Effective from 20 July 2021 until the new policy is announced.
This Privacy Policy is here to help you know the types of information we collect. The reason why the Department of Planning (Division), University Office (Office), Chiang Mai University (University) collect, including how you will access and update such information
The Department of Planning has created several services both online and offline to provide services for the admission system and the education registration system, consisting of student profile registration work. course administration, registration, educational processing Graduation examination and certification For students, teachers, staff of the university and guests The bureau’s services are available on the following platforms:
The website (Website) of the division under the Internet domain. https://planning.oou.cmu.ac.th
Contact through the staff of the department or the university. both directly and through others assigned by the Division or University
which this privacy policy Covering all platforms and covers service users, including students, teachers, staff of Chiang Mai University and guests that provides and uses information maintained by the Division and relevant departments within the university that oversees the information for the Division
Information that the Division collects
Division of data collection related to Planning and evaluation work, budget work, strategic information work, administrative work by collecting data. Anonymous and anonymous data collection using a CMU IT Account associated with the browser, application or device you are using. This allows the Division to offer services and information that is consistent with its users.
for personally identifiable information Or can be used to identify yourself, the office will treat it as personal information. in line with the Personal Data Protection Act B.E. 2562
Information you create or provide to the Bureau
when accessing the service of the Division You may be required to provide personal data such as email addresses, addresses, etc. for the Division to process. and can provide services to you You may be required to log in using CMU IT Account. The Division will also collect information that you create, upload or receive from others when using the Division’s services. This information includes things such as personal history, registration, etc.
Information we collect when you use our services
The Division collects information about the Division’s services. so that the division can serve and improve the service even better The information the stack collects in the service machine log includes a unique identifier. Browser type and settings Device type and settings operating system and network information The Division collects information about your app, browser and device interactions with our services. This includes the IP address, crash reports, system activity, as well as the date, time and referrer URL of your request.
Information for maintenance and improvement of the Division’s services
We also use your information to ensure that our services work as expected, such as complaints and suggestions. and use your information to improve our products, such as studying the pages of websites that have the most problems with visitors to improve the quality of service even further
Information to develop new services
The Division uses information gathered from the Services to help the Division develop new services, such as website accessibility studies. so that we can improve the website structure to make it easier to use
data to measure performance
The Division uses the data for analysis and measurement to understand how people use its services. For example, the Division analyzes information about your visits to its website to do things like optimize product designs. The stack uses several tools to do this, including Google Analytics, for example.
Information to communicate with you
The Division uses information it collects, such as university email addresses. to interact with you directly
Information to protect the stack, users and the public.
The Division uses information to help improve the security and reliability of its services. This includes detecting, preventing, and responding to misconduct, abuse, security risks. and technical problems that could harm the team, users or the public.
We will ask for your consent before using the information for any other purpose not specified in this Privacy Policy.
Managing, Monitoring and Updating Your Information
when signing in You can check and update information by going to the services you use, for example if you are a worker. You can access the meeting room reservation system.
deletion of your information
The Division reserves the right to maintain your personal information in the Division’s systems or in the university departments. For work and processing in accordance with the missions of the Division and the University and to comply with the relevant laws
Forwarding your information
The Division will not pass on your personal information to companies, organizations or individuals outside the university. except in the following cases
The Division will only transmit information with your consent.
The Division will forward personal information outside the university. When the department receives your consent, such as forwarding information to outside companies that provide services to the university, etc.
For processing or providing services from outside parties
The Division delivers personal information to other departments in the University or other companies and organizations that have been assigned by the Division or the University in writing to process the data. or provide services to students, professors or university staff using personal information to help the University fulfill its mission. By proceeding in accordance with the methods and in accordance with the Division’s privacy policy including appropriate confidentiality and security measures.
for legal reasons
The Division will transfer personal information off-campus if we believe in good faith that access, use, retention or disclosure is reasonably necessary. to comply with applicable laws regulations legal process or requesting information from the government This includes preventing harm to the rights, property or safety of the University, its users or the public as required or permitted by law.
Keeping your information safe
The Division does its best to protect your information. from access Unauthorized alteration, disclosure or destruction of information that the Bureau maintains. By doing at least the following:
The Division uses encryption to keep your information private during transmission.
