- Diligent Boards – diligent.com
- BoardDocs® – boarddocs.com
- BoardEffect – boardeffect.com
- BoardPad – boardpad.com
- Diligent Entities (formerly known as Blueprint OneWorld) – blueprintoneworld.com
- EquityEffect (formerly known as TruEquity) – equityeffect.com
- iCompass – icompasstech.com
- Manzama – manzama.com
- CGLytics – cglytics.com
1. Personal information we use
You can generally visit our websites without actively entering any personal information about yourself. However, in certain areas of this site, we may ask you to contact us with questions or comments, or request more information about our services. In these cases, we will collect personal information from you directly as described below.
We may be required to collect certain personal information about you either by law or as a consequence of any contractual relationship we have with you. Failure to provide this information may prevent or delay the fulfillment of these obligations. We will inform you at the time your information is collected whether certain data is compulsory and the consequences of the failure to provide such data.
1.1 Information we collect
We collect the following categories of information:
- Personal details (e.g. name, title, employer, organization or similar professional or employment related information). For example, we might collect this data from you to verify your identity and disclose it to other Diligent group companies.
- Contact details (e.g. phone number, email address, postal address, phone number, or similar identifiers). For example, we might collect this data from you to contact you about services you request and disclose it to our vendors who manage our files.
- Additional commercial information about your organization (e.g. annual operating budget, number of board members, number of committee members). For example, we might collect this data from you to compile reports, which is one of our business lines, and disclose it to recipients of our services.
- Demographic information (e.g. age, education status, sex, etc. including protected classifications). For example, we might collect this data from your employer to supplement the information we collect from you, and disclose it to recipients of our services.
- Account information (such as user ID, contact details, answers to security questions, or similar identifiers). For example, we collect this data from you when you sign up on our site, so that we can identify you. We may disclose this data to our vendors; and
- Commercial information about your usage of our services or the websites (such as support requests, recordings of or information from phone calls with our sales or support teams, or information provided to us to resolve such support requests). For example, we collect this data from you when you submit service requests or when engaging with our sales or support teams, to allow us to assist with your requests. We may disclose this information with vendors.
We collect information about you from you directly, from your employer or organization, from publicly available websites and filings, and/or from our business partners.
1.2 Special categories of personal data
2. How we use your personal information and the basis on which we use it
We use your personal information to:
- Identify and authenticate you: We use your identification information to verify your identity when you access and use our services and to ensure the security of your personal information. We do this to comply with our contractual obligations to you or your organization.
- Provide you with services: We process your personal information to provide the services you or your organization have requested. We do this to comply with our contractual obligations to you or your organization.
- Improve our services: We analyze information about how you use our services to provide an improved experience for our customers of all our services, including product testing and site analytics. It is in our legitimate interest to use the information provided to us for this purpose, so we can understand any issues with our services and improve them.
- Communicate with you: We may use your personal information when we communicate with you, for example if we are providing information about changes to the terms and conditions or if you contact us with questions. It is in our legitimate interest to provide you with appropriate responses and provide you with notices about our services.
- Market our services: We may use your personal information to build a profile about you and place you into particular marketing segments in order to understand your preferences better and to appropriately personalize the marketing messages we send to you. It is in our legitimate interest to provide more relevant and interesting advertising messages. Where necessary, we will obtain your consent before sending such marketing messages.
- Exercise our rights: We may use your personal information to exercise our legal rights where it is necessary to do so, for example to detect, prevent and respond to fraud claims, intellectual property infringement claims or violations of law or our applicable contract terms and conditions.
- Comply with our obligations: We may process your personal information to, for example, carry out fraud prevention checks or comply with other legal or regulatory requirements, where this is explicitly required by law.
- Customize your experience: When you use the services, we may use your personal information to improve your experience of the services, such as by providing interactive or personalized elements on the services and providing you with content based on your interests.
We may post customer testimonials on our websites which might contain personal information. We obtain the customer’s consent via email prior to posting the testimonial to post their name, title, and organization name along with their testimonial. If you wish to update or delete your testimonial, you can contact us at firstname.lastname@example.org.
3. The information we collect on behalf of the Clients
Where a customer of ours has retained us to provide services and either provides us with personal information or requires us to collect personal information on their behalf in connection with such services, then our use of such personal information shall be limited to the purpose of providing these services.
In the circumstances described under this Section, we have no direct relationship with the individuals whose personal information we process. If your data is processed on behalf of one of our customers, please contact the customer you interact with directly. We may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the service agreements with our Clients.
An individual whose data is being processed in the circumstances described in this section should direct any queries with respect to access, correction, amendment, or deletion of inaccurate data to our customer (the data controller). If requested to remove data, we will respond within a reasonable timeframe.
Personal information processed under this section will be retained as long as needed to provide services to our customer. We will retain this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
4. Your rights over your personal information
You have certain rights regarding your personal information, subject to local law. These may include the following rights to:
- access your personal information
- rectify the information we hold about you
- erase your personal information
- restrict our use of your personal information, including limiting disclosures made for valuable consideration
- object to our use of your personal information
- receive your personal information in a usable electronic format and transmit it to a third party (right to data portability)
- receive a disclosure regarding how we have collected and used your personal information
- lodge a complaint with your local data protection authority.
If you would like to discuss or exercise these rights, please contact us at the details below. We will request that you provide us with information for us to verify your identity and process your request. Once we verify your request, we will comply with it to the extent required by applicable law. Note, that in some cases, we may be prohibited from disclosing certain information, such as Social Security numbers, or may be permitted to retain information, for example to complete the transaction for which it was provided.
We encourage you to contact us to update or correct your information if it changes or if the personal information we hold about you is inaccurate.
