Privacy Policy
FLEXIDAO PRIVACY NOTICE
LAST UPDATED SEPTEMBER 2024
This Privacy Notice explains in detail how FLEXIDAO collects, uses and discloses your personal data. Please read this Privacy Notice carefully before submitting any personal data to us.
1. About the Privacy Notice.
1.1 This Flexidao Privacy Notice (the “Privacy Notice”) governs the processing of personal data collected from natural persons (“you” and “your”) and is applicable to Flexidao S.E.S S.L (“we,” “our,” or “us”) as related to our services, which collectively include: i) the use of the online platform Flexidao available at https://www.flexidao.com (the “Platform”) ii) social media messages and marketing campaigns and iii) the use of our products and services.
The Privacy Notice does not cover any third-party websites, applications, software, products or services that integrate with the Platform or are linked to from the Platform.
1.2 This Privacy Policy sets out the essential details relating to your personal data relationships with Flexidao as:
- A website visitor
- A prospective client
- A job applicant and
- Partners
1.3 Data controller. The Platform is owned and operated by Flexidao S.E.S S.L. having a registered office at Gran via Carles III, 98, floor 10, Barcelona (Spain), with company number B67109082 ("Flexidao"). We act in the capacity of a data controller with regard to the personal data processed through the Platform in terms of the GDPR and other applicable data protection laws. As a data controller, we are responsible for collecting your personal data through the Platform and making decisions about the purposes for which your personal data is used.
1.4 Minors. The Platform is not intended for use by persons who are minors in their country of residence.
1.5 Term and termination. This Privacy Notice enters into force on the effective date indicated at the top of the Privacy Notice and remains valid until terminated or updated by us.
1.6 Amendments. The Privacy Notice may be changed from time to time to address the changes in laws, regulations, and industry standards.
2. THE PERSONAL DATA WE COLLECT AND FOR WHAT PURPOSES
2.1 What Personal Data we collect from you. We collect personal information that may include first and last name, business email address, phone number and/or company name.
In addition, we may collect data uploaded by you, your employer or other users of the Software that may be required to use Flexidao services. We expect all users to follow their organization’s privacy policy and any applicable regulatory requirements when uploading, accessing and using personal information into our application. The data uploaded may include personal information like:
- Employee names, email addresses and contractual agreements
- Vendor names, email addresses, contractual agreements or other personal data necessary for Flexidao services
- Customer names and email addresses used to provide services within Flexidao ’s platform
- As a job applicant, we may also collect your resume and cover letter.
2.2 When We may ask you to provide personal information (if):
- You submit a contact form in the Platform
- You request a free trial or demo.
- You refer a friend to us.
- You connect with us directly via phone calls or video conferencing platforms.
- You participate in programs we may offer from time to time.
- You participate in chats.
- You pay for our services.
2.3 We comply with data minimisation principles. We do not not use your personal data for any difference from the purposes for which your personal data was provided. Thus, we collect only a minimal amount of personal data through the Platform that is necessary for your use of the Platform and pursuing our legitimate business interests. We use your personal information to:
- Deliver the contracted services and allow full use of the Platform functionality as purchased by the clients.
- Deliver training and support to our application end users and/or carry out the transactions you have requested.
- To communicate with you directly through emails, calls, chats and video conferencing.
- Advertise and market our products and services, including delivering interest-based advertisements on this website and other sites or content syndication platforms and websites.
- Carry out market research to understand how to improve our services and their delivery.
2.4 Cookies. To enrich and perfect your online experience, Flexidao uses "Cookies", similar technologies and services provided by others to display personalized content, appropriate advertising and store your preferences on your computer. Flexidao uses cookies to help Flexidao identify and track visitors, their usage of http://flexidao.com/ , and their website access preferences. Flexidao visitors who do not wish to have cookies placed on their computers should set their browsers to refuse cookies before using Flexidao's websites, with the drawback that certain features of Flexidao's websites may not function properly without the aid of cookies. By continuing to navigate our website without changing your cookie settings, you hereby acknowledge and agree to Flexidao's use of cookies. To find out more, visit our Cookie Policy page.
2.5 Sensitive data. We do not collect or have access to any special categories of personal data (“sensitive data”) from you, unless you decide, at your own discretion, to provide such data to us. Sensitive data is information that relates to your health, genetics, biometrics, religious and political beliefs, racial origins, membership of a professional or trade association, sex life, or sexual orientation.
2.6 Sources of personal data. We obtain your personal data from the following categories of sources:
- Directly from you. For example, if you submit certain personal data directly to us when registering on the Platform, completing the necessary forms, or contacting us.
- Directly or indirectly through your activity on the Platform. When you use the Platform, we automatically collect technical information about your use of the Platform.
