CALLIDUSCLOUD GDPR DATA COLLECTION & PROCESSING NOTICE


About this data collection and processing notice

NOTICE: Please read this notice carefully as it contains important information about how we collect and process personal information about you.

Callidus Software Inc., doing business as CallidusCloud, together with its affiliates, which includes subsidiaries and entities that Callidus Software Inc. operates (collectively, “CallidusCloud,” “we,” or “us”) is committed to protecting your privacy and the personal information collected and processed about you.

By visiting and using CallidusCloud’s website, mobile site, and/or applications (together, the “Site”), registering to use our services offered through the Site, or providing your personal information to us at our corporate events (the “Services”), you understand that you will be subject to the terms set forth in this notice (“Data Use Notice”).

This Data Use Notice describes how we collect information about you, what we do with that information, and also what controls you have over that information in relation to your use of our Site and Services. Your information will be held and managed by CallidusCloud, acting either as a data controller, or, if you are a customer or end user of CallidusCloud, as a data processor.

Throughout this Data Use Notice we use ‘plain English’ summaries which are intended to give you guidance about what each section is about. Please click the link below to learn more about:

How we collect your information:

This section gives you more information about what information we collect about you and how we collect it, whether we collect it directly from you or other sources.

When using our Site or the Services, we may collect and process the following information about you:

Information provided directly by you

  • information (such as your name, email address, postal address, telephone number and other contact details) that you provide by completing forms on the Site or using the Service, including information about you if you register as a user of the Site or subscribe to a Service, information about you that you upload or submit to the Site or Service, or information you provide to us when requesting information or material from us;
  • Information and other details of any transactions made by you through the Site including but not limited to financial and billing information, including account numbers and other financial-related information provided by you when making transactions through the Site or when using our Services;
  • Information contained in communications you send to us, for example to report a problem or to submit queries, concerns or comments regarding the Site (or its content) or the Services;
  • Information from surveys that we may, from time to time, conduct on the Site that you respond to or participate in; or
  • Information from any employment materials you send us, for example, a CV, resumé or other details of your employment history.

Information about you collected from other sources

We may collect information about you when using the Site and/or our Services:

  • Automatically-Collected Information. We may automatically collect certain information about the computer or devices that are used to access the Site or use the Services, including mobile devices, through commonly-used information-gathering tools, such as cookies and web beacons. Such information includes standard information from your browser or device (such as browser/device type and language), your Internet Protocol address, and the actions you take on CallidusCloud’s Sites, such as the pages viewed and the links clicked. We use this information to ensure the proper functioning and security of our Site and Services and to optimize our Site or Services. Our use of cookies to process personal information is explained thoroughly in Section 3 of our Privacy Policy, which you should please read.
  • Location Information. We may collect information about your location when you access the Site or use our Services through a mobile device. If you do not want to provide us with location-tracking information, you can disable the GPS or other location-tracking functions on your device; provided your device allows you to do this.
  • Information Collected From Third Parties and Contractors. We may obtain information about you from third parties, such as marketers, partners, researchers, and others. If you access the Site or use the Services through a third-party connection or log-in, you authorize CallidusCloud to collect, store, and use, in accordance with this Data Use Notice, any and all information available to CallidusCloud through the third-party interface.
  • Aggregate or De-Identified Data. We may aggregate and/or de-identify information collected by the use of the Site or the Services or via other means such as corporate events so that the information is not intended to identify you. This Data Use Notice does not restrict our use or disclosure of aggregated and/or de-identified information.

How we use your information:

Information is collected for the purposes stated in this Data Use Notice and will not be further processed in a manner that is incompatible with those purposes.

We will collect and use your information as described in this Data Use Notice and as permitted by applicable laws, including in circumstances where it is necessary: (i) to provide or fulfil Services requested by or for you; (ii) for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into such a contract; (iii) for compliance with a legal obligation to which we are a subject; (iv) to pursue our legitimate interests; or (v) where you have given us your express consent.

