- 1.3 Website. We may collect information on User interacts with our Site, promotions, or advertisements. Third parties may also collect Personal Data as described below.
- 1.3.a Forms/Chats. If you contact or interact with us on the site via chat or site forms, we may collect information such as your name, phone number, email address, as well as any other content that you provide.
- 1.3.b Analytics. We may collect and allow third parties to collect information about how you use and interact with our Site and Services. Examples of third-party providers of analytics and similar services we currently use include:
- o Google Analytics. Used to track site statistics and user demographics, interests and behavior on websites.
- 1.3.c Ad Networks. We may receive Personal Data about you and your activities whether as part of or outside our Services through partnerships, or about your experiences and interactions from our partner ad networks.
- 1.4 Personal Data we Receive from Third Parties or Affiliates for Use in our Services. We may receive Personal Data that others provide about you when they use the Services (through Contacts provided to us as described above), or obtain information from other sources, including but not limited to public or licensed APIs (“Open Data”), third-party data partners and affiliates (Contacts+), and data research. We do not control, supervise, or respond for how the third parties process your Personal Data.
- 1.4.a Open Data. Open Data includes information that is in the public domain or has been declared public knowledge by someone with the authority to do so and can freely be given to anyone. Personal Data may be collected through our open data sources. We openly share this data, while abiding by relevant terms and conditions.
- 1.4.b Data Providers. We may collect Personal Data from reliable marketing/data providers gathered from sources including but not limited to public records, warranty information, surveys, opt-in subscriptions, public filings, public directories, and other publicly available sources.
- 1.5 Personal Data we Receive from Third Party Services for Use in Sales/Marketing. We may receive Personal Data from other third-party sources, third-party data partners and affiliates, and data research.
- 1.5.a Prospects Lists. In an effort to personalize and provide information on FullContact products or Services that may be of interest to you, we may collect Personal Data from third-party sources such as name, email, company name, job titles, and more.
- 1.6 Personal Data You Provide Us in Claim Your Data
- 1.6.a Authorization Data. When you want to verify your Personal Data via our Services, we may require you to provide certain information such as your general location, phone number, and email address(s) prior to granting access to your Personal Data for verification purposes only.
To the extent permitted by applicable law, Personal Data does not include:
Publicly Available Data – Publicly available information from government records.
Deidentified, Aggregate, or Anonymous Information – “Deidentified Information” means information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular individual, and for which FullContact has implemented technical safeguards and business processes that prohibit reidentification of the individual. “Aggregate Information” means information that relates to a group or category of individuals, from which individual identities have been removed, that is not linked or reasonably linkable to any individual or household, including via a device. “Anonymous Information” means information that is not associated with or linked to an individual and does not, by itself, permit the identification of an individual.
- HOW WE USE PERSONAL DATA
We primarily use, store, and process Personal Data to provide, understand, improve, and develop our Services, create and maintain a trusted and safer environment, and comply with our legal obligations. We also use Personal Data for the following purposes:
2.1 Provide, Maintain, and Support the Services
Additionally, to provide you technical support, we may need to review your Account and the contents of your Account to identify, research, troubleshoot, and resolve any issues that you report to us or that we otherwise become aware of.
2.2 Improve, Personalize, and Develop Services
We use Personal Data we collect to improve and personalize the Services and to develop new ones. For example, we use Personal Data to troubleshoot and protect against errors; perform data analysis and testing; conduct research and surveys; and develop new features and Services.
2.3 Provide, Personalize, Measure, and Improve our Advertising and Marketing
We may process Personal Data for marketing purposes including offering you products or Services that may be of interest to you (such as information about FullContact Services or partner campaigns and other third party services). We may also administer referral programs, rewards, surveys, sweepstakes, contests, newsletters, or other promotional activities or events sponsored or managed by FullContact or its third party partners. You can opt-out of receiving marketing communications from us by following the unsubscribe instructions included in our marketing communications or changing your notification settings within your FullContact Account.
2.4 Combine Contacts for Identity Resolution & Verification Services
Certain categories of Personal Data may be combined to build more complete contact records of individuals (“Completed Contact Data”). Completed Contact Data reside in the FullContact Database and may be processed for the following purposes in connection with providing Identity Resolution and Verification Services:
- Grouping contacts and contact elements into unique individuals to create Completed Contact Data.
