Effective Date of Current Policy: 5/1/2019
SignalFx complies with the requirements of the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework (collectively “Privacy Shield”), as set forth by the U.S. Department of Commerce and the Federal Trade Commission (“FTC”), regarding the collection, use, and retention of Personal Information transferred from the European Economic Area and Switzerland to the United States. We have certified to the Department of Commerce that it adheres to the Privacy Shield Principles and Supplemental Principles. If there is any conflict between the terms in this Policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit https:// www.privacyshield.gov. Additionally, we may protect information through other legally valid methods, including international data transfer agreements.
3. TRANSPARENCY/NOTICE—TYPES of Personal Information We Collect and How We Use It
Our primary goals in collecting Personal Information are to provide and improve our Services, to administer your use of the Services (including your Account, if you are an Account holder) and to enable you to enjoy and easily navigate our Services. The types of Personal Information we may collect (directly from you or from Third-Party sources) and our privacy practices depend on the nature of the relationship you have with SignalFx and the requirements of applicable law. Some of the ways that we may collect Personal Information include:
- You may provide Personal Information directly to us through interacting with the Services, participating in surveys, during events such as sweepstakes, and requesting Services, or information.
- As you navigate the Services, certain passive information may also be collected about your visit, including through cookies and similar technologies as described below.
We endeavor to collect only that information which is relevant for the purposes of Processing. Below are the ways we collect Personal Information and how we use it.
3.1 Types of Personal Information We Collect
We collect Personal Information regarding our current, prospective, and former clients, customers, users, visitors, guests, and employees (collectively “Individuals”).
- Information You Provide Directly to Us. When you use the Services or engage in certain activities, such as registering for an Account with us, responding to surveys, requesting Services or information, or contacting us directly, we may ask you to provide some or all of the following types of information:
- Communications with Us. We may collect Personal Information from you such as your name, email address, postal address, telephone number or information regarding your employer when you choose to request information about our Services, create an Account, subscribe to our software service, register for our newsletter or blog updates, request to receive customer or technical support, or otherwise communicate with us.
- Billing Information. We may collect a credit card number or other billing information when you create an Account and subscribe to our software services so that we can bill you for use of the Services.
- Surveys. From time to time, we may contact you to participate in online surveys. If you do decide to participate, you may be asked to provide certain information which may include Personal Information. All information collected from your participation in our surveys is provided by you voluntarily. We may use such information to improve our products, Sites and/or services and in any manner consistent with the policies provided herein.
- Posting on the Site. SignalFx may offer publicly accessible, blogs, private messages, or community forums. You should be aware that, when you disclose information about yourself in our blogs, private messages, and community forums, the Site will collect the information you provide in such submissions, including any Personal Information. If you choose to submit content to any public area of the Site, such content will be considered “public” and will not be subject to the privacy protections set forth herein.
- Registration for Sweepstakes or Contests. Occasionally, we may run sweepstakes and contests. We ask those who enter in the sweepstakes or contests to provide contact information (e.g., an e-mail address). If you participate in a sweepstakes or contest, your contact information may be used to reach you about the sweepstakes or contest, and for other promotional, marketing and business purposes. All sweepstakes/contests entry forms will provide a way for participants to opt out of any communications that are not related to awarding prizes.
- Automatic Data Collection. Our servers automatically record certain information about how a person uses our Services (“Log Data”). Log Data may include information such as your Internet Protocol (IP) address, browser type, operating system, the web page that you visited before accessing our Services, the pages or features of our Services which you browsed and the time spent on those pages or features, search terms, the links on our Services that you clicked on, cookie identifiers, mobile carrier, mobile advertising identifiers, MAC address, IMEI, Advertiser ID, and other device identifiers that are automatically assigned to your computer or device when you access the Internet, browser language, pages that you visited after using the Services, the date and time of your visit, or other actions taken through the use of the Services such as preferences, CPU utilization, and other statistics, including performance metrics.
- Information Submitted Via Services. You agree that we are free to use the content of any communications submitted by you via the Services, including any ideas, inventions, concepts, techniques, or know-how disclosed therein, for any purpose including developing, manufacturing, and/or marketing goods or Services. We will not release your name or otherwise publicize the fact that you submitted materials or other information to us unless: (a) you grant us permission to do so; (b) we first send notice to you that the materials or other information you submit to a particular part of a Service will be published or otherwise used with your name on it; or (c) we are required to do so by law.
