Effective as of March 22, 2024
This Privacy Statement describes how Decodex, Inc. and our affiliate entities (“Decodex”, “we”, “us”, or “our”) collect, use, share or otherwise process information relating to individuals (“Personal Data”) and the rights associated with that processing.
RESPONSIBLE ENTITY
We are responsible for the processing of your Personal Data as described in this Privacy Statement, unless specified otherwise, and act as the controller of such Personal Data.
This Privacy Statement does not apply to the extent we process Personal Data in the role of a processor or service provider on behalf of our clients, including where we offer to our clients various products and services through which our clients (or their affiliates) collect, use, share or process Personal Data via our products and services.
We may make available to you services provided by third parties. When services are provided by us and they link to this Privacy Statement, this Privacy Statement applies. When these offerings are provided by third parties, the privacy statement of the third party applies and this Privacy Statement does not.
Our websites and services may contain links to other websites, applications, platforms and services maintained by third parties. The information practices of these third parties, including the social media platforms that host our branded social media pages, are governed by their privacy statements, which you should review to better understand their privacy practices.
In some circumstances, we also collect, or our partners provide us with, publicly available information which may contain Personal Data that you have published or that has been made available online. The way in which our partners collect this is detailed in their own privacy policies, available on their websites.
PERSONAL DATA YOU PROVIDE
This Privacy Statement applies to the processing of Personal Data collected by us when you:
The Personal Data we collect directly from you may include identifiers, professional or employment-related information, financial account information, commercial information, visual information, and internet activity information, among others. We may collect such or similar information in the following interactions:
If you provide us, our service providers or our affiliates with any Personal Data relating to other individuals, you represent that you have the authority to do so, and where required, have obtained the necessary consent, and acknowledge that it may be used in accordance with this Privacy Statement. If you believe that your Personal Data has been provided to us improperly, or want to exercise your rights relating to your Personal Data, please contact us by using the information in the “Contact Us” section below.
PERSONAL DATA PROVIDED BY OTHERS
We also collect information about you from other sources including partners from whom we collect or purchase Personal Data or who provide us with publicly available information which may contain Personal Data. We may combine this information with Personal Data provided by you.
Services. The Personal Data we collect to provide our products and services may include information you have made publicly available online (such as when using social media sites) or that is published by third parties and contains information about you (such as news articles). For a select number of services, we collect this Personal Data from partners who may receive this data when you visit or use their services or through the third parties they work with. In addition, the Personal Data we collect to provide our products and services may include location information from third parties, which helps us offer features like identity management and multi-factor authentication.
Advertising. The Personal Data we collect from other sources for the purposes of tailored advertising includes identifiers, professional or employment-related information, education information, commercial information, visual information, internet activity information, and inferences about preferences and behaviors. We, collect this from third party providers of business contact information, including mailing addresses, job titles, email addresses, phone numbers, intent data (or user behavior data), IP addresses, social media profiles, LinkedIn URLs and custom profiles for purposes of targeted advertising, delivering relevant email content, event promotion and profiling, determining eligibility and verifying contact information. This helps us update, expand, and analyze our records, identify new clients, and create more tailored advertising to provide services that may be of interest to you.
Additional sources. In addition to the aforementioned, we collect Personal Data from (i) other individuals at your organization who may provide us with your personal information, which may include Personal Data and special categories of Personal Data, to the extent you consent to providing it and sharing it, for the purposes of obtaining services and assessing our goals related to encouraging diversity within our vendors; (ii) platforms such as GitHub to manage code check-ins and pull requests for open-source or community development projects, where we may associate your code repository username with your community account so we can inform you of program changes that are important to your participation or relate to additional security requirements; and (iii) publicly available sources online where necessary for security purposes (such as accessible through search engines or public social media sites), which may also include images, physical descriptions and other pertinent information necessary to address a credible security threat to our employees, events or premises.
DEVICE AND USAGE DATA
We use common information-gathering tools, such as tools for collecting data, cookies, web beacons, pixels, and similar technologies to collect information that may contain Personal Data as you navigate our websites, our services, or interact with emails we have sent to you.
Data. As is true of most websites, we gather certain device information when individual users visit our websites. This information may include identifiers, commercial information, and internet activity information such as IP address (or proxy server information), device and application information, identification numbers and features, location, browser type, plug-ins, integrations, Internet service provider, mobile carrier, the pages and files viewed, searches, referring website, app or ad, operating system, system configuration information, advertising and language preferences, date and time stamps associated with your usage, and frequency of visits to the websites. This information is used for the purposes set out in “Purposes for Personal Data Processing” below.
