Effective Date: 17 January 2018
We at OneTrust LLC and OneTrust Technology Limited (collectively, “OneTrust,” “we” and “us”) know you care about how your personal information is used and shared, and we take your privacy seriously. Please read the following to learn more about how we collect, store, use and disclose information about you when you interact or use our websites (collectively the “Websites”) or any related events, trade shows, sales or marketing, and/or if you use any of our products, services or applications (including any trial) (collectively the “Services”) in any manner.
What information does OneTrust Collect?
Information You Provide to Us:
When you use the Websites: We may collect any Personal Information that you choose to send to us or provide to us, for example, on our “Request a Demo” (or similar) online form or if you register for a OneTrust webinar. If you contact us through the Websites, we will keep a record of our correspondence.
When you use the Services: We receive and store information you provide directly to us. For example, when setting up new users, we collect Personal Information, such as name and e-mail address, to provide them with Services. The types of information we may collect directly from our customers and their users include: names, usernames, email addresses, postal addresses, phone numbers, job titles, transactional information (including Services purchased), as well as any other contact or other information they choose to provide us or upload to our systems in connection with the Services.
Information We Automatically Collect:
When you use the Websites: When you visit the Websites, we collect certain information related to your device, such as your device’s IP address, referring website, what pages your device visited, and the time that your device visited our Website.
When you use the Services: Usage information – we keep track of user activity in relation to the types of Services our customers and their users use, the configuration of their computers, and performance metrics related to their use of the Services. Log information – we log information about our customers and their users when you use one of the Services including Internet Protocol (“IP”) address. Information collected by cookies and other similar technologies – we use various technologies to collect information which may include saving cookies to users’ computers.
For further information, please see the section below headed “Cookies and other Tracking Technologies”.
How do we use the information?
Websites: We will use the information we collect via our Websites:
- To administer our Website, our events and for internal operations, including troubleshooting, data analysis, testing, statistical and survey purposes;
- To improve our Website to ensure that content is presented in the most effective manner for you and for your computer;
- Analyze customers’ use of the Websites for trend monitoring, marketing and advertising purposes;
- For purposes made clear to you at the time you submit your information – for example, to fulfill your request for a demo, to provide you with access to one of our webinar’s or whitepaper’s or to provide you with information you have requested about our Services; and
- As part of our efforts to keep our Website safe and secure.
Services: We may use the information we collect from our customers and their users in connection with the Services we provide for a range of reasons, including to:
- To set up a user account,
- Provide, operate and maintain the Services;
- Process and complete transactions, and send related information, including transaction confirmations and invoices;
- Manage our customers’ use of the Services, respond to enquiries and comments and provide customer service and support;
- Send customers technical alerts, updates, security notifications, and administrative communications;
- Investigate and prevent fraudulent activities, unauthorized access to the Services, and other illegal activities; and
- For any other purposes about which we notify customers and users.
We may also use the information you send to us via the Websites and/or Services, to communicate with you via email and, possibly, other means, regarding products, services, offers, promotions and events we think may be of interest to you or to send you our newsletter, if this is in accordance with your marketing preferences. However, you will always be able to opt-out of such communications at any time (see the “Your Choices” section below).
How do we share and disclose information to third parties?
We do not rent or sell your Personal Information to anyone. We may share and disclose information (including Personal Information) about our customers in the following limited circumstances:
Vendors, consultants and other service providers: We may share your information with third party vendors, consultants and other service providers who we employ to perform tasks on our behalf. These companies include (for example) our payment processing providers, website analytics companies (e.g., Google Analytics), product feedback or help desk software providers (e.g. ZenDesk), CRM service providers (e.g., Salesforce), email service providers (e.g., Sendgrid) and others.
If OneTrust has received your Personal Information in the United States and subsequently transfers that information to a third party agent or service provider for processing, OneTrust shall remain responsible for ensuring that such third party agent or service provider processes your Personal Information to the standard required by our Privacy Shield commitments (see the sections below headed “Additional Information for Users in the European Economic Area (“EEA”)” and “International Data Transfers”). Unless we tell you differently and you consent, our agents do not have any right to use the Personal Information we share with them beyond what is necessary to assist us.
Business Transfers: We may choose to buy or sell assets, and may share and/or transfer customer information in connection with the evaluation of and entry into such transactions. Also, if we (or our assets) are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Information could be one of the assets transferred to or acquired by a third party.
Protection of OneTrust and Others: We reserve the right to access, read, preserve, and disclose any information as necessary to comply with law or court order; enforce or apply our agreements with you and other agreements; or protect the rights, property, or safety of OneTrust, our employees, our users, or others.
