Last Updated August 19, 2019
508 Software is committed to adhering with the EU-US Privacy Shield Framework (the “Framework”) and the Framework’s Principles (“Principles”) regarding all Personal Information received in the United States (“U.S.”) from the European Union (EU) in reliance on the Privacy Shield, and currently is undergoing the certification process for such participation. As such, 508 Software is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC). 508 Software’s commitment to the Framework and Principles is outlined in Sections G & H, below. To learn more about the Framework and Principles You can visit the Privacy Shield Website.
508 Software has created this privacy statement in order to fully disclose its information gathering and dissemination practices for the 508 Software Website and related websites (“Website”), and the products and services offered and provided through the Website (“Products”).
Table of Contents
- Background Information
- A Word from 508 Software
- Information 508 Software Collects
- Information 508 Software Collects Through the Website
- User Content
- Providing Your Information to 508 Software
- User Account
- Third-Party Websites and Service Providers
- Third-Party Applications
- Information Relating to Children (COPPA)
- Cookies and Web Beacons
- Targeting Cookies
- Purpose of Processing & Use and Disclosure of Information
- How Your Personal Information is Used
- Disclosure of Information to Third Parties
- Securing the Transmission and Storage of Information
- Change of Control
- Data Choices Available to You
- Opt-In and Disclosure
- Opt-Out Options
- Registration Email and Contact by 508 Software
- User Account Preferences
- California Residents
- Rights of European Users under the GDPR
- Data Controller
- Data Processor
- Legal Basis for Processing
- GDPR Rights:
- Right of Confirmation
- Right of Access
- Right to Rectification
- Right to Erasure (Right to be Forgotten)
- Right to Restriction of Processing
- Right to Data Portability
- Right to Object and Automated Decision-Making
- Right to Object to Processing
- Retention Policy
- Cross-Border Data Transfers
- Privacy-Related Inquiries and Complaints
- Privacy Shield Policy
- EU-US Privacy Shield Principles
A. BACKGROUND INFORMATION
- Description of the types of Personal Information (Yours and that of third parties) collected through the Website and Products;
- How collected Personal Information is used;
- With whom the collected Personal Information may be shared;
- The choices available to You regarding the collection, use, and distribution of such information;
- Security procedures that are in place to protect against the loss, misuse, or alteration of Personal Information under 508 Software’s control; and
- Instructions on how You may access and correct any inaccuracies in the information collected about You.
A note about the Website and Products: Some of 508 Software’s Products, data centers, service providers, affiliates, or operating partners and servers may be located in other countries. As such, the Website and Products may be subject to the laws of numerous countries and jurisdictions, some of which may require 508 Software to disclose certain information about its users. 508 Software is committed to keeping Your Personal Information private while using its best efforts to comply with all applicable laws in the jurisdiction(s) in which it operates.
B. A WORD FROM 508 SOFTWARE
In agreement with the General Data Protection Regulation (“GDPR”), 508 Software will provide the utmost respect for and protection of any data/information it receives that could potentially identify You, including Your name, email address, personal telephone number, mailing address, payment information, photos of You, IP address, and any other information that may lead to You being personally identified without Your consent (“Personal Information”).
C. INFORMATION 508 SOFTWARE COLLECTS
Information 508 Software Collects Through the Website
The Website does not collect Personal Information from Your computer when You browse the Website and request pages from 508 Software’s servers. This means that, unless You voluntarily and knowingly provide 508 Software with Personal Information, 508 Software will not know Your name, email address, or any other personally identifiable information.
When You use the Website, 508 Software, or trusted authorized third parties, may also collect certain technical and routing information about Your computer (also known as environment variables) to facilitate Your use of the Website and Products enabled thereby. When You browse the Internet, Your Internet browser (such as Mozilla Firefox, Google Chrome, or Microsoft Internet Explorer) automatically transmits some information to 508 Software every time You access content on one of 508 Software’s Internet domains. Examples of such information include the URL of the particular web page You visited, the IP address of the computer You are using, or the browser version that You are using to access the Website. All of this information may be collected by 508 Software and used to help improve its offerings to You.
