The Congress of Neurological Surgeons (“CNS,” “us” or “we”) understands that data privacy and the protection of Personal Information is important to our members, business partners, website visitors and app users. This Privacy Policy describes how CNS and its affiliates that link to this Privacy Policy, each being a data controller, collects, processes, uses, and discloses information that identifies, relates to, or could reasonably be linked to you as an individual or household. We refer to this information as “Personal Information,” throughout this Privacy Policy. Information that has been de-identified by CNS or others is no longer personal information and is not covered by the terms of this Privacy Policy. The CNS’s website (www.CNS.org) and our mobile app (the “app”) are referred to collectively in this Privacy Policy as the “Site.” CNS is committed to protecting the privacy of the users of the Site. We will use and disclose your personal information as stated in this Privacy Policy. You should read this Privacy Policy before visiting our website, using our app, applying to become a CNS member, submitting information or articles to us, or otherwise using our services.
The Personal Information we collect depends on the interactions you have with us, such as whether you are a CNS member, a website visitor, an app user, or a journal contributor, the location in which you reside, and applicable law. Please note that specific information about data privacy practices (a “Specific Notice”) in addition to this Privacy Policy may be provided depending on the specific interactions you have with us. In the event of a conflict between this Privacy Policy and a Specific Notice, the Specific Notice will prevail unless specifically stated otherwise. For information about the information practices of the Joint Sections of the CNS and the American Academy of Neurological Surgeons (“AANS”), including how the CNS collects, uses and discloses information as part of this partnership, please see the below section titled “Joint Sections.”
Site Visitor Data
In addition to web logs described below, CNS routinely gathers data on Site activity, such as how many people visit the Site, the web pages or mobile screens they visit, where they come from, how long they stay, etc. This data helps us improve our content and overall usage. Such information is not shared with other organizations for their independent use.
The Site does not honor a browser’s signal or header request not to track the user’s activity.
Data Caching
To ensure a positive user experience, certain data may be temporarily or permanently cached by the Site on users’ devices.
Personal Information Collection
Sources of Information Collection
Information You Voluntarily Provide. If you voluntarily provide us with Personal Information, including when you apply for membership, order products from the CNS, sign up for or attend an event held by the CNS, or submit written work to the CNS, we collect Personal Information from you. This Personal Information may include your name, email address, mailing address, phone or mobile number, age or date of birth, employer or institution, your device location, payment information. We may record certain speaking engagements, events, and workshops held by the CNS, which may result in our collection of Personal Information from event participants and registrants. We do not intentionally collect patient health information (“PHI”), and users should not submit PHI when using our services.
Information We Automatically Collect. When you visit and interact with our website and websites that we manage or use our app, we, and the third-party companies we partner with, may collect and store certain information by using technologies such as server logs, cookies, web beacons, clear gifs, tags, e-tags, flash cookies, pixels, code, Javascript packages, software development kits, and similar technologies. The information collected by these technologies includes information about your device, browser, and visit that does not inherently reveal your specific identity but may constitute Personal Information in some circumstances. Depending on your activities on the Site and your settings on your browser, the information collected by us and the third-party companies may include software and hardware attributes of the device, device ID information, regional and language settings, performance data about the Site, network provider, IP address, browser or operating system type and version, demographic or inferred-interest information, search terms, the activities and actions taken on the site, as well as information you have submitted to us through the Site. Third parties may also receive additional information such as advertising IDs associated with you or your device.
We may also use web beacons and other technologies to collect information about your interaction with our email communications. When you open or view the content of our emails, we and the third-party companies we partner with will receive information including confirmation that the email was viewed, the time that the email was opened, the IP address of the device that was used to open the email, the type of software used to read the email, and the existence of any cookies previously sent. For more information about information we automatically collect, please see the below section titled “Cookies, Log Data and Other Technologies.”
Information We Collect from Other Sources. We may collect information about you from other sources and we may combine information from other sources with information we collect through our services or through our interactions with you. For example, we may collect information about you from third parties, including identity, education and credential verification services, mailing list providers, and publicly available sources. We may also collect information about you through your membership in the American Association of Neurological Surgeons (AANS), including your membership in the Joint Sections of the AANS and CNS. For more information about the Joint Sections, please see the below section titled “Joint Sections.”
