---
title: "CXP Privacy Policy"
canonical: "https://resources.pathify.com/space/USA/55378934/CXP%20Privacy%20Policy"
format: markdown
---
> ℹ️ **Version: 2026-08-24 **
> ℹ️ 
> ℹ️ Current version can be found at: [http://pathify.com/cxp-privacy-policy](http://pathify.com/cxp-privacy-policy)

## In this article:

> Macro (toc)

---

# **1. Introduction **

Your educational institution (the “**University**,” “**we**,” “**us**,” or “**our**”) is committed to protecting the privacy and security of personal information collected from students, faculty, staff, prospective students, alumni, and other members of the University community. This Privacy Policy describes how the University collects, uses, discloses, and safeguards personal information through its Campus Experience Platform (the “**CXP**”), which is powered by Pathify, a third-party technology provider. 

# **2. About the CXP and Pathify **

The CXP is a digital engagement hub operated by the University and powered by Path Education Inc. (“**Pathify**”). Pathify provides the underlying cloud-based technology infrastructure that enables the University to centralize access to institutional systems, including the Student Information System (SIS), Learning Management System (LMS), campus communications, and other resources in a single, personalized interface accessible via web browser and native mobile application. 

Pathify acts as a service provider and data processor on behalf of the University. In that capacity, Pathify may access and process personal data only as necessary to provide and maintain the CXP’s services, in accordance with its contractual obligations to the University. Pathify has agreed to treat personal data as confidential and not to share it with third parties except as described in its agreement with the University. For more information about Pathify’s own data practices, you may review Pathify’s Privacy Policy at [https://pathify.com/privacy-policy/](https://pathify.com/privacy-policy/) . Institutional administrators or contract reviewers seeking additional detail about Pathify’s processing of data on behalf of institutional customers, including international transfer mechanisms, may also review Pathify’s Data Processing Addendum at [https://pathify.com/data-processing-addendum](https://pathify.com/data-processing-addendum). 

# **3. Categories of Personal Data We Collect **

The University collects and processes the following categories of personal data through the CXP: 

- **Identifiers and Contact Information. **This may include your name, university identification number, email address, phone number, mailing address, date of birth, and username or login credentials.

- **Educational Records. **This includes enrollment status, course registrations, grades, GPA, academic standing, degree progress, transcripts, class schedules, financial aid information, and other records maintained by the University in its capacity as an educational institution. Educational records are subject to the Family Educational Rights and Privacy Act (“FERPA”), as further described in Section 7. Information that qualifies as FERPA-protected education records is referred to in this Privacy Policy as “FERPA Records”.
- **Employment and Institutional Role Information. **For faculty and staff, this may include job title, department, office location, employment status, and role-based permissions within the CXP.
- **Device and Usage Information. **This includes IP address, browser type and version, operating system, device identifiers, pages visited within the CXP, clickstream data, session duration, referring URLs, and interactions with CXP features such as widgets, communities, and tasks.
- **Communications and User-Generated Content. **This includes messages sent through the CXP, posts in community forums or groups, content uploaded to the CXP, and interactions with the AI Agent (described in Section 6 below).
- **Location Data. **With your permission, the CXP may collect information regarding your approximate geographic location.
- **Cookies and Tracking Technologies. **The CXP uses cookies, web beacons, and similar technologies to collect information about your browsing activity, preferences, and interactions with the CXP. Additional detail regarding the categories of cookies used and how you may manage them is set forth in Section 8 below.

# **4. How We Use Your Data **

The University uses the personal data collected through the CXP for the following purposes: 

- **Providing and Personalizing CXP Services. **We use your data to operate the CXP, authenticate your identity, assign role-based permissions, display personalized dashboards, surface relevant tasks and deadlines, and deliver targeted communications, resources, and content based on your institutional role and interests.
- **Academic and Administrative Support. **We use educational records and related data to support academic advising, enrollment services, financial aid administration, degree audit, and other core institutional functions.
- **Communications and Community Engagement. **We use your data to facilitate communications between members of the University community, enable participation in campus groups and organizations, deliver announcements, and support student engagement activities.
- **CXP Improvement and Analytics. **We use aggregated and de-identified usage data to analyze CXP performance, improve user experience, identify trends in student engagement, and inform institutional decision-making.
- **Safety and Security. **We use your data to maintain the security and integrity of the CXP, detect and prevent fraud, enforce our terms of use, and comply with legal obligations.
- **Legal Compliance. **We process personal data as necessary to comply with applicable laws, regulations, and institutional policies.

