Effective Date: July 26, 2019
Please feel free to address any questions or concerns regarding data privacy to our Data Protection Officer (DPO) at firstname.lastname@example.org or at
49 Geary Street #238
San Francisco, CA 91408
CLASSIFICATION OF USERS
There are three (3) types of users who may be connected to our services.
“Visitors” are people who visit our Site without logging on or requesting information.
“Customers” are persons who, on behalf of themselves or an entity request information from us regarding SaaS or related services or use of Services via log-on to our Site either for a limited time free trial or by purchasing the SaaS we offer.
END USER INFORMATION
In the course of Customers using our Services, their customers, members, contractors or employees (“End Users”) may provide personally identifiable information using the Services End User data from customers or users of our customer’s services is under the control of the Customer, who is the data controller.
End User information which may be considered personal data will be governed by our Master Agreement and Schedules providing the SaaS to our Customers who are the data controllers and who instruct us how to process the data or use the SaaS to process the data they collect. However, for entities or individuals that are Customers, and which are located in the European Economic Area (EEA) or Switzerland or serving subjects located in the European Economic Area (EEA) or Switzerland, we will govern our use of End User Data based on the execution of a Data Processing Addendum or other written agreement incorporating EU Standard Contractual Clauses.
END USER DATA SUBJECT REQUESTS
Individuals who have provided information to Contentstack’s Customers must send requests regarding the exercise of their digital rights under the General Data Protection Regulation (GDPR) and state implementing laws to the particular Contentstack Customer who is the data controller.
Contentstack may collect information automatically using web tracking technologies such as cookies, web beacons, pixel tags, clear GIFs and third party tracking services in order to ensure that the Sites and Services operate efficiently and to collect data related to usage of the Sites and Services such as, but not limited to, the browser type, language preference, referring site, and the date and time of each visitor request (“Tracking Information”).
We use both session-based and persistent cookies. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire. They are unique and allow us to do site analytics and customization, among other similar things. If you access our Site through your browser, you can manage your cookie settings.
Contentstack does not link Tracking Information to individual user Personal Information; nor does it include the Personal Information with the Tracking Information that Contentstack shares with the web tracking companies that use and process the Tracking Information without your consent, except as strictly necessary to provide and improve the Services (including customer support services). Some Tracking Information may include log or other data, such as IP address data, that is unique to you. You may be able to modify your browser settings to alter which web tracking technologies are permitted when you use the Sites and Services, but this may affect the performance of the Sites and Services.
POTENTIALLY IDENTIFYING DATA
We collect the IP Addresses of Visitors and Customers, which is, for account Users, and visitors that make inquiries, linked with users either through cookies, or for those Customers who log on to our Site to use the SaaS.
Customers who access Contentstack's Sites or use the SaaS choose to interact with Contentstack in ways that require Contentstack to gather personally-identifying information such as name, address (email or physical),credit card billing information, username, passwords. The amount and type of information that Contentstack gathers depends on the nature of the interaction.
We ask Visitors who sign up for an account at Contentstack or who have questions to provide a username and email address.
Those who engage in transactions with Contentstack by purchasing access to the Contentstack platform to use the SaaS or sign up for a trial period - are asked to provide name, address and additional payment and billing information (e.g. purchase order or bank information) and user name and password. Once signed up and the SaaS is purchased, Customer employees or contractors given access to the Services on behalf of a Customer will be asked to provide their name and email address and a password.
We also collect Customer content and track Customer usage of the SaaS and other Services as part of the Services.
HOW WE USE YOUR INFORMATION
For Visitors, if you do not purchase the SaaS but want information, we use your contact information to follow up on your request. We may also ask your consent to communicate with you regarding the provision of services or notify you about new services, changes and improvements.
To Provide the Services
With respect to our Customers and their account users, Contentstack does not disclose personal identifying information for marketing purposes other than as described below. We use such personal data, as well as Tracking Information connected with your personal data for purposes of account and services administration and providing the Services. We link IP Addresses with cookies and your email address in order to identify you and track your use of the Services.
For Customer employees or contractors we link your email address to the Customer master account to coordinate provision of the SaaS and related Services as well as to track usage of the SaaS.
If you provide your payment information, we will use that information to charge you for the Services you purchase.
Fraud and SaaS stability and security
We use Personal Data, Content, Tracking Information, and your usage history to detect fraud, abuse, violation of our contract terms, violation of any laws, rules or regulations, to ensure the stability and security of our Services, to protect the rights, property or safety of Contentstack or to protect public safety and threats to public health
Direct Marketing and Updating You Regarding the Use of the Services.
We will use Customer contact information to contact you via email or by phone, if necessary, to let Customers know about Services we and our affiliates provide, new Services or features or to update you regarding Customer use of the Services.
To Improve the Quality of Services
We use Tracking Information and usage history to improve the quality of our Services, including, but not limited to user experience.
To the extent permitted by law, Contentstack will use Tracking Information to compile and/or create for analytical purposes, statistical, aggregated data relating to our users and the Sites and Services and display or share this information. Aggregated data is derived from Personal Information and Tracking Information but in its aggregated form it is de-identified in a manner so that it cannot be used to identify any individual or individuals. This data is used to understand our customer base, their needs, to develop, improve, and market our services.
Do Not Track Settings and Signals
Some web browsers may transmit “do not track” signals to the websites and other online services with which your web browser communicates. There is no standard that governs what, websites should do if they receive these signals. We currently do not respond to “Do Not Track” browser signals, settings or similar mechanisms. If and when a standard is established, we may revise our policy on responding to these signals. Third parties may collect personal information about your online activities over time and across sites when you visit the Sites or use the Sites or Services as set forth below.
