- The data practices on the DoControl website at docontrol.io (“Website”).
- DoControl’s practices with respect to the SaaS (the “Service”) that DoControl provides its customers (“Businesses”). As background, the Service offers Businesses a modern security layer enforcing advanced security features on the multiple SaaS applications they use, regardless of each SaaS application’s underlying capabilities.
PERSONAL DATA PROCESSED
We collect and process your contact information and billing information when you send us an inquiry or engage us to use our Service
You may contact us through email: firstname.lastname@example.org. When a representative of a Business wishes to use our Service, we collect that person’s contact details such as full name, email address, and information relating to the engagement between us and the Business. We will also collect, if necessary payment information such as credit card or bank account information in order to bill you for the Services. We refer to this as “Contact Information”.
The Service we provide involves processing information of the Business’s users
In order to provide the Service to a Business, we process personal information of the Business’s users using the Service. This includes your full name, email address and account user name.
The Service also processes personal data regarding the usage behavior and usage patterns in relation to the SaaS applications that the Business’s users use. This includes the end-user’s IP address and approximate location derived from the IP address.
We refer to this overall data as “Usage Information”.
You do not have a legal obligation to provide us with your Contact Information or Usage Information. However, if you choose to not share this information with us we may not be able to respond to your inquiry or provide you the Service.
We also collect analytics information about your use of the Website
When you visit the Website, we record and collect certain information about your interaction with the Website, including the IP address from which you access the Website or Service, time and date of access, type of browser used, language used, links clicked, and actions taken while using the Website or Service. We refer to this data as "Website Analytics Information".
DATA CONTROLLER AND PROCESSOR
The Business is the data controller of the Contextual Data like file names and sender and recipient information; DoControl is the merely data processor for this data.
Each Business is the data controller of its own Contextual Data (as defined below). DoControl may process the Contextual Data only for the provision of the Service to you.
For that matter, Contextual Data means information: (a) that identifies or depicts the Business’s content that is controlled or monitored through the Service, such as, by way of example only, file names; or (b) that identifies individuals who have a bearing to the Business’s content, such as, for example, sender or recipient name and email address.
HOW WE PROCESS PERSONAL DATA
To respond to and handle your inquiry and manage our relationship with the Business
We process your Contact Information to contact you about your inquiry and handle your inquiry, to bill for the Service and manage our engagement with the Business.
To provide you with the Service
We process Usage Information in order to give you access to use the Service.
To understand user behavior and assess security risks
We also process Usage Information in order to detect and assess security threats and calculate security risk scores which in turn helps us to improve the Business’s security posture regarding the SaaS applications that you and your fellow co-workers use.
We also aggregate data on how you and your fellow co-workers use SaaS applications and use that to detect threats and calculate risk scores on an organization-level (Business-specific), app-level, and user-level basis.
We refer to this overall data as "Risk Assessment Information".
To maintain the Website
We process the Website Analytics Information to provide, maintain and improve your user experience when accessing our Website. We also will use the Analytics Information for quality assurance and for development and enhancement of the Website.
WHO PROCESSES YOUR DATA
We will not share your information with third parties, except in the events listed below or when you provide us your explicit and informed consent.
We will share Risk Assessment Information associated with your account with the representatives of the Business you work at.
We will share Usage Information and Risk Assessment Information associated with your account with representatives of the Business you work at, for their visibility into the organization-level, app-level, and user-level security risks.
We will process information with our service providers helping us to operate our business.
We will process personal information with the assistance of our service providers who assist us with the internal operations of the Website and Service. These companies are authorized to use your personal information in this context only as necessary to provide these services to us and not for their own promotional purposes. These service providers include Amazon Web Services, Inc.
We will share information with competent authorities, if you abuse your right to use the Service, or violate any applicable law.
If you have abused your rights to use the Website or Service, or violated any applicable law, we will share information with competent authorities and with third parties (such as legal counsels and advisors), for the purpose of handling of the violation or breach.
We will share your information if we are legally required.
We will share information if we are required to do so by a judicial, governmental or regulatory authority.
We will share your Information with third-parties in any event of change in our structure.
If the operation of our business is organized within a different framework, or through another legal structure or entity (such as due to a merger or acquisition), we will share information only as required to enable the structural change in the operation of the business.
What are cookies?
Cookies are text files, comprised of small amount of data, that are saved on your computer or other device (e.g. smartphone, tablet, etc.) when you use the internet and visit various websites.
The information that the cookies maintain is read by the website you visit, during the session of your visit to the website (these are called ‘session’ cookies), and when you return to visit it again (these are called ‘persistent’ cookies).