- From third parties. We may receive information about you from third parties to whom you have previously provided your personal data, if those third parties have a lawful basis for disclosing your personal data to us.
3. TECHNICAL (NON-PERSONAL) DATA WE COLLECT
3.1 IP address. When you visit and browse the Platform, we or our third-party analytics service providers collect your IP address. We use your IP address to analyze the technical aspects of your use of the Platform, prevent fraud and abuse of the Platform, and ensure the security of the Platform.
3.2 Use of the Platform. In order to analyze your use of the Platform, we and our analytics service providers automatically collect certain technical non-personal data about your use of the Platform. Such data does not allow us to identify you as an individual person in any manner. The information collected includes: access times, the pages you view, the links you click on, the search terms you enter , actions you take in connection with any of the visited pages, your device information such as IP address, location, browser type and language, the Uniform Resource Locator (URL) of the website that referred you to our website
4 RETENTION OF PERSONAL DATA
4.1 Your personal data is stored in our systems only for as long as such personal data is required for the purposes described in this Privacy Notice or until you request us to delete your personal data, whichever comes first. After your personal data is no longer necessary for its primary purposes and we do not have another legal basis for storing it, we securely delete your personal data from our systems.
4.2 We retain non-personal data pertaining to you for as long as necessary for the purposes described in this Privacy Notice.
4.3 Retention as required by law. In certain cases, we are required by law to store your personal data for a certain period of time (e.g., for business records or accountancy purposes). Thus, we keep your personal data for the time period stipulated by the applicable law and securely delete it as soon as the required storage period expires.
5. HOW DO WE SHARE AND DISCLOSE YOUR DATA
5.1 We might use third parties to help us provide our services. They will have access to your information as collected by the website, as reasonably necessary to perform the contracted tasks on our behalf. We use a limited number of data processors. We choose them only if they agree to ensure an adequate level of protection of your personal data that is consistent with this Privacy Notice and the applicable data protection laws. The data processors that have access to your personal data are: Our hosting and cloud storage service provider, Our email marketing service provider and Our analytics service provider. If you want more information about the service providers we operate with, please contact us.
5.2 Disclosure of technical (non-personal) data. Your technical (non-personal) data may be disclosed to third parties for any purpose. For example, we may share it with prospects or partners for business or research purposes, for improving the Platform, planning the Content, responding to lawful requests from public authorities or developing new products and services.
5.3 Legal requests. If we are contacted by a public authority, we may need to disclose information about you to the extent necessary for pursuing a public interest objective, such as national security or law enforcement.
5.4 Successors. In case the Platform is sold partly or fully, we will provide your personal data to a purchaser or successor entity and request the successor to handle your personal data in line with this Privacy Notice. We will notify you of any changes of the data controller.
5.5 Selling personal data. We do not sell your personal data to third parties. However, some of your personal data, including online identifiers (e.g., cookie-generated data and IP addresses) may be used for advertising, marketing, and monetisation purposes.
6. PROTECTION OF YOUR PERSONAL DATA
6.1 Flexidao discloses potentially personally-identifying and personally-identifying information only to those of its employees, contractors and affiliated organizations that (i) need to know that information in order to process it on Flexidao behalf or to provide services available at Flexidao's website, and (ii) that have agreed not to disclose it to others. Some of those employees, contractors and affiliated organizations may be located outside of your home country; by using Flexidao's website, you consent to the transfer of such information to them.We implement organizational and technical information security measures to protect your personal data from loss, misuse, unauthorized access, and disclosure.
6.2 Security breaches. Flexidao takes all measures reasonably necessary to protect against the unauthorized access, use, alteration or destruction of potentially personally-identifying and personally-identifying information however, we cannot be liable for any unlawful destruction, loss, use, copying, modification, leakage, and falsification of your personal data that was caused by circumstances that are beyond our reasonable control.
7. YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA
7.1 You have certain rights to control how we process your personal data.
7.2 The list of your rights. You can exercise your rights listed below, unless, in very limited cases, the applicable law provides otherwise:
- Right of access: you can get a copy of your personal data that we store in our systems and a list of purposes for which your personal data is processed;
- Right to rectification: you can rectify inaccurate personal data that we hold about you;
- Right to to be forgotten: you can ask us to erase your personal data from our systems;
- Right to restriction: you can ask us to restrict the processing of your personal data;
- Right to data portability: you can ask us to provide you with a copy of your personal data in a structured, commonly used and machine-readable format and move that personal data to another processor;
- Right to object: you can ask us to stop processing your personal data;
- Right to withdraw consent: you have the right to withdraw your consent, if you have provided one; or
- Right to complaint: you can submit your complaint regarding our processing of your personal data.
