NASPO Privacy Policy
The National Association of State Procurement Officials (NASPO) respects the privacy of its members and other individuals with whom it interacts and is committed to protecting it through compliance with this Privacy Policy (“Policy”). NASPO has adopted this Policy to govern the process of personal data collection and information sharing.
This Policy describes how NASPO may collect, use, share, and safeguard personal information collected at NASPO or a NASPO controlled entity’s events and on NASPO websites and platforms, including www.naspo.org, www.naspovaluepoint.org, the NASPO Network, the NASPO Procurement U Learning Management System, and the NASPO eMarketPlace, and any mobile websites, mobile applications, social media sites, and any other digital services and platforms officially operated by NASPO or a NASPO controlled entity (each a “NASPO Site”). This Policy does not apply to information collected through third-party websites or services that are not controlled by NASPO.
Information Collected
NASPO typically collects two kinds of information about individuals: (a) information that an individual provides that personally identifies the individual; and (b) information that NASPO automatically collects when an individual visits a NASPO Site, or that an individual provides to NASPO, that does not personally identify the individual.
(1) Personal Information. “Personal Information” means information that can be used to specifically identify or contact an individual, such as the individual’s name, employer and job title, address, email, phone number, date of birth, driver’s license number, or financial account information.
- Generally, NASPO does not automatically collect Personal Information from an individual visiting a NASPO Site.
- NASPO may request, collect, or otherwise provide individuals with an opportunity to submit Personal Information in connection with certain activities on NASPO Sites, including, but not limited to:
- Registration screens and online forms;
- Participation in a survey or questionnaire;
- Membership and other applications;
- Participation in the NASPO Network or similar NASPO-provided online service, community, or message board;
- Participation in the NASPO Procurement U Learning Management System; and
- Participation in NASPO-provided or NASPO-sponsored events and training.
- If Personal Information is publicly available or directly disclosed by a person on a public forum maintained by NASPO, that information may be collected and used by NASPO and others.
(2) Non-Personal Information. “Non-Personal Information” means any information that does not personally identify an individual.
- Non-Personal Information can include certain Personal Information that has been de-identified (i.e., information that has been rendered anonymous). NASPO automatically collects certain Non-Personal Information from individuals when accessing a NASPO Site (“Usage Data”). This information can include, but is not limited to, IP addresses, the type
of browser being used (e.g., Safari, Chrome, Edge), the third-party website from which the visit originated, the operating system being used, the search terms entered on a NASPO Site, the specific webpages visited, and the duration of the visit. Some Usage Data may be considered Personal Information under applicable law if it can reasonably be linked to a specific individual. - NASPO may obtain Non-Personal Information from information provided by an individual or a third-party to NASPO, either separately or together with Personal Information.
- NASPO may collect information about the location of a device used to access NASPO Sites, including precise location derived from GPS, Wi‑Fi, or IP address, and other information that indicates an individual’s current or prior location (e.g., geotag information in photographs).
Use of Personal and Non-Personal Information
(1) Use of Personal Information. NASPO may use Personal Information submitted by an individual for the following, non-exhaustive list of purposes:
- Operate NASPO Sites;
- Respond to member requests;
- Deliver products or services requested by members;
- Process membership applications;
- Contact individuals via surveys to conduct research about opinions of current products/services, or of potential new products/services that may be offered;
- Provide input on particular needs to NASPO staff to make current and planned initiatives increasingly relevant to the individual’s needs;
- Facilitate data analysis by NASPO in the execution of any business functions provided by NASPO in order to improve business processes, products/services/events/trainings, and to provide more meaningful interactions with NASPO Sites;
- Provide future service and support;
- Inform individuals of other products or services available from NASPO or its affiliates;
- Secure lodging, transportation, and other services associated with NASPO provided or sponsored events or trainings;
- Notify event or training participants about event information such as reminders, updates, logistical changes, and post-event satisfaction data collection;
- Capture event emergency contact information (name, phone number, relationship) to identify designated individuals in case of emergency or crisis situation;
- Participate in the NASPO Network or similar NASPO provided online services, community, or message boards; and
- Participate in NASPO-provided or NASPO-sponsored events and trainings.