We will contact you if we need additional information from you in order to honor your requests.
If you are a California resident, we will not deny you goods or services, charge a different price or rate, or provide a different level or quality of goods or services on account of your decision to exercise any of the above rights which may apply to you.
5. Information Sharing
We may share your personal information with third parties under the following circumstances:
- Vendors and business partners. We may share your personal information with our service providers and business partners that perform marketing services and other business operations for us. For example, we may partner with other companies to ship your order or offer customer service. These companies are authorized to use your personal information only as necessary to provide these services to us.
- Diligent group companies. Diligent Corporation works closely with other businesses and companies that fall under within the Diligent group of companies. We may share certain information about your personal details and contact information, cookie information, service usage information, or use of our website) with other Diligent group companies for provision of customer support services pursuant to a contract, marketing purposes, internal reporting and customer insights and service optimization. A list of companies within the Diligent group with which your personal information may be shared can be found here.
- Law enforcement agency, court, regulator, government authority or other third party. We may share your personal information with these parties where we believe this is necessary to comply with a legal or regulatory obligation, or otherwise to protect our rights or the rights of any third party. Where permitted by law or regulation and reasonably practicable, we will attempt to notify you of such requirements.
- The company or organization that has made you an authorized user of any services.
Because we operate as part of a global business, the recipients referred to above may be located outside the jurisdiction in which you are located (or in which we provide the services). See the section on “International Data Transfer” below for more information.
- Professional or employment-related information
- Contact details
- Demographic Information
- Education information
- Protected classifications
- Commercial information
- Biometric information
- Internet or other electronic network activity information
- Geolocation data
- Audio, electronic, visual, thermal, olfactory, or similar information
- Inferences drawn from any of the information identified above
6. Information Security and Storage
We implement technical and organizational measures to ensure a level of security appropriate to the risk to the personal information we process. These measures are aimed at ensuring the ongoing integrity and confidentiality of personal information. We evaluate these measures on a regular basis to ensure the security of the processing.
We will keep your personal information for as long as we have a relationship with you. Once our relationship with you has come to an end, we will retain your personal information for a period of time that enables us to:
• Maintain business records for analysis and/or audit purposes
• Comply with record retention requirements under the law
• Defend or bring any existing or potential legal claims
• Deal with any complaints regarding the services
• Enforce our commercial agreements.
We will delete your personal information when it is no longer required for these purposes. If there is any information that we are unable, for technical reasons, to delete entirely from our systems, we will put in place appropriate measures to prevent any further processing or use of the data.
7. International Data Transfer
Your personal information may be transferred to, stored and processed in various countries, including those that are not regarded as ensuring an adequate level of protection for personal information under European Union law or by the European Commission. We have put in place appropriate safeguards (such as contractual commitments) in accordance with applicable legal requirements to ensure that your data is adequately protected. For more information on the appropriate safeguards in place, please contact us at the details below.
8. EU-U.S. and Swiss-U.S. Privacy Shield
Diligent Corporation (“Diligent”) and Manzama LLC (“Manzama”) participate in and have certified their compliance with the EU-US Privacy Shield Framework and the Swiss-US Privacy Shield Framework. Diligent and Manzama are committed to subjecting all personal data received from European Union (EU) Member States, the United Kingdom (UK) and Switzerland, respectively, in reliance on each Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework and to view our certification, visit the US Department of Commerce’s Privacy Shield List: https://www.privacyshield.gov/list.
Diligent and Manzama are responsible for the processing of personal data they receive, under each Privacy Shield Framework, and subsequently transfer to a third party acting as an agent on their behalf. Diligent and Manzama comply with the Privacy Shield Principles for all onward transfers of personal data from the EU, the UK and Switzerland, including the onward transfer liability provisions.
With respect to personal data received or transferred under the Privacy Shield Frameworks, Diligent and Manzama are subject to the regulatory enforcement powers of the US Federal Trade Commission. In certain situations, Diligent and Manzama may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed to your satisfaction, please contact our US-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Under certain conditions, described in more detail on the Privacy Shield website https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
9. Links to Other Sites
Our site includes links to other websites whose privacy practices may differ from our practices. If you submit personally identifiable information to any of those sites, your information is governed by their privacy policies. We are not responsible for the privacy practices or the content of any sites to which our sites provide links. We encourage you to carefully read the privacy statement of any website you visit.
Social Media Widgets
Our websites includes Social Media Features, such as the Facebook Like button, and Widgets, such as the Share this button or interactive mini-programs that run on our websites (the “Features”). These Features may collect your Internet protocol address, which page you are visiting on our website, and may set a cookie to enable the Feature to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our website. Your interactions with these Features are governed by the privacy statement of the company providing it.
10. Contact Us
Diligent Corporation and, with respect to individual service specific inquiries or relationships, the relevant group companies available here, are the controllers responsible for the personal information we collect and process.
Our European Union representative is Diligent Boardbooks Limited, whose registered office is located at 1 Strand, Grand Buildings, First Floor, London, WC2N 5HR United Kingdom.
Our Data Protection Officer can be contacted at: email@example.com.
If you have questions or concerns regarding the way in which your personal information has been used, please contact firstname.lastname@example.org. If you have inquiries related to data subject access requests, please contact email@example.com. If you prefer an alternative to email, you may reach out through our support phone number (1.866.262.7326 or otherwise at our page here) and our representatives will attempt to assist.[WA1] If you would like to opt out of certain disclosures, please click here: Do Not Sell My Personal Information.
We are committed to working with you to obtain a fair resolution of any complaint or concern about privacy. If, however, you believe that we have not been able to assist with your complaint or concern, you have the right to make a complaint to the data protection authority.
11. Changes to the Policy
Last Updated: The 1st day of January 2020