Categories of Personal Information We Collect
Depending on your interactions and relationship with us, the CNS may collect the following types of Personal Information from or about you.
-
Identifiers, such as your name, contact information, address, telephone number, online identifiers, and demographic information such as age or date of birth.
-
Protected classification characteristics under state or federal law, such as demographic information age and gender.
-
Commercial information, such as records of products or services purchased, billing details, events attended, and information about previous transactions, including credit card information.
-
Internet or other similar network activity, such as information about your interactions with our Services or advertisements.
-
Geolocation data, such as the approximate location of your device that accesses our Services.
-
Audio, electronic and visual information, including photographs, videos, if you provide a testimonial or voice recording, or if you participate in a webinar or online or in-person event that we record.
-
Inferences we derive from the information that we collect to create profiles reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
-
Social media profile information, when you share it with us or use it to contact us.
-
Account-related information, such as the username and password associated with your account.
-
Device information and unique device identifiers, such as your IP address, operating system, or the serial number of your device.
-
Preference information, including your communication, language and time zone preferences.
-
Any other personal information you choose to provide to us.
-
Any other personal information you consent to the collection of at the time of collection.
We may not collect each of the above categories of Personal Information from every individual who interacts with us. We may also combine personal information we receive from or about you from one source with personal information we receive from or about you from other sources, or across various interactions with you.
How We Use Personal Information
CNS processes and uses your Personal Information for our legitimate business purposes, with your consent, to perform our contractual obligations, to provide you with services, products, or information you request from us, where we have a legal obligation, and for other purposes disclosed to you at the time data is collected. The Personal Information we collect about you may be used for the following purposes, depending on how you interact with us, including to:
-
Provide services, programing and support to our members, prospective members, surgeons and their institutions or employers, website visitors, individuals or groups who submit written works for our consideration, and any other individuals who interact with us.
-
Send you confirmations, invoices, technical notices, updates, security alerts, and administrative messages.
-
Send requested product or service information.
-
Communicate with you about CNS events, offerings, and programming.
-
Respond to your comments, inquiries and customer service requests.
-
Complete transactions with you. CNS does not store any payment information; all transactions are completed through our payment processor, which protects and stores data in accordance with the PCI standards.
-
Administer your CNS account.
-
Market to you, if you opt-in to receive marketing communications.
-
Personalize your experience and bring you relevant content. We may use information to create profiles about our members and users.
-
Monitor and analyze trends regarding our members and website visitors, at an aggregate level.
-
Conduct research and analysis.
-
Improve, develop, customize, and refine our operations, products, services, website, app, and offerings, including offerings that involve the use of Artificial Intelligence or Machine Learning.
-
Detect, investigate, and prevent fraudulent transactions and other illegal activities on our website, and to protect our intellectual property.
-
Act as we believe to be necessary or appropriate: (a) under applicable law; (b) to comply with legal process and for any legal purpose; (c) to investigate security breaches; (d) to respond to requests from public and government authorities; (e) to enforce our terms and conditions; (f) to protect our operations; (g) to protect our rights, privacy, safety or property, you or others; and (h) to allow us to pursue available remedies or limit the damages that we may sustain.
-
Verify, update, reconcile, and maintain accurate records relating to membership, certification status, training pathway participation, and related professional services.
-
Carry out any other purpose you consent to or that we disclose to you at the time your information is collected.
Cookies, Log Data and Other Online Technologies
Depending on your activities on the Site and the settings on your browser, our Site may use cookies, web beacons, pixel tags and similar technologies (collectively, “cookies”). Cookies are pieces of information stored directly on a user’s computer or mobile device that automatically collect certain information from users such as browser type, time spent online, pages visited, referring URL, and additional aggregated website traffic data. We and our service providers use cookies to personalize users’ experience, save users’ preferences, facilitate navigation, display information more effectively, collect statistical information, and for security purposes.
Our website may use the following types of cookies:
-
Functionality. These cookies are necessary for us to ensure that the website functions properly.
-
Security. These cookies are necessary for us to mitigate the risk of data breaches and similar attacks by ensuring that requests are submitted to our websites from proper domains.
-
Authentication. These cookies allow us to authenticate user requests and to maintain session information related to users.
-
Preference. These cookies allow our websites to remember which events you have signed up or registered for, and products you place in your shopping cart.
