Privacy Notice

This Privacy Notice explains how the Board of Governors collects, uses, maintains, and protects information through the Blevins Legislative Docket Manager, including its legislative information website, agenda tools, records access features, staff workflows, and related online services, collectively referred to as the “System” or “Site.”

The System is provided to support public access to legislative records, Board actions, agenda materials, meeting information, and related governance records. By using the System, you acknowledge the practices described in this Privacy Notice.

1. Scope of This Notice

This Privacy Notice applies to information collected through the System. It does not apply to third-party websites, external services, or other systems that may be linked from the System unless expressly stated.

Because the System supports legislative transparency and public recordkeeping, some information available through or submitted to the System may be public by law, policy, or official Board practice.

2. Information We Collect

A. Public Legislative Records

The System publishes legislative and governance-related information that is public by nature or made public through Board action, law, policy, or administrative process. This may include, but is not limited to:

  1. Board members;

  2. Sponsors;

  3. Co-sponsors;

  4. Agenda items;

  5. Ordinances;

  6. Resolutions;

  7. Policies;

  8. Meeting agendas;

  9. Meeting minutes;

  10. Votes;

  11. Action summaries;

  12. Staff reports;

  13. Public notices;

  14. Attachments;

  15. Public hearing materials, when applicable;

  16. Committee materials;

  17. Public comments, when applicable; and

  18. Other records related to Board legislative activity.

These records may be retained, archived, indexed, searched, downloaded, or disclosed in accordance with applicable public records and records-retention requirements.

B. Account Information

Certain features of the System are available only to authorized Board members, staff, administrators, contractors, vendors, or other approved users.

For authorized users who sign in, the System may receive limited account information from the user’s organization through single sign-on, including Microsoft Entra ID. This information may include:

  1. Name;

  2. Email address;

  3. Username or user principal name;

  4. Organization or department;

  5. Assigned role or group membership;

  6. Authentication status;

  7. Account identifier; and

  8. Other identity claims necessary to confirm access rights.

The System uses this information to identify the user, assign permissions, maintain account security, and support authorized legislative workflows.

The System does not receive or store the user’s Microsoft Entra ID password.

C. Technical and Security Information

When you access or use the System, certain technical information may be collected automatically to operate, secure, troubleshoot, and improve the System. This may include:

  1. IP address;

  2. Browser type and version;

  3. Device type;

  4. Operating system;

  5. Referring page or link;

  6. Date and time of access;

  7. Pages or records requested;

  8. Session identifiers;

  9. Login and logout activity;

  10. Error messages;

  11. Security events;

  12. Audit logs;

  13. System performance data; and

  14. Other basic request or diagnostic information.

This information is used for security, auditing, compliance, troubleshooting, system administration, and operational reliability.

D. Submitted Information

If the System allows users to submit information, upload materials, enter comments, manage agenda items, update workflows, or submit records, the System may collect the information provided by the user.

Submitted information may become part of the Board’s records and may be subject to disclosure, retention, review, publication, or archival requirements.

Users should not submit confidential, privileged, personal, sensitive, or protected information unless they are authorized to do so and the System specifically permits such submission.

3. How We Use Information

The Board of Governors uses information collected through the System to:

  1. Publish legislative records and Board materials;

  2. Provide public access to agenda items, meetings, votes, policies, ordinances, resolutions, and related records;

  3. Authenticate authorized users;

  4. Manage user roles, permissions, and access rights;

  5. Support agenda preparation and legislative workflow management;

  6. Maintain security and prevent unauthorized access;

  7. Monitor System performance and availability;

  8. Troubleshoot technical issues;

  9. Maintain audit logs and administrative records;

  10. Comply with records-retention, public records, open meeting, legal, audit, and administrative requirements;

  11. Protect the integrity of legislative records;

  12. Respond to user questions, support requests, or security concerns; and

  13. Improve System reliability and usability.

The Board of Governors does not sell personal information.

The System is not used for advertising or cross-site behavioral tracking.

4. Single Sign-On and Microsoft Entra ID

Authorized user sign-in is handled through Microsoft Entra ID or another approved organizational identity provider.

When a user signs in, the identity provider authenticates the user and sends the System only the identity claims needed to match the user to an authorized account and assigned role. These claims may include the user’s name, email address, account identifier, and role or group information.