Providing Your Information to 508 Software
You never have to provide Personal Information to 508 Software. However, should You choose to withhold certain required information, 508 Software may not be able to provide You with some or all of the Products. Some of the information 508 Software asks You to provide may be identified as mandatory or optional. If You do not provide the mandatory information with respect to a particular activity, You may not be able to engage in that activity or make such a purchase. 508 Software will inform You of the mandatory or optional nature of the requested or required information.
When You submit Personal Information to 508 Software through the Website, You understand and AGREE that this information may be transferred across national boundaries and may be stored and processed in any of the countries in which 508 Software and its affiliates and subsidiaries maintain offices. You also ACKNOWLEDGE that in certain countries or with respect to certain activities, the collection, transferring, storage, and processing of Your information may be undertaken by trusted affiliates of 508 Software. 508 Software may use affiliates to aid in the facilitation of technical support services that may potentially receive limited access to Your Personal Information. Though these affiliates may change from time to time, such affiliates are bound by contract to only process information per 508 Software’s instruction, to provide appropriate measures to protect Personal Information against accidental or unlawful destruction, loss alteration, and unauthorized disclosure or access, to assist 508 Software in responding to individuals exercising their rights under the Framework, and for understanding on whether onward transfers of data is allowed.
Payoneer, PayPal, Tipalti, 2Checkout, and any other third-party payment service providers designated by 508 Software are responsible for payment information You provide 508 Software, which will be subject to their respective privacy policies, such as:
When registering for a User Account, if and as applicable, or otherwise contacting 508 Software in connection with Your interest in any Products, 508 Software may ask You to provide certain information. Such information may include Your name, email, address, phone number, and other personally identifiable information. It is completely optional and voluntary for You to register for a User Account, engage in activities requiring a User Account, or to provide any personal identifiable information. However, certain information, which may be considered Personal Information, may be required for proper identification in order for You to engage in certain services provided by 508 Software or receive technical support.
Once You create a User Account, You will be deemed a Registered User. You may also request to change information associated with Your User Account by contacting 508 Software at email@example.com.
If You wish to deactivate your User Account, You may contact 508 Software at firstname.lastname@example.org. When You deactivate Your personal account, all information stored and maintained as part of Your User Account may be retained for archival, backup and record purposes.
Third-Party Websites and Service Providers
The Website may contain links to websites owned and operated by third parties. These links are presented for Your convenience and information. 508 Software does not control these third-party websites and is not responsible for their privacy practices or content. 508 Software does not control the information collection and distribution policies on such websites other than those that are under the control of 508 Software itself. Content on third-party websites may not reflect Products, services, and/or information provided by 508 Software. Third parties may also set their own cookies and/or use web beacons, which may be used to identify some of Your preferences or to recognize You if You have previously had contact with these third parties. 508 Software does not control the use of such technology by third parties, the information they collect, or how they use such information. You should direct all concerns regarding any third-party website directly or to the site administrator or webmaster.
508 Software also may use third-party advertising companies to serve ads when You visit the Website. These companies may use general information about Your visits to the Website as well as other websites in order to provide ads about goods and services of interest to You. If You would like more information about this practice and Your choices as to not having Your information used by these companies, please direct such concerns to the respective company’s administrator or webmaster, as detailed below under the subheading “Targeting Cookies”, or contact 508 Software’s DPO as outlined in Section G below.
