Information Gathered from Third Parties
We may obtain User Information from certain third-party sources, such as public databases, social media platforms, third-party data brokers, and our joint marketing and resale partners. We take steps to ensure that such third parties are legally permitted or required to disclose User Information to Us, provided, however, that We are not responsible for the accuracy or use of such User Information. Our use and disclosure of User Information is described further elsewhere in this Notice (see Use of User Information and Disclosure of User Information).
Additionally, in the course of providing the Digital Shadows SearchLight and/or ReliaQuest GreyMatter Digital Risk Protection service offerings to Our customers, we search and store parts of publicly-available webpages and files on the Internet and the “dark web” to check for security risks that might negatively impact Our customers. Our activities in connection with the Digital Shadows SearchLight and/or ReliaQuest GreyMatter Digital Risk Protection service offerings are important services that substantially assist Our customers in identifying and addressing inadvertent or intentional exposure of commercial or personal data or information. Because of the scale of our efforts, the Internet content that we search and store may contain or consist of publicly-available data or information related to an identifiable person. Although we do not intentionally search for or store data or information related to individuals who are not also related to Our customers, persons who believe data or information relating to them may have been collected or made available to Us may direct questions about or comments on such practices by contacting us in the manner described in the Contact Information section of this Notice.
Website Usage Data
We may automatically collect User Information about your interaction with Our website, using usage data tracking and analytics technologies, like cookies and clear gifs. This User Information provides information about how users interact with Our website, which allows Our sales, marketing, and product management teams to, among other things, prepare reports on use of the website, analyze website insights, create new features or functionalities for or further develop the website and enrich the website user interface and experience. Additional information about the methods We use to automatically collect User Information with respect to Our website, as well as users’ choices with respect to Our collection of User Information, is described elsewhere in this Notice (see Cookies).
Information Collection by Third Parties
In the course of accessing or using Our website, procuring or using of Our services, or engaging in any live, mailed, or electronic communications with Us, users may provide User Information to third parties or third parties may use information collection or tracking technologies to collect User Information about users. These third parties may include:
- The users’ electronic communication devices (e.g., phones, tablets, laptops, and desktop computers) or telecommunications service provider;
- The manufacturers, distributors, or retailers of the users’ electronic communication devices (including their components), as well the parties who may control or access the users’ electronic communication devices, such as their employers;
- The developers of the operating system or other applications operating on the users’ electronic communication devices or with which the users interact using their electronic communication devices, including the Internet browsers through which users access Our website; or
- The persons responsible for developing, hosting or otherwise making available webpages and associated content, including the third parties of such persons, to the extent users interact with links or plug-ins to other webpages and associated content through or in connection with Our website.
The User Information these third parties collect may be associated with users directly, or the third parties may collect User Information about particular users over time and across different websites, apps, and other online or offline services or interactions.
For example, Our website may include social network sharing plug-ins or widgets that may provide User Information to the associated social networks or third parties regarding users’ interaction with our website, even if such users do not click on or otherwise interact with the plug-in or widget. When a user loads a page on Our website that has a social media plug-in from a third-party site or service, such as a “Like” or “Share” button, the user is also loading content from the third-party site or service, and the information transmitted to such third-party site or service may include identifiers assigned by the site or service, such as browser type, operating system, device type, IP address, and the URL of the web page where the plug-in or widget appears. In addition, third-party sites or services may use information collection or tracking technologies, like cookies, to collect User Information about users for targeted online marketing and other purposes.
We do not control these third parties' information collection or tracking technologies, We do not accept responsibility or liability for the conduct of such third parties, and this Notice does not detail the data handling policies and practices of such third parties. If users have any questions about the third parties described in this section of the Notice (Information Collection by Third Parties), users should contact the relevant third party directly.
Use of User Information
We use User Information that We collect, as outlined elsewhere in this notice (see Collection of User Information), for the following purposes:
- Website and services: To provide, improve, and customize Our website and services, which furthers our legitimate interest in operating Our business and communicating with the public regarding Our website and services; supporting or provisioning users’ procurement, access to, and use of Our website or services; analyzing, understanding, and obtaining insights into how Our website and services are being used by users and how users are communicating with Us; benchmarking, auditing, developing, and improving Our website, services, and communications; monitoring the health, performance, and security of Our website and services; and exploring and developing new methods of developing and growing Our business.
