June 19, 2015
- TRUSTe Certification
- Choices You Have about Sharing Information in your ORCID Record
- Information We Collect and How We Collect It
- How We Use Information We Collect
- How We Share Information We Collect
- Access, Review, Editing and Changing Data
- Transparency, Disputed Records, & Removal of Data
- Information Security
- International Data Transfer; Governing Law
- Enforcement and Arbitration
- Children's Privacy
- Single Sign On
- Changes to this Policy
- Questions or Concerns
ORCID, Inc. (referred to as “ORCID”, “us” “our” and “we”) is a nonprofit organization whose mission is to solve the name ambiguity problem in scholarly communication by creating and operating an open-access registry (referred to as the "Registry") of persistent unique identifiers for individual researchers, and an open and transparent linking mechanism with other ID schemes and research objects such as publications, grants, and patents.
In this document we use “you” to refer to researchers and other users of the Websites and Registry.
2.0 TRUSTe Certification
The TRUSTe program covers only information that is collected through the Websites at https://orcid.org.
- Member: An organization that has entered into a fee-based Membership Agreement with ORCID.
- Member Creator: An ORCID Member with a specific employee-employer and/or student-institution relationship with you that has created an ORCID Record (including obtaining an ORCID identifier) on your behalf. Before creating an ORCID Record for you, a Member must first warrant to ORCID that is has the authority to do so.
- ORCID Record or Record: The composite data set other than system data (e.g., user ID, password, log files), including the ORCID iD, pertaining to a specific individual and stored in the Registry.
- Record Holder: The owner of an ORCID Record. Generally, this is the person featured in the record. If an ORCID Record is created on behalf of someone who is an employee or student, the employer or school is the Record Holder until the individual Claims the record.
- Trusted Organization: An ORCID Member organization to which you have given the right to view, edit, and/or deposit specific data in your ORCID Record. (For example, you may grant a publisher the right to update information about your publications, or grant a funder the right to read information about grants that is otherwise not viewable by the public through the Registry.)
- Trusted Individual: A Trusted Individual is a person to whom you have given the authority to manage your ORCID Record on your behalf, including selecting privacy settings, naming Trusted Organizations, and editing and depositing data. Trusted Individuals must agree to ORCID’s Terms and Conditions of Use. (Also see Section 5.3.)
- Claim: The process of indicating that an ORCID Record created by a Member Creator refers to you and taking over ownership of the Record Account.
5.0 Choices You Have about Sharing Information in your ORCID Record
We are committed to providing you with meaningful choices about your privacy and the ability to control how your information is used. A core ORCID principle is that you control the privacy settings of your own ORCID Record data through various opt-in and opt-out features, regardless of whether you create your own ORCID Record, or an ORCID Record is created on your behalf by a Member Creator. To that end, ORCID allows you the right to control how your information is published on and shared via the ORCID Registry.
5.1 The Privacy Settings
When you create an ORCID Record, you can choose to make any element (other than the ORCID iD, which is always visible) visible to everyone (Public), visible only to a selected groups of Member institutions (Trusted Organizations) that you have indicated that you trust (Limited Access), or visible only to you and Trusted Individuals you designate (Private), as further described in the definitions of Public, Limited Access, and Private below.
If a Member Creator creates an ORCID Record on your behalf, the Member Creator selects the initial privacy settings. You will receive an email from ORCID inviting you to Claim the Record. If you do not Claim your Record, the Member Creator may continue to edit and update the Record, and make privacy selections. If you do not initially Claim your Record, you can still Claim your Record at any time in the future and take over management of the Record.
visible by everyone
Data marked as Public will be available to the public for viewing and use. Note that if a Member Creator creates an ORCID Record for you, we will email you and give you a period of time (set forth in the email but at least 10 days) to let us know if you object to having your information shared with the public via the Registry. If we do not hear back from you within the given time, we assume that you are comfortable with the selections made by the Member Creator, and will share data according to the privacy settings set by the Member Creator, including that marked as Public.
