NAVEX Global Privacy Statement
Effective November 12, 2012
This privacy statement applies to navexglobal.com and NAVEX websites, services and products that collect data and display these terms. It does not apply to any NAVEX Global site, service or product that does not display or link to this statement or that contains its own privacy statement.
NAVEX Global, Inc. (formerly Global Compliance Services, Inc., EthicsPoint, Inc., ELT, Inc. and Policy Technologies International, Inc.) is committed to protecting your privacy in a variety of ways including using industry accepted security measures to protect against loss, misuse and alteration of data contained in our systems. This Privacy Policy is designed to describe how we secure and maintain our customers' and visitors' personal information. Any information given to us will never be sold, rented, traded, or leased.
NAVEX Global does not publish text, images, or multimedia content that portray nudity, foul language, violence or other information not suitable for children. Web sites maintained by NAVEX Global are not directed to children under the age of 13. NAVEX Global will not knowingly collect or maintain personally identifiable information from or about anyone under 13. NAVEX Global is committed to complying with privacy laws to which it is subject and adhering to the highest industry standards for privacy.
NAVEX Global is not responsible for content saved to any NAVEX Global system by reporters or client company representatives.
Collection and Use of Personally Identifiable Information
NAVEX Global collects personally identifiable information from reporters, users of our products and services and visitors to our site in different ways.
Reporters:
No personally identifying information is automatically collected from reporters using NAVEX Global applications. Personally identifying information, such as name and email address, is stored only when a reporter voluntarily gives this information for use by a client company.
Clients:
Names, contact information, usernames and passwords for licensed users are stored in our database for access to our software applications. This information is kept secure on our private servers and is only used to assist you in accessing your account as a client. No information is released outside of the NAVEX Global system unless specifically authorized and requested by the client.
Visitors:
NAVEX Global enables visitors to submit personally identifying information such as name and email address through visitors' completion and submission of inquiry forms related to the provision of services and subscription forms associated with newsletters and seminars. When NAVEX Global collects personally identifiable information from opt-in participants, such information is used by NAVEX Global only to respond to visitors' requests. In instances where opt-in participants' requests relate to NAVEX Global partners, NAVEX Global will provide personally identifiable information only to respond to that request. NAVEX Global does not sell, rent, lease, trade or share visitors' personally identifiable information. NAVEX Global communicates only to users who affirmatively express an interest in receiving e-mails relevant to their interests, and visitors may "opt-in" and "opt-out" of receiving email communications through selections available on emails received. For participants of our web seminars, the only personally identifiable information we share is web seminar registration information and it is only shared with our web seminar presenters to provide this service. They are not permitted to use this information for their own marketing purposes.
Secure Communications
NAVEX Global will take reasonable precautions to protect personal information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction.
All communications between the NAVEX Global site and a user's web browser are accomplished using, at a minimum, 128 bit SSL encryption and Verisign certificates to protect confidential data. NAVEX Global does not allow users to transfer or receive confidential information unless they are using a validated 128 bit (or greater) encrypted session.
We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
If you have any questions about security on our Web site, you can send email us at itsecurity@navexglobal.com with "Questions about Web site Security" in the subject line.
We do not link this automatically-collected data to personally identifiable information.
Automatic Information Storage
Session Variables may be used temporarily in your system cache to create ease-of-use during your transaction. Examples of such information are automatically produced alphanumeric numbers held during your session on our site to facilitate page-to-page transactions. We only store name, email, phone, address, company name or any other identifying information for licensed users; no information is stored for others unless otherwise stated in this policy.
Use of Cookie and Log File Technology
A cookie is a small text file that is stored on a user’s computer for record-keeping purposes. NAVEX Global utilizes Cookie technology for purposes of Website traffic analysis such as the time/date of the visit, the time/date of last visit, the page viewed, the referrer, transaction information for eCommerce pages, and other data. NAVEX Global tracks click behavior in the e-mails it sends out. This data is used to update specific user-profile information, ascertain the areas of most interest to opt-in e-mail recipients, and to personalize e-mail messages to them. In addition, we use session ID cookies. These session Cookies are used to make it easier for you to navigate our site. A session ID Cookie expires when you close your browser.
If you reject Cookies, you may still use our site, but your ability to use some areas of our site, such as contests or surveys, will be limited.
