1. What does this Policy cover?
Imprivata respects your privacy and is committed to protecting your information and complying with all applicable privacy laws in the conduct of its business. Privacy laws in the United States, European Economic Area (EEA), and other locations may govern the proper use, processing, disclosure, storage, and protection of Personal Data. This statement describes Imprivata's practices regarding the use and disclosure of Personal Data that may be collected.
- What information we collect and why we collect it.
- How we use that information.
- The categories of third parties to which we may send that information.
- International transfers of data
- The choices we offer, including how to access and update information.
2. What type of information does Imprivata collect and why?
Our primary goal in collecting information is to provide you with a friendly, customized, and efficient experience. We collect the following types of information:
- Other Information. "Other Information" is any information that does not and cannot be used to reveal your identity or that of another individual, such as information which has been fully and permanently anonymized and aggregated. We use this information to facilitate our operation of the Sites and for other purposes described below.
3. Children’s Data
Imprivata does not knowingly collect personal Information from children under the age of 13. If you are under the age of 13, please do not provide any information to us. If we become aware that we have collected information from a child under the age of 13, we will make commercially reasonable efforts to delete such information from our systems.
4. How does Imprivata collect information?
We and our service providers collect Personal Data and Other Information in a variety of ways, including:
- Through the Sites:
We collect information through the Sites, e.g., when you request a demo, register for a webinar, contact us, subscribe to our digital communications, download content (e.g., whitepapers, analyst reports, etc.), register to use our Sites, apply for employment, etc.
We collect information from you offline, such as when you attend one of our events or our booth at trade shows and exhibits, during phone calls with sales representatives, or when you contact an Imprivata representative.
- From Other Sources:
In order to enhance our ability to provide relevant marketing, offers, and services to you, we obtain information about you from other sources, such as public and third-party databases, joint marketing partners, social media platforms, and from other third parties.
- Through Your Browser or Device:
Certain information is collected by most browsers or automatically through your device, such as your Media Access Control (MAC) address, device type (computer, tablet, smartphone, etc.), screen resolution, operating system name and version, language, Internet browser type and version, and the name and version of the Sites you are using. Your Internet Protocol (IP) Address is a number that is automatically assigned to the device that you are using by your Internet Service Provider (ISP). An IP Address may be identified and logged automatically in our server log files whenever you access the Sites, along with the time and or length of the visit and the page(s) that you visited. Collecting IP Addresses is standard practice and is done automatically by many websites, applications, and other services. Imprivata uses IP Addresses to calculate usage levels of the Sites, help diagnose problems with its servers, administer the Sites, and for monitoring the regions from which you navigate to Imprivata's Sites. If you use a mobile device to access our Sites, we may receive information about the location of your device. In some cases, even if you are not using a mobile device, information about your general location may be discernible from your device’s IP address or the URLs we receive.
- As a Customer:
Imprivata collects information such as your location, use of Imprivata solutions, your preferred means of communication when you voluntarily provide it in subscription center or otherwise. Unless combined with Personal Data, this information does not personally identify you or any other user of the Sites. We, and our service providers, track and collect App usage data, such as the date and time the App on your device accesses our servers and what information and files have been downloaded to the App based on your device number.
We collect Personal Information only when you provide such information directly to us in connection with a Product or Service offering. We ask for Personal Information such as your name and e-mail address when you correspond with us for information or support. We may also retain any messages you send to us through the Service and may collect content and information you provide through logs.
- Through Feedback:
We may, from time to time, contact you to request your voluntary feedback on Imprivata products and services through surveys, beta agreements, research studies, etc.
- Through Cookies and Other Similar Technologies:
- Through Aggregation: Aggregated Personal Information does not personally identify you or any other user of the Sites (for example, we may aggregate Personal Information to calculate the engagement of our marketing content by region).
