This CRECENTRIC, Inc. (“CREcentric” or “we” or “us” or “our”) privacy policy (the “Privacy Policy”) is designed to help you understand what information we collect, including information that directly or indirectly identifies an individual (“personal information”), and how we use or share that information.
For self-hosted (on-premises) products, please see the first section of this Privacy Policy. For all other CREcentric products, services, and interactions, please see the remainder of the policy starting with the section entitled “Scope of this Privacy Policy.”
Self-Hosted (On-Premises) Products
This is the only section of the Privacy Policy that applies to end users of our self-hosted (on-premises) products. With self-hosted products, the Customer (defined below) that purchases the CREcentric product also controls the processing of end user data. If the Customer permits, CREcentric can collect limited service and usage data like error and diagnostics information, security alerts, and log file reports associated with device identifiers. We refer to this information as “telemetry data,” and it does not include any end user personal identifiers or message contents.
We may share telemetry data collected through our self-hosted products in limited ways to support the product and comply with law, as follows:
If you would like to learn more about our self-hosted products practices, you can contact us at privacy@crecentric.com. If you are a Customer purchasing a self-hosted product, you can see the sections relating to Customers below to learn how we process your personal information collected through our business interactions.
Scope of this Privacy Policy
The remainder of this Privacy Policy applies to:
Our different practices for each of these groups are described below. Please read this Privacy Policy carefully. By accessing or using any part of the Services or the Sites, you acknowledge that you have been informed of our practices with regard to your personal information and other data. If you do not agree to this Privacy Policy, please immediately cease use of the Services and the Sites and please shut down your account.
Customer Control of Services Data
In order to provide the Services, CREcentric is utilized by an organization (either an employer or another entity or person) (each, a “Customer”) under a contract that governs the delivery, access, and use of the Services. When you are an end user of our Services, the Customer has authorized you to access the Services. The Customer owns and controls the messages, files, or other content submitted to the Services, including your personal information (the “Customer Data”) and your account with the Services and any associated Customer Data that you provide. In these cases, CREcentric acts as a data processor (or service provider) within the meaning of applicable privacy laws, and the processing of Customer Data is governed by any data processing agreement between CREcentric and the Customer in addition to this Privacy Policy. The Customer also controls and manages any third party services they use in conjunction with the Services. The Customer controls the processing of Customer Data through the Services. Please contact the Customer if you have any questions related to such Customer’s specific settings and privacy practices in relation to the Services.
1. Contact Us
Please contact us at privacy@crecentric.com if you have any complaints, questions, comments, or concerns with respect to your privacy or this policy.
If you believe that any account credentials for the Services have been compromised, please contact us immediately at privacy@crecentric.com.
2. Information We Collect and How We Use It
We collect information that you provide and information that we receive automatically. As described below, our information practices vary depending on whether you are acting as a visitor to our Sites, a CREcentric Customer, or an end user of our Services.
Please be aware that some of the information described below is required to offer the Sites and Services, and if this information is not provided, we may not be able to provide the Sites and Services. We may use the information we collect for any lawful purpose, including the purposes specifically described below. We may also use information that has been aggregated or deidentified, so that it cannot reasonably be associated with a specific person, for any business purpose.
Information Collected About Website Visitors: If you are a visitor to our Sites, we collect information about you as described below. We may also combine the information we collect about you with information we obtain from third parties.
Information You Provide to Us: We collect personal information that you provide when you send us a message through our Sites, register for or create an account with the Sites, or request more information about our Services. This information includes your name, email address, phone number, other contact details, and other information you choose to provide us.
Technical Information We Collect Automatically: When you use or visit the Sites, we may send cookies to your computer or device that allow us to uniquely identify your browser, computer, or device. Please see our Cookies Policy for more information about our collection and use of cookies. We may use cookies (and similar technologies) to collect other technical information when you use or visit the Sites, such as Internet Protocol (IP) address, location, browser type and settings, date and time the Sites were used, the web page that you were visiting before accessing our Sites, information about your activities on the Sites, external links and the features or content which you accessed from our Sites. When you access the Sites with a device (including a mobile device), we may also collect and store a unique identifier associated with your device and additional information about the device, including user settings, location, operating system of the device, and crash settings.
Information Collected About Customers:
As described below, we collect information from our Customers, such as administrative users of our Services and individuals who purchase our Services on behalf of their employer. We may also combine the information we collect about our Customers with information we obtain from third parties.
Information You Provide to Us: We collect personal information that you provide when you register for or create an account with our Services or request more information about our Services. We may also collect Customer information through helpdesk systems, forums, web input forms, surveys, and ticketing tools. This information may include your name, email address, phone number, other contact details, and other information you choose to provide. It can also include business information like billing details (such as payment information and billing addresses) and your organization’s name, phone number, domain, email address, and physical address.