We collect and use your information for the following purposes:

  • To perform the Services requested by you. For example, if you fill out a “Contact Me” web form, we will use the information provided to contact you about your interest in the Services. This data processing is necessary to provide or fulfil a service requested by or for you.
  • To plan and host events. For example, corporate events, host online forums and social networks in which event attendees may participate, and populate online profiles in relation to the Services. This data processing is necessary to provide or fulfil a service requested by or for you.
  • For marketing purposes. For example, we may use your information to further discuss your interest in the Services and to send you information regarding CallidusCloud and its group companies such as information about promotions, events, products or services. We will only send you marketing communications and updates about our products, services and events with your prior consent. You can withdraw your consent at any time. Data processing for marketing purposes is a legitimate business interest.

    You may manage your receipt of marketing and non-transactional communications by clicking on the “unsubscribe” link located on the bottom of CallidusCloud’s marketing emails. Additionally, you may send a request to legal-privacy@calliduscloud.com.

    You have the right to contact us at any time to object to the further processing of your information for the purposes of direct marketing to you, including any profiling related to such marketing.

  • For financial and payment purposes. For example, for checking financial qualifications and collect payment from you, where applicable. This data processing is necessary to provide or fulfil a service requested by or for you.
  • For operating and improving CallidusCloud’s Site and your customer experience. For example, we may collect and analyze data on your use of our website and process it for the purpose of improving our online customer experience. Data collected could include data about your device, such as unique device identifiers, information about your mobile phone or other mobile device(s), browser types, browser language, operating system, and the state or country from which you accessed the Services. Data collected could also include information related to the ways in which you interact with the Services, such as referring and exit pages and URLs, platform type, the number of clicks and domain names. This data allows us to understand our customers, their interaction with our website and improve our website to better serve our customers. We may use third-party analytics providers and technologies, including cookies and similar tools, to assist in collecting this information. Data processing for analytical and operational improvement purposes is a legitimate business interest.
  • For security purposes. For example, we may use your data to protect CallidusCloud and its third parties against security breaches and to prevent fraud and violation of CallidusCloud’s applicable agreements. Data processing for security purposes is a legitimate business interest.
  • For hosting purposes. For example, if you are our customer, we may collect and host your data to provide Services to you. If your employer is our customer, we may process your data in accordance with providing Services to them. However, we will not review, share, distribute, or reference any such data except as provided in a services agreement between us and our customer, or as may be required by law. Data processing for the purpose of hosting our Services is a legitimate business interest.
  • For customizing the Services with location-based information, advertising, and features. For example, if location-tracking on your mobile device shows you are close to a Callidus corporate event, we may reach out to you and let you know you should visit our nearby event. If you access the Services through a mobile device and you do not want your device to provide us with location-tracking information, you can disable the GPS or other location-tracking functions on your device, provided your device allows you to do this. This data processing is necessary to provide or fulfil a service requested by or for you, and can be disabled by you.
  • Protection of CallidusCloud and Others. For example, we may disclose your information to: (i) comply with legal obligations; (ii) enforce any agreements that you entered into with us; (iii) respond to claims that any content violates the rights of third parties; (iv) respond to your requests for customer service; and/or (v) the extent necessary for the purposes of the legitimate interests pursued by us or by the third party or parties to whom the data are disclosed, except where such interests are overridden by the interests for fundamental rights and freedoms of the data subjects. We may also disclose information to law enforcement agencies in emergency circumstances, where the disclosure of such information is consistent with the types of emergency disclosures permitted or required by law. This is data processing for compliance with a legal obligation.
  • Business Transfers. For example, we reserve the right to disclose and transfer all of your information, to a successor (or potential successor) company in connection with a merger, acquisition, or sale of all, or components, of our business, or in connection with due diligence associated with any such transaction. Data processing for this purpose is a legitimate business interest.

Sharing your information:

You have the right to know who we share your information with.

