Privacy Policy
Empire State Development (ESD)
Thank you for visiting the Empire State Development ("ESD") websites (hereinafter referred to simply as "website" or “Site”). The website is designed to make it easier and more efficient for individuals and businesses to get information from and, in certain circumstances, to interact with ESD. ESD recognizes the importance of protecting a website visitor's privacy and has taken measures to protect user’s privacy with respect to a visit to this website. By viewing this website, you agree to this Privacy Policy. If you do not agree, you must cease use of this website immediately.
This Privacy Policy covers the following:
-
Who we are
-
Summary of Privacy Policy
-
Information Collected Automatically
-
How we use your information
-
Who may use your information
-
Third-party links and services
-
How we protect your information
-
Where your information is processed
-
Marketing communications
-
How long we keep your information
-
Your rights
-
Contact us
Who We Are
The Site is owned by New York State and operated by Empire State Development (ESD). ESD is the umbrella organization for New York’s two principal economic development entities: The New York State Urban Development Corporation and the Department of Economic Development. You can find out more about ESD here: https://esd.ny.gov/about-us/corporate-info. We refer to ESD as “we”, “us” or “our” in this Privacy Policy.
Consistent with the provisions of the Internet Security and Privacy Act, the Freedom of Information Law, the Personal Privacy Protection Law, the EU General Data Protection Regulation (EU GDPR), the UK General Data Protection Regulation (UK GDPR) and Canada’s Personal Information and Electronic Documents Act (CA PIPEDA), this policy describes ESD's privacy practices regarding information collected from users of this website. This policy describes what information is collected and how that information is used. Because this privacy policy only applies to ESD's website, you would be well advised to examine the privacy policy of any website, including other state agency websites, that you may access.
For the purposes of this policy, "personal information" or “personal data” means any information concerning a natural person which, because of name, number, symbol, mark, or other identifier, can be used to identify that natural person. State Agency website shall have the meaning set forth in section 202 of the New York State Technology Law. User shall have the meaning set forth in section 202 of the New York State Technology Law. ESD does not collect any personal information about you unless you provide that information voluntarily by sending an e-mail, responding to a survey, or completing an on-line transaction. We do not knowingly collect or process data from anyone under the age of sixteen (16) years old.
Summary of Privacy Policy
ESD respects your privacy. ESD will not collect personal identifying information about you when you visit our websites, unless you choose to provide us with that information. Exceptions to this policy are when such information is required for law enforcement investigations or in the case of hackers, or others who might attempt to do harm to ESD's system. ESD will not retain "cookies" beyond the session in which they are obtained. ESD may archive web server activity logs or related summaries at our discretion for an indefinite period to be used to study Site usage and to aid in our efforts to improve all aspects of our sites. ESD will retain e-mail communications long enough to allow us to appropriately respond.
If you do submit personal information and requests via this website, that information may be used only by ESD or its affiliates and only: (1) in the compilation of data for use only by ESD and its affiliates; or (2) to provide you with information or materials about ESD or New York State or to distribute prizes. This information will not be shared with any other organization.
Where appropriate, ESD may add additional terms and conditions of use and privacy for certain interactive events or programs. In such circumstances, access to the additional terms and conditions will be conspicuously displayed.
This Privacy Policy was last updated on October 2022 and applies from that date. We may occasionally amend this Privacy Policy and reserve the right to modify it at any time. Any new policy will automatically be effective when it is published at https://www.iloveny.com/privacy/. You should therefore return to at https://www.iloveny.com/privacy/ regularly to view our most up to date Privacy Policy. You should also print a copy for your records.
Information Collected Automatically When You Visit this Website
When visiting this website ESD automatically collects and stores the following information about your visit:
- User client hostname. The hostname or Internet Protocol address of the user requesting access to a state agency web site.
- HTTP header, "user agent." The user agent information includes the type of browser, its version, and the operating system on which that the browser is running.
- HTTP header, "referrer." The referrer specifies the web page from which the user accessed the current web page.
- System date. The date and time of the user's request.
- Full request. The exact request the user made.
- Status. The status code the server returned to the user.
- Content length. The content length, in bytes, of any document sent to the user.
- Method. The request method used.
- Universal Resource Identifier (URI). The location of a resource on the server.
- Query string of the URI. Anything after the question mark in a URI.
- Protocol. The transport protocol and the version used.