# **5. Third-Party Services and Data Sharing **

The University may share personal data with the following categories of third parties: 

- **Pathify (Service Provider/Data Processor). **As described in Section 2, Pathify processes personal data on the University’s behalf to operate and maintain the CXP. Pathify does not sell personal data and is contractually prohibited from using personal data for any purpose other than providing services to the University.
- **Integrated Systems and Vendors. **The CXP integrates with various institutional systems. Data may be exchanged between the CXP and these systems to deliver a unified user experience. Each integrated system is subject to its own privacy policies and the University’s vendor management requirements.
- **AI and Analytics Services. **Pathify’s AI Agent leverages third party services for natural language processing. The AI Agent is powered by Google Gemini. Your query text and certain content from the institutional sources designated by the University may be transmitted to Google Gemini for processing. The Agent’s use of your own institutional records as context is off by default; the University enables it by choice and selects which specific data points are included (for example, your grade point average or student identifier), with each data point remaining off until the University turns it on. Where the University has enabled the Agent to use your own records to answer a question (for example, your grades, account balance, or enrollment status), those record values are transmitted to Google Gemini to generate the response. This Privacy Policy does not represent that your records are withheld from Google Gemini. Query text that you enter may itself contain personal information and is transmitted to Google Gemini for processing.
- **Other Third Parties. **The University may share personal data with third parties when required by law, court order, or governmental request; when necessary to protect the rights, safety, or property of the University or its community members; or with your consent.
- **No Sale of Personal Information. **The University does not sell or share personal information, as that term is defined under the CCPA/CPRA.

# **6. AI Agent **

Where your University has enabled it, the CXP includes an AI-powered Agent (“Agent”) that provides automated responses to user queries. The following disclosures apply to your interactions with the Agent: 

- **What the Agent Does. **The Agent is an artificial intelligence system. By interacting with the Agent, you acknowledge that you are communicating with AI. The Agent uses artificial intelligence and natural language processing to provide responses to questions about University services drawn from institutional content sources designated by the University, including integrated institutional systems such as the Student Information System (“SIS”) and Learning Management System (“LMS”), CXP content (such as FAQs, events, and pages), and whitelisted external websites designated by the University. Responses are generated algorithmically based on the Agent’s underlying language model and the source content. Responses should not be relied upon as authoritative for any Consequential Decision (a decision affecting a person’s access to, eligibility for, or compensation in areas such as education, employment, housing, lending, insurance, health care, or essential government services) or for any matter where precise accuracy is required; you should verify important information with the appropriate University office.
- Data the Agent Collects and Processes. When you interact with the Agent: (i) where you are signed in, your authenticated user identity and institutional role are used by the Agent to retrieve information from integrated institutional systems; (ii) the text of your query is transmitted to Google Gemini, Pathify’s AI service provider, for generation of a response; and (iii) information retrieved from integrated institutional systems (such as your course schedule, account balance, or GPA) is used by the Agent to inform its response to you. The Agent’s use of your own records as context is off by default and is enabled only if the University chooses to turn it on, selecting which specific data points are included (for example, your grade point average or student identifier), with each data point remaining off until the University turns it on. Where the University has enabled the Agent to use your own records to answer a question, those record values are transmitted to Google Gemini to generate the response; this Privacy Policy does not represent that your records are withheld from Google Gemini. Which data points the University has enabled may change over time. If the Agent’s data flows materially change, this Privacy Policy will be updated. Your query text, which you control, may itself contain personal information that you choose to include; such query text is transmitted to Google Gemini for processing.
- How Agent Interactions Are Stored and Used. Conversation transcripts are retained by Pathify for the duration of the applicable customer contract, subject to backup, legal hold and security archive requirements, and are accessible by University administrators and Pathify staff. Internal logs, which may contain prompts in error messages, are retained by Pathify for thirty days. Pathify also records actions taken in the CXP, including changes to configuration settings and user actions such as page visits and interactions, without the content of those interactions. These records support the analytics available to University administrators. A record of a configuration change is retained for up to ten years from the date it is recorded. All other activity records are deleted within ninety days following the end of the University’s contract with Pathify. Aggregate and anonymized Agent usage data, such as the number of conversations, common keywords, and active usage metrics, may be collected and analyzed by University administrators to improve institutional services and support. Safety and topic detection. Where the University enables it, the Agent may screen conversation content to detect potential safety concerns or University-designated topics, and may route the conversation, or a notification, to a named University staff member or office. Escalations are directed to University staff for review. No adverse or consequential decision about you is made automatically. This detection is automated and fallible, is designed to use the same data-flow envelope otherwise applicable to the active AI Agent function and configuration, and does not replace the University’s own safety processes. It is an aid, not a safeguard. It is not continuous, it will not detect every concern, and you should never rely on it in an emergency. If you are in crisis, contact the University’s support services, emergency personnel or a qualified professional, and in a life-threatening emergency call 911.
- Third-Party AI Infrastructure. The Agent is powered by Google Gemini, a generative AI service operated by Google. Your query text and certain content from the institutional sources designated by the University may be transmitted to Google Gemini for processing. Google’s processing is governed by Google’s applicable data processing terms, which include contractual provisions designed to ensure that the disclosure of personal information does not constitute a “sale” under the CCPA/CPRA. Pathify accesses Google Gemini only through the enterprise paid services and not through any consumer or no-cost service, and maintains those arrangements such that Google does not use your query text or institution-sourced records to train, develop, or improve Google’s foundation models. The Agent’s use of your own institutional records as context is off by default; the University enables it by choice and selects which specific data points are included (for example, your grade point average or student identifier), with each data point remaining off until the University turns it on. Where the University has enabled the Agent to use your own records to answer a question, those record values are transmitted to Google Gemini to generate the response. Query text that you enter may itself contain personal information and is transmitted to Google Gemini for processing. When record context is enabled, those records are processed by Google Gemini as part of generating your response; they are not abstracted away or withheld from that processing.
- **Limitations. **The Agent is an automated tool and may not always provide perfectly accurate or complete information. Responses sourced from institutional pages, FAQs, or external websites are labeled accordingly and may be subject to inaccuracy. Users should not rely on the Agent as a substitute for direct consultation with University offices on critical matters. When configured by the University, the Agent may perform web searches of publicly available content. The Agent retrieves information from sources authorized by the University, which may include if selected by the University, from public web pages.

