Last Updated June 24, 2022
This Policy applies when you interact with our websites located at https://www.finalsite.com/, https://www.finalsitesupport.com/, https:training.finalsite.com and any other websites, pages, features or content we own or operate (collectively, the “Site(s)”); when, as a subscriber to our service, you use services available through our online Finalsite platform (the “Platform”) and when you use our other products or services that direct you to this Policy (collectively, including the Sites and the Platform the “Service(s)”).
In providing our Services to subscribers of our Platform (“Clients”), Finalsite is a data processor as we process personal information on behalf and at the direction of the Clients. This Policy does not apply to Finalsite’s processing when it is a data processor. If you have submitted personal information to a Client through a website or a mobile application powered by us, you should directly contact that Client for assistance with any requests or questions relating to the processing of your personal information.
We may, in our sole discretion, modify or update this Policy from time to time. If we make a change to this Policy that we believe materially changes how we use your personal information or reduces your rights, we will notify you here or by means of a notice on our home page.
1. Personal Information We Collect
Finalsite collects certain personal information about you and your use of our Services. The definition of personal information (used interchangeably with “personal data” for European residents) depends on the applicable law based on your physical location. Only the definition that applies to your physical location will apply to you under this Policy. The personal information that Finalsite collects falls into three primary categories: (1) information you voluntarily provide to us, (2) information we collect from you automatically, and (3) information we collect from third parties.
Information You Voluntarily Provide to Us. We, or service providers that assist us in providing, maintaining, and operating our Services, may collect the following types of personal information from you:
- Web Forms. We may collect your name, email, school information and phone number when you request demos, free website reports, free consultations, or would like to get in touch with us for other matters. Personal information that you provide by email or web forms will be used only for such purposes as are described at the point of collection (for example on a web form), such as to send information to you or respond to your questions or comments. If you provide contact information, we may contact you to clarify your comment or question, or to learn about your level of interest in, or satisfaction with our services.
- Event and Training Registration. If you register for a Finalsite event or would like to participate in a training course, we may request certain personal information from you on our order form. We may ask you to provide contact information (such as name, email, school information, job title, role, organization name) and, for chargeable events, financial information (such as credit card number and expiration date). We use this information for billing purposes for event registration or to contact you if we have difficulty processing your order.
- Customer Service. When you engage with our support team, we may collect records, copies of your correspondence (including email addresses), and any additional information you choose to share with us.
- Professional Materials. We periodically offer content in the form of e-books, guides and free courses that might be useful to school professionals. In order to view these contents, we may ask you to provide your name, email, role, school information and country information.
- Testimonials. Our client contracts include client permission to post testimonials, both written and video, on our website. Permission to display client reference information (name, school, phone number) is obtained from our clients prior to displaying them on our site. If you wish to update or delete your testimonial, you can contact us at firstname.lastname@example.org.
- Blog and Forums. We offer publicly accessible blogs and community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request the removal of your personal information from our blog or community forum, please contact us at email@example.com. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why. Additionally, when you subscribe to our blog and would like to receive periodical updates, we may collect your name, email and role.
- Surveys. Occasionally we may provide you the opportunity to participate in surveys on our Sites. If you participate, we may request certain personal information from you. Participation in these surveys is entirely voluntary. The requested information typically includes contact information (such as name and email address). We use this information to improve our services and product offerings.
Information We Automatically Collect. To the extent permitted under the applicable law, we may collect certain types of information automatically, such as whenever you interact with the Sites or use the Services. We may collect the following types of information automatically from you:
- Usage Data. When you browse our Sites, we automatically collect log data such as your web request, Internet Protocol (“IP”) address, browser type, domain names, referring and exit pages and URLs, pages viewed and the order of these page views, the date and time you access our servers, and other diagnostic data.
- Device Information. When you use your desktop or mobile devices to access our Services, we may be able to identify your device’s unique device identifier, MAC address, operating system, and your mobile device’s advertising ID.
- Location Information. When you use our Services, we may infer the generic physical location and geographic regions of your device from your Wi-Fi, Bluetooth and other device settings. For example, your IP address may indicate your general geographic region. You may choose not to share your location details with us by adjusting your mobile or desktop device’s location services settings. For instructions on changing the relevant settings, please contact your service provider or device manufacturer.
Information We Collect From Third Parties. From time to time, we may obtain information about you from third-party sources as required or permitted by law. These sources may include:
- Marketing Partners and Analytics Providers: Unless prohibited by applicable law, we may obtain your personal information from marketing partners and analytics providers so that we can better understand which of our Services may be of interest to you and to provide us information necessary to improve our Services.
