LAST UPDATED: January 15, 2019
Due to the global nature of the aPriori Services, our privacy practices may vary among the states, countries and regions in which we operate in order to comply with applicable legal requirements.
1. INFORMATION WE MAY COLLECT
The aPriori Services gather certain information automatically, some of which may be considered personal information under applicable law.
We may collect, among other things, the following types of information:
- Address (including billing and shipping address)
- Telephone number
- Email address
- Fax number
- Professional information, such as employer or organizational affiliation for a customer or partner
- Payment or financial information for billing purposes
- Screen name
- Screen sharing views, at the request of customers, for support and QA purposes
- Any data in any files uploaded, emailed or otherwise provided by customers for support and QA
- Operating system type and version, web server type and version, database type and version
- Unique IDs such as a cookie placed on a computer or mobile device, or device IDs
- IP address or MAC address, and information derived from an IP or MAC address, such as geographic location
- Website server log information automatically reported by your browser each time you access a web page, which may include information such as your web queries or navigation requests, browser type, Internet Protocol (IP) address, number of clicks on website hyperlinks, the domain names visited, landing pages visited, and web pages viewed
- Browsing activities, cookies and similar data, and platform or mobile application use data
- Referring domain, destination domain and destination path
- User IDs and passwords for customers with accounts on the aPriori Services
- Information about the performance, security, software configuration and availability of our software on your servers and network
- Website user statistics and website and portal use and viewing activity records
- Communication preferences
- Other similar information
We may also collect information, including personal information, in the following situations:
- Registration, purchase and use of the aPriori Services: Information such as name, email address, telephone number, company/organization, financial information (for billing purposes), and other information, may be collected in connection with registration for, purchase of or use of certain aPriori Services. Customers may update their information by logging into their account. Information may also be collected to track license use.
- Communications: Personal information such as name, email address, and other information, may be collected, when provided in any communications, whether via email, social media, telephone or otherwise.
- Support: Personal information may be collected in connection with customer support, whether via screen sharing, email, social media, telephone or otherwise.
- Surveys and Research: We may collect personal information from anyone participating in research and surveys.
- User Comments and Content: If you post any comments or content on our website(s), you should be aware that any personally identifiable information you choose to provide there may be read, collected, or used by third parties. We are not responsible for the information you choose to submit and we cannot guarantee that third parties have not made copies of or will not use such information in any way.
2. USE OF INFORMATION
aPriori Services may use the information, including personal information, collected in connection with the aPriori Services for the purpose of providing the Services to our customers, as well as for supporting our business functions, such as fraud prevention, marketing, analytics and legal functions, and other legitimate purposes.
To the extent permitted by applicable law and, for customer data, as permitted by our customer agreements, we may use information collected in connection with our Services:
- To operate the aPriori Services and provide support.
- To fulfill customer requests, such as to create an aPriori Services account or complete customer purchases.
- To communicate with our customers; to inform customers and users of products, programs, services and promotions.
- To send customers information regarding the aPriori Services and issues specifically affecting aPriori Services.
- To respond to reviews, comments, or other feedback provided to us.
- To support and personalize our Services, websites, mobile services, and advertising.
- To protect the security and integrity of our Services, content, and our business.
- To provide support
- For benchmarking, data analysis, audits, developing new products, enhancing the aPriori Services, facilitating product, software and applications development, improving our services, conducting research, analysis, studies or surveys, identifying usage trends, as well as for other analytics purposes.
- To meet our contractual requirements, to comply with applicable legal or regulatory requirements and our policies, and to protect against criminal activity, claims and other liabilities.
- For any other lawful purpose for which the information is provided.
Aggregate Information. To the extent permitted by applicable law, we may use, process, transfer, and store any data about individuals and customers or partners in an aggregated manner. We may combine personal information with other information, collected online and offline, including information from third party sources. We may also use information in other ways with consent or as permitted by applicable law. By using the aPriori Services, our customers agree that we are hereby licensed to collect, use, share and store aggregated data collected through the aPriori Services for benchmarking, analytics, A/B testing, metrics, research, reporting, machine learning and other business purposes.
3. SHARING OF INFORMATION
To the extent permitted by applicable law, aPriori may share and disclose information, including personal information, as set forth below:
- Customers. We may share information with our customers and their service providers and other platforms that may assist those customers.
- Affiliates and Agents. We may share information with our affiliates or any business partners or agents acting on our behalf.
- Service Providers. We may share information with our service providers, agents, vendors and other third parties we use to support and advertise the aPriori Services and our business. We share personal information with such third parties to the extent necessary to provide services to us, and pursuant to binding contractual obligations.