- Information from Other Sources. We may receive information about you from other sources, including through Third-Party services and organizations to supplement information provided by you. For example, if you access our Services through a Third-Party application, such as an App Store or SNS, we may collect information about you from that Third-Party application that you have made public via your privacy settings. Information we collect through App Stores or SNS accounts may include your name, your SNS user identification number, your SNS user name, location, sex, birth date, email, profile picture, and your contacts on the SNS. This supplemental information allows us to verify information that you have provided to us and to enhance our ability to provide you with information about our business, products, and Services.
3.2 Lawful basis for processing
SignalFx reviewed its data processing methodologies and determined that contractual assent (e.g. assent obtained via an MSA or Terms and Conditions) and legitimate interest were the most effective means by which to ensure that SignalFx has established a lawful and transparent basis for processing customer data.
3.3 How we Use Your Information
We acquire, hold, use, and Process Personal Information about Individuals for a variety of business purposes, including:
- To Provide Products, Services, or Information Requested. We may use information about you to fulfill requests for products, Services, or information, including information about potential or future Services, including to:
- Generally manage Individual information and Accounts;
- Respond to questions, comments, and other requests;
- Provide access to certain areas, functionalities, and features of our Services;
- Contact you to answer requests for customer support or technical support; or
- Allow you to register for events.
- Administrative Purposes. We may use Personal Information about you for its administrative purposes, including to:
- Measure interest in our Services;
- Develop new products and Services;
- Ensure internal quality control;
- Verify Individual identity;
- Communicate about Individual Accounts and activities on our Services and systems, and, in our discretion, changes to any SignalFx policy;
- Send email to the email address you provide to us to verify your Account and for informational and operational purposes, such as Account management, customer service, or system maintenance;
- Process payment for products or services purchased;
- Process applications and transactions;
- Prevent potentially prohibited or illegal activities; or
- Enforce our Services Agreement.
- Marketing Our Products and Services. We may use Personal Information to provide you with materials about offers, products, and Services that may be of interest, including new content or Services. We may provide you with these materials by phone, postal mail, facsimile, or email, as permitted by applicable law. Such uses include:
- To tailor content, advertisements, and offers;
- To notify you about offers, products, and services that may be of interest to you;
- To provide Services to you and our sponsors;
- For other purposes disclosed at the time that Individuals provide Personal Information; or
- Otherwise with your consent.
You may contact us at any time to opt out of the use of your Personal Information for marketing purposes, as further described in Section 6 below.
- Research and Development. We may use Personal Information to create non-identifiable information that we may use alone or in the aggregate with information obtained from other sources, in order to help us to optimally deliver our existing products and Services or develop new products and Services. From time to time, we may perform research (online and offline) via surveys. We may engage Third-Party service providers to conduct such surveys on our behalf. All survey responses are voluntary, and the information collected will be used for research and reporting purposes to help us better serve Individuals by learning more about their needs and the quality of the products and services we provide. The survey responses may be utilized to determine the effectiveness of our Services, various types of communications, advertising campaigns, and/or promotional activities. If an Individual participates in a survey, the information given will be used along with that of other study participants. We may share anonymous Individual and aggregate data for research and analysis purposes.
- Direct Mail, Email and Outbound Telemarketing. Individuals who provide us with Personal Information, or whose Personal Information we obtain from Third Parties, may receive periodic emails, newsletters, mailings, or phone calls from us with information on our or our business partners’ products and services or upcoming special offers/events we believe may be of interest. We offer the option to decline these communications at no cost to the Individual by following the instructions in Section 6 below.
- Anonymous and Aggregated Information Use. We may use Personal Information and other information about you to create anonymized and aggregated information, such as de-identified demographic information, de-identified location information, information about the computer or device from which you access our Services, or other analyses we create. Anonymized and aggregated information is used for a variety of functions, including the measurement of visitors’ interest in and use of various portions or features of the Services. Anonymized or aggregated information is not Personal Information, and we may use such information in a number of ways, including research, internal analysis, analytics, and any other legally permissible purposes. We may share this information within SignalFx and with Third Parties for our or their purposes in an anonymized or aggregated form that is designed to prevent anyone from identifying you.
- Sharing Content with Friends or Colleagues. Our Services may offer various tools and functionalities. For example, SignalFx allows you to provide information about your friends through our referral services, such as “Tell a Friend.” Our referral services may allow you to forward or share certain content with a friend or colleague, such as an email inviting your friend to use our Services. Email addresses that you may provide for a friend or colleague will be used to send your friend or colleague the content or link you request, but will not be collected or otherwise used by us or any other Third Parties for any other purpose.
- Other Uses. We may use Personal Information for which we have a legitimate interest, such as direct marketing, individual or market research, anti-fraud protection, or any other purpose disclosed to you at the time you provide Personal Information or with your consent.