THE AGENT DOES NOT PROVIDE, AND NO OUTPUT SHALL BE CONSTRUED AS, PROFESSIONAL ADVICE OF ANY KIND, INCLUDING, WITHOUT LIMITATION, LEGAL, FINANCIAL, MEDICAL, ACCOUNTING, TAX, OR OTHER PROFESSIONAL ADVICE. YOU SHOULD CONSULT WITH QUALIFIED PROFESSIONALS REGARDING ANY MATTERS REQUIRING PROFESSIONAL EXPERTISE OR JUDGMENT. ANY RELIANCE YOU PLACE ON THE OUTPUTS IS STRICTLY AT YOUR OWN RISK. 

THE AGENT IS NOT DESIGNED OR INTENDED TO PROVIDE EMOTIONAL SUPPORT, CRISIS INTERVENTION, MENTAL HEALTH COUNSELING, OR ANY FORM OF PSYCHOLOGICAL ASSISTANCE. YOU SHOULD NOT USE THE AGENT AS A SUBSTITUTE FOR HUMAN INTERACTION, PROFESSIONAL MENTAL HEALTH SERVICES, OR SUPPORT FROM TRAINED COUNSELORS OR THERAPISTS. IF YOU ARE EXPERIENCING A MENTAL HEALTH CRISIS, EMOTIONAL DISTRESS, OR ANY OTHER EMERGENCY SITUATION, PLEASE CONTACT YOUR INSTITUTION’S APPROPRIATE SUPPORT SERVICES, EMERGENCY PERSONNEL, OR A QUALIFIED MENTAL HEALTH PROFESSIONAL IMMEDIATELY. IN THE EVENT OF A LIFE-THREATENING EMERGENCY, PLEASE CALL 911 OR YOUR LOCAL EMERGENCY SERVICES. 

The Pathify Terms of Use that you accept when you first access the CXP, available at [https://pathify.com/terms-of-use](https://pathify.com/terms-of-use) , prohibit using the Agent to generate discriminatory or harmful content, and prohibit the use of Agent-generated content to make, or materially influence, consequential decisions affecting a consumer’s access to, eligibility for, or compensation in education, employment, financial or lending services, insurance, health care, housing, or essential government services, as specified in applicable law, including SB 26-189. Where the University enables the Agent’s safety and topic detection described in Section 6, that detection escalates matters to University staff and does not make decisions. Whether a function is subject to statutory automated decision-making rights and obligations is determined by the applicable statutory definition under applicable law. 