In addition, some licensed users of our application access certain online forms where we offer these users the option to have the form pre-populate with their name, contact information, location, and other relevant information, through a Cookie. However, users are required to consent to the placement of a Cookie prior to it being activated and consent may be withdrawn at any time by simply accessing the form and un-ticking the box giving NAVEX Global permission to store the information. Any Cookie that is unused for 30 days will automatically expire.
As is true of most Web sites, we gather certain information automatically and store it in log files. This information includes internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and clickstream data.
We use this information, to analyze trends, to administer the site, to track users’ movements around the site and to gather demographic information about our user base as a whole.
We do not link automatically-collected data through the use of cookies and log files to personally identifiable information.
Use of Third Party Services
NAVEX Global contracts with third parties for Web-based services that include email delivery and content streaming, that may collect non-personally identifiable visitor data including IP address of their server and pages visited. These third parties may only use personally identifiable information, for example, email addresses, for the service requested and not for their own marketing purposes.
Terms
No company other than NAVEX Global is allowed to access information stored on our servers, unless expressly authorized by NAVEX Global. Unauthorized access to this information is a violation of the law. NAVEX Global has placed security measures and firewalls on all network servers in an attempt to prevent outside parties from accessing private information. In the event of a breach of security, NAVEX Global will press charges to the fullest extent possible against those parties illegally accessing information on our servers.
Safe Harbor
NAVEX Global complies with the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland. NAVEX Global has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. To learn more about the Safe Harbor program, and to view NAVEX Global’s certification, please visit http://www.export.gov/safeharbor.
Access to Personal Information
Upon request by mail or email (to the addresses noted below in the Contact Information section), NAVEX Global will grant individuals reasonable access to personal information that it holds about them, unless otherwise legally unable to do so. In addition, NAVEX Global will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete. NAVEX Global shall provide a response to an access request within 30 days of receiving such request.
Disclosure Pursuant to Judicial or Government Subpoenas, Warrants or Orders
We reserve the right to disclose your personally identifiable information as required by law and when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, or legal process served on our Web site.
Breach of Privacy Policy
If you have received unwanted, unsolicited email sent by NAVEX Global or from any NAVEX Global system or purporting to be sent via NAVEX Global, please forward a copy of that email with your comments to info@navexglobal.com for review.
NAVEX works with TRUSTe on its privacy policy and practices have been reviewed by TRUSTe for compliance with TRUSTe's program requirements including transparency, accountability and choice regarding the collection and use of your personal information. TRUSTe's mission, as an independent third party, is to accelerate online trust among consumers and organizations globally through its leading privacy trustmark and innovative trust solutions. If you have questions or complaints regarding our privacy policy or practices, please contact us at privacy@ethicspoint.com. If you are not satisfied with our response you can contact TRUSTe here.
If you have any complaints regarding our compliance with Safe Harbor you should first contact us at privacy@navexglobal.com with “Complaint regarding Safe Harbor Compliance” in the subject line. If contacting us does not resolve your complaint, you may raise your complaint with TRUSTe by Internet at http://www.truste.org/consumers/watchdog_complaint.php, fax at 415-520-3414, or mail at Watchdog Complaints, TRUSTe, 685 Market Street, Suite 270, San Francisco, CA, USA 94105. If you are faxing or mailing TRUSTe to lodge a complaint, you must include the following information: our name, the alleged privacy violation, your contact information, and whether you would like the particulars of your complaint to be shared with us. For information about TRUSTe or the operation of TRUSTe's dispute resolution process, see http://www.truste.org/consumers/watchdog_complaint.php or request this information from TRUSTe at any of the addresses listed above. The TRUSTe dispute resolution process shall be conducted in English.
Contact Information
Questions or comments regarding this Policy should be submitted to NAVEX Global by mail or e-mail as follows:
NAVEX Global, Inc.
Attention: Privacy Officer
6000 Meadows Road
Suite 200
Lake Oswego, OR 97035
USA
privacy@navexglobal.com
Changes To This Privacy Policy
If we decide to change our privacy policy, we will post those changes to this privacy statement, the home page, and other places we deem appropriate so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. We reserve the right to modify this privacy statement at any time, so please review it frequently. If we make material changes to this policy, we will notify you here, by email, or by means of a notice on our home page.


