EDT Privacy Statement

Introduction

Your privacy and trust are important to us and this Privacy Statement (“Statement”) provides important information about how EDT handles personal information. This Statement applies to our website, application, product, software, or service that links to it (collectively, our “Services”). Occasionally, a Service will link to a different Privacy Statement that will outline the particular privacy practices of that Service.

Please read this Statement carefully and contact our  Data Protection Team if you have any questions about our privacy practices or your personal information choices. It is important that you check back often for updates to this Statement. If we make changes we consider to be important, we will let you know by placing a notice on the relevant Services and/or contact you using other methods such as email.

This Statement was last updated on 11th March 2018.

Personal information

EDT is committed to the responsible handling and protection of personal information.

Personal information means any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.

We collect, use, disclose, transfer, and store personal information when needed to provide our Services and for our operational and business purposes as described in this Statement. We want to be clear about our privacy practices so that you can make informed choices about the use of your information, and we encourage you to contact us  at any time with questions or concerns.

The types of personal information we collect

We collect personal information from you, for example, if you request information, purchase or use our Services, or request customer support. We may ask you to provide information such as your name, address, phone number, email address, user name and password, and information about your device. Not all of the personal information EDT holds about you will always come directly from you. It may, for example, come from your employer, other organizations to which you belong, or a professional service provider such as your tax or accounting professional or lawyers, if they use our Services. We also collect personal information from third parties such as our clients, 3rd party service providers, and publicly available websites, to offer Services we think may be of interest and to help us maintain data accuracy and provide and enhance the Services.

In addition, our servers, logs, and other technologies automatically collect certain information to help us administer, protect, and improve our Services; analyze usage; and improve users’ experience. We share personal information with others only as described in this Statement, or when we believe that the law permits or requires it.

Occasionally we collect and process what may be considered sensitive personal information.

Sensitive personal information is a subset of personal information and is generally defined as any information related to racial/ethnic origin, political opinions, religious beliefs, trade union membership, physical or mental health, and other medical information including biometric and genetic data, or sexual life or preferences. In some instances, sensitive personal information may also include criminal allegations or convictions, precise geolocation information, financial and bank account numbers, or unique identifiers such as government-issued national insurance numbers, driver’s license, and passport numbers.

For example, if you purchase software from us or subscribe to our Services, we may collect payment information, such as financial or bank card information, and other information necessary for us to process the transaction. Information that is considered sensitive under applicable law will be handled in accordance with such laws.

How we use personal information

We process personal information for these Service- and business-related purposes

  • Account setup and administration:  We use personal information such as your name, email address, phone number, and information about your device to set up and administer your account, provide technical and customer support and training, verify your identity, and send important account, subscription, and Service information.
  • Marketing and events:  We use personal information to deliver marketing and event communications to you across various platforms, such as email, telephone, text messaging, direct mail, and online. If we send you a marketing email, it will include instructions on how to opt out of receiving these emails in the future. Please remember that even if you opt out of receiving marketing emails, we may still send you important Service information related to the services / software and we may still retain the personal information.
  • Hosted services:  Some of our Services provide data and document storage as an integral part of the product or solution offering. Any information stored by or on behalf of our customers is controlled and managed by and only made accessible to those customers or others our customers may authorise from time to time. Our access to this information is limited to EDT personnel with a business reason to use it, such as technical support, software engineering, testing or troubleshooting.
  • Legal obligations:  We may be required to use and retain personal information for legal and compliance reasons, such as the prevention, detection, or investigation of a crime; loss prevention; or fraud. We may also use personal information to meet our internal and external audit requirements, information security purposes, and as we otherwise believe to be necessary or appropriate: (a) under applicable law, which may include laws outside your country of residence; (b) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include such authorities outside your country of residence; (c) to enforce our terms and conditions; and (d) to protect our rights, privacy, safety, or property, or those of other persons.