-
Analytics. These cookies assist us with learning more about how users and visitors use our websites, including pages visited, how much time is spent on each page, and similar information. We use this information in the aggregate.
-
Third Parties. Some of the cookies on our website are third-party cookies, meaning they are placed by third parties and transmit the information collected to the third party who placed the cookie. We do not control the data use or sharing practices of these third parties. If you do not wish to accept third party cookies, we encourage you to update your browser settings accordingly.
In addition, we, and third-party companies we partner with, may collect and store some information in the form of log files that record website activity. For example, log file entries are generated every time a user visits a particular page or clicks an image on our Site, and collects information on how many “hits” a particular web page is getting (a.k.a. “click-through data”), the dates and times that you use the Site, the pages you visit, the amount of time spent on specific pages, and other similar usage information, and general data (including the name of the web page from which you entered our Site)
The use of cookies has become standard among website operators. Most browsers are initially set up to accept cookies. You are responsible for monitoring and configuring available privacy settings on the Site. Be aware that when using a shared device to access the Site your privacy settings may be reset by other users of the shared device. You can usually set your browser to refuse cookies that are not necessary or to indicate when a cookie is being set. If you refuse cookies, you may not be able to use certain functions on our website and our website may not function as smoothly as it does when cookies are enabled.
Information Disclosure
We may disclose personal information to any person performing auditing, legal, operational, or other services for us. We will use information which does not identify the individual for these activities whenever reasonably possible. Information disclosed to vendors or contractors for operational purposes may not be re-disclosed to others by such a vendor or contractor, except as permitted and applicable law. The CNS may disclose Personal Information to third parties in the following circumstances, and as otherwise described in this Privacy Policy:
Service Providers, Vendors, and Consultants. We disclose Personal Information to our service providers, vendors, and consultants who carry out work at our direction and on our behalf, and who require Personal Information in order to perform services on our behalf. In such cases, these companies must abide by our data privacy and security requirements, and are not allowed to use your personal information they receive from us for any other purpose.
Business Transfers. We may disclose your information to parties acquiring all or part of our assets. If we transfer your information to an acquirer, we will use reasonable efforts to direct the acquirer to use your information in a manner that is consistent with this Privacy Policy. Where feasible, we will provide you with notice of any acquisition and give you the opportunity to exercise any rights you may have involving transferring your information to the new entity. If any bankruptcy or reorganization proceeding is brought by or against us, your Personal Information may be considered a company asset that may be acquired by or transferred to third parties.
Organizational Affiliates and Sister Entities. We may share your information with our organizational affiliates and sister entities for marketing, recruitment, and internal reporting purposes. Some of these affiliates and sister entities include, for example, the American Academy of Neurological Surgeons (AANS), and the Joint Sections of the AANS and CNS, including the Joint Section on Disorders of the Spine and Peripheral Nerves, and the Society of Neurological Surgeons. Sharing information with these entities allows us to run our organization more efficiently, and ensures that you receive relevant content and information from us. For more information on the Joint Sections personal information practices, please see the section titled “Joint Sections” below.
Law Enforcement Agencies, Courts, Regulators, Government Authorities, or Other Third Parties. We may disclose your information: (1) to comply with a legal obligation or a court order; (2) when we believe in good faith that the law requires it; (3) at the request of governmental authorities conducting an investigation; (4) to verify or enforce our policies, procedures, terms of service, and other agreements, or to protect the rights, property, safety or security of CNS, our members, vendors, business partners, service providers, affiliates, website visitors or the public; (5) to respond to an emergency; or (6) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual illegal activity.
Marketing Partners. In some circumstances, we may permit certain advertising companies and publishers to collect Personal Information on our websites or about our members. These marketing partners may access Personal Information we have collected from you and combine it with other information they have collected about you. We may collaborate with our marketing partners to jointly send tailored promotional communications to you using the combined set of information. You may opt-out from receiving marketing communications from us at any time by changing your communication preferences in your member profile, or by using the “unsubscribe” link any marketing emails you receive from us. This opt-in requirement applies to promotional or commercial marketing communications and does not apply to transactional, membership, certification, credentialing, administrative, compliance, or service-related communications.