3.4 Cookies, Web Beacons, Analytics Information, and Interest-Based Advertising
Like many website owners, we use automated data collection tools such as Cookies and Web Beacons, and other technologies (“Web Technologies”) to automatically collect information through the Services. We use Web Technologies that are essentially small data files placed on your computer, tablet, mobile phone, or other devices that allow us to record certain pieces of information whenever you visit or interact with our sites, services, applications, messaging, and tools, and to recognize you across devices.
- Web Beacons. Web Beacons (also known as clear gifs, page tags or pixel tags) are tiny graphics with a unique identifier that may be included on our Services for several purposes, including to deliver or communicate with Cookies, to track and measure the performance of our Services, to monitor how many visitors view our Services, and to monitor the effectiveness of our marketing campaigns. Unlike Cookies, which are stored on the user’s hard drive, Web Beacons are typically embedded invisibly on web pages or in an e-mail.
- Analytics. We may also use Google Analytics and Google Analytics Demographics and Interest Reporting to collect information regarding visitor behavior and visitor demographics on some of our Services, and to develop website content. This analytics data is not tied to any Personal Information. For more information about Google Analytics, please visit google.com/policies/privacy/partners/. You can opt out of Google’s collection and Processing of data generated by your use of the Services by going to http://tools.google.com/dlpage/gaoptout.
Our uses of such Web Technologies fall into the following general categories:
- Advertising or Targeting Related. We may use first-party or third-party cookies and web beacons to deliver content, including ads relevant to your interests, on our sites or on Third-Party sites. This includes using technologies to understand the usefulness to you of the advertisements and content that has been delivered to you, such as whether you have clicked on an advertisement.
If you would like to opt out of the Web Technologies we employ on our sites, services, applications, or tools, you may do so by blocking, deleting, or disabling them as your browser or device permits.
3.5 Third-Party Websites, Social Media Platforms, and Software Development Kits
Our Services may include publicly accessible blogs, community forums, or private messaging features. The Site and our other Services may also contain links and interactive features with various social media platforms (e.g., widgets). If you already use these platforms, their cookies may be set on your device when using our Site or other Services. You should be aware that Personal Information which you voluntarily include and transmit online in a publicly accessible blog, chat room, social media platform or otherwise online, or that you share in an open forum may be viewed and used by others without any restrictions. We are unable to control such uses of your information when interacting with a social media platform, and by using such services you assume the risk that the Personal Information provided by you may be viewed and used by third parties for any number of purposes.
3.6 Third-Party Payment Processing
When you make purchases through the Services, we process your payments through Third-Party service providers. The Third-Party service providers may collect certain financial information from you to process a payment on behalf of SignalFx, including your name, email address, address, credit card number, and other billing information. These Third-Party service providers may also provide such information to us.
5. Onward Transfer—SignalFx May Disclose Your Information
5.1 Information We Share with third parties
- We Use Vendors and Service Providers. We may share any information we receive with vendors and service providers. The types of service providers (processors) to whom we entrust Personal Information include service providers for: (i) provision of IT and related services; (ii) provision of information and services you have requested; (iii) payment processing; (iv) customer service activities; and (v) in connection with the provision of the Site. These third-party services providers have access to your Personal Information only for the purpose of performing services on our behalf and are expressly obligated not to disclose or use your Personal Information for any other purpose, other than to comply with applicable legal requirements.
- Business Partners. We may share Personal Information with our business partners, and affiliates for our and our affiliates’ internal business purposes or to provide you with a product or service that you have requested. We may also provide Personal Information to business partners with whom we may jointly offer products or services, or whose products or services we believe may be of interest to you. In such cases, our business partner’s name will appear, along with SignalFx. We require our affiliates and business partners to agree in writing to maintain the confidentiality and security of Personal Information they maintain on our behalf and not to use it for any purpose other than the purpose for which we provided it to them.
- Privacy Shield. With respect to onward transfers to Agents under Privacy Shield, Privacy Shield requires that we remain liable should our Agents Process Personal Information in a manner inconsistent with the Privacy Shield Principles.
- Displaying to Other Users. The content you post to the Site may be displayed on the Site. Other users of the Site may be able to see some information about you, such as your name if you submit a review. We are not responsible for the privacy practices of the other users who will view and use the posted information.
