1. Privacy Overview
2. Visitors and Users Outside of the United States
For purposes of the European Union’s General Data Protection Regulation (“GDPR”), we act both as a “Controller” where we have direct control of your Personal Data and as a “Processor” where we may process your Personal Data on behalf of one of our customers (“Customers”) who may in turn provide our Services to you. We act as a Controller for any of your Personal Data that is stored in your own account. However, if you are using the Services either (i) as an employee, contractor or other engagement of a Customer; or (ii) a person engaging with one of our Customers, then your interactions with respect to that Customer (includingany associated Personal Data) are controlled by that Customer and we act as a Processor on their behalf.
If you reside in the EU, you may have legal rights with respect to your Personal Data, including those set forth under the GDPR and the Digital Services Act (“DSA”).
3. Children’s Online Privacy Protection Act (COPPA)
4. Collection of Information
We collect several types of information from and about Customers, visitors to our Website and users of our Services, including information that can be used to identify an individual (“Personal Data“). We may collect this information: (i) from you, either directly or indirectly, when you provided it to us; and (ii) automatically as you navigate through our Website and Services, which information collected automatically may include usagedetails, IP addresses, and information collected through cookies, web beacons, and other tracking technologies.
The information we collect may include: (i) information that you provide by filling in forms on or through our Services, including without limitation, information provided at the time of registering to use our Website, subscribing to our Services, or requesting further services; (ii) records and copies of your correspondence (including email addresses), if you contact us; (iii) your responses to questionnaires or surveys that we might ask you to complete for research purposes; (iv) financial information, if any, provided on or through the Services; (v) your search queries through the Services; (vi) information we may ask you for when you report a problem with our Services; and (vii) optional information we may request that you provide, including without limitation, company annual revenues, number of employees, or industry.
You also may provide information: (i) to be published or displayed (hereinafter, “Posted”) on public areas of the Services, including without limitation, bulletin board, blogs, or chatrooms; (ii) to be transmitted to other users of the Services or third parties; or (iii) relating to your customers, or that you authorize your customer to enter such information in the Services, to facilitate use of the Services (collectively, “User Contributions”). You maintain a wide array of options for the types of information to be entered concerning your customer base (i.e. names, email addresses, telephone numbers, account numbers, etc.). DaySmart does not monitor the types of information of your User Contributions. Your User Contributions are posted on our Services, transmitted to others, and stored at your own risk. Additionally, we cannot control the actions of other users or visitors of the Services with whom you may choose to share your User Contributions and such third parties may use your User Contribution to send you unsolicited messages. Please be aware that no security measures are perfect or impenetrable. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons. USERS ASSUME ALL RESPONSIBILITY FOR ANY LOSS OF PRIVACY OR OTHER HARM RESULTING FROM THEIR VOLUNTARY DISCLOSURE OF PERSONAL DATA OF THEMSELVES OR THAT OF OTHERS.
You may elect to use our referral program to inform friends or others about our Website or Services. When using the referral program, we may request the third party’s name, email address, phone number, mailing address, or other contact information. DaySmart will automatically send the third party a one-time email or make other contact inviting such third-party to visit our Website. DaySmart does not store this information. By electing to use the referral program you represent that you have obtained the consent of the third party.
Like most service providers and website operators, DaySmart may gather from visitors and users of the Services information of the sort that Web browsers, depending on their settings, may make available through automatic data collection technologies. That information may include your Internet Protocol (IP) address, communication data, traffic data, operating system, and browser type, while navigating and immediately after leaving the Service. Although such information is not Personal Data, it may be possible for DaySmart to determine from an IP address your Internet service provider and the geographic location of your point of connectivity as well as other statistical usage data.
We also may use these technologies to collect information about your online activities over time. The information we collect automatically may include Personal Data. DaySmart analyzes information gathered from visitors and users of the Services to improve our Services and to deliver a better and more personalized service, including by enabling us to: (i) estimate our audience size and usage patterns; (ii) store information about your preferences, allowing us to customize our Services to your individual interest; (iii) speed up your searches; and (iv) recognize you when you return to our Website. DaySmart may release information gathered from the Services in the aggregate, such as by publishing a report on trends in the usage of the Service.
