Effective starting: December 31, 2019
For individuals in the EU, California and Nevada please see our supplemental policies below. These supplemental policies specifically describe the rights you may have and our contact details.
• What information we collect
• How we use and share your information
• The choices available to you regarding our use of your Personal Information and how you can access and update this information.
“PBI® Services” include our:
· • Website
· • SaaS Products
but do not include:
· • Third Party Products: these are third-party products or services that you may choose to integrate with a PBI product or services. You should always review the policies of third-party products and services to make sure you are comfortable with the ways in which they collect and use your information.
A “Device” is any computer used to access the PBI Services, including without limitation a desktop, laptop, mobile phone, tablet or other consumer electronic device.
“You” or “your” refers to the individual who uses this website or our services, or directly contacts us.
The terms “using” and “processing” information include subjecting the information to statistical or other analysis and using or handling information in any way, including, but not limited to collecting, storing, evaluating, modifying, deleting, using, combining, disclosing and transferring information within our organization.
Add-On: a bundle of code, resources and configuration files that can be used with a PBI product to add new functionality or to change the behavior of that product’s existing features.
Content: any information or data that you upload, submit, post, create, transmit, store or display in a PBI Service.
Personal Information: information that may be used to readily identify or contact you as an individual person, such as: name, address, e-mail address, or telephone number, login information, marketing preferences, company affiliation, or payment card information. Personal information also includes other pieces of information which can be used to identify you, either directly or indirectly, such as a cookie.
Personal information may become available to PBI through your use of our website and through your submission of additional information to PBI. Our collection and use of your personal information will depend on the extent to which you provide us with your personal information through this website, when and if our website requests information from you. We may also combine information about you that we have with information we obtain from other sources.
Personal information does not include information that has been anonymized such that it does not allow for the ready identification of specific individuals.
Website: the www.portfoliobi.com website and any related websites, sub-domains and pages.
Changes to this Privacy Statement
What type of information do we collect?
We collect personal information if you request products or services from us, use an on-line form to send information to us or anytime you request information from us. We collect the following information:
Account and Profile Information: We collect information about you and your company as you register for an account, create or modify your profile, make purchases through, use, access, or interact with the PBI Services (including but not limited to when you upload, download, collaborate on or share Content). Information we collect includes:
· • Contact information such as name, e-mail address, mailing address and phone number
· • Billing information such as account numbers and billing address
· • Profile information such as username and job title
· • Preferences information such as notification and marketing preferences
You may provide this information directly when you enter it.
In some other cases another user (such as a system administrator) may create an account on your behalf and may provide your information, including Personal Information (most commonly when your company requests that you use our products or services). We collect information under the direction of our clients and often have no direct relationship with the individuals whose personal
Content: We collect and store Content that you create, input, submit, post, upload, transmit, store or display in the process of using our SaaS Products or Website. Such Content includes any Personal Information or other sensitive information that you choose to include (“Incidentally-collected Personal Information”).
Other submissions: We collect other data that you submit to our website or as you participate in any interactive features of the PBI Services, participate in a survey, promotion, activity, event, apply for a job, request client support, communicate with us via e-mail or otherwise communicate with us. For example, information regarding a problem you are experiencing with a PBI
product could be submitted to our Support Services.
Information you provide to us and we collect from your use of Portfolio BI Services
Web Logs: As is true with most websites and services delivered over the Internet, we gather certain information and store it in log files when you interact with our Website and SaaS Products. This information includes:
· • the date and time of your website visit
· • what pages you went to and information you search for
· • locale and language preferences
· • identification numbers associated with your Devices, your mobile carrier and system configuration information
· • the site you had been to before you came to us
· • the type of browser you are using
· • your operating system and URLs of referring/exit pages
· • your internet protocol (IP) address
· • your server address and internet services provider
In the case of our SaaS Product, the URLs you accessed (and therefore included in our log files) include usernames as well as elements of Content as necessary for the SaaS Product to perform the requested operations.