In addition, we gather certain information as part of your use of our products and services (“Usage Data”). This information may include: (i) identifiers, such as user ID, organization ID, username, email address and user type; (ii) commercial information; and (iii) internet activity information such as IP address (or proxy server), mobile device number, device and application identification numbers, location, language, browser type, Internet service provider or mobile carrier, user interactions such as the pages and files viewed, website and webpage interactions including searches and other actions you take, operating system type and version, system configuration information, date and time stamps associated with your usage and details of which of our products and product versions you are using. This information is used for the purposes set out in detail in “Purposes for Personal Data Processing” below. In addition, we may use aggregated Usage Data for other internal business purposes, such as to identify additional client opportunities and to ensure that we are meeting the demands of our clients and their users. Please note that this Usage Data is primarily used to identify the uniqueness of each user logging on (as opposed to specific individuals), apart from where it is strictly required to identify an individual for security purposes or as required as part of our provision of the services to our clients.
Cookies, web beacons and other tracking technologies. We use technologies such as web beacons, pixels, tags, and JavaScript, alone or in conjunction with cookies, to gather information about the use of our websites and how people interact with our emails.
When you visit our websites, we, or an authorized third party, may place a cookie on your device that collects information, including Personal Data, about your online activities over time and across different sites. Cookies allow us to track use, infer browsing preferences, and improve and customize your browsing experience.
We use both session-based and persistent cookies on our websites. Session-based cookies exist only during a single session and disappear from your device when you close your browser or turn off the device. Persistent cookies remain on your device after you close your browser or turn your device off. To change your cookie settings and preferences for one of our websites, click the Cookie Preferences link in the footer of the page. You can also control the use of cookies on your device, but choosing to disable cookies on your device may limit your ability to use some features on our websites and services.
We also use web beacons and pixels on our websites and in emails. For example, we may place a pixel in a marketing email that notifies us when you click on a link in the email. We use these technologies to operate and improve our websites and marketing emails. – please see more details in the “Advertising Cookies” row in the table below. For instructions on how to unsubscribe from our marketing emails, please see “Your preferences for email and SMS communications” below.
The following describes how we use different categories of cookies and similar technologies and your options for managing the data collection settings of these technologies:
Behavioral advertising. As described above, we or one of our authorized partners may place or read cookies on your device when you visit our websites for the purpose of serving you targeted advertising (also referred to as “online behavioral advertising” or “interest-based advertising”). To learn more about targeted advertising and advertising networks, please visit the opt-out pages of the Network Advertising Initiative, here, and the Digital Advertising Alliance, here.
Opt-out from cookies. In many cases you may opt-out from the collection of non-essential device data on your web browser by managing your cookies at the browser or device level. In addition, if you wish to opt-out of interest-based advertising, click here. To manage the use of functional and advertising cookies on this website, click the Cookie Preferences link in the footer of the page. To opt-out of targeted advertising that is provided to us and to third parties, you may also contact us as described in “Contact is” below. Please note, however, that by blocking or deleting cookies and similar technologies used on our websites, you may not be able to take full advantage of the websites.
While some internet browsers offer a “do not track” or “DNT” option that lets you tell websites that you do not want to have your online activities tracked, these features are not yet uniform and there is no common standard adopted by industry groups, technology companies, or regulators. Therefore, we do not currently commit to responding to browsers’ DNT signals with respect to our websites. We take privacy and meaningful choice seriously and will make efforts to continue to monitor developments around DNT browser technology and the implementation of a standard.
Social Media. Our websites may use social media features, such as the “Tweet” button and other sharing widgets (“Social Media Features”). Social Media Features may allow you to post information about your activities on our website to outside platforms and social networks. Social Media Features may also allow you to like or highlight information we have posted on our website or our branded social media pages. Social Media Features are either hosted by each respective platform or hosted directly on our website. To the extent the Social Media Features are hosted by the platforms themselves, and you click through to these from our websites, the platform may receive information showing that you have visited our websites. If you are logged in to your social media account, it is possible that the respective social media network can link your visit to our websites with your social media profile.
We also may allow you to log in to certain of our websites using sign-in services. These services authenticate your identity and provide you the option to share certain Personal Data from these services with us such as your name and email address to pre-populate our sign-up form.
Your interactions with Social Media Features are governed by the privacy policies of the companies providing them.