Professional Certification and Credentialing Organizations. We may disclose limited Personal Information, such as name and contact information, to professional certification boards, credentialing bodies, training pathway administrators, and similar mission-aligned organizations where reasonably necessary to support certification eligibility, examination administration, credential verification, professional compliance communications, data accuracy, or related professional purposes. Such disclosures will be subject to appropriate contractual, privacy, and security safeguards.
On occasion, we sell mailing lists to third parties, which may include Personal Information such as your name and address if you are a member of CNS or the Joint Sections. We only include your information on these mailing lists when you opt-in.
Artificial Intelligence. Some of products and services the CNS makes available to members or other individuals may utilize artificial intelligence (“AI”) to collect, store, process, compile, and refine information. These products and services include, for example, CNS’s ChatBot feature in its app. A chatbot is a software application that mimics human conversations in text or voice interactions on our Site. It enables communication between a human and a machine, which can take the form of messages or voice commands. Users should not submit any confidential, sensitive, or patient-identifiable information when using AI-powered features. The chatbot is designed to work without the assistance of a human operator. It responds to questions posed to it in natural language as if it were a real person using a combination of pre-programmed scripts and machine learning algorithms. When asked a question, the chatbot will answer using the knowledge database that is currently available to it. If you use our chatbot service, we will collect any personal information you provide to use. We will also create, record, and store a transcript of your chat interaction with us which will be shared with and stored by our third-party service providers. Third parties that the CNS uses may also offer AI-enhanced features, such as Zoom, which the CNS may use for some member meetings and educational webinars. The CNS relies on third parties to provide and offer AI tools, and therefore, if you choose to utilize products, services, or other offerings of the CNS that involve AI, your information will be disclosed to the AI developer and used in the AI environment, including, in certain cases, to improve or train the underlying models. For more information about how the CNS uses AI, please contact us using the information below.
Non-Personal Information. Aggregated, anonymized or pseudonymized data that is otherwise non-personal information may be shared with vendors, consultants, and other service providers, or used for research purposes.
Sharing with your Consent or as Otherwise Disclosed. We may also share your information with your consent, at your direction, or as you otherwise authorize us to when disclosed at the time your information is collected.
Links to Other Sites
CNS’s website may contain links to other websites, including affiliates of the CNS such as the Joint Sections, or sister entities of the CNS such as the AANS, as well as links to non-affiliated third parties, such as social networks or business partners. These linked sites may have Personal Information collection and use practices that differ from the CNS’s practices, and we encourage you to review the privacy policies of websites that you visit before submitting your Personal Information. Please be aware that if you disclose Personal Information, sensitive information or patient information through public forums, at an event, or on online message boards, this information may be collected and used by others. We take no responsibility for the content, security, or confidentiality of any information posted on or conveyed in these public spaces.
Joint Sections
If you are a member of CNS, you have the opportunity to join a Joint Section of the CNS and the AANS. If you are a member, please note that the Joint Sections share information about their members with both the CNS and AANS. The CNS also shares information about its members with the Joint Sections. This information sharing between the Joint Sections and the CNS occurs so that both the Joint Sections and the CNS can provide services to their members. You may also receive content from the Joint Sections if you are not a member of the Joint Sections, but have indicated that you practice in a particular subspeciality, as indicated above in the “Information Disclosure” section.
Even though the CNS and AANS are sister organizations and jointly operate the Joint Sections, the AANS is a separate organization from CNS with its own distinct policies and practices. At times, these policies and practices differ from the policies and practices of CNS. Accordingly, the privacy and Personal Information practices of AANS may differ from CNS in various ways. We encourage you to review AANS’s privacy policy and Personal Information practices before joining one of the Joint Sections, as information involving members of the Joint Sections are shared with both the CNS and AANS.
Information Security
The CNS knows that information security is of the utmost importance to our members, prospective members, website visitors, app users, and CNS community. CNS maintains reasonable technical, administrative, physical and organizational safeguards proportionate to the sensitivity of information we collect that are designed to prevent unauthorized access, use and disclosure of Personal Information. However, we cannot guarantee the security of Personal Information, as no electronic data transmission or processing of Personal Information is completely secure. We encourage you to assist us with securing your Personal Information by using a strong password and not disclosing your login credentials to anyone. If we become aware of an incident that affects your personal data, we will investigate and endeavor to comply with all required reporting obligations.