Analytics Information from Website and SaaS Products: We collect analytics information when you use our Website and SaaS Products to help us improve our products and services as well as improve our websites and to guarantee their security and continued proper functioning.
In the SaaS Products, this analytics information consists of the feature and function of the PBI Service being used, the associated license identifier and domain name, the username and IP address of the individual who is using the feature or function (which will include Personal Information if the Personal Information was incorporated into the username), the sizes and original filenames of attachments, and additional information required to detail the operation of the function and which parts of the PBI Services are being affected. As such, the analytics information we collect may include Personal Information or sensitive business information that the user has included in Content that the user chose to upload, submit, post, create, transmit, store or display in a PBI Service.
Analytics Information Derived from Content. Analytics information also consists of data we collect as a result of running queries against Content across our user base for the purposes of generating Usage Data. “Usage Data” is aggregated data about a group or category of services, features or users that does not contain Personal Information. Though we may happen upon sensitive or Personal Information as we compile Usage Data from Content across user instances, this a byproduct of our efforts to understand broader patterns and trends. It is not a concerted effort by us to examine the Content of any particular customer.
Cookies and Other Tracking Technologies
We use various Internet technologies alone or in combination to collect information about you and your use of our website for many reasons, such as administering and facilitating your access to and use of our website, understanding your behavior on our website, and analyzing usage behavior and target advertising to you.
You can instruct your browser, by changing its options, to stop accepting cookies or to prompt you before accepting a cookies from websites you visit. If you do not accept cookies, however, you may not be able to use all aspects of our Website or SaaS Products. Portfolio BI and our third-party partners also collect information using web beacons (also known as “tracking pixels”). Web beacons are electronic images that help us to deliver cookies, count visits, understand usage and campaign effectiveness and determine whether an e-mail has been opened and acted upon.
Opt-Out from the setting of cookies on your individual browser
In addition to utilizing the user preference center, where available, you may opt-out from the collection of non-essential device and usage data on your web browser (see the “What device and usage data we process” section, above) by managing your cookies at the individual browser level. In addition, if you wish to opt-out of interest-based advertising or targeted advertising that is
provided to us and to third parties by Portfolio BI DMP, please send an email request to email@example.com. Please note, however, that by blocking or deleting cookies and similar technologies used on our websites, you may not be able to take full advantage of the websites.
While some internet browsers offer a “do not track” or “DNT” option that lets you tell websites that you do not want to have your online activities tracked, these features are not yet uniform and there is no common standard that has been adopted by industry groups, technology companies or regulators. Therefore, we do not currently commit to responding to browsers’ DNT signals with respect to our websites. Portfolio BI takes privacy and meaningful choice seriously and will make efforts to continue to monitor developments around DNT browser technology and the implementation of a standard.
How we use Information we collect
General Uses: We use the Information we collect about you (including Personal Information to the extent applicable) for a variety of purposes and on the legal bases including to:
· • process and complete transactions and send you related information;
· • verify financial information and to collect payments to the extent that doing so is necessary to complete a transaction and perform our contract with you;
· • send transactional messages, including responding to your comments, questions, and requests, providing client service and support, and sending you technical notices, updates, upgrades, security alerts, and support and administrative messages; if you fill out a “Contact Me” web form or request user support, or if you contact us by other means including via a phone call, we process your Personal Data to perform our contract with you and to the extent it is necessary for our legitimate interest in fulfilling your requests and communicating with you;
· • send promotional communications, such as providing you with information about services, features, surveys, newsletters, offers events and sending updates; and providing other news or information about us and our select partners. You have the ability to opt out of receiving any of these communications as described below under “Your choices”;
· • monitor and analyze trends, usage and activities in connection with PBI Services and for marketing or advertising purposes; We process your Personal Data to conduct marketing research, advertise to you, provide personalized information about us on and off our websites and to provide other personalized content based upon your activities and interests to the extent it is necessary for our legitimate interest in advertising our websites or, where necessary, to the extent you have provided your prior consent;
· • assessing and improving user experience: we process device and usage data in order to analyze trends and to assess and improve the overall user experience to the extent it is necessary for our legitimate interest in developing and improving the service offering, or where we seek your valid consent;
· • promoting the security of our websites and services: we process your Personal Data by tracking use of our websites and services, creating aggregated, non-personal data, verifying accounts and activity, investigating suspicious activity and enforcing our terms and policies, to the extent this is necessary for our legitimate interest in promoting the safety and security of the services, systems and applications and in protecting our rights and the rights of other investigate and prevent fraudulent transactions, unauthorized access to PBI Services, and other illegal activities;
· • enable you to communicate, collaborate, and share Content with users you designate;
· • complying with legal obligations: we process your Personal Data when cooperating with public and government authorities, courts or regulators in accordance with our legal obligations under applicable laws to the extent this requires the processing or disclosure of Personal Data to protect our rights or is necessary for our legitimate interest in protecting against misuse or abuse of our websites, protecting personal property or safety, pursuing remedies available to us and limiting our damages, complying with judicial proceedings, court orders or legal processes or to respond to lawful requests.