Many security services and authentication using CMU IT Account of the Information Technology Service Office Chiang Mai University To help protect your account
Data Collection Inspection Division Storage and processing practices including physical safety measures to prevent unauthorized access to the system
The Division has limited access to personal information for its employees, employees and representatives. that need that information for data processing Those with this access must comply with strict contractual confidentiality requirements. and may be penalized or terminated for failure to comply with such requirements.
data storage
The stack stores all the data at the stack’s servers on campus. And there are some backup systems in the service machines outside the university. by collecting data in the university There is a standard external data protection system. and in accordance with the requirements of the law The storage of data in the device outside the university. It will be stored in the service provider of a standard service provider. and the data is encrypted according to industry standards. to protect access to content within the data Storing data on machines outside the university Comply with Disaster recovery plan best practices
When this policy comes into effect
This Privacy Policy applies to all services that the Bureau and its entities are assigned to. including website mobile application and services that provide services on third-party websites, such as those on the Information Technology Service Chiang Mai University This Privacy Policy does not apply to services that have separate privacy policies that do not comply with this Privacy Policy.
Changes to this Policy
The Division changes this Privacy Policy from time to time. The Division will not reduce your rights under this Privacy Policy without your express consent. The stack always indicates the date when the last change was published and we have other documentary records. for you to read as well If there are significant changes Division will announce more clearly. (For certain services, this may include email notifications of privacy policy changes.)
Other issues related to your privacy
publicly accessible sources
For example, we may collect information that is publicly available or from other public sources. to improve our service
Your information that the Bureau uses to provide the Division’s services
Here are some examples of how the Division uses your information to provide the Bureau’s services.
The division uses IP addresses that scope to provide certain services, such as those that require services only for devices within the university’s network.
The Division uses a unique identifier stored in a cookie on the device to help verify that you are the one who should have access to the Division’s services. through the university’s CMU IT Account authentication system
Storing information to keep our services working as intended
For example, our system checks regularly to check for problems. And if the pile finds something wrong in some features Reviewing the activity data gathered before problems occur helps piles fix things faster.
Collecting information for improvement
For example, we use cookies to analyze how people interact with the Division’s services. And analytics can help piles build better services. For example, analytics can help piles know that people are taking too long to do something. or unable to perform certain steps The Division will then redesign or improve the existing service.
Data retention for security and reliability
Some examples of how the Division uses your information to help keep its services safe and reliable include the automatic collection and analysis of IP address information and cookies to prevent abuse. This violation can take many forms, such as sending spam to users. or blocking access by running a distributed denial of service (DDoS) attack.
violation detection
When the stack detects spam, malware, and illegal content. and other forms of infringement in the system which violates the Division’s policy The Division may disable access to your Division’s systems or take other appropriate action. In some cases, the Division may also report violations to the appropriate authorities.
legal process or requesting information from the government
Like other government regulators, universities often receive requests from governments and courts to disclose user data. Complying with these legal requests is based on respect for the privacy and security of the information you hold with the department and the university. The university’s legal team reviews every request. regardless of the type of request To ensure that the request is in accordance with the law and this Privacy Policy.
more explanation
Cookies and Similar Technologies
Cookies are small files containing strings of characters that are sent to your computer when you visit various websites. when going back to the same website again Cookies allow the website to remember your browser. Cookies may store user preferences and other information. You can configure your browser to refuse all cookies or to notify when a cookie is sent. However, some website services may malfunction without cookies.
equipment
A device is a computer that can access the stack’s services, such as desktop computers, tablets, smart speakers, and smartphones.
Non-personally identifiable information
This is recorded information about a user that no longer identifies or references the individual user’s identity.
IP address
Every device that connects to the Internet has a unique number, known as an Internet Protocol (IP) address. These numbers are usually assigned by geographic area, so IP addresses can often be used to determine the origin of the device when the device is located. connect to the internet
personal information
This is the information you provide to the Division and that identifies you, such as your name, email address or other information. that the office can link to such information, such as information that we have linked to your CMU IT Account
CMU IT Account
It is an account on a computer system issued by the Information Technology Service Office. Chiang Mai University to staff and students of the University by being a specific personal account and can be used to refer to an individual
Service machine record
Our service provider automatically logs the user’s web page requests while visiting the website. in general Server logs include your website requests, Internet Protocol address, browser type. browser language date and time of your request as well as one or more cookies that can identify your browser.
unique identifier
A unique identifier is a string of characters used to uniquely identify a browser, application, or device. Ability to reset identifiers by user and access patterns
Unique identifiers may be used for purposes such as security and fraud detection. Remembering preferences, such as the unique identifiers that cookies store, will only allow websites to display content in your browser that is relevant to you. You can configure your browser to reject all cookies or to notify when a cookie is sent. But you may not be able to access some of the Division’s services.
version update information
July 4, 2019 – First policy announcement