- Generating and returning a unique identifier for an individual and associated Completed Contact Data
- Linking (or “matching”) input contact records to Completed Contact Data for purposes of identifying an individual, searching for an individual, and/or linking to other contact records (such as those submitted by 3rd-parties) associated with the same individual.
- Deduplicating a set of input contact records based on unique individuals
- Inferring linkages between and/or deduplicating existing Completed Contact Data
- Verifying the accuracy and recency of contact elements contained within input contact records
For example, someone may search or lookup a Contact by name and email address. FullContact connects the name and email with a Completed Contact Data within the FullContact Database for one of the reasons above. No additional Contact Data beyond the unique identifier are returned to the User submitting the search.
2.5 Combine Contacts for Contact Enrichment Services
Certain categories of Personal Data may be made available to our customers and partners in connection with providing Enrichment Services.
Contact enrichment is often combined with Identity Resolution so that, for example, a User is able to match a Contact that they possess to our Completed Contact Data, and receive back a subset of the contact information from the relevant Completed Contact Data for that individual and/or other contacts records linked to the same individual. For example, we may return an individual’s name to support features such as caller ID. Other examples of data that may be returned by our Enrichment Services include: social handles, hashed identifiers, basic demographic information, profile photos, consumer interests, and professional information such as business emails, organizational affiliation and job title. See our developer docs for a list of currently available enrichment data.
2.6 Creation of Deidentified, Aggregate, or Anonymous Information
We may create Deidentified Information, Aggregate Information, or Anonymous Information records from Personal Data by excluding certain private data in a manner that makes the data not personally identifiable. We use this Deidentified Information, Aggregate Information, or Anonymous Information to analyze request and usage patterns so that we may enhance the content of our Services and improve Site navigation. FullContact reserves the right to use Deidentified Information, Aggregate Information, and Anonymous Information for any purpose, including providing Services to our Users, and disclose Deidentified Information, Aggregate Information, and Anonymous Information to third parties in its sole discretion, including (but not limited to) regulatory compliance, industry and market analysis, demographic profiling, modeling, marketing and advertising, and other business purposes.
- HOW PERSONAL DATA IS SHARED
3.1 When You Consent, Agree or Direct Us to Share
You may authorize us to disclose your Personal Data to others, such as when you connect a third party application or website to access your FullContact Account, when you participate in promotional activities conducted by FullContact partners or third parties or when you exercise consent as requested in the use of our Services.
3.2 Sharing Between Users
3.3 Compliance with Law, Responding to Legal Requests, Preventing Harm, and Protection of Yours or Our Rights
3.4 Service Providers
FullContact uses a variety of third party service providers to help us provide our Services. These Service providers may be located anywhere worldwide in countries outside your country of residence. In particular, currently use service providers based in Europe, India, Asia Pacific and North and South America.
In order to facilitate payments for Services we provide, certain information as described above may be shared with the relevant payments service providers. This payment related data sharing is necessary for the performance of the contract between you and us.
3.5 Corporate Affiliates
To enable or support us in providing the Services, we may share your Personal Data, in compliance with local data privacy laws, within our corporate family of companies that are related by common ownership or control.
- Sharing with FullContact, Inc. Even if your country of residence is not the United States, your Personal Data may be shared with FullContact, Inc. which provides the technical infrastructure for the Services, product development and maintenance, customer support, trust and safety and other business operation services to other FullContact affiliates and subsidiaries.
- Sharing with FullContact Affiliates and Subsidiaries. Your Personal Data may be shared with our wholly owned affiliates and subsidiaries. Personal Data shared in these circumstances may include Contact information.
3.6 Social Media Platforms
Where permissible according to applicable law we may use certain derivative Personal Data about you, such as a cryptographic hash of a personal email and share it with social media platforms, such as Facebook or Google, to generate leads, drive traffic to our Sites or otherwise promote our Services. The social media platforms with which we may share your Personal Data are not controlled or supervised by FullContact. Therefore, any questions regarding how your social media platform processes your Personal Data should be directed to such platform.
Please note that you may, at any time ask FullContact to cease processing your Personal Data for these direct marketing purposes by sending an email to: opt-out@FullContact.com.
