A hand pulls open a drawer of an oak library card catalogue
Fig. PRecords kept in order, and only the ones that have a reason to exist.
Doc. 11Privacy policy

This site keeps what an inquiry needs, and says for how long.

This privacy policy covers duke.us.org: the inquiry form, the support chat, the server logs and the advertising tags that run when you allow them. It is written for applicants, parents and visitors to Duke University who want to know what happens to the details they type in.

Document
Privacy policy
Version
1.0
Effective
September 28, 2026
Applies to
duke.us.org

Effective date

This policy takes effect on September 28, 2026, and that is also the date it was last updated. Earlier versions, if any are published, stop applying on that date.

Who runs this site

The site is operated by Duke, trading at duke.us.org. The postal address is BOX 90502 705 BROAD STREET, DURHAM, NC 27708, DURHAM, NC, United States. For the purposes of European data protection law, Duke is the controller of the personal data described here.

What we collect

Less than most sites. There is no account, no password, no payment and no card data, because nothing is sold here and no payment is taken.

From the inquiry form

When you send the form, goza0bc.php writes your name, phone, email, address, the kind of inquiry, your message, the requested specification (the program, term or detail you typed) and your consent tick. With it, automatically, it records your IP address, your browser's user-agent string, the referring URL, the moment the form was rendered and the moment it was sent.

From the support chat

jadi0e5.php keeps the conversation: what you write, what staff reply, and any name, phone or email you choose to give. A token is stored in your browser so you can come back to the same conversation.

Technical and log data

The web server logs each request: IP address, time, the page asked for, the status of the answer and the user-agent string.

Cookie and storage identifiers

Your consent choice is stored in your browser under site_consent_v2. Nothing else on this site persists a choice. If you allow storage, the advertising and measurement tags set their own identifiers; the cookie policy lists each one.

Advertising click identifiers

If you arrive from a paid ad, the link carries a click identifier: gclid from Google, msclkid from Microsoft or fbclid from Meta. It arrives in the address bar and in the referring URL.

What each category is used for

  • Form data: to read your question, route it to the right office and write back.
  • Chat data: to hold the conversation and let you return to it.
  • Rendered and sent times, IP address and user-agent: to spot automated spam. A form filled in two seconds after it loaded is almost always a script.
  • Server logs: to keep the site running and to trace faults and abuse.
  • The consent record: to remember your answer so the banner does not ask on every page.
  • Click identifiers and advertising cookies: to measure whether an ad led to an inquiry, only after you allow it.

We do not sell any of it, and we do not use it to decide anything about an application.

Legal basis for each purpose

PurposeLegal basisNote
Answering your inquiryConsent, and steps you ask for before any agreement (contract)You tick the consent box before sending
Running the support chatConsentYou start the chat yourself
Spam checks and server logsLegitimate interestKeeping the site and inbox usable
Storing your consent choiceLegal obligation and legitimate interestWe must be able to show what you chose
Measurement and advertisingConsentOff until you press Allow

Advertising platforms that send visitors here

This site receives paid traffic today. Google Ads, Microsoft Advertising and Meta Ads run campaigns that link to it. Each platform attaches its own click identifier to the link you click:

  • Google Ads adds gclid.
  • Microsoft Advertising adds msclkid.
  • Meta Ads adds fbclid, where a campaign runs there.

With your permission, the identifier lets the platform connect the click to a later inquiry, so the university can see which ads are worth running. Without your permission, the platform tags run with storage denied and cannot set advertising cookies. No platform has a say in what this policy states.

Consent Mode v2

Before any page content loads, the site sets Google's consent mode defaults. Four signals start at denied: ad_storage, ad_user_data, ad_personalization and analytics_storage. They stay denied until you press Allow in the cookie banner. When you press Decline, or later withdraw consent through Cookie settings in the footer, all four are set back to denied at that moment. While they are denied, tags may send cookieless pings that carry no identifier stored on your device.