· • for other purposes about which we obtain your consent.
Notwithstanding the foregoing, we will not use Personal Information appearing in our Analytics Logos or Web Logs for any other purpose. The use of Information collected through our Portfolio BI Services shall be limited to the purposes disclosed in this policy.
Information sharing and disclosure
We will not share or disclose any of your Personal Information or Content with third parties except as described in this policy. We do not sell your Personal Information or Content.
Access by your system administrator: You should be aware that the administrator of your PBI Services may be able to:
· • access information in and about your PBI Services account;
· • access communications history, including file attachments, for your PBI Services account;
· • disclose, restrict, or access information that you have provided or that is made available to you when using your PBI Services account, including your Content; and
· • control how your PBI Services account may be accessed or deleted.
Access by Service Providers, Business Partners and Others: We work with third party service providers to provide Website, application development, hosting, maintenance, back-up, storage, virtual infrastructure, payment processing, analysis, security enhancement, research and analytics, marketing, customer support and data enrichment as well as in individual instances, with professional advisers acting as processors or joint controllers including lawyers, bankers, auditors and insurers who provide consultancy, banking, legal, insurance and accounting services, and to the extent we are legally obliged to share or have a legitimate interest in sharing your Personal Data; these service providers may have access to or process your information for the purpose and pursuant to the legal bases of providing those services for us. Please be aware that you are providing your information to these third parties acting on behalf of Portfolio BI.
Access with affiliates within Portfolio BI corporate group and companies that we acquire in the future when they are made part of the Portfolio BI corporate group, to the extent such sharing of data is necessary to fulfill a request you have submitted via our websites or for customer support, marketing, technical operations and account management purposes.
If we are involved in a merger, reorganization, dissolution or other fundamental corporate change, or sell a website or business unit, or if all or a portion of our business, assets or stock are acquired by third party, with such third party, we will use reasonable efforts to notify you of any transfer of Personal Data to an unaffiliated third party.
What about websites you link to?
Security of information
We maintain industry-standard physical, electronic, and procedural safeguards to guard your Personal Information. All Personal Information is stored in a database and may be used to create a profile to customize our response to your requests. In addition, PBI has technological and operational security policies and procedures in place to protect your personally identifiable information from loss, misuse, alteration or unintentional destruction. Our personnel have been trained to maintain the privacy and security of such information.
It is also important for you to protect against unauthorized access to your password and to your computer.
If you send us a resume or curriculum vitae (CV), such as to apply online for a position with PBI, we will use this personal information provided to match you with available opportunities.
Our policy towards children
Portfolio BI Services are not directed to individuals under 13. Children should not have access to the Portfolio BI website without parental permission. We do not knowingly collect Personal Information from children under 13. If we become aware that a child under 13 has provided us with Personal Information, we will take steps to delete such information. If you become aware that a child has provided us with Personal Information, please contact us at firstname.lastname@example.org.