(2) Use of Non-Personal Information. NASPO may use, and share in aggregated, anonymous form, with NASPO affiliated companies and third parties, Non-Personal Information, by itself or aggregated with information it has obtained from others, for the following, non-exhaustive list of purposes:
- Help analyze traffic to determine which pages within the NASPO Sites are the most popular and to understand customer needs and trends;
- Better understand how users access and use the NASPO Sites, for the purposes of trying to improve NASPO Sites and to respond to user preferences, including language and location customization, personalized help and instructions, or other responses to users’ usage of the NASPO Sites;
- Carry out targeted promotional activities and deliver customized and personalized content and advertising;
- Assess the effectiveness of and improve advertising and other marketing and promotional activities on or in connection with NASPO Sites;
- Operate, improve, and expand the products and services offered to individuals;
- Provide customer service, maintain security, and detect fraud or illegal activities;
- Archival and backup purposes in connection with the provision of NASPO Sites; and
- Enforce NASPO’s Terms of Use and other applicable policies.
Cookies and Web Beacons
NASPO automatically receives and stores certain types of Non-Personal Information whenever visitors interact with NASPO Sites. For example, like many websites, NASPO uses “cookies” and “web beacons” (also called “clear gifs” or “pixel tags”) to obtain certain types of information when web browsers access the NASPO Sites. “Cookies” are small files that are transferred
to a computer’s hard drive or a web browser’s memory to enable NASPO systems to recognize the browser and to provide convenience and other features to the visitor, such as recognizing them as a frequent user of the NASPO Site. This activity simplifies the process of submitting Personal Information, such as billing addresses and shipping addresses.
When returning to the same NASPO Site, the information previously provided can be retrieved, so individuals can easily use the NASPO Site features that they customized.
Individuals have the ability to accept or decline cookies. Most web browsers automatically accept
cookies, but individuals can usually modify their browser setting to decline cookies if preferred. If
individuals choose to decline cookies, they may not be able to fully experience the interactive features
of the sites’ services. More information about cookies can be found at www.allaboutcookies.org.
(1) Web Beacons. “Web beacons” are tiny graphics with a unique identifier, similar in function to cookies, and may be used to track the online movements of users, when an email has been opened, and to provide other information.
(2) Examples of the information NASPO collects and analyzes in this manner include the internet protocol (IP) address used to connect a computer to the internet; computer and connection information such as browser type and version, operating system, and platform; a visitor’s behavior on a NASPO Site, including the URL they come from and go to next (whether this URL is on the NASPO Site or not); and cookie number.
NASPO Security Measures
NASPO takes steps it considers reasonable to protect Personal Information collected via NASPO Sites from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. NASPO secures the information on computer servers in a controlled, secure environment, protected from unauthorized access, use, or disclosure. When Personal Information (e.g., a credit card number) is transmitted to other websites, it is protected through the use of encryption, such as the Transport Layer Security (TLS) and Secure Socket Layer (SSL) protocols. Keep in mind, however, that despite such reasonable safeguards, NASPO cannot guarantee or warrant the security of any information disclosed or transmitted to NASPO online, and NASPO is not responsible for the theft, destruction, or inadvertent disclosure of Personal Information. In addition, other internet sites or services that may be accessible through NASPO Sites have separate data and privacy practices independent of NASPO, and therefore NASPO disclaims any responsibility or liability for their policies or actions. Those vendors and others should be contacted directly with questions about their privacy policies.
