Privacy policy
This Privacy Policy (“Privacy Policy”) explains how information is collected and used by DoControl, Inc. (“DoControl” or “we”, “us”, “our”).
This Privacy Policy applies to the following:
- The data practices on the DoControl website at docontrol.io (“Website”).
- DoControl’s practices with respect to the SaaS (the “Service”) that DoControl provides its customers (“Businesses”). As background, the Service offers Businesses a modern security layer enforcing advanced security features on the multiple SaaS applications they use, regardless of each SaaS application’s underlying capabilities.
We are committed to protecting and respecting data privacy. Please read this Privacy Policy carefully.
PERSONAL DATA PROCESSED
We collect and process your contact information and billing information when you send us an inquiry or engage us to use our Service
You may contact us through email: contact@docontrol.io. When a representative of a Business wishes to use our Service, we collect that person’s contact details such as full name, email address, and information relating to the engagement between us and the Business. We will also collect, if necessary payment information such as credit card or bank account information in order to bill you for the Services. We refer to this as “Contact Information”.
The Service we provide involves processing information of the Business’s users
In order to provide the Service to a Business, we process personal information of the Business’s users using the Service. This includes your full name, email address and account user name.
The Service also processes personal data regarding the usage behavior and usage patterns in relation to the SaaS applications that the Business’s users use. This includes the end-user’s IP address and approximate location derived from the IP address.
We refer to this overall data as “Usage Information”.
You do not have a legal obligation to provide us with your Contact Information or Usage Information. However, if you choose to not share this information with us we may not be able to respond to your inquiry or provide you the Service.
We also collect analytics information about your use of the Website
When you visit the Website, we record and collect certain information about your interaction with the Website, including the IP address from which you access the Website or Service, time and date of access, type of browser used, language used, links clicked, and actions taken while using the Website or Service. We refer to this data as "Website Analytics Information".
DATA CONTROLLER AND PROCESSOR
The Business is the data controller of the Contextual Data like file names and sender and recipient information; DoControl is the merely data processor for this data.
Each Business is the data controller of its own Contextual Data (as defined below). DoControl may process the Contextual Data only for the provision of the Service to you.
For that matter, "Contextual Data"means information: (a) that identifies or depicts the Business’s content that is controlled or monitored through the Service, such as, by way of example only, file names; or (b) that identifies individuals who have a bearing to the Business’s content, such as, for example, sender or recipient name and email address.
DoControl is the data controller of the information described in this Privacy Policy
DoControl is the data controller of the other information explained in this Privacy Policy. We determine the purposes and means of processing that data as part of our Service. We only process such data for the purpose of providing the Service to businesses.
HOW WE PROCESS PERSONAL DATA
To respond to and handle your inquiry and manage our relationship with the Business
We process your Contact Information to contact you about your inquiry and handle your inquiry, to bill for the Service and manage our engagement with the Business.
To provide you with the Service
We process Usage Information in order to give you access to use the Service.
To understand user behavior and assess security risks
We also process Usage Information in order to detect and assess security threats and calculate security risk scores which in turn helps us to improve the Business’s security posture regarding the SaaS applications that you and your fellow co-workers use.
We also aggregate data on how you and your fellow co-workers use SaaS applications and use that to detect threats and calculate risk scores on an organization-level (Business-specific), app-level, and user-level basis.
We refer to this overall data as "Risk Assessment Information".
To maintain the Website
We process the Website Analytics Information to provide, maintain and improve your user experience when accessing our Website. We also will use the Analytics Information for quality assurance and for development and enhancement of the Website.
We will use the Website Analytics Information to prevent fraud, resolve disputes, troubleshoot problems, assist with any investigations, enforce our terms of use for the Website and take other actions otherwise permitted by law.
WHO PROCESSES YOUR DATA
We will not share your information with third parties, except in the events listed below or when you provide us your explicit and informed consent.
We will share Risk Assessment Information associated with your account with the representatives of the Business you work at.
We will share Usage Information and Risk Assessment Information associated with your account with representatives of the Business you work at, for their visibility into the organization-level, app-level, and user-level security risks.
We will process information with our service providers helping us to operate our business.
We will process personal data with the assistance of our service providers who assist us with the internal operations of the Website and Service. These companies are authorized to use your personal data in this context only as necessary to provide these services to us and not for their own promotional purposes. These service providers include Amazon Web Services, Inc.
We will share information with competent authorities, if you abuse your right to use the Service, or violate any applicable law.
If you have abused your rights to use the Website or Service, or violated any applicable law, we will share information with competent authorities and with third parties (such as legal counsels and advisors), for the purpose of handling of the violation or breach.
We will share your information if we are legally required.
We will share information if we are required to do so by a judicial, governmental or regulatory authority.
We will share your Information with third-parties in any event of change in our structure.
If the operation of our business is organized within a different framework, or through another legal structure or entity (such as due to a merger or acquisition), we will share information only as required to enable the structural change in the operation of the business.
COOKIES
What are cookies?
Cookies are text files, comprised of small amount of data, that are saved on your computer or other device (e.g. smartphone, tablet, etc.) when you use the internet and visit various websites.
The information that the cookies maintain is read by the website you visit, during the session of your visit to the website (these are called ‘session’ cookies), and when you return to visit it again (these are called ‘persistent’ cookies).
We use cookies necessary to operate the Website and for website statistics.
We use cookies for a number of purposes, as briefly explained below:
Necessary. Cookies that are strictly necessary for the functioning of the Website. The Website cannot operate properly without these cookies. You can set your browser to block or alert you about these cookies, but some parts of the Website may not function properly.