# **7. FERPA Rights **

The Family Educational Rights and Privacy Act (“**FERPA**”), 20 U.S.C. § 1232g, and its implementing regulations at 34 CFR Part 99, protect the privacy of student education records. Education records within the meaning of FERPA are referred to in this Privacy Policy as “FERPA Records”. Where this Privacy Policy refers to educational records or student data, the subset that constitutes FERPA Records is handled under the FERPA-specific rules described in the University’s contractual arrangements with Pathify. Students have the following rights under FERPA with respect to their education records: 

- **Right to Inspect and Review. **You have the right to inspect and review your education records within 45 days after the day the University receives a request for access. Requests should be made in writing to the University office that maintains the record.
- **Right to Request Amendment. **You have the right to request the amendment of any education record you believe is inaccurate, misleading, or otherwise in violation of your privacy rights under FERPA. Requests should be made in writing and should clearly identify the part of the record you want changed and specify why it is inaccurate or misleading.
- **Right to Consent to Disclosure. **You have the right to provide written consent before the University discloses personally identifiable information from your education records, except to the extent that FERPA and 34 CFR § 99.31 authorize disclosure without consent.
- **Right to File a Complaint. **You have the right to file a complaint with the U.S. Department of Education concerning alleged failures by the University to comply with the requirements of FERPA. The office that administers FERPA is the Student Privacy Policy Office, U.S. Department of Education, 400 Maryland Avenue SW, Washington, DC 20202.

School Official Exception and the CXP. FERPA permits the University to disclose personally identifiable information from education records without prior written consent to school officials with legitimate educational interests, including contractors and other parties to whom the University has outsourced institutional services or functions, subject to the requirements of 34 CFR § 99.31(a)(1)(i)(B). Third-party service providers that meet the criteria set forth in the University’s FERPA annual notification may be designated as school officials under this exception. Where so designated and where the required contractual and policy conditions are satisfied, such service providers may operate under the school official exception, remain under the direct control of the University with respect to the use and maintenance of education records, are subject to the use and redisclosure restrictions of 34 CFR § 99.33(a), and are contractually required to meet the criteria for legitimate educational interest as set forth in the University’s FERPA annual notification and in their agreements with the University. 

For the full text of the University’s FERPA annual notification, please contact the University. 

# **8. Cookies and Tracking Technologies **

The CXP uses cookies, web beacons, pixel tags, and similar tracking technologies to distinguish you from other users, remember your preferences, analyze CXP usage, and improve the service. The specific categories of tracking technologies used, and their purposes, are as follows: 

**8.1 Strictly Necessary Cookies **

These cookies are essential for the operation of the CXP and enable core functionality such as security, authentication, session management, and load balancing. You cannot opt out of strictly necessary cookies because the CXP cannot function without them. 

**8.2 Functionality Cookies **

These cookies allow the CXP to remember choices you make, such as language preferences, login credentials, and interface customizations, to provide a more personalized experience. 

**8.3 Analytics and Performance Cookies **

These cookies collect information about how users interact with the CXP, such as pages visited, features used, and session duration. The information collected is used to improve the functionality and user experience of the CXP and may be provided by third-party analytics services acting as service providers to the University. 

**8.4 Cookies Used by Our Service Providers **

Our service providers, including Pathify and its sub-processors, may use their own cookies to provide functionality to the CXP. These service providers are contractually limited to using such cookies only for purposes of providing services to the University. 

**8.5 Managing Cookies **

You may control or delete cookies through your browser settings. Most browsers allow you to refuse cookies, delete existing cookies, or configure notifications when cookies are being sent. Please note that disabling strictly necessary cookies may affect the functionality of the CXP. For more information about managing cookies in specific browsers, please consult your browser’s documentation. See also Section 10 regarding our handling of Do Not Track and Global Privacy Control signals. 

# **9. US State Privacy Notice **

Depending on your state of residency, you may have certain privacy rights, subject to certain exceptions, as follows: 

