This privacy statement (the “Privacy Statement”) is effective May 24, 2018.
Illumio, Inc. and its subsidiaries around the world (“Illumio” or “we”) understand that when our clients, partners and other individuals provide personal data to Illumio, they place their trust in us. Illumio takes this trust seriously and is committed to compliance with the laws of all countries in which it operates, including the General Data Protection Regulation and other applicable data protection laws around the globe.
This Privacy Statement describes Illumio’s practices regarding the collection, use and disclosure of personal information about an identified or identifiable natural person (“personal data”) processed through the use of Illumio’s website at www.illumio.com (the “Site”). This Privacy Statement does not apply to any third-party websites, services or applications, even if they are accessible through our Site.
If your company has engaged Illumio to provide Illumio products and/or services (collectively, the “Services”), your company and Illumio have agreed to a separate agreement that, among other things, governs the use of all of the data collected and maintained by Illumio in connection with the operation of the Services. The agreement between your company and Illumio takes precedence over conflicting provision in this Privacy Statement.
Our primary goals in collecting information are to provide and improve our Site, to administer your use of the Site, and to enable you to enjoy and easily navigate our Site. We collect and use personal data that you provide in order to operate our business, provide our products and services, send marketing and other communications, and comply with applicable laws and regulations. In addition to the personal data you provide to us directly, we may also process personal data about you that we receive from our clients or third parties. The types of personal data we process will depend on the purpose.
|To provide our products and services||Contact details (such as name, email, address, company name, phone number and other information necessary) to provide services to our clients and our client’s customers, including providing product support updates|
|To improve our products and services||Contact details to conduct quality controls and evaluate the performance of our products and services, including conducting customer satisfaction surveys.|
|To conduct due diligence||Contact details and publicly available information about financial or reputational status of a client or third party supplier/partner|
|To generate sales and marketing leads||Contact details, marketing preferences, publicly available social media information to maintain a client relationship management database and send relevant newsletters, solution updates, event notifications and other marketing communications|
|To manage relationships with clients, suppliers and partners||Contact details and payment information in order to execute contracts, generate invoices and make payments|
|To respond to inquiries or requests for information||Contact details for electronic communication|
|To secure our premises and networks||Contact details for authentication to use guest networks, collaboration tools and visit our offices; images captured through our video systems set up for security purposes in our offices.|
When we receive personal data about you from our clients in order to provide our services, Illumio processes the personal data as instructed by our clients and in accordance with our contractual obligations. Our clients are responsible for complying with regulations or laws regarding notice, disclosure, and/or obtaining consent prior to transferring the personal data to Illumio for processing.
We do not sell or otherwise disclose personal data about our website visitors or others that interact with Illumio or our products or services, except as described herein. We may share your personal data with authorized Illumio personnel in our subsidiaries with a need to know the information in order to process the personal data for the purpose we collected it. We also share personal data with third parties who are acting on our behalf in order to provide the products or services you request or to support our relationship with you. These third parties are not authorized by us to use or disclose the information except as necessary to perform services on our behalf pursuant to a contractual obligation or to comply with legal requirements. Illumio requires such third parties to comply with applicable data protection and privacy laws and agree to implement and maintain appropriate technical and organizational security measures to safeguard the personal data.
Our sharing may include:
We use reasonable security procedures and technical and organizational measures to protect against accidental or unlawful destruction, loss, disclosure or use of personal data we handle. Our network and systems used to provide services are governed by corporate Information security policies, which are based upon standards, including International Organization for Standardization (ISO) 27001 and National Institute of Standards and Technology (NIST). We limit access to and use of your personal data to authorized persons and trusted third parties who have a reasonable need to know the information in order to perform our services and business operations and who are bound by confidentiality obligations.
We retain your personal data only for as long as is necessary to fulfill the purpose for which the data was collected from you and in consideration of and compliance with applicable legal or regulatory requirements to maintain the data for legitimate purposes. For example, where required by law for audits or accounting requirements, to enforce our agreements or handle disputes. When personal data is no longer needed for the purpose it was collected or processed or to comply with a legal obligation, we securely destroy it.
We rely on you to provide accurate, complete and current personal data to us. If you need to correct or update the personal data you provided to us, in many cases, you can edit your data from the location where you provided the personal data to us. If you are not able to access it yourself, we will respond in a timely manner to all reasonable requests to access, correct or delete your personal data. Requests and questions can be submitted to email@example.com.
For individuals whose personal data we collect directly or instruct our trusted third party to collect on our behalf, Illumio, Inc. or one of our subsidiaries located in the EU, EEA or Switzerland is a data controller under the General Data Protection Regulation. The type of data we process as a data controller includes contact details such as name, company, email, phone, website preferences and other information collected for marketing or business operation purposes. We process personal data as a data controller using the following legal basis:
If you are resident of EU, EEA or Switzerland, you may exercise the following rights:
Please note that in case we ask for your consent to processing, you are free to refuse to give consent and you can withdraw your consent at any time without any adverse negative consequences. The lawfulness of any processing of your personal data that occurred prior to the withdrawal of your consent will not be affected. You can exercise these rights by contacting us at firstname.lastname@example.org. If you consider that the way we process your personal data infringes your rights under the GDPR or is not compliant, you can lodge a complaint with Illumio directly or with a supervisory authority in the EU Member state in which you reside or where the data was processed.
Illumio is a global enterprise based in the United States with operations in countries around the world. Authorized Illumio personnel and third parties acting on our behalf may access, use and process personal data collected from you in a country that is different from the country where you entered the personal data, which may have less stringent data protection laws. As a network security company, Illumio has implemented global privacy practices for processing personal data protected under various data protection laws. Illumio transfers personal data between the countries in which we operate in accordance with the standards and conditions of applicable data privacy laws, including standards and conditions related to security and processing and acceptable transfer mechanisms.
With respect to personal data coming from the EU or Switzerland, Illumio complies with the EU-U.S. and Swiss-U.S. Privacy Shield Framework as set forth by the US Department of Commerce regarding the collection, use, and retention of personal data from individuals in the European Union member countries and Switzerland. Illumio has certified that it adheres to the Privacy Shield Privacy Principles and agrees that if there is any conflict between the principles in this Privacy Statement and the Privacy Shield Privacy Principles, the Privacy Shield Principles shall govern. Illumio commits to resolve complaints about our collection or use of your personal data. EU or Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact us at privacy@Illumio.com. For any Privacy Shield complaints that cannot be resolved with us directly, EU or Swiss individuals may bring a complaint through the JAMS alternative dispute resolution process. Information about how to file a complaint with JAMS can be found here. The services of JAMS are provided at no cost to you. Finally, as a last resort and in limited situations, EU or Swiss individuals may seek redress from the Privacy Shield Arbitration Panel, a binding arbitration mechanism.
When we share your personal data under the Privacy Shield framework with a third party, Illumio is responsible for the processing of your personal data. Illumio remains liable under the Privacy Shield Principles if our third party service provider processes your personal data in a manner inconsistent with the Privacy Shield Principles. The U.S. Federal Trade Commission has jurisdiction over Illumio’ compliance with the Privacy Shield.
It is not our intent to collect personal data from children under the age of consent in their country of residence. Our Site is not designed to attract children and we request that children under the age of consent not submit personal data to us through our Site.
Any personal data that we process is subject to the Privacy Statement in effect at the time such personal data is processed. We may, however, modify and revise this Privacy Statement from time to time. If we make any material changes to this Privacy Statement, we will notify you of such changes by posting the updated Privacy Statement on the Site or by sending you an email or other notification, and we will indicate when such changes will become effective.