3.7 Business Transfers
If FullContact undertakes or is involved in any merger, acquisition, reorganization, sale of assets, bankruptcy, or insolvency event, then we may sell, transfer or share some or all of our assets, including your Personal Data, in connection with such transaction, or in preparation for or contemplation of such transaction (e.g., due diligence).
- PERSONAL DATA RETENTION
We generally retain your Personal Data for as long as is necessary for the performance of the Services to you and our other Users and to comply with our legal obligations. This includes information that you have made available to the FullContact Database for the purposes of improving the Services for both you and other Users of our Services.
You may request that we delete your Personal Data and close your FullContact Account or you can delete your End User Contact Data and close your Account on your own. Please note that if you request the deletion of your Personal Data or if you delete your Personal Data:
- We may retain some of your information as necessary for fraud detection and prevention and enhancing safety. For example, if we suspend a FullContact Account for fraud or safety reasons, we may retain certain information from that Account to prevent that user from opening a new FullContact Account in the future.
- We may retain and use your information to the extent necessary to comply with our legal obligations. For example, we may keep some of your information for tax, legal reporting, and auditing obligations.
- Information you have shared with other systems (e.g., Google) may continue to exist in those systems, and in some cases be publicly visible.
- Some copies of your information (e.g., log records) may remain in the FullContact Database, but are disassociated from personal identifiers.
- Because we maintain backup to protect our Services from accidental or malicious loss and destruction, residual copies of your information will be included in backups and may not be removed from our backup systems.
- THIRD PARTY WEBSITES
- PERSONAL DATA PROTECTION
We have implemented reasonable and appropriate administrative, technical, organizational, and physical measures to help protect your Personal Data. Some of the safeguards we use to protect your Personal Data are firewalls and data encryption, and information access controls. If you know or have reason to believe that your Account ID have been lost, stolen, misappropriated, or otherwise compromised or in case of any actual or suspected unauthorized use of your Account, please contact us following the instructions in the “Contact Us” Section below.
6.2. Our International Operations and Data Transfers
6.3 EU-US and Swiss-US Privacy Shield
With respect to Personal Data received or transferred pursuant to the Privacy Shield Framework, FullContact is subject to the authority of the Federal Trade Commission. If you have any questions or concerns relating to our Privacy Shield certification, contact us at: FullContact, Inc., Legal Department, 1200 17th St., Denver, CO 80202 or via email firstname.lastname@example.org. If we are not able to resolve your concern, you may also contact our designated Privacy Shield independent dispute resolution provider, BBB EU Privacy Shield. In certain circumstances, you may also have the right to pursue binding arbitration through the Privacy Shield Framework, as described in Annex I to the Privacy Shield Principles.
- YOUR RIGHTS
7.1 Email Choices
7.2 Access, Correction, and Deletion
FullContact allows any individual, including the End Users of our Services, to access, modify, and set permissions with respect to Personal Data that it holds about them. You and any individual may access and make corrections and choices about their Personal Data by choosing “Own Your Personal Data” on the FullContact Site.
Please note however that, if you request that we delete your Personal Data, we will not do so to protect your rights and freedoms because, if we do, another User may later upload your contact information and we will not have a record that you requested that your contact information be deleted. Were permitted or required by applicable law, instead of deleting your End User Contact Data from the FullContact Database, we will retain it but flag it, restrict any further processing and not use or share it with any third parties. Finally, FullContact provides you with the ability to export your Personal Data, End User Contact Data, or Completed Contact Data from some of our Services at any time using industry standard formats.
Further information for data subjects can be found at Privacy Notice for Data Subjects.
- CALIFORNIA PRIVACY RIGHTS
8.1 Notice of Disclosure for California Residents. FullContact must disclose whether the following categories of Personal Data are disclosed for a “business purpose” or “valuable consideration” as those terms are defined under California law. Note that while a category below may be marked, that does not necessarily mean that we have Personal Data in that category about you. In the preceding twelve months, we have disclosed the following categories of Personal Data in the manner described.
||Personal Data is Disclosed for a Business Purpose
||Personal Data is Disclosed for Valuable Consideration
|1.1.a. Contact Information
|1.1.b. Payment Information
|1.1.c. Product Related Communication
|1.1.d Usage Data
|1.1.e. Connected 3rd Party Services/Integrations
|1.2.a. Contact Data
|1.3.c Ad Networks
|1.4.a Open Data
|1.4.b Data Providers
|1.5.a Prospect Lists
8.2 Right to Opt Out of Disclosure of Personal Data for Valuable Consideration. Residents of California have the right to direct us to not sell Personal Data. To exercise the right to opt-out, you (or your authorized agent) may submit a request to us by visiting the following link: “Own Your Personal Data”. Once you make an opt-out request, we will wait at least twelve months before asking you to reauthorize Personal Data sales. However, you may change your mind and opt back into Personal Data sales at any time by visiting the following webpage link: “Own Your Personal Data”. You do not need to create an Account with us to exercise your opt-out rights. We will only use Personal Data provided in an opt-out request to review and comply with the request.