- *Right to Access. *You may have the right to request that we disclose what personal information we collect, use, disclose, and sell about you.
- *Right to Correction. *You may have the right to request correction of personal information that we maintain about you if you find that the personal information is inaccurate.
- *Right to Deletion. *You may have the right to request that we delete personal information that we have collected from you.
- *Data Portability. *You may have the right to request a copy of your personal information in a portable and, to the extent technically feasible, readily usable format.
- *Right to Withdraw Consent. *You may have the right to withdraw your consent to the processing of your personal information.
- *Right to Limit Use and Disclosure of Sensitive Personal Information. *You may have the right to limit the processing of your sensitive personal information.
- *Right to Opt-Out. *You may have the right to opt-out of certain uses of your personal information such as for (i) targeted advertising, (ii) “sale” or “sharing” for cross-context behavioral advertising, or (iii) profiling or automated decision-making activities that result in a legal or similarly significant effect on you. Except as described below, the University does not engage in these activities. If the University enables an Agent function that is used to make or materially influence a decision producing a legal or similarly significant effect on you, it will update the disclosure below accordingly.
- *Right to List of Third Parties. *You may have the right to obtain a list of third parties to which we have disclosed personal information.
- *Right to Appeal. *If we decline to take action regarding your request, we will inform you of our decision and reasoning behind it. If you wish to appeal our decision, please contact us using the contact details the University publishes for privacy enquiries. Within sixty (60) days of receipt of an appeal, we will inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decisions. If your appeal is denied, you may contact the Attorney General to submit a complaint.

No Agent function is used to make or materially influence a consequential decision unless the University enables one, and no such function is enabled by default. Where the University enables such a function, it may involve profiling that furthers automated decisions, and the University will provide the applicable notice and rights. Where a function meets the statutory definition of automated decision-making technology used to materially influence a consequential decision under applicable law, the University will honor the applicable statutory notice, opt-out, access, correction, and meaningful-human-review rights. 

# **9A. California Supplemental Notice **

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”). The University provides these rights whether or not it is an entity to which the CCPA applies. 

**Categories of Personal Information Collected. **In the twelve (12) months preceding the Effective Date of this Privacy Policy, we have collected the following categories of personal information, as defined by the CCPA/CPRA, through the CXP: 

- **Category A (Identifiers). **Examples: name, University identification number, postal address, IP address, email address, account name. *Collected: Yes. *
- **Category B (Customer Records, Cal. Civ. Code § 1798.80(e)). **Examples: enrollment information, academic records, employment-related information. *Collected: Yes. *
- **Category C (Protected Classifications). **Examples: age, national origin, disability status, veteran status, where voluntarily provided or required by law. *Collected: Varies by institutional workflow. *
- **Category D (Commercial Information). **Examples: records of products or services purchased. *Collected: Limited, to the extent financial aid or university billing records are accessed through the CXP. *
- **Category E (Biometric Information). **Examples: fingerprints, facial recognition data, voiceprints. *Collected: No. Under the AI Agent’s current configuration, voice input is transcribed to text and the voice signal itself is not analyzed, so no voiceprint or other biometric identifier is collected. If a live-voice capability that processes the voice signal is enabled in the future, this disclosure will be updated. *
- **Category F (Internet or Electronic Network Activity). **Examples: browsing history within the CXP, interactions with CXP features, search history within the CXP. *Collected: Yes. *
- **Category G (Geolocation Data). **Examples: approximate location derived from IP address or device settings. *Collected: Yes, with user permission where applicable. *
- **Category H (Sensory Data). **Examples: audio recordings, video recordings. *Collected: Yes (transiently processed for transcription; audio not retained). Under the AI Agent’s current configuration, voice input is transcribed to text and audio recordings are not intentionally retained in the AI Agent workflow. If a live-voice capability that processes or retains the audio signal is enabled in the future, this disclosure will be updated. *
- **Category I (Professional or Employment Information). **Examples: job title, department, employment status. *Collected: Yes, for faculty and staff users. *
- **Category J (Education Information, 20 U.S.C. § 1232g; 34 CFR Part 99). **Examples: grades, transcripts, class schedules, degree progress. *Collected: Yes. Education records are also subject to FERPA and are referred to as FERPA Records, as further described in Section 7. *
- **Category K (Inferences Drawn from Other Personal Information). **Examples: inferences used to generate personalized dashboards and role-based content. *Collected: Yes. *

**Sale and Sharing of Personal Information. **The University does not sell or share personal information, as those terms are defined under the CCPA/CPRA. The University does not knowingly sell or share the personal information of consumers under the age of 16. 

**Sensitive Personal Information. **The University does not use or disclose sensitive personal information for purposes other than those permitted under the CCPA/CPRA. To the extent the University collects sensitive personal information through the CXP (which may include account log-in credentials in combination with any required password or security code, or precise geolocation), it identifies those categories here and provides the right to limit their use and disclosure; the University confirms the categories of sensitive personal information it collects through the CXP. 

