Last Updated: May 23, 2018
At Documoto, we take your privacy seriously. This Policy describes how we collect, use, process, and disclose information that we gather about you. This information comes from our primary website www.documoto.com and other sites we use from time to time such as support.documoto.com (“Websites”); from usage of the Documoto Web Application and Software through web browsers, APIs, and the Documobile application (“Services”); and from your interactions with Documoto personnel through phone calls, emails, and other methods. This Policy also outlines your rights and choices with regard to the information collected about you.
This policy applies to all visitors to our website, to all users of our Services, whether or not you are a paying customer, and to all other individuals that have interactions with Documoto, Inc. When you use our Services, access our Websites, or contact Documoto personnel, you are accepting the terms, conditions and practices within this Policy.
For EU Residents, this Policy is intended to comply with the EU General Data Protection Regulation (“GDPR”). If you have any questions about this Policy, please contact us at firstname.lastname@example.org.
Information We Collect About You
We receive information about you that may be personally identifiable, such as your name and email address, and other information that does not identify you. This Policy is intended to cover information about you that could be considered personally identifiable information, or could be utilized to connect you to personally identifiable information.
Our Services are used by customers and their designated users to create, distribute and share information (“Content”) from a variety of sources. While principally technical in nature, this Content may include personal information about you, obtained by our customers or provided by you through provisioning the Services, through Services features such as comments, transactional activities such as shopping cart and order submittals, and other means. All Content, including your login information under the customer’s account, is owned by our customers, and Documoto has no control over this Content. As a provider of the Services, acting under the direction of our customers, Documoto is acting in the role of a Processor for all Content managed by the Services.
Documoto collects data about you through your interactions with our Websites, through your interactions with our Services, and through your interactions with Documoto personnel. We also collect information about you from third- party sources that extend or enrich information that you have provided.
Information You Provide. When you interact with our websites, you may volunteer information such as name, email address, and other personally identifiable information. You may also provide information through your use of the Services, such as updating your profile or adding an email address. During interactions with Documoto personnel, you may provide any type of information to Documoto at your discretion. If you transact business with us, you may be asked to provide further information such as billing address, credit card number, or other financial information. However, aside from financial information required to transact business, we do not request sensitive information from you. If you attend events such as webinars, whether directly through Documoto or via a Documoto partner, you may provide personal data such as your name, email, and phone number.
Information Others May Provide. Our customers, through their interaction with the Services, may provide us with information on you that they require for your use of the Services or that is needed to provision your account.
Information from Other Sources. We may obtain other information about you, including personal and non-personal information, from publicly available sources, or from third parties that provide data enrichment services. We use these sources to obtain additional information about you such as your address and location, your employer, and other demographic data.
Information from tracking technologies. Our Websites and Services use several technologies to collect information about you, your browser, your computer, and how you are interacting with us. Some of these technologies are provided by third parties, which are not covered under this Policy.
• Cookies. Our Services and Websites utilize cookies to provide a personalized online experience and to track your online activities, including the pages you visited, the links you clicked, and other activities. We do not allow any cookies used for tracking or advertising outside of Documoto.
• Internet information. We may use standard internet techniques to collect technical and implicit information about you, such as your IP address, your IP country and location, date/time stamps, referring URL, and other information.
• Website monitoring. Our Services and Websites may also use technologies to monitor your interactive session, such as tracking the time you spend on various pages, your mouse movements, and your overall navigation through the Services and Websites.
• Beacons. Emails sent to you by the Websites and Services may contain standard technologies such as web beaconstotrackyourreadingoftheemailandyournavigationthroughanyofthelinkswithintheemail. This tracking enables us to understand the usefulness and effectiveness of these emails and associated campaigns and activities.
• Analytics. We may use providers such as Google Analytics to collect and process non-personal information about you, which we use to better understand the usage of our Websites and Services.
Our Websites and Services are intended to be used by adults only. We do not knowingly collect any personal information from children under the age of 13.
Where We Store Information About You
Our principal data center is located in the United States. Information may also be sent to servers in other countries around the world.
How We Use and Share Your Information
All usage is for legitimate business interests, which are not overridden by your interests and fundamental rights. We use your information within Documoto for the following purposes:
• To provide you with access to the Services and the functionality contained within them.
• To personalize your experience with the Services and Websites.
• To assist our customers where they are providing support to you.
• To perform normal business operations such as billing, order fulfillment, legal, and administration.
• To notify you regarding the status of the Services and Websites.
• To provide you with support and incident assistance on the Services and Websites.
• To communicate with you by phone, email, postal mail, or other means such as social media and text
• To help us with our marketing and sales efforts.
• To email tailored sales and marketing information to you, if you have not opted out of these communications.
Page 2 of 4 Documoto_Privacy_Policy_20180523
• To compile analytics and statistics on your use of our Services and Websites so that we can better understand how they are used and how we might improve them.
How We Share Your Information
All of the information we collect about you is used only for Documoto purposes. We do not share information with others except as detailed below, and we do not sell your information to third parties.
• Authorized service providers. We may share information with third party service providers where it is required to perform a business activity, such as processing a credit card, delivering an email, supporting our Websites and Services, or other functions. We share only the information needed to perform the business activity, and the service provider is not permitted to use your personal information for any other purpose.
• To legal authorities in response to a lawful demand. How We Protect Your Information
We utilize a variety of controls and procedures to prevent unauthorized use and disclosure of your personal information. Our Websites and Services have appropriate hardware and software restrictions that limit access. We grant access to employees only to the minimum extent needed to conduct their job responsibilities. Passwords are salted and hashed prior to encryption and cannot be deciphered even by Documoto employees. All information is encrypted in transit to prevent your information from being compromised.
Our Services are provided under a SaaS model and hosted at Amazon Web Services. We utilize techniques and technologies such as VPNs, data isolation, password complexity rules, firewalls, and IP restrictions to limit access, and reporting and monitoring tools to notify us of unauthorized attempts at access. If you would like further information on our security model, security monitoring, or physical access, or would like information on SSAE 16 audits or SOC1/SOC2 reports, please contact email@example.com. Some information is only available upon executing a Non-Disclosure Agreement.
Your information security is a shared responsibility between you and your partner companies, including Documoto. No system can ever be perfectly secure, and while we have undertaken many actions to secure your information, we cannot promise that your information will always remain secure. Please always take care to protect your personal information, avoid unsecure mechanisms such as email when communicating personal information, and notify us immediately at firstname.lastname@example.org if you suspect any unauthorized access or compromise of your personal information.
In some cases, your information may be stored and managed by third party solution providers such as Google or Hubspot, which are not covered under this Policy.
How You Can Manage Your Information
If you have concerns regarding personal or sensitive information that may be contained within Content, or you would like to review, modify, or delete Content, please notify the appropriate Documoto customer directly. We can assist you with finding and contacting the customer.
You may opt out of sales and marketing emails by following the instructions in any email that is sent to you, or contact Documoto at email@example.com. We may still send you important transactional, event, or administration emails to you, even if you have opted out of sales and marketing emails.
How We Update This Policy
We may update this Policy from time to time to reflect changes to our practices or to ensure compliance with legal frameworks. For significant and material changes, we will attempt to notify you by email using the address in your account, and/or we will post the notice through the Websites and/or Services prior to the change taking effect.
Published May 23, 2018