Effective Date: April 27, 2020
Please note that Nelnet Business Solutions, Inc. (“Nelnet”, “we”, “our”, or “us”) offers Services related to education, including tuition management, payment administration and processing, financial needs assessment, school management, online application, and online enrollment. To provide these Services, we must store and maintain information about educational institutions (or other entities) we serve, along with personal information regarding administrators, staff members, parents, and students. Access to the data will be restricted to authorized associates and will be used only for the purpose of providing Services to you or the Institution.
We are committed to providing you a useful and enjoyable online experience. This Policy explains our collection and use practices regarding consumer information, including how and what we share with our related companies and with unrelated entities. Protecting your privacy is important to Nelnet and our employees. We want you to understand what information we collect and how we use it.
This Policy is subject to change from time to time, so be sure to check back occasionally to ensure you have read the most current version. It is effective as of the date listed above and applies to our Services that link to this policy. Even if you read and/or agreed to a prior privacy statement, you need to review this updated version. We reserve the right at any time, and in our sole discretion, to change or modify this Policy. If any such changes or modifications are made, we will update the “Effective Date” appearing at the top of this web page. Such changes or modifications shall be effective immediately upon posting to the Website, and supersede any prior versions of this Policy.
This Policy governs the privacy policies of this Website or the Nelnet mobile device application(s) only.
Information We Collect
Why We Collect Information
We collect information so we can identify you as our customer, to establish, manage and protect your accounts, to complete your transactions, to create and offer you products and services you might be interested in, to personalize and improve upon your experience with us and to comply with various legal and regulatory requirements.
We may collect information from your visit or as part of the registration and administration of your account, in order to personalize and improve upon your experience with us, such as, without limitation, age and individual preferences (“Non-Identifying Information”).
The Services may place “Cookies” on a visitor’s device. Cookies are small text files. Our Cookies save anonymized data about individual visitors, allowing our Services to recognize information about a visitor and help deliver personalized content and other services and functions. Cookies make your Internet experience quicker and more convenient. The Services use both session cookies, which terminate when a user closes his or her browser, and persistent cookies, which remain on the user’s device until they expire or are manually deleted. The Services also contain coding from our business and technology partners which generates third party cookies. Third party cookies allow our business and technology partners to store non-Identifying Information they can access when you visit this or other websites. Accepting a cookie from a web or device browser does not give us access to any Personally Identifiable Information.
Most website and mobile device browsers allow you to control cookies, including whether or not to accept them and provide the ability to remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser. Blocking cookies may result in a lower quality experience for you while you are using our Services.
Device and Connection Information
When you use our Services, we will identify the Internet Protocol (IP) address of your computer or handheld device. The IP address does not identify you personally, but it lets us identify the device you are using. We store IP addresses in case we need to track a connection for security purposes. We may also collect other device-specific information about the device you are using, including what type of device it is and hardware model, what operating system you are using, device settings, unique device identifies, geo-location data, and crash data. Whether we collect some or all of this information often depends on what type of device you are using and its settings. Check the policies of your device manufacturer or software provider to learn more about what information your device makes available to us.
Web Beacons (1×1 Pixels or GIFS)
Our Services may contain coding known as Web Beacons that use 1×1 pixel images to capture and transmit the online activity of users on our Services. These Web Beacons typically transmit information about form completions and other activities in order to measure advertising effectiveness or store analytics information. In addition, we may use Web Beacons in HTML-based emails. This allows us to evaluate the effectiveness of our email communications and our marketing campaigns by showing how many emails recipients have opened.
Like most websites, our servers utilize log files. Log files store information including internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, platform type, date/time stamp, and number of clicks. Log files are used to analyze trends, administer the Website, track Users’ movement in the aggregate, and gather broad demographic information for aggregate use. We use log file information at times to help identify you as you browse and to gather broad technical and demographic information on who uses our website.
Google Analytics Feature
Other Analytics Tools
In addition to or in lieu of Google Analytics, we may use other similar web analytics tools to collect information about our Website. Regardless of the tool selected, we use this information only to improve the Website. Any analytics tools we use collect only the IP address assigned to you on the date you visit the Website, not your name or other identifying information. We do not combine the information collected by analytics tools with Personally Identifiable Information. We only use analytics tools that are GDPR-compliant and that meet our auditing and privacy standards.
