Effective October 1, 2018
Last Updated September 24, 2018
Definitions of Data Controller and Processor
- A Controller is an agency, entity, or legal person who determines the purposes and means of processing Personal Data.
- A Processor is an agency, entity, or legal person with responsibility for processing Personal Data on behalf of a Controller.
Skytap as a Data Processor
Skytap primarily provides its customers with hosting infrastructure, has limited knowledge of customer data within that infrastructure, and only processes hosted data in accordance with the customer’s instructions. Skytap is a Processor of hosted data. The customer is the Controller for that hosted data.
Skytap collects information under the direction of its customers and may have no direct relationship with the individuals whose Personal Data it processes. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct their query to the Skytap customer (the Data Controller).
Similarly, Skytap has no direct control over the data collected by its customers. Skytap customers choose the geographical regions for the storage of data for which they are the Controller, are directly responsible for the security, configuration, and administration of their Skytap environments, and are responsible for adhering to legal and regulatory requirements for the data which they collect and process as a Controller.
Skytap as a Data Controller
In some circumstances, such as during the account registration process for customer use of Skytap Services, Skytap collects and maintains Personal Data. This data is collected and maintained solely for the offer and maintenance of Skytap Services for customer use, and for the relevant communications and uses detailed within this policy. For these purposes, Skytap is the Controller.
The collection and processing of your Personal Data for direct use and administration of our Services is based on contractual obligation, necessary to provide you with access and use of the Services.
Personal Data We Collect
Definition of Personal Data
“Personal Data” is any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable person is one who can be identified by referencing an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Information you give us
Skytap requires some of your Personal Data to effectively operate, while providing you the best experiences with our Services. Some of this data comes directly from you when you perform transactions with Skytap, such as place an order, create a Skytap account, administer your organization’s dashboard access, or register for a newsletter. This data may include name, username, title, address, organization or employer, phone number, and/or email address.
Information we collect automatically
As is true of most websites, we also gather certain information automatically when you visit our website, mobile application, or interact with our Services. This information is used to analyze aggregated trends and to administer our Services, and may include Internet protocol (IP) addresses, the type of device you use, operating system and version, device identifier, where the application was downloaded from, usage information, events that occur within the application, performance data, browser type, Internet service provider (ISP), referring/exit pages, the files viewed on our site (e.g., HTML pages, graphics, etc.), date/time stamp, and/or clickstream data. Please see the Cookies and Similar Technology section below for more details.
Information we receive from third parties
We may receive information about you from other sources, including publicly available databases or from third parties. This data helps us to update, expand, and analyze our records, identify new customers, and identify Services that may be of interest to you. This may include purchased marketing data about our customers from third parties, that is combined with information we already have about you, to create more tailored advertising and Services.
When you download and use our Services, we may automatically collect information on the type of device you use, operating system version and the device identifier (or “UDID”).
Within our mobile application we may send you push notifications from time-to-time in order to update the services, or to notify you about any events or promotions that we may be running. If you no longer wish to receive these types of communications, you may turn them off at the device level.
We use mobile analytics software to allow us to better understand the functionality of our mobile software on your phone. This software may record information such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and where the application was downloaded from.
How We Use Personal Data
This section describes how Skytap uses the Personal Data that we collect to operate our business and to provide you our Services, including improvements to those Services and in the personalization of your experiences. We may also use the data to communicate with you, providing account information, security updates and Service information. We may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the service agreements with our customers. Additionally, data is used to market our Services, to comply with applicable laws and legal processes, to enforce our terms and conditions, and to allow us to pursue available remedies or limit any damages that we may sustain.
To provide a requested service or carry out a contract with you
We use data collected from you in the following ways:
- Customer Support: to diagnose and repair technical issues and provide other customer care and support services.
- Account Notifications: to communicate Service and account notifications to you. For example, we may contact you by phone, email, or other means to inform you of account status, usage, and billing details, and to notify you when security updates are available.
- Security, Safety, and Dispute Resolution: to protect the security and safety of our Services and our customers, to detect and prevent fraud, to resolve disputes, and to enforce our agreements.
- Providing the Services: to carry out your transactions with us and to provide our Services to you, such as the account administration, authorization, and audit tools provided within our Services.