None of the foregoing information is deemed to constitute personal information. The information that is collected automatically is used to improve this website's content and to help ESD understand how users are interacting with the website. This information is collected for statistical analysis, to determine what information is of most and least interest to our users, and to improve the utility of the material available on the website. The information is not collected for commercial marketing purposes and ESD is not authorized to sell or otherwise disclose the information collected from the web-site for commercial marketing purposes.
Personal information we collect is information provided directly by you. This may include:
- Name
- Address
- Phone
- Gender
- Age of Children Under 18
We may use publicly accessible information to verify information we are provided with and to manage and expand our business.
How We Use Your Information
We use information collected about you only as outlined in this Privacy Policy.
Our primary purpose in collecting your personal data is to provide you with the services, products, offers and information you have requested and those which we believe will optimize your use of the Site. We may use your personal data for the following purposes:
• To provide the information, or services, offers or support you request and related after-sales services;
• To identify you by email address and postal code, and contact you from time to time with I LOVE NY tourism and marketing updates (subject to the relevant permissions you provide to us);
• To provide personalized, targeted, or location-based content, services, and marketing from us (subject to the relevant marketing permissions)*;
• To carry out research, including market research, statistical research on campaign effectiveness and site traffic to assist us in improving the services we provide to you and tailor the I LOVE NY events; and
• To keep track of the areas of our Site you visit to enable us to tailor it to better match your interests and/or preferences. This is extracted and downloaded by NYS ESD and or by Simpleview CRM staff as required for testing on behalf of NYS ESD.
We will only process your personal data where we have your consent to do so, which you may withdraw at any time, or otherwise where this is necessary for:
-
The performance of our contract with you for the provision of ESD services or products or to take preliminary steps at your request;
-
Us to fulfill our legal obligations; or,
-
The purposes of the legitimate interests pursued by us or by a third party.
A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests. Our legitimate interests are those where we consider that we have implemented sufficient checks and protections to ensure that your rights and interests are not unreasonably intruded on. However, you can object to processing based on legitimate interests, and if you do so, we will stop processing the personal data unless we can show compelling legitimate grounds which override your rights and interests, or we need the data to establish, exercise or defend legal claims – see “Your rights” at page 9 If you are a user based in Canada, we will only process your personal where we have your consent to do so and not for the purposes of legitimate interest (subject to certain permitted exceptions).
We may disclose your personal data to enforce our policies, to comply with our legal obligations or in the interests of security, public interest or law enforcement in any country where we have entities or affiliates. For example, we may respond to a request by a law enforcement agency or regulatory or governmental authority. We may also disclose data in connection with actual or proposed litigation, or to protect our property, security, people and other rights or interests.
We share your information with NYS ESD staff as determined by NYS ESD, Simpleview CRM staff, Simpleview Marketing Automation Specialist staff, Simpleview Account Services staff and third parties who help deliver our products and services to you. Examples include hosting our web servers, analyzing data, providing marketing assistance, and providing customer service. These companies will have access to your personal information as necessary to perform their functions, but they may not use that data for any other purpose.
A user may opt-out from receiving email communications. The unsubscribe link in email communications offers the recipient a chance to opt-out of marketing email communications. The history of these opt-ins/opt-outs syncs to a database.
Marketing can create email campaigns using synced, contact-based advanced searches. These searches may reside in various user groups within the database.
Information gathered through forms is integrated into a database and can be used to build and manage marketing campaigns. Additionally, email subscriptions are also managed in this database.
More information can be found here.
Cookies
Technologies such as “cookies” are used by ESD and our Site analytics providers such as Google Analytics. Cookies are small pieces of information that are stored by your browser on your computer’s hard drive. Our Site uses “cookies” to help you access our Site. Also, our Site’s cookies help speed up navigation, keep track of items and help to provide you with custom-tailored content. In addition, ESD also uses cookies to remember information that you gave us so you do not have to re-enter it each time you visit our Site. Examples of cookies and other technologies used to collect data include the following:
Purpose |
Type |
Duration |
More Information |
|
Quantcast |
Audience insights and measurements |
Third party |
13 months |
|
Quantcast |
Audience insights and measurements |
First party |
13 months |
|
|
Analytics, translate, and map integrations |
First party |
1 day |
|
|
Analytics, translate, and map integrations |
First party |
2 years |
|
|
Social feeds and sharing |
Third party |
3 months |
|
|
Social feeds and sharing |
First party |
3 months |
|
Disqus |
Commenting on Public Relations Module posts |
First party |
1 year |
|
AddThis |
Social sharing integration |
Third party |
13 months |
|
YouTube |
Serving video content |
Third party |
5 months |
|
Vimeo |
Serving video content |
Third party |
See privacy policy link |
|
Cloudinary |
File storage |
Third party |
See privacy policy link |
|
Act-On |
Marketing automation platform |
Third party |
12 months |
|
Crowdriff |
Social media and user-generated content |
First party |
8 days |
|
Adara - Yield Optimizer Pixel |
Audience insights and measurements |
First party |
2 months |
|
Adara SEM Tag |
Audience insights and measurements |
Third Party |
1 Week |
The cookies we use will only be accessed by us and those third parties named in the table above for the purposes referred to in this part of the Privacy Policy. Those cookies will not be accessed by any other third party.