7.3 How to exercise your rights. If you would like to exercise any of your rights listed in section 7.2 please contact us by email at [email protected] and explain your request in detail. In order to verify the legitimacy of your request, we may ask you to provide us with an identifying piece of information that allows us to identify you in our system. We will answer your request within a reasonable time. Likewise, and especially if you consider that you have not obtained full satisfaction in the exercise of your rights, you may file a claim with the national supervisory authority by contacting the Spanish Data Protection Agency, C/ Jorge Juan, 6 – 28001 Madrid.
7.4 Non-discrimination. We do not discriminate you if you decide to exercise your rights. It means that we will not (i) deny any goods and services, (ii) charge you different prices, (iii) deny any discounts or benefits, (iv) impose penalties, or (v) provide you with a lower quality services.
8. ADVERTISING
8.1 You may be served targeted interest-based advertisements on the Platform and other websites on the Internet. Such advertisements are generated on the basis of your use of the Platform, other websites on the Internet, and the data generated by cookies installed in your browser.
8.2 You can control how targeted advertising is shown to you or opt-out from targeted advertising. Please note that, depending on the country where you reside, advertisements are served and third-party marketing activities are conducted on an opt-in or opt-out basis.
8.3 Links To External Sites Our Service may contain links to external sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy and terms and conditions of every site you visit. We have no control over, and assume no responsibility for the content, privacy policies or practices of any third party sites, products or services.
8.4 Communications preferences You may choose to receive or not receive marketing communications from us. Please click the “Unsubscribe” link in the email we sent you to stop receiving marketing communications. Even if you opt-out of receiving marketing communications, we may still communicate with you regarding security and privacy issues, servicing your account, fulfilling your requests, or administering any promotion or any program in which you may have elected to participate. If you are unable to find the ou-tout instructions, please contact us at [email protected] for assistance.
9. CONTACT US
If you have any questions about this Privacy Notice or our data protection practices, please contact us by: Email: [email protected]
Appendix
A.1 For Individuals Based in the European Economic Area (EEA), United Kingdom (UK) and Switzerland
If you are based in one of these jurisdictions, Flexidao is the controller of your personal data collected in the following instances:
- When you visit our Platform
- When we process your personal data for sales and marketing purposes
Flexidao is a processor of all personal data processed on the application, on behalf of our clients. We only process the personal data under their direction. Please contact your employer or the organization that granted you access to the application for details on their privacy practices.
We only process personal data if we have a lawful basis for doing so. The lawful bases applicable to our processing as controller are:
- Consent: We will ask for your express and informed consent every time we collect your personal data on this legal basis.
- Contractual basis: We process the personal data as necessary to fulfill our contractual terms with you or our clients.
- Legitimate interest: We process the names, contact details, job titles, companies of our existing and prospective clients for our marketing purposes, including market research and sales leads generation.
You have the following rights under the GDPR.
You may also lodge a complaint with your local supervisory authority:
- EU Data Protection Authorities (DPAs). See their contact details here National Data Protection Authorities.
- Information Commissioner’s Office (ICO)
- Swiss Federal Data Protection and Information Commissioner (FDPIC).
A.2 For Individuals Based in The United States
Under the California Privacy Rights Act (‘CPRA’) – which amended and expanded on CCPA, Connecticut Data Privacy Act (‘CTDPA’), Virginia Commonwealth Data Protection Act (‘CDPA’), Utah Consumer Privacy Act (‘UCPA’), and the Colorado Privacy Act (‘CPA’), consumers may be able to exercise the following rights in relation to the personal information about them that we have collected (subject to certain limitations at law):
- The right to access/know any or all of the information relating to your personal information that we have collected, processed or disclosed in the preceding 12 months (upon verification of your identity).
- The right to request the deletion of personal information we have collected from you.
- The right to opt-out of personal information sales to third parties now or in the future. However, we do not sell your personal information.
- The right to opt-in to personal information sales to third parties for consumers under the age of 16. However, we do not sell personal information of minor consumers.
- The right to opt-out of sharing of personal information to third parties now or in the future. To view the information we have shared in the preceding 12 months, refer to section
- The right to request rectification/correction of inaccurate personal information, considering the nature and purposes of the processing of the information. (Not Applicable under UCPA)
- The right to limit use and disclosure of sensitive personal information to that which is necessary to perform the services or provide the goods reasonably expected by an average consumer. (Applicable under CCPA, as amended by CPRA)
- The right to opt-out of the processing of sensitive personal information (I.e., data that reveals ethnic or racial origin, mental or physical health diagnosis, religious beliefs, sexual orientation, or citizenship or immigration status. (Applicable under UCPA)
- The right to opt-out of targeted advertising. (Applicable under CPA, CTDPA, UCPA, VCDPA)
- The right to opt-out of profiling in connection with automated decisions. (Applicable under CPA, CTDPA, UCPA)
Please note that if exercising these rights limits our ability to process personal information (such as a deletion request), we may no longer be able to provide you with our products and services or engage with you in the same manner. Additionally, Flexidao has established processes (including reviewing business processes, systems and resources on a periodic basis) to ensure consumers who exercise any of the above rights under US state privacy laws are not discriminated against.