Where we have a legitimate interest
We use data collected from you in the following ways:
- Service Personalization: to include personalized features and recommendations that enhance your productivity and user experience enjoyment, and automatically tailor your Service experiences based on the data we have about your activities, interests, and locations. To better understand how to access and control the Personal Data collected for these types of processing, please see the Access and Control section below.
- Business Operations: to develop aggregate analysis and business intelligence that enable us to operate, protect, make informed decisions about, and report on the performance of our business.
- Service Improvement: to continually improve our Services, including adding new features or capabilities. For example, we use error reports to improve security features of our Services, and usage data to determine new features or Services to prioritize.
Where we rely on legitimate interest for processing your information, we carry out a ‘balancing test’ to ensure that our processing is necessary and that your fundamental rights of privacy are not outweighed by our legitimate interests, before we go ahead with such processing. You can find out more about the information in these balancing tests by contacting us using the details below.
Where we have your consent
- We use data we collect to communicate with you in a variety of formats and to tailor those communications to you. Examples include inviting you to participate in surveys, email subscriptions, and promotional communications from Skytap by email, SMS, physical mail, or telephone. For information about managing your contact data, email subscriptions, and promotional communications, please visit the Access and Controls section of this privacy statement.
Automated decision making
Skytap employs automated decision making (also known as “profiling”) in the processing of your data in very limited ways, and only in accordance with the specifications of this Policy and applicable laws. For example, we may auto-assign customer support personnel to respond to your inquiries, based on your organization or employer, and necessary details of that contract, or auto-assign a regional contact to assist you, based on your location. These actions are necessary to provide you with our Services and related support.
Similarly, some automated decision making is used, with your consent, to determine appropriate communications to you, as detailed above.
Reasons We Share Personal Data
This section describes how Skytap may share and disclose Personal Data. Customers determine their own policies and practices for the sharing and disclosure of data, and Skytap does not control how they choose to share or disclose Information.
Skytap may share your Personal Data with your consent, or as necessary to complete a transaction or provide a Service you have requested or authorized. For example:
- If you elect to use connected third-party applications, we may share Personal Data with companies who provide those applications. In those cases, we encourage you to review and understand the terms and conditions and privacy policies of those third parties, over whom we have no control.
- We may disclose generic, aggregated (pseudonymized) demographic information, not linked to any specific Data Subject, regarding Skytap visitors and users to our business partners, trusted affiliates, and suppliers or agents working on our behalf.
- We may use third-party service providers to help us operate or administer the Services. For example, companies we’ve hired to provide customer service support or to assist in protecting and securing our services and systems may need access to Personal Data to complete those functions. In such cases, these companies must abide by our data privacy and security requirements and are not allowed to use Personal Data they receive from us for any other purpose.
- We may disclose Personal Data to a third-party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings).
- As we believe to be necessary or appropriate, we may disclose Personal Data: (a) under applicable laws, including laws outside your country of residence; (b) to comply with a subpoena or other legal process; (c) to respond to requests from public and government authorities, including public and government authorities outside your country of residence; (d) to enforce our terms and conditions; (e) to protect our operations or those of any of our affiliates; (f) to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or others; and (g) to allow us to pursue available remedies or limit the damages that we may sustain.
How We Protect Your Information
Skytap has adopted reasonable security measures to protect Personal Data against loss, theft, unauthorized access, alteration, disclosure, or destruction. These measures include policies, procedures, employee training, physical access control, and technical elements relating to data access controls. In addition, Skytap uses industry standard encryption to facilitate the exchange and transmission of data. Skytap only processes Personal Data in compliance with the purposes for which it has been collected, in accordance with this Policy.
In the event that Personal Data is acquired by an unauthorized person, and applicable law requires notification, we will promptly notify the affected Data Subject. Notice will be consistent with the legitimate needs of law enforcement, and any measures necessary for Skytap or law enforcement to determine the scope of the breach and to ensure or restore the integrity of a system. Skytap may delay notification if we, or a law enforcement agency, determine that the notification will impede a criminal investigation. In such case, notification will not be provided unless and until we or the agency determines that notification will not compromise the investigation.
We only retain your Personal Data for as long as is necessary for us to use your information as described above or to comply with our legal obligations. Please be advised that this means that we may retain some of your information after you cease to use our Services. For instance, we may retain your data as necessary to meet our legal obligations, such as for tax and accounting purposes.