2. Cookies and Other Tracking Technologies
• Analyze our web traffic using an analytics package
• Identify whether you already visited our Sites
• Store information about your preferences
• To recognize when you return to our Sites
If you want to exercise your rights regarding personal information collected via cookies and similar tracking technologies, please see the Your Rights and Choices section below.
3. How We Use Your Information
We use your personal information as described in this Policy for business and commercial purposes, or as disclosed to you prior to such processing taking place. We may process your personal information:
- To Provide Finalsite’s Services. We will use your personal information to provide information or perform Services that you request, including managing your request as a registered user to our Platform. For example, when you register to our events, we may require your payment information to process your registration. Third parties such as payment processing companies may also access and/or collect your personal information when assisting us to fulfill your registration or other order. We work diligently with such third parties to protect your information.
- To Maintain Legal and Regulatory Compliance. Our Services are subject to certain laws and regulations which may require us to process your personal information. For example, we process your personal information to fulfill our business obligations, ensure compliance with education and student information protection laws, to manage risk as required under applicable laws and regulations, or to respond to requests by judicial process or governmental agency.
To Enforce Compliance with Our Terms, Agreements and Policies. When you access or use our Services, you are bound to our Terms. We may process your personal information for compliance purposes, such as carrying out our obligations and enforcing our Terms or other legal rights, including those arising from any contracts entered into between you and us, including for billing and collection.
To Detect and Prevent Fraud and Security Risks. We may process your personal information to help monitor, prevent and detect fraud and abusive use of our Service, monitor and verify your identity so that unauthorized users do not gain access to your information, enhance system security, and combat spam, malware, malicious activities or other security risks.
To Provide Customer Support or Respond to You. We collect any information that you provide to us when you contact us. Without your personal information, we cannot respond to you or ensure your continued use and satisfaction of the Services. For users of our Ask the Community and Share an Idea portals, your data is submitted to our partners aha.io and Slack. Additionally, we may copy your data into other tools as we act upon your suggestions. You may withdraw from participation in the portals by either making a support request at https://www.finalsitesupport.com or sending an email to firstname.lastname@example.org.
To Provide Marketing Communication. We may collect your email address, phone number or other electronic addresses that you voluntarily provide to us when you subscribe to our marketing communications. We will occasionally send you information on products, services and promotions. When you no longer wish to receive these marketing messages from us, you can opt out at any time by unsubscribing or following the instructions contained within such messages, emailing us at email@example.com. Our Platform users may opt out by clicking on the “My Account” button in the upper left corner of the Platform home page, and selecting “My Subscriptions”. Then under “Current Subscriptions” click on “Email Mailing List Settings”.
To Research and Develop of Our Services. We may process your personal information and derive analytical and statistical data to better understand the way you use and interact with our Services. For instance, analyzing where, on which types of devices and how our Site is used, how many visitors we receive, and where they click on the Site may help us improve our existing Services and to build new Services. Please see our Cookies and Other Similar Tracking Technologies section for more information.
To Personalize Your Experience. We may process your information to personalize your experience. By personalization, we enable you to more easily interact with our Services across platforms and devices.
To Facilitate Corporate Acquisitions, Mergers and Transactions. We may process any information regarding your account and your use of our Services as is necessary in the context of corporate acquisitions, mergers or other corporate transactions.
With Your Consent. For any other purpose disclosed to you prior to you providing us your personal information or which is reasonably necessary to provide the services or other related services requested, with your permission or upon your direction.
4. Why We Share Your Information
We share your personal information as needed to fulfill the purposes described in this Policy and as permitted by applicable law. We may disclose your personal information as described below.
- As Required by Law. We may access, preserve, and disclose information about you if we believe doing so is required or appropriate to (a) comply with law enforcement requests and legal processes, such as a court order or subpoena; (b) comply with requests from auditors, examiners or other regulators; (c) respond to your requests; or (d) protect your, our, or others’ rights, property or safety.
- Within Our Corporate Organization. We may share your personal information within our organization to provide you with the Services and take actions based on your request.
- With Our Service Providers. We may share your personal information with third-party service providers acting on our behalf to help us operate our Services. Service providers and vendors provide us with support services such as credit card processing, website hosting, single-sign-on, community and feedback management, analytics services, surveys and research services, and network maintenance. These third parties can only use your information in accordance with our written instructions and must comply with the information security protections we have put in place.