Technical Information We Collect Automatically: When you use or visit the Sites, we may send cookies to your computer or device that allow us to uniquely identify your browser, computer, or device. Please see our Cookies Policy for more information about our collection and use of cookies. We may use cookies (and similar technologies) to collect other technical information when you use or visit the Sites, such as Internet Protocol (IP) address, location, browser type and settings, date and time the Sites were used, the web page that you were visiting before accessing our Sites, information about your activities on the Sites, external links and the features or content which you accessed from our Sites. When you access the Sites with a device (including a mobile device), we may also collect and store a unique identifier associated with your device and additional information about the device, including user settings, location, operating system of the device, and crash settings.
Information Collected from CREcentric Services:
If you are an end user of the Services we provide to our Customers, we may collect information related to your use of our Services, as described below.
Service and Usage Information: When end users use our Services, we collect information that is generated that provides context about the way end users use the Services such as team and channel memberships, system preferences, features they use, content and links they interact with, the types of files shared and what third party services are used (if any).
Log and Device Information: We may also record log file information each time end users access and use the Services, such as Internet Protocol (IP) address, location, browser type and settings, date, and time. When end users access the Service with a device (including a mobile device), we may also collect and store a unique identifier associated with an end user’s device and additional information about the device accessing the Services, including user settings, location, the operating system of the device, and crash settings.
Information Shared with Third Parties and For What Purposes
We do not sell, trade, or otherwise transfer the information described above to unaffiliated third parties for monetary consideration. We may share information about website visitors, Customers, and end users of the Services with other entities for specific purposes. This sharing may include:
We may share information that has been de-identified or aggregated without limitation.
How We Protect Information
We implement a variety of security measures aimed at maintaining the safety of the personal information we collect from loss, misuse, and unauthorized access or disclosure. These steps take into account the sensitivity of the information we collect, process, and store, as well as the current state of technology. Given the nature of communications and information processing technology, we cannot guarantee that information we collect will be absolutely safe.
Cookies and Similar Technologies
As noted above, we use cookies and similar technologies on our Sites and Services. Please read our Cookies Policy for more details.
Digital Advertising and Analytics
Our Services do not collect, use, or share information for advertising. However, in connection with our Sites, we may partner with ad networks and other ad serving providers (“Advertising Providers”) that serve ads on behalf of us and others on non-affiliated platforms. Some of those ads may be personalized, meaning that they are intended to be relevant to you based on information Advertising Providers collect about your use of the Sites and other sites or apps over time, including information about relationships among different browsers and devices. This type of advertising is known as interest-based advertising.
To opt out of these practices or learn more about this type of advertising, you may visit the Digital Advertising Alliance Webchoices tool at www.aboutads.info/choices. You can also opt out of Google ad tracking by following the instructions on this page: https://adssettings.google.com/. As described below in the “California Privacy Rights” section of this Privacy Policy, California residents (such as our Customers and website visitors) also have a right under California law to opt out of sharing of personal information for interest-based advertising (also known as “cross-context behavioral advertising”). This right can be exercised by using the Webchoices and Google ad tracking tools described above.
Electing to opt out from interest-based advertising will not stop advertising from appearing in your browser or applications. It may make the ads you see less relevant to your interests. If you use a different browser or device, you may need to renew your opt-out choice.
We may also work with third parties that collect data about your use of the Sites and other sites or apps over time for non-advertising purposes. We use Google Analytics and other third-party services to improve the performance of the Sites and for analytics and marketing purposes. For more information about how Google Analytics collects and uses data when you use the Sites, visit www.google.com/policies/privacy/partners, and to opt out of Google Analytics, visit tools.google.com/dlpage/gaoptout.
Our Legal Bases for Processing in the EU
If the GDPR is applicable as per Art. 3 of the GDPR, then references to “personal information” in this Privacy Policy are equivalent to “personal data” governed by the GDPR.
As described above, we rely on various legal bases to process the personal information we collect. Our legal basis for processing this personal information depends on the personal information concerned and the specific context in which we process it. We will normally collect personal information only where we need the personal information to perform a contract (e.g. to provide our Services), where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms, or where we have your consent. In some cases, we may also have a legal obligation to process personal information.
International Data Transfers and Storage
In order for us to operate and provide our Sites and Services globally, the personal information you provide to us or that we collect may be transferred or accessed in various countries, including the United States of America. If you are located in the European Economic Area, Switzerland, or the United Kingdom, please note that we may transfer information, including personal information, to a country and jurisdiction that offers a level of protection that may, in certain instances, be less protective of your personal information than the jurisdiction you typically reside in.
