GROVE HR - Privacy Policy

 

Last modified: 13/01/2020

 

Privacy Policy

This Privacy Policy describes how we - Grove HR (together with its affiliates companies - “grovehr.com”, “we”, “our” or “us”) collect, store, use and disclose personal data regarding individuals (“you”) who: (i) visit or otherwise interact with our websites (“Visitors”), available at www.grovehr.com, or any other website, webpage, e-mail, text message or online ad under our control (collectively - “Sites”); (ii) use our cloud-based visual work management platform, via the Sites, or the monday.com desktop or mobile applications, addons or extensions (the “Users”; and together with the Sites - the “Service”).

Your privacy is important to us, and we are strongly committed to making our practices regarding your personal data more transparent and fairer. Please read this Privacy Policy carefully and make sure that you fully understand and agree to it.

You are not legally required to provide us with any Personal Data (defined below), and may do so (or avoid doing so) at your own free will.

If you do not wish to provide us with such Personal Data, or to have it processed by us or any of our Service Providers (defined below), please simply do not enter our Sites or use our Service. You may also choose not to provide us with “optional” Personal Data, but please keep in mind that without it we may not be able to provide you with the full range of our services or with the best user experience when using our Service.

This Privacy Policy forms part of our Terms of Service (“Terms”). Any capitalized but undefined term in this Privacy Policy shall have the meaning given to it in the Terms.

DATA.

Account Information. KMS may use your Account Information as necessary to provide the Service to you, to contact you or a User regarding KMS’s or its Affiliates’ products and services.

We collect technical data, profile data, customer data, content, and other data received from you, your organization or other third party sources.

We collect various types of personal data regarding our Users as well as data regarding Visitors to our Sites. Such data is typically collected and generated through your interaction with us or our Service, through automatic means, or directly from you, from other Users, from our Customers, or from other third parties (including Service Providers, as hereinafter defined).
Specifically, we collect the following categories of data (which, to the extent it relates to an identified or identifiable individual, is deemed as “Personal Data“):

Data automatically collected or generated: When you visit, interact with, or use our Service, we may collect, record or generate certain technical data about you. We do so either independently or with the help of third party Service Providers (as defined in Section SECURITY below), including through the use of “cookies” and other tracking technologies (as detailed in Section SECURITY below).

Such data consists of connectivity, technical and aggregated usage data, such as IP addresses and general locations, device data (like type, operating system, mobile device id, browser version, locale and language settings used), date and time stamps of usage, the cookies and pixels installed or utilized on such device and the recorded activity (sessions, clicks and other interactions) of Visitors and Users in connection with our Service. In addition, phone calls (e.g. with our customer success or product consultants) may be automatically recorded, tracked and analyzed, for purposes including analytics, service-, operations-, and business quality control and improvements, and record-keeping purposes.

User Data received from you: When you contact us or sign up to the Service and create your individual profile (“User Profile”), you may provide us with Personal Data. This includes your name, workplace and position, contact details (such as e-mail, phone and address), account login details (e-mail address and passwords which are automatically hashed), as well as any other data you choose to provide when you use our Service, contact us, or interact with others via our Service. For example, you may connect your Google account when you sign up or login to the Service, and thereby provide us with your name, e-mail address, image and other details listed on your profile there. You may also provide us with your profile photo, location, time-zone, skills, device, general location, and activity logs and data; as well as your preferences, characteristics and objectives for using the Service (collectively, “User Data”).

You may also send us a “Contact Us” or support requests, or provide us with feedback, reviews, or answers to surveys or promotions, including by submitting an online form on our Service or social media channels, by posting on any of our online public forums or communities, by sending an e-mail to any of our designated addresses, or any other form of communication. Such data may include details on a problem you are experiencing, contact information and any other documentation, screen recording, screenshots or other information.

Our Customers may provide us with additional User Data such as their billing details, business needs and preferences. To the extent that such data concerns a non-human entity (e.g. the bank account of a company or business), we will not regard it as “Personal Data” and this Privacy Policy will not apply to it.

Data obtained through Analytics Tools: We use analytics tools (e.g. Google Analytics) to collect data about the use of our Sites and Service. Analytics tools collect data such as how often Users and Visitors visit or use the Sites or Service, which pages they visit and when, and which website, ad or e-mail message brought them there.

Customer Data. "Customer Data" means the records and other data you submit to and store in the Service about your employees and employment processes. Customer Data does not include Enrichment Data. You grant KMS the worldwide, nonexclusive right to copy, display, modify, store, process and otherwise use Customer Data, and permit KMS’s service providers to do so, during and after the term of this Agreement in order to do the following: (a) provide the Service and make Customer Data available to you, (b) improve the Service and KMS’s other products and services, and (c) create Enrichment Data (defined below) and make Enrichment Data available as part of the Service. You own and retain all rights in the Customer Data. After the Agreement ends KMS will use Customer Data on an ongoing basis to create Enrichment Data and make Enrichment Data available.

