Please feel free to address any questions or concerns regarding data privacy to our Data Protection Officer (DPO) at email@example.com or at
49 Geary Street #238
San Francisco, CA 91408
There are three (3) types of users who may be connected to our services.
“Visitors” are people who visit our Site without logging on or requesting information from us.
“Customers” are persons who, on behalf of themselves or an entity request information from us regarding SaaS or related services or use of Services via log-on to our Site either for a limited time free trial or by purchasing the SaaS.
In the course of Customers using the SaaS, their customers, members, contractors or employees (“End Users”) may provide personally identifiable information to us using the SaaS via Customer websites or applications.
End User information, which may be considered personal data will be governed by our Master Agreement and Schedules providing the SaaS to our Customers who are the data controllers and who instruct us how to process the data or use the SaaS to process the data they collect. However, for entities or individuals that are Customers, and which are located in the European Economic Area (EEA) or Switzerland or serving subjects located in the European Economic Area (EEA) or Switzerland, we will govern our use of End User Data based on the execution of a Data Processing Addendum or other written agreement incorporating EU Standard Contractual Clauses for processors.
Individuals who have provided information to Built.io’s Customers must send requests regarding the exercise of their data subject rights under the General Data Protection Regulation (GDPR) and state implementing laws to the particular Built.io Customer who is the Data Controller.
Built.io may collect information automatically using web tracking technologies such as cookies, web beacons, pixel tags, clear GIFs and third party tracking services in order to ensure that the Sites and Services operate efficiently and to collect data related to usage of the Sites and Services such as, but not limited to, the browser type, language preference, referring site, and the date and time of each visitor request (“Tracking Information”).
We use both session-based and persistent cookies. Session-based cookies last only while your browser is open and are automatically deleted when you close your browser. Persistent cookies last until you or your browser delete them or until they expire. They are unique and allow us to do site analytics and customization, among other similar things. If you access our Site through your browser, you can manage your cookie settings.
Built.io does not link Tracking Information to individual user Personal Information; nor does it include the Personal Information with the Tracking Information that Built.io shares with the web tracking companies that use and process the Tracking Information, except as strictly necessary to provide and improve the Services (including customer support services). Some Tracking Information may include log or other data, such as IP address data, that is unique to you. You may be able to modify your browser settings to alter which web tracking technologies are permitted when you use the Sites and Services, but this may affect the performance of the Sites and Services.
If you do not wish to receive cookies, you may deactivate storing cookies on your computer by changing your browser settings accordingly. Please note that the functionality of the Sites and Services may be impaired and the range of functionalities may be severely limited if you deactivate cookies.
We collect the IP Addresses of Visitors and Customers, which is, in certain situations linked with users either through cookies, or for those Customers who log on to our Site to use the SaaS.
Customers who access Built.io's Sites or use the SaaS choose to interact with Built.io in ways that require Built.io to gather personally-identifying information such as name, address (email or physical), credit card billing information, username, passwords). The amount and type of information that Built.io gathers depends on the nature of the interaction.
We ask Visitors who sign up for an account at Built.io or who have questions to provide a username and email address.
Those who engage in transactions with Built.io by purchasing access to the Built.io platform to use the SaaS or sign up for a trial period - are asked to provide name, address and additional billing information (credit card or bank information) for provision to Braintree (we do not store payment information) and user name and password. Once signed up and the SaaS is purchased, Customer employees or contractors will be asked to provide their name and email address and a password.
We also collect Customer content and track Customer usage of the SaaS and other Services as part of the Services.
For Visitors, if you do not purchase the SaaS but want information, we use your contact information to follow up on your request. We may also ask your consent to communicate with you regarding the provision of services or notify you about new services, changes and improvements.
With respect to our Customers and their account users, Built.io does not disclose personal identifying information for marketing purposes other than as described below. We use such personal data, as well as Tracking Information connected with your personal data for purposes of account and services administration and providing the Services. We link IP Addresses with cookies and your email address in order to identify you and track your use of the Services.
For Customer employees or contractors we link your email address to the Customer master account to coordinate provision of the SaaS and related Services as well as to track usage of the SaaS.
If you provide your payment information, we will use that information to charge you for the Services you purchase using Braintree, but we do not store your credit card or other payment information.
We use Personal Data, Content, Tracking Information, and your usage history to detect fraud, abuse, violation of our contract terms, violation of any laws, rules or regulations, to ensure the stability and security of our Services, to protect the rights, property or safety of Built.io or to protect public safety and threats to public health
We will use Customer contact information to contact you via email or by phone, if necessary, to let Customers know about Services we and our affiliates provide, new Services or features or to update you regarding Customer use of the Services.
We use Tracking Information and usage history to improve the quality of our Services, including, but not limited to user experience.
To the extent permitted by law, Built.io will use Tracking Information to compile and/or create for analytical purposes, statistical, aggregated data relating to our users and the Sites and Services and display or share this information. Aggregated data is derived from Personal Information and Tracking Information but in its aggregated form it is de-identified in a manner so that it cannot be used to identify any individual or individuals. This data is used to understand our customer base, their needs, to develop, improve, and market our services.
Some web browsers may transmit “do not track” signals to the websites and other online services with which your web browser communicates. There is no standard that governs what, websites should do if they receive these signals. We currently do not respond to “Do Not Track” browser signals, settings or similar mechanisms. If and when a standard is established, we may revise our policy on responding to these signals. Third parties may collect personal information about your online activities over time and across sites when you visit the Sites or use the Sites or Services as set forth below.