Information Relating to Children (COPPA)
The Children’s Online Privacy Protection Act (COPPA) was passed by the U.S. Congress in November 1998. COPPA provides parents with specific rights regarding their children’s privacy. For additional information and resources on COPPA, please visit the Federal Trade Commission (FTC) website. The 508 Software Website and any Products available therewith are not directed at children under 13 years of age and, therefore, COPPA does not apply. However, 508 Software recognizes that children under the age of 13 may potentially access the Website and subscribe to the newsletter, purchase software and Products, or download software programs. Parents and Legal Guardians may request 508 Software to review, delete or stop the collection of any personally identifiable information of their child(ren). You may do so by contacting 508 Software by email at email@example.com.
Cookies and Web Beacons
The Website uses “cookie” and “web beacon” technology. “Cookies” are short pieces of data generated by a web server that a website stores on a user’s computer. Certain pages on 508 Software’s Website may require the use of a cookie for purposes of keeping information You enter on multiple pages together. Cookies also enable 508 Software to customize the Website and offerings to Your needs and provide You with a better online experience with 508 Software. In addition, cookies are used to:
- Measure usage of various pages on 508 Software’s Website to help make 508 Software’s information more pertinent to Your needs and easier for You to access;
- Identify and categorize the Internet webpages from which a visitor came to the Website and in order to observe browsing patterns; and
- Provide functionality such as online orders, 508 Software Products, and other functionalities that 508 Software believes would be of interest and value to You.
In addition, any service providers 508 Software may use to serve and host advertisements may use session or persistent cookies to track the number of times the Website is accessed and whether the Website was accessed via an ad. There are no automatically-placed cookies within these ads, a cookie is placed on Your computer only if and when You click on an advertisement. The cookie generated from the advertisement does not contain any personally identifiable information and will remain on Your hard drive until You delete it. Furthermore, 508 Software may use email tracking services in order to receive read receipts and related information when sending emails, however, these services are used by 508 Software for these reasons and not to collect any Personal Information about You.
You may set your browser to block cookies (consult the instructions for Your particular browser on how to do this), although doing so may adversely affect Your ability to perform certain transactions, use certain functionalities, and access certain content on the 508 Software Website.
Web beacons are used in combination with cookies to help website operators understand how visitors interact with their websites. A web beacon is typically a transparent graphic image (usually 1-pixel x 1-pixel) that is placed on a website. As opposed to cookies, which are stored on a user’s computer hard drive, web beacons are embedded invisibly on web pages and are about the size of the period at the end of this sentence. These web beacons are not tied to personally identifiable information. The use of web beacons allows a website to measure the actions of the visitor opening the page that contains the web beacon. It makes it easier to follow and record the activities of a recognized browser, such as the path of pages visited on a website. 508 Software uses the information provided by web beacons to develop a better understanding of how the Website’s visitors use the Website, and to facilitate those visitors’ interactions with the Website. 508 Software may make the aggregate data obtained from web analytics (including from its third-party analytics providers, if applicable) publicly available. If this data is made publicly available, none of the information will be personally identifying information or potentially-personally identifying information.
508 Software may use targeting cookies to record Your Website visits, the pages You viewed and the hyperlinks You followed. 508 Software may use this information and share it with third parties to make the Website and advertising more relevant to You.
508 Software’s trusted advertising affiliates help it place advertisements on and off the Website and perform analytics. Please read 508 Software’s current affiliates’ privacy and cookies policies below:
508 Software uses Google Analytics to analyze Website usage, with a performance cookie, which collects standard Internet log and visitor information in an anonymized form. The information collected is transmitted to Google and then used to compile aggregate information on Website usage. 508 Software also uses Google Ads to oversee online advertisements and to determine with which advertisements users most frequently click and respond. These cookies remain on Your device even after You have logged out or quit a session. To opt out of being tracked by Google Ads visit Google Ads Help.
D. PURPOSE OF PROCESSING & USE AND DISCLOSURE OF INFORMATION
How Your Personal Information is Used
508 Software collects Personal Information from You in order to record and support Your participation in the activities provided by 508 Software. 508 Software may use Your email address to send a confirmation email when You sign up for a User Account and, if necessary, may use other information You provide to contact You in order to process a purchase or provide a Product You have selected. Your Personal Information also may be used to keep You informed about Products and special offers.