When we share personal information

EDT shares or discloses personal information when necessary to provide Services or conduct our business operations as described below. When we share personal information, we do so in accordance with data privacy and security requirements. We may occasionally share non-personal, anonymised, and statistical data with third parties. Below are the parties with whom we may share personal information and why.

  • Within EDT:  Personal information will be made available to personnel if necessary for the provision of Services, account administration, sales and marketing, customer and technical support, and business development and product engineering, for instance. All of our employees and contractors are required to follow our data privacy and security policies when handling personal information.
  • Our third-party service providers:  We partner with and are supported by service providers around the world. Personal information will be made available to these parties only when necessary to fulfill the services they provide to us, such as software, system, and platform support; direct marketing services; cloud hosting services; advertising; data analytics; and order fulfillment and delivery. Our third-party service providers are not permitted to share or use personal information we make available to them for any other purpose than to provide services to us.
  • Third parties for legal reasons:  We will share personal information when we believe it is required, such as:
    • To comply with legal obligations and respond to requests from government agencies, including law enforcement and other public authorities, which may include such authorities outside your country of residence.
    • In the event of a merger, sale, restructure, acquisition, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings)
    • To protect our rights, users, systems, and services.

Where we store and process personal information

EDT is a global organisation, and your personal information may be stored and processed outside of your home country. We take steps to ensure that the information we collect is processed according to this Privacy Statement and the requirements of applicable law wherever the data is located.

EDT has networks, databases, servers, systems, support, and help desks located throughout our offices around the world. We collaborate with third parties such as cloud hosting services, suppliers, and technology support located around the world to serve the needs of our business, workforce, and customers. We take appropriate steps to ensure that personal information is processed, secured, and transferred according to applicable law. In some cases, we may need to transfer your personal information within EDT or to third parties in areas outside of your home country. The areas in which these recipients are located will vary from time to time, but may include the United States, Europe, Asia and other countries where EDT has a presence or uses contractors.

When we transfer personal information from the EU to other countries in which applicable laws do not offer the same level of data privacy protection as in your home country, we take measures to provide an appropriate level of data privacy protection. In other words, your rights and protections remain with your data. For example, we use approved contractual clauses, multiparty data transfer agreements, and other measures designed to ensure that the recipients of your personal information protect it

How we secure personal information

EDT takes data security seriously, and we use appropriate technologies and procedures to protect personal information. Our information security policies and procedures are closely aligned with widely accepted international standards and are reviewed regularly and updated as necessary to meet our business needs, changes in technology, and regulatory requirements.

For example:

Policies and procedures

  • We have measures in place to protect against accidental loss and unauthorized access, use, destruction, or disclosure of data
  • We have a Business Continuity and Disaster Recovery strategy that is designed to safeguard the continuity of our service to our clients and to protect our people and assets
  • We place appropriate restrictions on access to personal information
  • We implement appropriate measures and controls, including monitoring and physical measures, to store and transfer data securely
  • We conduct Privacy Impact Assessments in accordance with legal requirements and our business policies

Training for employees and contractors

  • We require privacy, information security, and other applicable training on a regular basis for our employees and contractors who have access to personal information and other sensitive data
  • We take steps to ensure that our employees and contractors operate in accordance with our information security policies and procedures and any applicable contractual conditions

Vendor risk management

  • We require, through the use of contracts and security reviews, our third-party vendors and providers to protect any personal information with which they are entrusted in accordance with our security policies and procedures

How long we keep personal information

The types of personal information we collect

EDT’s team works in conjunction with EDT’s Data Protection Officer to implement policies and rules relating to the retention of personal information. We retain personal information for as long as we reasonably require it for legal or business purposes. In determining data retention periods, EDT takes into consideration local laws, contractual obligations, and the expectations and requirements of our customers. When we no longer need personal information, we securely delete or destroy it.

