TrustCloud Privacy Policy (1 June 2020)

Effective as of June 1, 2020.

Overview

This “Privacy Policy” describes the privacy practices of TrustCloud Corporation and our subsidiaries and affiliates (collectively, “TrustCloud”, “we”, “us”, or “our”) in connection with the www.trustcloud.ai website and any other website or mobile application that we own or control and which posts or links to this Privacy Policy (collectively, the “Service”), and the rights and choices available to individuals with respect to their information.

We provide important information for individuals located in the European Union, European Economic Area, and United Kingdom (collectively, “Europe” or “European”) below.

Table of Contents

 

Personal Information We Collect

Information you provide to us.  Personal information you provide to us through the Service or otherwise includes:

  • Business and personal contact information, such as your first and last name, email and mailing addresses, phone number, professional title and company name.
  • Content you choose to upload to the Service, such as text, files, images, audio, and video, along with the metadata associated with the files you upload.
  • Profile information, such as your username and password or other authentication credentials that you may set to establish an online account with us, or information such as your photograph, interests, and preferences.
  • Registration information, such as information that may be related to a service, an account or an event you register for.
  • Feedback or correspondence, such as information you provide when you contact us with questions, feedback, or otherwise correspond with us online.
  • Demographic Information, such as your city, state, country of residence, age and postal code.
  • Financial information, such as your stated income, economic standing, financial account numbers or payment card information.
  • Transaction information, such as information about payments to and from you and other details of products or services you have purchased from us.
  • Usage information, such as information about how you use the Service and interact with us, including information associated with any content you upload to the websites or otherwise submit to us, and information you provide when you use any interactive features of the Service.
  • Marketing information, such as your preferences for receiving communications about our activities, events, and publications, and details about how you engage with our communications
  • Other information that we may collect which is not specifically listed here, but which we will use in accordance with this Privacy Policy or as otherwise disclosed at the time of collection.

Information we obtain from social media platforms. We may maintain pages for our Company on social media platforms, such as Facebook, LinkedIn, Twitter, Google, YouTube, Instagram, and other third party platforms. When you visit or interact with our pages on those platforms, the platform provider’s privacy policy will apply to your interactions and their collection, use and processing of your personal information. You or the platforms may provide us with information through the platform, and we will treat such information in accordance with this Privacy Policy.

Information we obtain from other third parties.  We may receive personal information about you from third-party sources. For example, a business partner may share your contact information with us if you have expressed interest in learning specifically about our products or services, or the types of products or services we offer. We may obtain your personal information from other third parties, such as partner websites, referral websites, marketing partners, publicly-available sources and data providers.

Cookies and Other Information Collected by Automated Means 

We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and activity occurring on or through the Service. The information that may be collected automatically includes your computer or mobile device operating system type and version number, manufacturer and model, device identifier (such as the Google Advertising ID or Apple ID for Advertising), browser type, screen resolution, IP address, the website you visited before browsing to our website, general location information such as city, state or geographic area; and information about your use of and actions on the Service, such as pages or screens you viewed, how long you spent on a page or screen, navigation paths between pages or screens, information about your activity on a page or screen, access times, and length of access.  Our service providers and business partners may collect this type of information over time and across third-party websites and mobile applications.

On our webpages, this information is collected using cookies, browser web storage (also known as locally stored objects, or “LSOs”), web beacons, and similar technologies, and our emails may also contain web beacons.

 See our Cookie Policy for more information.

Referrals

Users of the Service may have the opportunity to refer friends or other contacts to us. If you are an existing user, you may only submit a referral if you have permission to provide the referral’s contact information to us so that we may contact them.

How We Use Your Personal Information

We use your personal information for the following purposes and as otherwise described in this Privacy Policy or at the time of collection:

To operate the Service.  We use your personal information to:

  • provide, operate and improve the Service
  • provide information about our products and services
  • establish and maintain your user profile on the Service
  • facilitate your to login to the Service via third-party identity and access management providers, such as GSuite or Okta.
  • enable security features of the Service, such as by sending you security codes via email or SMS, and remembering devices from which you have previously logged in
  • facilitate social features of the Service, such as by identifying and suggesting connections with other users of the Service and providing chat or messaging functionality
  • communicate with you about the Service, including by sending you announcements, updates, security alerts, and support and administrative messages
  • understand your needs and interests, and personalize your experience with the Service and our communications
  • provide support and maintenance for the Service
  • respond to your requests, questions and feedback

For research and development. We analyze use of the Service to analyze and improve the Service and to develop new products and services, including by studying user demographics you have provided and use of the Service.

To send you marketing and promotional communications about our products and services.  We may send you TrustCloud-related marketing communications as permitted by law. You will have the ability to opt-out of our marketing and promotional communications as described in the Opt out of marketing section below.

