COLLECTION AND UTILIZATION OF PERSONAL INFORMATION
3.1 Customer Information – In order to use the Services, users may be required to have a valid SIR account to log in to the Services (“Account”). When you register for the Services or create an Account, SIR collects certain information from you (collectively, “Account Information”). When you register for the Services, SIR will collect the following Personal Information:
- Full Name
- Email address
When our users utilize the Services to send invoices, receipts and other documents SIR collects your IP address and mobile device ID. The Services will also keep track of invoices, receipts and other documents and transaction history.
3.2 Invoices, Receipts and other documents Recipients – SIR customers use the Services to create and send invoices, receipts and other documents to their clients and other third parties (“Recipients”). In order to provide these Services, SIR collects Personal Information about the Recipients from our customers. Such Personal Information may include:
3.3 Use of Personal Information – In addition to the purposes identified above, SIR may use Personal Information to:
- authenticate access to the Account and provide access to the Services;
- provide, operate, maintain and improve the Services;
- send technical notices, updates, security alerts and support and administrative messages;
- provide and deliver the Services and features you request, process and complete transactions, and send you related information, including confirmations and invoices;
- respond to comments, questions, and requests and provide customer service and support;
- communicate with customers about services, features, surveys, newsletters, offers, promotions, and provide other news or information about us and our select partners;
- investigate and prevent fraudulent transactions, unauthorized access to the Services, and other illegal activities;
- personalize and improve the Services, and provide content, features, and/or advertisements that match your interests and preferences or otherwise customize your experience on the Services;
- monitor and analyze trends, usage, and activities in connection with the Services and for marketing or advertising purposes;
- enable you to communicate, collaborate, and share files with users you designate; and
- to comply with our legal obligations, resolve any disputes that we may have with any of our users, and enforce our agreements with third parties.
When you visit the Website, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Website, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Website, and information about how you interact with the Website. We refer to this information as “Device Information”.
We collect Device Information using the following technologies:
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org.
- “Log files” track actions occurring on the Website, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps.
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Website.
The Website uses “cookies” to collect information and improve our products and services. A cookie is a small data file that is stored on your device. Cookies cannot be used to see any other data on your computer, nor can they determine your email address or identity.
We may use “persistent cookies” for customer registration ID and login password for future logins to our service.
We may use “session cookies” for Website visitors, including Recipients, to enable certain features of our service, to better understand how you interact with our Services and to monitor aggregate usage and web traffic routing on our Website and Platform.
The Website may also use technologies such as beacons, scripts, and tags. These technologies may be used for analyzing trends, administering the website, tracking users’ movements around the website, and gathering demographic information about our user base as a whole. Various browsers may offer their own management tools for removing these types of tracking technologies.
We may also use third-party ad companies to help provide some of our advertising services. These third parties may place cookies on your computer and collect data about your online activities across websites or online services when you are logged into the third-party service, including for targeted advertising.
DATA STORAGE LOCATION AND TRANSFER OF PERSONAL INFORMATION
SIR processes and stores its data, including Personal Information, on servers located in the United States. SIR may also share or disclose some personal data to:
- Third-party service providers: We may use service providers to process data including your personal data on our behalf. This processing is for several purposes, including for example sending out marketing material. Third party service providers process personal data only according to our instructions, under biding legal agreement, are bound by confidentiality clauses and are not allowed to use your personal data for other purposes.
- Payment providers and (other) financial institutions: We may need to share certain personal data with the payment service provider and the relevant financial institution to handle payments from you and to you. We may furthermore share data with relevant financial institutions, if we consider it strictly necessary for fraud detection and prevention purposes.
- Competent authorities: We disclose personal data to law enforcement agencies to the extent it is required by law or is strictly necessary for the prevention, detection or prosecution of criminal acts and fraud. We may need to further disclose data to competent authorities to protect and defend our rights or properties, or the rights and properties of our business partners.
By submitting Personal Information or otherwise using the Services, you agree to this transfer, storing or processing of your Personal Information in United States. You acknowledge and agree that your Personal Information may be accessible to law enforcement and governmental agencies in United States under lawful access regimes or court order.