- Marketing – Interest-Based Advertising and Third-Party Marketing. Through our Services, we may allow Third-Party advertising partners to set tracking tools (e.g., cookies) to collect information regarding your activities (e.g., your IP address, page(s) visited, time of day). We may also share such de-identified information as well as selected Personal Information (such as demographic information and past purchase history) we have collected with Third-Party advertising partners. These advertising partners may use this information (and similar information collected from other websites) for purposes of delivering targeted advertisements to you when you visit non-SignalFx related websites within their networks. This practice is commonly referred to as “interest-based advertising” or “online behavioral advertising. We may allow access to other data collected by the Site to facilitate transmittal of information that may be useful, relevant, valuable or otherwise of interest to you. If you prefer that we do not share your Personal Information with Third-Party advertising partners, you may opt out of such sharing at no cost by following the instructions in Section 6 below.
- Disclosures to Protect Us or Others (e.g., as Required by Law and Similar Disclosures). We cooperate with government and law enforcement officials or private parties to enforce and comply with the law. We may access, preserve, and disclose your Personal Information, other Account information, and content if we believe doing so is required or appropriate to: (i) comply with law enforcement or national security requests and legal process, such as a court order or subpoena; (ii) respond to your requests or claims; (iii) protect yours’, ours’ or others’ rights, property, or safety; (iv) to enforce our policies or contracts; (v) to collect amounts owed to SignalFx; (vi) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation or prosecution of suspected or actual illegal activity; or (vii) if we, in good faith, believe that disclosure is otherwise necessary or advisable to stop any activity that we consider illegal, unethical or legally actionable activity.
5.2 INTERNATIONAL Data Transfers
You agree that all Personal Information collected via or by us may be transferred, Processed, and stored anywhere in the world, including but not limited to, the United States, the European Union, in the cloud, on our servers, on the servers of our affiliates or the servers of our service providers. Your Personal Information may be accessible to law enforcement or other authorities pursuant to a lawful request. By providing information to us, you explicitly consent to the storage of your Personal Information in these locations.
6. Opt-Out (RIGHT TO OBJECT TO PROCESSING)
You have the right to object to and opt out of certain uses and disclosures of your Personal Information. Where you have consented to SignalFx’s Processing of your Personal Information or Sensitive Personal Information, you may withdraw that consent at any time and opt out of further Processing by contacting [email protected]. Even if you opt out, we may still collect and use non-Personal Information regarding your activities on our Sites and/or information from the advertisements on Third-Party websites for non-interest based advertising purposes, such as to determine the effectiveness of the advertisements.
6.2 Email and Telephone Communications
We maintain telephone “do-not-call” and “do-not-mail” lists as mandated by law. We process requests to be placed on do-not-mail, do-not-phone and do-not-contact lists within 60 days after receipt, or such shorter time as may be required by law.
6.3 Mobile devices
We may occasionally send you push notifications through our mobile applications with notices that may be of interest to you. You may at any time opt out from receiving these types of communications by changing the settings on your mobile device. We may also collect location-based information if you use our mobile applications. You may opt out of this collection by changing the settings on your mobile device.
6.5 “Do Not Track”
Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. DNT is a way for users to inform websites and services that they do not want certain information about their webpage visits collected over time and across websites or online services. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.
6.6 Cookies and Interest-Based Advertising
As noted above, you may stop or restrict the placement of cookies on your computer or remove them from your browser by adjusting your web browser preferences. Please note that cookie-based opt-outs are not effective on mobile applications. However, on many mobile devices, application users may opt out of certain mobile ads via their device settings.
The online advertising industry also provides websites from which you may opt out of receiving targeted ads from our data partners and our other advertising partners that participate in self-regulatory programs. You can access these, and also learn more about targeted advertising and consumer choice and privacy, at www.networkadvertising.org/managing/opt_out.asp, or http://www.youronlinechoices.eu/ and www.aboutads.info/choices/. You can also choose not to be included in Google Analytics here.
7. Rights of Access, Rectification, Erasure, and Restriction
Although we make good faith efforts to provide Individuals with access to their Personal Information, there may be circumstances in which we are unable to provide access, including but not limited to: where the information contains legal privilege, would compromise others’ privacy or other legitimate rights, where the burden or expense of providing access would be disproportionate to the risks to the Individual’s privacy in the case in question or where it is commercially proprietary. If we determine that access should be restricted in any particular instance, we will provide you with an explanation of why that determination has been made and a contact point for any further inquiries. To protect your privacy, we will take commercially reasonable steps to verify your identity before granting access to or making any changes to your Personal Information. To protect your privacy, we will take commercially reasonable steps to verify your identity before granting access to or making any changes to your Personal Information.
8. Data Retention
9. Security of Your Information
We take reasonable measures to protect the information that we collect from or about you (including your Personal Information) from unauthorized access, use or disclosure. Please be aware, however, that no method of transmitting information over the Internet or storing information is completely secure. Accordingly, we cannot guarantee the absolute security of any information. We do not accept liability for unintentional disclosure.