To comply with law. We use your personal information as we believe necessary or appropriate to comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas or requests from government authorities.

For compliance, fraud prevention, and safety.  We may use your personal information and disclose it to law enforcement, government authorities, and private parties as we believe necessary or appropriate to: (a) protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims); (b) enforce the terms and conditions that govern the Service; and (c) protect, investigate and deter against fraudulent, harmful, unauthorized, unethical or illegal activity.

With your consent.  In some cases we may specifically ask for your consent to collect, use or share your personal information, such as when required by law. 

To create anonymous, aggregated or de-identified data.  We may create anonymous, aggregated or de-identified data from your personal information and other individuals whose personal information we collect.  We make personal information into anonymous, aggregated or de-identified data by removing information that makes the data personally identifiable to you.  We may use this anonymous, aggregated or de-identified data and share it with third parties for our lawful business purposes, including to analyze and improve the Service and promote our business. 

How We Share your Personal Information

We do not share your personal information with third parties without your consent, except in the following circumstances or as described in this Privacy Policy:

Affiliates.  We may share your personal information with our corporate parent (if applicable), subsidiaries, and affiliates, for purposes consistent with this Privacy Policy.

Service providers.  We may share your personal information with third party companies and individuals that provide services on our behalf or help us operate the Service (such as customer support, hosting, analytics, email delivery, marketing, and database management services). These third parties may use your personal information only as directed or authorized by us and in a manner consistent with this Privacy Policy, and are prohibited from using or disclosing your information for any other purpose.

Third-party platforms. If you have enabled features or functionality that connect the Service to a third-party platform or social media network (such as by logging in to the Service using your account with the third-party, providing your API key or similar access token for the Service to a third-party, or otherwise linking your account with the Service to a third-party’s services), we may disclose the personal information that you authorized us to share. We do not control the third party’s use of your personal information.

Other users of the Service and/or public communities, at your explicit request. We may provide functionality that enables you to disclose personal information to other users of the Service or the public. For instance, you may be able to maintain a user profile with information about yourself that you can make available to other users or the public (for example, to post in a forum). You may also be able to submit content to the Service (such as comments, reviews, surveys, blogs, photos, and videos), and we may display information such as your name, username, and a link to your user profile along with the content you submit. We may make available settings through a “Settings” page that enables you to exercise choice regarding certain information that is displayed publicly or to other users.  We do not control how other users or third parties use any personal information that you make available to other users or the public.

Professional advisors. We may disclose your personal information to professional advisors, such as lawyers, investors, bankers, auditors and insurers, where necessary in the course of the professional services that they render to us.

For compliance, fraud prevention and safety. We may share your personal information for the compliance, fraud prevention and safety purposes described above

Business transfers.  We may sell, transfer or otherwise share some or all of our business or assets, including your personal information, in connection with a business transfer transaction (or potential business transfer transaction) such as a corporate divestiture, merger, consolidation, acquisition, reorganization or sale of assets, or in the event of bankruptcy or dissolution.

Your Choices

Access or Update Your Information. If you have registered for an account with us, you may review and update certain personal information in your account profile by logging into the account.

Opt out of marketing communications.  You may opt out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us at privacy@trustcloud.ai.  You may continue to receive service-related and other non-marketing emails. 

Cookies & Browser Web Storage.  We may allow service providers and other third parties to use cookies and similar technologies to track your browsing activity over time and across the Service and third party websites. For more details, see our Cookie Policy.

Do Not Track.  Some Internet browsers may be configured to send “Do Not Track” signals to the online services that you visit.  We currently do not respond to “Do Not Track” or similar signals.  To find out more about “Do Not Track”, please visit https://www.allaboutdnt.com.

Choosing not to share your personal information. Where we are required by law to collect your personal information, or where we need your personal information in order to provide the Service to you, if you do not provide this information when requested (or you later ask to delete it), we may not be able to provide you with our services.  We will tell you what information you must provide to receive the Service by designating it as required at the time of collection or through other appropriate means.

Other sites, mobile applications and services

The Service may contain links to other websites, mobile applications, and other online services operated by third parties.  These links are not an endorsement of, or representation that we are affiliated with, any third party.  In addition, our content may be included on web pages or in mobile applications or online services that are not associated with us. We do not control third party websites, mobile applications or online services, and we are not responsible for their actions.  Other websites and services follow different rules regarding the collection, use and sharing of your personal information.  We encourage you to read the privacy policies of the other websites and mobile applications and online services you use.

Security practices

The security of your personal information is important to us.  We employ a number of organizational, technical and physical safeguards designed to protect the personal information we collect.  However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal information.