**California Shine the Light (Cal. Civ. Code § 1798.83). **California Civil Code Section 1798.83 permits California residents to request a notice disclosing the categories of personal information that we have disclosed to third parties for their direct marketing purposes during the preceding calendar year. The University does not disclose personal information to third parties for their direct marketing purposes. California residents may submit requests for information under this law by contacting the University. 

**California Minor Users (Cal. Bus. & Prof. Code § 22581). **California Business and Professions Code Section 22581 permits California residents under the age of 18 who are registered users of online sites, services, or applications to request and obtain removal of content or information they have publicly posted. To request removal, please contact the University and include the email address associated with your CXP account. Please note that such a request does not guarantee complete or comprehensive removal of the content, and applicable law may not permit or require removal in certain circumstances. 

# **9B. Colorado Supplemental Notice **

If you are a Colorado resident, you have the following additional rights under the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.) and Colorado Senate Bill 26-189 (the automated decision-making technology law that repealed and reenacted the former Colorado Artificial Intelligence Act, codified at C.R.S. § 6-1-1701 et seq., effective January 1, 2027): 

- **Access, Correction, and Deletion. **You have the right to access, correct, and delete your personal data.
- **Opt-Out Rights. **You have the right to opt out of the processing of your personal data for purposes of targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects concerning you. To exercise an opt-out right, including any opt-out of profiling, contact the University using the method described in its own privacy notice. Where the University enables an Agent function that is used to make or materially influence a consequential decision, the University will describe, in plain language, the logic of that processing, the decisions it informs, and the categories of personal data used, and will provide the profiling opt-out right available under the Colorado Privacy Act. Separately, where automated decision-making technology is used to materially influence a consequential decision, Colorado Senate Bill 26-189 provides rights of access and correction, meaningful human review, and reconsideration where the decision results in an adverse outcome.
- **AI Interaction Disclosure. **The AI Agent is an artificial intelligence system. When you interact with the Agent, you are interacting with AI. This disclosure is provided as a baseline transparency practice and, where applicable, to support compliance with C.R.S. § 6-1-1704.
- **Rights Regarding Consequential Decisions. **In addition to the general Colorado privacy rights described above, Colorado Senate Bill 26-189 provides rights that apply specifically where automated decision-making technology, including the AI Agent, is used to materially influence a consequential decision about you. If that occurs, you may have the right to access the personal data used and to correct personal data that is factually incorrect and, to the extent commercially reasonable, to request meaningful human review and, where the decision results in an adverse outcome for you, to request reconsideration of that decision. The University’s current design intent is that the Agent’s core question-and-answer function not be used to make or materially influence consequential decisions; The rights described in this paragraph apply to any Agent function that is used to make or materially influence a consequential decision. These rights are provided in accordance with C.R.S. § 6-1-1705.
- **Acceptable Use of the AI Agent. The Terms of Use prohibit use of the Agent **to generate content that is discriminatory or harmful on the basis of protected characteristics including age, color, disability, ethnicity, genetic information, national origin, race, religion, reproductive health, sex, veteran status, or any other classification protected under applicable law.
- **AI Agent Scope. **The AI Agent’s core question-and-answer function is designed to provide general information, referrals, and answers to questions. That function is not designed or intended to make, or materially influence, consequential decisions affecting a consumer’s access to, eligibility for, or compensation in education, employment, financial or lending services, insurance, health care, housing, or essential government services. Where the University enables the Agent’s safety and topic detection described in Section 6, that detection escalates matters to University staff and does not make decisions. Whether a function is subject to these statutory rights is determined by the applicable statutory definition under applicable law.

To exercise any of the rights described above, please contact the University.

# **10. Do Not Track and Global Privacy Control Signals **

**Do Not Track (“DNT”). **Some web browsers include a “Do Not Track” feature that signals to websites that you do not want your online activities tracked. Because there is no common industry standard for how online services should respond to DNT signals, the CXP does not currently respond to DNT signals. 

**Global Privacy Control (“GPC”). **The CXP honors the Global Privacy Control browser signal where required by applicable law. If you access the CXP with the GPC signal enabled, we will treat the signal as a valid request to opt out of the “sale” or “sharing” of your personal information and of targeted advertising, to the extent such activities apply to your personal information. A GPC signal is typically specific to the browser or device from which it is submitted and may need to be enabled separately on each browser or device you use. More information about the Global Privacy Control is available at [https://globalprivacycontrol.org/](https://globalprivacycontrol.org/) . 

