Skip to content

Privacy Policy Statement

Kayako Limited (the “Company”, “we”, or “us”) respects your privacy. This Privacy Policy Statement (“Privacy Policy”) describes the ways we collect information from and about you, what we do with the information, and your privacy rights. By accessing our website, or purchasing our products or services, you agree to this Privacy Policy in addition to any other agreements we might have with you. In the event that such agreements contain terms that conflict with this Privacy Policy, the terms of those agreements will prevail.

Scope

This Privacy Policy includes the Company’s Privacy Policy Statement and applies to personal data processed by us in our business, including on our websites, mobile applications, and other online or offline offerings (collectively, the “Services”).

Company’s Privacy Policy Statement

  1.  Our Collection of your Information

Personal Data

The information we collect may include your personal data, such as your name, contact information, IP addresses, product and service selections and other data that may identify you.  We collect personal data about you at several different points, including but not limited to the following:

  • when we correspond with you as a customer or prospective customer;
  • when you visit our website or use the Platform;
  • when you use our software or services;
  • when you register as an end-user of our services and an account is created for you;
  • when you enroll in our newsletter or loyalty program;
  • when you decide to participate in a survey;
  • when you contact us for help;
  • when you attend our customer conferences or webinars;
  • when the websites or mobile apps send us error reports or application analytics data; and
  • when you provide content on our forums, blogs, or social media pages. Any content you provide on these channels will be considered “public”.
  1. Information Collected Automatically or From Others

Automatic Data Collection.  We may collect certain information automatically when you use the Services.  This information may include your Internet protocol (IP) address, user settings, MAC address, cookie identifiers, mobile carrier, mobile advertising and other unique identifiers, details about your browser, operating system or device, location information, Internet service provider, pages that you visit before, during and after using the Services, information about the links you click, and other information about how you use the Services.  Information we collect may be associated with accounts and other devices. Our Services, such as those related to location data management, may collect precise geolocation information in accordance with applicable law.

In addition, we may automatically collect data regarding your use of our Services, such as the types of content you interact with and the frequency and duration of your activities.  Unless contrary to applicable law or contractual agreement, we may combine your information with information that other people provide when they use our Services, including, when the option is available, information about you when they tag you.

Cookies, Pixel Tags/Web Beacons, Analytics Information, and Interest-Based Advertising technologies.  We, as well as third parties that provide content, advertising, or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services.  Technologies are essentially small data files placed on your computer, tablet, mobile phone, or other devices that allow us and our partners to record certain pieces of information whenever you visit or interact with our Services.

  • Cookies. Cookies are small text files placed in visitors’ computer browsers to store their preferences.  Most browsers allow you to block and delete cookies.  However, if you do that, the Services may not work properly.
  • Pixel Tags/Web Beacons. A pixel tag (also known as a web beacon) is a piece of code embedded in the Services that collects information about users’ engagement on that web page.  The use of a pixel allows us to record, for example, that a user has visited a particular web page or clicked on a particular advertisement.

Web Analytics Services. We use Google Analytics, a service for the marketing analysis of the site provided by Google, Inc. Google Analytics uses cookies to allow us to see how you use our site, so we can improve your experience. Google’s ability to use and share information collected by Google Analytics about your visits to the site is restricted by the Google Analytics Terms of Use available at http://www.google.com/analytics/terms/us.html and the Google Privacy Policy available at http://www.google.com/policies/privacy/. You can prevent Google Analytics from recognizing you on return visits to the site by disabling cookies in your browser. If you prefer to not have data reported by Google Analytics, you can install the Google Analytics Opt-out Browser Add-on available at https://tools.google.com/dlpage/gaoptout.

Information from Other Sources. We may obtain information about you from other sources, including through third-party services and organizations to supplement information provided by you.  For example, if you access our Services through a third-party application, such as an app store, a third-party login service, or a social networking site, we may collect information about you from that third-party application that you have made public via your privacy settings.  Information we collect through these services may include your name, your user identification number, your user name, location, gender, birth date, email, profile picture, and your contacts stored in that service.  This supplemental information allows us to verify information that you have provided to us and to enhance our ability to provide you with information about our business, products, and Services.