A.2.1 How to Exercise Your Consumer Rights
To exercise any of your right mentioned above, please submit a request by contacting us at [email protected]
We will need to verify your identity before processing your request.
In order to verify your identity, we will generally require sufficient information from you so that we can match it to the information we maintain about you in our systems. Sometimes we may need additional personal information from you to be able to identify you. We will notify you.
We may decline a request where we cannot verify your identity or locate your information in our systems or as permitted by law. In this case, we may request that you provide additional information reasonably necessary to authenticate you and your request.
You may choose to designate an authorized agent to make a request under the CCPA on your behalf. No information will be disclosed until the authorized agent’s authority has been reviewed and verified. Once an authorized agent has submitted a request, we may require additional information (i.e., written authorization from you) to confirm the authorized agent’s authority.
If you are an employee/former employee of a Flexidao client that uses our application and services, please direct your requests and/or questions directly to your employer or former employer.
If you are a third party (auditor, business associate, etc.), who was given access to the Flexidao application by a Flexidao client, please direct your requests and/or questions directly to the Flexidao client that gave you access.
If Flexidao does not take action on your Consumer Rights Request within the 45 days, or in the event of an extension, within the maximum 90-day response period, we will inform you in writing of the reasons for not taking action, as well as provide an explanation of any rights you have to appeal the decision. For opt-out or limit use and disclosure requests submitted under the CCPA, Flexidao will respond as soon as feasibly possible, with up to a maximum of 15 days.
For consumers residing in Virginia, within 60 days of receipt of an appeal, and for consumers residing in Colorado, within 45 days of receipt of an appeal, Flexidao will inform the consumer, in writing, of any action taken/not taken in response to the appeal, including an explanation of the reasons for the decisions. If the appeal is denied, Flexidao will provide consumers with an online mechanism, if available, or another method which allows the consumer to contact the Attorney General to submit a complaint.
A.3 For Individuals Based in Australia
This section is applicable to individuals whose personal information is collected, stored, used or disclosed by an APP Entity under the Australian Privacy Principles (“APPs”) contained in the Privacy Act of 1988.
A.3.1 Providing Anonymous and Pseudonymous Options
You have the option of anonymity or using a pseudonym when dealing with Flexidao. However, this option may not be made available to you in certain cases, including if it’s impractical for Flexidao to allow this option or when Flexidao is required or authorized to deal with an identified individual by or under the law.
A.3.2 Collection, Use and Disclosure of Personal Information
Flexidao collects personal information only by lawful and fair means. Additionally, Flexidao collects personal information directly from you or your authorized representative, unless we have your consent for collection from another source (i.e., third parties), it is required or authorized by law, or it is unreasonable to collect the information only from you.
Flexidao only uses and discloses your information for the purpose for which it was collected (the primary purpose) unless one or more of the following apply:
- You have consented
- You would reasonably expect the secondary purpose
- It is required or authorized by or under law
- Flexidao believes that it is reasonably necessary for an enforcement body’s activities
A.3.3 Your Rights Under the APPs
You have the following rights related to the collection, use and disclosure of your personal data:
- Be informed about the collection and use of your personal data
- Access your personal information
- Correction of your personal information to ensure accuracy and completeness
- Request to not receive direct marketing communications from us or to not disclose your personal information to others for direct marketing purposes
If you wish to access your personal information or correct that information, please contact us at [email protected] . You may opt-out (unsubscribe) of receiving marketing communications by using the links provided in our emails. If you are unable to find the ou-tout instructions, please contact us at security@flexidao.com for assistance.
If you are concerned about Flexidao’s handling of your personal information, you may lodge a complaint in writing to either the mail or email address listed below and we will provide a written response to your complaint within a reasonable time (30 days).
You may also complain directly to the Office of the Australian Information Commissioner (OAIC) by:
- Email: [email protected] (be aware that email isn’t encrypted, if you’re concerned about this, use the online form on OAIC’s website which is secure)
- Mail: GPO Box 5218, Sydney NSW 2001 (send it by registered mail if you’re concerned about sending it by standard post)
- Fax: 02 9284 9666