|5.1.2 LIMITED ACCESS||
visible by those you trust
People and Organizations I trust
Data marked Limited Access may be viewed through the Registry by you and your designated Trusted Individual(s) (if any) and Trusted Organizations (if any) (and the Member Creator until you Claim the Record). You can elect to share a field or specific data within a field with Trusted Organizations. Trusted Organizations will have these permissions for the time period that you specify, either for a single use, or until you revoke these permissions on the Registry account settings page of your Record. They will also have edit and deposit rights for information they add to your record if you or your Trusted Individuals grant them such rights. At any time, you can elect to terminate permissions for any Trusted Organization on the Account Settings page of your Record. Note that once you give an organization the right to view Limited Access data, ORCID has no control over how the organization uses the Limited Access data, including sharing it with others. Therefore, you should only grant Trusted Organization status to those that you trust.
visible by only me
Data marked as Private may be viewed through the Registry only by you and any Trusted Individual(s) you designate. Private data are not shared with the public, Trusted Organizations or other Members of ORCID (except in the case of a Member Creator until you Claim your Record or the Trusted Organization that added the data to your record unless you remove this permission).
Only our staff, and our agents’ or contractors’ staff, with a “need to know” to manage the Registry and process data for us are able to view Private and Limited Access Data. See How We Use Information We Collect and Information Security, below.
5.2 Changing Settings
You can change your privacy settings at any time. However, the new settings will only apply after you have made the change. ORCID has no control over uses of data already made available via the Registry or disclosures made in places other than the Registry.
5.3 Trusted Individuals
You may delegate management of your ORCID Record to one or more Trusted Individuals (such as your research administrator or administrative assistant). A Trusted Individual can act on your behalf with respect to your ORCID Record, including editing and depositing data, naming Trusted Organizations, and designating privacy settings. S/he will have access to all information in your ORCID Record, including Limited Access and Private data. Therefore, you should only grant Trusted Individual status to a person you trust. ORCID cannot control how a Trusted Individual will interact with your ORCID Record. You may revoke Trusted Individual status at any time at the Account Settings page of your Record.
5.4 Claiming Records / Unclaimed Records
If a Member Creator creates an ORCID Record on your behalf, you will receive an email from ORCID inviting you to Claim the Record. Until you Claim a Record, the Member Creator may continue to make privacy selections with respect to your Record, and edit, update and close your Record. When you Claim a Record and at any time thereafter, you can elect to take over management of your Record, including through a Trusted Individual. Any changes you make to privacy settings will override Member Creator settings.
6.0 Information We Collect and How We Collect It
ORCID collects information from users of the Websites and Registry in four ways: information you directly give us; information given to us by a third parties; information we collect from your use of the ORCID Websites; and information we collect from cookies, also known as tracking technologies (See Section 6.4).
6.1 Information You Give Us
To use certain features of the ORCID Website, users must register with ORCID. Registration requires that you provide us with personal information including your name and email address. You are not required to register with us to use the ORCID Websites; however, if you do not register, certain features (e.g., creating an ORCID Record or serving as a Trusted Individual) are not available.
If you want to create an ORCID Record (including obtaining an ORCID identifier), you will need to provide ORCID with personal information, including, at minimum, your name and email address. If you want to claim an ORCID Record created on your behalf (see below: Information Provided by a Third Party), you will need to register with ORCID and confirm your name and email address. You may also include certain additional information about yourself in your ORCID Record, such as affiliations, title, education, grants, patents, and publications.
We also collect information from you if you contact the Help Desk, the ORCID Ombudsman or Executive Director, or make posts in any online chat rooms, blogs or other public forums offered from time to time on the Websites. ORCID may associate your Account information (e.g., name and email address) with these activities.
