available within it.
Risk3sixty collects and uses information for the following purposes:
- Contact information, in order to deliver requested content (whitepapers) and market its services;
- Login information and usage information regarding Phalanx, in order to provide Phalanx and optimize its performance.
Risk3sixty does not use information for any purpose not described herein. If we process data for additional purposes in the future, such purposes shall be consistent with the purposes for which the data was originally collected. Otherwise, we will notify you of new purposes for processing and provide you the opportunity to opt out.
In addition, risk3sixty does not sell or disclose your data to third parties for marketing purposes. All third parties to whom disclosures may be made are disclosed in the section of this Policy titled “HOW WE SHARE DATA.”
Types of Data Processed
The information we collect from you depends on the nature of your relationship with
us, as well as whether we are a controller or processor. The information we collect may include Contact Information, Login Information, Usage Information, or Business-related Information as detailed below. Collectively, these types of information may be referred to as
“Personal Data” herein.
Your contact information is also collected when you use Phalanx based on our legitimate interest of personalizing the services and providing accurate logging capabilities.
Login information includes your username and password used to access Phalanx. Our legitimate interest in processing this data is to provide the Phalanx platform to our customers
Usage information is collected from various monitoring and analytics tools to fulfil our legitimate
interest of understanding your usage of the Phalanx platform. (See “Analytics and Tracking” below.)
Websites or Events:
We will use the information we collect via our Websites:
- To administer our Website, our events and for internal operations, including troubleshooting, data analysis, testing, statistical and survey purposes;
- To improve our Website to ensure that content is presented in the most effective manner for you and for your computer;
- For trend monitoring, marketing and advertising;
- For purposes made clear to you at the time you submit your information – for example, to fulfill your request for a demo, to provide you with access to one ofour webinar’s or whitepaper’s or to provide you with information you have requested about our Services; and
- As part of our efforts to keep our Website secure.
Our use of your Personal Information may be based on our legitimate interest to ensure network and information security, and for our direct marketing purposes, or you consenting to it (e.g. when you request a demo).
We may use the information we collect from our customers and their users in connection with the Services we provide for a range of reasons, including to:
- Set up a user account,
- Provide, operate and maintain the Services;
- Process and complete transactions, and send related information, including transaction confirmations and invoices;
- Manage our customers’ use of the Services, respond to inquires and comments and provide customer service and support;
- Send customers technical alerts, updates, security notifications, and administrative communications
- Investigate and prevent fraudulent activities, unauthorized access to the Services, and other illegal activities; and
- For any other purposes about which we notify customers and users.
We use your Personal Information in this context based on the contract that we have in place with you or our legitimate interest for security purposes (e.g. the prevention and investigation of fraudulent activities). Personal Information will be deleted based on the terms of the contract. You can exercise your rights regarding your personal information by contacting us.
You are not required to share the Personal Data that we request.
However, if you choose not to share such information, we will generally be unable to provide the Phalanx platform to you or interact with you regarding our services.
risk3sixty will never collect more of your Personal Data than is necessary for the intended purpose of processing that information. If you feel any data collected is not necessary for the intended purpose, please notify our Chief Privacy Officer.
Please see the YOUR PRIVACY RIGHTS section below to learn more about how you can control the information risk3sixty processes about you.
How We Share Data
Any data you provide may be shared with our affiliates in order to fulfil the purposes described herein. Risk3sixty will not disclose your data to third parties for direct marketing purposes.
Sharing with third party service providers. Risk3sixty engages with the following subprocessors to process Personal Data. Risk3sixty has reviewed subprocessor security policies and appropriate certifications to ensure that the subprocessor protects Personal Data in accordance with risk3sixty’s security standards.
|Amazon Web Services||Cloud Infrastructure||United States|
|Microsoft 0365||Electronic Communication||United States|
|Hubspot||Marketing content||United States|
|Google Analytics||Website Analytics||United States|
|Sendgrid||Send Email||United States|
Analytics and Tracking:
On some of our Websites, we also may utilize Google Analytics, a web analysis service provided by Google, to better understand your use of the Website and Services. Google Analytics collects information such as how often users visit the Websites, what pages they visit and what other sites they used prior to visiting. Google uses the data collected to track and examine the use of the Websites, to prepare reports on its activities and share them with other Google services. Google may use the data collected on the Websites to contextualize and personalize the ads of its own advertising network.
Google offers an opt-out mechanism for the web available here
Engaging in corporate transactions.
Complying with law / protecting legal rights. We may be required to disclose your information to comply with applicable laws (including laws outside of your country of residence), regulations, court orders, government and law enforcement requests, including national security or other law enforcement requirements. Additionally, if we reasonably believe that it is necessary or appropriate, we reserve the right to use or disclose your information to allow us to pursue available claims or remedies and protect our legal rights, property or the safety of our employees, users or others, to the extent allowed by applicable law. This includes exchanging information with companies and organizations for the purposes of fraud detection.
How We Keep Your Information Safe
ISO 27001/27701: The security of your personal information is important to us. We have implemented technical, organizational and administrative security measures to protect your information from unauthorized access, disclosure, misuse, alteration, accidental loss or destruction. In addition, we align to the ISO 27001 and ISO 27701 framework.
Risk3sixty has developed a comprehensive Information Security Policy to define security requirements for all personal information and preserve the confidentiality, integrity, and availability of personal information. The Information Security Policy, and all associated policies and procedures, are reviewed at least annually.
Technical measures to protect information include data encryption, access controls, and vulnerability management.
Risk3sixty defines security and privacy obligations for third party service providers, which providers must adhere to. A list of service providers is located above.
Storage and Retention of your Information
We will retain your Personal Data for as long as it is necessary to fulfil the purpose for which it was collected. We may also retain cached or archived copies of information provided to us. All data is encrypted in transit and encrypted at rest.
Your Privacy Rights
risk3sixty provides the ability for you to exercise certain rights with respect to your personal data. Please be aware that, if you do not allow us to collect your information from you, we will generally be unable to provide the Phalanx platform to you or interact with you regarding our services.
Your choices. In accordance with applicable law, you may be entitled to exercise your rights and choices as follows:
- Access and Rectification. You may access and correct information in your Phalanx profile through the Settings module. In addition, you may review your Phalanx usage log through the same module. If other information about you is incorrect, or you would like to access your data, you may respond to the person contacting you to request correction. Your access will be limited to Contact Information held by risk3sixty.
- Opt Out and Erasure. You may opt out of marketing solicitations at any time, as well as request erasure of your personal data provided to us. Please note that data collected for risk3sixty’s legitimate interests is not permitted to be erased.
- Right to Object. You may object to processing of your personal data in cases where risk3sixty relies on its legitimate interests to process your data. Risk3sixty has documented its legitimate interests and will provide them to you if you exercise this right.
- Data Portability. You are entitled to request copies of Personal Data that you have provided to us in a structured, commonly used and machine-readable format and/or request that this information be transmitted to another service provider (where technically feasible).
Privacy Relating to Minors
As a company focused on serving the needs of businesses, risk3sixty does not promote or market its services to minors and we do not knowingly collect information from minors as defined by applicable law. If we discover we have received any Personal Data from a person under the age of 13 in violation of this Policy, we will take reasonable steps to delete that information as quickly as possible.
If you believe we have any information from or about anyone under the age of 13, please contact us.
Updates and How to Contact Us
Written inquiries may be addressed to our Data Privacy Officer at:
Chief Privacy Officer
555 South Atlanta St.
Roswell, GA 30075