Phone logs. If you use certain features of our services on a mobile device, we may also collect telephony log information (like phone numbers, time and date of calls, duration of calls, SMS routing information and types of calls), device event information (such as crashes, system activity, hardware settings, browser language), and location information (through IP address, GPS, and other sensors that may, for example, provide us with information on nearby devices, Wi-Fi access points and cell towers).
PURPOSES OF PROCESSING PERSONAL DATA
We collect and process your Personal Data (including, where legally permissible, special categories of Personal Data) for the following purposes and relying on the following legal bases. If we need to collect and process Personal Data by law, or under a contract we have entered into with you, and you fail to provide the required Personal Data when requested, we may not be able to perform our contract with you.
PERSONAL DATA SHARING
We may share your Personal Data with:
We may also share aggregated Usage Data with our service providers for the purpose of helping us in analysis and improvements. Additionally, we may share Usage Data on an aggregate basis in the normal course of operating our business; for example, we may share information publicly to show trends about the general use of our services.
Anyone using our communities, forums, blogs, or chat rooms on our websites may read any Personal Data or other information you choose to submit and post.
For more information on the recipients of your Personal Data, please contact us by using the information in “Contact Us” below.
CHILDREN
Our websites and services are not directed at children. We do not knowingly collect Personal Data from children under the age of 13. We do not knowingly collect Personal Data for children between 13-18 unless we have obtained consent from a parent or guardian or such collection is subject to a separate agreement with us or the visit by a child is unsolicited or incidental. If you believe we have mistakenly or unintentionally collected Personal Data of a minor without appropriate consent please contact us by using the information in “Contact Us” below and we will take steps to delete their Personal Data from our systems.
RETAINING PERSONAL DATA
We may retain your Personal Data for a period of time consistent with the original purpose of collection (see “Purposes for Personal Data Processing” above) or as long as required to fulfill our legal obligations. We determine the appropriate retention period for Personal Data on the basis of the amount, nature, and sensitivity of the Personal Data being processed, the potential risk of harm from unauthorized use or disclosure of the Personal Data, whether we can achieve the purposes of the processing through other means, and on the basis of applicable legal requirements (such as applicable statutes of limitation).
After expiry of the applicable retention periods, your Personal Data will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will implement appropriate measures to prevent any further use of such data.
For more information on data retention periods, please contact us by using the information in the “Contact Us” below.
YOUR RIGHTS TO YOUR PERSONAL DATA
Your rights. You may have certain rights relating to your Personal Data, subject to local data protection laws. Depending on the applicable laws these rights may include the right to:
Where we process your Personal Data for direct marketing purposes or share it with third parties for their own direct marketing purposes, you can exercise your right to object at any time to such processing without having to provide any specific reason for such objection.
Please note that Automated Decision-Making currently does not take place on our websites or in our services.
Exercising your rights. To exercise your rights, please contact us by using the information in “Contact Us” below. Your Personal Data may be processed in responding to these rights. We try to respond to all legitimate requests within one month unless otherwise required by law, and will contact you if we need additional information from you in order to honor your request or verify your identity. Occasionally it may take us longer than a month, taking into account the complexity and number of requests we receive. If you are an employee of a Decodex client, we recommend you contact your employer’s system administrator for assistance in correcting or updating your information. Some registered users may update their user settings, profiles, organization settings and event registrations by logging into their accounts and editing their settings or profiles. To update your billing information, discontinue your account or request return or deletion of your Personal Data and other information associated with your account, please contact us by using the information in “Contact Us” below.
Your rights to client data. As described above, we may also process Personal Data submitted by or for a client to our products and services. To this end, if not stated otherwise in this Privacy Statement or in a separate disclosure, we process such Personal Data as a processor on behalf of our client (and its affiliates) who is the controller of the Personal Data. We are not responsible for and have no control over the privacy and data security practices of our clients, which may differ from those explained in this Privacy Statement. If your data has been submitted to us in our role as a processor by or on behalf of our client and you wish to exercise any rights you may have under applicable data protection laws, please inquire with them directly. Because we may only access a client’s data upon their instructions, if you wish to make your request directly to us, please provide us the name of our client who submitted your data to us. We will refer your request to that client, and will support them as needed in responding to your request within a reasonable timeframe.
Your preferences for email and SMS communications. If we process your Personal Data for the purpose of sending you marketing communications, you may manage your receipt of marketing and non-transactional communications from us by clicking on the “unsubscribe” link located on the bottom of our marketing emails or by replying or texting ‘STOP’ if you receive our SMS communications. You may also turn off push notifications on our apps on your device, or unsubscribe by contacting us using the information in the “Contact Us” section, below. Please note that opting out of marketing communications does not opt you out of receiving important business communications related to your current relationship with us, such as communications about your subscriptions or event registrations, service announcements or security information.
Your preferences for telemarketing communications. If you want your phone number to be added to our internal Do-Not-Call telemarketing register, please contact us by using the information in “Contact Us” below. Please include your first name, last name, company and the phone number you wish to add to our Do-Not-Call register. Alternatively, you can always let us know during a telemarketing call that you do not want to be called again for marketing purposes.
SECURING YOUR PERSONAL DATA
We take appropriate precautions including organizational, technical, and physical measures to help safeguard against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure of, or access to, the Personal Data we process or use. While we follow generally accepted standards to protect Personal Data, no method of storage or transmission is 100% secure. You are solely responsible for protecting your password, limiting access to your devices and signing out of websites after your sessions. If you have any questions about the security of our websites, please contact us by using the information in “Contact Us” below.
CHANGES TO THIS PRIVACY STATEMENT
We will update this Privacy Statement from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. If we do, we will update the “effective date” at the top. If we make a material update, we may provide you with notice prior to the update taking effect, such as by posting a notice on our website or by contacting you directly, or where required under applicable law and feasible, seek your consent to these changes. We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing and sharing of your Personal Data.
CONTACT US
If you have a privacy concern, complaint, or question, please email us at privacy@decodex.co or mail your inquiries to:
Decodex, Inc.
3450 Triumph Blvd
Suite 135
Lehi, UT 84043
ADDITIONAL DISCLOSURES FOR PROTECTED DATA
Certain financial and health Personal Data (“Protected Data”) contained in our services are regulated by certain laws, including the Health Insurance Portability and Accountability Act (“HIPAA”) and the Gramm-Leach-Bliley Act (“GLBA”). Upon granting us access to your Protected Data in our services, we will collect, use and share your information with you, your legal representatives, government agencies, and others who you authorize in the services. We have have the right to collect, use and share your Protected Data with your healthcare providers, insurance providers and insurance plan sponsors, and our business associates, as needed for the following purposes:
ADDITIONAL DISCLOSURES FOR CALIFORNIA RESIDENTS
The California Consumer Privacy Act (as amended by the California Privacy Rights Act) requires businesses to disclose whether they sell or share Personal Data. As a business covered by the CCPA, we do not sell Personal Data. We may share Personal Data (in the form of identifiers and internet activity information) with third party advertisers for purposes of targeting advertisements on non-Decodex websites, applications and services. In addition, we may allow third parties to collect Personal Data from our sites or services if those third parties are authorized service providers who have agreed to our contractual limitations as to their retention, use, and disclosure of such Personal Data, or if you use our sites or services to interact with third parties or direct us to disclose your Personal Data to third parties.
California law requires that we detail the categories of Personal Data that we disclose for certain “business purposes,” such as to service providers that assist us with securing our services or marketing our products, and to such other entities as described in “Purposes for Personal Data Processing” and “Personal Data Sharing”. We disclose the following categories of Personal Data for our business purposes:
California law grants state residents certain rights, including the rights to know and access specific types of Personal Data, to learn how we process Personal Data, to request deletion of Personal Data, to request correction of Personal Data, to opt-out of sharing your Personal Data for third party advertising purposes, and not to be denied goods or services for exercising these rights.
If you are a California resident under the age of 18 and have registered for an account with us, you may ask us to remove content or information that you have posted to our website(s). Please note that your request does not ensure complete or comprehensive removal of the content or information, because, for example, some of your content may have been reposted by another user.
For information on how to exercise your rights, please refer to ”Exercising your rights” above. If you are an authorized agent wishing to exercise rights on behalf of a California resident, please contact us using the information in “Contact Us” above and provide us with a copy of the consumer’s written authorization designating you as their agent.
If you would like to opt-out of shares using your cookie identifiers, turn on a Global Privacy Control in your web browser or browser extension. Please see the California Privacy Protection Agency’s website at https://oag.ca.gov/privacy/ccpa for more information on valid Global Privacy Controls. If you would like to opt-out of shares using other identifiers (like email address), please refer to ”Exercising your rights” above.
We may need to verify your identity and place of residence before completing your rights request.
We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.