ETHOPASS PRIVACY POLICY
Last Updated: September 1, 2020
Ethopass believes in an individual’s right to security and anonymity. It’s the core of what we do and why we exist. This Privacy Policy describes Ethopass’s privacy practices with regards to:
visitors to https://www.ethopass.com/ (including any subdomains of this website or other websites owned by Ethopass or operated on our behalf)(the “Website”);
users who download and use the Cryptex software (the “Cryptex”) from the Website, browser extension stores (e.g., Google Chrome Web Store), and mobile application stores (e.g., Apple App Store)
The Cryptex and the HARBINGER PROTOCOL are collectively referred to in this Privacy Policy as the “Products”.
BY VISITING OUR WEBSITE OR USING OUR PRODUCTS OR BY OTHERWISE GIVING US YOUR INFORMATION, YOU AGREE TO THE TERMS OF THIS PRIVACY POLICY.
If you have questions about this Privacy Policy, please contact us at legal@ethopass.com.
This Privacy Policy is organized into the following ten sections:
What Websites are Covered by this Privacy Policy?
What Information Do We Collect?
How Do We Use the Information Collected?
What About the Security of Personal Information?
What About Customer Testimonials, Comments and Reviews?
What About Cryptex End User Personally Identifiable Information?
What Age Restrictions Apply?
What are My Data Protection Rights, Controls and Choices?
How Do We Handle Changes to Our Privacy Policy?
What if I have Additional Questions?
WHAT WEBSITES ARE COVERED BY THIS PRIVACY POLICY?
Ethopass has established this Privacy Policy to help you to understand how Ethopass collects and uses personally identifiable information. This Privacy Policy covers the information practices of Websites that link to this Privacy Policy, including, but not limited to https://www.ethopass.com/.
Ethopass’s Websites may contain links to other websites. Ethopass is not responsible for the information practices or the content of such other websites. Ethopass encourages you to review the privacy policies of other websites to understand their information practices.
WHAT INFORMATION DO WE COLLECT?
Ethopass does not collect data, including, but not limited to, personally identifiable information, from users who download and use the Cryptex. Ethopass collects personally identifiable information from visitors to its Website only if they voluntarily provide such information. This information is collected in accordance with this Privacy Policy from sources that include but are not limited to Customer registration forms on the Website.
Personal Information You Provide to Us. Ethopass only collects personally identifiable information voluntarily provided by you through our interactions with you for the purposes described below, including to operate effectively and provide you with the best experiences with our Products. Ethopass receives and stores any information entered on its Website when you express an interest in obtaining information about the Products, information about becoming a Customer, or when you register as a Customer. When a visitor expresses an interest in obtaining information about the Products, has a question about the Products, or about becoming or registering to be a Customer, Ethopass may require the visitor to provide personal contact information, such as name, company name, address, phone number, email address, and any other information necessary for us to communicate with visitors or provide a software license to a Customer for the HARBINGER PROTOCOL (collectively, “Personal Information”). The Personal Information visitors provide may be used for such purposes as communicating with visitors about the Products, including special offers, announcements, and new features or software updates, and onboarding and managing Customers, including providing Customer support.
Non-Identifiable Information. Ethopass does not automatically collect information through the use of commonly-used information-gathering tools, such as cookies, as visitors navigate or interact with Ethopass’s Website. Our Products are provided in such a way that the use of cookies is not necessary.
Payment Information. When making a software license purchase from us, Customers may be required to use our partners (e.g., Xero) and/or trusted payment processors (collectively, “Payment Service Providers”).
Your use of such Payment Service Provider services will be governed by their own terms of use and privacy policy, which apply to their collection of your financial information, such as credit card information.
You acknowledge and agree that any credit card and/or other billing and payment information that you provide directly to us may be shared by us with the Payment Service Providers solely for the purposes of effecting payment to us and servicing your account.
We will treat such information as personally identifiable information. We may always retain and use such information as necessary to comply with our legal obligations, resolve disputes, establish or exercise our legal rights or defend against legal claims and enforce our agreements.
Third Party Data. We also obtain data from third parties. We protect data obtained from third parties according to the practices described in this Privacy Policy, plus any additional restrictions imposed by the source of the data. These third party sources vary over time and include:
Data from third party customer support software providers we use, including, but not limited to, Zendesk and GitLab.
Communication services, including email providers and social networks (e.g., Telegram), when you give us permission to access your data on such third party services or networks.
HOW DO WE USE THE INFORMATION COLLECTED?