6.2 Information Provided by a Third Party
A Member Creator may obtain an ORCID identifier and create an ORCID Record for you. In the process, the Member Creator provides ORCID with personal information about you, including at a minimum your name and email address. Before a Member Creator creates an ORCID Record and has an ORCID identifier assigned on your behalf, we ask the entity to represent and warrant that it has the authority and your consent to provide us with information about you, to contact you about the Record, and to distribute certain information in the Record to the public. If the Member Creator represents to us that it has the authority to create an ORCID Record and have an ORCID identifier assigned, but not your your consent to make the data available through the Registry, it must mark the data it deposits as Private, and the information will not be made publicly available unless you change the privacy setting. If the Member Creator creates a Record for you, we will email you at the address provided by the Member Creator and give you a period of time (set forth in the email but at least 10 days) to let us know if you object to having any information shared via the Registry; if we do not hear back from you within the given time, we will assume that you comfortable with the privacy selections made by the Member Creator, and will share any data marked as Public by the Record Creator. Please note that Member Creators, not ORCID, determine whether they have the authority and consent to (i) create an ORCID Record on your behalf, and (ii) make certain Record data available to the public based on their internal policies, contracts they may have with you and applicable laws. See Choices You Have About Sharing Information in the ORCID Registry above.
Trusted Organizations may deposit information in your Record if you give them the authority to do so. You may provide this authorization on a Member website that has integrated with ORCID, or directly in the ORCID Registry.
Your Trusted Individuals may edit and deposit information in your Record. You may specifically designate or remove Trusted Individuals in the ORCID Registry at the Account Settings page of your Record.
In some instances an ORCID Member or its agent may contact us to let us know that they have information about new publications or other research activity that you may want to add to your record; in that case, ORCID will contact you and ask if you want to do so.
6.3 Information ORCID collects from your use of the Websites
ORCID will collect information about your use of the Websites and Registry. We do this to monitor when and by whom Registry information has been changed, and also to monitor traffic on the Websites and Registry. When a visitor accesses our Websites or Registry, we collect certain information using web analytics tools, including details about the users, such as the visitor’s IP address, the type and version of the Internet browser that is being used, the site from which the visitor accesses our Websites, the type of device being used (e.g. computer, smart phone, tablet), or the screen resolution; and details about usage, including page traffic. We do not link this automatically collected data to other information we collect about you.
6.4 Information from Tracking Technologies
Behavioral Advertising. While ORCID does not provide advertising on our websites or use advertising to promote the ORCID websites, we partner with a third party to display some sections of our websites, such as images or embedded videos. This third party also provides services to either display advertising on websites or to manage advertising on other sites. Our third party partner may use technologies such as cookies to gather information about your activities on this site and other sites in order to provide you advertising based upon your browsing activities and interests. If you wish to not have this information used for the purpose of serving you interest-based ads, you may opt-out by visiting www.aboutads.info/choices if you are in the United States, or http://youronlinechoices.eu/ if you are outside the United States.
Local Storage Object (Flash & HTML5). We partner with third party providers that use Local Storage Objects (LSOs) such as HTML5 to store content information and preferences. The third parties with whom we partner to provide certain features on our site use LSOs such as HTML 5 and Flash to collect and store information.
Various browsers may offer their own management tools for removing HTML5 LSOs. To manage Flash LSOs please click here: http://www.macromedia.com/support/documentation/en/flashplayer/help/sett...
7.0 How We Use Information We Collect
We use the information we collect to provide the ORCID Websites and Registry to the public and to Members:
- If a Member Creator creates an ORCID Record on your behalf, we will use the email address they provide to contact you to Claim your Record.
- If you have an ORCID Record we may use your email address to contact you with requests from Members to deposit or edit information in your ORCID Record. We may also contact you about your use of the ORCID Websites and Registry.
- We will also use personal information to send you newsletters, special offers, promotions and other information about ORCID. You may subscribe during the registration process or at http://orcid.org/newsletter/subscriptions.
