Blue Endurance obtains Personal Data about you from various sources to provide our Services and to manage our Sites. “You” may be a visitor to one of our websites or a user of one or more of our Services (“User”).
2. Personal Data We Collect
a. Personal Data that we collect about you.
Personal Data is any information that relates to an identified or identifiable individual. The Personal Data that you provide directly to us through our Sites and Services will be apparent from the context in which you provide the data. In particular, when you register for an account we collect your full name, email address, and account log-in credentials.
When you respond to emails or surveys we collect your email address, name and any other information you choose to include in the body of your email or responses. If you contact us by phone, we may collect the phone number you use to call us. If you contact us by phone as a Blue Endurance User, we may collect additional information in order to verify your identity. This may include your contact details, such as name, postal address, telephone number, and email address.
You may also choose to submit information to us via other methods, including: (i) in response to marketing or other communications, (ii) through social media or online forums, (iii) through participation in an offer, program or promotion, (iv) in connection with an actual or potential business relationship with us, or (v) by giving us your business card or contact details at trade shows or other events.
b. Information that we collect automatically on our Sites.
Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language, plug-ins, add-ons and the language version of the Sites you are visiting;
Usage data, such as time spent on the Sites, pages visited, links clicked, language preferences, and the pages that led or referred you to our Sites.
3. How We Use Personal Data
a. Our products and services.
We rely upon a number of legal grounds to ensure that our use of your Personal Data is compliant with applicable law. We use Personal Data to facilitate the business relationships we have with our Users, to comply with our legal obligations, and to pursue our legitimate business interests.
b. Marketing and events-related communications.
We may send you email marketing communications about Blue Endurance products and services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with the consent requirements that are imposed by applicable law. For example, when we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and, with your permission, include you on our marketing information campaigns.
When you visit our Sites, we (and our service providers) may use Personal Data collected from you and your device to target advertisements for Blue Endurance Services to you on our Sites and other sites you visit (“interest-based advertising”), where allowed by applicable law. We do not use, share, rent or sell the Personal Data of our Users’ Customers for interest-based advertising. We do not sell or rent the Personal Data of our Users or our Site visitors.
4. How We Disclose Personal Data.
Blue Endurance does not sell or rent Personal Data to marketers or unaffiliated third parties. We share your Personal Data with trusted entities, as outlined below.
We share Personal Data with other Blue Endurance entities in order to provide our Services and for internal administration purposes.
We share Personal Data with a limited number of our service providers. We have service providers that provide services on our behalf, such as identity verification services, website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, and auditing services. These service providers may need to access Personal Data to perform their services. We authorize such service providers to use or disclose the Personal Data only as necessary to perform services on our behalf or comply with legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf. Our service providers are predominantly located in the European Union and the United States of America.
Our Users and third parties authorized by our Users
Compliance and harm prevention
We share Personal Data as we believe necessary: (i) to comply with applicable law, or payment method rules; (ii) to enforce our contractual rights; (iii) to protect the rights, privacy, safety and property of Blue Endurance, you or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.
5. Your Rights and Choices.
You have choices regarding our use and disclosure of your Personal Data:
Opting out of receiving electronic communications from us
If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.
How you can see or change your account Personal Data
If You would like to review, correct, or update Personal Data that You have previously disclosed to us, You may do so by signing in to your Blue Endurance account or by contacting us.
Your data protection rights
Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Data we control about you:
— The right to request confirmation of whether Blue Endurance processes Personal Data relating to you, and if so, to request a copy of that Personal Data;
— The right to request that Blue Endurance rectifies or updates your Personal Data that is inaccurate, incomplete or outdated;
— The right to request that Blue Endurance erase your Personal Data in certain circumstances provided by law;
— The right to request that Blue Endurance restrict the use of your Personal Data in certain circumstances, such as while Blue Endurance considers another request that you have submitted (including a request that Blue Endurance make an update to your Personal Data); and
— The right to request that we export to another company, where technically feasible, your Personal Data that we hold in order to provide Services to you.
Where the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time. You may also have the right to object to the processing of your Personal Data on grounds relating to your particular situation.
Process for exercising data protection rights
In order to exercise your data protection rights, you may contact Blue Endurance as described in the Contact Us section below. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may consult with the data protection authority in your country.
For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.
6. Security and Retention.
We make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data within our organization against unauthorized access, destruction, loss, alteration or misuse. Your Personal Data is only accessible to a limited number of personnel who need access to the information to perform their duties. Unfortunately, no data transmission or storage system can be guaranteed to be completely secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.
We retain your Personal Data as long as we are providing the Services to you. We retain Personal Data after we cease providing Services directly or indirectly to you, even if you close your Blue Endurance account, to the extent necessary to comply with our legal and regulatory obligations, and for the purpose of fraud monitoring, detection and prevention. We also retain Personal Data to comply with our tax, accounting, and financial reporting obligations. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.
7. International Data Transfers.
8. Use by Minors.
The Services are not directed to individuals under the age of thirteen (13), and we request that they not provide Personal Data through the Services.
10. Links To Other Websites.
The Services may provide the ability to connect to other websites. These websites may operate independently from us and may have their own privacy notices or policies, which we strongly suggest you review. If any linked website is not owned or controlled by us, we are not responsible for its content, any use of the website or the privacy practices of the operator of the website.
11. Jurisdiction-specific Provisions.
a. European Economic Area
If you are a resident of the EEA and believe we process your information in scope of the General Data Protection Regulation (GDPR), you may direct your questions or complaints to the Office of the Data Protection Commissioner. If you are a resident of the UK and the UK is no longer a Member State of the EU, you may direct your questions or concerns to the UK Information Commissioner’s Office.
b. California (United States)
This section provides additional details about the personal information we collect about California consumers as well as the rights of California consumers under the California Consumer Privacy Act (CCPA).
How We Collect, Use, and Disclose your Personal Information.
The Personal Data We Collect section describes the personal information we may have collected over the last 12 months, including the categories of sources of that information. We collect this information for the purposes described in the How We Use Personal Data section. We share this information as described in the How We Disclose Personal Data section.
Your CCPA Rights and Choices.
As a California consumer and subject to certain limitations under the CCPA, you have choices regarding our use and disclosure of your personal information:
Exercising the right to know
You may request, up to twice in a 12-month period, the following information about the personal information we have collected about you during the past 12 months:
— The categories and specific pieces of personal information we have collected about you;
— The categories of sources from which we collected the personal information;
— The business or commercial purpose for which we collected the personal information;
— The categories of third parties with whom we shared the personal information; and
— The categories of personal information about you that we disclosed for a business purpose, and the categories of third parties to whom we disclosed that information for a business purpose.
Exercising the right to delete
You may request that we delete the personal information we have collected from you, subject to certain limitations under applicable law.
Exercising the right to opt-out from a sale
You may request to opt out of any “sale” of your personal information that may take place. As described in Advertising, we do not use, share, rent or sell the Personal Data of our Users’ Customers for interest-based advertising. We do not sell or rent the Personal Data of our Users, their Customers or our Site visitors.
The CCPA provides that you may not be discriminated against for exercising these rights.
To submit a request to exercise any of the rights described above, you may contact Blue Endurance at firstname.lastname@example.org. We may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. Authentication based on a government-issued and valid identification document may be required.
12. Contact Us
Blue Endurance LLC
PO Box 380822
Cambridge, MA 02238, USA