Information Sharing
NASPO does not sell, rent, or lease collected Personal Information to third parties. NASPO may, from time to time, contact individuals on behalf of external business partners about a particular offering that may be of interest. In those cases, Personal Information (such as e-mail, name, address, telephone number) is not transferred to the third party. In addition, NASPO may share data with trusted partners to perform services on NASPO behalf, to help NASPO perform statistical analysis, send email or postal mail, provide customer support, or arrange for deliveries. All such third parties are prohibited from using Personal Information except to provide these services to or on behalf of NASPO, and they are required to maintain the confidentiality of such information. NASPO does not use or disclose sensitive personal information, such as race, religion, or political affiliations, without an individual’s explicit consent.
NASPO may contract with third parties to provide administration of some business functions and conference/event related services. NASPO may share Personal Information collected for said purposes in the execution of the services provided.
Specific examples of the data required for full delivery on conference-related services are:
- ADA needs and dietary preferences/needs shared with events staff, the conference hotels, as well as off-site restaurants, caterers, vendors, and/or venues providing services to the conference.
- Contact information such as name and selected preferences to confirm rooming needs and reservations at the conference hotel.
- Contact information such as name and preferences used to confirm travel or transportation arrangements, where appropriate.
- Contact information such as name, phone number, credentials/designation, place of employment, mailing address, and/or email address to share with event attendees to facilitate peer-to-peer communications.
- Emergency contact information including names, phone numbers, and relationship types used only to communicate with designated individuals in case of an emergency or crisis situation.
Email Communications
NASPO may share email contact information with its partners to assist in providing email communications. Individuals may unsubscribe from receiving these communications from NASPO by clicking the “unsubscribe” link included at the bottom of the email, or by emailing NASPO as provided in the “Contact Information” section below. However, NASPO reserves the right to send individuals transactional emails such as customer service communications in connection with the products or services it provides, or individuals have purchased from NASPO. For security reasons, individuals should not send sensitive Personal Information, such as passwords, social security numbers, credit card information, or bank account information to NASPO via email.
Transfer of Assets
NASPO does not provide Personal Information to third parties, except as described herein. However, as NASPO continues to develop its business, NASPO trusted partners and/or contracted third parties as described above may change due to changes in contractual relationships or they may undergo a merger, reorganization, or similar corporate event which may necessitate transitioning of the Personal Information shared by NASPO to the new/changed organization.
Legal Necessity
Notwithstanding anything herein to the contrary, NASPO reserves the right to disclose any information about individuals if required to do so by law, with respect to copyright and other intellectual property infringement claims, or if NASPO believes that such action is necessary to: fulfill a government request; conform with the requirements of law or legal process, protect or defend NASPO’s legal rights or property, or in an emergency to protect the health and safety of NASPO Site users and/or the general public.
Children’s Privacy
NASPO Sites are neither directed to children nor intended to be used by children. Users under the age of majority in their place of residence may use the NASPO Sites only with the consent or under the supervision of their parent or legal guardian. If NASPO learns that it has received information directly from a child under 13 without verified parental consent, NASPO will use that information only to respond and will delete it.
Individual Consent
By visiting NASPO Sites, individuals are accepting the policies that are described in this Policy and consenting to the collection and use of information by NASPO. NASPO will post any changes to this Policy it may make from time to time on NASPO Sites. If individuals do not agree to this Policy, or to any changes NASPO may subsequently make, immediately stop accessing NASPO Sites.
Notification of Unauthorized Access
NASPO will promptly notify affected individuals in the event NASPO becomes aware of any unauthorized access to Personal Information that is in NASPO’s possession.
Contact Information
Questions or comments regarding this Policy should be submitted via email to .
Changes to Privacy Policy
This Policy may be amended from time to time. The effective date of this Policy may be found on the first page of the Policy. If individuals submitted Personal Information to NASPO prior to the above effective date, and desire to opt out of having that previously submitted Personal Information from being treated under the new Policy, please contact NASPO via email outlined above.
Rights Reserved
Nothing in this Policy is intended to limit any rights an individual may have under applicable privacy and data protection laws. NASPO will comply with all applicable data privacy laws.