Privacy and Data Protection in Epsis
This Privacy Statement was published 20 November, 2018.
In Epsis we are committed to protect and respect your privacy in compliance with EU- General Data Protection Regulation (GDPR) 2016/679, dated April 27th 2016. This privacy statement explains when and why we collect personal information, how we use it, the conditions under which we may disclose it to others and how we keep it secure. This Privacy Statement applies to the use of our products and to our sales, marketing and customer contract fulfilment activities. It also applies to individuals seeking a job in Epsis.
Who are we?
Epsis AS provides consultancy services and supporting technologies that support our customers in creating significant value by optimising their business operations. We do this by connecting experts, technology and processes in to new ways of working, enabled by our technology platform – Epsis TeamBox. Our company’s headquarters is in Bergen, Norway, and have a presence in Houston, USA and Aberdeen, UK. The headquarters’ registered office address is Kokstadflaten 31, 5257 Kokstad, Norway.
Epsis AS is the data controller. Any query about your Privacy Rights should be sent to firstname.lastname@example.org
When do we collect personal data about you?
- When you request a licence for one of our products
- When you raise a product support request through our support portal
- When you interact with us in person, through correspondence, by phone, by social media, or through our websites.
- When we collect personal information from other legitimate sources, such as third-party data aggregators, Epsis partners, public sources or social networks. We only use this data if you have given your consent to them to share your personal data with others.
- We may collect personal data if it is considered to be of legitimate interest, and if this interest is not overridden by your privacy interests. Before data is collected we make sure an assessment is made, ensuring that there is an established mutual interest between you and Epsis.
Why do we collect and use personal data?
We collect and use personal data to perform direct sales, direct marketing and customer service. We also collect data about suppliers, partners and persons seeking a job or working in our company.
We may use your information for the following purposes:
- Send you marketing communications which you have requested. These may include information about our products and services, events, activities, and promotions of our associated partners’ products and services. This communication is subscription based and requires your consent.
- Send you information about the products and services that you have purchased from us.
- Perform direct sales activities in cases where legitimate and mutual interest is established.
- Provide you content and venue details on a webinar or event you signed up for.
- Reply to a ‘Contact me’ or other web forms you have completed on our website (www.epsis.no) e.g. to download a whitepaper or case study.
- Follow up on incoming requests (customer support, emails, chats, or phone calls).
- Provide access to our Customer Support portal.
- Perform contractual obligations such as order confirmation, license details, invoice, reminders, and similar. The contract may be with Epsis directly or with an Epsis partner.
- Notify you about any disruptions to our services (system messages).
- Contact you to conduct surveys about your opinion on our products and services.
- Process a job application.
Our legal basis for collecting personal data
Collecting personal data based on consents
The collection of personal data based on consent from the data subject will be done by using “Consent Forms” that will store documentation related to the consent given by the individual. Individual consents will always be stored and documented in our systems.
Collecting personal data based on contracts
We use personal information for fulfilling our obligations related to contracts and agreements with customers, partners and suppliers.
Collecting personal data based on legitimate interest
We may use personal data if it is considered to be of legitimate interest, and if the privacy interests of the data subjects do not override this interest. Normally, to establish the legal basis for data collection, an assessment has been made during which a mutual interest between Epsis and the individual person has been identified. This legal basis is primarily related to our sales and marketing purposes. We will always inform individuals about their privacy rights and the purpose for collecting personal data.
What type of personal data is collected?
We collect name, phone number, title and email address, in addition to your company’s name and contact information. We may also collect feedback, comments and questions received from you in service-related communication and activities, such as meetings, phone calls, documents, and emails. From our websites we may collect IP-address and actions taken on the site.
If you apply for a job at Epsis, we collect the data you provide during the application process.
Epsis does not collect or process any special categories of personal data, such as public unique identifiers or sensitive personal data.
How long do we keep your personal data?
We store personal data for as long as we find it necessary to fulfill the purpose for which the personal data was collected, while also considering our need to answer your queries or resolve possible problems, to comply with legal requirements under applicable laws, to attend to any legal claims/complaints, and for safeguarding purposes.
This means that we may retain your personal data for a reasonable period of time after your last interaction with us. When the personal data that we have collected is no longer required, we will delete it in a secure manner. We may process data for statistical purposes, but in such cases, data will be anonymized.
Your rights to your personal data
You have the following rights with respect to your personal data:
- The right to request a copy of your personal data that Epsis holds about you.
- The right to request that Epsis corrects your personal data if inaccurate or out of date.
- If you are a customer or partner and you have registered a profile on our Support Portal, you may update your user profile by logging into the Support Portal and selecting “Profile Settings”.
- The right to request that your personal data is deleted when it is no longer necessary for Epsis to retain such data.
- The right to withdraw any consent to personal data processing at any time. For example, your consent to receive e-marketing communications:
- If you want to withdraw your consent to e-marketing, please make use of the link to manage your subscriptions included in our communication. Please note that you may still receive system messages and administrative communications from Epsis, such as order confirmations, system messages and notifications about your account activities.
- The right to request that Epsis provides you with your personal data and, if possible, to pass on this information directly (in a portable format) to another data controller when the processing is based on consent or contract.
- The right to request a restriction on further data processing, in case there is a dispute in relation to the accuracy or processing of your personal data.
- The right to object to the processing of personal data, in the case data processing has been based on legitimate interest and/or direct marketing.
Any query about your Privacy Rights should be sent to email@example.com
Do we share your data with anyone?
We do not share, sell, rent, or trade your information with any third parties without your consent, except from what is described below:
Third-party Service Providers working on our behalf:
We may pass your information on to our distributors, agents, sub-contractors and other associated organizations with the purpose of them providing services to you on our behalf.
If required by law:
We will disclose your personal information if required by law or if we, as a company, reasonably believe that disclosure is necessary to protect our company’s rights and/or to comply with a judicial proceeding, court order or legal process. However, we will do what we can to ensure that your privacy rights continue to be protected.
Use of sub-contractors (processors and sub-processors)
If the sub-contractor processes Personal Data outside the EU/EEA area, such processing must be in accordance with the EU Privacy Shield Framework, EU Standard Contractual Clauses for transfer to third countries, or another specifically stated lawful basis for the transfer of personal data to a third country.
Changes to this Privacy Statement
Epsis reserves the right to amend this Privacy Statement at any time. The applicable version will always be found on our websites. We encourage you to check this Privacy Statement occasionally to ensure that you are happy with any changes.
If we make changes that significantly alter our privacy practices, we will notify you by email or post a notice on our websites prior to the change taking effect.
Your right to complain to a supervisory authority
If you are unhappy with the way in which your personal data has been processed, you may, in the first instance, contact firstname.lastname@example.org
If you remain dissatisfied, then you have the right to apply directly to your national supervisory authority for a decision. For Norway this is: