Last updated: July 10, 2018
1. WHO IS THE CONTROLLER OF YOUR PERSONAL INFORMATION?
Now is the controller of your personal information. We are responsible for, and control, the processing of your information.
2. WHAT INFORMATION DO WE COLLECT?
In the context of rendering our Services, we may collect information about you. This information regularly includes the following:
• If you create an account: Name, email address, phone number, password, Internet Protocol (IP) address.
• If you request our products or services or if you make a purchase: Name, email address, mailing address, phone number, company name, job title, IP address, information on the purchase or request, information on your payment.
• If you complete a Now form or application: Name, email address, phone number, IP address.
• If you contact us (via our Sites or via phone, sms, email or letter), e.g. for an information request support request or any other inquiry: Name, email address, phone number, IP address, information on our communication with you and any additional information you provide.
• If you sign up for our newsletter: Name, email address, information on whether you are already a customer, marketing campaign information such as your reaction to our marketing, whether you open our marketing emails or click the links contained in these emails.
• If you participate in our online surveys or any of our marketing initiatives, including contests, events or promotions: Name, email address, phone number, information on the event you participated in.
• If you participate in our forums, reviews or provide user-generated content or submissions: Name, email address, phone number, password, IP address, any other information you submit.
• If you merely visit our Sites: IP address, network file system, browser data, browser type, device type, device ID, Uniform Resource Locators (URL), operating system, internet service provider, referring and exit pages, date/time stamp, clickstream data, language preferences, whether you access the Service from multiple devices, and other actions you take on the Sites.
When you access our Service from a mobile device, we may collect unique identification numbers associated with your device or our mobile application (including, for example, a UDID, Unique ID for Advertisers (“IDFA”), Google AdID, or Windows Advertising ID), mobile carrier, device type, model and manufacturer, mobile device operating system brand and model, phone number, and, depending on your mobile device settings information on your usage of our Sites.
• If you connect to our Service from third-party sites: We may receive personal information about you from third parties and combine it with information we collect through our Service. For example, we may obtain information when you log in through a third-party social network or authentication service, such as Google or Facebook. These services will authenticate your identity and provide you the option to share certain personal information with us, which could include your name, email address, address book and contacts, or other information. Our Service integrates with social sharing features and other related tools which let you share actions you take on our Service with other apps, sites, or media, and vice versa. Your use of such features enables the sharing of information with your business associates, friends or the public, depending on the settings you establish with the social sharing service. Similarly, when you interact with us through a third-party service, we may receive information from such third party service, including your profile information, picture, user ID associated with your account, and any other information you permit the third party service to share with third parties. The data we receive from these third-party sites is dependent upon that third party’s privacy policies and your privacy settings on that third-party site. You should always review and, if necessary, adjust your privacy settings on third-party websites and services before linking or connecting them to our Service.
3. HOW DO WE COLLECT YOUR INFORMATION?
This personal information is collected in many ways and may include:
• personal information you provide to us directly: Most of the personal information we receive comes to us voluntarily from our users in the course of using our Services, such as when visiting our Sites, communicating with us or in the process of requesting and using our Service.
You are free to choose which information you want to provide to us or whether you want to provide us with information at all. However, some information, such as your name, address, payment information and information on your requested Services may be necessary for the performance of our contractual obligations. Without providing this information, you will not be able to request or use certain Services or enter into a contract with us.
• Information we receive from third parties. From time to time, we may receive information about you from third parties and other users, for example if you choose to link, create, or log in to your Now account with a third party website that uses our API, or whose API we use, we may receive information about you or your connections from that third party. We may also receive personal information from law enforcement agencies and marketing partners.
4. WHY AND ON WHICH LEGAL GROUNDS DO WE COLLECT AND USE YOUR PERSONAL INFORMATION?
Please note, that the notice on the legal grounds refers to the legal justifications under the European General Data Protection Regulation (“GDPR”) only.
The reasons for using your personal information may differ depending on the purpose of the collection. Regularly we use your information for the following purposes and on the following legal grounds:
• We use your information in order to perform our contractual services or in preparation for a contract with you. If you order Services from Now or if you contact us to request our Services, we use your information to provide to you the features and functionality of the Services. Information we use includes: information we need to contact you or otherwise communicate with you; information to manage your account; information to enable the usage of Services; information necessary for customer support; information for invoicing and payment follow up.