- Sales and marketing: To deliver and facilitate communications about Our business and services, cybersecurity-related developments, and other relevant information in forms such as surveys, alerts or notifications, newsletters, invitations, and announcements. We will normally ask users to agree—or “opt-in”—to receiving sales and marketing communications but sometimes, where users have previously communicated with Us or requested information from Us, We will send such communications about the same or similar communication or information after users have the option and elect not to opt-out of receiving such communications. Additional information about the sales and marketing communications opt-out process is described elsewhere in this Notice (see Sales and Marketing Communications Opt-Out).
- Legal interests: To comply with, conform to the requirements of, or carry out Our obligations and enforce Our rights arising under any applicable law or legal agreements between Us and users or the persons on whose behalf users act, such as users’ employers, to the extent We believe necessary or appropriate in the relevant circumstances. We also use User Information to further our legitimate interest in preventing, detecting, and deterring fraudulent activities, misuse of our website and services, or other inappropriate conduct and to promote the health, safety, and security of Our users, customers, website, services, and other third parties.
- Administrative and corporate transactions: For general business administrative purposes and to explore or consummate certain corporate or enterprise transactions, such as a reorganization, merger, liquidation, receivership or transfer of some or all of Our business assets or equity.
- Consent or Instruction: To discharge actions that users instruct us to undertake or for which users provide consent or to interact with and respond to users’ other inquiries, communications, or requests for information.
We do not sell User Information for monetary consideration, and we will not sell User Information without providing any notice or right of opt-out as may be required under applicable law.
Disclosure of User Information
We disclose User Information that we collect and use, as outlined elsewhere in this notice (see Collection of User Information and Use of User Information), to the following groups of persons:
- ReliaQuest group: To Our personnel, subsidiaries, parent and holding companies, and other interests under our control to provide Our website and services and to communicate with users.
- Service providers: To Our service providers, contractors, vendors, subprocessors, and other third parties, who support or enable Us to provide Our website and services, to communicate with users, and to perform related services, such as web hosting providers, customer relationship management tool providers, information technology service providers, analytics providers, and those applicable persons identified in Our current list of Third Party Platform Providers.
- Channel vendors and customers: To Our authorized resellers, managed security service and channel vendors, who assist Us in selling or delivering Our services and communicating with users, and, in the case of information gathered pursuant to our search of publicly-available information (see Information Gathered from Third Parties), to Our customers who have subscribed to the Digital Shadows SearchLight and/or ReliaQuest GreyMatter Digital Risk Protection service offerings.
- Professional advisers and government entities: To consultants, advisers, and similar professional service providers, public or private adjudicative bodies (such as courts, arbitrators, or administrative tribunals), public or private enforcement, legislative, or investigative bodies (such as regulatory or law enforcement agencies), and other affected or interested persons in connection with Our efforts to comply with, conform to the requirements of, or carry out Our obligations and enforce Our rights arising under any applicable law or legal agreements between Us and users or the persons on whose behalf users act, such as users’ employers, to the extent We believe necessary or appropriate in the relevant circumstances and to further our legitimate interest in preventing, detecting, and deterring fraudulent activities, misuse of our website and services, or other inappropriate conduct and to promote the health, safety, and security of Our users, customers, website, and services, and other third parties.
- Administrative and corporate transactions: To consultants, advisers, and similar professional service providers, and targets, bidders, financiers, and similar interested persons in connection with our exploration or consummation of certain corporate or enterprise transactions.
- Consent or Instruction: To the persons necessary or appropriate for Us to discharge actions that users instruct Us to undertake or for which users provide consent or to respond to other inquiries, communications, or requests for information.
Jurisdiction-Specific Information on Privacy Rights
Depending on where users reside or the jurisdiction in or through which users access or use Our website, procure or use Our services, or engage in any live, mailed, or electronic communication with Us, and the laws applicable to such users and the relevant User Information in those circumstances, users may be able to exercise one or more of the following privacy rights related to the User Information that We collect or are otherwise made available to us:
- Right of access: The right to request access to User Information that We hold about the requesting user and information about Our use of such User Information and with whom We share such User Information. This may include the right to request that We provide a copy of the requesting user’s User Information, as well as the following information about Our collection, use, and disclosure of such User Information over the twelve-month period preceding the request: (i) the categories of and specific items of User Information We have collected about the requesting user; (ii) the categories of sources from which We collect such User Information; (iii) the categories of business or commercial purposes for collecting such User Information; (iv) the categories of third parties to whom such User Information was disclosed for a business purpose; and/or (v) and categories of User Information disclosed for a business purpose.