The technologies we use for this automatic data collection may include:
- Flash Cookies. Certain features of our Services may use local stored objects (or Flash cookies) to collect and store information about your preferences and navigation to, from, and on our Website. Flash cookies are not managed by the same browser settings as are used for browser cookies.
- Web Beacons. Pages of the Services and our e-mails may contain web beacons. A
“web beacon” (as referred to as clear gifs, pixel tags, and single-pixel gifs) is an object that is embedded in a web page or email that is usually invisible to the user and allows website operators to check whether a user has viewed a particular web page or an email. DaySmart may use web beacons in conjunction with the Services and in emails to count users and visitors who have visited particular pages and viewed emails. Web beacons are not used to access Personal Data and will be used to compile aggregated statistics about Services usage. You may not decline web beacons. However, they can be rendered ineffective by declining all cookies or modifying your browser setting to notify you each time a cookie is tendered, permitting you to accept or decline cookies on an individual basis.
- Google Analytics. We use Google Analytics to help us understand how our people use our Service. You can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics by using the Google Analytics Opt-out Browser Add-on.
- Mobile Device. If you use a mobile device to access the Services, we may collect device information (such as your mobile device ID, model and manufacturer), operating system, version information and IP address.
- Geo-Location Information. Unless we have received your prior consent, we do not access or track any location-based information from your mobile device at any time while using our Service, except that it may be possible for DaySmart to determine from an IP address the geographic location of your point of connectivity, in which case we may gather and use such general location data.
- No mobile information will be shared with third parties/affiliates for marketing/promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
We do not collect any “Special Categories” of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). Nor do we collect any information about criminal convictions and offences.
Third-Party Hosted Pages and Cookies
Do Not Track Notice
We do not track our users over time and across third party websites to provide targeted advertising and therefore we do not respond to Do Not Track (DNT) signals. However, some third-party sites do keep track of your browsing activities when they serve you content, which enables them to tailor what they present to you. If you are visiting such sites, please set the DNT signal on your browser so that third parties know you do not want to be tracked. Click the following links for information on how to set the DNT signal on Google Chrome, Mozilla Firefox, Safari, and Microsoft Edge.
5. Use of Information Collected
We use information that we collect about you or that you provide to us, including any Personal Data, to: (i) present our Services and their contents to you and to other users; (ii) provide you with information, products, or services; (iii) fulfill any other purpose for which you provide it; (iv) provide you with notices about your account and the Services; (v) carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection; (vi) notify you about changes to our Services, or any other products or service we offer or provide through it; (vii) allow you to participate in interactive features of the Services; (viii) use in any other way we may describe when you provide the information; and (ix) use for any other purpose with your consent.
We may also use your information to contact you about goods and services that may be of interest to you. If you do not want us to use your information in this way, please check the relevant box located on the form on which we collect your data adjust your user preferences in your account profile. For more information, see Choices About How We Use and Disclose Your Information.
6. Disclosure of Information Collected
We may disclose aggregated information about our visitors and users, and information that does not identify any individual, without restriction.
DaySmart does not share, sell, rent, or trade any Personal Data with third parties for their promotional purposes.
7. Choices About How We Use and Disclose Your Information
We strive to provide you with choices regarding the personal information you provide to us. We have created mechanisms to provide you with the following control over your information:
We do not control third parties’ collection or use of your information to serve interest-based advertising. However these third parties may provide you with ways to choose not to have your information collected or used in this way. You can opt out of receiving targeted ads from members of the Network Advertising Initiative (“NAI“) on the NAI’s website.
Residents of certain states, such as California, Nevada, Colorado, Connecticut, Virginia, and Utah may have additional personal information rights and choices. Please see Your State Privacy Rights for more information.
8. Accessing and Correcting Information
We may be unable to delete your Personal Data except by also deleting your account. We may not accommodate a request to change information if we believe the change would violate any law or legal requirement or cause the information to be incorrect.
Residents of certain states, such as California, Nevada, Colorado, Connecticut, Virginia, and Utah may have additional personal information rights and choices. Please see Your State Privacy Rights for more information.
