5. Purposes for which we process Personal Data and the legal bases on which we rely
We collect and process your Personal Data for the purposes and on the legal bases identified in the following:
- Promoting security of our websites: We process your Personal Data by tracking use of our websites, creating aggregated, non-personal data, verifying accounts and activity, investigating suspicious activity and enforcing our terms and policies, to the extent this is necessary for our legitimate interest in promoting the safety and security of the systems and applications used for our websites and in protecting our rights and the rights of others;
- Managing user registrations: If you have registered for an account with us, we process your Personal Data by managing your user account for the purpose of performing our contract with you according to applicable terms of service;
- Handling contact and user support requests: If you fill out a “Contact Me” web form or request user support, or if you contact us by other means, we process your Personal Data to perform our contract with you and to the extent, it is necessary for our legitimate interest in fulfilling your requests and communicating with you;
- Managing event registrations and attendance: We process your Personal Data to plan and host events or webinars for which you have registered or that you attend, including sending related communications to you, to perform of our contract with you;
- Developing and improving our websites: We process your Personal Data to analyze trends and to track your usage of our websites and interactions with our emails to the extent it is necessary for our legitimate interest in developing and improving our websites and providing our users with more relevant and interesting content;
- Registering office visitors: We process your Personal Data for security reasons, to register visitors to our offices and to manage non-disclosure agreements that visitors may be required to sign, to the extent such processing is necessary for our legitimate interest in protecting our offices and our confidential information against unauthorized access.
- Complying with legal obligations: We process your Personal Data when cooperating with public and government authorities, courts or regulators in accordance with our legal obligations under applicable laws to the extent this requires the processing or disclosure of Personal Data to protect our rights or is necessary for our legitimate interest in protecting against misuse or abuse of our websites, protecting personal property or safety, pursuing remedies available to us and limiting our damages, complying with judicial proceedings, court orders or legal processes or to respond to lawful requests.
Where we need to collect and process Personal Data by law, or under a contract we have entered into with you, and you fail to provide the required Personal Data when requested, we may not be able to perform our contract with you.
6. Who do we share Personal Data with?
We may share your Personal Data as follows:
- With our contracted service providers, who provide services such as IT and system administration and hosting, credit card processing, research and analytics, marketing, customer support, and data enrichment for the purposes and pursuant to the legal bases described above; such service providers comprise companies located in these countries: USA, India, Romania. Some of the providers are Google, Amazon, Twilio and Zoho.
- If you use our websites to register for an event or webinar organized by one of our affiliates, with the affiliate to the extent this is required on the basis of the affiliate’s contract with you to process your registration and ensure your participation in the event; in such instances, our affiliate will process the relevant Personal Data as a separate controller and will provide you with further information on the processing of your Personal Data, where required
- If you attend an event or webinar organized by us or download or access an asset on our website, with sponsors of the event, if required by applicable law, you may consent to such sharing via the registration form or by allowing your attendee badge to be scanned at a sponsor booth. In these circumstances, your information will be subject to the sponsors’ privacy statements. If you do not wish for your information to be shared, you may choose to not opt-in via event/webinar registration or elect to not have your badge scanned, or you can opt-out in accordance with Section 9 below;
- With sponsors of contests or promotions for which you register;
- With third-party social media networks, advertising networks and websites, which usually act as separate controllers, so that 3r Behavioral Solutions can market and advertise on third-party platforms and websites;
In individual instances, with professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers based in countries in which we operate (USA) who provide consultancy, banking, legal, insurance and accounting services, and to the extent we are legally obliged to share or have a legitimate interest in sharing your Personal Data;
- With affiliates within the 3r Behavioral Solutions, Inc corporate group and companies that we acquire in the future when they are made part of the 3r Behavioral solutions corporate group, to the extent such sharing of data is necessary to fulfill a request you have submitted via our websites or for customer support, marketing, technical operations, and account management purposes. 3r Behavioral Solution is currently the only operating company in the group.
- If we are involved in a merger, reorganization, dissolution or other fundamental corporate change, or sell a website or business unit, or if all or a portion of our business, assets or stock are acquired by the third party, with such third party. In accordance with applicable laws, we will use reasonable efforts to notify you of any transfer of Personal Data to an unaffiliated third party.
Any Personal Data or other information you choose to submit in communities, forums, blogs or chat rooms on our websites may be read, collected and used by others who visit these forums, depending on your account settings.
For further information on the recipients of your Personal Data, please contact us by using the information in the “Contacting us” section, below.