# **11. Your Rights Under the GDPR **

If you are located in the European Economic Area (“EEA”), the General Data Protection Regulation (“GDPR”) provides you with the following rights. Equivalent rights are available under the United Kingdom GDPR and the Data Protection Act 2018, and under the Swiss Federal Act on Data Protection. 

- **Right of Access. **You have the right to request access to the personal data we hold about you, along with information about how we process it.
- **Right to Rectification. **You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
- **Right to Erasure (Right to Be Forgotten). **You have the right to request that we delete personal data about you in certain circumstances.
- **Right to Restrict Processing. **You have the right to request that we restrict our processing of your personal data in certain circumstances.
- **Right to Data Portability. **You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.
- **Right to Object. **You have the right to object to our processing of your personal data in certain circumstances, including where we rely on legitimate interests as our legal basis.
- **Right to Withdraw Consent. **Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time.
- **Right to Lodge a Complaint. **You have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal data violates the GDPR.

The legal bases on which the University processes personal data include: your consent (where required); the performance of a contract to which you are a party; compliance with a legal obligation; protection of your vital interests or those of another person; performance of a task carried out in the public interest or in the exercise of official authority vested in the University; and the legitimate interests of the University or a third party. 

To the extent personal data is transferred outside the EEA, the United Kingdom, or Switzerland, such transfers are made in reliance on appropriate safeguards, including Standard Contractual Clauses adopted by the European Commission, as further described in Pathify’s Data Processing Addendum. 

To exercise any of the rights described above, please contact the University. 

# **11A. Australia Supplemental Notice **

If you are located in Australia, the University provides you with the following rights, whether or not it is an entity to which that law applies, under the Privacy Act 1988 (Cth) (the “Privacy Act”), including the Australian Privacy Principles (the “APPs”) and the Notifiable Data Breaches scheme (the “NDB Scheme”) in Part IIIC of the Privacy Act. References in this Section 11A to “personal information” have the meaning given in the Privacy Act and include personal data otherwise referenced in this Privacy Policy. 

- **Right of Access (APP 12). **You have the right to request access to the personal information we hold about you, subject to the exceptions in APP 12 and other applicable law.
- **Right to Correction (APP 13). **You have the right to request that we correct personal information we hold about you that is inaccurate, out of date, incomplete, irrelevant, or misleading, in accordance with APP 13.
- **Notifiable Data Breach Notification. **If we become aware of an Eligible Data Breach (as defined in the NDB Scheme) involving your personal information, we will provide notification consistent with the NDB Scheme and applicable law, working with the University where the breach involves personal information handled on the University’s behalf.
- **Overseas Disclosures. **Personal information may be disclosed to recipients located outside Australia, including in connection with subprocessors that support the CXP. The University and Pathify take reasonable steps to ensure that such recipients are subject to contractual obligations that together provide a substantially similar level of protection to the APPs, as further described in Pathify’s Data Processing Addendum.
- **Complaint to the OAIC. **If you believe that we have handled your personal information in a way that breaches the APPs, you may lodge a complaint with the Office of the Australian Information Commissioner (the “OAIC”) at [http://www.oaic.gov.au](http://www.oaic.gov.au).

To exercise any of the rights described above, please contact the University.

# **11B. New Zealand Supplemental Notice **

If you are located in New Zealand, the University provides you with the following rights, whether or not it is an entity to which that law applies, under the Privacy Act 2020 (NZ) (the “NZ Privacy Act”), including the Information Privacy Principles (the “IPPs”). References in this Section 11B to “personal information” have the meaning given in the NZ Privacy Act and include personal data otherwise referenced in this Privacy Policy. 

- **Right of Access (IPP 6). **You have the right to confirm whether we hold personal information about you and to access that information, subject to the grounds for refusal in the NZ Privacy Act and other applicable law.
- **Right to Correction (IPP 7). **You have the right to request correction of personal information we hold about you, and to request a statement of correction be attached if we decline.
- **Information About Indirect Collection (IPP 3A). **Where personal information about you is collected from a source other than you, you have the right to be informed of that collection consistent with IPP 3A as it takes effect on 1 May 2026.
- **Notification of Privacy Breach. **If we become aware of a privacy breach involving your personal information that is likely to cause serious harm under the NZ Privacy Act, we will provide notification consistent with the NZ Privacy Act, working with the University where the breach involves personal information handled on the University’s behalf.
- **Cross-Border Disclosures (IPP 12). **Personal information may be disclosed to recipients located outside New Zealand, including in connection with subprocessors that support the CXP. Pathify takes reasonable steps to ensure that such recipients are subject to contractual obligations that together provide protections comparable to those required by IPP 12, as further described in Pathify’s Data Processing Addendum.
- **Complaint to the OPC. **If you believe that we have interfered with your privacy under the NZ Privacy Act, you may make a complaint to the New Zealand Office of the Privacy Commissioner (the “OPC”) at [http://www.privacy.org.nz](http://www.privacy.org.nz) .

