WEBSITE PRIVACY PRACTICES
The following terms apply to users of our Website.
COLLECTION – WEBSITE
How we collect your personal information depends upon how you use and interact with our Website. Some information is provided directly by you, while other information may be collected through automated technologies.
Legal Basis for Collection. When accessing our Website, we collect personal information from you where 1) we have your consent, 2) where your personal information is necessary for us to provide a Service (for example, when you register for a webinar), or 3) where we have a legitimate interest to process your information and that legitimate interest is not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may have a legal obligation to process your personal information, or to process your personal information in order to exercise, establish or defend legal claims.
Website Access. More specifically, we may collect information when you provide it directly to us though the Website in webforms such as webinar registration forms or when you download white papers, articles or other collateral. The type of information collected on these forms includes the following:
Website Information Collection
We may collect the following types of information from you:
- First Name / Last Name
- Email Address
- Work Location
- Job Title
- Log-in credentials
Collected from Third Parties. We may receive information about you from other sources, including publicly available databases or third parties from whom we have purchased data, and combine this data with information we already have about you. This helps us to update, expand and analyze our records, identify new customers, and provide information about products and services that may be of interest to you. If you provide us personal information about others, or if others give us your information, we will only use that information for the specific purpose for which it was provided to us. Examples of the types of personal information that may be collected from external sources include name, business contact details such as email, phone number, and job title.
Do Not Track Requests. NAVEX Global does not process or respond to “Do Not Track” signals from your browser or other mechanisms that enable choice regarding the collection of personal information about your online activities over time and across third-party websites or online services.
HOW WE USE PERSONAL INFORMATION – Website
We use personal information collected from the Website to respond to requests for information, including marketing and advertising communications, and to continue developing and improving the Website.
When you make requests on the Website We use information collected from on the Website to respond to visitors' requests. NAVEX Global does not sell, rent, lease, trade or share visitors' personal information other than as outlined in this Policy. When you provide us with your personal information or otherwise choose to sign up to receive email communications from us, we will use that information to send those communications to you. Individuals may "opt-out" of receiving e-mail communications through links available on e-mails received.
Webinar Participants. For participants of our web seminars (“webinars”), the only personal information we share is webinar registration information and it is only shared with our webinar presenters for the limited purpose of providing this service.
Interest Based Ads. Some information, like name and email, are collected for advertising purposes. This means you might see an advertisement from us on other sites you visit. Sometimes we allow third party advertising companies and ad networks to use automatic data collection technologies to collect similar information about you for purposes of providing you with interest-based ads. Interest-based ads are helpful because they are more likely to be tailored to your particular interests. They are also more likely to help you discover new services that are actually relevant to you and your interests. Also, if interest-based tracking is enabled, you likely will not see the same ads over and over because the number of times you see a particular interest-based ad is usually limited. By opting-out of interest-based ads, you lose all of these benefits.
Data Retention. Where NAVEX Global serves as the controller of the data, such as where we use personal information for our own independent business purpose, we will retain your information in accordance with our data retention practices as follows: We will retain your information for the necessary period of time that it serves the purpose for which it was originally collected or subsequently authorized and in accordance with applicable law. For example, we will retain your information for as long as your account is active, as necessary to comply with our legal obligations and rights, to resolve disputes, and to enforce our agreements.
HOW WE SHARE INFORMATION – Website
Where we share personal information with third parties, we do so as set forth below. Any information we collect will never be sold, rented, traded, shared or leased other than as outlined in this Privacy Statement.
Service Providers and Analytics. NAVEX Global contracts with select third parties to provide us with Web-based services that include e-mail delivery and content streaming; these services may collect certain visitor data and click through data, including IP address, referring page, pages visited on our Website and whether you opened and email, and clicked on any content within that email. These companies are authorized to use directly identifying data, for example, e-mail addresses, only as necessary to provide for the service requested, in accordance with NAVEX Global’s privacy practices and pursuant to written instructions.
Posts and Feedback. Our web properties offer publicly accessible community forums and discussion boards. You should be aware that any information you provide in a community forum or discussion board may be read, collected, and used by others who access them. To request removal of your personal information from our discussion board or community forum, contact us at email@example.com. In some cases, we may not be able to remove your personal information and if that is the case, we will let you know and the reason why. If you choose to comment on our blog you will be required to create an account and login to a third-party’s site to do so. The third party solely manages the login component and any personal information you provide to them.
YOUR RIGHTS – Website
NAVEX Global acknowledges that you may have the right to access your personal information.
Rights provided under the Privacy Shield Frameworks to personal information transferred from European Union (EU) member countries and Switzerland to the United States. NAVEX Global respects your control over your information and, upon request, we will confirm whether we hold or are processing information that we have collected from you. You also have the right to amend or update inaccurate or incomplete personal information, request deletion of your personal information or request that we no longer use it. Under certain circumstances we will not be able to fulfill your request, such as if it interferes with our regulatory obligations, affects legal matters, we cannot verify your identity, or it involves disproportionate cost or effort, but in any event we will respond to your request within a reasonable timeframe and provide you an explanation. In order to make such a request of us, please use this web form.
Application Users Note. Please note that where personal information is collected within the software applications we offer, we do so on behalf of customer organizations, which determined the means and purposes of processing, and those customer organizations manage the data in accordance with their own internal policies and procedures. Any questions related to how that customer organization may process, use or share your information should be directed to that customer organization by contacting them directly. Unless otherwise prohibited by law, we will honor and support any instructions they provide us with respect to your personal information.
European Economic Area, Switzerland or United Kingdom Citizen Rights. Individuals who reside in the European Economic Area (EEA), including Switzerland and the United Kingdom (UK) have additional rights reserved under the General Data Protection Regulation (GDPR), the UK Data Protection Act and/or ePrivacy Directive, as applicable. This section details those additional rights and information on how to exercise them:
- You may request to access, correct, update or request deletion of your personal information based on information collected from accessing our Website or participating in our Forums or Webinars.
- You may request additional information related to the purposes for which we process your personal information, the categories of personal information we process, where we originally collected the information, who we share it with, and how long we will retain it.
- You may object to our processing of your personal information, request that we restrict the processing of your personal information or request portability.
- You have the right to opt-out of marketing communications we sent you at any time. You can do so by clicking the “unsubscribe” or “opt-out” link in the marketing emails we send to you. You may also opt-out of other forms of marketing (such as postal or telemarketing).
- Where we have collected and processed your personal information with your consent, you can withdraw your consent at any time. However, withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal nor will it affect the processing of your personal information conducted in reliance on lawful processing grounds other than consent.
- Upon your request, and where it is technically feasible, NAVEX Global will provide you with a copy of your personal information or transmit it directly to another controller.
- You have the right to submit a complaint to a data protection authority about our collection and use of your personal information. For more information, please contact your local data protection authorities. Contact details are available here.
To make a request please use this web form or email us at firstname.lastname@example.org with “Personal Information Request” in the subject line, and provide us with full details in relation to your request, including your contact information and any other detail you feel is relevant. NAVEX Global will provide a response to an access request within 30 days of receiving such request or if we cannot, we will notify you and provide you with the reason for the delay.
Identity Verification Requirement. We are required by law to verify that any request submitted was made by someone with the legal right to access the data. Therefore, prior to accessing or divulging any information pursuant to a data subject access request, we may request that you provide us with additional information in order for us to verify your identity and legal authority.
Under certain circumstances we may not be able to fulfill your request, such as where doing so would interfere with our regulatory or legal obligations, where we cannot verify your identity, or if your request involves disproportionate cost or effort; in any event, we will respond to your request within a reasonable time frame and as required by law, and provide you an explanation.