• We use your information if justified by our legitimate interests. The usage of your information may also be necessary for our own business interests. For example, we may use some of your information to evaluate and review our business performance, create financial statements; improve our Services or to identify potential cyber security threats. If necessary we may also use your information to pursue or defend ourselves against legal claims. If you are already a customer, we may use your email address and names for our email marketing campaigns. You can object to this use at any time by following the link to unsubscribe at the bottom of our marketing emails.
• We use your information after obtaining your consent. In some cases, we may ask you to grant us separate consent to use your information. You are free to deny your consent and the denial will have no negative consequences for you. You are free to withdraw your consent at any time with effect for the future. If you have granted us consent to use your information, we will use it only for the purposes specified in the consent form.
• We use your information to comply with legal obligations. We are obligated to retain certain information because of legal requirements, for example, tax or commercial laws.
We will only use your information for the purposes for which we have collected them. We will not use your information for other purposes. We do not use your personal information for automated individual decision-making.
5. WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
We may share your personal information with:
• Promotional partners: We share your personal information with third parties when you engage in certain activities through our Services that are sponsored by them, such as purchasing products or services offered by a third party, electing to receive information or communications from a third party, or electing to participate in contests, sweepstakes, games or other programs sponsored, in whole or in part, by a third party;
• Service providers and advisors: We share your information with third party vendors and other service providers that perform services on our behalf, as needed to carry out their work for us, which may include identifying and serving targeted advertisements, processing of payments, handling of data processing, data verification, data storage, surveys, research, internal marketing, delivery of promotional, marketing and transaction materials, and maintenance and security. These third parties include: Facebook, Inc., Google, Inc., Gartner, Inc., International Data Corporation, Stripe, ObjectLabs Corporation, Amazon, Inc., Salesforce, Inc. (including Pardot), Invoice Ninja, Survey Monkey, Inc., Wootric, Slack, and G2 crowd, Inc. Any such service providers and advisors will be given limited access to personal information as it reasonably necessary for delivering its service and will, if they are acting on our behalf and exclusively under our instructions, be bound by appropriate data processing agreements;
• Purchasers and third parties in connection with a business transaction: We may disclosed your information to third parties in connection with an Now related transaction, such as a merger, sale of Now assets or shares, reorganization, financing, change of control or acquisition of all or a portion of our business by another company or third party, or in the event of a bankruptcy or related or similar proceedings;
• Law enforcement, regulators and other parties for legal reasons: We may disclose your personal information to third parties as required by law or subpoena or if we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to enforce our Terms of Service or to protect the security or integrity of our Service; and/or (c) to exercise or protect the rights, property, or personal safety of Now, our visitors, or others;
• The General Public: If you post comments on our public forum, we share information, such as your personal profile and the content you post, with the general public. You may choose to hide our profile picture.
We, and our third-party partners, Facebook, Inc., Google, Inc., Gartner, Inc., International Data Corporation, Stripe, ObjectLabs Corporation, Amazon, Inc., Salesforce, Inc., Invoice Ninja, Survey Monkey, Inc., Wootric, Slack, and G2 crowd, Inc. automatically collect certain types of usage information when you visit our Service, read our emails, or otherwise engage with us. We typically collect this information through a variety of tracking technologies, including cookies, web beacons, embedded scripts, location-identifying technologies, file information, and similar technology (collectively, “tracking technologies”). We may collect and store information locally on your device using mechanisms such as browser storage and application data caches. We may collect analytics data or use third-party analytics tools such as Google Analytics to help us measure traffic and usage trends for the Service and to understand more about the demographics of our users. You can learn more about Google’s practices at http://www.google.com/policies/privacy/partners and view its currently available opt-out options at https://tools.google.com/dlpage/gaoptout. We may also work with third-party partners to employ technologies, including the application of statistical modeling tools, which permit us to recognize and contact you across multiple devices.
We use or may use the data collected through tracking technologies to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the site; (b) provide custom, personalized content and information, including targeted content and advertising; (c) recognize and contact you across multiple devices; (d) provide and monitor the effectiveness of our Service; (e) monitor aggregate metrics such as total number of visitors, traffic, usage, and demographic patterns on our Service; (f) diagnose or fix technology problems; and (g) otherwise to plan for and enhance our Service.
• Cookie settings in Internet Explorer
• Cookie settings in Firefox
• Cookie settings in Chrome
• Cookie settings in Safari web and https://support.apple.com/kb/ph21411?locale=en_US.
We honor Do Not Track signals from your browser.
7. HOW DO WE USE THIRD-PARTY TRACKING AND ONLINE ADVERTISING?
We want you to understand how we use your information in the context of online advertising and tracking.
Interest-Based Advertising. We participate in interest-based advertising and use third-party advertising companies including Google, Inc., Facebook, Inc., and LinkedIn, Inc. to serve you targeted advertisements based on your browsing history. We may share or we may permit third-party online advertising networks, social media companies, and other third-party services, such as HubSpot, DoubleClick and AdRoll Roundtrip to collect information about your use of our Sites over time so that they may play or display ads on our Service, on other devices you may use, and on other websites, apps, or services. Typically, the information we share is provided through cookies or similar tracking technologies, which recognize the device you are using and collect information, including click stream information, browser type, time and date you visited the site, and other information. We and our third-party partners use this information to make the advertisements you see online more relevant to your interests, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research.
Cross-Device Linking. We, or our third-party partners, may link your various devices so that content you see on one device can result in relevant advertising on another device. We do this by collecting information about each device you use when you are logged in to our Service. We may also work with third-party partners who employ tracking technologies or the application of statistical modeling tools to determine if two or more devices are linked to a single user or household. We may share a common account identifier (such as an email address or user ID) with third-party advertising partners to help recognize you across devices. We, and our partners, can use this cross-device linkage to serve interest-based advertising and other personalized content to you across your devices, to perform analytics, and to measure the performance of our advertising campaigns.
Your Choices: You can regulate and opt out of online tracking and advertising. Note, however, that some of these opt-outs may not be effective unless your browser is set to accept cookies. If you delete cookies, change your browser settings, switch browsers or computers, or use another operating system, you will need to opt-out again.
• Interest-based advertising. To learn about interest-based advertising and how you may be able to opt-out of some of this advertising, you may wish to visit the Network Advertising Initiative’s online resources at http://www.networkadvertising.org/choices and/or the DAA’s resources at www.aboutads.info/choices. You may also manage certain advertising cookies by visiting the EU-based Your Online Choices at www.youronlinechoices.eu.
• Cross-device linking. Please note that opting-out of receiving interest-based advertising through the NAI’s and DAA’s online resources will only opt-out a user from receiving interest-based ads on that specific browser or device, but the user may still receive interest-based ads on his or her other devices. You must perform the opt-out on each browser or device you use.
• Mobile advertising. You may also be able to limit interest-based advertising through the settings on your mobile device by selecting “limit ad tracking” (iOS) or “opt-out of interest based ads” (Android). You may also be able to opt-out of some—but not all—interest-based ads served by mobile ad networks by visiting http://youradchoices.com/appchoices and downloading the mobile AppChoices app.
Google Analytics and Advertising. We use Google Analytics to recognize you and link the devices you use when you visit our site or Service on your browser or mobile device, log in to your account on our Service, or otherwise engage with us. Google Analytics allows us to better understand how our users interact with our Service and to tailor our p advertisements and content to you. For information on how Google Analytics collects and processes data, as well as how you can control information sent to Google, review Google’s site “How Google uses data when you use our partners’ sites or apps” located at www.google.com/policies/privacy/partners/. You can learn about Google Analytics’ currently available opt-outs, including the Google Analytics Browser Ad-On here https://tools.google.com/dlpage/gaoptout/.
We may also utilize certain forms of display advertising and other advanced features through Google Analytics, such as Remarketing with Google Analytics, Google Display Network Impression Reporting, and Google Analytics Demographics and Interest Reporting. These features enable us to use first-party cookies (such as the Google Analytics cookie) and third-party cookies (such as the HubSpot, DoubleClick and Addroll Roundtrip advertising cookies) or other third-party cookies together to inform, optimize, and display ads based on your past visits to the Service. You may control your advertising preferences or opt-out of certain Google advertising products by visiting the Google Ads Preferences Manager, currently available at https://google.com/ads/preferences, or by visiting NAI’s online resources at http://www.networkadvertising.org/choices.