We will not sell, rent, or share Personal Data with third parties outside of our company without your consent, except in the following ways:
Law Enforcement and Internal Operations
Built.io provides Personal Data and Tracking Information to our affiliates that need to use such Information to provide the Services.
We sometimes contract with other companies and individuals to perform functions or services on our behalf, such as software maintenance, data hosting, sending email messages, etc. We necessarily have to share your Personal Data with such third parties as may be required to perform their functions. We take steps to ensure that these parties take protecting your privacy as seriously as we do, including entering into Data Processing Addendum, EU Model Clauses and/or ensuring they have EU-U.S. and Swiss-US Privacy Shield certification.
Here is a list of the third party tools and applications we use which may collect Personal Data or Tracking Information from you directly on our behalf and share it with us
Braintree. Braintree processes payments on our behalf using credit card and other payment transactions. Braintree collects payment information and contact information to validate and process payments since we do not store credit card information. Braintree, which is owned by PayPal, is self-certified under the US-EU Privacy shield and we have entered into a Data Processing Addendum with them to familiarize yourself with Braintree's privacy practices and that of its parent company PayPal, go to https://www.paypal.com/us/webapps/mpp/ua/privacy-full
We also use Google Forms to collect inquiries from our Site. Processing takes place in the United States.
We use the tool Freshdesk supports us in the processing of customer requests using cookies. The recorded information is processed by Freshdesk on different servers some of which are located in the United States. Freshdesk information about your browser, your hardware and software, your Internet service provider as well as your IP address, which can also be sent to the United States. Freshdesk uses this information to provide the services described above. Freshdesk is self certified under the US-EU Privacy Shield and we have a Data Processing Addendum in place with them. For more information on data protection visit Freshdesk visit: http://www.freshdesk.com/privacy/ If you do not want to go to Freshdesk, you can refuse to set a cookie in your browser settings.
We use Salesforce.com to collect personal information related to sales (name, contact information, employer) in order to follow up on inquiries and sales to our customers or potential customers who have contacted us. Salesforce is self-certified under the US-EU Privacy Shield and the Swiss-U.S. Privacy Shield framework to process data in the United States and its data is only shared subject to a Data Protection Addendum as well as Binding Corporate Rules. For more information about SalesForce’s privacy practices follow this link to https://www.salesforce.com/company/privacy/full_privacy.jsp
We also may use Marketo to track, follow up and market products to existing customers based on the name, email address and other contact information provided and tracking information collected through cookies. If you would like to be removed from such marketing, follow the removal instructions at the bottom of the emails sent to you. Processing takes place in the United States. Marketo is self-certified under U.S.-E.U. Privacy shield. Data processed in the United States under a Data Privacy Addendum and Standard Contractual Clauses. Please refer to Marketo’s Privacy Notice for more information.
To sign documents we used the API (data interface) and services of HelloSign. It collects your name and other information necessary to execute contracts for digital signature. Hellosign is self certified under the US-EU Privacy Shield and we have a Data Processing Addendum in place with themFor more information on Hello Sign privacy, please visit Hello Sign: https://www.hellosign.com/info/privacyPolicy
We also may use Outreach to send you emails after you sign up for the Services or if you indicate an interest in receiving information and track your interaction with those emails based on the email address Customers provide to us. Outreach is also self-certified under the US-EU Privacy Shield program and we have a Data Processing Addendum with EU Standard Contractual Clauses in place with them. As with Outreach, if you wish for us to remove yourself, just follow the instructions at the bottom of the email communications. For more information on Outreach, follow the link to https://www.outreach.io/legal/privacy-policy/
We collect Customer Personal Data for potential customers to reach out to regarding the services.
Right to Review and Rectify Your Personal Data.
Customers can update most of their Personal Data by logging on to their account (except their contact email, which can not be edited because it is tied to the account). However, if additional assistance is required to change or delete inaccuracies within your Personal Data or you would like to know what information about you was collected, please contact us at privacy@Built.io.com.
Right to Remove or Withdraw Consent.
You have the right to withdraw consent where such consent is required to share or use data and you may request that we delete your Personal Data. If you receive communications from us and no longer wish to receive them, please follow the removal instructions in the email or change your account settings. You can delete your Personal Data by logging into your account and deleting your account.
However, since your Personal Data is required for us to provide the Services to you, deleting it, especially your email address, will also terminate your access to the services. Deleting your Personal Data does not mean that all of it will be removed. We may be required by law, to retain Customer Persona Data to exercise or defend legal claims, fulfill contractual obligations with our customers; retain some information in connection with our obligation to provide the Services. We may de-identify and anonymize some data for purposes of retaining it.
If you would like us to transmit your Personal Data to another company providing similar services, we will work with them to do so upon request and verification of such request with both the requestor and the company receiving the Personal Data.
We take steps to delete data after we no longer have a legitimate purpose for retaining it. After master accounts are terminated, we delete Customer Content data and End User data within 180 days after termination. We retain Customer information as long as necessary to achieve legitimate business purposes (such as to defend against legal claims or archive with anonymization techniques) or as required by law.
Protection of Personal Data
We have implemented reasonable administrative, technical and physical security measures to protect your personal information against unauthorized access, destruction or alteration. For example:
However, because no security system can be 100% effective, we cannot completely guarantee the security of any information we store, process or transmit.
The Sites and Services do not knowingly collect personal information from users under the age of 16 nor are they intended to be used by anyone under 16. If you are under the age of 16, you are not permitted to use the Sites and Services or to disclose Personal Information using the Sites and Services. If we learn we have collected or received Personal Information from a child under 16, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us at firstname.lastname@example.org.