Data Protection and Privacy Statement & Service Level Agreement
1. Purpose and Scope of the Statement
This statement explains the principles, policies, and procedures of Persian Gulf University regarding the protection of users' personal information and privacy, as well as the level of services provided through the university's website and electronic systems.
The purpose of this statement is to provide transparency regarding the collection, processing, use, storage, and protection of information and to clarify the rights and responsibilities of users and the university.
2. Legal Basis and the University's Commitment
Persian Gulf University is committed to protecting users' privacy and information in accordance with applicable laws, regulations, policies, and administrative requirements.
In this regard, the university observes the relevant provisions concerning information protection, privacy, electronic services, and protection of users' information, including Article 7 of Resolution No. 1127128 of the Supreme Administrative Council dated 28/12/1395, to the extent applicable.
The university seeks to collect and process information only to the extent necessary for providing services, fulfilling legal and administrative obligations, improving services, and ensuring the security and proper operation of its systems.
3. Purposes of Data Collection and Processing
Information may be collected and processed for purposes including, but not limited to:
- Providing and managing electronic and administrative services.
- Communicating with users and responding to their requests.
- Sending service-related notifications and messages.
- Managing educational and academic records and services.
- Providing legal and administrative services where necessary.
- Improving the quality, performance, security, and usability of services.
- Preparing statistical and analytical reports for service improvement.
- Preventing misuse, unauthorized access, and security incidents.
4. Types of Information That May Be Collected
Depending on the type of service used, the following categories of information may be collected:
- Identity information: such as name, surname, national identification information, student or personnel identification information, where required.
- Contact information: such as telephone number, mobile number, email address, and other information required for communication.
- Hardware and device information: including information related to the device used to access the university's services.
- Software and browser information: including operating system, browser type and version, and technical information required for service operation.
- Technical information: such as IP address, access date and time, referring page, and information related to the user's interaction with the website.
5. Cookies and Similar Technologies
The university's website and electronic services may use cookies and similar technologies to maintain user sessions, remember preferences, improve the user experience, analyze website usage, and enhance the security and performance of services.
Users may manage or restrict cookies through their browser settings. However, disabling certain cookies may affect the proper functioning of some services.
6. Use and Retention of Information
Information collected through the university's electronic services is used only for legitimate purposes related to the provision, management, security, and improvement of services or for fulfilling legal and administrative obligations.
Depending on the nature of the information and the applicable requirements, information may be retained for as long as necessary to fulfill the relevant purpose or legal, administrative, and operational requirements.
The university takes reasonable measures to prevent unauthorized access, modification, disclosure, loss, or destruction of information.
7. Information Security and Protection
Persian Gulf University takes appropriate technical, administrative, and organizational measures, within its available capabilities, to protect information against unauthorized access, misuse, alteration, disclosure, loss, or destruction.
Access to information is managed according to operational, administrative, and security requirements, and access to information is limited to authorized individuals and systems to the extent necessary.
8. Service Level Agreement
Persian Gulf University seeks to provide high-quality, reliable, and accessible electronic services to users. This Service Level Agreement describes the general principles governing the provision of services, methods for monitoring service quality, and the responsibilities of the university and users.
The university continuously monitors the availability and proper operation of its electronic services and makes reasonable efforts to maintain service continuity.
The university's website and electronic services are intended to remain available continuously, subject to the availability of telecommunications infrastructure, internet connectivity, hosting infrastructure, and other technical dependencies.
In the event of technical problems, maintenance, infrastructure failures, or circumstances beyond the university's control that affect service availability, appropriate measures will be taken to restore services as soon as reasonably possible.
9. Requests, Complaints, and User Feedback
Users may submit their requests, comments, suggestions, or complaints through the communication channels provided on the university's website.
Users may use the Contact Us section of the university website to communicate their requests and feedback.
Where a request is registered through a system that provides a tracking code or password, users should retain the relevant information in order to follow up on the status of their request.
For correspondence registered through the university's administrative correspondence system, users may use the relevant tracking facilities provided by the university.
10. Sharing and Disclosure of Information
Personal information will not be disclosed to third parties except where disclosure is necessary for providing a requested service, fulfilling legal or administrative obligations, protecting the security of systems and users, or where disclosure is otherwise permitted or required by applicable laws and regulations.
Where information must be shared with service providers or authorized entities for operational purposes, appropriate measures will be taken to ensure that such information is handled within the applicable requirements and purposes.
11. User Rights
Subject to applicable laws, regulations, technical limitations, and the nature of the relevant service, users may have the following rights:
- To be informed about the purposes for which their information is collected.
- To request access to their personal information where applicable.
- To request correction of inaccurate or incomplete information.
- To withdraw consent where processing is based on consent and withdrawal is legally and technically possible.
- To request cessation of information sharing where applicable.
- To request deletion of information where there is no legal or operational requirement for its retention.
- To submit questions, requests, or complaints through the university's available communication channels.
12. User Responsibilities
Users are responsible for protecting their usernames, passwords, authentication information, and other access credentials and must not disclose them to unauthorized persons.
Users are also responsible for ensuring that the information they provide to the university is accurate and up to date and for using electronic services in accordance with applicable laws, regulations, and university policies.
13. Limitation of Liability
The university makes reasonable efforts to ensure the availability, accuracy, security, and continuity of its electronic services. However, service interruptions or limitations may occur due to technical failures, telecommunications infrastructure, internet service disruptions, cyber incidents, force majeure, or other circumstances beyond the university's reasonable control.
Accordingly, the university cannot guarantee uninterrupted availability of all services under all circumstances and will take reasonable measures to restore affected services and minimize their impact.
14. Changes to This Statement
Persian Gulf University may update or revise this statement when necessary due to changes in laws and regulations, technical developments, changes in services, or improvements to information protection and privacy practices.
The latest version of this statement will be published on the university website, and users are encouraged to review it periodically.
Important: The information provided in this statement describes the general principles governing data protection, privacy, and electronic service provision at Persian Gulf University. Specific services may have additional terms, procedures, or requirements that will be communicated to users where applicable.
Contact Information
For questions, requests, suggestions, or complaints concerning privacy, information protection, or electronic services, users may contact Persian Gulf University through the communication channels available on the university website.