GDPR Access, Accuracy and Deletion Rights
DaySmart acknowledges the rights of certain individuals located in European Economic Area Countries (“EEAS”) to access their Personal Data and other Personal Data to review, change, edit, and/or delete it. Where DaySmart is acting as a “Controller” of Personal Data, we will provide you access to your Personal Data as required by GDPR and in accordance with applicable law. If we act as “Processor” with respect to your Personal Data, we will communicate your request to the appropriate data controller.
9. Your State Privacy Rights
State consumer privacy laws may provide their residents with additional rights regarding our use of their personal information.
California Privacy Notice
This California Privacy Notice applies solely to all visitors, users, and others who reside in the State of California. We adopt this notice to comply with the California Consumer Privacy Act of 2018 (“CCPA”) and any terms defined in the CCPA have the same meaning when used in this Policy.
Our Website collects information that identifies, relates to, describes, references, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer, household, or device (“CCPA Information”). CCPA Information does not include (i) Publicly available information from government records, or (ii) deidentified or aggregated consumer information.
In particular, our Website has collected the following categories of CCPA Information from consumers within the last twelve (12) months:
|A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.
|B. Personal information categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e)).
|A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information.Some personal information included in this category may overlap with other categories.
|C. Protected classification characteristics under California or federal law.
|Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).
|D. Commercial information.
|Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.
|E. Biometric information.
|Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical patterns, and sleep, health, or exercise data.
|F. Internet or other similar network activity.
|Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.
|G. Geolocation data.
|Physical location or movements.
|H. Sensory data.
|Audio, electronic, visual, thermal, olfactory, or similar information.
|I. Professional or employment-related information.
|Current or past job history or performance evaluations.
|J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).
|Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.
|K. Inferences drawn from other personal information.
|Profile reflecting a person’s preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes.
Use of CCPA Information
Sharing CCPA Information
Your Rights and Choices
The CCPA provides consumers (California residents) with specific rights regarding their personal information. This section describes your CCPA rights and explains how to exercise those rights.
- Right to Know and Data Portability. You have the right to request that we disclose certain information to you about our collection and use of your CCPA Information over the preceding 12 months. Once we review your request and confirm your identity, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- [The categories of third parties with whom we share that personal information.]
- [If we sold or disclosed your personal information for a business purpose, two separate lists disclosing:
- sales, identifying the personal information categories that each category of recipient purchased; and
- disclosures for a business purpose, identifying the personal information categories that each category of recipient obtained.]
- The specific pieces of personal information we collected about you (also called a data portability request).
- Right to Delete. You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive your request and confirm your identity, we will review your request to see if an exception allowing us to retain the information applies. We may deny your deletion request if retaining the information is necessary for us or our service provider(s) to:
- Complete the transaction for which we collected the personal information, provide a good or service that you requested, take actions reasonably anticipated within the context of our ongoing business relationship with you, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, or otherwise perform our contract with you.
- Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for such activities.
- Debug products to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise their free speech rights, or exercise another right provided for by law.
- Comply with the California Electronic Communications Privacy Act (Cal. Penal Code § 1546 et. seq.).
- Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the information’s deletion may likely render impossible or seriously impair the research’s achievement, if you previously provided informed consent.
- Enable solely internal uses that are reasonably aligned with consumer expectations based on your relationship with us.
- Comply with a legal obligation.
- Make other internal and lawful uses of that information that are compatible with the context in which you provided it.
We will delete or permanently and irrevocably anonymize personal information not subject to one of the above exceptions from our records and will direct our service providers to take similar action. To exercise any of your rights relating to access, portability, or deletion of CCPA Information, Please submit a verifiable request by using our privacy portal OR writing us at: [email protected]
Response timing and Format. Upon receiving a consumer request for access, portability, or deletion of CCPA Information, we will We will confirm receipt of your request within ten (10) business days. If you do not receive confirmation within the 10-day timeframe, please contact us [via our privacy portal] [OR] [by writing us at: [[email protected]]
We endeavor to substantively respond to a verifiable consumer request within forty-five (45) days of its receipt. If we require more time (up to another 45 days), we will inform you of the reason and extension period in writing.