We will use reasonable efforts to ensure that our communications activities comply with applicable law and to implement procedures to obtain necessary permissions before sending you e-mails with information about Portfolio BI’s products and services. At any time, you may request that we discontinue sending you promotional materials, and we will use reasonable efforts to comply with your request. Please follow the opt-out instructions provided in our communication or contact us at email@example.com.
Portfolio BI does not rent, sell or share personal information about you with other people, companies or other entities, unless you specifically provide to Portfolio BI your permission to do so.
Portfolio BI does not knowingly collect or utilize any sensitive personal information, such as, health information, full financial account information, or government identifiers. In the EEA, we do not knowingly collect or utilize any personal information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic or biometric data for the purpose of uniquely identifying an individual, or data concerning an individual’s health, sex life, or sexual orientation. We ask that you not provide us with such information.
Storing and Processing Your Information
Your information may be collected, accessed, processed and stored in the United States as well as in any other country where we or our affiliates maintain facilities. The servers on which Personal Information is stored are kept in a controlled environment. While we take reasonable efforts to guard your Personal Information, no security system is impenetrable and due to the inherent nature of the Internet as an open global communications vehicle, we cannot guarantee that information, during transmission through the Internet or while stored on our systems or otherwise in our care, will be absolutely safe from intrusion by others, such as hackers. In addition, we cannot guarantee that any incidentally-collected Personal Information you choose to store in websites or SaaS Products are maintained at levels of protection to meet specific needs or obligations you may have relating to that information. Where data is transferred over the Internet as part of a Website or SaaS Product, the data is encrypted using industry standard SSL (HTTPS).
We retain your personal information where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax, or accounting requirements) and for a period of time consistent with the original purpose as described in this Notice. We determine the appropriate retention period for personal information
on the basis of the amount, nature, and sensitivity of your personal information processed, the potential risk of harm from unauthorized use or disclosure of your personal information and whether we can achieve the purposes of the processing through other means, as well as on the basis of applicable legal requirements (such as applicable statutes of limitation).
After expiration of the applicable retention periods, we will either delete or anonymize your personal information or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
Compliance with Laws and Law Enforcement Requests; Protection of our Rights: We may disclose your information (including your Personal Information) to a third party if (a) we believe that disclosure is reasonably necessary to comply with any applicable law, regulation, legal process or governmental request, (b) to enforce our agreements, policies and terms of service, (c) to protect the security or integrity of Portfolio BI’s products and services, (d) to protect Portfolio BI, our customers or the public from harm or illegal activities, or (e) to respond to an emergency which we believe in the good faith requires us to disclose information to assist in preventing the death or serious bodily injury of any person. Portfolio BI will respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims. We may also share your personal information in order to investigate, prevent, or take action against illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of Portfolio BI Terms and Conditions, or as otherwise required by law.
Business Transfers: We may share or transfer your Information (including your Personal Information) in connection with, or during negotiations of any merger, sale of company assets, financing or acquisition of all or a portion of our business of another company. In the event that Portfolio BI or any of its assets are acquired by a third party, Personal Information held by Portfolio BI may be one of the assets transferred. In such an event, we will notify you as explained below, under “Changes to this Privacy Statement.”
Aggregated or Anonymized Data: We may also share aggregated or anonymized information that does not directly identify you with the third parties described above.
With Your Consent. We will share your Personal Information with third parties when we have your consent to do so.
Information We Do Not Share
We do not share Personal Information about you with third parties for their marketing purposes (including direct marketing purposes) without your permission.
You may opt out of receiving promotional communication from Portfolio BI by using the unsubscribe link within each e-mail or sending us an e-mail at firstname.lastname@example.org to have your contact information removed from our promotional e-mail list or registration database. Although opt-out requests are usually processed immediately, please allow ten (10) business days for a removal request to be processed. Even after you opt out from receiving promotional messages
from us, you may continue to receive transactional messages from us regarding Portfolio BI Services.
Your Privacy Rights
You may have certain rights relating to your Personal Data, subject to local data protection laws.