By using the Site or providing Personal Information to us, you agree that we may communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Site. If we learn of a security system’s breach, we may attempt to notify you electronically by posting a notice on the Site or sending an e-mail to you. You may have a legal right to receive this notice in writing.
10. International Users
If you are visiting from the European Union or other regions with laws governing data collection and use, please note that you are agreeing to the transfer of your information to the United States and to Processing of your data globally. By providing your Personal Information, you consent to any transfer and Processing in accordance with this Policy.
11. Children’s Privacy
Our Services are not directed to children under 13 (or other minimum age as required by local law) and we do not knowingly collect Personal Information from children under 13. If you learn that your child has provided us with Personal Information without your consent, you may alert us at [email protected]. If we learn that we have collected Personal Information of a child under 13 we will take steps to delete such information from our files as soon as possible and terminate the child’s account.
12. Redress/Compliance and Accountability
If you are an EU or Swiss citizen and feel that we are not abiding by the terms of this Policy, or are not in compliance with the Privacy Shield Principles, please contact us at the contact information provided above.
In addition, we have agreed to refer unresolved complaints related to Personal Information to JAMS Privacy Shield Dispute Resolution Program. For more information and to submit a complaint regarding Individual data to JAMS, a dispute resolution provider which has locations in the United States and the EU, visit: https://www.jamsadr.com/eu-us-privacy-shield.
Such independent dispute resolution mechanisms are available to citizens free of charge. If any request remains unresolved, you may contact the national data protection authority for your EU Member State.
You may also have a right, under certain conditions, to invoke binding arbitration under Privacy Shield; for additional information, see https://www.privacyshield.gov/article?id=ANNEX-I-introduction. The FTC has jurisdiction over our compliance with the Privacy Shield.
13. Other Rights and Important Information
- New Uses of Personal Information. Additionally, before we use Personal Information for any new purpose not originally authorized by you, we will endeavor to provide information regarding the new purpose and give you the opportunity to opt out. Where consent of the Individual for the Processing of Personal Information is otherwise required by law or contract, we will endeavor to comply with the law or contract.
13.2 California Privacy Rights
This Policy shall be implemented by SignalFx and all its operating divisions, subsidiaries and affiliates. We have put in place mechanisms to verify ongoing compliance with Privacy Shield Principles and this Policy. Any Employee that violates these privacy principles will be subject to disciplinary procedures.
The following capitalized terms shall have the meanings herein as set forth below.
- “Agent” means any Third-Party that Processes Personal Information pursuant to the instructions of, and solely for, SignalFx or to which SignalFx discloses Personal Information for use on its behalf.
- “Employee” refers to any current, temporary, permanent, prospective or former employee, director, contractor, worker, or retiree of SignalFx or its subsidiaries worldwide.
- “Personal Information” is any information relating to an identified or identifiable natural person (“Individual”).
- “Privacy Shield” means the seven (7) principles of the Privacy Shield Framework: (1) notice, (2), choice, (3) accountability for onward transfer, (4) security, (5) data integrity and purpose limitation, (6) access, and (7) recourse, enforcement, and liability. Additionally, it includes the sixteen (16) supplemental principles described in the Privacy Shield: (1) sensitive data, (2) journalistic exceptions, (3) secondary liability, (4) performing due diligence and conducting audits, (5) the role of the data protection authorities, (6) self-certification, (7) verification, (8) access, (9) human resources data, (10) obligatory contracts for onward transfers, (11) dispute resolution and enforcement, (12) choice – timing of opt-out, (13) travel information, (14) pharmaceutical and medical products, (15) public record and publicly available information, and (16) access requests by public authorities.
- “Process” or “Processing” means any operation which is performed upon Personal Information, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- “Sensitive Data” or “Sensitive Personal Information” is a subset of Personal Information which, due to its nature, has been classified by law or by policy as deserving additional privacy and security protections. Sensitive Personal Information includes Personal Information regarding EU residents that is classified as a “Special Category of Personal Data” under EU law, which consists of the following data elements: (1) race or ethnic origin; (2) political opinions; (3) religious or philosophical beliefs; (4) trade union membership; (5) genetic data; (6) biometric data where Processed to uniquely identify a person; (6) health information; (7) sexual orientation or information about the Individual’s sex life; or (8) information relating to the commission of a criminal offense.
- “Third-Party” is any company, natural or legal person, public authority, agency, or body other than the Individual, SignalFx or SignalFx’s Agents.
15. Revision history