Necessary. Cookies that are strictly necessary for the functioning of the Website. The Website cannot operate properly without these cookies. You can set your browser to block or alert you about these cookies, but some parts of the Website may not function properly.
Statistics. Analytics cookies that help us understand how you and other users interact with our Website by collecting data that does not directly identify you.
You can always delete or disable cookies.
You can always delete the cookies saved on your device through the settings of your computer browser or device. You can also disable cookies for future use through the settings of your computer browser or device.
SECURITY AND DATA RETENTION
We generally will retain your Contact Information, Usage Information, Risk Assessment Information and Analytics Information for as long you and your Business uses the Service, and thereafter for another 45 days.
We will retain Contact Information, Usage Information and Analytics Information for the duration needed to support our ordinary business activities in providing the Service to you and your Business. Thereafter, we will retain your information for another 45 days following termination of our Service to you. After 45 days, we will either anonymize or delete the information, unless we are required to retain such information under applicable law.
Nevertheless, we will retain financial transaction information about bills and charges for the extended period required for financial bookkeeping purposes.
We implement measures to secure your Information
We implement measures to reduce the risks of damage, loss of information and unauthorized access or use of information. These include encryption for data in transit and at rest. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure personal information, it is not guaranteed, and you cannot expect that the Website or Service will be immune from information security risks.
INTERNATIONAL DATA TRANSFERS
We will internationally transfer information in accordance with applicable data protection laws.
If we transfer your personal data for processing at locations outside your jurisdiction, we will abide by data transfer rules applicable to these situations.
ADDITIONAL INFORMATION FOR INDIVIDUALS IN THE EU
DoControl’s contact information
The following is the contact information of DoControl:
100 riverside blvd suite 14p, New York, NY 10069
Legal basis under EU law for processing your personal data.
The legal basis under EU law for processing your Contact Information for the purpose of responding to and handling your inquiry, is our legitimate interests in responding to your inquiry.
The legal basis under EU law for processing Contact Information to bill for the Service and manage our engagement with the Business is our legitimate interests in receiving the payments due for the Service and administering our relationship with the Business.
The legal basis under EU law for processing Usage Information to give you access to the Service is your and our legitimate interests in providing the Service you’ve signed up for.
The legal basis under EU law for processing Risk Assessment Information in order to detect and assess security threats and calculate security risk scores, is the legitimate interest of you and the Business in improving their information security.
The legal basis under EU law for processing Website Analytics Information is our legitimate interest in maintaining, developing and enhancing the Website.
The legal basis under EU law for processing your Website Analytics Information for the purpose of handling instances of abusive use of the Website is our legitimate interests in defending and enforcing against violations and breaches that are harmful to our business.
The legal basis under EU law for sharing Usage Information and Risk Assessment Information associated with your account with representatives of the Business you work at the legitimate interest of the Business you work at in improving their information security.
The legal basis under EU law for processing your information with authorities or where we are legally required to share it, is our legitimate interests in complying with mandatory legal requirements imposed on us.
The legal basis under EU law for processing your information in the event of a change in our corporate structure is our legitimate interests in our business continuity.
You have certain rights to access, update or delete information, obtain a copy of your information, and object or restrict certain data processing activities.
If you are in the EU, you have the following rights under the GDPR:
Right to Access your personal data that we process and receive a copy of it.
Right to Rectify inaccurate personal data we have concerning you and to have incomplete personal data completed.
Right to Data Portability, that is, to receive the personal data that you provided to us, in a structured, commonly used and machine-readable format. You have the right to transmit this data to another service provider. Where technically feasible, you have the right that your personal data be transmitted directly from us to the service provider you designate.
Right to Object, based on your particular situation, to using your personal data on the basis of our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or for the establishment, exercise of defense of legal claims. You may also object at any time to the use of your personal data for direct marketing purposes.
Right to be Forgotten. Under certain circumstances, such as when you object to us processing your data and we have no compelling legitimate grounds to override your objection, you have the right to ask us to erase your personal data. However, we may still process your personal data if it is necessary to comply with a legal obligation we are subject to under laws in EU Member States or for the establishment, exercise or defense of legal claims.
If you wish to exercise any of your EU rights, please contact us at: email@example.com.
We reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. Where we are not able to provide you the information that you have asked for, we will explain the reason for this.
You have a right to submit a complaint to the relevant supervisory data protection authority.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint to the supervisory authority, in particular in the Member State of your residence, place of work or place of alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here.
CHANGES TO THIS PRIVACY NOTICE
Last Update: February 3, 2021