HOW WE SHARE INFORMATION
We will not sell, rent, or share Personal Data with third parties outside of our company without your consent, except in the following ways:
Law Enforcement and Internal Operations
Contentstack provides Personal Data and Tracking Information to our affiliates that need to use such Information to provide the Services.
We sometimes contract with other companies and individuals to perform functions or services on our behalf, such as software maintenance, data hosting, sending email messages, etc. We necessarily have to share your Personal Data with such third parties as may be required to perform their functions. We take steps to ensure that these parties take protecting your privacy as seriously as we do, including entering into Data Processing Addendum, EU Model Clauses and/or ensuring they have EU-U.S. and Swiss-US Privacy Shield certification.
Third Party Service Providers
We also may use Marketo to track, follow up and market products to existing customers based on the name, email address and other contact information provided and tracking information collected through cookies. If you would like to be removed from such marketing, follow the removal instructions at the bottom of the emails sent to you. Processing takes place in the United States. Marketo is self-certified under U.S.-E.U. Privacy shield. Data processed in the United States under a Data Privacy Addendum and Standard Contractual Clauses. Please refer to Marketo’s Privacy Notice for more information.
We also may use Outreach to send you emails after you sign up for the Services or if you indicate an interest in receiving information and track your interaction with those emails based on the email address Customers provide to us. Outreach is also self-certified under the US-EU Privacy Shield program and we have a Data Processing Addendum with EU Standard Contractual Clauses in place with them. If you wish for us to remove yourself, just follow the instructions at the bottom of the email communications. For more information on Outreach, follow the link to https://www.outreach.io/legal/privacy-policy/.
We use Salesforce.com to collect personal information related to sales (name, contact information, employer) in order to follow up on inquiries and sales to our customers or potential customers who have contacted us. Salesforce is self-certified under the US-EU Privacy Shield and the Swiss-U.S. Privacy Shield framework to process data in the United States and its data is only shared subject to a Data Protection Addendum as well as Binding Corporate Rules. For more information about SalesForce’s privacy practices follow this link to https://www.salesforce.com/company/privacy/full_privacy.jsp.
We use the tool "Zendesk" on our website and within our SaaS, an offer of Zendesk Inc, which supports us in the processing of Customer requests (inquiries and customer support) using cookies to link request to Customer email.. The recorded information is processed by Zendesk on different servers some of which are located in the United States. Zendesk information about your browser, your hardware and software, your Internet service provider as well as your IP address, which can also be sent to the United States. Zendesk uses this information to provide the services described above. Zendesk is self certified under the US-EU Privacy Shield, has filed Binding Corporate Rules with the Dutch and UK authorities, and we have a Data Processing Addendum in place with them. For more information on data protection visit Zendesk visit: https://www.zendesk.com/company/customers-partners/privacy-policy/. If you do not want to go to Zendesk, you can refuse to set a cookie in your browser settings.
Third Party Sources
We collect Customer Personal Data for potential customers to reach out to regarding the services. For a list of third party data providers please go to our Third Party Providers and Data Sources Disclosure Page.
Your Information Choices
Right to Review and Rectify Your Personal Data
Customers can update most of their Personal Data by logging on to their account (except their contact email, which can not be edited because it is tied to the account). However, if additional assistance is required to change or delete inaccuracies within your Personal Data or you would like to know what information about you was collected, please contact us at email@example.com.
Right to Remove or Withdraw Consent
You have the right to withdraw consent where such consent is required to share or use data and you may request that we delete your Personal Data. If you receive communications from us and no longer wish to receive them, please follow the removal instructions in the email or change your account settings. You can delete your Personal Data by logging into your account and deleting your account.
However, since your Personal Data is required for us to provide the Services to you, deleting it, especially your email address, will also terminate your access to the services. Deleting your Personal Data does not mean that all of it will be removed. We may be required by law, to retain your data to exercise or defend legal claims, fulfill contractual obligations with our customers; retain some information in connection with our obligation to provide the Services. We may de-identify and anonymize some data for purposes of retaining it.
If you would like us to transmit your Personal Data to another company providing similar services, we will work with them to do so upon request and verification of such request with both the requestor and the company receiving the Personal Data.
We take steps to delete data after we no longer have a legitimate purpose for retaining it. After master accounts are terminated, we delete Customer Content data and End User data within 180 days after termination. We retain Customer information as long as necessary to achieve legitimate business purposes (such as to defend against legal claims or archive with anonymization techniques) or as required by law.
Protection of Personal Data
We have implemented reasonable administrative, technical and physical security measures to protect your personal information against unauthorized access, destruction or alteration. For example:
- SSL encryption (https) everywhere where we deal with Personal Data.
- Password protection on your account.
- Customer Personal Data is kept on secure, encrypted servers, located in the US.
- SSL encryption and API key for backend storage of User Content
- Restricting staff access to Personal Data protected by password logs and two factor authentication.
- Regular staff privacy and security training
However, because no security system can be 100% effective, we cannot completely guarantee the security of any information we store, process or transmit.
Third Party Links and Services
Users Under 16 Years of Age
The Sites and Services do not knowingly collect personal information from users under the age of 16 nor are they intended to be used by anyone under 16. If you are under the age of 16, you are not permitted to use the Sites and Services or to disclose Personal Information using the Sites and Services. If we learn we have collected or received Personal Information from a child under 16, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at firstname.lastname@example.org.