  1.  Legal Basis for Processing your Personal Data (EEA, UK and Switzerland only)

With respect to personal data of individuals from the European Economic Area (“EEA”), the United Kingdom (“UK”) or Switzerland, our legal basis for collecting and using the personal data will depend on the personal data concerned and the specific context in which we collect it. Our Company will generally collect personal data from you or a third party only where: (a) we have your consent to do so, (b) where we need the personal data to perform a contract with you (e.g. to deliver the services you have requested), or (c) where the processing is in our or a third party’s legitimate interests (and not overridden by your data protection interests or fundamental rights and freedoms).

  1.  Our Use of your Personal Data

Our Company may use information that we collect about you to:

Fulfil our contract with you and provide you with our Services, such as:

  • delivering the products and services that you have requested;
  • managing your customer relationship and provide you with customer support;
  • communicating with you by email, postal mail, telephone or mobile devices about products or services that may be of interest to you either from us, or other third parties;
  • undertaking activities to verify or maintain the quality or safety of a service or device;
  • processing your financial information and other payment methods for products or Services purchased;
  • managing our business, and
  • allowing you to register for events

Analyze and improve our Services pursuant to our legitimate interest, such as:

  • detecting security incidents, protecting against malicious, deceptive, fraudulent or illegal activity, and prosecuting those responsible for that activity;
  • performing research and analysis about your use of, or interest in, our Services or content offered by others, and short-term, transient use, such as contextual customization of ads;
  • undertaking research for technological development and demonstration;
  • improving, upgrading or enhancing our Services or device or those of our Providers;
  • verifying your identity and preventing fraud;
  • debugging to identify and repair errors that impair existing intended functionality, and
  • enforcing our terms and conditions

Provide you with additional content and Services, such as:

  • developing and display content and advertising tailored to your interests on our websites or mobile applications;
  • auditing relating to interactions, transactions and other compliance activities;
  • verifying your eligibility and deliver prizes in connection with promotions, and
  • performing functions you consent to or that are otherwise described to you at the time of collection.

Use De-identified and Aggregated Information.  We may use personal data and other data about you to create de-identified and aggregated information, such as de-identified demographic information, de-identified location information, information about the computer or device from which you access our Services, or other analyses we create.

Share Content with Friends or Colleagues.  Our Services may offer various tools and functionalities.  For example, we may allow you to provide information about your friends or colleagues through our referral services.  Our referral services may allow you to forward or share certain content with a friend or colleague, such as an email inviting your friend to use our Services.

Process Information on Behalf of Our Customers (as processors).   Our customers may choose to use our Services to process certain data of their own, which may contain personal data.  The data that we process through our Services is processed by us on behalf of our customer, and our privacy practices will be governed by the contracts that we have in place with our customers, not this Privacy Policy.

If you have any questions or concerns about how such data is handled or would like to exercise your rights, you should contact the person or entity (i.e., the data controller) who has contracted with us to use the Service to process this data.  Our customers control the personal data in these cases and determine the security settings within the account, its access controls and credentials.  We will, however, provide assistance to our customers to address any concerns you may have, in accordance with the terms of our contract with them.  For a list of our sub-processors, contact us as described below.

  1.  Our Disclosure of your Personal Data to Third Parties

We may share your personal data with third parties only in the ways that are described in this Privacy Policy.

Below is a list of categories of personal data (from the California Consumer Privacy Act) we have collected and disclosed about consumers for a business purpose in the past 12 months:

Category A: Identifiers;

Category B: Personal Data categories listed in the California Customer Records statute (Cal. Civ. Code § 1798.80(e));

Category D: Commercial information;

Category F: Internet or other electronic network activity;

Category G: Geolocation data;

Category I: Professional or employment-related information.

The above list does not include information about personal data collected and disclosed while operating as a service provider to our customers.

We have not sold consumers’ personal information in the preceding 12 months.

In addition to any other disclosures described in this Privacy Policy, our disclosures to others may include:

  • Affiliates and Service Providers. we may provide your information to affiliated entities within our corporate group, as well as with vendors who perform functions on our behalf; such parties provide hosting and maintenance services, virtual infrastructure, payment processing, analysis and other services for us;
  • third-party contractors may have access to our databases.  Usually these contractors sign a standard confidentiality agreement;
  • Business Partners. we may share your data with any parent company, subsidiaries, joint ventures, other entities under a common control or third-party acquirers. We expect these other entities will honor this Privacy Policy;
  • Disclosure for Merger, Sale or Other Asset Transfer. we may allow a potential acquirer or merger partner to review our databases, although we would restrict their use and disclosure of this data during the diligence phase;
  • Disclosure to Protect Us or Others. as required by law enforcement, government officials, or other third parties pursuant to a subpoena, court order, or other legal process or requirement applicable to our Company; or when we believe, in our sole discretion, that the disclosure of personal data is necessary to prevent physical harm or financial loss; to report suspected illegal activity or to investigate violations of our agreements or Company policies; to enforce our terms and conditions, to protect the security or integrity of our products and services, and
  • when you give us permission to do so.