- During Business Transaction or Other Asset Transfers. We may disclose and transfer information about you to buyers, service providers, advisors, potential transactional partners or other third parties in connection with the advisors, potential transactional partners or other third parties of a corporate transaction in which we are acquired by or merged with another company, or we sell, liquidate, or transfer all or a portion of our business or assets. By engaging with us or using our Services, you understand and agree to our assignment or transfer of rights to your personal information. In the event of any such change in ownership or control of your personal information, we will notify you of such changes to the extent required under applicable law.
- With Our Business Partners. Subject to applicable law, we may share your personal information with our business partners, such as, for permitted marketing purposes, or for co-sponsored events based on your voluntary participation.
- With Your Consent. We may share your personal information for any purpose with your consent.
5. How We Protect Your Information
We follow generally accepted standards to protect the personal information submitted to us, both during transmission and once it is received. We maintain our Services and all associated information with technical, administrative, and physical safeguards to protect against the loss, unauthorized access, destruction, misuse, modification and improper disclosure of your personal information. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. We cannot guarantee the security of our databases or the databases of the third parties with which we may share such information, nor can we guarantee that the information you supply will not be intercepted while being transmitted over the internet. If you feel that the security of any account you might have with us has been compromised, you should contact us immediately at firstname.lastname@example.org.
6. Retention of Your Personal Information
We will retain your information for as long as your account is active, as needed to provide Services to our Clients or for other purposes stated in this Policy. We will cease to retain your personal information or remove the means by which the personal information can be associated with you as soon as it is reasonable to assume that such retention no longer serves the purpose for which the personal information was collected and is no longer necessary for legal or business purposes. If you wish to cancel your account or request that we no longer use your information to provide you services contact us at email@example.com. Please note that, we may still retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
7. Your Rights and Choices
Depending on the applicable law where you reside, you may exercise the right to access, correct, or delete your personal information that we have collected or has been previously provided to us. If you would like to exercise your rights under applicable law, please contact us at firstname.lastname@example.org. In your request, please make clear what personal information you would like to have access, changed or removed from our database. We may seek to verify your identity when we receive your privacy rights request to ensure the security of your personal information.
Marketing Communications. When you no longer wish to receive marketing messages from us, you can unsubscribe at any time by unsubscribing or following the instructions contained within such messages, emailing us at email@example.com. Our Platform users may opt out by clicking on the “My Account” button in the upper left corner of the home page, and selecting “My Subscriptions”. Then under “Current Subscriptions” click on “Email Mailing List Settings.” If you have any account for our Services, we will still send you non-promotional communications, such as service-related or account-related emails.
Additional Rights for California Residents. You may have additional privacy rights if you are a California Residents, see Section 10 “Notice to California Residents” below for more information.
Additional Rights for Individuals in the European Economic Area, the United Kingdom, Switzerland and Brazil. You may have additional privacy rights if you use or access our Service from the European Economic Area, the United Kingdom, Switzerland and Brazil, see Section 11 “Notice to Individuals in the European Economic Area, the United Kingdom, Switzerland and Brazil” below for more information.
8. Third-Party Sites
When you leave www.finalsite.com you will go to sites outside of our control. These external sites may send their own cookies to users, collect data, or solicit personal information. The privacy policies and procedures described here for Finalsite do not apply to any external links. We encourage you to read the privacy policies of any site you link to from ours, especially if you share any personal information. Be informed. You are the person best qualified to protect your own privacy.
9. How We Protect Children’s Information
Our Services are not directed to, and we do not knowingly collect personal information directly from, children under the age of 16 (or other age as required by local law). If you are under 16, please do not attempt to fill out our forms or send any personal information about yourself to us. If we become aware that a child under 16 has provided us with personal information contrary to our Clients’ processing instructions, we will take steps to delete such information from our filesystems, unless we have a legal obligation to keep it.
10. Notice to California Residents
This section applies only to California residents. The purpose of this section is to inform California residents (“consumers” or “you”), at or before the time of collection of personal information, about our data collection practices and your privacy-related rights under California law, including the California Consumer Privacy Act of 2018, as amended (“CCPA”) and the California Privacy Rights Act (“CPRA”). Your “right to know” about personal information collected, used, and disclosed by Finalsite includes what categories of personal information we collect from you and the purpose for its collection; how we use those categories of personal information; and how we share the personal information you entrust to us. For purposes of this section 10, the term “personal information”, as defined under the CCPA, is used.