Enrichment Data. “” means the data we create based on the combination, aggregation, and/or analysis of Customer Data with similar data from other KMS customers, Usage Data, third party sources, or any combination of these. We provide you Enrichment Data as part of the Service. While Enrichment Data is based in part on Customer Data, KMS owns and retains all rights in the Enrichment Data, other than your Customer Data that is included among the Enrichment Data. Enrichment Data that is made available as part of the Service and that contains Customer Data that identifies you and your personnel are made available only to you or those third parties to whom you authorize to view that Enrichment Data; Enrichment Data that is made available generally (such as data about salary competitiveness within or across industries) will not reveal your identity, any of your Customer Data or the identity of your Users or your employees. KMS grants you a worldwide, nonexclusive right during the term of this Agreement to copy, display, modify, store, and otherwise use the Enrichment Data as part of your use of the Service.

Usage Data. As a part of the Service, KMS and its service providers may collect, process, store, modify, aggregate, and otherwise use statistics and other data regarding your use of the Service, such as the number and types transactions you conduct using the Service (“Usage Data”). Usage Data does not include your Customer Data or your Account Information. KMS owns and retains all rights in the Usage Data. We may use the Usage Data for any business purposes (including software use optimization and product marketing) provided that such use does not reveal your identity, any of your Customer Data or the identity of your Users or your employees.

Location. KMS processes on your behalf may be transferred to, and stored and processed in, the United States or any other country in which KMS or its Affiliates or subcontractors maintain facilities. You agree to any such transfer to any such country and to store and process Account Information and Customer Data in order to provide the Services.

General Use by KMS. KMS may transfer Customer Data, Usage Data and Aggregate Data to a third party in connection with (a) a permitted assignment of this Agreement or (b) a delegation of hosting, transmission or other duties, as long as the third party provider agrees to abide by confidentiality obligations similar to the ones contained in this Agreement. In addition, KMS may disclose Account Information, Customer Data, Usage Data, and Aggregate Data if required by law or to any government body upon its audit or other inspection of the records or facilities of KMS or its providers. You represent and warrant that you have the right to use and permit KMS and its Affiliates to use your Account Information and Customer Data in accordance with this Agreement.

 

SECURITY.

Data. KMS will implement commercially reasonable safeguards intended to protect the confidentiality of Account Information and Customer Data. KMS will maintain a security policy that complies with the ISO 27001 standards for the establishment, implementation, control, and improvement of the Information Security Management System and the ISO/IEC 27002 code of best practices for information security management (“Information Security Policy”). Subject to your agreement to non-disclosure obligations KMS specifies, KMS will make the Information Security Policy available to you, along with other information reasonably requested by you regarding KMS security practices and policies.

Cookies and tracking technology. We and our Service Providers use cookies and other technologies for performance, tracking, analytics and personalization purposes.

Our Sites and Service (including some of our Service Providers) utilize “cookies”, anonymous identifiers, container tags and other technologies in order for us to provide our Service and ensure that it performs properly, to analyze our performance and marketing activities, and to personalize your experience. Such cookies and similar files or tags may also be temporarily placed on your device. Certain cookies and other technologies serve to recall Personal Data, such as an IP address, previously indicated by a User. To learn more about our practices concerning Cookies and Tracking, please see our Cookie Policy.

Please note that we do not change our practices in response to a “Do Not Track” signal in the HTTP header from a browser or mobile application, however, most browsers allow you to control cookies, including whether or not to accept them and how to remove them. You may set most browsers to notify you if you receive a cookie, or you may choose to block cookies with your browser.

Data Sharing. We share your data (& feedback) with our Service Providers; our Customers; within our group; in accordance with legal compliance and amongst Users on your shared boards.

Legal Compliance: In exceptional circumstances, we may disclose or allow government and law enforcement officials access to your Personal Data, in response to a subpoena, search warrant or court order (or similar requirement), or in compliance with applicable laws and regulations. Such disclosure or access may occur if we believe in good faith that: (a) we are legally compelled to do so; (b)disclosure is appropriate in connection with efforts to investigate, prevent, or take action regarding actual or suspected illegal activity, fraud, or other wrongdoing; or (c) such disclosure is required to protect the security or integrity of our products and services.

