Information We Collect
“Personal Data” (or personal information) means any information about an individual from which that person can be identified. For instance, it may include your name, telephone number, email address, or payment information, and in some places like the European Economic Area (“EEA”) even your IP address. However, it does not include anonymous data – where any identifiers connected to an individual have been permanently removed. We collect a variety of Personal Data about our customers and visitors to the Platform in different ways.
Categories of Personal Data that we Collect
The Personal Data that we collect falls into these general categories (with some overlap in some instances):
- Identity Data: such as company of employment and title, first name, last name, username or similar identifier and an encrypted version of your login/password.
- Contact Data: includes email address.
- Profile Data: includes your username and password, preferences, feedback and survey responses, as well as any profile data which we have added (for example, using analytics and profiling).
- Financial Data: such as payment card details.
- Transaction Data: includes details about purchases and payments to and from you and other details relating to your activity on the Platform.
- Technical Data: such as internet protocol (IP) address, your login data, browser type and version, location, and other technology on the devices you use to access the Platform.
- Usage Data: includes information about how you use our Platform, products and services.
- Tracking Data: this is information we or others collect about you from cookies and similar tracking technologies.
- Marketing and Communications Data: includes your preferences in receiving direct marketing from us, as well as your communication preferences.
We do not – and do not wish to – collect any special categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data), nor do we collect any information about criminal convictions and offences.
We also collect, as a processor, any Personal Data of a third-party that you include in any data you provide through the Platform and you act as the controller of such Personal Data.
Know that if you choose not to share certain Personal Data with us, or refuse certain contact permissions, we might not be able to provide the services you need. This is especially true of Identity Data, which is necessary for us to enable your use of the Platform, or of Financial Data, which we need to collect and retain in order to validate and record any financial transactions on the Platform.
How and When We Collect Your Personal Data
We use different methods to collect Personal Data from and about you:
Direct interaction with the Platform. You may provide us your Identity, Contact and Financial Data by registering on the Platform or by corresponding with us, mostly by email or through social media. This includes Personal Data you provide when you:
- create an account on the Site;
- register for the Platform;
- make inquiries or request information be sent to you;
- ask for marketing to be sent to you;
- engage with us on social media;
- contact customer services; or
- leave comments or reviews
Automated technologies or interactions. As you interact with us, such as browsing our Site, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We may also collect Tracking Data when you use our Platform.
Third parties or publicly available sources. We may receive Personal Data about you from various types of third parties, including:
- Technical Data and/or Tracking Data from analytics providers, advertising networks and partners, and search information providers (such as Google);
- Identity and Contact Data from data partners; and
- Data from any third parties who are permitted by law or have your permission to share your Personal Data with us.
California Specific Rights
To the extent you are a ‘consumer’ as defined under the California Consumer Privacy Act of 2018 (“CCPA”) and Analyze is a ‘business’ as defined under CCPA, the following applies to you:
Subject to the provisions of the CCPA, you have the right to request in the manner provided herein, for the following:
a. Right to request for information about the:
- Categories of Personal Data Analyze has collected about you.
- Specific pieces of Personal Data Analyze has collected about you.
- Categories of sources from which the Personal Data is collected.
- Business or commercial purpose for collecting Personal Data.
- Categories of third parties with whom the business shares Personal Data.
b. Right to request for deletion of any Personal Data collected about you by Analyze.
If you seek to exercise the foregoing rights to access or delete Personal Data which constitutes ‘personal information’ as defined in CCPA, please contact us at Support@goanalyze.io. We respond to all requests we receive from you wishing to exercise your data protection rights within a reasonable timeframe in accordance with applicable data protection laws. By writing to us, you agree to receive communication from us seeking information from you in order to verify you to be the consumer from whom we have collected the Personal Data from and such other information as reasonably required to enable us to honour your request.
Cookies are text files stored on your device which allow us to track and identify our visitors, their usage of the site and website preferences. You can configure your device not to accept our cookies if you wish, although certain features of our site may not work if you do this.
How we use information we collect
We will only use your Personal Data as allowed by law. In general, we will use your Personal Data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you. For example, when you register for the Platform, that’s a contract.
- Where it is necessary for our legitimate interests, which may include our business interests, but only where your interests and fundamental rights do not override those interests. For example, when we analyze issues that users encounter, or when we analyze system performance.
- Where we need to comply with a legal or regulatory obligation. For example, keeping Financial and Transactional Data for tax compliance.
Generally, we do not rely on consent as a legal basis for processing your Personal Data other than where the law requires it, for example in relation to sending certain direct marketing communications. Where our legal basis is consent, you have the right to withdraw consent any time.
For our EEA users and visitors, see Legal Bases for Processing Personal Data to find out more about the lawful bases that we will rely on to process your Personal Data.