- Right of correction: The right to request that We correct inaccurate User Information maintained about the requesting user.
- Right to erase or delete: The right to request that We delete the requesting user’s User Information in certain circumstances and subject to certain exceptions. We cannot delete User Information except by also deleting the relevant user account.
- Right to object or restrict: The right to object to Our processing of the objecting user’s User Information and, in certain circumstances, the right to require Us to stop processing such User Information We hold about the objecting user other than for storage purposes and/or the right to restrict or limit Our use or disclosure of sensitive User Information, if any, to only what is necessary to provide users with the ability to access or use Our website, procure or use Our services, or engage in any communication with Us.
- Right to portability: The right to request the portability of the requesting user’s User Information that We process.
- Right to withdraw consent: Where We rely on consent to process a user’s User Information, the right to withdraw consent at any time by notifying Us in the manner described in the Contact Information section of this Notice. Withdrawing consent will not affect the lawfulness of Our processing before the user withdrew the user’s consent or the processing of the user’s User Information on another lawful basis.
- Right to nondiscrimination: We will not discriminate against a user for exercising the rights to which the user is entitled.
- Right to opt-out of sale: We do not sell User Information for monetary consideration. To the extent that We sell User Information within the meaning of applicable data privacy laws, the user would have the right to instruct Us not to sell the instructing user’s User Information.
- Right to avoid automated decision-making: We do not engage in automated processing, as defined under applicable data privacy laws, to produce legal effects concerning users. If We ever employ automated processing that significantly impacts users in accordance with applicable data privacy laws, users will retain the right to opt out of decisions made solely through automated processing.
If a user is entitled to one or more of the foregoing rights, the user may exercise the right(s) to which the user is entitled by notifying Us of the user’s specific request in the manner described in the Contact Information section of this Notice. If a user is unsure if the user is entitled to one or more of the foregoing rights, the user should consult the laws and regulations of the user’s applicable jurisdiction. We will use commercially reasonable efforts to comply with users’ requests.
For users’ protection, We will only respond to verifiable requests. Accordingly, We may need to collect certain information from the requesting user to verify the user’s identity, such as the user’s email address, government-issued identification, or date of birth, before providing a substantive response to the user’s request. We may need to retain certain information for recordkeeping or legal purposes or to complete any transactions initiated before the user’s request.
The user may also be able to designate an authorized agent to exercise the right(s) to which the user is entitled. To do so, the user must provide the authorized agent written and signed permission to exercise such rights on the user’s behalf. We reserve the right to require the user’s agent to verify the agent’s identity and to confirm directly with the user that the user has provided the authorized agent permission to exercise the user’s right(s).
The rights and procedures described this section are in addition to the other terms of this Notice and are intended to supplement the remainder of this Notice where required by applicable law. The rights to which users may be entitled vary by the applicable jurisdiction and the facts and circumstances in which the rights are invoked, and, accordingly, one or more of the rights or procedures described in this section of the Notice may not apply, in full or in part, to a particular user. Furthermore, some rights may be limited by applicable law, such as if fulfilling a user’s request for access to or deletion of User Information will adversely affect other individuals or Our trade secrets or intellectual property, an overriding public interest justifications exist, or We are by law required to disclose, retain, or delete or deny access to User Information.
International Transfers of User Information
ReliaQuest is based in the United States of America (“USA”), but We have global operations. When users access or use Our website, procure or use Our services, or communicate with ReliaQuest, users provide User Information to ReliaQuest in the USA. ReliaQuest’s subsidiaries and the third parties to whom ReliaQuest discloses User Information or from whom ReliaQuest receives User Information are based in the USA, European Union, United Kingdom, India, Singapore and other jurisdictions, some of which may not have laws that require the same level of protection for User Information as where a user resides or the jurisdiction in which the user accesses or uses Our website, procures or uses Our services, or communicates with ReliaQuest. We implement appropriate transfer mechanisms in accordance with applicable law to protect the User Information that We transfer, including by using the standard contractual clauses approved by the European Union’s European Commission and the United Kingdom’s Information Commissioner’s Office and as further described below. Users may request additional information about the transfer mechanisms employed by ReliaQuest in the manner described in the Contact Information section of this Notice.