We may share your information with:

  • Any of our group affiliates, or to our agents, partners or contractors who assist us in providing the Services we offer through our Site. The assistance provided by our agents, partners or contractors may be related to our marketing activities such as: updating marketing lists, data analytics, advertising, market research, participation in a contest or sweepstakes, and receiving and sending communications. Transactional assistance may also be provided by our agents, partners or contractors, including: processing transactions, fulfilling requests for information, billing, sales execution, and fulfillment of orders. Other support services provided may include: data storage, transfer, analysis and processing, legal services, providing IT, and in other tasks as requested, from time to time. Our agents, partners and contractors will only use your information to the extent necessary to perform their functions and are subject to contractual restrictions prohibiting them from using your information for any other purpose.

    To receive a list of the agents, partners or contractors assisting us in the processing of your information please send your request to legal-privacy@calliduscloud.com. This list may change and will be updated from time to time.

  • From time to time, CallidusCloud may partner with other companies to jointly offer products or services. If you purchase or specifically express interest in a jointly-offered product or service from CallidusCloud, CallidusCloud may share information about you collected in connection with your purchase or expression of interest with our joint promotion partner(s). If you do not want your information to be shared in this manner, you may email legal-privacy@calliduscloud.com. However, we do not control our business partners’ use of the information that we share with them about you that we collect, and their use of the information will be in accordance with their own privacy policies.

California Do Not Track Disclosure

We are committed to providing you with meaningful choices about the information collected on the Services that is shared with third parties, and that is why we provide the opt-out choices set forth in this Data Use Notice. However, we do not recognize or respond to browser-initiated Do Not Track (“DNT”) signals, in part because no common industry standard for DNT has been adopted by industry groups, technology companies, or regulators, nor is there a consistent standard of interpreting user intent. We take privacy and meaningful choice seriously and will make efforts to continue to monitor developments in these areas.

Public Forums, Refer a Friend, and Customer Testimonials

We may provide bulletin boards, blogs, or chat rooms through the Services. Any information you submit in such a forum may be read, collected, or used by others who visit these forums. We are not responsible for the information you choose to submit in these forums. We are not responsible for the privacy policies or the content of such sites.

You may elect to use our referral program to inform friends about the Services. When using the referral program, CallidusCloud requests the friend’s name and email address. CallidusCloud will automatically send the friend a one-time email inviting him or her to visit CallidusCloud’s websites. CallidusCloud does not store this information. CallidusCloud posts a list of customers and testimonials on CallidusCloud’s websites that contain information such as the names and titles.

CallidusCloud obtains the consent of the individuals concerned prior to posting such information or testimonials.

Transfer of information overseas:

You have the right to know if and where your information may be transferred. This section provides information on the existence of transfers of your information by us.

The personal information about you that we collect is sent to and stored on secure servers located as noted below or in the systems of the third parties that we use, where applicable. Such storage is necessary in order to process the information.

CallidusCloud Server locations include:

Sacramento, CA – US
Ashburn, VA – US
Chicago IL – US
Frankfurt, Germany
London, UK
Dublin, Ireland
Singapore, Singapore

Personal information may be transferred by us to the third parties mentioned in the circumstances described above (see Sharing your information), which may be situated outside the European Economic Area (EEA) and may be processed by our staff operating outside the EEA.

Standard Contractual Clauses

We will take all steps reasonably necessary to ensure that it is subject to appropriate safeguards, such as relying on a recognized legal adequacy mechanism which may include by entering into EC approved standard contractual clauses relevant to transfers of personal information (see http://ec.europa.eu/justice/dataprotection/internationaltransfers/transfer/index_en.html) and that it is treated securely and in accordance with this Data Use Notice.

EU-U.S. Privacy Shield

CallidusCloud has self-certified under the EU-U.S. Privacy Shield framework set forth by the U.S. Department of Commerce and the European Union. Please click here to view our Privacy Shield Notice. For more information on the EU–U.S. Privacy Shield, please visit the U.S. Department of Commerce’s Privacy Shield website here.

Security:

The security of your information is important to us. This section describes the basics of the types of measures we put in place to protect your information.

We have appropriate physical, electronic, and managerial procedures to safeguard and help prevent unauthorized access and maintain data security of, and to use correctly, the information we collect online. These safeguards vary based on the sensitivity of the information that we collect and store. We have implemented procedures designed to limit the dissemination of your information to only such designated staff as are reasonably necessary to carry out the stated purposes we have communicated to you.