- Advertising and Marketing. To the extent permitted by applicable law, we may share information with third parties for marketing, advertising, promotions, contests, or other similar purposes. If required by applicable law, we will share such data for advertising and marketing purposes only in an aggregate, anonymous, and de-identified manner.
- Mergers, Acquisitions, Divestitures. We may share, disclose or transfer information to a buyer, investor, new affiliate, or other successor in the event aPriori, or any affiliate, portion, group or business unit thereof, undergoes a business transition, such as a merger, acquisition, consolidation, reorganization, divestiture, liquidation or dissolution (including bankruptcy), or a sale or other transfer of all or a portion of any assets of aPriori or any affiliates or during steps in contemplation of such activities (e.g., negotiations and due diligence).
- Law Enforcement and National Security. We may share information with legal, governmental, or judicial authorities, as instructed or required by those authorities or applicable laws, or to comply with any law or directive, judicial or administrative order, legal process or investigation, warrant, subpoena, government request, regulatory request, law enforcement or national security investigation, or as otherwise required or authorized by law.
- Protection of Rights, Property or Safety. We may also share information if, in our sole discretion, we believe disclosure is necessary or appropriate to protect the rights, property or safety of any person, or if we suspect fraud or other illegal activity,
aPriori may also disclose personal information for other purposes or to other third parties when an individual has consented to, or requested, such disclosure, or where a customer has obtained permission from such individual, or where such disclosure is otherwise legally permitted for legitimate business purposes, and, for customer data, with such customer’s authorization or otherwise in accordance with aPriori’s agreement with such customer.
We may use the following types of cookies and similar technologies:
- Strictly necessary cookies required for the operation of the aPriori Services. They include, for example, cookies that enable you to log into secure areas.
- Analytical/performance cookies that collect information about how you use the aPriori Services. They allow us to recognize and count the number of visitors and to see how visitors move around our website. This helps us to improve the way our website works. [These cookies are sometimes placed by third party providers of web traffic analysis services.]
- Functionality cookies that remember choices you make and recognize you when you return. This enables us to personalize our content, greet you by name and remember your preferences (for example, your choice of language or region).
- Targeting cookies that collect information about your browsing habits such as the pages you have visited and the links you have followed. We use this information to make our website more relevant to your interests, and, if we enable advertising, to make advertising more relevant to you, as well as to limit the number of times you see an ad. These cookies are usually placed by third-party advertising networks. [They remember the other websites that you visit and this information is shared with third-party organizations, for example, advertisers.]
Most internet browsers accept cookies by default. You can block cookies by activating the setting on your browser that allows you to reject all or some cookies. The help and support area on your internet browser should have instructions on how to block or delete cookies. Some web browsers (including some mobile web browsers) provide settings that allow you to control or reject cookies or to alert you to when a cookie is placed on your computer, tablet or mobile device. Although you are not required to accept cookies, if you block or reject them, you may not have access to all of the features available through the aPriori Services. For more information, visit the help page for your web browser or see http://www.allaboutcookies.org or visit www.youronlinechoices.com which has further information about behavioral advertising and online privacy.
We may use third party analytics such as Google Analytics or similar analytics services. For information on how Google processes and collects your information regarding Google Analytics and how you can opt-out, please see https://tools.google.com/dlpage/gaoptout.
5. DATA RETENTION
To the extent permitted by applicable law, we may retain information for as long as the account of the customer for whom we collected the information is active, for at least twenty-four (24) months thereafter, or as long as is reasonably necessary to provide the aPriori Services or as needed for other lawful purposes. We may retain cached or archived copies of information. We may retain anonymized or pseudonymized, aggregated data indefinitely, to the extent permitted under applicable law. We may be required to retain some data for a longer period of time because of various laws and regulations or because of contractual obligations. We also will retain information as long as reasonably necessary to comply with our legal obligations, resolve disputes and enforce our agreements.
6. CHOICES AND OPT-OUT
To the extent required by applicable law, or in our discretion otherwise, we will allow customers and individuals to limit use of personal information. If at any time after providing us with your personal information such information changes or you change your mind about receiving information from us, you may request access to your data or that your data be changed.
If you no longer wish to receive our communications, you may opt-out of receiving them at any time by following the instructions included in each communication, by going to our Unsubscribe page https://get.apriori.com/SubscriptionManagement.html, or by mail at 300 Baker Avenue, Suite 330, Concord, MA 01742; Attn: Data Security Coordinator.