Except as described in this Privacy Policy, we will not give, sell, rent, or loan any identifiable Personal Information to any third party, without either a visitor’s prior consent or another legal basis. We may disclose such information to respond to subpoenas, court orders, or legal process, or to establish or exercise our legal rights or defend against legal claims. We may also share such information if we believe it is necessary in order to investigate, prevent, or take action regarding illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of our Terms of Use or other related contract terms, or as otherwise required by law. We may also provide non-personal, summary, or group statistics about our Customers, sales, traffic patterns, and related Product information to reputable third-party vendors, but such statistical data will not include Personal Information.
Below are the specific purposes for which we use the information we collect.
Improvement of the Products
We are always looking for ways to improve our Products. We use collective learnings about how people use our Products, and feedback provided directly to us, to troubleshoot and to identify trends, usage, activity patterns, and areas for integration and improvement of the Products. For example, we examine aggregated usage patterns of our Customers to ensure that the Products perform as well as possible. In some cases, we apply these learnings across the Product versions to improve and develop similar features or to better facilitate the interoperability of the third-party applications that Customers use with the Products. We also may test and analyze certain new features with some users based on preferences a Customer may have communicated to us.
Provision of the Products
To provide the Products and personalize Customers’ experience, we use information about our Customers, including to process transactions with Customers, provide support to Customers, and operate and maintain the Products.
Security of the Products
For security purposes, we use information about Customers and their use of the Products to verify accounts and activity, to monitor suspicious or fraudulent activity and to identify violations of Terms of Use, and to assist Customers in their monitoring of such suspicious or fraudulent activity.
Our Legitimate Interests
To protect our legitimate business interests and legal rights, and where required by law or where we believe it is necessary to protect our legal rights, interests, and the interests of others, we use information about you in connection with legal claims, compliance, regulatory and audit functions, and disclosures in connection with the acquisition, merger, or sale of a business.
Your Consent
With your consent, we may use information about you for a specific purpose not listed above. For example, we may publish testimonials or featured Customer stories to promote the Products, with your permission.
Legal Bases for Processing (for EEA Users)
If you are an individual in the European Economic Area (EEA), we collect and process information about you only where we have a legal basis or bases for doing so under applicable EU laws. The legal bases depend on the Products that you use and how you use them, and/or how you interact with the Website(s), and/or whether you have a business relationship (for example, if you are an employee) with an Ethopass Customer or prospective Customer. This means we collect and use your Personal Information only where:
We need it to provide you the Products, including to operate the Products, provide Customer support and personalized features and to protect the safety and security of the Products;
It satisfies a legitimate interest (which is not overridden by your data protection interests, in our assessment after our analysis in compliance with applicable data protection laws), such as for research and development, to market and promote the Products and provide information to Customers and prospective Customers in such regard, and to protect our legal rights and interests;
You give us consent to do so for a specific purpose; or
We need to process your Personal Information to comply with a legal obligation.
WHAT ABOUT THE SECURITY OF PERSONAL INFORMATION?
Trust is earned, not given. Security is what we do, and we take the security of the Personal Information you provide to us very seriously. We use appropriate administrative, organizational, technical, and physical safeguards that are designed to protect the Personal Information we collect and process about you. However, no security system is impenetrable, and due to the inherent nature of the Internet, we cannot guarantee that data, including Personal Information, during transmission through the Internet or while stored on our systems or otherwise in our care, is 100% secure.
We only keep your Personal Information for as long as we have an ongoing legitimate business need to do so (for example, to fulfill the purposes outlined in this Privacy Policy, to operate the Website, to provide the Products or to comply with legal, tax, or accounting requirements, to enforce our agreements, or to comply with our legal obligations).
When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymise it. If this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.
We will retain Personal Information we process on behalf of visitors for as long as needed to provide Products to visitors. We will retain and use this Personal Information as necessary to comply with legal obligations, resolve disputes, and enforce our agreements.
WHAT ABOUT CUSTOMER TESTIMONIALS, COMMENTS, & REVIEWS?
We may post Customer testimonials, comments, and reviews on our Website, which may contain Personal Information. We do obtain the Customer's consent via email prior to posting the testimonial, in order to be able to post their name along with their testimonial. If you wish to update or delete your testimonial, you can contact us at legal@ethopass.com.
WHAT ABOUT CRYPTEX END USER PERSONALLY IDENTIFIABLE INFORMATION?