Who receives data

  • Google Ireland Ltd / Google LLC, for Google Ads. It attaches gclid to a click and receives the consent signals. Its privacy policy is at policies.google.com/privacy.
  • Microsoft Ireland Operations Ltd, for Microsoft Advertising. It attaches msclkid. Its handling is covered by the Microsoft privacy statement at privacy.microsoft.com.
  • Meta Platforms Ireland Ltd, for Meta Ads. It attaches fbclid where a campaign runs there. Its policy is at facebook.com/privacy/policy.
  • The hosting provider that serves this site and stores the inquiry database.
  • The mail provider that carries the notification of your inquiry to the operator's inbox.

Nobody else. No data broker, no list rental.

Transfers outside the country of collection

The site is run from the United States. If you write from Europe, your data travels to the United States to be answered. The advertising platforms are named above with their Irish entities; they move data between Europe and the United States under the EU-US Data Privacy Framework where they are certified, and under the European Commission's Standard Contractual Clauses otherwise.

How long we keep it

RecordKept for
Inquiries and their email copies36 months
Chat transcripts12 months
Server and access logs30 days
The record of a consent choice12 months

After the period ends the record is deleted, not archived.

How it is protected

Every page is served over HTTPS. The inquiry database sits outside the public web folder and is reachable only by the operator's staff through a password-protected panel. Form input is checked on the server before it is stored, and two hidden fields catch most automated submissions. Staff who read inquiries see what they need to answer them. No system is perfect; if we learn of a breach that affects you, we tell you.

Your rights under the GDPR

If you reach this site from the European Economic Area or the United Kingdom, the GDPR gives you these rights over your data:

  • Access: a copy of what we hold about you.
  • Rectification: correction of anything wrong.
  • Erasure: deletion, where we have no legal reason to keep it.
  • Restriction: we keep it but stop using it while a dispute is settled.
  • Portability: your form data in a common machine-readable file.
  • Objection: to processing we base on legitimate interest.
  • Withdrawing consent at any time, without affecting what was lawful before you withdrew.

Your rights under US state law

US state privacy law applies to this site. In California the CCPA, as amended by the CPRA, gives you the right to know what personal information we collect and why, to delete it, to correct it, to limit use of sensitive information, and to opt out of the sale or sharing of personal information. We do not sell personal information. Sharing a click identifier with an ad platform for cross-context advertising can count as sharing under the CCPA, so you can opt out by pressing Decline, by using Cookie settings, or by sending a Global Privacy Control signal. Residents of the other states with privacy laws in force have similar rights and use them the same way. Exercising a right never changes how your inquiry is answered.

Global Privacy Control

If your browser sends the Global Privacy Control signal (the Sec-GPC header), the site treats it as an opt-out of sale, sharing and advertising storage. It does not ask you again, and the banner's Allow button does not override it on that browser.

Children

This site is not directed at children under 13 and we do not knowingly take data from them. If a child has sent us something, write to [email protected] and we delete it.

Complaints

Tell us first if you can; most problems are fixed faster that way. You also have the right to complain to your state Attorney General, and in California to the California Privacy Protection Agency. Visitors from Europe may complain to the data protection authority of the country where they live.

How to use these rights

Use the data request page, email [email protected], or write to BOX 90502 705 BROAD STREET, DURHAM, NC 27708, DURHAM, NC, United States. Say which right you are using and give the email you wrote from, so we can find the record. We answer within 14 days. We may ask one question to confirm the request is yours before we hand anything over.

Changes to this policy

When the policy changes, the new version goes up on this page with a new version number and effective date in the masthead above. A change that affects how existing data is used is also announced in the cookie banner, which asks for your choice again.

Contact

A person reads every message. Email [email protected], call (919) 684-5600, or write to BOX 90502 705 BROAD STREET, DURHAM, NC 27708, United States. The cookie policy and terms of use sit alongside this document.

Duke, duke.us.orgVersion 1.0, effective September 28, 2026