Disclosures for National Security or Law Enforcement: Under certain circumstances, we may be required to disclose your Personal Information in response to valid requests by public authorities, including to meet national security or law enforcement requirements.
Is Personal Information about me secure?
We use appropriate technical, organizational and administrative security measures to protect any information we hold in our records from loss, misuse, and unauthorized access, disclosure, alteration and destruction. Unfortunately, no company or service can guarantee complete security. Unauthorized entry or use, hardware or software failure, and other factors, may compromise the security of user information at any time. Among other practices, your account is protected by a password for your privacy and security. You must prevent unauthorized access to your account and Personal Information by selecting and protecting your password appropriately and limiting access to your computer or device and browser by signing off after you have finished accessing your account.
Cookies and other tracking technologies
- Assisting you in navigation;
- Assisting in registration, login, and your ability to provide feedback;
- Analyzing your use of our products, services or applications; and
- Assisting with our promotional and marketing efforts (including behavioral advertising).
We also may use clear gifs in HTML-based emails sent to our users to track which emails are opened by recipients. This information is used to enable more accurate reporting, improve the effectiveness of our marketing, and make our Services and Websites better for our users.
Your Privacy Rights
What choices do I have?
You can always opt not to disclose information to us, but keep in mind some information may be needed to register with us or to take advantage of some of our features.
If you have any account for our Services, we will still send you non-promotional communications, like service related emails.
How can I update and access my information (Exercise my Data Subject Rights)?
Our Privacy team will examine your request and respond to you as quickly as possible!
Please note that we may still use any aggregated and de-identified Personal Information that does not identify any individual, and may also retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
California residents are entitled to ask us for a notice identifying the categories of Personal Information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this notice, please submit a written request to: [email protected]
If you are a resident of the European Economic Area, please see the section below headed “Additional Information for users in the European Economic Area” for further information about your privacy rights.
International Data Transfers
International Data Transfers – Additional information for users in the European Economic Area (“EEA”)
OneTrust is self-certified to the EU-US Privacy Shield Framework
This section sets out the privacy principles we follow with respect to transfers of Personal Information from the EEA to the United States, including Personal Information we receive from individuals residing in the EEA who visits our Websites and/or who may use of our Services or otherwise interact with us.
Please note that for users located in the EEA, the term Personal Information used in this policy is equivalent to the term “personal data” under applicable European data protection laws.
To learn more about the Privacy Shield program, see the US Department of Commerce’s Privacy Shield website located at https://www.privacyshield.gov. To view our certification on the Privacy Shield list, please visit https://www.privacyshield.gov/
Director of Privacy
We will investigate and attempt to resolve any complaints or disputes regarding the use or disclosure of personal data within 45 days of receiving your complaint. OneTrust LLC has further committed to refer unresolved privacy complaints under the EU-U.S. Privacy Shield Principles BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers/ for more information and to file a complaint.
Under certain limited circumstances, individuals in the EEA may invoke binding Privacy Shield arbitration as a last resort if all other forms of dispute resolution (discussed above) have been unsuccessful. To learn more about this method of resolution and its availability to you, please visit https://www.privacyshield.gov/.
OneTrust LLC is subject to the jurisdiction of the U.S. Federal Trade Commission for purposes of Privacy Shield enforcement.
Please note that OneTrust LLC is required to disclose Personal Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
OneTrust is self-certified to the Swiss-U.S. Privacy Shield Framework
Director of Privacy
OneTrust has further committed to refer unresolved privacy complaints under the Swiss-US Privacy Shield Principles to an independent dispute resolution mechanism, the BBB EU PRIVACY SHIELD, operated by the Council of Better Business Bureaus. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit http://www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and to file a complaint.
Under certain limited circumstances, individuals in Switzerland may invoke binding Privacy Shield arbitration as a last resort if all other forms of dispute resolution (discussed above) have been unsuccessful. To learn more about this method of resolution and its availability to you, please visit https://www.privacyshield.gov/.
California and Delaware “Do Not Track” Disclosures
We do not knowingly collect or solicit personal information from anyone under the age of 13. If you are under 13, please do not attempt to register for the Services or send any Personal Information about yourself to us. If we learn that we have collected Personal Information from a child under age 13, we will delete that information as quickly as possible. If you believe that a child under 13 may have provided us Personal Information, please contact us at [email protected].
What if I have questions about this policy?
If you have any questions or concerns regarding our privacy policies, please send us a detailed message to [email protected], and we will try to resolve your concerns.
© 2018 OneTrust, LLC. All Rights Reserved.