All data is encrypted via SSL/TLS when transmitted between the client-side and server-side components of the Analyze platform. Additionally, all the communication between our backend services happens in a closed network that is not reachable from the outside.
Analyze recognizes the privacy interests of children and we encourage parents and guardians to take an active role in their children’s online activities and interests.
Our Platform and services are not intended for minors and Analyze does not target the Platform or any of its services to minors. Analyze does not knowingly collect Personal Data from minors. If you are under the age of 18, please do not register and do not provide us with any Personal Data.
Information We Share
Agents and contractors
Analyze may share Personal Data with our third-party agents, contractors, or service providers who are hired to perform services on Analyze’s behalf. These providers may operate or support certain functions of the Platform, or process Personal Data on our behalf in order to assist us with certain functions. Below is an illustrative list of functions for which we may use third-party service providers and the names of the providers we may use to perform these functions:
- Analytics services (e.g., Google Inc.)
- Email marketing outsourcing (e.g. Mailchimp or equivalent)
- Advertising services (e.g. Google Ads, Facebook Ads)
- Customer support services (e.g. Froged, Freshdesk. etc.)
- Hosting and content delivery network services (e.g., Amazon Web Services A.K.A. AWS)
- Communication services (e.g. Internal communication with our dev team for specific issues on accounts)
We may disclose Personal Data about you as required or permitted by law and/or to comply with a judicial proceeding, court order, or legal process. To the extent permitted by applicable law, we also may disclose Personal Data about you in response to a request from law enforcement agencies, regulators or other public agencies (including schools or children services) or if we believe such disclosure may prevent a crime, facilitate an investigation related to public safety or protect the safety of individuals, protect the security or integrity of our Platform, or enable us to take precautions against liability or to protect our rights.
We may disclose or otherwise transfer information about our users, including Personal Data, to an acquirer, successor, or assignee as part of any merger, acquisition, sale of assets, or similar transaction, or in the event of an insolvency, bankruptcy, or receivership in which information is transferred to one or more third parties as one of our business assets.
Information via Cookies
We also share data with third parties connected to advertising, retargeting and analytics. Please see Cookies above, for more information about who those third parties are.
We share aggregated, automatically-collected or otherwise non-personal information with third parties for various purposes, including (i) compliance with reporting obligations; (ii) for business or marketing purposes; (iii) to assist us and other parties in understanding our users’ interests, habits and usage patterns for certain programs, content, services, advertisements, promotions and/or functionality available through the Platform. We do not share personal information about you in this case.
Social Network Plugins
We may use social plugins on our Platform and may include icons that allow you to interact with third-party social networks. If you use any social plugins, the relevant third-party may set a cookie when your browser creates a connection to the servers of such social networks and the plugin may transmit your data to the social networks.
Legal Basis For Processing Personal Data
The table below shows the different ways that we use Personal Data, and which of the legal bases we rely on to do so.
|Purpose/Activity||Type of Personal Data||Lawful basis for processing|
|To sign you up and register you as a new customer||IdentityContact||Performance of a contract with you – i.e., to enable your use of the Platform|
|To process and deliver your purchases including:
(a) Manage payments, fees and charges;
(b) Collect and recover money owed to us or our partners
|IdentityContactFinancial Transaction||Performance of a contract with you – i.e., in order to enable you to make payments. Necessary for our legitimate interests – i.e., to enable a variety of services on the Platform, and to recover debts due to us|
|To manage our relationship with you which will include:
(b) Asking you to leave a review or take a survey
|To deliver direct marketing to you||IdentityContactProfileUsageMarketing and CommunicationsTrackingTechnical||For most direct marketing communications where you have signed up on the Platform, it is in our legitimate interests to use your Personal Data in this way|
|To administer and protect the Platform, including: hosting of data, troubleshooting and bug fixes, analysis, testing, maintenance, and reporting||IdentityContactTrackingTechnical||Performance of a contract with you – i.e., to enable your use of the Platform Necessary for our legitimate interests – i.e., to run our business and provide a functional and secure Platform, to provide administration and IT services, for network security, to prevent fraud Necessary to comply with a legal obligation – i.e., if there are any specific security issues with the Platform|
|To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you||IdentityContactProfileUsageMarketing and CommunicationsTrackingTechnical||Necessary for our legitimate interests – i.e., to understand how customers use our products/services, to develop new features and enhance existing ones, or grow our business, to inform our marketing strategy|
|To improve our Platform, services, user experience and marketing strategy by using data analytics||TechnicalTrackingUsage||Necessary for our legitimate interests – i.e., to best connect users to our services, to keep our Platform updated and relevant, to develop our business and to inform our marketing strategy, and to attract new company customers|
|To make suggestions and recommendations to you about additional features or services that may be of interest to you||IdentityContactProfileUsageTechnical||Necessary for our legitimate interests – i.e., to enhance our current offerings, develop new features, increase our business and user base|
|In order to resolve legal claims (including existing claims/litigation and potential disputes) involving you or Analyze.||All Personal Data||Necessary for our legitimate interests – i.e., to defend our business in the event of a dispute or assist users where their legal claims against a third-party stem from their activity on our Platform Necessary to bring or defend a claim|
Note that we may process your Personal Data for more than one lawful ground depending on the specific purpose for which we are using your data. We do not carry out any automated decision making.