You may regulated the frequency or opt-out of receiving these messages by unchecking the box as you register. You may unsubscribe at http://orcid.org/newsletter/subscriptions, by changing your email preferences in your Account Settings, or by clicking on the unsubscribe message included in each newsletter. Please note that we reserve the right to notify you about changes or updates to your ORCID account and the Registry as described in the preceding paragraph.
- We use the information we collect to operate, protect, evaluate and improve the ORCID Websites and Registry, its features, and ORCID operations generally. Note that this use includes Private and Limited Access data; for example, we may use such data for disambiguation or to resolve any disputes about identity and Records.
- We also use the information we collect about when and by whom information was deposited in your ORCID Record to help verify questions you have about your Record or resolve any disputes about the accuracy of information in a Record.
8.0 How We Share Information We Collect
8.1 With the Public & Members
In addition to ORCID’s commitment to giving Record holders control over their ORCID Records, ORCID seeks to support open access to information for the research community. ORCID shares with the public free of charge any data marked as Public through the Registry for viewing and use.
Your designated Trusted Individuals have access to all of your Record information (other than your password) including data marked as Limited Access and Private. Your designated Trusted Organizations are able to view your Public data and the Limited Access data you have approved sharing.
If there is a dispute regarding data in your Record, we may share your email address with your permission and relevant deposit history (e.g., what data was deposited by whom) with the disputing or depositing party or a third party dispute resolution agent, so that the dispute may be resolved.
Our Terms and Conditions of Use (for individuals) and our Membership Agreement (for Members) state that individual data Records may not be used in any manner that is defamatory or misleading; cannot be modified so as to make them false, incomplete, or misleading; are subject to your rights of publicity; and if any person or entity uses the data for marketing purposes, they must give you the right to opt-out of such communications. Although we post this notice, ORCID does not undertake the responsibility to police third party uses of data. If you object to a third-party use of your data, you should contact and make a complaint directly to the third party.
The Public Data File
In addition, annually, ORCID will release to the public a downloadable data file, the “Public Data File”, containing all Public data from ORCID Records created or Claimed by individuals. The public will have free access to the data for viewing and use. ORCID is releasing the Public Data File under a CC0 1.0 Public Domain Dedication developed by Creative Commons, in which ORCID waives all copyright and related rights it owns in the Public Data File to the extent permitted by law. Accordingly, ORCID does not impose restrictions or conditions (including those contained in the Terms and Conditions of Use and the Membership Agreement) on use of the Public Data File, but it has posted recommended community norms for use. ORCID is sharing the Public Data File to ensure that all scholarly communication stakeholders, including organizations that are not Members of ORCID, have broad access to what we hope becomes a vital part of the scholarly communication infrastructure.
8.2 With our Vendors
We may share your information with agents or contractors (for example, a vendor may host ORCID’s servers, or an an ORCID Contractor may need to check Records for inconsistencies), but only on a “need to know” basis to help us operate ORCID, the Registry and the Websites, and only if the vendor signs a written agreement which requires it to maintain the confidentiality and security of your information and not to use it for other purposes. These companies are authorized to use your personally identifiable information only as necessary to provide these services to us.
- Users of the Registry may not use the email or physical addresses obtained from the Registry to send any marketing or other commercial communication to anyone, unless they give the person the right to opt-out of such communications.
- Users may not use any Record Data to send junk mail, spam, chain letters, pyramid schemes, or other similar communications.
Because the Public Data File is released under a CC0 Waiver, we cannot impose any restrictions on use; however we do suggest that people follow community norms in using the Public Data File as well. ORCID does not otherwise limit commercial use of Public Data by third parties or of Limited Access Data by entities to which you (or a Trusted Individual) gives access. You can block commercial re-use of any data by marking it Private and by controlling who you grant permissions as a Trusted Organization.
- Aggregated Data: We may share aggregated usage data with our Members or others in the research community or publish information based on aggregated usage data so Members and others can understand how the ORCID Registry is being used. We will only do so in a way that your personal identity is protected.