As described above, 508 Software may collect information about Your use of the Website and Products. 508 Software may use this aggregate, non-identifying statistical data for statistical analysis, marketing, or similar promotional purposes.
Disclosure of Information to Third Parties
508 Software may use the services of third parties, such as email service providers, purchase, shipping and order processing merchants and marketing companies that act as independent contractors on behalf of 508 Software. These parties are prohibited from using personally identifiable information for any purpose other than for the purpose 508 Software specifies and are expected to provide the same level of protection for Personal Information as required by the EU-US Privacy Shield Principles. 508 Software does provide non-personally identifiable information to certain service providers for their use on an aggregated basis for the purpose of performing their contractual obligations to 508 Software. 508 Software prohibits the sale or transfer of Personal Information to entities outside of the 508 Software’s affiliates for their use without Your approval.
Securing the Transmission and Storage of Information
Change of Control
In the event that all or substantially all of 508 Software’s stock and/or all or substantially all assets are transferred or sold to another entity, 508 Software may transfer personally identifiable information to the acquiring entity. If, as a result of such a business transition, Your Personal Information will be used in a materially different manner, You will be given notice as to these different manners and the opportunity to re-consent or object to such material new purposes.
E. DATA CHOICES AVAILABLE TO YOU
Opt-In and Disclosure
You may always choose whether or not to disclose Personal Information and that choice will not prevent You from using the Website and having limited access to the Website and Products. Please note, however, if You should choose to withhold certain requested information, 508 Software may not be able to provide You with some or all of the Products dependent upon the collection of this information. You will be given an opportunity to “opt-in” and select Your preference choices for any items that are optional and which are not prerequisite for 508 Software rendering of services.
You can choose at any time to opt-out of receiving emails from 508 Software by clicking the unsubscribe link at the bottom of any email You receive from 508 Software or by contacting 508 Software directly at firstname.lastname@example.org. If You elect to opt-out, 508 Software will not, as applicable, share Your Personal Information with third parties or send You emails. However, 508 Software may continue to use Your Personal Information for internal purposes, to enhance Your user experience or as necessary to administer the Website or comply with applicable law.
Registration Email and Contact by 508 Software
508 Software reserves the right to send a one-time registration or payment confirmation email, and infrequent service alert messages to users to inform them of specific changes that may impact their ability to use Products or a service that they have previously signed up for, purchased, or used, regardless of email contact opt-in status. 508 Software also reserves the right to contact You if compelled to do so as part of a legal proceeding or if there has been a violation of any applicable licensing, warranty, or purchase agreements. 508 Software is retaining this right because in limited cases 508 Software feels that it may need to contact You as a matter of law or regarding matters that will be important to You. This does not allow 508 Software to contact You to market a new or existing Products if You have asked 508 Software not to do so, and issuance of these types of communications are rare.
User Account Preferences
If and as applicable, when You create a User Account with 508 Software and/or provide Your email address and other personal identification information, subject to Your personal preferences, You CONSENT to allowing 508 Software to periodically contact You via email and provide information about special offers and promotions that may be of interest to You. These communications will relate to 508 Software offers and/or the promotions of select, reputable third parties with whom 508 Software has a strategic marketing relationship because they offer products or services that 508 Software believes would be of interest to You. 508 Software may use a third-party email service provider to send emails to You. This service provider is prohibited from using Your email address for any purpose other than to send 508 Software-related emails. If You do not wish to receive emails with updates and information please unsubscribe by sending an email to email@example.com. In addition, every time You receive an email, You will be provided the choice to opt-out of future emails by following the “unsubscribe” (or similar) instructions provided in the email. You may also opt-out online by updating Your User Account as described under the subheading “User Account” in Section C, above.
