Privacy and Security
Last updated on July 24, 2017
We reserve the right to update and change this Policy from time to time and will provide notice to you by changing the “last updated” date above. All changes are prospective only. It is your obligation to be familiar with the most current version of the Policy. Continued use of the Service after any such changes shall constitute your acknowledgment of and consent to such changes. You can review the most current version of the Policy at any time at https://www.assetas.com/privacy.
If you are using the Service on behalf of a company or other legal entity, you represent and warrant that you have the authority to bind that company or other legal entity to this Policy, in such event, “You” will refer and apply to that company or other legal entity.
We collect, use and disclose two types of information: Personal Information and Non-Personal Information.
“Personal Information” is information that is directly associated with a specific person or entity, including but not limited to, names, email addresses, usernames, passwords, and payment information.
“Non-Personal Information” is information we collect or compile that by itself cannot be directly associated with a specific person or entity.
We may further compile “Non-Personal Information” into “Aggregate Data”. This Policy in no way restricts or limits our collection and use of Non-Personal Information and Aggregate Data, and we may share Non-Personal Information and Aggregate Data that we collect or compile with third parties for various purposes, including to help us better understand our customer needs and improve our Service, and for advertising and marketing purposes.
We automatically receive certain types of information when you interact with our Service. That information includes your computer’s IP address, access times, browser type and language, and referring website addresses. We may also collect information about the type of operating system you use, your account activity, and files or pages accessed or used by you.
You reserve the right to ask us what personal data is being processed and the rationale for such processing if that should ever be unclear.
While using our Service, you will have access to all data within your account. You reserve the right to access this data and/or request copies of this data.
While using our Service, you’ll be able to update all personally identifiable information to maintain accuracy.
You maintain the right to withdraw consent to manual or automated data processing when previous consent has been given. This could include all future processing or processing during a specific timeframe. This could include the removal of data from an account or a request to remove an email from a specific mailing list.
You reserve the right to erasure and data portability. You will have the ability to export data in your account and keep for yourself or import it into another system. After Service cancellation, data will not be retained on our servers if requested in writing. In addition, you can delete any type of personally identifiable information within your account or request to be removed from any type of customer communication at any time.
OPT-OUT OF TARGETED ADVERTISING
We have also included information about cookies set by third parties. Given that these relate to third party services, we cannot guarantee the completeness or accuracy of the list, but we can say that we have done our best to ensure the list is as accurate as possible at the time this policy was prepared.
ai_session. This cookie is used by Microsoft Application Insights software, which collects statistical usage and telemetry information for our web application. This is a unique anonymous session identifier cookie. The main purpose of this cookie is performance and this cookie expires in 1-hour.
ai_user. This cookie is used by Microsoft Application Insights software, which collects statistical usage and telemetry information for apps built on the Azure cloud platform. This is a unique user identifier cookie enabling counting of the number of users accessing the application over time. The main purpose of this cookie is performance and this cookie expires in 1-year.
AspNetCore.Antiforgery. This cookie authenticates the user when data forms are used on the website. The main purpose of this cookie is security and this cookie expires at the end of the session.
ARRAffinity. This cookie is used to affinitize a user to a specific instance of our application and allows the user to return to the same application instance. This cookie does not have any security or sensitive information.
We recommend that you review your browser's privacy settings and adjust them accordingly if you wish to deny cookies from any sites.
USE OF PERSONAL INFORMATION
We use collected information about you to process your requests or billing transactions, to provide you with information or services you request, to inform you about other information, events, promotions, products, or services we think will be of interest to you, and to support and facilitate your usage of the Service.
We also use collected information to track engagement in key product areas in an effort to continually improve the user experience. As mentioned above, you reserve the right to remove yourself from that type of tracking.
INFORMATION SHARING AND DISCLOSURE
We will not give, sell, rent, share, or trade any of your Personal Information or any data that you store using our Service to any third-party except i) with your explicit consent or ii) as outlined in this Policy. We reserve the right to share Non-Personal Information and Aggregate Data as described in this Policy.
We may share Personal Information with third-party service and technology providers to facilitate the operation of the Service, to perform related services (e.g., without limitation, maintenance services, database management, web analytics and improvement of the Service’s features, or to process credit card payments), or to assist us in analyzing how our Service is used.
We may disclose Personal Information to a third party to comply with a court order, subpoena, search warrant, or other legal processes; to comply with legal, regulatory, or administrative requirements of any governmental authorities; to protect and defend us, our subsidiaries and our affiliates, and our officers, directors, employees, attorneys, agents, contractors, and partners, in connection with any legal action, claim, or dispute; to enforce the Terms of Service; to prevent imminent physical harm; and in the event that we find that your actions violate any laws, our Terms of Service, or any of our usage guidelines for specific products or services.
MODIFYING YOUR PERSONAL INFORMATION
If you are a registered user of our Service, you may review, update, correct or delete your personal information by logging into the Service and editing your profile.
We are very concerned with safeguarding your information. We take reasonable steps to protect the information we collect from you to prevent loss, misuse and unauthorized access, disclosure, alteration, and destruction. Highly confidential personal information such as credit card data is protected with encryption using Secured Socket Layer (SSL) technology during transmission over the Internet. But, remember that no method of transmission over the Internet or method of electronic storage is 100% secure.
Your account information and access to our Service is accessible only through the use of an individual username and password. You should keep your password confidential and do not disclose it to any other person. Please note that we will never ask you to disclose your password in an unsolicited phone call or email. You are responsible for all activities which are conducted using your account or password.
All data in the Service is stored and processed through Microsoft Azure, which has its processing in the United States of America. You can learn more about Azure’ privacy and security processes at https://azure.microsoft.com/en-us/overview/trusted-cloud/privacy/.
In the case of a data breach, we will notify affected users – without undue delay and where feasible – within 72 business hours. The notification will include the nature of the breach, likely consequences, a detail action plan and a main technical point of contact at Assetas.