We have implemented a number of security measures designed to protect your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. For instance, we use firewalls, password protection, secure socket layer, encryption, and other security measures to help prevent unauthorised access to your personal data.
In addition, we limit access to your Personal Data to our employees, agents, contractors and other third-parties who have a business need to know. They will only process your Personal Data on our instructions and they are subject to a duty of confidentiality.
We have implemented procedures to handle any suspected Personal Data breach (or unauthorised access) and will notify you and any applicable regulator of a breach as legally required.
We will only keep your Personal Data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. In some circumstances you can ask us to delete your data; see EEA Rights: Staying in Control of Your Information: Your Legal Rights below for further information.
General Retention Periods
Subject to exceptions as required or permitted by applicable law, we retain Personal Data that is necessary for your use of the Platform as long as you are a user of the Platform. Given the nature of our services and tax-related matters, we retain certain Financial Data and related information for as long as required by law.
Metadata on the Platform which is needed for the purposes of IT security and maintaining the Platform in general, can be retained for the prevention of fraud and abuse, and therefore will be retained for such purpose, generally for a period of up to three years. This includes (for instance) IP address.
There are exceptions from static retention periods that have to be taken into consideration. For instance, we cannot delete Personal Data when there are legal obligations to retain the Personal Data (e.g. arising from tax or commercial law). This is particularly true of data Financial Data and payment information.
Additionally, we cannot delete Personal Data when it is needed for the establishment, exercise or defense of legal claims (“litigation hold”). In this case, the Personal Data can be retained as long as needed for exercising respective potential legal claims.
Time frame of deletion
If Personal Data can no longer be retained it will be erased without undue delay, generally within one month, unless exceptions apply.
In some instances, we may choose to anonymise your Personal Data instead of deleting it, for statistical use, for instance. When we choose to anonymise, we make sure that there is no way that the Personal Data can be linked back to you or any specific user.
With respect to all of the rights listed below, please click in order to exercise your rights.
- Your right to rectification. You have a right to rectify, update or complete any inaccurate Personal Data, pending verification of your identification. Most of this can be accomplished by going to your “Account Settings” and making any changes there. For instance, if your contact details change, or if you spot any errors in the information we hold about you, we recommend starting with your “Account Settings”. If, after visiting your “Account Settings”, you are still unable to rectify the information, please contact us directly here.
- Your right of access. You have the right to obtain a copy of all Personal Data that Analyze holds about you, such as personal details, correspondence, marketing preferences, consent information, complaints, queries and payment history, generally, within a 30-day time limit and free of charge. You may limit the amount of data that you would like to obtain if you do not wish to access all of the records.
- Your right to move your data (portability). Under certain circumstances, you can request that a data collector move your data to another service provider however, this is not an automatic right.
- Your right to object to processing. You have to right to request that Analyze stop certain data processing activities that involve processing your Personal Data. This isn’t an automatic right, and Analyze’s ability to restrict processing will depend on the type of data that for which you are making this request.
- Your right to request deletion You have a right to request that Analyze delete your Personal Data that it holds. This isn’t an automatic right, and what Analyze is able to delete will depend on the type of data that Analyze holds about you, whether it was obtained via consent, what purpose it serves, and whether Analyze has an obligation to keep the data, among other things.
These rights are subject to certain rules around when you can exercise them. You can see a lot more information on them, if you are interested, on the UK Information Commissioner’s Office website, for instance.
For all requests mentioned above, we may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that Personal Data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
- You have a right to lodge a complaint with a Supervisory Authority. If you feel that Analyze is not processing your Personal Data in a manner that complies with the GDPR, you have a right to lodge a complaint with the supervisory authority of your country of residence. Of course, we would appreciate the chance to deal with your concerns before you approach a supervisory authority, so please contact us in the first instance.
- You have a right to withdraw your consent. For activities where you have provided consent to Analyze, you have a right to withdraw your consent at any time.
- Your rights in relation to automated decision making and profiling That’s a right you have for us to be transparent about any profiling we do, or any automated decision making.
If you wish to exercise any of the rights set out above, please contact us (see How to Contact Analyze About Privacy).