Please note that these third parties may be in other countries where the laws on processing personal data may be less stringent than in your country.

Potential for Other Users to Contact You

To the extent that a given application supports personal messaging functionality between and among end users, you may receive personal messages from other end users.  You can disable this functionality by using the unsubscribe and other disabling instructions in the given application.

  1.  Our Security Measures to Protect your Personal Data

Our Company uses industry-standard technologies when transferring and receiving data exchanged between our Company and other companies to help ensure its security. This site has security measures in place to help protect information under our control from the risk of accidental or unlawful destruction or accidental loss, alteration or unauthorized disclosure or access. However, “perfect security” does not exist on the Internet.  Also, if this website contains links to other sites, our Company is not responsible for the security practices or the content of such sites.

  1.  Our Use of Automatic Collection Technologies

  • Automatic Collection Technologies. We, as well as third parties that provide content, advertising, or other functionality on the Services, may use cookies, pixel tags, local storage, and other technologies to automatically collect information through the Services. Our uses of these Technologies fall into the following general categories:
    • Operationally Necessary. This includes Technologies that allow you access to our Services, applications, and tools that are required to identify irregular site behavior, prevent fraudulent activity and improve security or that allow you to make use of our functionality;
    • Performance Related. We may use Technologies to assess the performance of our Services, including as part of our analytic practices to help us understand how our visitors use the Services;
    • Functionality Related. We may use Technologies that allow us to offer you enhanced functionality when accessing or using our Services.  This may include identifying you when you sign into our Services or keeping track of your specified preferences, interests, or past items viewed;
    • Advertising or Targeting Related. We may use first party or third-party Technologies to deliver content, including ads relevant to your interests, on our Services or on third-party sites.
  • Website Links. We may create links to other websites. We will make a reasonable effort to link only to sites that meet similar standards for maintaining each individual’s right to privacy. However, many other sites that are not associated with or authorized by our Company may have links leading to our site. Our Company cannot control these links and we are not responsible for any content appearing on these sites. Since this website does not control the privacy policies of third parties, you are subject to the privacy practices of that third party. We encourage you to ask questions before you disclose any personal data to others.
  • App Links. A given application may provide you with an advertising link to other, third-party sites and applications. Such third-party sites will have their own data collection practices and policies.  Please review the privacy policy for such sites and exercise caution in providing information that personally identifies you.  We have no responsibility, access, or control over the data collection practices and policies of such third-party sites and applications.  You will use such sites and applications at your own risk and outside of the scope of this Privacy Policy.  The provision of such advertisements is done on an “As Is” basis, with no endorsements or representations.
  • Cross-Device Tracking. Your browsing activity may be tracked across different websites and different devices or apps.  For example, we may attempt to match your browsing activity on your mobile device with your browsing activity on your laptop.  To do this our technology partners may share data, such as your browsing patterns, geo-location and device identifiers, and will match the information of the browser and devices that appear to be used by the same person.
  • Notice Regarding Third-Party Websites, Social Media Platforms and Software Development Kits. Our Company websites and mobile apps may use third parties to present or serve the advertisements that you may see at its web pages and to conduct research about the advertisements and web usage. This Privacy Policy does not cover any use of information that such third parties may have collected from you or the methods used by the third parties to collect that information. We do not endorse, screen or approve and are not responsible for the privacy practices or content of such other websites or applications. Visiting these other websites or applications is at your own risk.

Our Services may include publicly accessible blogs, forums, social media pages, and private messaging features.  By using such Services, you assume the risk that the personal data provided by you may be viewed and used by third parties for any number of purposes.  In addition, social media buttons such as Twitter and LinkedIn (that might include widgets such as the “share this” button or other interactive mini-programs) may be on our site.  These features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the feature to function properly.  These social media features are either hosted by a third party or hosted directly on our site.  Your interactions with these features apart from your visit to our site are governed by the privacy policy of the company providing it.