In particular, if you are located in the EEA and UK these rights include:
• To access your Personal Data held by us (right to access);
• To rectify inaccurate Personal Data and, taking into account the purpose of processing the Personal Data, ensure it is complete (right to rectification);
• To erase/delete your Personal Data, to the extent permitted by applicable data protection laws (right to erasure; right to be forgotten);
• To restrict our processing of your Personal Data, to the extent permitted by law (right to restriction of processing);
• To transfer your Personal Data to another controller, to the extent possible (right to data portability);
• To object to any processing of your Personal Data carried out on the basis of our legitimate interests (right to object). Where we process your Personal Data for direct marketing purposes or share it with third parties for their own direct marketing purposes, you can exercise your right to object at any time to such processing without having to provide any specific reason for such objection;
• Not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects (“Automated Decision-Making”). Automated Decision-Making currently does not take place on our websites or in our services; and
• To the extent we base the collection, processing and sharing of your Personal Data on your consent, to withdraw your consent at any time, without affecting the lawfulness of the processing based on such consent before its withdrawal.
How to exercise your rights
To exercise your rights, please contact us by using the information in the “Contacting us” section, below. We try to respond to all legitimate requests within one month and will contact you if we need additional information from you in order to honor your request. If you are an employee of a Portfolio BI customer, we recommend you contact your company’s system administrator for assistance in correcting or updating your information.
Some registered users may update their user settings, profiles, organization settings and event registrations by logging into their accounts and editing their settings or profiles.
To update your billing information, discontinue your account and/or request return or deletion of your Personal Data and other information associated with your account, please contact us by using the information in the “Contacting us” section, below.
Your rights relating to customer data
As described above, we may also process Personal Data submitted by or for a customer to our cloud products and services. To this end, if not stated otherwise in this Privacy Statement or in a separate disclosure, we process such Personal Data in the role of a mere processor on behalf of a customer (and/or its affiliates) who is the responsible controller of the Personal Data concerned .We are not responsible for and have no control over the privacy and data security practices of our customers, which may differ from those set forth in this Privacy Statement. If your data has been submitted to us by or on behalf a Portfolio BI customer and you wish to exercise any rights you may have under applicable data protection laws, please inquire with the applicable customer directly. Because we may only access a customer’s data upon instruction from that customer, if you wish to make your request directly to us, please provide to us the name of the Portfolio BI customer who submitted your data to us. We will refer your request to that customer and will support them as needed in responding to your request within a reasonable timeframe.
Your preferences for email and SMS marketing communications
If we process your Personal Data for the purpose of sending you marketing communications, you may manage your receipt of marketing and non-transactional communications from Portfolio BI by clicking on the “unsubscribe” link located on the bottom of Portfolio BI marketing emails, by replying or texting ‘STOP’ if you receive Portfolio BI SMS communications, or by contacting us at email@example.com requesting to unsubscribe.
Please note that opting out of marketing communications does not opt you out of receiving important business communications related to your current relationship with us, such as communications about your subscriptions or event registrations, service announcements or security information.
Privacy Shield Notice
Portfolio BI (referred to in this policy as “PBI”, “we”, “us” or “our”) complies with the EU-U.S. Privacy Shield Framework and adheres to the Privacy Shield Principles regarding the collection, use, and retention of personal information transferred from the European Union to the U.S.
Under the Privacy Shield Framework, PBI is responsible for the processing of personal data it receives from the EU, the European Economic Area and Switzerland and then transfers to a third party acting as an agent on its behalf. We remain liable in accordance with the Privacy Shield Principles if third-party agents that we engage to process such personal data on our behalf do so in a manner inconsistent with the Privacy Shield Principles, unless we prove that we are not responsible for the event giving rise to the damage. PBI will share your personal information with third parties (i.e., vendors whose services PBI uses to deliver, maintain, or operate our services or business, including to market our services to you). If you wish to limit or restrict the use or sharing/disclosure of your personal information, you can email us at firstname.lastname@example.org.