8. HOW DO WE SAFEGUARD YOUR INFORMATIN ON INTERNATIONAL DATA TRANSFERS?
As we are located in the USA, any information you provide, will be processed and stored in the USA. If you are in the European Union or European Economic Area, this may mean that your personal information will be stored in a jurisdiction that offers a level of protection that may, in certain instances, be less protective of your personal information than the jurisdiction you are typically a resident in.
If we transfer information from the European Union to third parties outside the European Union and to countries not subject to schemes which are considered as providing an adequate data protection standard, we will either enter into contracts which are based on the EU Standard Contractual Clauses with these parties.
9. HOW DO WE STORE AND PROTECT YOUR INFORMATION?
We will store personal information for as long as necessary to fulfill the purposes for which we collect the personal information, in accordance with our legal obligations and legitimate business interests. In general, information on performed business transactions will be blocked from general access within 90 days after completion of the transaction and deleted once statutory retention requirements expire. For example, national commercial or financial codes may require to retain certain information for up to 10 years.
We implement a variety of security measures to maintain the safety of your personal information when you use our Services. Some of the safeguards we use are firewalls and data encryption, physical access controls to our data centers, and information access authorization controls. In the event that any information under our control is compromised as a result of a breach of security, we will take reasonable steps to investigate the situation and, where appropriate, notify those individuals whose information may have been compromised and take other steps, in accordance with any applicable laws and regulations.
10. WHAT RIGHTS AND CHOICES DO YOU HAVE?
We want you to understand your rights and choices regarding how we may use your personal information. Depending on how you use your information, these rights and choices may include the following:
Profile and Data Sharing Settings. You may update your profile information, such as your username and profile photo, and may change some of your data sharing preferences by logging into your online account.
Access to your Device Information. You may control the app’s access to your device information through your “Settings” app on your device. For instance, you can withdraw permission for the app to access your address book, location, photo stream, and camera.
How to control your communications preferences. You can stop receiving promotional email communications from us by clicking on the “unsubscribe link” provided in the bottom of such communications. We make every effort to promptly process all unsubscribe requests.
EU users’ specific rights and choices. If you are a resident of the European Union, you have the following rights with respect to your personal information that we hold:
• Right of access. The right to obtain access to your personal information.
• Right to rectification. The right to obtain rectification of your personal information without undue delay where that personal information is inaccurate or incomplete.
• Right to erasure. The right to obtain the erasure of your personal information without undue delay in certain circumstances, such as where the personal information is no longer necessary in relation to the purposes for which it was collected or processed.
• Right to restriction. The right to obtain restriction of the processing undertaken by us on your personal information in certain circumstances, such as, where the accuracy of the personal information is contested by you, for a period of time enabling us to verify the accuracy of that personal information.
• Right to portability. The right to portability allows you to move, copy or transfer personal information easily from one organization to another.
• RIGHT TO OBJECT: YOU HAVE THE RIGHT TO OBJECT TO ANY PROCESSING BASED ON OUR LEGITIMATE INTERESTS WHERE THERE ARE GROUNDS RELATING TO YOUR PARTICULAR SITUATION. YOU CAN OBJECT TO MARKETING ACTIVITIES FOR WHATEVER REASON WHATOSEVER.
If you wish to exercise one of these rights, please contact us using the contact details below.
You also have the right to lodge a complaint with a data protection authority. Further information about how to contact your local data protection authority is available at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.
11. CHILDREN’S PRIVACY
From children under the age of 16 residing in the EU, we will not process any personal information on the ground of a consent.
12. YOUR CALIFORNIA PRIVACY RIGHTS
If you are a California resident, California Civil Code Section 1798.83 permits you to request information regarding the disclosure of personal information to third parties for their direct marketing purposes during the immediately preceding calendar year. You may make one request each year by emailing us at firstname.lastname@example.org.
13. LINKS TO OTHER WEB SITES AND SERVICES
The Service may contain links to and from third-party websites of our business partners, advertisers, and social media sites and our users may post links to third-party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for their policies. We strongly recommend that you read their privacy policies and terms and conditions of use to understand how they collect, use, and share information. We are not responsible for the privacy practices or the content on the websites of third-party sites.
14. HOW TO CONTACT US