7. CROSS-DEVICE TRACKING
When you use your mobile device to interact with us or use the aPriori Services, we may receive information about your mobile device, including a unique identifier for your device. We and our service providers and third parties we collaborate with, including ad networks, may use cross-device/cross-context tracking. For example, you might use multiple browsers on a single device, or use various devices (such as desktops, smartphones, and tablets), which can result in your having multiple accounts or profiles across these various contexts and devices. Cross-device/cross-context technology may be used to connect these various accounts or profiles and the corresponding data from the different contexts and devices.
8. EMPLOYMENT OPPORTUNITIES
We provide you with a means for submitting your resume or other personal information through our website or Services for consideration for employment opportunities at aPriori. Personal information received through resume submissions will be kept confidential. We may contact you for additional information to supplement your resume, and we may use your personal information within aPriori, or keep it on file for future use, as we make our hiring decisions.
9. THIRD PARTY SITES
To prevent unauthorized access or disclosure, to maintain data accuracy, and to ensure the appropriate use of personal information, we employ procedural and technological measures that are reasonably designed to help safeguard the information we collect, including storing all personal information in secure databases protected via a variety of industry-standard access and security controls and procedures. Only authorized aPriori personnel have access to the personal information, including server logs and cookie utilization data that we collect. These individuals are required to follow strict security policies and procedures. aPriori may use encryption, secure socket layer, firewall, password protection and other physical security measures to help prevent unauthorized access to such. aPriori may also place internal restrictions on who in the company may access data to help prevent unauthorized access to such information.
Unfortunately, no data transmission over the Internet or data storage system can be guaranteed to be 100% secure. Therefore, despite our efforts, we cannot guarantee its absolute security. We do not warrant or represent that personal information about you will be protected against, loss, misuse, or alteration by third parties.
If you use the Services, you are responsible for maintaining the confidentiality of your access information and password. You are responsible for restricting access to your computer, and you agree to accept responsibility for all activities that occur under your password. We cannot secure any personal information that you release on your own, that you request us to release or that is released through another third party to whom you’ve given access.
Where required under applicable law or by contract, we will notify the appropriate parties or individuals of any loss, misuse or alteration of personal information so that such parties or individuals can take the appropriate actions for the due protection of their rights. If such personal information is information of an aPriori customer, we will notify such customer and coordinate with them regarding any required notices to particular individuals.
12. INTERNATIONAL DATA TRANSFERS
The aPriori Services may be provided using resources and servers located in various countries around the world, including the United States and other countries. Therefore, personal information about individuals or customers may be transferred, processed and stored outside the country where the aPriori Services are used, including to countries outside the European Union (“EU”), European Economic Area (“EEA”), the United Kingdom or Switzerland, where the level of data protection may not be deemed adequate by the European Commission.
13. CALIFORNIA PRIVACY RIGHTS
Under California’s “Shine the Light” law, California residents who provide personal information in obtaining products or services for personal, family or household use may be entitled to request and obtain from us, once per calendar year, information about customer information we have shared, if any, with other businesses for such other businesses’ own direct marketing uses. If applicable, this information would include the categories of resident information and the names and addresses of those businesses with which we shared such resident information for the immediately prior calendar year. To obtain this information, please contact us as indicated below. Please include sufficient personal identification information so that we can process the request, including that you are a California resident.
14. QUESTIONS, COMPLAINTS AND DISPUTES
Attn: Data Security Coordinator
300 Baker Avenue, Suite 170
Concord, MA 01742
Phone: +1 (978) 371-2006
CLASS ACTION WAIVER. YOU AND WE AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR OUR INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING.
“Personal Data” means any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of such natural person; and
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
EU-U.S. and Swiss-U.S. Privacy Shield Notice. We have certified our compliance with the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield (collectively, the “Privacy Shield Framework”) with respect to the Personal Data of users of the aPriori Services who are residents of the European Union (“EU”), European Economic Area (“EEA”), the United Kingdom and Switzerland that we receive and process through the aPriori Services. We certify that we adhere to the Privacy Shield Framework principles of notice, choice, onward transfer, security, data integrity, access, liability and enforcement (the “Privacy Shield Principles”) for Personal Data of users of the aPriori Services in the countries participating in the Privacy Shield Framework. We are responsible for the processing of personal data we receive under the Privacy Shield Framework and subsequently transfer to a third party agent, and may be liable for onward transfers in violation of the Privacy Shield Principles. Our certification is available here. We may also process Personal Data relating to individuals in Europe via other compliance mechanisms, including use of the European Union Standard Contractual Clauses.