The System does not receive, collect, or store the user’s Microsoft Entra ID password.

Users are responsible for protecting their organizational credentials and reporting suspected unauthorized access, credential compromise, or account misuse to the appropriate administrator.

5. Cookies and Session Management

The System uses a session cookie or similar session technology to keep authorized users signed in and to maintain a secure session while they use the System.

The session cookie is used for authentication, security, and basic System functionality. It is not used for advertising, marketing, or cross-site tracking.

Session cookies may expire automatically after a period of inactivity, logout, browser closure, or another security event.

Users may configure their browsers to limit or block cookies, but doing so may prevent certain System features from working properly.

6. Public Records and Disclosure

The System exists in part to provide public access to legislative records. Information published through the System may be publicly accessible, searchable, downloadable, retained, archived, or disclosed as part of the Board’s official or public records.

Information submitted through the System may also be subject to disclosure under applicable public records, transparency, open meeting, archival, audit, or records-retention laws.

The Board of Governors may disclose information when required or permitted by law, policy, subpoena, court order, audit, investigation, public records request, security review, or administrative process.

7. Data Retention

Legislative records are retained in accordance with applicable records-retention schedules, archival requirements, Board policy, and legal obligations.

Account records, access logs, audit logs, security logs, and technical data may be retained for the period necessary to support security, operations, compliance, auditing, troubleshooting, and administrative needs.

Session data generally expires automatically according to System settings, security controls, or logout events.

The retention period for a particular record may depend on the type of record, legal requirements, Board policy, administrative need, and whether the information is part of an official legislative record.

8. Security

The Board of Governors uses reasonable administrative, technical, and physical safeguards designed to protect the System and information processed through it.

These safeguards may include access controls, role-based permissions, authentication, audit logging, encryption, monitoring, session controls, vendor controls, and administrative review.

However, no website, online service, or information system can be guaranteed to be completely secure. Users should use reasonable caution, protect their credentials, avoid sharing accounts, and promptly report suspected security incidents.

9. Access Controls for Authorized Users

Authorized users may receive access based on their role, department, office, committee assignment, administrative responsibility, or other approved purpose.

Access rights may be reviewed, changed, suspended, or removed to protect security, comply with policy, reflect role changes, or support System administration.

Users may only access information and features they are authorized to use. Unauthorized access, attempted access, credential sharing, or misuse of restricted information may result in suspension of access, administrative action, investigation, or other appropriate response.

10. Third-Party Services

The System may use or link to third-party services, including identity providers, hosting providers, document viewers, analytics or logging tools, accessibility tools, streaming services, or other operational vendors.

Third-party services may collect or process information according to their own terms, privacy notices, security practices, or contractual obligations.

The Board of Governors is not responsible for the privacy or security practices of third-party websites or services that are not controlled by the Board.

11. Children’s Privacy

The System is intended for public access to legislative records and for use by authorized Board-related users. It is not designed to collect personal information from children.

Users should not knowingly submit personal information about minors unless authorized and appropriate under applicable law, Board policy, or official procedure.

12. User Responsibilities

Users are responsible for:

  1. Using the System lawfully and appropriately;

  2. Protecting login credentials;

  3. Avoiding submission of unnecessary sensitive information;

  4. Reporting suspected security incidents;

  5. Ensuring submitted information is accurate and authorized;

  6. Following applicable Board policies and procedures; and

  7. Understanding that submitted or published information may become part of the public record.

13. Changes to This Privacy Notice

The Board of Governors may update this Privacy Notice at any time.

Updated notices may be posted on the System or otherwise made available. Continued use of the System after an updated notice is posted indicates acknowledgment of the revised notice.

Users should review this Privacy Notice periodically.

14. Contact Information

Questions about this Privacy Notice, public records, legislative records, agenda materials, account access, accessibility, corrections, or System use may be directed to the Office of the Clerk of the Board or other designated Board office.

Technical questions about login, authentication, account access, security, or System functionality may be directed to the designated System administrator or support contact.

15. Legal Review

This Privacy Notice is provided as a general administrative template and is not legal advice. It should be reviewed and approved by qualified legal counsel before adoption, publication, or reliance.