If you have an account with us, we will deliver our written response to that account. If you do not have an account with us, we will deliver our written response by mail or electronically, at your option.
Any disclosures we provide will only cover the 12-month period preceding our receipt of your request. The response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
3. Notice of Right to Opt-Out. Even though we do not sell your CCPA Information, like most companies, we partner with third parties, such as Google, to manage our marketing of DaySmart on other platforms, where such advertising is based on your past visits to our Products. These third party partners may use technologies, such as cookies, to gather information about your activities on the Website to deliver such advertising to you when you visit their platforms. For instance, if you visit www.daysmart.com, a cookie may be attached to your browser in the form of a Google pixel that allows DaySmart to deliver advertising to you on Google-based platforms.
[We do NOT sell or rent your personal information to any third parties for their own advertising or marketing purposes.]
4. Non-Discrimination. We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
- However, we may offer you certain financial incentives permitted by the CCPA that can result in different prices, rates, or quality levels. Any CCPA-permitted financial incentive we offer will reasonably relate to your personal information’s value and contain written terms that describe the program’s material aspects. Participation in a financial incentive program requires your prior opt-in consent, which you may revoke at any time.
5. Other California Privacy Rights. California’s “Shine the Light” law (Civil Code Section § 1798.83) permits users of our Website that are California residents to request certain information regarding our disclosure of personal information to third parties for their direct marketing purposes. To make such a request, please [use our privacy portal] [OR] [write us at: [[email protected]]].
Other States’ Privacy Notice
Colorado, Connecticut, Virginia, and Utah each provide their state residents with rights to: Confirm whether we process their personal information; Access and delete certain personal information; Data portability; Opt-out of personal data processing for targeted advertising and sales.
Colorado, Connecticut, and Virginia also provide their state residents with rights: to Correct inaccuracies in their personal information, taking into account the information’s nature processing purpose; and to Opt-out of profiling in furtherance of decisions that produce legal or similarly significant effects. To exercise any of these rights please use our privacy portal OR write us at: [email protected].
Nevada provides its residents with a limited right to opt-out of certain personal information sales. Residents who wish to exercise this sale opt-out rights may use our privacy portal OR write us at: [email protected]. However, please know we do not currently sell data triggering that statute’s opt-out requirements.
Privacy Appeal Rights
10. Data Security and Retention
DaySmart uses commercially reasonable security measures to protect your information from unauthorized access, maintain data accuracy, and help ensure the appropriate use of information. When the Services are accessed using the Internet, DaySmart utilizes Transport Layer Security (TLS) technology to protect the information using both server authentication and data encryption.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password and/or username for access to certain parts of our Service, you are responsible for keeping such information confidential. We ask you not to share your password or username with anyone. We ask you to select unique and secure passwords when setting up profiles in our Service.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we do our best to protect your information, we cannot guarantee the security of your information transmitted to our Service. Any transmission of Personal Data is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Service. DaySmart may use online hosting services (such as, for example, Amazon Web Services) in connection with providing the Services (including without limitation, for the purposes of processing and storing Personal Data).
We will only retain your Personal Data for as long as necessary to fulfill the purposes we collected it for, including the purposes of satisfying any legal, accounting, or reporting requirements. To determine the appropriate retention period for Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of your Personal Data, the purposes for which we process your Personal Data, and whether we can achieve those purposes through other means, and the applicable legal requirements.
11. Telephone Monitoring
As part of DaySmart customer service assurance practice, telephone conversations over phones may be monitored or recorded as a part of normal business operations. Monitored or recorded calls will be used for quality assurance and training purposes.
13. Contacting Us
14. Dispute Resolution
United States Dispute Resolution
MANDATORY BINDING ARBITRATION; Governing Law and Jurisdiction
International Dispute Resolution
If you believe that DaySmart is not processing your Personal Data in accordance with the requirements set out herein or applicable EEA data protection laws, you can at any time lodge a complaint with the data protection authority of the EEA country in which you live. We would, however, appreciate the chance to deal with your concerns before you approach the data protection authority so please contact us in the first instance.
DaySmart commits to cooperate with EU data protection authorities (DPAs) and comply with the advice given by such authorities with regard to human resources data transferred from the EU in the context of the employment relationship.