Downing College Home
Privacy Policy
Downing College >  Privacy Policy

Privacy Policy for the Downing College Web Site

General

This policy explains what information we gather when you visit the Downing College web site, and explains how that information is used.

It is important for you to appreciate that the web site provides extensive links to other independent sites, both within the College and University and elsewhere. This policy applies only to direct accesses to the Downing web site - URLs starting http://www.dow.cam.ac.uk/. You will need to consult the appropriate information on other sites for information on their policies.

Any changes to this privacy policy will be posted on this page. It was last updated on 21 September 2004.

Data collected

In common with most web sites, this site automatically logs certain information about every request made of it (see below for more details). This information is used for system administration, for bug tracking, and for producing usage statistics. The logged information may be kept indefinitely.

Relevant subsets of this data may be passed to computer security teams as part of investigations of computer misuse involving this site or other computing equipment in the College or University. Data may be passed to the administrators of other computer systems to enable investigation of problems accessing this site or of system misconfigurations. Data may incidentally be included in information passed to contractors and computer maintenance organisations working for the University, in which case it will be covered by appropriate non-disclosure agreements. Otherwise the logged information is not passed to any third party except if required by law. Summary statistics are extracted from this data and some of these may be made publicly available, but those that are do not include information from which individuals could be identified.

[You should appreciate that a log is a record of what a server sees, not necessarily what was initially sent. If a request is sent via a proxy the log file will show the proxy's address. If someone has forged your address the log file will show your address]

A number of fill-in forms are provided on this site. The pages containing these forms include information on how data submited on them will be processed and used.

This site makes use of the Cambridge Web Authentication System (see http://raven.cam.ac.uk/) for authentication of access to confidential information. For this purpose a cookie is created. The cookie is set with no expiry date, which will prevent standards-compliant browsers from storing it on disk and will cause them to delete it at the end of the browser session. It is also set so that it will only be returned to the originating site. No other cookies are set and therefore users not entitled to access the confidential information will never have a cookie set by the site.

Logged data

The following data is automatically logged for each request:

Logging of additional data may be enabled temporarily from time to time for specific purposes. In addition, the computers on which the web site is hosted keep records of attempts (authorised and unauthorised) to use them for purposes other than access to the cache. This data typically includes the date and time of the attempt, the service to which access was attempted, the name or network address of the computer making the connection, and may include details of what was done or was attempted to be done.

Access to personal data

For the purpose of the UK Data Protection Act 1998, the 'Data Controller' for the processing of data collected by this site is the Master, Fellows and Scholars of Downing College in the University of Cambridge, and the point of contact for subject access requests is the College Data Protection Officer (Mr R.J. Stibbs, Downing College, Cambridge CB2 1DQ, tel. 01223 334600, fax 01223 334679 E-mail: data.protection@dow.cam.cam.ac.uk).

The College is also Data Controller in respect of any personal data served as content by this site.