We may use third-party APIs and software development kits (“SDKs”) as part of the functionality of our Services.  APIs and SDKs may allow third parties including analytics and advertising partners to collect your personal data for various purposes including to provide analytics services and content that is more relevant to you.  For more information about our use of APIs and SDKs, please contact us as set forth below.

  1. Limiting Use, Disclosure, Retention

Whenever applicable, our Company identifies the purposes for which the information is being collected before or at the time of collection. The collection of your personal data will be limited to that which is needed for the purposes identified by our Company. Unless you consent, or we are required by law, we will only use the personal data for the purposes for which it was collected. If our Company will be processing your personal data for another purpose later on, our Company will seek your further legal permission or consent; except where the other purpose is compatible with the original purpose. We will keep your personal data only as long as required to serve those purposes. We will also retain and use your personal data for as long as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

  1.  International Transfers of your Personal data

We are a global company. Information about you may be stored and processed in the European Economic Area, the United States or any other country in which our Company or agents or contractors maintain facilities, and by accessing our websites and using our mobile apps, software and services, you consent to the transfer of your information outside of your country. Such countries may have laws which are different, and potentially not as protective as the laws of your own country.

Whenever we share personal data originating in the EEA, the UK or Switzerland, we will rely on lawful measures to transfer that data, such as the Privacy Shield or the EU standard contractual clauses. If you reside in the EEA, UK or other regions with laws governing data collection and use, please note that you are agreeing to the transfer of your personal data to the United States and other jurisdictions in which we operate. By providing your personal data, you consent to any transfer and processing in accordance with this Policy.

  1.  Accuracy of Personal data

We do our best to ensure that the personal data we hold and use is accurate. We rely on the customers we do business with to disclose to us all relevant information and to inform us of any changes.

  1. Your Access to and Updating of your Personal data

Reasonable access to your personal data may be provided upon request made to our Company at the contact information provided below. If access cannot be provided within that time frame, our Company will provide the requesting party a date when the information will be provided. If for some reason access is denied, we will provide an explanation as to why access has been denied. We may charge a reasonable fee in advance for copying and sending the information requested.

You can change any of the personal data volunteered to us by logging into the Kayako customer area: https://my.kayako.com.

If you would like us to delete any personal data held about you, we will do so on request unless we need to hold the information as part of the provision of products and services to you.

  1. Your Choices

We offer those who provide personal data a means to choose how we use the information provided. Where you have consented to the processing of your personal data, you may withdraw that consent at any time and prevent further processing by contacting us as described below.  Even if you opt out, we may still collect and use non- personal data regarding your activities on our Services and for other legal purposes as described above.

Marketing. You may manage your receipt of marketing and non- transactional communications by clicking on the “unsubscribe” link located on the bottom of our marketing emails. Note that you will continue to receive transaction-related emails regarding products or Services you have requested.  We may also send you certain non-promotional communications regarding us and our Services, and you will not be able to opt out of those communications (e.g., communications regarding the Services or updates to our Terms or this Privacy Policy).

We process requests to be placed on do-not-mail, do-not-phone and do-not-contact lists as required by applicable law.

Mobile Devices. We may send you push notifications through our mobile application.  You may at any time opt- out from receiving these types of communications by changing the settings on your mobile device.  We may also collect location-based information if you use our mobile applications.  You may opt-out of this collection by changing the settings on your mobile device.

“Do Not Track.” Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers.  Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.

Cookies and Interest-Based Advertising. You may stop or restrict the placement of Technologies on your device or remove them by adjusting your preferences as your browser or device permits.  The online advertising industry also provides websites from which you may opt out of receiving targeted ads from data partners and other advertising partners that participate in self-regulatory programs.  You can access these and learn more about targeted advertising and consumer choice and privacy, at www.networkadvertising.org/managing/opt_out.asp, http://www.youronlinechoices.eu/, https://youradchoices.ca/choices/, and www.aboutads.info/choices/.  To separately make choices for mobile apps on a mobile device, you can download DAA’s AppChoices application from your device’s app store.  Alternatively, for some devices you may use your device’s platform controls in your settings to exercise choice.

Please note you must separately opt out in each browser and on each device.  Advertisements on third-party websites that contain the AdChoices link may have been directed to you based on information collected by advertising partners over time and across websites.  These advertisements provide a mechanism to opt out of the advertising partners’ use of this information for interest-based advertising purposes.

