PRIVACY POLICY
Who We Are
​
Since 1993, Doody Enterprises has been the most trusted source of timely, expert reviews of newly published books, print and electronic, in the health sciences. We specialize in timely, targeted information update services for health sciences librarians that combine customized weekly literature update emails with content-rich websites.
To provide these unique information services, Doody Enterprises has forged successful relationships with more than 250 book publishers in the health sciences and established a network of approximately 8,500 academic health sciences professionals as expert reviewers.
Health sciences librarians around the world rely on the comprehensive bibliographic and evaluative information in our comprehensive database of health sciences books to help guide their collection development decisions Further, dozens of healthcare societies, institutions, publishers and book intermediaries have purchased site licenses to our content.
This privacy policy applies to all visitors and customers using or accessing any of the websites that we produced and maintain for the services that we provide, including Doody’s Core Titles (DCT), Doody’s Review Service (DRS), and Doody’s Collection Development Monthly (DCDM). It also applies to all other services that we provide and to human resources data of our employees and contractors.
Doody Enterprises Inc. is a registered corporation in Illinois, USA. Our mailing address is:
Doody Enterprises, Inc.
1100 Lake Street, Suite 202
Oak Park, IL 60301
USA
For any privacy-related questions, you can reach us at csr@doody.com.
​
Who We Share Your Data With
​
We use a third-party service to process payment information when your place a credit card order on DCT or DRS. We provide them with your payment method, email address, name and billing address in order to authorize your payment. Other than this, we do not use third-party services (data processors) on any of our sites. We do not share personal information with any other third-party in our normal course of business.
​
We may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.
​
If we ever were to engage in any onward transfers of your data with third parties for a purpose other than which it was originally collected or subsequently authorized, we would provide you with an opt-out choice to limit the use and disclosure of your personal data.
​
Cookies
​
A cookie is a string of information that a website stores on a visitor’s computer, and that the visitor’s browser provides to the website each time the visitor returns. We use cookies across our sites to help identify and track visitors, their usage of our services, and their website access preferences. We describe the specific cookies used in the sections below. Visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using our websites, with the drawback that certain features may not function properly without the aid of cookies.
What Personal Data We Collect And Why We Collect It
General Statement
Doody Enterprises, Inc. collects and uses your personal information to operate the Doody Enterprises, Inc. web sites and deliver the services you have requested. Doody Enterprises, Inc. also uses your personally identifiable information to inform you of other products or services available from Doody Enterprises, Inc. and its affiliates. Doody Enterprises, Inc. may also contact you via surveys to conduct research about your opinion of current services or of potential new services that may be offered. Doody Enterprises, Inc. does not sell, rent or lease its customer lists to third parties. Doody Enterprises, Inc. may, from time to time, contact you on behalf of external business partners about a particular offering that may be of interest to you. In those cases, your unique personally identifiable information (e-mail, name, address, telephone number) is not transferred to the third party.
Doody Enterprises, Inc. will occasionally update this Statement of Privacy to reflect company and customer feedback. Doody Enterprises, Inc. encourages you to periodically review this Statement to be informed of how Doody Enterprises, Inc. is protecting your information.
Registered Users
​
-
If you create an account on one of our sites, you will be prompted to select a Username and provide your Email Address.
-
When choosing a Username, we strongly advise you not use or include your real name. Usernames cannot bechanged.
-
Your Username and Email Address are stored in the website’s database. Your Email Address is used to send you an email with a link to set your password or to send you an email with a link to reset your password in the event you forget your password. We also use your Email Address to send periodic informational messages.
-
Once an account is created, you must contact us to have it deleted.
-
Accounts have a numeric User ID assigned to them when they are created. The User ID cannot be changed.
-
You may complete your Profile by providing your First Name, Last Name, and/or Affiliation info. These additional details are also saved in the website’s database. For the DRS web site, you may edit these details, and your Email Address, in your Profile at any time.
-
Your Username, First Name, Last Name and Email Address are accessible by our employees on an administrative site.