- Legal Reasons: If (a) we are required by law, public safety or public policy, or we are served with a warrant, court order, or subpoena; or (b) we need to defend against legal claims and bankruptcy proceedings, we may provide your information, including Limited Access and Private data to regulators, enforcement agents, government entities, or others making claims against us. We will provide information about any government data requests received and Accounts affected to the extent allowed. We may also share your information, including Limited Access and Private data, to enforce our Terms and Conditions of Use and Membership Agreements (including investigation of potential violations).
9.0 Access, Review, Editing and Changing Data
You may review, delete, and edit information in your ORCID Record and change preferences. Please note that changes will be applied prospectively. For example, if you change a privacy setting from Public to Private, or Limited Access, there is no way to stop people who have previously viewed or downloaded the Public data from using it.
- You may review information about you and change your privacy settings in your ORCID Record by logging into your ORCID Record. If you think that any information in your Record is wrong, we strive to give you ways to update it quickly or delete it, subject to legitimate business or legal purposes, including the Dispute Procedure outlined below in Transparency, Disputed Records and Removal of Data.
- You may choose to disable your ORCID Record in the Registry by deactivating the Account from the Account Settings page of your Record. In the event that an ORCID Record is disabled, we will maintain as Private your name and email address, so as not to assign the same identifier to another person and to allow you to re-claim your identifier in the future.
- You may make yourself “invisible” to the public by marking all fields other than the ORCID identifier Private.
- You may revoke Trusted Organization or Trusted Individual status at any time using the Account Settings page.
- You may update your password, email, and notifications preferences at any time using the Account Settings page.
- You may contact ORCID Support at http://orcid.org/help/contact-us to remove a Record created for you by your employer or affiliated organization acting as a Member Creator. Or, you may first Claim the Record, in which case you may deactivate the account from the Account Settings page of your Record.
Records of Deceased Persons
An ORCID Record of a person that was created before the person deceased is maintained as-is, according to the following:
- Record data, privacy settings, Trusted Individual, and Trusted Organization designations of the ORCID Record remain as set by the Record owner before being deceased.
- If the ORCID Record owner selected one or more Trusted Individuals, such persons may continue to manage the record as per the Record owner's wishes.
- Any current Trusted Organizations may still write/access the record according to the settings at the time before the person is deceased. However, Trusted Individuals (if they exist) may affect these settings as outlined previously.
- Posthumous publications may be added to the ORCID Record only if arrangements had been made prior to death (e.g., one or more Trusted Individuals were assigned who add the publication(s), and/or a Trusted Organization relationship had been made that would allow for the addition of the publication(s) without further action.)
- A person who has assumed management of the deceased researcher’s email account may request that all email from ORCID to the researcher be turned off.
- No indication is made by ORCID to highlight Records of deceased persons, though Trusted Individuals, at their discretion, could use existing fields to provide this detail, if desired, for example, including such information in the biography field, or after the person’s name.
- If ORCID is contacted to remove or correct a Record for someone who is deceased, the requestor will be referred to the Record's Trusted Individual(s) (if any), or, if needed, the request will be handled according to ORCID’s established Dispute Procedure described in Section 10.
10.0 Transparency, Disputed Records, & Removal of Data
To ensure the transparency of the ORCID Registry, we keep an audit trail of when and by whom Registry information has been deposited or changed and any changes to privacy settings. ORCID will use this information to assist you in addressing concerns about the provenance of data in the Registry and questions about identity ambiguity or theft. If you have a concern about the accuracy of data in your ORCID Record or another ORCID Record or another ORCID Record, please submit a ticket to our Help Desk. We will review your concerns in accordance our Dispute Procedure. ORCID reserves the right (but shall not be required) to remove or hide from the Registry and its servers any Record data that violates the privacy, publicity or other rights of any person, is the subject of a dispute, or for any other good cause, including without limitation, in any situation in which ORCID is advised by legal counsel that the retention or public availability of such data poses a legal risk to ORCID.