Additionally, ReliaQuest complies with the EU-U.S. Data Privacy Framework (“EU-U.S. DPF”), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF,” and together with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, the “DPF”) as set forth by the U.S. Department of Commerce. ReliaQuest has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (“EU-U.S. DPF Principles”) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF. ReliaQuest has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (“Swiss-U.S. DPF Principles,” and together with the EU-U.S. DPF Principles, the “Principles”) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this Notice and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the DPF and the Principles, and to view Our certification, please visit https://www.dataprivacyframework.gov/.
We describe elsewhere in this Notice the types of User Information that We collect or that are otherwise made available to Us (see Collection of User Information), the purposes for which We use User Information (see Use of User Information), the types of third parties to whom We disclose User Information and the purposes for which We make such disclosures (see Disclosure of User Information), the privacy rights that certain users may exercise with respect to their User Information (see Jurisdiction-Specific Information on Privacy Rights), and how users may contact and communicate with Us regarding Our collection, use, and disclosure of User Information, including the options users may have for limiting such collection, use, or disclosure (see Contact Information)
In compliance with the DPF and the Principles, ReliaQuest commits to resolve complaints about Our collection, use, or disclosure of User Information. Users residing in or subject to the laws of the European Union, the United Kingdom, or the Swiss Confederation with inquiries or complaints regarding our compliance with the DPF and the Principles should first contact ReliaQuest in the manner described in the Contact Information section of this Notice. If a user does not receive timely acknowledgement of the user’s complaint from Us, or if We have not addressed the user’s complaint to the user’s satisfaction, users may refer a complaint to the data protection supervisory authority (or its designee) in the user’s applicable jurisdiction. If neither We nor the applicable data protection supervisor authority address a user’s complaint, the user may have the possibility to engage in binding arbitration through the Data Privacy Framework Panel. For more information on the Data Privacy Framework Panel, users should review Annex I of the EU-U.S. DPF Principles.
ReliaQuest is subject to the investigatory and enforcement powers of the Federal Trade Commission (“FTC”), and the FTC has jurisdiction over ReliaQuest’s compliance with the DPF and the Principles. ReliaQuest has further committed to cooperate with the panel established by the data protection authorities of the European Union, the United Kingdom, or the Swiss Confederation with regard to unresolved DPF complaints concerning human resources data transferred from the European Union, the United Kingdom, or the Swiss Confederation in the context of the employment relationship. In certain circumstances, We may be required to disclose User Information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. In cases of onward transfer to third parties of User Information relating to users residing in or subject to the laws of the European Union, the United Kingdom, or the Swiss Confederation pursuant to the DPF and the Principles where such User Information is not protected in accordance with the DPF and the Principles, ReliaQuest is potentially liable.
Cookies
Our website uses certain usage data tracking and analytics technologies, like cookies and clear gifs, to help Us identify users and users’ interests, remember users’ preferences, analyze users’ interactions with Our website, market Our services to users, control access to certain content on Our website, monitor and protect Our website, and to process communications or requests for information from users. In this section of the Notice, we refer to these types of usage data tracking and analytics technologies simply as “Cookies.”
Cookies that We Use
We classify the Cookies that we use, as described in the below chart, into the following categories:
- Essential: This kind of Cookie is necessary for the core functionality of Our website and ensures that it operates securely and as intended. Use cases for these Cookies include enabling users to navigate the website, access secure areas, or perform essential actions such as logging in, completing transactions, or remembering privacy preferences. Without these Cookies, certain critical website features may not function properly.
- Functional: This kind of Cookie is used to implement additional functionalities of Our website or to enhance its features or performance. Use cases for these Cookies include the implementation of website support or engagement features, like live web chat, non-necessary forms, or automatically-filled text boxes, or providing quantitative measures of website visitors and the website’s performance for troubleshooting and analytics so We can improve the performance of Our website and provide more relevant content to users.
- Marketing: This kind of Cookie is used to provide behavioral advertising and re-marketing analytics data. In other words, these Cookies are used to deliver advertisements that are relevant to users and their interests, to limit how frequently (if at all) that users are presented with an advertisement, to help gauge the efficacy of Our advertisements and understand users’ behavior after they are presented or engage with an advertisement.
For more information on the above categories of Cookies, or for information on the specific Cookies We utilize, please click on the “Details” link on the Cookie banner that appears when visiting Our website.