your Requests

As part of processing your request, we will require you to provide certain personal data about you to verify your identity in accordance with CCPA requirements. This information may include your first and last name, email address, physical address, telephone number, account number, and the nature of your relationship with us.

You may also designate an authorized agent to make a request on your behalf. To comply with such a request, we will require the personal data referenced above for identification verification purposes as well as the first and last name, email address, and telephone number of your authorized agent.

Once we verify your request, we will make every attempt to respond within forty-five (45) days. If we require more time, we will inform you of the reason and the extension period in writing. If we cannot comply with your request, we will respond in writing with the reasons why.

Any disclosure will only cover the twelve (12)-month period preceding the receipt of the request.

We do not charge a fee to process or respond to your request unless there are excessive, repetitive, or manifestly unfounded requests. If we determine that your request warrants a fee, we will tell you why, in writing, along with a cost estimate before completing your request.

You may only make a personal data access request up to two (2) times in any twelve (12) month period.

12.5 Residents Under 18

If you are a California resident under the age of eighteen (18) and have provided content or information with us, you may request that we remove content or information that you have posted to our websites. This request does not ensure that we will completely remove the content or information as some of your content may have been reposted by another user.

  1. Changes to This Privacy Policy

We will update this Privacy Policy from time to time to reflect changes in our practices, technologies, and legal requirements. When we make a modification to the Privacy Policy, we will update the effective date at the end of this document.

If we make a material update, we may provide you with notice prior to the update taking effect by posting a notice on our websites or contacting you directly. We will seek your consent to these changes where required by applicable law if feasible.

We encourage you to periodically review this Privacy Policy to stay informed about our collection, processing, and sharing of your personal data.

By accessing or using the Site in any manner, shall be considered acceptance of this Privacy Policy.

  1. Notification of Copyright Infringement Concerns

If any User believes that its copyrighted work has been copied and is accessible on the Supply Trace Research Pilot websites in a way that constitutes copyright infringement, please send a notice through the Contact Us form..

Notices must include each of the following:

  1. The electronic or physical signature of the owner of the exclusive right that is allegedly infringed, or the electronic or physical signature of someone authorized to act on the owner’s behalf;
  1. Identification of the copyrighted work claimed to have been infringed, or, if multiple copyrighted works at a single online site are covered by a single notification, a representative list of such works at that site;
  1. Identification of the material, claimed to be infringing or to be the subject of infringing activity, for which disabling of access or removal is sought, and information reasonably sufficient to permit us to locate the material;
  1. If the infringement claimed is by reason of intermediate and temporary storage, or caching, of material, include also a statement confirming that the infringing material has been removed from the originating site or access to it has been disabled or that a court has ordered that the material be so removed or that access to such material be disabled;
  1. If the infringement claimed is by reason of referring or linking users to an online location containing infringing material or infringing activity, by using information location tools, then, instead of the identification under paragraphs (3) or (4), provide identification of the reference or link, to the claimed material or activity, that is to be removed or access to which is to be disabled, and information reasonably sufficient to permit us to locate that reference or link;
  1. Information reasonably sufficient to permit us to contact you, such as an address, telephone number, and, if available, an electronic mail address at which you may be contacted;
  1. A statement that you has a good faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law; and,
  1. A statement that the information in the notification is accurate, and under penalty of perjury, that you are authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.
  1. Acceptable Use Policy

15.1 Generally

The Supply Trace Research Pilot and its affiliates Acceptable Use Policy (“AUP”) is intended to foster responsible use of the Supply Trace Research Pilot’s infrastructure, networks, cloud-based offerings, systems, services, websites, facilities and products (collectively, the “Supply Trace Research Pilot Infrastructure and Services”) by our customers and other users. Users consent to be bound by the terms of this AUP. Supply Trace Research Pilot reserves the right to modify this AUP in its discretion at any time. Modifications will be effective when posted and users are expected to check this page from time to time to take notice of any changes we make, as they are legally binding on each User. Users’ use of the Supply Trace Research Pilot websites after we make modifications constitutes acceptance of our modifications.

15.2 Suspension; Termination

If the Supply Trace Research Pilot determine that any User has violated any portion of this AUP, we may terminate the User’s use of the website. We will suspend service for violation of the AUP on the most limited basis as we determine is reasonably practical under the circumstances to address the underlying violation. The Supply Trace Research Pilot will attempt to notify user prior to suspending service for violation of the AUP (which may be via email or any other notification). However, the Supply Trace Research Pilot may suspend service without notice if the Supply Trace Research Pilot becomes aware of a violation of this AUP or any applicable law or regulation that exposes the Supply Trace Research Pilot to criminal or civil liability, or that exposes the Supply Trace Research Pilot or any third party property to harm. Harm may include, but is not limited to, risk of having one or more IP addresses placed on blacklists. We may take any further action as we deems appropriate under the circumstances to eliminate or preclude repeat violations. The Supply Trace Research Pilot is not liable for any type of damages that Users or third parties may suffer resulting in whole or in part from the Supply Trace Research Pilot’s exercise of its rights under this AUP. This exclusion of liability does not include the Supply Trace Research Pilot’s liability for death or personal injury caused by its negligence, or any other liability that the Supply Trace Research Pilot cannot exclude or limit by law.

  1. Miscellaneous

To learn more important information about the Terms and Conditions of use of this website, please visit the Terms of Use page of this website.

This website may contain links or frames of other websites, which may or may not be affiliated with the Supply Trace Research Pilot. These links and frames are available with the sole purpose of providing further benefits to users. The inclusion of these links and frames does not mean that The Supply Trace Research Pilot has knowledge of, agrees or is responsible for them or their content. Therefore, the Supply Trace Research Pilot cannot be held liable for any loss or damage suffered as a result of using such links or frames.

  1. Contacting Us

To exercise your rights regarding your personal data, or if you have questions about this Privacy Policy or our privacy practices, please submit your request through the Contact Us form.  

Please be aware that your request may have limitations, according to applicable law.