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal information, we cannot guarantee the security of your data transmitted to our website and any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.

Retention:

This section explains how long we will retain your personal information for following termination of our commercial relationship and the reasons for retention.

We will only keep your information as long as it remains necessary for the identified purpose(s) for which it was originally collected and for up to eight (8) years afterwards or otherwise permitted by local laws, or as required for our business operations or by applicable laws.

We may need to retain certain personal information even once a customer account has been closed or deleted to enforce our terms, for fraud prevention, to identify, issue or resolve legal claims and/or for proper record keeping purposes. We may also retain a record of any stated objection by you to receiving our updates for the purpose of ensuring we can continue to respect your wishes and not contact you further. For example, if you request to stop receiving emails from us, we will retain your email address for use on an email “suppression list” to ensure you do not receive further emails, as requested.

All retained information will remain subject to the terms of this Data Use Notice. If you request that your name be removed from our databases, it may not be possible to completely delete all your information due to technological and legal constraints.

Your Rights:

This section provides details about your rights in relation to your personal information.

You may ask us to:

  • Access all the personal information about you held by us. On request, we will provide you with a copy of this information. We reserve the right to charge a reasonable fee taking into account the administrative costs of providing the information or taking the action requested. You can exercise your right of access to your personal information:

Please note that we may be required to ask you for further information in order to confirm your identity before we provide the information requested.

  • Correct or erase your personal information where appropriate. Please note, you may review and update certain user profile information by logging in, as applicable, to the relevant portions of the Services where such information may be updated;
  • Restrict the processing of your personal information whilst we investigate your concern;
  • Where your processing is based on your consent, you have a right to receive your information in a commonly used electronic format or ask we move the data in that format to another provider where your request relates to the data that you gave us direct and where technically possible (data portability); and
  • Withdraw your consent at any time when the processing relies upon consent.

If you remain unhappy with a response you receive you can also refer the matter to your data protection supervisory authority (see http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm).

Linked sites and advertisements

The Site or Services may contain links to third-party websites. We are not responsible for the privacy practices or the content of those third-party websites. Any information you provide via those services is subject to the applicable third party privacy policies and is not covered by this Data Use Notice.

Children

Our Sites and Services do not target and are not intended to attract children under the age of 13. CallidusCloud does not knowingly solicit personal information from children under the age of 13. Should we learn or be notified that we have collected information from users under the age of 13, we will immediately delete such personal information. If you are under 13 in your country of residence, please ask your parent or guardian to provide their information for you.

Your California Privacy Rights

California law permits users who are California residents to request and obtain from us once a year, free of charge, a list of the third parties to whom we have disclosed their personal information (if any) for their direct marketing purposes in the prior calendar year, as well as the type of personal information disclosed to those parties. If you are a California resident and would like to request this information, please provide a written acknowledgement that you are a resident of California and address your request to:

CallidusCloud
4140 Dublin Blvd., Suite 400
Dublin, CA 94568
Attn: Marketing Department

How you can access and update your information

You may review and update certain user profile information by logging in, as applicable, to the relevant portions of the Site or Services where such information may be updated, or by contacting legal-privacy@calliduscloud.com.

Changes to this Data Use Notice

CallidusCloud reserves the right to change this Data Use Notice from time to time. Please check this page periodically for changes. If we make any material changes to this Data Use Notice we will notify you before they take effect either through the Site or by sending you a notification. Any such material changes will only apply to personal information collected after the revised Data Use Notice took effect.

Contact Us:

Have additional privacy questions or need further info? This section is about how to contact us.

If you have any questions, comments, or concerns regarding this Data Use Notice or CallidusCloud’s privacy practices, they may be submitted via email to legal-privacy@calliduscloud.com, or in writing by addressing your inquiries to:

CallidusCloud
4140 Dublin Blvd., Suite 400
Dublin, CA 94568
Attn: Data Protection Officer

© 2018 Callidus Software Inc.

This Policy was last modified on February 12, 2018.