  1. Your Privacy Rights

Depending on where you reside, you may have the right to exercise additional rights available to you under applicable laws, including:

  • Right of erasure. You may have a broader right to erasure of personal data that we hold about you. For example, if it is no longer necessary in relation to the purposes for which it was originally collected. Please note, however, that we may need to retain certain information for record keeping purposes, to complete transactions or to comply with our legal obligations, among other things.
  • Right to object to processing. You may have the right to request that we stop processing your personal data, including the right to opt in or opt out of the sale of your Personal Data to third parties, or to stop sending you marketing communications.
  • Right to restrict processing. You may have the right to request that we restrict processing of your personal data in certain circumstances. For example, where you believe that the personal data we hold about you is inaccurate or unlawfully held.
  • Right to data portability: In certain circumstances, you may have the right to be provided with your personal data in a structured, machine readable and commonly used format and to request that we transfer the personal data to another data controller without hindrance.

If you would like to exercise any of the above rights, please contact our support team or contact our Data Protection Officer (see our contact details in the “Contacting Us” Section below). We will consider your request in accordance with applicable laws. To protect your privacy and security, we may take steps to verify your identity before complying with the request.

You may also have the right to make a GDPR complaint to the relevant Supervisory Authority. A list of Supervisory Authorities is available here:  http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.  If you need further assistance regarding your rights, please contact us using the contact information provided below and we will consider your request in accordance with applicable law. In some cases, our ability to uphold these rights for you may depend upon our obligations to process personal data for security, safety, fraud prevention reasons, compliance with regulatory or legal requirements, or because processing is necessary to deliver the services you have requested. Where this is the case, we will inform you of specific details in response to your request.

  1.  Additional California Privacy Rights (United States only)

If you are a California resident, the California Consumer Privacy Act may entitle you to certain rights under Section 13 in addition to the disclosures about data collection, use and sharing contained herein. Also, California Civil Code Section 1798.83 permits you to request certain information regarding our disclosure of personal data to third parties for the third parties’ direct marketing purposes. To make such a request, please contact us by sending an email to privacy@kayako.com.

Our site, products, and services are not intended to appeal to minors. However, if you are a California resident under the age of 18, and a registered user of our Site or Service, California Business and Professions Code Section 22581 permits you to request and obtain removal of content or information you have publicly posted. To make such a request, please send an email with a detailed description of the specific content or information to privacy@kayako.com. We will process your request in compliance with applicable law.

Under California law, California residents who have an established business relationship with us may opt-out of our disclosing personal data about them to third parties for their marketing purposes.

  1. Notice to End Users of Customers

    Most of our services are intended for use by organizations. Where the services are made available to you through an organization (e.g. your employer), that organization is the administrator of the services and is responsible for the accounts and/or service over which it has control. Please direct your data privacy questions to your administrator, as your use of the services is subject to that organization's policies. We are not responsible for the privacy or security practices of an administrator's organization, which may be different from this policy.

Administrators may be able to:

  • help you exercise the rights described in “Your Privacy Rights” Section (if applicable);
  • allow you to reset your account password;
  • restrict, suspend or terminate your access to the services;
  • access information in and about your account;
  • access or retain information stored as part of your account;
  • change your information, including profile information associated with your account; and
  • allow you or restrict your ability to edit, restrict, modify or delete information.

Please contact your organization or refer to your administrator’s organizational policies for more information.

  1.  Children’s Privacy

Because of the nature of our business, our services are not designed to appeal to minors. We do not knowingly attempt to solicit or receive any information from anyone under the age of 17 (or other age as required by local law).  If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us immediately. If we learn that we have collected any personal data in violation of applicable law, we will promptly take steps to delete such information and terminate the child’s account.

  1.  Changes to our Privacy Policy

Our Company may amend this Privacy Policy at any time by posting a new version. It is your responsibility to review this Privacy Policy periodically as your continued use of this website and our products and services represents your agreement with the then-current Privacy Policy.

  1.  Contacting Us

If you have any questions about this Privacy Policy, the practices or concerns of this site, please contact our Data Protection Officer at: privacy@kayako.com.

 

Last Updated: March 30, 2021

Privacy Policy | Legal | Sitemap   © Kayako 2024