If you choose to link your Google Drive account to a Nelnet product for easy access to your files, Nelnet will use Google’s OAuth protocols to establish that connection. Nelnet will not use this information in any manner inconsistent with this policy or for any purpose other than allowing you access to your Google Drive. Nelnet will not read, edit, delete, or copy files or information without your permission or as instructed by you. You may disconnect Nelnet’s site or application at any time by removing access through your Google account.
Do Not Track Signals
Do Not Track is a feature in your web browser, which enables you to opt-out of the third party tracking of your online activities over time and across third party websites. We do not track users across third party websites to provide targeted advertising, and therefore, do not process or comply with any web browser’s “do not track” signal or other similar mechanism that indicates a request to disable online tracking of individual users who visit this Website or use our Services. Third parties cannot collect any Personally Identifiable Information from this Website unless you provide it to them directly.
Personally Identifying Information
We may collect Nonpublic Personal Information about you from the following sources:
- Information from this Website or paper forms
- Information about your transactions with us or others
- Information we receive from third parties, such as your academic institution
“Nonpublic Personal Information” is nonpublic, personally identifiable financial information about you that we obtain in connection with providing a financial product or service to you. For example, Nonpublic Personal Information includes information regarding your account balance, payment history, and overdraft history, if applicable.
We may collect Personally Identifiable Information about you as well, including:
- Your first and last name
- Your home address
- Your home or work telephone number
- Your birth date
- Your email address
“Personally Identifiable Information” is individually identifiable information about an individual consumer collected by us and maintained in an accessible form.
How We Use Your Information
Uses of Information
Certain Non-Identifying Information would be considered a part of your Personally Identifiable Information if it were combined with other identifiers (for example, combining your zip code with your street address) in a way that enables you to be identified. But the same pieces of information are considered Non-Identifying Information when they are taken alone or combined only with other non-identifying information (for example, your viewing preferences). We may combine your Personally Identifiable Information with Non-Identifying Information and aggregate it with information collected from other Users to attempt to provide you with a better experience, to improve the quality and value of the Services and to analyze and understand how our Website and Services are used. We may also use the combined information without aggregating it to serve you specifically, for instance to deliver a product to you according to your preferences or restrictions.
If you supply us with your e-mail address, we may let you know by e-mail about other products and services and product enhancements that may be of interest to you. You will have the opportunity to tell us you do not want to receive future messages with each message you receive. If you e-mail a question or comment to us, we will use your e-mail address to reply to you and we will temporarily store your e-mail address, your message, and our reply for quality assurance or to satisfy applicable laws and regulations. When we collect your e-mail address this way, we will not use it for marketing our products and services unless you have given us permission.
If you wish to change any of your personal information, you may change it by logging into your account; by contacting Customer Service, either through email, mail, or telephone; or by contacting your Educational Institution.
What We Share
We do not sell personal information to third parties. All personal information collected is used by us or our affiliates to perform services, comply with laws or carry out internal functions.
We may share your information with companies that are affiliated with us, such as our direct or indirect subsidiaries or parent or sister companies. As we continue to develop our business, we may buy or sell companies, subsidiaries, or business units. Your Personally Identifiable Information may be included as an asset in connection with mergers, acquisitions, reorganizations, or sales of assets including in the event of bankruptcy.
Sometimes the law or other circumstances also require that we disclose Nonpublic Personal Information and/or Personally Identifiable Information about you to nonaffiliated third parties. Some examples are: when you ask or permit us to do so; in response to subpoenas or court orders; when we suspect fraud or criminal activity; to protect our property and rights or those of a third party; to protect the safety of the public or any person; or to prevent or stop activity we may consider to be, or to pose a risk of being, illegal, unethical, or legally actionable activity.
VERMONT RESIDENTS: We will not disclose nonpublic personal financial information about you other than as permitted by law unless you authorize us to make that disclosure. Your authorization must be in writing or, if you agree, in electronic form. If you wish to authorize us to disclose your nonpublic personal financial information to nonaffiliated third parties, you may notify us at the address found under the “How to Contact Us” section below.
If you become an inactive User, we will continue to adhere to the privacy policies and practices described in this Policy.
Our Security Procedures
We are committed to providing you a useful and enjoyable online experience. We implement reasonable and appropriate physical, procedural, and electronic safeguards to protect your information.
To access information and send e-mail via the Website, you will need a browser that supports the use of Transport Layer Security protocols. This encryption technology helps ensure the authenticity of your online sessions and secures data being transmitted over the public Internet.