To ensure that Your request is honored, You must provide 508 Software with information sufficient for 508 Software to accurately identify and access Your records. The information 508 Software requires is Your full name, address, telephone number, and/or the email address You provided to 508 Software when You requested the pertinent Products. The information requested, or any other information per each individual case, is viewed as sufficient for 508 Software to ensure You are who You proclaim to be. 508 Software reserves the right to contact You to verify that it has accurately identified Your record.
If You are a California resident, You can request a notice disclosing the categories of Personal Information that 508 Software may share with third parties for their direct marketing purposes during the preceding calendar year. To request this notice, please submit Your request to 508 Software’s DPO at firstname.lastname@example.org. Please allow up to 30 days for a response. For Your protection and the protection of all of 508 Software’s users, 508 Software may ask You to provide proof of identity before it can answer such a request. 508 Software does not respond to general do not track (DNT) requests.
F. RIGHTS OF EUROPEAN USERS UNDER THE GDPR
508 Software complies with the principles of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (GDPR). If You are a natural person of the EU within the meaning of the GDPR (“Qualified Individual”), You are afforded certain additional rights by the GDPR as further described within this Section.
If and when 508 Software receives Your Personal Information directly from You via its Website or Products, it performs the functions of a ‘data controller’, as defined by the GDPR, and has the ability to determine how personal information is collected, for what purposes, and how this data is to be processed. As the data controller, 508 Software has implemented many technical and operational measures to ensure the most complete protection of Personal Information processed through its Website and Products.
Legal Basis for Processing
Article 6(1)(a) of the GDPR serves as the legal basis for processing operations for which 508 Software obtains consent for a particular purpose. If the processing of Personal Information is necessary for the performance of a contract to which You are a party, as is the case, for example, when processing operations are necessary for a particular Product, the processing is based on Art. 6(1)(b). The same applies to such processing operations which are necessary for carrying out pre-contractual measures, for example in the case of inquiries or functionality reviews concerning 508 Software Products or services. If 508 Software is subject to a legal obligation by which processing of Personal Information is required, such as for the fulfillment of tax obligations, the processing is based on Art. 6(1)(c). If the processing of Personal Information is necessary to protect Your vital interests or that of another Qualified Individual, then the processing is based on Art. 6(1)(d). Finally, processing operations could be based on Article 6(1)(f) if processing is necessary for the purposes of the legitimate interests pursued by 508 Software or by a third party, except where such interests are prohibited or overridden by Your fundamental rights and freedoms under the GDPR.
- Right of Confirmation
- Right of Access
- Right to Rectification
- Right to Erasure (Right to be Forgotten)
- Right to Restriction of Processing
You may obtain confirmation of whether or not Your Personal Information is being processed. If You wish to exercise Your right of confirmation, You may contact 508 Software using the contact information as provided in Section G, below.
You may obtain information about Your stored Personal Information at any time and a copy of this information. If You wish to exercise Your right of access, You may contact 508 Software using the contact information as provided in Section G, below.
You may request the rectification of any inaccurate Personal Information. Taking into account the purposes of the processing, You have the right to have inaccurate or incomplete Personal Information completed or deleted, by means of first appropriately identifying Yourself and then providing a supplementary statement. If You wish to exercise Your right of rectification please may contact 508 Software in accordance with Section G, below.
You may request the erasure of Your Personal Information by contacting 508 Software using the contact information provided in Section G, hereof. Furthermore, You may delete Your User Account information, as applicable, by accessing Your User Account settings page on the Website or within the Product(s). Please note that while any changes You make will be reflected in active user databases within a reasonable time, 508 Software may retain all information You submit for the prevention of fraud and abuse, analytics, satisfaction of legal obligations, or where 508 Software otherwise reasonably believes that it has a legitimate reason to do so, such as for archiving purposes within the public interest.