We will keep your Personal Information for as long as it remains necessary for the identified purpose or as required by law, which may extend beyond the termination of our relationship with you. When an Account becomes inactive for an extended period of time, we will delete the Account and related data with prior advance notice to the Account holder.
Our customers who may use the Services to store invoices, receipts and other data including Personal Information, in accordance with their own retention policies.
ACCESS, CORRECTION AND ACCURACY RIGHTS TO PERSONAL DATA
You have the right to access the Personal Information we hold about you in order to verify the Personal Information we have collected in respect to you and to have a general account of our uses of that information. Upon receipt of your written request, we will provide you with a copy of your Personal Information, although in certain limited circumstances, and as permitted under law, we may not be able to make all relevant information available to you, such as where that information also pertains to another user. In such circumstances we will provide reasons for the denial to you upon request. We will endeavor to deal with all requests for access and modifications in a timely manner.
We will make every reasonable effort to keep your Personal Information accurate and up to date, and we will provide you with mechanisms to update, correct, delete or add to your Personal Information as appropriate. As appropriate, this amended Personal Information will be transmitted to those parties to which we are permitted to disclose your information. Having accurate Personal Information about you enables us to give you the best possible service.
RESIDENTS OF THE EUROPEAN ECONOMIC AREA (“EEA”)
The legal basis on which SIR relies to process Personal Information (known as “Personal Data” under the EU General Data Protection Regulation) is consent, fulfillment of our contracts with customers, as well as pursuit of legitimate business activities.
Where we collect Personal Data directly from the data subjects, such as our customers, and make decisions in regards to processing such Personal Data, we act as the data controller. Otherwise, where we process Personal Data on behalf of third parties (such as when our customers use the Services to process Personal Data of their clients), we are the data processor.
If you are a resident of the EEA, you have certain data protection rights. SIR takes reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed of what Personal Data we hold about you and if you want it to be removed from our systems, please contact us using the contact information set out below. Note that where we act as the data processor on behalf of our users, you will be required to contact the data controller directly to exercise your rights.
In certain circumstances, where we act as data controller, you have the following data protection rights:
- Request access to your Personal Information (commonly known as a “data subject access request”) – This enables you to receive a copy of the Personal Information we hold about you where we are the data controller and to check that we are lawfully processing it.
- Request correction of the Personal Information that we hold about you – This enables you to have any incomplete or inaccurate information we hold about you corrected, though we may need to verify the accuracy of the new information you provide to us.
- Request erasure of your Personal Information – This enables you to ask us to delete or remove Personal Information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Information where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully, or where we are required to erase your Personal Information to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Object to processing of your Personal Information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your Personal Information for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which overrides your rights and freedoms.
- Request restriction of processing of your Personal Information – This enables you to ask us to suspend the processing of your Personal Information in the following scenarios: (a) if you want us to establish the information’s accuracy; (b) where our use of the information is unlawful but you do not want us to erase it; (c) where you need us to hold the information even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your information but we need to verify whether we have overriding legitimate grounds to use it.
- Request the transfer of your Personal Information to you or to a third party – We will provide to you, or a third party you have chosen, your Personal Information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
- Withdraw consent at any time where we are relying on consent to process your Personal Information. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain services to you. We will advise you if this is the case at the time you withdraw your consent.
Please note that we may ask you to verify your identity before responding to such requests. You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the EEA. If you wish to exercise any of the rights set out above, please contact us using the contact details below.
CALIFORNIA PRIVACY RIGHTS
This section provides additional details about the Personal Information we collect about California consumers and the rights afforded to them under the California Consumer Privacy Act (the CCPA).
For more details about the Personal Information SIR has collected, please see the section “Information you provide us” above. We collect this Personal Information for commercial purposes described above. SIR does not sell (as that term is defined in the CCPA) the Personal Information we collect.
Subject to certain limitations, the CCPA provides California consumers the right to request to know more details about the categories or specific pieces of Personal Information we collect (including how we use and disclose this Personal Information), to delete their Personal Information, to opt out of any “sales” of Personal Information that may be occurring, and to not be discriminated against for exercising these rights.
California consumers may make a request pursuant to their rights under the CCPA by contacting us at the contact information below. We will verify your request using the information associated with your account, if available, including email address. Government identification may be required. Consumers can also designate an authorized agent to exercise these rights on their behalf.