We take careful steps to safeguard customer information. We restrict access to your personal and account information to those employees who need to know that information to provide Services to you, and we regularly train our employees on privacy, information security, and their obligation to protect your information. We maintain reasonable and appropriate physical, electronic, and procedural safeguards to guard your Nonpublic Personal Information and Personally Identifiable Information and we regularly test those safeguards to maintain the appropriate levels of protection.
You can help safeguard your Nonpublic Personal Information and Personally Identifiable Information by taking a few simple precautions. Protect your account numbers, passwords, and customer access numbers. Never disclose confidential information to unknown callers. You should always use a secure browser and current virus detection software, and never open email from unknown sources.
The Website is not directed to children under 13. We do not knowingly collect, maintain, or use personally identifiable information from children under age 13. If a parent or guardian becomes aware that his or her child has provided us Personally Identifiable Information without their consent, he or she should contact us using the information in the “How to Contact Us” section, below. If we confirm collected such information, we will take all reasonable measures to delete that information from our system as soon as possible. For users of our learning management system and related products, we may collect and store certain information as required to provide learning management tools to schools, teachers, and students who use such tools.
Links to Other Websites and Services
We are not responsible for the collection and use of information by companies or individuals unaffiliated with us whose websites may contain links to the Website, including vendors where you may shop. Please remember that when you use a link to go from our Website to another website, our Policy does not apply to third party websites or services. Your browsing and interaction on any third party website or service are subject to that third party’s own rules and policies. Please note that when you shop with a vendor who is linked to the Website, even though you may have started your visit with us, and even though our pages may still appear, your transactions are completed with a separate organization, not with us. In addition, you agree that we are not responsible and we do not have control over any third parties that you authorize to access your user content. If you are using a third party website or service, and you allow such a third party access to your user content, you do so at your own risk. This Policy does not apply to information we collect by other means (including offline) or from other sources other than through the Website and applications.
California Resident Disclosure
The California Consumer Protection Act provides California Residents with specific rights regarding their personal information. This section describes how we treat your personal information in light of the CCPA. As stated above we do not disclose nonpublic personal information about you to nonaffiliated third parties. We do not sell your personal information, and only use your personal information for the following reasons:
- Provide consumer services.
- Comply with the law.
- Carry out internal functions.
Right of Deletion
Consumers have the right to have their information deleted if the information is no longer needed to provide the services they’ve requested. To submit a request to delete all personal information please email AskPrivacy@nelnet.net.
How to Contact Us
If you have any questions about this Policy, please contact us by email or regular mail at the following address:
Nelnet Business Solutions, Inc.
121 South 13th Street, Suite 301
Lincoln, NE 68508
Effective Date: May 25, 2018
PRIVACY NOTICE FOR EUROPEAN UNION RESIDENTS:
Striving to provide superior customer service, Nelnet Business Solutions, Inc. (“Nelnet”, “we”, “our”, or “us”) places great emphasis on its customers and their privacy rights. In doing so, Nelnet will comply with European Union Privacy Directives, most notably the EU General Data Protection Regulation. By providing our services, we may from time to time collect, store, use or process your personal data for legitimate business purposes, such as improving our products and services. Nelnet’s processing of your data is necessary for compliance with its contractual and legal obligations. Personal data means any identifier information, such as your name, social security number, identification number, location data, or other online identifiers and factors.
Although your data is generally stored within the United States, an international data transfer may occur if third party, cloud-based storage companies that Nelnet employs use servers located outside the United States. Nelnet uses appropriate technical and organizational security measures including encryption of personal data and follows various industry standards and best practices to protect your personal data. Additionally, Nelnet requires its vendors and processors to abide by the European Union General Data Protection Regulation and to apply adequate security and technical safeguards. We will not transfer your data to or store your data in countries that have not been awarded an adequacy decision by the European Commission.
For general processing purposes, Nelnet will store your personal data for a period of seven years. However, Nelnet may retain such information for shorter or longer periods where legally required to do so based on industry rules, contractual requirements, or other legal obligations.
You have the right to withdraw consent for processing at any time. Further, you have the right to request access to and rectification, restriction or erasure of your personal data. Nelnet will afford you these rights, but it may not be able to do so where the processing is based on its contractual obligations, based on other legitimate interests, or carried out in the public interest. Along with these rights, if you believe that your data has been mishandled in violation of a privacy directive, you have the right to lodge a complaint with the relevant supervisory authority. If you have questions or concerns about our data processing practices, please address such inquiries to our Data Protection Officer.
Contact Details for Privacy and Data-related Inquiries
Contact Your Educational Institution or Merchant
Chief Compliance Officer