5. Will Imprivata share any of the information it receives?
We neither rent nor sell your personal information to anyone. Imprivata may disclose personal data to approved third party data processors retained or contracted by Imprivata, such as business partners and subcontractors, including, without limitation, affiliates, vendors, service providers and suppliers. We may share certain personal information with third parties who conduct marketing studies and data analytics, including those that provide tools or code which facilitates our review and management of our web site and services, such as Google Analytics or similar services from other providers. Details on how Imprivata shares personal information is described below:
- Subsidiaries and Affiliates:
- Agents and Service providers:
We contract with other companies and people to perform tasks on our behalf and may need to share your information with them to provide products or services to you. Examples may include removing repetitive information from customer lists, analyzing data, providing marketing assistance, billing or processing credit card payments, hosting our Sites and Service Offerings, and providing customer service or technical support. We may also provide your personal information to agents who will use it to verify aggregate usage data that we provide to our partners. In all cases where we share your information with such agents, we explicitly require the agent to acknowledge and adhere to Imprivata's privacy and customer data handling policies.
- Imprivata custom portal and social media pages:
Personal Data may also be disclosed by you through the Sites, on message boards, chat, profile pages, and other services to which you are able to post information and materials (including, without limitation, the Imprivata Support and Learning Center and the Social Media Pages). This information can appear in public ways, such as through search engines or other publicly available platforms and can be "crawled" or searched by third parties. Please do not post any information that you do not want to reveal to the public at large.
- Promotional offers:
We may send offers to certain customers on behalf of other businesses with whom we have a partnership. However, when we do so, we do not give the other business your personal information. We will always ask for your permission if we intend to share your personal information in this manner.
- Business Transfers:
In some cases, we may choose to buy or sell assets or businesses. In these types of transactions, customer information is typically one of the business assets that are transferred. Moreover, if Imprivata, or substantially all of its assets, were acquired then customer information would be one of the assets that are transferred.
- Profiling and Automated Decision-making:
Imprivata combines data obtained by the methods described in Section 3 to help us determine what products and services might be of interest to you when you might be ready to make a purchase based on repeated interaction with Imprivata and certain third-party websites, emails, and content. Imprivata marketing and sales personnel are involved in this process and no automated decisions are made that would result in legal effects or similarly significantly affect an individual.
- Protection of Imprivata and others:
We may release personal information when we believe in good faith that release is necessary to comply with that law; enforce or apply our conditions of use and other agreements; or protect the rights, property, or safety of Imprivata, our employees, our users, or others. This includes exchanging information with other companies and organizations for fraud protection and credit risk reduction. We release Personal Data, as we believe necessary and appropriate to law enforcement, tax, fraud prevention, credit risk agencies, other companies and organizations, as well as any other lawfully permitted or mandated third parties.
- With your consent:
6. Will Imprivata sell my information?
Imprivata does not sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate orally, in writing, by electronic, or other means the Personal Information it collects from you to another business or third party for monetary or other valuable consideration.
7. How will Imprivata communicate with me?
Service Email: As someone with an active account, we may send you service-related email messages, which are not promotional in nature, on occasions and when it is necessary. Similarly, if you request assistance with a Site or one of our products or services, we will communicate with you through email or other online help sessions until we have addressed your questions.
Customer Service: Based upon the information you provide us, we will communicate with you in response to your inquiries, to provide the services you request, and to manage your account. We may communicate with you by email, through an online help forum, or by telephone.
Newsletters and Promotions: If you register for our newsletters, whitepapers, and/or other educational or promotional content, or otherwise indicate your interest in our Products and/or Services, we will follow up via email and telephone with recommendations for our products and services based on your likely interests. You can unsubscribe or opt/out of any or all email marketing you may receive at any time.
8. Is information about me protected and secure?
Imprivata considers information security to be a top priority and is committed to protecting the security of your Personal Data. Imprivata does not collect more information than is necessary and implements systems, applications and procedures to secure personal information, to minimize the risks of theft, damage, loss of information, or unauthorized access or use of information, in particular, where the processing involves the transmission of data over a network, and against all other unlawful forms of processing. When we transmit highly confidential data over the Internet, we protect it through encryption.