In the event that personal information is transferred outside of the European Economic Area, Switzerland, or the United Kingdom to a country which is not subject to an adequacy decision by relevant regulators or considered adequate as determined by applicable laws, we will take steps to ensure the personal information is protected (e.g., by implementing approved Standard Contractual Clauses or relying on other data transfer mechanisms as available under applicable laws).
Additionally, while CREcentric remains self-certified under the EU-U.S. Privacy Shield and Swiss – U.S. Privacy Shield, we are not relying on these frameworks for transfers of personal information. To learn more about the Privacy Shield Program, please see https://www.privacyshield.gov/welcome.
Retention of Personal Information
We retain the personal information we collect for as long as we need to provide our Sites and/or Services, or as required to comply with our legal obligations. After such time, we may delete, de-identify, or aggregate this information within 60 days, unless otherwise required by law.
If you have an account on CREcentric Sites or Services, we will retain your information for as long as your account is active or as needed to perform our contractual obligations, provide our Sites or Services to you, comply with legal obligations, resolve disputes, preserve legal rights, or enforce our agreements. We may delete, de-identify, or aggregate this information to the extent possible once it is no longer necessary to fulfill the purposes for which it was collected and processed.
Depending on the Services plan, Customers may be able to customize their retention settings for end user information such that they are different than CREcentrict’s standard data retention practices. Customers may also apply different settings to messages, files, or other types of Customer Data. The deletion of Customer Data and other use of the Services by Customer may result in the deletion and/or de-identification of certain personal information and other information.
European Privacy Rights
Individuals in the European Union, European Economic Area, or the United Kingdom may have certain rights with respect to personal information processed through the Sites and Services. If your personal information was submitted to us by a Customer or your account is controlled by a Customer, then please contact the applicable Customer directly to learn about the rights you may have. Otherwise, please email privacy@crecentric.com to exercise any of the below rights.
Subject to certain exceptions and limitations, you may have the right:
In addition to the above-listed rights, you may also have the right to lodge a complaint with your local data protection authority. Further information about how to contact your local data protection authority is available at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.
The provision of personal information is neither a statutory nor contractual requirement nor a requirement necessary to enter into a contract. You are not obliged to provide personal information. There are no consequences resulting from failure to provide such information. We also do not process personal information for the purpose of automated decision-making.
California Privacy Rights for Business Contacts
If you are a California resident who is a CREcentric Customer, a visitor to our Sites, or another business contact of CREcentric (collectively, our “Business Contacts”), this section contains disclosures required by the California Privacy Rights Act (“CPRA”) and applies only to “personal information” we process about you that is subject to the CPRA.
This section does not cover personal information processed to provide our Services, because we process such information on behalf of our Customers as a “service provider” or “processor.” To learn more about the rights that may be available to you as an end user of the Services under state privacy laws, like the CPRA, please visit our Customers’ privacy policies.
Personal Information We Collect and Disclose. In the past 12 months, we collected and disclosed the categories of personal information about our Business Contacts listed below.
.
Categories of Sources. We collect this personal information from the following categories of sources:
Why We Collect, Use, and Share Personal Information. We collect, use, and disclose personal information about our Business Contacts for our business and commercial purposes described in the “Information We Collect and How We Use It” and the “Information We Share with Third Parties and For What Purposes” sections of this Privacy Policy above.
Recipients of Personal Information. We may disclose each category of personal information we collect about our Business Contacts to the categories of third parties described in the “Information We Share with Third Parties and For What Purposes” section of this Privacy Policy above.
While we do not sell the personal information we collect about our Business Contacts, we may share such personal information for interest-based advertising purposes (also known as “cross-context behavioral advertising”) by allowing third-party advertising providers to collect data on our Sites as described above under “Digital Advertising and Analytics” section of this Privacy Policy.
Your Rights Regarding Personal Information. California residents who are our Business Contacts have certain rights with respect to the personal information collected by businesses like CREcentric. If you are a California resident who is our Business Contact, you may exercise the following rights regarding your personal information, subject to certain exceptions and limitations:
While the CPRA provides an opt-out opportunity for certain uses or disclosures of “sensitive personal information” (as defined under the CPRA), CREcentric uses and discloses such information only for purposes permitted by the CPRA that do not require an opt-out opportunity.
To exercise any of the above rights, please email privacy@crecentric.com.
Verification Process and Required Information. Note that we may need to request additional information from you to verify your identity or understand the scope of your request, although you will not be required to create an account with us to submit a request or have it fulfilled. We will require you to provide, at a minimum, your name, business email address, and business phone number. We will verify your request using the information associated with your account, including email address. Government identification may be required.
Authorized Agent. You may designate an authorized agent to make a CPRA request on your behalf by submitting a written, signed permission to privacy@crecentric.com.
Minors. We do not knowingly sell or share the personal information of minors under 16 years of age.