Our websites are not directed at children. We do not knowingly collect Personal Data from children under the age of 16 If you are a parent or guardian and believe your child has provided us with Personal Data without your consent, please contact us by using the information in the “Contacting us” section, below, and we will take steps to delete such Personal Data from our systems.
8. How long do we keep your Personal Data?
We may retain your Personal Data for a period of time consistent with the original purpose of collection (see the “Purposes for which we process Personal Data and the legal bases on which we rely” section, above). We determine the appropriate retention period for Personal Data on the basis of the amount, nature and sensitivity of your Personal Data processed, the potential risk of harm from unauthorized use or disclosure of your Personal Data and whether we can achieve the purposes of the processing through other means, as well as on the basis of applicable legal requirements (such as applicable statutes of limitation).
After the expiry of the applicable retention periods, your Personal Data will be deleted. If there is any data that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further use of such data.
For further information on applicable data retention periods, please contact us by using the information in the “Contacting us” section, below.
9. Your rights relating to your Personal Data
9.1 Your rights
You have certain rights relating to your Personal Data, subject to local data protection laws. Depending on the applicable laws and, in particular, if you are located in the EEA, these rights may include:
- To access your Personal Data held by us (right to access);
- To rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete (right to rectification);
- To erase/delete your Personal Data, to the extent permitted by applicable data protection laws (right to erasure; right to be forgotten);
- To restrict our processing of your Personal Data, to the extent permitted by law (right to restriction of processing);
- To transfer your Personal Data to another controller, to the extent possible (right to data portability);
- Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects (“Automated Decision-Making”). Automated
- Decision-Making currently does not take place on our websites; and
- To the extent we base the collection, processing, and sharing of your Personal Data on your consent, to withdraw your consent at any time, without affecting the lawfulness of the processing based on such consent before its withdrawal.
If you are a resident of California, under the age of 18 and have registered for an account with us, you may ask us to remove the content or information that you have posted to our websites. Please note that your request does not ensure complete or comprehensive removal of the content or information, because, for example, some of your content may have been reposted by another visitor to our websites.
9.2 How to exercise your rights
To exercise your rights, please contact us by using the information in the “Contacting us” section, below. We try to respond to all legitimate requests within one month and will contact you if we need additional information from you in order to honor your request. Occasionally it may take us longer than a month, taking into account the complexity and number of requests we receive. If you are an employee of a 3r Behavioral Solutions customer, we recommend you contact your company’s system administrator for assistance in correcting or updating your information.
Some registered users may update their user settings, profiles, organization settings, and event registrations by logging into their accounts and editing their settings or profiles.
To discontinue your account and/or request return or deletion of your Personal Data and other information associated with your account, please contact us by using the information in the “Contacting us” section, below.
9.3 Your rights relating to Customer Data
As described above, we may also process Personal Data in the role of a processor (see the “Responsible 3r Behavioral Solutions entity” section above). If your data has been submitted to us by a 3r Behavioral Solutions customer and you wish to exercise any rights you may have under applicable data protection laws, please inquire with the applicable customer directly. Because we may only access a customer’s data upon instruction from that customer, if you wish to make your request directly to us, please provide us the name of the 3r Behavioral Solutions customer who submitted your data to us. We will refer your request to that customer and will support them as needed in responding to your request within a reasonable timeframe.
10. How we secure your Personal Data
We take precautions including organizational, technical and physical measures to help safeguard against the accidental or unlawful destruction, loss, alteration, and unauthorized disclosure of, or access to, the Personal Data we process or use.
While we are GDPR compliant and follow generally accepted standards to protect Personal Data, no method of storage or transmission is 100% secure. You are solely responsible for protecting your password, limiting access to your devices and signing out of websites after your sessions. If you have any questions about the security of our websites and applications, please contact us by using the information in the “Contacting us” section, below.
11. Changes to this Privacy Statement
We will update this Privacy Statement from time to time to reflect changes in our practices, technologies, legal requirements and other factors. If we do, we will update the “effective date” at the top of this Privacy Statement. If we make an update, we may provide you with notice prior to the update taking effect, such as by posting a conspicuous notice on our website or by contacting you using the email address you provided.
We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing, and sharing of your Personal Data.
12. Contacting us
To exercise your rights regarding your Personal Data, or if you have questions regarding this Privacy Statement or our privacy practices please fill out this form or mail us at:
3r Behavioral Solutions Data Protection Officer
12100 Sunset Hills Rd suite 150,
Reston, VA 20190
Data Protection Officer Email: firstname.lastname@example.org
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy.