Slemma EU-U.S. Privacy Shield Notice

Slemma, Inc. (“We” or “Our”) has certified with the EU-U.S. Privacy Shield with respect to the personal data we receive and process on behalf of our customers through our online application and platform (the “Services”). Slemma certifies that it adheres to the Privacy Shield Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement for personal data submitted by our customers in participating European countries through the Services, and our Privacy Shield certification will be available here.

Data Processed

We provide the Services so that our customers don’t have to build their own solutions for data visualization. In providing these Services, we process data our customers submit to the Services or instruct us to process on their behalves in connection with the Services (“Customer Data”)

Purposes of Data Processing

In order to provide the Services, we capture and store some information about you:

  • Account creation information. Users provide information such as an email address and password to create an account.
  • Account setup information. When a Customer creates a team using the Services, we collect an email address, a team name, user name for the individual setting up the team, and password. For more information on team set-up, click here.
  • Billing and other information. For Customers that purchase a paid version of the Services our third party payment processors may collect and store billing address and credit card information on our behalf.
  • Services usage information. This is information about how you are accessing and using the Services, which may include administrative and support communications with us and information about the teams, features, and what third party integrations you use (if any).
  • Contact information. With your permission, any contact information you choose to import is collected when using the Services.
  • Log data. When you use the Services our servers automatically record information, including information that your browser sends whenever you visit a website or your web app sends when you are using it. This log data may include your Internet Protocol address, the address of the web page you visited before using the Services, your browser type and settings, the date and time of your use of the Services, information about your browser configuration and plug-ins, language preferences, and cookie data.
  • Device information. We may collect information about the device you are using the Services on, including what type of device it is, what operating system you are using, device settings, application IDs, unique device identifiers, and crash data. Whether we collect some or all of this information often depends on what type of device you are using and its settings.
  • Geo-location information. WiFi and IP addresses received from your browser or device may be used to determine approximate location.
  • Services integrations. If, when using the Services, you integrate with a third party service, we will connect that service to ours. The third party provider of the integration may share certain information about your account with Slemma. However, we do not receive or store your passwords for any of these third party services.

All data stored by us is only used for internal processing, and never sold or otherwise given away.

Third Parties With Whom We May Share Customer Data

We use a limited number of third party providers to assist us in providing the Services to our customers. As of the date hereof, these third party providers perform technical operations such as database monitoring, data storage and delivery, hosting services, and customer support software tools. These third parties may access, process or store personal data in the course of providing these services, but based on our instructions only.

And we use third party payment processor - Stripe Inc., which adheres to the Privacy Shield Principles including the Supplemental Principles, (collectively, the “Privacy Shield Principles”) for Personal Data received from entities in the European Economic Area (the “EEA”) and Switzerland. More information about Stripe Inc here.

If we receive personal data subject to our certification under the Privacy Shield and then transfer it to a third-party service provider acting as an agent on our behalf, we have certain liability under the Privacy Shield if both (i) the agent processes the personal data in a manner inconsistent with the Privacy Shield and (ii) we are responsible for the event giving rise to the damage.

Questions or Complaints

If you are a resident of a European country participating in the Privacy Shield and you believe we maintain your personal data within the scope of this Privacy Shield certification, you may direct any questions or complaints concerning our Privacy Shield compliance to help@slemma.com.

We will work with you to resolve your issue.

Dispute Resolution

If you are a resident of a European country participating in the Privacy Shield and you have not received timely response to your concern, or we have not addressed your concern to your satisfaction, you may seek further assistance, at no cost to you, from EU Data Protection Authorities for EU/EEA Data Subjects, which is an independent dispute resolution bodies.

Arbitration

You may also be able to invoke binding arbitration for unresolved complaints but prior to initiating such arbitration, a resident of a European country participating in the Privacy Shield must first: (1) contact us and afford us the opportunity to resolve the issue; (2) seek assistance from EU Data Protection Authorities for EU/EEA Data Subjects; and (3) contact the U.S. Department of Commerce (either directly or through a European Data Protection Authority) and afford the Department of Commerce time to attempt to resolve the issue. If such a resident invokes binding arbitration, each party shall be responsible for its own attorney’s fees. Please be advised that, pursuant to the Privacy Shield, the arbitrator(s) may only impose individual-specific, non-monetary, equitable relief necessary to remedy any violation of the Privacy Shield Principles with respect to the resident.

U.S. Federal Trade Commission Enforcement

Our Privacy Shield compliance is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC).

Right of Access

Some international users (including those whose personal data is within the scope of this Privacy Shield certification) have certain legal rights to access certain personal data we hold about them and to obtain its correction, amendment or deletion. Those users may exercise those rights through the options described in their Account settings or by contacting us via help@slemma.com.

Requirement to Disclose

We may disclose personal data when we have a good faith belief that such action is necessary to: conform to legal requirements or to respond to lawful requests by public authorities, including to meet national security or law enforcement requirements; or to enforce our contractual obligations.

If we engage in a merger, acquisition, bankruptcy, dissolution, reorganization, sale of some or all of Slemma’s assets, financing, acquisition of all or a portion of our business, a similar transaction or proceeding, or steps in contemplation of such activities (e.g. due diligence). In this event, we will notify you by electronic means before information about you is transferred and becomes subject to a different privacy policy.