Statistics. Analytics cookies that help us understand how you and other users interact with our Website by collecting data that does not directly identify you.
You can always delete or disable cookies.
You can always delete the cookies saved on your device through the settings of your computer browser or device. You can also disable cookies for future use through the settings of your computer browser or device.
SECURITY AND DATA RETENTION
We generally will retain your Contact Information, Usage Information, Risk Assessment Information and Analytics Information for as long you and your Business uses the Service, and thereafter for another 45 days.
your Business uses the Service, and thereafter for another 45 days.
We will retain your personal data for as long as necessary to provide our Service, and as necessary to comply with our legal obligations, resolve disputes, and enforce our policies. Retention periods will be determined taking into account the type of information that is collected and the purpose for which it is collected, bearing in mind the requirements applicable to the situation and the need to destroy outdated, unused information at the earliest reasonable time.
We implement measures to secure your Information
We implement measures to reduce the risks of damage, loss of information and unauthorized access or use of information. These include encryption for data in transit and at rest. However, these measures do not provide absolute information security. Therefore, although efforts are made to secure personal data, it is not guaranteed, and you cannot expect that the Website or Service will be immune from information security risks.
INTERNATIONAL DATA TRANSFERS
We will internationally transfer information in accordance with applicable data protection laws.
If we transfer your personal data for processing at locations outside your jurisdiction, we will abide by data transfer rules applicable to these situations.
LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA
The legal basis under EU law for processing your Contact Information for the purpose of responding to and handling your inquiry, is our legitimate interests in responding to your inquiry.
The legal basis for processing Contact Information to bill for the Service and manage our engagement with the Business is the performance of our contractual obligations towards your, our legitimate interests in receiving the payments due for the Service and administering our relationship with the Business, and our compliance legal obligations.
The legal basis for processing Usage Information to give you access to the Service is your and our legitimate interests in providing and improving the Service you’ve signed up for.
The legal basis under EU law for processing Risk Assessment Information in order to detect and assess security threats and calculate security risk scores, is the legitimate interest of the Business in improving their information security.
The legal basis for processing Website Analytics Information, including for the purpose of handling instances of abusive use of the Website is our legitimate interest in maintaining, developing and enhancing the Website, as well as defending and enforcing against violations and breaches that are harmful to our business.
The legal basis under EU law for processing your information with authorities or where we are legally required to share it, is our compliance with mandatory legal requirements imposed on us.
YOUR RIGHTS WITH REGARD TO YOUR PERSONAL DATA
You have certain rights to access, update or delete information, obtain a copy of your information, and object or restrict certain data processing activities.
The rights set out below shall apply to anyone regardless of residence or applicable laws:
Right to Access your personal data that we process and receive a copy of it.
Right to Rectify inaccurate personal data we have concerning you and to have incomplete personal data completed.
Right to Data Portability, that is, to receive the personal data that you provided to us, in a structured, commonly used and machine-readable format. You have the right to transmit this data to another service provider. Where technically feasible, you have the right that your personal data be transmitted directly from us to the service provider you designate.
Right to Object, based on your particular situation, to using your personal data on the basis of our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or for the establishment, exercise of defense of legal claims. You may also object at any time to the use of your personal data for direct marketing purposes.
Right to Restrict the processing your personal data (except for storing it) if you contest the accuracy of your personal data, for a period enabling us to verify its accuracy; if you believe that the processing is unlawful and you oppose the erasure of the personal data and request instead to restrict its use; if we no longer need the personal data for the purposes outlined in this Privacy Policy, but you require them to establish, exercise or defense relating to legal claims, or if you object to processing, pending the verification whether our legitimate grounds for processing override yours.
Right to be Forgotten. Under certain circumstances, such as when you object to us processing your data and we have no compelling legitimate grounds to override your objection, you have the right to ask us to erase your personal data. However, we may still process your personal data if it is necessary to comply with a legal obligation we are subject to under applicable laws or for the establishment, exercise or defense of legal claims.
Please note that these rights are not absolute, and may be subject to our own legitimate interests and regulatory requirements, in compliance with data protection legislation. Users, including those outside the EU, are welcome to contact us for any questions or requests through our contact details below.
If you wish to exercise any of your rights, please contact us at: contact@docontrol.io.
We reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. Where we are not able to provide you the information that you have asked for, we will explain the reason for this.
You have a right to submit a complaint to the relevant supervisory data protection authority.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint to the supervisory authority, in particular in the Member State of your residence, place of work or place of alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here.
CHANGES TO THIS PRIVACY NOTICE
If we change this Privacy Policy, we will make efforts to proactively notify you of such changes.
From time to time, we may change this Privacy Policy. If we do so, we will make efforts to proactively notify you of such changes. In any event, the latest version of the Privacy Policy will always be accessible at https://www.docontrol.io/privacy.
Last Update: August 27, 2022
DOCONTROL'S CONTACT INFORMATION
The following is the contact information of DoControl:
DoControl, Inc.
333 West 39th St #403, New York, NY 10018
Email: contact@docontrol.io
If you reside in the EU, you may also approach our EU representative via the following contact information:
- By writing to European Data Protection Office ("EDPO") at Avenue Huart Hamoir 71, 1030 Brussels, Belgium; or
- By using EDPO’s online request form: https://edpo.com/gdpr-data-request/.
If you reside in the UK, you may also approach our UK representative via the following contact information:
- By writing to EDPO UK at 8 Northumberland Avenue, London WC2N 5BY, United Kingdom; or
- By using EDPO’s online request form: https://edpo.com/uk-gdpr-data-request/.