To exercise any of the rights described above, please contact the University. **12. Data Retention **

The University retains personal data for as long as necessary to fulfill the purposes for which it was collected, including to provide the CXP, comply with legal obligations, resolve disputes, and enforce our agreements. Retention periods vary based on the type of data, the purpose of collection, and applicable legal and regulatory requirements. Education records are retained in accordance with the University’s records retention schedule and applicable law. These criteria apply to each category of personal information identified in Section 9A; the University may specify category-specific retention periods in its own records-retention schedule. 

# **13. Data Security **

The University implements technical, administrative, and physical safeguards designed to protect personal data from unauthorized access, use, disclosure, alteration, or destruction. These safeguards include access controls, encryption in transit and at rest where applicable, secure authentication, regular security assessments, and contractual requirements imposed on Pathify and other service providers. 

While the University takes reasonable steps to safeguard your personal data, no method of electronic transmission or storage is completely secure. If you have reason to believe that your account or personal data has been compromised, please contact the University immediately. Additional information regarding our response to security incidents is set forth in Section 14. 

# **14. Breach Notification **

In the event of a security incident that results in the unauthorized access to, acquisition of, use of, or disclosure of personal data maintained through the CXP, the University will provide notice to affected individuals and to applicable regulatory authorities in accordance with applicable law, including state breach notification statutes, FERPA, the Health Insurance Portability and Accountability Act (“HIPAA”) to the extent applicable, the CCPA/CPRA, the GDPR, and other applicable data protection laws. Notice will be provided without unreasonable delay following the University’s determination that a reportable security incident has occurred, and in any event within the timeframe required by applicable law. 

The University’s incident response procedures include: (i) investigation and containment of the incident; (ii) assessment of the scope of personal data affected; (iii) coordination with Pathify and other service providers, which are contractually required to notify the University of security incidents affecting personal data processed on the University’s behalf; (iv) notification to affected individuals, regulators, and other parties entitled to notice; and (v) remediation to prevent recurrence. 

If you have reason to believe that your personal data maintained through the CXP has been compromised, please contact the University immediately. 

# **15. Accessibility **

The University is committed to making the CXP and this Privacy Policy accessible to individuals with disabilities in accordance with applicable law, including the Americans with Disabilities Act (“**ADA**”), Section 504 of the Rehabilitation Act, and, for public institutions, Title II of the ADA, where applicable. The University’s accessibility standard for digital resources is substantial conformance with the Web Content Accessibility Guidelines (WCAG) 2.2 Level AA or such successor standard as the University may adopt. Pathify conforms the CXP to that standard, provides a current accessibility conformance report on request, and remediates material accessibility defects on a reasonable timeline. 

If you experience difficulty accessing any portion of the CXP or this Privacy Policy, or if you require this Privacy Policy or any related privacy disclosure in an alternative accessible format (such as large print, Braille, or an accessible electronic format), please contact the University. The University will work to provide the requested information in a timely and accessible manner and to address any accessibility barriers you have encountered. 

# **16. Links to Other Websites **

The CXP may contain links to websites, services, or resources that are not operated or controlled by the University or Pathify. These third-party sites have their own privacy policies, and neither the University nor Pathify is responsible for their content, privacy practices, or security. We encourage you to review the privacy policies of any third-party sites you access through links in the CXP. 

# **17. Children’s Privacy **

The CXP is not intended for use by children under the age of thirteen (13). Where the University makes the Agent available on a public page that does not require sign-in, the University determines who may use it and remains responsible for any consents required for that use. The University does not knowingly collect personal information from children under 13 through the CXP. If you believe that a child under 13 has provided personal information through the CXP, please contact us immediately so that we can take appropriate steps to delete such information. 

# **18. Changes to This Privacy Policy **

The University may update this Privacy Policy from time to time to reflect changes in our practices, applicable laws, or CXP functionality. When we make material changes, we will update the “Effective Date” at the top of this Privacy Policy and provide notice through the CXP or other appropriate channels. Where consent is required by applicable law for a new use of your information, the University will obtain that consent separately. 

---