-
If you attempt to log in to our site, we will set a temporary cookie to determine if your browser accepts cookies at all. This cookie contains no personal data and is discarded when you close your browser.
-
If you have an account and you log in to a site, we will set up several cookies to save your login information and some of your screen options. The logged-in cookies last for two days, and the screen options cookies last for a year.
-
If you select “Remember Me” these cookies will persist for two weeks. If you log out of your account, the login cookies will be removed. It is important that you log out if you are using a public computer.
-
For DRS users that register on the DRS sites, we also store the data they provide in their profile indefinitely, as well as any lists they create and store in the DRS website’s List Manager function. All registered users can see, change or delete most of that data at any time except their login name/nickname.
​
Email/Chat/Contact Forms
​
-
We use Microsoft Office 365 to process all internal email and communication with our customers.
-
Customers that email us or use any of the contact forms on our websites, will have their email address, IP address, and any data provided in the contact form or body of the email stored in Office 365 archives.
-
We keep most email communication indefinitely to help us provide support and improve our services. Individuals can request copies of any previous correspondence with us at any time.
​
Analytics
​
-
We use a proprietary, in-house analytics engine to compile anonymous activity and statistics reporting.
-
We use Google Analytics for tracking visitors and aggregating information about the traffic to our websites. The Google Analytics privacy policy can be found here: https://policies.google.com/privacy. You can learn more about how to opt-out of tracking in Google Analytics here.
​
Marketing Campaigns
​
-
We use email to communicate important content updates to subscribers on regular, scheduled basis.
-
We may send you “system” emails, such as password reset requests, renewal notifications, or payment notifications/receipts even if you have not opted-in to email marketing lists.
-
All emails sent by us will include an unsubscribe link in the footer of the email. Emails sent to you may also include standard tracking, including open and click activities.
-
We use a third-party service for some email marketing to everyone who has opted-in to our email marketing, Constant Contact. Constant Contact’s privacy policy is found here.
-
We may utilize social media and web advertising campaigns. These service providers use cookies on our sites and/or pixel tracking to serve ads across the different platforms.
-
Google AdSense & DoubleClick (privacy policy| opt out)
-
Twitter (privacy policy| opt out)
-
Facebook (privacy policy| opt out)
-
Paying Customers
​
-
For credit card payment transactions, we use Blue Pay. Blue Pay’s privacy policy can be found here.
-
To comply with accounting and legal requirements, we keep data on financial transactions in the systems above for up to 10 years.
Hosting
​
-
All web servers and hosting are managed by our team on private servers located in St. Louis, MO. This includes website hosting, backups, web database, file storage, and log files.
What Rights You Have Over Your Data
​
If you are a registered user on our site you can request to see or download the data we have about you.
For registered users or paying customers, this will also include profile information and download, payment, and support ticket histories.
You can also request “to be forgotten” and we will erase any personally identifiable data we have about you. Of course, this excludes data we need for administrative or security purposes or if we are required by law to retain some of the data.
An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data, should direct his/her query to csr@doody.com. We will respond within a reasonable timeframe, not to exceed one week.
How We Protect Your Data
The security and reliability of our service is our number one priority. We invest heavily in the training of our staff and our infrastructure to ensure that best practices are followed in everything that we do.
​
-
Every Doody Enterprises employee and contractor goes through background checks and an onboarding process that includes a trial period where access to customer data is provided only when working directly under the supervision of another staff member.
-
All staff only have access to systems that are directly required to complete the functions of their job.
-
All staff (including any contractors) undergo initial training to ensure proper understanding of all security-related processes. Staff regularly attend industry conferences and otherwise stay informed of best practices and relevant trends.
-
We only use third-party services that are fully vetted and adhere to the highest levels of privacy and security practices.
What Data Breach Procedures We Have In Place
​
Should any event occur where customer data has been lost, stolen, or potentially compromised, our policy is to alert our customers via email no later than 48 hours of our team becoming aware of the event. We will also report such incident to any required data protection authority. We will work closely with any customers affected to determine next steps such as any end-user notifications, needed patches, and how to avoid any similar event in the future.