We do not collect personally identifiable information about individual end users that use the Cryptex on their own device or with a Customer (each a “Customer End User”). If you are a Customer End User and would no longer like to use Ethopass's Products, please contact that Customer directly.
We have no direct relationship with a Customer End User. Any such individual who seeks access to, or who seeks to correct, amend, or delete inaccurate data, or who seeks to exercise any other right(s) they may have as a data subject of a Customer, should direct their query to the Customer (the data controller) that uses the Products. In the unlikely event that a Customer has provided personally identifiable information about Customer End Users to Ethopass, if the Customer requests that Ethopass remove Customer End User personally identifiable information to comply with data protection regulations, we will respond to their request within 30 business days.
The security of data, which may include Personal Information, that is submitted by Customers to Ethopass (“Customer Data”), is very important to us. We maintain a comprehensive written information security program that contains industry-standard, administrative, technical, and physical safeguards designed to prevent unauthorized access to Customer Data.
WHAT AGE RESTRICTIONS APPLY?
As an enterprise software company providing the Products to Customers, our communications, business processes, and the Products themselves are not directed to individuals under age 18. We do not knowingly collect Personal Information from children under age 18. If we become aware that a child under age 18 has improperly provided us with Personal Information, we will take steps to delete such information. If you become aware that a child has provided us with Personal Information, please contact us.
WHAT ARE MY DATA PROTECTION RIGHTS, CONTROLS AND CHOICES?
We do not collect Personal Information from end users of the Cryptex or Customer End Users. We only collect Personal Information from Customers. Notwithstanding the foregoing, you have the following data protection rights, controls and choices.
You can access, review, change, update or delete your Personal Information at any time by emailing us at legal@ethopass.com.
You can request to have us remove your Personal Information from a Website testimonial. In some cases, we may not be able to remove your Personal Information, in which case we will let you know if we are unable to do so and why.
If you are a resident of the EEA, you can object to processing of your Personal Information, ask us to restrict processing of your personal information, or request portability of your personal information.
You can opt out of receiving promotional emails from us by clicking the “unsubscribe” link in the email or by emailing legal@ethopass.com. If you choose to no longer receive marketing information, we may still communicate with you about such things as your security updates, product functionality, responses to service requests, or other transactional, non-marketing, or administrative related purposes.
If we have collected and processed your Personal Information with your consent, then you can withdraw your consent at any time. Please note, though, that withdrawing your consent will not impact the lawfulness of any processing we conducted before you withdrew your consent, nor will it impact the processing of your Personal Information we conducted in reliance on lawful processing grounds other than consent.
You have the right to complain to a data protection authority about our collection and use of your Personal Information. For more information, please contact your local data protection authority. Contact details for data protection authorities in the EEA, Switzerland, and certain non-European countries (including the US and Canada) are available here.
If you would like to exercise any of your rights relating to your Personal Information, please start by contacting us using the contact details provided under the “What if I Have Additional Questions” section of this Privacy Policy.
We respond to all requests we receive from individuals wishing to exercise their data protection rights under applicable data protection laws. To protect your privacy and security, we take reasonable steps to verify your identity before granting you account access or making corrections to your Personal Information.
HOW DO WE HANDLE CHANGES TO OUR PRIVACY POLICY?
Ethopass may amend or update this Privacy Policy from time to time. You can review the most current version of this Privacy Policy at any time at http://www.ethopass.com/privacy/. Use of information we collect is subject to the Privacy Policy in effect at the time such information is used. If we make material changes in the way we use Personal Information, we will notify you by posting an announcement on the Websites or sending you an email prior to the change becoming effective. Your continued use of the Products following any such change constitutes your agreement to be bound by such changes to the Privacy Policy. Your only remedy, if you do not accept the terms of this Privacy Policy, is to discontinue use of the Products.
WHAT IF I HAVE ADDITIONAL QUESTIONS?
We have appointed a Data Protection Officer responsible for overseeing the implementation of the privacy program across Ethopass. If you have any questions about this Privacy Policy or Ethopass’s Websites, please contact us directly at: legal@ethopass.com. Written inquiries may be addressed to:
Ethopass, LLC
Attn: General Counsel
1245 Pearl St., Suite 208
Boulder, CO 80302
USA
If you wish to contact Ethopass’s representative pursuant to Article 27 of the General Data Protection Regulation, inquiries may be directed to:
Ethopass, LLC
Attn: General Counsel
1245 Pearl St., Suite 208
Boulder, CO 80302
USA