When determining the relevant retention periods, we take the following factors into account:
- our contractual obligations and rights in relation to the information involved;
- legal obligation(s) under applicable law to retain data for a certain period of time;
- our legitimate interest where we have carried out a balancing test;
- statute of limitations under applicable law(s);
- (potential) disputes;
- if you have made a request to have your information deleted; and
- guidelines issued by relevant data protection authorities.
Otherwise, we securely erase your information once this is no longer needed.
Your Rights as a Data Subject
You have a number of rights when it comes to your Personal Data. Further information and advice about your rights can be obtained from the data protection regulator in your country.
1. The right to object to processing
What does this mean?
You have the right to object to certain types of processing, including processing for direct marketing. You can access and manage your preferences for these as detailed in the Access and Controls section of this document.
2. The right to be informed
3. The right of access
You have the right to obtain access to your Personal Data information that Skytap processes, in order to ensure that we’re using your information in accordance with data protection laws. Upon request, we will provide you with information about whether we hold any of your personal information.
4. The right to rectification
You are entitled to have your information corrected if it’s inaccurate or incomplete. You can manage this as detailed in the Access and Controls section of this document.
5. The right to erasure
This is also known as ‘the right to be forgotten’ and enables you to request the deletion or removal of your information where there’s no compelling reason for us to keep using it. This is not a general right to erasure; there are exceptions.
6. The right to restrict processing
You have rights to ‘block’ or suppress further use of your information. When processing is restricted, we can still store your information, but may not use it further. Skytap maintains lists of individuals who have asked for further use of their information to be ‘blocked’ or ‘restricted’ to ensure the request is respected in future.
7. The right to data portability
You have rights to obtain and reuse your Personal Data for your own purposes across different services. If you request a copy of the Personal Data that Skytap maintains on you, we will deliver it in .csv format or similar.
8. The right to lodge a complaint
You have the right to lodge a complaint about the way we handle or process your Personal Data with your national data protection regulator.
9. The right to withdraw consent
If you have given your consent to anything we do with your Personal Data, you have the right to withdraw your consent at any time (although if you do so, it does not mean that anything we have done with your Personal Data with your consent up to that point is unlawful). This includes your right to withdraw consent to us using your Personal Data for marketing purposes. You can review and manage your consent as detailed in the Access and Controls section.
Please contact us using the details below to exercise any of your rights. We usually act on requests and provide information free of charge, but may charge a reasonable fee to cover our administrative costs of providing the information for:
- baseless or excessive/repeated requests, or
- further copies of the same information.
Alternatively, we may be entitled to refuse to act on the request.
Please consider your request responsibly before submitting it. These requests do not apply to mandatory service communications that are part of certain Skytap services, or to surveys or other informational communications that can be managed directly (see details in the Access and Controls section). We’ll respond as soon as we can. Generally, this will be within 30 days from when we receive your request, unless the request will take substantially longer to fulfill.
If you cannot access certain Personal Data collected by Skytap via the Preference Center, directly through the Skytap Services you use, or if you do not have a personal Skytap account, you can always contact Skytap by emailing us at email@example.com.
Access and control to your Personal Data is managed by the Skytap Preference Center. For example, in the Preference Center you may elect to:
- Receive electronic communications from us. Change your mind? Opt-out for those promotional emails.
- Allow the sharing of your Personal Data with our affiliates for their direct marketing purposes. Similarly, you may update your preference to opt-out if you so desire via the Preference Center.
- Strictly Necessary Cookies: These cookies are necessary for the website to function. They are usually only set in response to actions made by you that amount to a request for services, such as logging in or filling in forms. These cookies do not store any Personal Data.
- Performance Cookies: These cookies allow us to count visits and traffic sources, so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. All of the information collected by these cookies is aggregated and therefore pseudonymous. If you do not allow these cookies we will not know when you have visited our site and will not be able to monitor its performance.
- Functionality Cookies: These cookies enable the website to provide enhanced functionality and personalization, such as playback of tutorial videos, and customer support chat functionality. They may be set by us or by third-party providers whose services we have added to our pages. If you do not allow these cookies, then some or all of these services may not function properly.
- Targeting Cookies: These cookies may be set through our site by us or our advertising partners. They may be used to build a profile of your interests and show you content in which you may be interested. Generally, they do not store any Personal Data, but are based on uniquely identifying your browser and internet device. However, we sometimes use these cookies to do individualized tracking down to the name for marketing purposes. If you do not allow these cookies, you will experience less targeted content. If you wish to opt out of interest-based advertising, click here or if located in the European Union click here. Please note that you will continue to receive generic ads.
- Web Beacons: Skytap web pages may contain electronic images known as web beacons (also called single-pixel gifs) that we use to help deliver cookies on our websites, count users who have visited those websites and deliver co-branded Services. We also include web beacons in our promotional email messages or newsletters to determine whether you open and act on them.
- Analytics Services: Skytap Services often contain web beacons or similar technologies from third-party analytics providers, which help us compile pseudonymized aggregated statistics about the effectiveness of our promotional campaigns or other operations. These technologies are strictly prohibited from collecting or accessing information that directly identifies you. If you do not allow these services, we will not be able to monitor the performance of some of our operations.
- Other Similar Technologies: In addition to standard cookies and web beacons, our Services can also use other similar technologies to store and read data files on your computer. This is typically done to maintain your preferences or to improve speed and performance by storing certain files locally. But, like standard cookies, these technologies can also be used to store a unique identifier for your computer, which can then be used to track behavior. If you block these at the browser level, you will experience less targeted content, and may also experience performance issues when visiting our website or using our Services.
International Data Transfers
Skytap may transfer your Personal Data to countries other than the one in which you live. We deploy the following safeguards when transferring Personal Data originating from the European Union or Switzerland to other countries not deemed adequate under applicable data protection law:
European Union Model Clauses
Skytap offers European Union Model Clauses, also known as Standard Contractual Clauses, to meet the adequacy and security requirements for our Customers that operate in the European Union, and other international transfers of Customer Data. A copy of our standard data processing addendum, incorporating Model Clauses, is available upon request by contacting us at firstname.lastname@example.org.
EU-U.S. Privacy Shield
Skytap participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. Skytap is committed to subjecting all Personal Data received from European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List. (https://www.privacyshield.gov/list)
Skytap is responsible for the processing of Personal Data it receives, under the Privacy Shield Framework, and subsequently transfers to third parties acting as an agent on its behalf. Skytap complies with the Privacy Shield Principles for all onward transfers of Personal Data from the EU, including the onward transfer liability provisions.
With respect to Personal Data received or transferred pursuant to the Privacy Shield Framework, Skytap is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Skytap may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Skytap commits to cooperate with EU data protection authorities, and comply with the advice given by such authorities, with regard to human resources data transferred from the EU in the context of the employment relationship.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Under certain conditions, more fully described on the Privacy Shield website https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
Skytap is committed to fulfilling its responsibilities under Canada’s Personal Data Protection and Electronic Documents Act (PIPEDA). For purposes of fulfilling these responsibilities, if applicable, you consent to using Skytaps website and services, and you consent to Skytap’s collection and use of your Personal Data for the purposes described above. If you do not consent, you may not access our website or the Services. Please contact our Data Protection Officer (see below) with any questions, concerns or requests about how Personal Data is collected or used.
Other Important Privacy Information
Notice to End Users
Skytap Services are intended for use by organizations and are administered to you by your organization. Your use of Skytap Services may be subject to your organization’s policies and procedures. If your organization is administering your use of the Skytap Services, please direct your privacy inquiries to your administrator. Skytap is not responsible for the privacy or security practices of our customers, which may differ from those set forth in this privacy statement.
If you use an email address provided by an organization you are affiliated with, such as an employer or school, to access Skytap online services, the owner of the domain (e.g., your employer) associated with your email address may: (i) control and administer your Skytap online services account and (ii) access and process your data, including the contents of your communications and files.
Information from Children
Skytap’s website and services are not designed for use by children under the age of 13. Skytap does not voluntarily or knowingly collect information from children under 13. As such, if you are under the age of 13, please stop using this website and/or Skytap services. If you are a parent or guardian and believe that we may have collected Personal Data from someone under the age of 13, please let us know by emailing email@example.com.
Inquiries may also be addressed to:
Data Protection Officer
719 2nd Avenue, Suite 800
Seattle, WA 98104