Your right to access and correct your personal information

We respect your right to access and control your information, and we will respond to requests for information and, where applicable, will correct, amend, or delete your personal information.

  • Access to personal information:If you request access to your personal information, we will gladly comply, subject to any relevant legal requirements and exemptions, including identity verification procedures. Before providing data to you, we will ask for proof of identity and sufficient information about your interaction with us so that we can locate any relevant data. We may also charge you a fee for providing you with a copy of your data (except where this is not permissible under local law).
  • Correction and deletion:In some jurisdictions, you have the right to correct or amend your personal information if it is inaccurate or requires updating. You may also have the right to request deletion of your personal information; however, this is not always possible due to legal requirements and other obligations and factors. Remember that you can update your account information by using the “Contact Us” form on our website.
  • Marketing preferences:To opt out of email marketing, you can use the “Contact Us” form on our website.
  • Filing a complaint:If you are not satisfied with how EDT manages your personal data, you have the right to make a complaint to a data protection regulator.

Cookies and similar technologies

A cookie is a small text file that is placed on a computer or other device and is used to identify the user or device and to collect information. Cookies are typically assigned to one of four categories, depending on their function and intended purpose: absolutely necessary cookies, performance cookies, functional cookies, and cookies for marketing purposes.

Types of cookies and why we use them

  • Absolutely necessary cookies:These cookies are essential to enable you to move around a website and use its features. Without these cookies, services you have asked for, like adding items to an online shopping cart, cannot be provided.
  • Performance cookies:These cookies collect information about how you use our websites. Information collected includes, for example, the Internet browsers and operating systems used, the domain name of the website previously visited, the number of visits, average duration of visit, and pages viewed. These cookies don’t collect information that personally identifies you and only collect aggregated and anonymous information. Performance cookies are used to improve the user-friendliness of a website and enhance your experience.
  • Functionality cookies:These cookies allow the website to remember choices you make (such as your username or ID, language preference, or the area or region you are in) and provide enhanced, more personal features. These cookies can also be used to remember changes you have made to text size, fonts, and other customizable parts of web pages. They may also be used to provide services you have asked for, such as watching a video or commenting on a blog. The information these cookies collect may be anonymised, and they cannot track your browsing activity on other websites.
  • Targeting and advertising cookies:These cookies track browsing habits and are used to deliver targeted (interest-based) advertising. They are also used to limit the number of times you see an ad and to measure the effectiveness of advertising campaigns. They are usually placed by advertising networks with the website operator’s permission. They remember that you have visited a website and this information is shared with other organizations, such as advertisers.

Managing cookies

You can manage website cookies in your browser settings, and you always have the choice to change these settings by accepting, rejecting, or deleting cookies. If you choose to change your settings, you may find that certain functions and features will not work as intended. All browser settings are slightly different, so to manage cookies, you should refer to the relevant settings within your browser.

We understand that you may want to know more about cookies. Here are some useful resources that provide detailed information about types of cookies, how they are used, and how you can manage your cookie preferences: www.aboutcookies.org or www.allaboutcookies.org. Please click below for detailed information on how to disable and delete cookies in some commonly used browsers:

Links and connections to third-party services

Our Services may contain links to and may be used by you in conjunction with third-party apps, services, tools, and websites that are not affiliated with, controlled, or managed by us. Examples include Facebook, LinkedIn, Twitter® and, third-party apps like voice software and readers. The privacy practices of these third parties will be governed by the parties’ own Privacy Statements. We are not responsible for the security or privacy of any information collected by these third parties. You should review the privacy statements or policies applicable to these third-party services.

Children’s privacy

EDT provides software solutions for professionals, and our Services are generally not aimed at children. If, however, we collect and use information about children, such as to develop an educational resource, we will comply with industry guidelines and applicable laws.

How to contact us

We understand that you may have questions or concerns about this Statement or our privacy practices or may wish to file a complaint. Please feel free to contact us at privacy@discoveredt.com.