Imprivata has comprehensive security policies and accompanying procedures which include but are not limited to access controls, encryption, 3rd party risk management, etc. All information collected and stored by Imprivata is maintained in secure data centers and/or otherwise subject to best practice access protection. Only employees or contractors who need customer information to perform a specific job (for example, a customer service representative) are granted access to it. All our employees and contractors are required to keep up to date on our privacy and security practices and are subject to confidentiality agreements and regular training.
9. International transfers
Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Sites or disclosing information to us you consent to the transfer of information to countries outside of your country of residence, which could have different data protection rules than those of your country or the country in which you were located when you initially provided the information. Where required, we put in place a solution to ensure that Personal Information transferred outside of the EEA is subject to adequate protection.
Imprivata complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework. We are committed to subjecting all Personal Information received from European Union (EU) member countries, the United Kingdom, and Switzerland, respectively, in reliance on each Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Frameworks, and to view our certification, visit the U.S. Department of Commerce’s Privacy Shield List: https://www.privacyshield.gov/list. Click here to access Imprivata’s Privacy Shield Policy.
Imprivata is responsible for the processing of Personal Information it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. Imprivata complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, the United Kingdom, and Switzerland, including the onward transfer liability provisions.
With respect to Personal Information received or transferred pursuant to the Privacy Shield Framework, Imprivata is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission.
10. What are my rights as a data subject?
The right to access your information.
The right to know whether your personal information is sold or disclosed and to whom.
The right to opt out of sale of your personal information.
The right to request that we delete some or all the information we have collected about you.
The right to equal service and price, even if you exercise your privacy rights.
The right to ask us to transmit your personal information that we have collected on you to another provider (where technically feasible).
Rectification of information: the right to request that we amend any of the information that we have collected about you.
The right to withdraw your consent to the processing of your data.
The right to request that we restrict the processing of your data.
The right to lodge a complaint regarding our collection, sharing and processing of data with competent authorities in the proper jurisdiction.
The right to lodge a complaint regarding our collection, sharing and processing of data with the Information Commissioner's Office or any other competent authority.
The right to not have to identify yourself, or of using a pseudonym in certain circumstances.
The right to stop receiving unwarranted direct marketing.
How can I exercise my rights?
If you would like to exercise any of your data subject rights, submit a consumer request to firstname.lastname@example.org. We will need to verify your identity in order to process any requests and will need your name, email address, and phone number to do so. Imprivata responds to requests within 30 days. If a request requires additional time to be processed, we will notify you in writing. Certain exceptions apply in the law. If your request is denied, we will provide you with the reasons for such a denial.
You can opt-out of receiving marketing messages from Imprivata by unsubscribing through the unsubscribe or opt-out link in an email, or by unsubscribing via the Imprivata Subscription Center: https://security.imprivata.com/email-subscription-center.html. If you need additional assistance, you may call 1 800 846 9407. Imprivata will never discriminate against you for exercising your rights as a consumer.
12. Data Retention
We retain the Personal Information we collect where we have an ongoing legitimate business need to do so (for example to comply with applicable legal, tax or accounting requirements). When we have no ongoing legitimate business need to process your Personal Information, we will either delete or aggregate it or, if this is not possible due to practical or legal requirements, then we will securely store your Personal Information. If you would like to request we no longer use your information to provide you with services, contact email@example.com.
13. Conditions of Use
This website is not intended for anyone under the age of 16 years. If you are younger than 16, you may not register with or use this website.
14. Third party sites
The Site may permit you to link to other websites on the Internet, and other websites may contain links to the Imprivata site. These other websites are not under Imprivata's control, and such links do not constitute an endorsement by Imprivata of those other websites or the services offered through them. The privacy and security practices of websites linked to or from the Imprivata site are not covered by this Privacy Statement and may differ from those of Imprivata. We encourage you to read the privacy statement of any website you may visit because we are not responsible for other sites' content or policies. Imprivata is not responsible for the privacy or security practices or the content of such websites.
16. Questions or Concerns
Your privacy is important to us and we will make every effort to resolve your concerns. If you have any questions, concerns, or would like to submit a complaint regarding privacy, please email firstname.lastname@example.org or call 1 800 846 9407. You may also visit https://imprivatadsr.ethicspoint.com for more details and to submit a Data Subject Request