Categories of Personal Information Collected
The chart below describes the categories of personal information we have collected in the preceding 12 months, the sources and purpose of such collection, and the parties to whom the information was shared for business purpose.
|Personal Information Category (corresponds to categories in CCPA §1798.140(o)(1))||Sources of Personal Information
(see Section 1 above for more information)
|Purpose of Information Collection||Disclosure of Personal Information|
|(A) Identifiers||Information you voluntarily provide to us; Information we automatically collect, as outlined in Section 1 above.||See Section 3, subsection 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, and 11.||See Section 4, subsection 1, 2, 3, 4, 5 and 6.|
(B) Personal information under California Civil Code section 1798.80
|Information you voluntarily provide to us; Information we automatically collect as outlined in Section 1 above.||See Section 3, subsection 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, and 11.||See Section 4, subsection 1, 2, 3, 4, 5 and 6.|
(C) Protected Classifications, including gender and age
|Information you voluntarily provide to us; Information we automatically collect, as outlined in Section 1 above.||See Section 3, subsection 2 and 3.||See Section 4, subsection 1, 2, 3 and 4.|
(D) Commercial information, such as records of service purchased
|Information you voluntarily provide to us; Information we automatically collect, as outlined in Section 1 above.||See Section 3, subsection 1, 2, 4, 5, 6, 7, 8, 9, and 10.||See Section 4, subsection 1, 2, 3 and 4.|
(F) Internet activity information, such as browsing history
|Information we automatically as outlined in Section 1 above.||See Section 3, subsection 1, 4, 5, 6, 7, 8, 9, and 10.||See Section 4, subsection 1, 2, 3, 4, and 6.|
(G) Geolocation data
|Information we automatically as outlined in Section 1 above.||See Section 3, subsection 1, 6, and 9.||See Section 4, subsection 3 and 6.|
(J) Inferences about preferences, characteristics, etc.
|Information you provide to us, Information we automatically collect, as outlined in Section 1 above.||See Section 3, subsection 7, 8, and 9.||See Section 4, subsection 2 and 3.|
Your Rights Under California Law
Access to Specific Information and Data Portability Rights. Subject to certain exceptions, if you are a California resident you have the right to request a copy of the personal information that we collected about you during the 12 months before your request. Once we receive your request and verify your identity, we will disclose to you:
- The categories of personal information we have collected about you;
- The categories of sources for the personal information we have collected about you;
- Our business or commercial purpose for the information collection;
- The categories of third parties with whom we share that personal information;
- The specific pieces of personal information we collected about you;
- The categories of your personal information that we sold, and
- The categories of third parties to whom your personal information was sold.
Deletion Requests. You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions.
Non-Discrimination. We recognize and respect that you have the right to not receive discriminatory treatment by the business for exercising any of your CCPA rights.
Shine the Light Law. If you are a California resident, you may opt out of us disclosing your personal information to third parties for direct marketing purposes. In your request, please specify that you want a “California Shine the Light Notice.”
Exercising Access, Data Portability and Deletion Rights. To exercise the access, data portability and deletion rights described above as a California resident, please submit a request to us by contacting us as described in the “Contact Us” section below. Before fulfilling your request, as required by law, we may ask you to verify personal information we already have on file to confirm your identity. If we cannot verify your identity based on the information we have on file, we may request additional information from you, which we will only use to verify your identity, and for security or fraud-prevention purposes.
Use of an Authorized Agent to Submit a Request. Only you or a person you formally authorize to act on your behalf, may make a verifiable consumer request related to your personal information as a California consumer. If you use an authorized agent to submit such a request, we will require written proof that the authorized agent has been authorized to act on your behalf or a copy of the power-of-attorney document granting that right.
12. Notice to Individuals in the European Economic Area, the United Kingdom, Switzerland and Brazil
This section only applies to individuals using or accessing our Service while located in the European Economic Area, the United Kingdom, Switzerland (collectively, the “European Countries”), or Brazil at the time of data collection. Pursuant to the European Union’s General Data Protection Regulation, the UK General Data Protection Regulation (collectively, the “GDPR”), and Brazil’s General Personal Data Protection Act (“LGPD”), for the sake of clarity, references to personal information in this Policy concerns personal data in the sense of the GDPR.
We may ask you to identify which country you are located in when you use or access some of the Services, or we may rely on your IP address to identify which country you are located in. If any terms in this section conflict with other terms contained in this Policy, the terms in this section shall apply to individuals in a European Country or Brazil.
Legal Bases for Processing Your Personal Information
|Section & Purpose of Processing||Legal Bases for Processing|
|Section 3(2) To Maintain Legal and Regulatory Compliance.
Section 3(4) To Detect and Prevent Fraud and Security Risks.
Section 4(1) As required by Law
|Based on our legal obligations. Article 6(1) lit.(c) GDPR; Article 7(II) LGPD.|
|Section 3(1) To Provide Finalsite’s Services.
Section 3(3) To Enforce Compliance with Our Terms, Agreements and Policies.