Third-Party Links and Tools
This Privacy Policy does not apply to any third-party websites, services, integrations, or applications, even if they are accessible through our Sites and/or Services. This Privacy Policy only applies to our Sites and Services, so when you follow links to other websites you should read those separate and independent privacy policies to learn about their data practices. We have no responsibility or liability for the content and activities of these linked sites, or for any third-party websites, services, integrations, or applications.
Your interactions with third-party companies and your use of their features are governed by the privacy policies of the companies that provide those features. We encourage you to carefully read the privacy policies of any accounts you create and use.
Your Choices
To opt out of our email marketing, you can use the link provided at the bottom of each marketing message. If you opt out of our email marketing, we will still send you messages related to our transactions and relationship with you, such as order confirmations.
For choices with respect to third-party interest-based advertising activities, please see the “Digital Advertising & Analytics” section above.
For choices we offer to California residents who are our Customers or other business contacts, please see the “Your California Privacy Rights” section above.
Updating Your Information
When you have an account with us, you may review, change, or update your contact information by logging into your account.
Changes to our Privacy Policy
If we decide to change our Privacy Policy, we will post those changes on this page. We encourage you to visit this page periodically to learn of any updates. Your continued use of the Sites and Services after an updated Privacy Policy is posted constitutes your consent to the revised Privacy Policy.
Our Obligations to you under the Privacy Shield
CREcentric has subscribed to the EU – U.S. Privacy Shield Framework and Swiss – U.S. Privacy Shield Framework (collectively, “Privacy Shield”) as set forth by the U.S. Department of Commerce, regarding the collection, use, and retention of personal information transferred from the European Union, the United Kingdom and/or Switzerland as applicable to the United States. CREcentric has certified to the Department of Commerce that it adheres to the Privacy Shield Principles.
If there are any conflicts between the terms in this Privacy Policy and the Privacy Shield, the Privacy Shield shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/list.
Privacy Shield Principles
CREcentric has certified that it adheres to the following Privacy Shield Principles of (1) Notice; (2) Choice; (3) Accountability for Onward Transfer; (4) Security; (5) Data Integrity and Purpose Limitation; (6) Access; and (7) Recourse, Enforcement and Liability with respect to any personal information received from citizens of the European Union and Switzerland.
(1) Notice, (2) Choice, and (3) Accountability for Onward Transfer of Personal information
CREcentric is required to take certain steps when transferring personal information received from the European Union and Switzerland to third parties (such as including necessary contractual provisions in our third-party contracts). CREcentric may be potentially liable in cases of onward transfer of EU and Swiss individuals’ data received pursuant to the Privacy Shield to third parties. We collect and process data in accordance with this Privacy Policy. Please see the “Information We Collect and How We Use It” section for further details of the types of data which we collect from you and the purposes for which we collect it.
(4) Security
CREcentric takes reasonable and appropriate administrative and technical security measures to protect the confidentiality, integrity and availability of personal information. CREcentric takes reasonable steps to protect personal information from loss, misuse and unauthorized access, disclosure, alteration and destruction.
(5) Data Integrity and Purpose Limitation
We only collect personal information that is relevant to providing our Sites and Services to you, or as otherwise notified to you. We take reasonable steps to ensure that CREcentric only receives personal information that is necessary, and that the personal information received by CREcentic is accurate, complete, and current.
(6) Access
Our Privacy Policy explains how you may request access to review, correct or delete your personal information that we maintain about you by emailing privacy@crecentric.com. We may limit or deny access to personal information where providing such access is unreasonably burdensome, expensive under the circumstances, or as otherwise permitted by the Privacy Shield Principles or law.
(7) Recourse, Enforcement, and Liability
In compliance with the Privacy Shield Principles, CREcentric commits to resolve complaints relating to your privacy and our collection or use of your personal information without any charge to you. European Union and Swiss individuals with inquiries or complaints regarding this Privacy Policy should first contact us at: Email address: privacy@crecentric.com
We will work to resolve your issue as quickly as possible, but in any event, within 45 days of receipt. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
CREcentric has also committed to cooperate with EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) by complying with the advice given by such authorities with regard to human resources data transferred from the EU in the context of the employment relationship with CREcentric. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, you have available to you, your national European Data Protection Board (EDPA) to file complaints about your information in Crecentric’s custody. Please contact the EU DPAs for more information or to file a complaint. To find your national EDPA, please refer to this web site https://edpb.europa.eu/about-edpb/board/members_en. The services of EU DPAs are provided at no cost to you.
In certain circumstances, the Privacy Shield Principles provides the right to invoke binding arbitration to resolve complaints not resolved by other means, as described in Annex I to the Privacy Shield Principles.
CREcentric is subject to the investigatory and enforcement powers of the Federal Trade Commission in the case of any failure to comply with the Privacy Shield