We will retain your information for as long as your Account is active, or as needed to provide you services, including reactivation. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
11.0 Information Security
We are committed to protecting the Registry and our users from unauthorized access to or unauthorized alteration, disclosure or destruction of personal information in the ORCID Registry or which we otherwise hold. For example:
- We store information about you in a data center with restricted access, and we use a variety of technical security measures to secure your data. We also use secure socket layer (SSL technology) and intrusion detection and virus protection software.
- We periodically review our information collection, storage and processing practices, including physical security measures.
- We restrict access to information marked as Private to ORCID employees, contractors and agents who need to know that information to manage the ORCID Registry and process such data for us, and who are subject to confidentiality obligations.
- We restrict access to information marked as Limited Access or which is otherwise not public to (i) Trusted Organizations granted permissions by users, and (ii) ORCID employees, contractors, and agents with a need to know to manage data in the ORCID Registry and process such data for us, and who are subject to confidentiality obligations.
- All passwords and security question answers are hashed and are not visible to ORCID, its contractors or agents, or even you.
Despite these measures, we cannot guarantee that unauthorized persons will not be able to hack our system or otherwise defeat our security measures.
Your access to some of our services and content may be password protected. To maintain the security of your information (or information in another person’s ORCID Record that you are authorized to view), please keep your username(s) and password(s) strictly confidential and do not disclose them to anyone. We also recommend that you sign out of your Account or service at the end of each session. You may also wish to close your browser window when you have finished your work, especially if you share a computer with someone else or are using a computer in a public place. You will be solely responsible for any action, activities, and access to our Websites and Registry that were taken through your username and password, and that occurred before you notified us of their loss. If you have any questions about security on our Websites, please contact us at http://orcid.org/help/contact-us.
12.0 International Data Transfer; Governing Law
13.0 Enforcement and Arbitration
If the complaint or dispute cannot be resolved through our internal process, and ORCID does not adequately respond to your question, please contact TRUSTe at https://feedback-form.truste.com/watchdog/request.
If you are not able to resolve your concerns through ORCID’s internal mechanism or through TRUSTe, arbitration as set forth in this paragraph will be your final and exclusive recourse for dispute resolution. If arbitration is necessary, it will be conducted by telephone and email, and if it must be done in person, it will be conducted in New York, NY, and each party consents to such jurisdiction. The arbitration will be conducted by one arbitrator who is a member of the American Arbitration Association, and under the rules of commercial arbitration of the American Arbitration Association. Both parties will bear equally the cost of arbitration (exclusive of legal fees and expenses). All decisions of the arbitrator(s) will be final and binding on both parties and enforceable in any court of competent jurisdiction. The arbitration panel should apply New York law, without regard to its conflict of laws principles. In addition, in the case of any disputes involving data transfers from outside the United States, the arbitration panel shall also apply the Safe Harbor Enforcement Principles issued by the U.S. Department of Commerce, without transferring the dispute to any other entity or jurisdiction for resolution.
14.0 Children's Privacy
ORCID provides general audience Websites and does not offer services directed to children. Should a child whom we know to be under 13 send personal information to us, we will delete that information immediately. Parents may also contact us through our Contact Us form to request removal of any personal information about a minor.
15.0 Single Sign On
You may log in to our site using sign-in services such as Facebook Connect or an Open ID provider. These services will authenticate your identity and provide you the option to share certain personal information with us such as your name and email address to pre-populate our sign up form. Services like Facebook Connect give you the option to post information about your activities on this Web site to your profile page to share with others within your network.
Our Websites offer publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal information from our blog or community forum, contact us at http://orcid.org/help/contact-us. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why. Alternatively, if you used a third-party application to post such information, you can remove it, by either logging into the said application and removing the information or by contacting the appropriate third party application.
17.0 Changes to this Policy
18.0 Questions or Concerns