International data transfers

We are headquartered in the United States and have service providers in other countries, and your personal information may be transferred to the United States or other locations outside of your state, province, or country where privacy laws may not be as protective as those in your state, province, or country. 

Children

The Service is not directed to, and we do not knowingly collect personal information from, anyone under the age of 16.  If a parent or guardian becomes aware that his or her child has provided us with information without their consent, he or she should contact us. We will delete such information from our files as soon as reasonably practicable.  We encourage parents with concerns to contact us.

How to Contact Us

Please direct any questions or comments about this Policy or privacy practices to privacy@trustcloud.ai.

Important Information for California Residents

This section applies only to California residents.  It describes how we collect, use and share Personal Information of California residents in operating our business, and their rights with respect to that Personal Information.  For purposes of this section, “Personal Information” has the meaning given in the California Consumer Privacy Act of 2018 (“CCPA“) but does not include information exempted from the scope of the CCPA.

Your California privacy rights

As a California resident, you have the rights listed below. However, these rights are not absolute, and in certain cases we may decline your request as permitted by law.

  • Information. You can request the following information about how we have collected and used your Personal Information during the past 12 months:
    • The categories of Personal Information that we have collected.
    • The categories of sources from which we collected Personal Information.
    • The business or commercial purpose for collecting and/or selling Personal Information.
    • The categories of third parties with whom we share Personal Information.
    • Whether we have disclosed your Personal Information for a business purpose, and if so, the categories of Personal Information received by each category of third party recipient.
    • Whether we’ve sold your Personal Information, and if so, the categories of Personal Information received by each category of third party recipient.

 

Statutory category of personal information (PI)
(click for details)
Source of the PI Purpose for collection Categories of third parties to whom we “disclose” the PI for a business purpose
Identifiers You
Public sources
Business partners
Our clients  
Service delivery
Research & development
Marketing
Compliance & Operations
Affiliates
Service-related third parties
Professional advisors
Authorities and others
Business transferees
Commercial Information You
Our clients  
Service delivery
Research & development
Marketing
Compliance & Operations
Affiliates
Service-related third parties
Professional advisors
Authorities and others
Business transferees
Financial Information You
Public sources
Business partners
Our clients  
Service delivery
Research & development
Marketing
Compliance & Operations
Affiliates
Service-related third parties
Professional advisors
Authorities and others
Business transferees
Online Identifiers You
Our clients  
Service delivery
Research & development
Marketing
Compliance & Operations
Affiliates
Service-related third parties
Professional advisors
Authorities and others
Business transferees
Internet or Network Information You
Automatic collection
Service delivery
Research & development
Marketing
Compliance & Operations
Affiliates
Service-related third parties
Professional advisors
Authorities and others
Business transferees

  • Access. You can request a copy of the Personal Information that we have collected about you during the past 12 months.
  • Deletion.  You can ask us to delete the Personal Information that we have collected from you.
  • Opt-in.  If we know that you are younger than 16 years old, we will ask for your permission (or if you are younger than 13 years old, your parent’s or guardian’s permission) to sell your Personal Information before we do so.
  • Nondiscrimination.  You are entitled to exercise the rights described above free from discrimination. This means that we will not penalize you for exercising your rights by taking actions such as denying you services; increasing the price/rate of services; decreasing service quality; or suggesting that we may penalize you as described above for exercising your rights. 

How to exercise your rights

You may exercise your California privacy rights described above as follows:

  • Right to information, access and deletion. You can request to exercise your information, access and deletion rights by emailing us at privacy@trustcloud.ai

We will need to confirm your identity and California residency to process your requests to exercise your information, access or deletion rights.  We cannot process your request if you do not provide us with sufficient detail to allow us to understand and respond to it.

Personal information that we collect, use and share

The chart below summarizes how we collect, use and share Personal Information by reference to the statutory categories specified in the CCPA, and describes our practices during the 12 months preceding the effective date of this Privacy Policy. Categories in the chart refer to the categories described above in the general section of this Privacy Policy.

Glossary

Statutory category Definition (categories may overlap) What we collect
Commercial Information Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies. Contact data
Identity data
Transaction data
Communications
Marketing data
Financial Information Bank account number, debit or credit card numbers, insurance policy number, and other financial information. Financial data
Identifiers Real name, alias, postal address, unique personal identifier, customer number, email address, account name, social security number, driver’s license number, passport number, or other similar identifiers. Contact data Identity data Data about others
Inferences The derivation of information, data, assumptions, or conclusions from any other category of Personal Information to create a profile about a person reflecting the person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities and aptitudes. May be derived from your: Device data Online activity data
Internet or Network Information Browsing history, search history, and information regarding a person’s interaction with an Internet website, application, or advertisement. Device data Online activity data
Online Identifiers An online identifier or other persistent identifier that can be used to recognize a person, family or device, over time and across different services, including but not limited to, a device identifier; an Internet Protocol address; cookies, beacons, pixel tags, mobile ad identifiers, or similar technology; customer number, unique pseudonym, or user alias; telephone numbers, or other forms of persistent or probabilistic identifiers (i.e., the identification of a person or a device to a degree of certainty of more probable than not) that can be used to identify a particular person or device. Device data Identity data

Notice to European Users

The information provided in this “Notice to European Users” section applies only to individuals in Europe.