Information Retention
We will retain your information for as long as reasonably necessary in light of the purpose for which it was collected. This may mean that CNS will continue to retain certain information after you close your account or resign your membership, as required by law or for our legitimate business purposes. We may also retain archived copies of information for a certain period of time. CNS does not store any payment information.
Rights Regarding Your Personal Information
You have the right to review and correct your Personal Information that we have received from you. You may do so by logging into your account and editing the information in your Member Profile. You can also change your communication preferences and opt-in or opt-out of marketing communications from CNS from within your Member Profile. We encourage you to review your Member Profile frequently to ensure that the information is accurate and up to date. If you are unable to review or correct your information in your Member Profile or if you would like to close your account, you may contact us using the information located in the “How to Contact Us” section below. We will endeavor to respond to all access requests within 30 days. Please note that if you contact us to exercise your rights, we will likely require additional information from you in order to verify your identity and respond to your request. If you are a resident of the European Union or United Kingdom and wish to exercise your privacy rights under the GDPR or UK GDPR, please see the section below titled “European Residents.”
Children
Our products and services are not directed to children under the age of 18. We do not knowingly collect Personal Information from anyone under the age of 18 without parental consent. If you become aware that we have collected Personal Information from an individual under the age of 18 without parental consent, please let us know so that we can take appropriate action.
International Transfers of Personal Information
The CNS is based in the United States in the state of Illinois but recognizes that its members, website visitors and other individuals who interact with the CNS may not be based in the United States. If you access our website or use our services from outside of the United States, it is necessary for us to transfer Personal Information to the United States in order to provide our services. Because the data protection laws of various countries differ, information transferred to the United States may not be subject to the same level of protection as the jurisdiction in which you reside. The CNS relies on your consent to transfer Personal Information to the United States. To the extent you do not consent to data transfers to the United States, please do not provide us with your Personal Information, visit our website, or use our app.
European Residents
The CNS recognizes that it may collect personal data (referred to in this policy as “Personal Information”) from European citizens in certain circumstances, and that this personal data is subject to Regulation EU 2016/679 (the “GDPR”), or the UK GDPR, as applicable. Our lawful basis for processing personal data related to European citizens is outlined above in the section titled “How we Use Personal Information.” We respect the rights conferred upon European citizens under the GDPR and UK GDPR and strive to uphold them to the extent they apply to us or to the personal data we collect from European citizens. In addition to the rights enumerated above which encompass the right to be informed right to access, and right to rectification of personal data, European citizens or their representatives have the right to request erasure of their personal data, to revoke consent to processing and/or restrict processing of their personal data, to data portability, and to complain to the relevant data protection authority about our data protection practices. To the extent permitted, we will attempt to verify any requests we receive before acting upon them.
As noted above, our organization is located in the United States. Accordingly, information collected and processed about you will be processed in the United States, which may not offer the same level of protection as the country you reside in. By providing information to the CNS or using our products and services (including visiting our website), you consent to your personal data being processed in the United States.
If you are a European resident and you have any questions regarding the personal data we process, our lawful basis for processing your personal data, and any rights you have regarding your personal data including exercising these rights, please contact us using the information provided below in the “How to Contact Us” Section.
Updates to Our Privacy Policy
The CNS may update this Privacy Policy from time to time as we add new features or modify the way in which we manage information, or as laws change that may affect our services. If we make material updates to this Policy, we will update the “last updated” date at the top of this Policy. Any changes will be effective immediately upon the posting unless otherwise indicated. Any revisions will apply both to information we already have about you at the time of the change, and any personal information created or received after the change takes effect. Where changes to this Privacy Policy will have a fundamental impact on the nature of processing or otherwise have a substantial impact on you, we may endeavor to provide you with more direct notice of the changes, and provide you with an opportunity to exercise any rights you have to cease our processing of your Personal Information. We encourage you to periodically reread this Privacy Statement, to see if there have been any changes to our policies that may affect you. Continued use of the website, app or continued membership in CNS after updates to our Policy will be deemed consent to the changes.
How to Contact Us
We encourage you to review this Privacy Policy in its entirety. Should you have any questions or concerns about our policies and privacy practices concerning the Site, your rights under this Policy, and your dealings with the Site privacy practices, please do not hesitate to contact our Privacy Manager at privacy@cns.org or write to us at:
Congress of Neurological Surgeons
Attn: Privacy Manager
10 North Martingale Road, Suite 190
Schaumburg, IL 60173