- EUROPEAN PRIVACY RIGHTS
In the use of our Services we mainly act as data processor and, in some cases, we may act as data controller when we determine the purposes and means of the processing of Personal Data.
EEA residents may exercise any of the rights described in this Section by using the applicable functionality in our Services or by contacting us directly. If you reside outside of the European Union, you may have similar rights under your local laws. Please note that we may ask you to verify your identity before taking action on your request.
9.1 Purposes and Legal Basis for Processing.
The purposes for processing are described in detail in Section 2 (“HOW WE USE PERSONAL DATA”). In the use of our Services when we act as data controller the legal basis for processing is as follows:
- Provide, Maintain, and Support the Services (Section 2.1): This use is based on our legitimate interest to deliver the Services to you and for the performance of a contract.
- Improve, Personalize, and Develop Services (Section 2.2): This use is based on our legitimate interest to deliver the Services to you and for the performance of a contract.
- Provide, Personalize, Measure, and Improve our Advertising and Marketing (Section 2.3): This use is based on our legitimate interest in marketing our Services, for the performance of a contract, and is based on your explicit consent.
- Combine Contacts for Identity Resolution & Verification Services (Section 2.4): This use is necessary to deliver certain Services to you in the performance of a contract, is based on our legitimate interest, and is based on your explicit consent.
- Combine Contacts for Contact Enrichment Services (Section 2.5): This use is necessary to deliver certain Services to you in the performance of a contract, is based on our legitimate interest, and is based on your explicit consent.
- Creation of Deidentified, Aggregate, or Anonymous Information (Section 2.6): This use is based on our legitimate interests to improve and market our Services.
9.2 Categories of Recipients of Data.
Recipients of data are detailed in Section 3 (“HOW PERSONAL DATA IS SHARED”).
9.3 Rectification of Inaccurate or Incomplete Information.
You have the right to ask us to correct inaccurate or incomplete Personal Data concerning you (and which you cannot update yourself within your FullContact Account).
9.4 Data Access and Portability.
In some jurisdictions, applicable law may entitle you to request copies of your Personal Data held by us. You may also be entitled to request copies of Personal Data that you have provided to us in a structured, commonly used, and machine-readable format, or request us to transmit this information to another service provider (where technically feasible).
9.5 Withdrawing Consent and Restriction of Processing.
Where you have provided your consent to the processing of your Personal Data by FullContact you may easily withdraw your consent at any time specifying which consent you are withdrawing. Please note that the withdrawal of your consent does not affect the lawfulness of any processing activities based on such consent before its withdrawal. Additionally, in some jurisdictions, applicable law may give you the right to limit the ways in which we use your Personal Data, in particular where (a) you contest the accuracy of your Personal Data; (b) the processing is unlawful and you oppose the erasure of your Personal Data; (c) we no longer need your Personal Data for the purposes of the processing, but you require the information for the establishment, exercise or defense of legal claims; or (d) you have objected to the processing pursuant to section below titled “Objection to Processing” and pending the verification whether the legitimate grounds of FullContact override your own.
9.6 Objection to Processing.
In some jurisdictions, applicable law may entitle you to require FullContact not to process your Personal Data for certain specific purposes, where such processing is based on legitimate interest. If you object to such processing we will no longer process your Personal Data for these purposes unless we can demonstrate compelling legitimate grounds for such processing or such processing is required for the establishment, exercise, or defense of legal claims.
Where your Personal Data is processed for direct marketing purposes, you may, at any time, ask us to cease processing your Personal Data for these direct marketing purposes by sending an email to: email@example.com.
9.7 Lodging Complaints.
You have the right to lodge complaints about the data processing activities carried out by us before the competent data protection authorities. If you are an EEA resident, you have the right to file a complaint with your applicable data protection authority.