Purpose
These various technologies are used in analyzing trends, administering the Site, tracking users’ movements around the Site and to gather demographic information about our user base as a whole. We may receive reports based on the use of these technologies on an individual as well as an aggregated basis.
As is true of most websites, we gather some information automatically and store it in system log files. This information includes IP addresses, browser type, Internet service provider, referring/exit pages, operating system, date/time stamp, and clickstream data. We use this information, to analyze trends, troubleshoot system-related issues, to administer the Site, to track users’ movements around the site and to gather demographic information about our user base as a whole.
The cookies are also: used to store content to enable the website owner to provide content directly to the visitor; used internally to improve website performance speed; to store information for visitor login and password protection; to determine whether a visitor has viewed an announcement pop-up; to determine how many times a visitor has viewed, agreed or declined to participate in an exit survey; and to determine whether to display website notifications, or cookie consent notification.
Cookie consent
In most cases we require your consent in order to use cookies on the Site. Exceptions to this apply such as where the cookie is essential in order for us to provide you with a service you have requested (e.g. to enable you to put items in your shopping basket and use our check-out process. If you visit our website when your browser is set to accept cookies, we will interpret this as an indication that you consent to our use of cookies and other similar technologies as described in this Privacy Policy. If you change your mind in the future about letting us use cookies, you can modify the settings of your browser to reject cookies or disable cookies completely.
If you do not want to accept cookies, you can change your browser settings so that cookies are not accepted. If you do this, please be aware that you may lose some of the functionality of this website. For further information about cookies and how to disable them please go for example to the UK Information Commissioner’s webpage on cookies: https://ico.org.uk/for-the-public/online/cookies/.
Information Collected When You E-mail or Complete a Transaction
During your visit to this website you may send an e-mail to ESD. Your e-mail address and the contents of your message will be collected. The information collected is not limited to text characters and may include audio, video, and graphic information formats included in the message. Your e-mail address and the information included in your message will be used to respond to you, to address issues you identify, to improve this website, or to forward your message to another State agency for appropriate action. Your e-mail address is not collected for commercial purposes and ESD will not sell or otherwise disclose your e-mail address for commercial purposes.
During your visit to this website you may complete a transaction such as a survey, registration, or order form. The information, including personal information, volunteered by you in completing the transaction is used by ESD to operate ESD's programs, which include the provision of goods, services, and information. The information collected by ESD may be disclosed by ESD for those purposes that may be reasonably ascertained from the nature and terms of the transaction in which the information was submitted.
Unless for a children's contest, ESD does not knowingly collect personal information from children or create profiles of children through this website. The collection of personal information submitted in an e-mail will always be treated as though it was submitted by an adult or with parental approval and supervision, and may, unless exempted from access by federal or State law, be subject to public access. The Agency strongly encourages parents and teachers to be involved in children's Internet activities and to provide guidance whenever children are asked to provide personal information on-line.
Third-party links and services
The Site may contain links to third parties’ websites. We are not responsible for the privacy practices or the content of those websites. Therefore, please read carefully any privacy policies on those links or websites before either agreeing to their terms or using those websites.
We may also use Google Analytics to gather statistics on site usage. This may involve the use of cookies. There are more details in Google’s own privacy policy. Google may aggregate data they collect from their various services including Google Analytics, Google Translate, Google Maps and YouTube. You acknowledge and accept that we have no control over Google’s data collection. You should look at Google’s privacy policy (available at https://policies.google.com/privacy) for details of their data collection practices. This Privacy Policy and aggregation of data will also apply to any data you choose to share with Google services using the functionality we provide on our Site.
If you have asked us to share data with third party sites (such as social media sites), their servers may not be secure. Our website allows you to connect with a number of social media sites and you should check their privacy policies before submitting your data to them. Those sites include:
- Facebook (privacy policy at https://www.facebook.com/privacy/explanation)
- Twitter (privacy policy at https://twitter.com/en/privacy)
- Instagram (privacy policy at https://help.instagram.com/519522125107875?helpref=page_content)
- Pinterest (privacy policy at https://policy.pinterest.com/en-gb/privacy-policy)
- Google, Gmail & Google+ (see above for more on Google)
- LinkedIn (privacy policy at https://www.linkedin.com/legal/privacy-policy)
- Tumblr (privacy policy at https://www.tumblr.com/privacy)
Note that, despite the measures taken by us and the third parties we engage, the Internet is not secure. As a result others may nevertheless unlawfully intercept or access private transmissions or data.
How We Protect Your Information
We take what we consider to be reasonable appropriate technical and organizational measures to guard against unauthorized or unlawful processing of your personal data and against accidental loss or destruction of, or damage to, your personal data. While no system is completely secure, we believe the measures implemented by the Site reduce our vulnerability to security problems to a level appropriate to the type of data involved.
Where your information is processed
By using this website to sign up to newsletters or alerts or by signing up offline (for example by completing a Customer Information Card) you agree that we may transfer your personal data to countries outside your current location including to or from European Union Nations, the European Economic Area, the United Kingdom, the United States of America, Canada or elsewhere. We will put in place what we consider to be appropriate security measures to safeguard your personal data where any transfer is made. Where your personal data is transferred to us through a vendor, as regards the EU, any transfer of your personal data will be subject to an EU-approved mechanism, and, as regards the UK any transfer of your personal data will be subject to a UK-approved mechanism, whichever is applicable. If we transfer your personal data outside your country we will take steps to ensure that your privacy rights continue to be protected in compliance with applicable data protection law and this Privacy Policy. There is a risk that your personal information may be accessible to foreign law enforcement, regulatory agencies and national security authorities outside your country.
Marketing communications
If you have given us permission, we may contact you by email, about New York State attractions or destinations that may be of interest to you. If you prefer not to receive any direct marketing communications from us, you can opt out at any time [e.g. by using the “Unsubscribe” option in any of the marketing communications we send you or by contacting us]. See further 'Your rights', below.
Retention of Information Collected Through this Web Site
The information collected through this website is retained by ESD in accordance with the records retention and disposition requirements of the New York State Arts & Cultural Affairs Law. Information on the requirements of the Arts & Cultural Affairs Law may be found at http://www.archives.nysed.gov. In general, the Internet services logs of ESD, comprising electronic files or automated logs created to monitor access and use of Agency services provided through this website, will be retained for several backup cycles and then destroyed unless relevant audit, documentation requirements have not been met or unless appropriate review and verification has been completed. Information, including personal information, that you submit in an e-mail or when you complete a survey, registration form, or order form is retained in accordance with the records retention and disposition schedule established for the records of the program unit to which you submitted the information. Information concerning these records retention and disposition schedules may be obtained through the Internet privacy policy contact listed in this policy. We will retain your personal data only as long as is necessary for the purposes set out in this Privacy Policy, or as is required by applicable law, including EU GDPR, UK GDPR and CA PIPEDA, and then we will delete it We maintain procedures for the secure disposal or destruction of personal information.
Disclosure of Information Collected Through This Web Site
The collection of information through this website and the disclosure of that information are subject to the provisions of applicable law, including the Internet Security and Privacy Act, EU GDPR, UK GDPR and CA PIPEDA. ESD will only collect personal information through this website or disclose personal information collected through this web-site if the user has consented to the collection or disclosure of such personal information. The voluntary disclosure of personal information to ESD by the user, whether solicited or unsolicited, constitutes consent to the collection and disclosure of the information by ESD for the purposes for which the user disclosed the information to ESD, as was reasonably ascertainable from the nature and terms of the disclosure.
However, ESD may collect or disclose personal information without consent if the collection or disclosure is: (1) necessary to perform the statutory duties of ESD, or necessary for ESD to operate a program authorized by law, or authorized by state or federal statute or regulation; (2) made pursuant to a court order or by law; (3) for the purpose of validating the identity of the user; or (4) if information to be used solely for statistical purposes that is in a form that cannot be used to identify any particular person.