As a Qualified Individual, You have the right to restrict processing where one of the following applies:
- The accuracy of the Personal Information is contested by the data subject, for a period enabling the controller to verify the accuracy of the Personal Information;
- The processing is unlawful and the data subject opposes the erasure of the Personal Information and requests instead the restriction of the controllers use of such data;
- The controller no longer needs the Personal Information for the purposes of processing, but it is required by the data subject for the establishment, exercise, or defense of legal claims; or
- The data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.
You may request to receive Your Personal Information in a structured, commonly used and machine-readable format. You have the right to transmit this data to another controller without interference.
Furthermore, You may have the Personal Information transmitted directly from one controller to another, where technically feasible and where such transmission does not adversely affect the rights and freedoms of others.
You may object to decisions based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects You, as long as the decision is not (i) necessary for entering into, or the performance of, a contract between You and 508 Software; (ii) authorized by EU or Member State law to which You are subject; or (iii) based on the data subject’s explicit consent.
You may object to the processing of Your Personal Information using the contact information provided in Section G below, unless there are legitimate grounds for the processing within the public interest, or for the establishment, exercise, or defense of legal claims.
If 508 Software processes Personal Information for direct marketing purposes, You shall have the right to object at any time to the processing of Your Personal Information for such purposes. This right also applies to profiling to the extent that the processing is related to such direct marketing purposes. If You object to 508 Software processing Your Personal Information for direct marketing purposes, then 508 Software will no longer process the Personal Information for such purposes.
508 Software only retains personally identifiable information about You for as long as Your User Account remains active and for as long as it needs to provide You with Products or otherwise fulfill the purposes for which 508 Software had initially collected such information, unless otherwise required by law. 508 Software will retain and use information as necessary to comply with its legal obligations, for archival purposes, to assist in the resolve of disputes, and to enforce its agreements.
Cross-Border Data Transfers
If and when sharing of information involves cross-border data transfers, for instance to the U.S. from an EU Member State, 508 Software uses data contracts with EU standard contract clauses or other suitable data clauses and safeguards to permit data transfers from the EU to other countries. These standard contractual clauses commit companies transferring and receiving Your Personal Information to protecting the privacy and security of Your data. Copies of 508 Software’s current standard contractual clauses may be available on request using the contact details listed below.
G. PRIVACY-RELATED INQUIRIES AND COMPLAINTS
508 Software LLC
Data Protection Officer: Mr. Fabian Rothe
ATTN: Privacy Matter
Mailing Address: 901 N. Pitt Street, STE 325-D, Alexandria, VA 22314, USA
Please note that if You provide 508 Software with inconsistent privacy preferences (for example, by indicating on one occasion that third parties may contact You with marketing offers and indicating on another occasion that they may not), 508 Software cannot guarantee that Your most recent privacy preference will be immediately honored.
508 Software is committed to cooperate with the panel established by the EU Data Protection Authorities (DPA) with regard to unresolved Privacy Shield Complaints concerning data transferred from the EU. If You are a Qualified Individual, You may lodge a free complaint with the DPA in the country where You reside if You are unsatisfied with how Your complaint is handled by 508 Software. If You are a Qualified Individual, You can find Your DPA by visiting the European Commission Website on Data Protection Authorities, selecting the country in which You reside, and following the links provided to make a complaint.
H. PRIVACY SHIELD POLICY
EU-US Privacy Shield Principles
Under certain limited conditions, You may be able to invoke binding arbitration as provided under the Privacy Shield Framework to address an otherwise unresolved complaint.
Copyright © 2019 508 Software LLC. All rights reserved. The Website, Products, and all documentation are the copyrighted property of 508 Software LLC and/or its licensors and protected by copyright laws and international intellectual property treaties. 508 Software™ and related logo, and all related Product and service names, design marks and slogans are the trademarks and/or registered trademarks of 508 Software LLC and/or its affiliates. All other Product and service marks contained herein are the trademarks of their respective owners. Any use of the 508 Software LLC or third-party trademarks or logos without the prior written consent of 508 Software LLC or the applicable trademark owner is strictly prohibited.