Section 3(5) To Respond to Requests.
Section 3(6) To Provide Services Communications.
Section 4(2) Within Our Corporate Organization.
Section 4(3) With Our Service Providers
Section 4(5) With Our Business Partners
|Based on our contract with you or to take steps at your request prior to entering a contract. Article 6(1) lit.(b) GDPR; Article 7(V) LGPD.|
Section 3(8) To Research and Develop Our Services.
|Based on our legitimate interest to operate our business and not overridden by your data protection interests or fundamental rights and freedom. Article 6(1) lit.(f) GDPR; ; Article 7(IX) LGPD.|
|Section 3(7) To Provide Marketing Communication.
Section 3(11) With Your Consent.
Section 4(7) With Your Consent
Based on your consent. Article 6(1) lit.(a) GDPR; Article 7(I) LGPD.
Individual Rights. We provide you with the rights described below when you use our Services. We may limit your individual rights requests: (a) where denial of access is required or authorized by law; (b) when granting access would have a negative impact on other’s privacy; (c) to protect our rights and properties; or (d) where the request is frivolous or unrealistic. If you would like to exercise your rights, please submit your request via our web form located here or contact us at firstname.lastname@example.org.
- Right to access. You may have the right to obtain a copy of your personal information that we hold about you, as well as other supplementary information, such as the purposes of processing, the categories of personal information that we process, the entities to whom we disclose your personal information, etc..
- Right to rectification. You may have the right to request us to correct any of your personal information in our files.
- Right to erasure. Under certain circumstances, you may have the right to request erasure of your personal information that we hold about you. This right is not absolute, and we may refuse your right to erasure if there are compelling legitimate grounds for keeping your information.
- Right to restriction. You have the right to request that we restrict our processing of your personal information in certain circumstances. For instance, this right may be available if you contest the accuracy of the personal information or you objected to our processing.
- Right to object to processing. You may have the right to object to our processing of your personal information at any time and as permitted by applicable law if we process your personal information on the legal bases of: consent, or legitimate interests. However, we may continue to process your personal information if it is necessary for the defense of legal claims, or for any other exceptions permitted by applicable law.
- Right to portability. Under circumstances, you may have the right to receive personal information we hold about you in a structured, commonly used, and machine-readable format so that you can provide that personal information to another controller.
- Right to lodge a complaint. Without prejudice to any other administrative or judicial remedy, you may have the right to lodge a complaint with a supervisory authority in a specific region according to applicable law.
- Automated Decision-Making. We do not make any decisions based on algorithms or other automated processing that significantly affect you.
12. International Transfers
Finalsite’s business operates on a global scale. When you access or submit information to us, your personal information may be transferred to, processed, maintained, and used on computers, servers and systems located where the data protection laws may not be as protective as those in your jurisdiction. If you are located outside the United States and choose to provide information to us, please note that we may transfer your personal information to the United States for further processing. We will take appropriate contractual or other steps to protect the relevant personal information in accordance with applicable laws.
We rely primarily on the European Commission’s Standard Contractual Clauses to facilitate the international and onward transfer of personal information collected in the European Economic Area (“EEA”), the United Kingdom and Switzerland (collectively “European Personal Information”), to the extent the recipients of the European Personal Information are located in a country that the European Countries consider to not provide an adequate level of data protection. We may also rely on an adequacy decision of the relevant regulatory body confirming an adequate level of data protection in the jurisdiction of the party receiving the information, or derogations in specific situations.
Finalsite is responsible for the processing of personal information it receives and subsequently transfers to a third party acting as an agent on its behalf. Before we share your information with any third party, we will enter into a written agreement that the third party provides at least the same level of protection for the personal information as required under applicable data protection laws.
We recognize that the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework are no longer recognized as a legal means to transfer personal information from the European Union, the United Kingdom and Switzerland to the U.S., however we retain its certification to demonstrate our adherence to its principles and as additional safeguards.
Active Internet Technologies, LLC dba Finalsite and certain of its affiliates participate in and have certified compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework. We are committed to subjecting all personal information received from European Union (EU) member countries, the United Kingdom and Switzerland, respectively, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List.
We are responsible for the processing of personal information it receives, under each Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. We comply with the Privacy Shield Principles for all onward transfers of personal information from the EU, the United Kingdom and Switzerland, including the onward transfer liability provisions.
With respect to personal information received or transferred pursuant to the Privacy Shield Frameworks, Awe are subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations we may be required to disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider, (free of charge) at https://feedback-form.truste.com/watchdog/request. Under certain conditions, more fully described on the Privacy Shield website, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
13. Contact Us