Further, the disclosure of information, including personal information, collected through this web site is subject to the provisions of the Freedom of Information Law and the Personal Privacy Protection Law.
ESD may disclose personal information to federal or state law enforcement authorities to enforce its rights against unauthorized access or attempted unauthorized access to ESD's information technology assets.
Confidentiality & Integrity of Personal Information
ESD is strongly committed to protecting personal information collected through this website against unauthorized access, use or disclosure. Consequently, ESD limits employee access to personal information collected through this website to only those employees who need access to the information in the performance of their official duties. Employees who have access to this information follow appropriate procedures in connection with any disclosures of personal information in accordance with this Privacy Policy.
In addition, ESD has implemented procedures to safeguard the integrity of its information technology assets, including, but not limited to, authentication, monitoring, auditing, and encryption. These security procedures have been integrated into the design, implementation, and day-to-day operations of this website as part of our continuing commitment to the security of electronic content as well as the electronic transmission of information.
For website security purposes and to maintain the availability of the website for all users, the Agency employs software to monitor traffic to identify unauthorized attempts to upload or change information or otherwise damage this website.
Your Rights
ESD does not collect any personal information about you unless you provide that information voluntarily by sending an e-mail, responding to a survey, or completing an on-line form. You may choose not to send us an e-mail, respond to a survey, or complete an on-line form. While your choice not to participate in these activities may limit your ability to receive specific services or products through this website, it will not normally have an impact on your ability to take advantage of other features of the website, including browsing or downloading information.
As explained above, after you consent to receiving marketing communication from us, you always have the right to opt-out of receiving marketing communications. In addition, if you access this website from an EU member nation, under US, UK or EU law you may have the right to object to the processing of your personal data for direct marketing purposes. If your objection is not to direct marketing in general, but to direct marketing by a particular channel e.g. email or telephone, please specify the channel you are objecting to.
In addition, under US, UK, EU or Canadian law you may have the right to access, correct, delete, restrict, be forgotten, or object to processing of, or request data portability of the personal data collected about you subject to some conditions and exceptions. You can find out more about these rights in the EU by reading the General Data Protection Regulation here: https://gdpr.eu/what-is-gdpr/. You can find out more about these rights in the UK by reading the UK General Data Protection Regulation (UK GDPR) here https://www.legislation.gov.uk/eur/2016/679/contents (please also see the UK Information Commissioner Office’s guidance here https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/). You can find more about these rights in Canada by reading CA PIPEDA here https://laws-lois.justice.gc.ca/ENG/ACTS/P-8.6/index.html.
In addition under US, UK, EU or Canadian law you may also have the right to lodge a complaint with a data protection regulator – in the case of the United Kingdom this is the Information Commissioner’s Office (https://ico.org.uk/); in the case of Canada, this is the Office of the Privacy Commissioner (https://www.priv.gc.ca/en/).
Contact Us
If you wish to enquire about or rely on any of these rights, about this Privacy Policy, the practices of this Site, or your dealings with this Site, we encourage you to contact us at:
Counsel’s Office
Empire State Development,
625 Broadway, Albany, N.Y. 12445
518-292-5120
or send an email with subject title “Privacy Inquiry” to webmaster@esd.ny.gov.
Access to Correction of Personal Information Collected via this Web Site
Any user may submit a request to ESD to determine whether personal information pertaining to that user has been collected through this website. Any such request shall be made in writing and must be accompanied by reasonable proof of identity of the user. Reasonable proof of identity may include verification of a signature, inclusion of an identifier generally known only to the user, or similar appropriate identification. Such requests should be made in writing to:
Counsel’s Office
Empire State Development
Albany, N.Y. 12445
Within five (5) business days of the receipt of a proper request ESD will attempt to provide a response or access to the personal information; deny access in writing, explaining the reasons therefore; or acknowledge the receipt of the request in writing, stating the approximate date when the request will be granted or denied, which date shall not be more than thirty (30) days from the date of the acknowledgment.
In the event that ESD has collected personal information pertaining to a user through the state agency website and that information is to be provided to the user pursuant to the user's request, the privacy compliance officer shall inform the user of his or her right to request that the personal information be amended or corrected under the procedures set forth in section 95 of the Public Officers Law.
Privacy Policy Disclaimer
The information provided in this privacy policy should not be construed as giving business, legal, or other advice, or warranting as failproof, the security of information provided through this website.