As further explained in the “International Users; Privacy Shield” section below, we encourage you to contact us should you have a Privacy Shield-related (or general privacy-related) complaint. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S. based third party dispute resolutions provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Under certain conditions, more fully described on the Privacy Shield website, if you are an EU, European Economic Area country or Swiss resident, you may invoke binding arbitration when other dispute resolution procedures have been exhausted. As further explained in the Privacy Shield Principles, a binding arbitration option will also be made available to you in order to address residual complaints not resolved by any other means. PBI is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (“FTC”).
Privacy Shield Related Complaints
If you are visiting from the European Union, the European Economic Area, Switzerland or other regions with laws governing data collection and use, please note that you are agreeing to transfer of your Personal Information to the United States to us. By providing your Personal Information, you consent to any transfer and processing in accordance with this Policy.
Supplemental Privacy Notice for California Consumers
While we hope to do more business with residents of California, we currently are not required to comply with the California Consumer Protection Act or CCPA. Nonetheless, PBI is committed to compliance with data protection laws as part of our commitment to conducting our business ethically and to observing applicable laws, rules and regulations. On a discretionary basis PBI may respond to California residents regarding their data. In general, California residents have:
· • The right to know the categories of data we have collection and the categories of sources;
· • The right to know the business purposes for sharing the data;
· • The right to know the categories of third parties with whom we have shared data; and
· • The right to access the specific pieces of data we process and the right to delete your data.
We will attempt to accommodate any requests from California residents in accordance with our general verification procedures.
California provides the following rights to its consumers. PBI will seek to honor these rights even though it does not meet the thresholds for compliance. If you would like to:
· • Request the general categories of information we collect about you;
· • Opt-out of sharing, disclosure, or sale of personal information; or
· • Request the deletion of personal information:
You may submit a request by either calling us at 888-995-1262 or by emailing us at: email@example.com. We may ask you to provide additional information to verify your request.
With respect to any request for deletion of information, there is no requirement to delete information if it is necessary to retain in order to:
• Complete the transaction for which the personal information was collected, provide a good or service requested by you, or a transaction reasonably anticipated within the context of our or one of our affiliate’s ongoing business relationship with you, or to otherwise perform a contract we have with you;
• Detect security incidents, protect against malicious, deceptive, fraudulent or illegal activity or prosecute those responsible for that activity;
• Facilitate solely internal uses that are reasonably aligned with your expectations based on your relationship with us or one of our affiliates;
• Comply with a legal obligation; or
• Otherwise use the personal information, internally, in a lawful manner that is compatible with the context in which it was provided.
Supplemental Privacy Notice for Nevada Residents
Personal Information Collection and Purposes of Use
Unless specifically stated, we do not share, disclose or sell personal information to third parties for their own use, but we do share your personal information with those who support our business. In these arrangements, use of the information we share is limited by policies, contracts, or similar restrictions.
Your Nevada Privacy Rights
You have the right to access and/or correct your personal information, or opt out of the sale of personal information.
We generally do not disclose or share personal information for profit. Under Nevada law, you have the right to direct us to not sell or license your personal information to third parties.
To exercise any rights under Nevada law, if applicable, you or your authorized representative may submit a request to firstname.lastname@example.org. We will respond to your verified request as soon as reasonably practicable, but no later than sixty (60) days after receipt. If circumstances cause any delay in our response, you will be promptly notified and provided a date for our response.
Changes to this Privacy Statement
We will update this Privacy Statement from time to time to reflect changes in our practices, technologies, legal requirements and other factors. If we do, we will update the “effective date” at the top of this Privacy Statement. If we make a material update, we may provide you with notice prior to the update taking effect, such as by posting a conspicuous notice on our website or by contacting you using the email address you provided.
We encourage you to periodically review this Privacy Statement to stay informed about our collection, processing and sharing of your Personal Data.
Questions or Suggestions
To exercise your rights regarding your Personal Data, or if you have questions regarding this Privacy Statement or our privacy practices please mail us at:
Portfolio BI, Inc. 1370 Broadway Floor 11, New York, NY 10018
Toll-Free Number: (888) 995-1262
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, and you are located in the EEA, you have the right to lodge a complaint with the competent supervisory authority.
Effective Date: December 31, 2019