Service Providers: We may engage selected third party companies and individuals to perform services complementary to our own. Such service providers include Third Party Service providers, hosting and server co-location services, communications and content delivery networks (CDNs), data and cyber security services, billing and payment processing services, fraud detection and prevention services, web analytics, e-mail distribution and monitoring services, session or activity recording services, remote access services, performance measurement, data optimization and marketing services, social and advertising networks, content providers, e-mail, voicemails, support and customer relation management systems, and our legal and financial advisors (collectively, “Service Providers“).

These Service Providers may have access to your Personal Data, depending on each of their specific roles and purposes in facilitating and enhancing our Service, and may only use it for such limited purposes as determined in our agreements with them. When our Service Providers contact you in order to offer or promote our Service, they may additionally interest you in their own services. Should you decide to engage in such activities with grovehr.com Service Providers, please note that such engagement is beyond the scope of grovehr.com’s Terms and Privacy Policy and will therefore be covered by our Service Provider’s terms and privacy policy.

Sharing Personal Data with our Customers and other Users: We may share your Personal Data with the Customer owning the Account to which you are subscribed as a User (including data and communications concerning your User Profile). In such cases, sharing such data means that the Account’s Admin(s) may access it on behalf of the Customer, and will be able to monitor, process and analyze your Personal Data. This includes instances where you may contact us for help in resolving an issue specific to a team of which you are a member (and which is managed by the same Customer).

Any Customer Data or other content submitted by you to private Boards may still be accessed, copied and processed by the Customer’s Admin(s). Your User Profile and User Data will also be made available to all the authorized Users who can view the same Board(s) as you. Please note that monday.com is not responsible for and does not control any further disclosure, use or monitoring by or on behalf of the Customer, that itself acts as the “Data Controller” of such data (as further described in Section 9 below).

If you register or access the Service using an e-mail address at a domain that is owned by your employer or organization (our Customer), and another team within such Customer’s organization wishes to establish an account on the Service, certain information about you including your name, profile picture, contact info and general use of your account may become accessible to the Customer’s Admins and Users.

Sharing your Feedback or Recommendations: If you submit a public review or feedback, note that we may (at our discretion) store and present your review to other users of our Sites and Service (including other Customers). If you wish to remove your public review, please contact us at support@monday.com. If you choose to send others an e-mail or message inviting them to use the Service, we will use the contact information you provide us to automatically send such invitation e-mail or message on your behalf. Your name and e-mail address may be included in the invitation e-mail or message.

Protecting Rights and Safety: We may share your Personal Data with others if we believe in good faith that this will help protect the rights, property or personal safety of grovehr.com, any of our Users or Customers, or any members of the general public.

Individual Requests. Other than User requests with respect to their Account Information as part of their use of the Service, KMS will not independently respond to requests from your employees or other individual data subjects about personal data in any Account Information or Customer Data we store, without your prior written consent, except where required by applicable law.

Incidents. If KMS becomes aware of any unlawful access to any Account Information or Customer Data stored under KMS’s control as part of the Services, or unauthorized access to such equipment or facilities resulting in loss, disclosure, or alteration of Account Information or Customer Data (each a “Security Incident”), then KMS will promptly (a) initiate remedial actions that are in compliance with applicable law and consistent with industry standards, and (b) notify you of the Security Incident, its nature and scope, the remedial actions we will undertake, and the timeline within which we expect to remedy the breach. You will be responsible for fulfilling your obligations under applicable law.

Communications: We engage in service and promotional communications, through e-mail, phone, SMS and notifications.

Service Communications: We may contact you with important information regarding our Service. For example, we may send you notifications (through any of the means available to us) of changes or updates to our Service, billing issues, service changes, log-in attempts or password reset notices, etc. Our Customers, and other Users on the same Account, may also send you notifications, messages and other updates regarding their or your use of the Service. You can control your communications and notifications settings from your User Profile settings. However, please note that you will not be able to opt-out of receiving certain service communications which are integral to your use (like password resets or billing notices).

Promotional Communications: We may also notify you about new features, additional offerings, events and special opportunities or any other information we think our Users will find valuable. We may provide such notices through any of the contact means available to us (e.g. phone, mobile or e-mail), through the Service, or through our marketing campaigns on any other sites or platforms.
If you do not wish to receive such promotional communications, you may notify monday.com at any time by sending an e-mail to support@monday.com, changing your communications preferences in your User Profile settings, or by following the “unsubscribe”, “stop”, “opt-out” or “change e-mail preferences” instructions contained in the promotional communications you receive.

UPDATES AND AMENDMENTS: We may update and amend this Privacy Policy from time to time by posting an amended version on our Service. The amended version will be effective as of the date it is published. When we make material changes to these Terms, we’ll provide Customer with notice as appropriate under the circumstances, e.g., by displaying a prominent notice within the Service or by sending Customer an email. Your continued use of the Service after the changes have been implemented will constitute your acceptance of the changes.