Personal information. References to “personal information” in this Privacy Policy are equivalent to “personal information” governed by European data protection legislation.

Controller. TrustCloud Corporation is the controller of your personal information covered by this Privacy Policy for purposes of European data protection legislation.

Legal bases for processing. We use your personal information only as permitted by law. Our legal bases for processing the personal information described in this Privacy Policy are described in the table below.

Processing purpose
Details regarding each processing purpose listed below are provided in the section above titled “How we use your personal information”.
Legal basis
To operate the Service
Processing is necessary to perform the contract governing our provision of the Service or to take steps that you request prior to signing up for the Service. If we have not entered into a contract with you, we process your personal information based on our legitimate interest in providing the Service you access and request.
To administer events and contests
For research and development
To send you marketing communications
To display advertisements
To manage our recruiting and process employment applications
For compliance, fraud prevention and safety
To create anonymous data
These activities constitute our legitimate interests. We do not use your personal information for these activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
To comply with law Processing is necessary to comply with our legal obligations.
With your consent Processing is based on your consent. Where we rely on your consent you have the right to withdraw it any time in the manner indicated when you consent or in the Service.

Use for new purposes. We may use your personal information for reasons not described in this Privacy Policy where permitted by law and the reason is compatible with the purpose for which we collected it. If we need to use your personal information for an unrelated purpose, we will notify you and explain the applicable legal basis.

Sensitive personal information. We ask that you not provide us with any sensitive personal information (e.g., information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background or trade union membership) on or through the Service, or otherwise to us.

If you provide us with any sensitive personal information to us when you use the Service, you must consent to our processing and use of such sensitive personal information in accordance with this Privacy Policy. If you do not consent to our processing and use of such sensitive personal information, you must not submit such sensitive personal information through our Service.

Retention

We retain personal information for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements, to establish or defend legal claims, or for fraud prevention purposes.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorized use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.

When we no longer require the personal information we have collected about you, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. If we anonymize your personal information (so that it can no longer be associated with you), we may use this information indefinitely without further notice to you.

Your rights

European data protection laws give you certain rights regarding your personal information. If you are located within the European Union, you may ask us to take the following actions in relation to your personal information that we hold:

  • Access. Provide you with information about our processing of your personal information and give you access to your personal information.
  • Correct. Update or correct inaccuracies in your personal information.
  • Delete. Delete your personal information.
  • Transfer. Transfer a machine-readable copy of your personal information to you or a third party of your choice.
  • Restrict. Restrict the processing of your personal information.
  • Object. Object to our reliance on our legitimate interests as the basis of our processing of your personal information that impacts your rights.

You may submit these requests by email to privacy@trustcloud.ai. We may request specific information from you to help us confirm your identity and process your request. Applicable law may require or permit us to decline your request. If we decline your request, we will tell you why, subject to legal restrictions. If you would like to submit a complaint about our use of your personal information or our response to your requests regarding your personal information, you may contact us or submit a complaint to the data protection regulator in your jurisdiction. You can find your data protection regulator here.

Cross-Border Data Transfer

If we transfer your personal information out of Europe to a country not deemed by the European Commission to provide an adequate level of personal information protection, the transfer will be performed:

  • Pursuant to the recipient’s compliance with standard contractual clauses, EU-US Privacy Shield (or Swiss-US Privacy Shield, as applicable), or Binding Corporate Rules
  • Pursuant to the consent of the individual to whom the personal information pertains
  • As otherwise permitted by applicable European requirements.

You may contact us if you want further information on the specific mechanism used by us when transferring your personal information out of Europe.

Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service. We may, and if required by law will, also provide notification of changes in another way that we believe is reasonably likely to reach you, such as via e-mail (if you have an account where we have your contact information) or another manner through the Service.

Any modifications to this Privacy Policy will be effective upon our posting the new terms and/or upon implementation of the new changes on the Service (or as otherwise indicated at the time of posting). In all cases, your continued use of the Service after the posting of any modified Privacy Policy indicates your acceptance of the terms of the modified Privacy Policy.