Our legal bases for the processing of Personal Data are: (i) consent or (ii) any other applicable legal bases, such as our legitimate interest in engaging in commerce, offering products and services of value to the customers of aPriori Services, preventing fraud, ensuring information and network security, direct marketing and advertising, and complying with industry practices.
Additional Rights for European Residents. As a resident of the EU or a country following substantially similar legislation regarding the protection of Personal Data, individuals may have one or more of the following additional rights:
Access. To request a copy of the Personal Data we have collected about you by contacting us.
Rectification & Erasure. To request that we rectify or delete any of the Personal Data about you that is incomplete, incorrect, unnecessary or outdated.
Objection. To object, at any time, to Personal Data about you being Processed for direct marketing purposes.
Restriction of Processing. To request restriction of Processing of Personal Data about you for certain reasons, such as, for example, if you consider Personal Data about you collected by us to be inaccurate or you have objected to the Processing and the existence of legitimate grounds for Processing is still under consideration.
Data Portability. To request and receive the Personal Data we have collected about you in a commonly used and machine-readable form.
Right to Withdraw Consent. If Personal Data about you is processed solely based on your consent and not for any other legitimate interest, to withdraw your consent at any time, without affecting the lawfulness of our Processing based on such consent before it was withdrawn, including processing related to existing contracts for our products and services.
Right to Lodge a Complaint with a DPA. If you believe our Processing of Personal Data about you is inconsistent with the applicable data protection laws, to lodge a complaint with your local supervisory data protection authority (“DPA”).
To exercise any of the above listed rights, please contact us as set forth below and provide sufficient details so that we can respond appropriately. We will process any requests in accordance with applicable law and within a reasonable period of time. We may need to verify the identity of the individual submitting a request before we can address such request. If the request relates to data our customers collect and process through the aPriori Services, we will refer the request to that customer and will support them in responding to the request. For aPriori customers, certain information may be reviewed, corrected and updated by logging into the aPriori Services account and editing the profile information.
Questions and Complaints. Residents of a country participating in the Privacy Shield Framework may direct any questions or complaints concerning our Privacy Shield compliance to our Privacy Shield and Data Protection Contact. We will work with you to resolve your issue.
If we have not responded to a concern relating to data processed under the Privacy Shield Framework in a timely manner, or we have not addressed the concern satisfactorily, you may contact our U.S.-based dispute resolution provider, at no cost, at https://www.jamsadr.com/file-an-eu-us-privacy-shield-or-safe-harbor-claim. The services of such dispute resolution provider are provided at no cost to you. If neither aPriori nor our independent dispute resolution provider resolve your complaint, you may have the possibility to invoke binding arbitration through the Privacy Shield Panel. However, prior to initiating such arbitration, a resident of a country participating in the Privacy Shield Framework must first: (1) contact us and afford us the opportunity to resolve the issue; (2) seek assistance from our designated independent dispute resolution provider; and (3) contact the U.S. Department of Commerce (either directly or through a European DPA) and afford the Department of Commerce time to attempt to resolve the issue. If such a resident invokes binding arbitration, each party shall be responsible for its own attorney’s fees. Pursuant to the Privacy Shield, the arbitrator(s) may only impose individual-specific, non-monetary, equitable relief necessary to remedy any violation of the Privacy Shield Principles with respect to the resident.
For Human Resources Data Only: If you are an aPriori job applicant or employee in the EU, the United Kingdom or Switzerland with a Privacy Shield complaint about your human resources data, and that complaint cannot be resolved with aPriori directly, aPriori commits to cooperate with the panel established by the EU data protection authorities (DPAs) and/or the Swiss Federal Data Protection and Information Commissioner, as applicable, with regard to that human resources data complaint. Please contact us to be guided to the relevant DPA office and contact information. A binding arbitration option will also be made available to you to address complaints not resolved by any other means.
U.S. Federal Trade Commission Enforcement. aPriori’s commitments under the Privacy Shield are subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
Compelled Disclosures. aPriori may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Privacy Shield and Data Protection Contact. Unless otherwise specified, the data controller of personal data uploaded to the aPriori Services is the aPriori customer for whom such Services are provided and aPriori is the processor of such data for such customer. In certain cases, aPriori may also be the controller of aggregated, anonymous or pseudonymous data relating to the aPriori Services. Our Privacy Shield and Data Protection Contact for the personal information collected in connection with the aPriori Services is:
Attn: Data Security Coordinator
300 Baker Avenue
Concord, MA 01742
Phone: +1 (978) 371-2006