- EXERCISING YOUR PRIVACY RIGHTS
10.1 No Fee Usually Required.
You will not have to pay a fee to access your Personal Data (or to exercise any of the other rights). However, we may charge a reasonable fee or decline to comply with your request if your request is clearly unfounded, repetitive, or excessive.
10.2 What We May Need from You.
When exercising your rights or otherwise assisting you, we may need to request specific information from you to help us confirm your identity. This is a security measure to ensure we do not disclose your Personal Data to any person who is not entitled to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
10.3 Time to Respond.
We try to respond to all legitimate requests within 30 days of your request. Occasionally it may take us longer than 30 days to respond, for instance if your request is particularly complex or you have made a number of requests. In this case, we will notify you of the delay, and may continue to update you regarding the progress of our response.
10.4 No Discrimination.
You will not be subject to discrimination as a result of exercising the rights described herein. In some cases, when you exercise one of your rights, we will be unable to comply with the request due to legal obligations or otherwise, or we will be unable to provide you certain products or services. These responses are not discrimination and our reasons for declining your request or ceasing services will be provided at that time.
10.5 Authorized Agent.
You may designate an authorized agent to make a request on your behalf. In order to designate an authorized agent to make a request on your behalf, you must provide a valid power of attorney, the requester’s identification information, and the authorized agent’s identification information.
- HOW TO CONTACT US
FullContact Inc. (a Delaware Company)
1200 17th Street, Suite 13-103 Denver, Colorado 80202
Addendum – 1.1 FullContact EU Privacy Shield Certification Information
EU-US Privacy Shield Certification
The following information aligns FullContact Privacy Statement with the specific points required by the Privacy Shield self-certification process, and ensures FullContact’s compliance with the EU-US Privacy Shield Framework.
FullContact has further committed to refer unresolved privacy complaints under the EU-US Privacy Shield Principles BBB EU PRIVACY SHIELD, a non-profit alternative dispute resolution provider located in the United States and operated by the Council of Better Business Bureaus.
If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed, please visit www.bbb.org/EU-privacy-shield/for-eu-consumers for more information and to file a complaint.
Please note that if your complaint is not resolved through these channels, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.
FullContact is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).”
- FullContact Inc. (a Delaware Company)
- 1200 17th Street Denver, Colorado 80202
Contact FullContact at the following email address or phone number for handling of complaints, access requests, and any other issues concerning FullContact’s compliance with the EU-US Privacy Shield Framework.
Data Protection Officer
Certifying FullContact compliance with the Privacy Shield Framework:
Chief Financial Officer
FullContact subsidiaries also adhering to the Privacy Shield Principles:
- CoBook SIA (a Latvian Company)
- nGame Inc. (a Delaware corporation)
- FullContact International, LLC (a Delaware corporation)
- Gentoo Labs, Inc. (a Delaware corporation)
Note differences in this policy regarding the term “human resources data”. Human Resources Data refers to personal data about employees, past or present, collected in the context of the employment relationship. Information other than Human Resources data includes the following: customer, client, visitor, and clinical trial data.
Purposes for which FullContact collects and processes personal data in reliance on the Privacy Shield:
User’s RIGHT to access their data:
FullContact takes privacy, trust and the management of personal information very seriously. Our link to manage your publicly available contact information is here – Own Your Personal Data. Through this interface a user can;
- Control and promote your single online identity
- Control the information that others see about you
- Correct data that is no longer valid
- Opt out completely and remove the public information that we have for your contact record
FullContact’s independent recourse mechanism:
- FullContact’s SOC 2 Audits are performed by The Moore Group, CPA firm
Federal Trade Commission will serve as the statutory body and has jurisdiction to investigate claims against FullContact regarding possible unfair or deceptive practices and violations of laws or regulations covering privacy.
FullContact Privacy Program Initiatives and Memberships
- FullContact retains the CPA Firm The Moore Group as our external SOC 2 Type Two audit and compliance resource.
- The Moore Group performs external audits to ensure FullContact’s compliance with currently advertised control levels
- The Moore Group can be found online at http://www.sas70certifications.com
- FullContact’s annual revenue as of December 31st, 2018 was between $5-25 Million
- FullContact’s industry sector is “Technology”
- FullContact currently employs between 100-250 people