Approved by: N.Gallo
Review date: 1/31/2020
Approved date: 1/31/2020
Effective date: 12/29/2016
Revised date: 1/31/2020
This privacy statement applies to mycompliancereport.com and ComplianceLine websites, services and products that collect data and display these terms. It does not apply to any ComplianceLine site, service or product that does not display or link to this statement or that contains its own privacy statement.
ComplianceLine does not publish text, images, or multimedia content that portray nudity, foul language, violence or other information not suitable for children. Web sites maintained by ComplianceLine are not directed to children under the age of 13. ComplianceLine will not knowingly collect or maintain personally identifiable information from or about anyone under 13. ComplianceLine is committed to complying with privacy laws to which it is subject and adhering to the highest industry standards for privacy.
ComplianceLine is not responsible for content saved to any ComplianceLine system by Hotline reporters or client company representatives
Collection and Use of Information
ComplianceLine collects different kinds of information in order to provide you with the best products and services and to operate effectively. Some of this information is provided directly by you, while other information may be provided by your employer in connection with use of our products and services. We may also gather information by observing how you interact with our website, products and services. The personal data that is provided to ComplianceLine will be disclosed to the organization with whom you are affiliated
What information we collect:
- Registration: When you, or your organization, sign up to use our sites or services, or you sign up to attend a webinar or get additional information about our products and services, we may receive certain necessary information such as your name, job title and contact information such as email address, phone number and address.
- Account/Report Access: To access some of our products and services you may be required to provide us specific information (such as your login credentials) that allows us to verify your identity before accessing certain data we host. This identity verification information is kept secure on our private servers and is only used to assist you in accessing your account or report; this information is not released outside of the relevant ComplianceLine system unless specifically authorized.
- Hotline Reporters: No personally identifying information is automatically collected from reporters using ComplianceLine applications. Personally identifying information, such as name and e-mail address, is stored only when a reporter voluntarily gives this information for use by a client company.
How we collect information:
ComplianceLine gathers information about how you use our sites and services in a number of ways, including:
- Web forms, such as when you type information into a registration form
- Technologies like cookies (please see Cookies for more information about this technology)
- Web logging, which enables us to collect the standard information your browser sends to every web site you visit such as your IP address, browser type and language, and the site you came from as well as pages you visit and links you click on within our site
How we use Personal Information:
ComplianceLine uses the information we collect to operate and improve our products and services and to respond to requests about promotions or products and services offered.
When ComplianceLine collects personally identifiable information from visitors to our sites, the information collected from opt-in users is used only to respond to visitors’ requests. In instances where opt-in participants’ requests relate to ComplianceLine partners, we will provide personally identifiable information only to respond to that request. ComplianceLine does not sell, rent, lease, trade or share visitors’ personally identifiable information other than as outlined in this Policy. When you provide us with your personally identifiable information or otherwise choose to sign up to receive email communications from us, we will use that information to send those communications to you. Individuals may “opt-in” and “opt-out” of receiving e-mail communications through selections available on e-mails received. For participants of our web seminars, the only personally identifiable information we share is web seminar registration information and it is only shared with our web seminar presenters to provide this service. They are not permitted to use this information for their own marketing purposes.
Licensed Users of Products and Services:
Personally identifiable information such as name, contact information, username and password is stored in our database for access to and use of certain software applications. This information is kept secure on our private servers and is only used to assist you in accessing your account. No information is released outside of the ComplianceLine system unless specifically authorized.
No personally identifiable information is automatically collected from reporters submitting a case. Personally identifying information, such as name and e-mail address, is collected and stored only when a reporter voluntarily gives this information.
Use of Cookie, Clear Gif and Log File Technology:
Technologies such as: cookies, beacons, tags, and scripts are used by us and our tracking utility partners. These technologies are used in analyzing trends, administering the site, tracking users’ movements around the site and to gather demographic information about our user base as a whole. We may receive reports based on the use of these technologies by these companies on an individual as well as aggregated basis.
A “cookie” is a small text file that is stored on a user’s computer.
ComplianceLine utilizes Cookie technology on our sites for purposes of Website traffic analysis such as the time/date of the visit, the time/date of last visit, the page viewed, the referring site, and other data. ComplianceLine also tracks click behavior in the e-mails it sends out. This data is used to update specific user-profile information, ascertain the areas of most interest to opt-in e-mail recipients, and to personalize e-mail messages to them.
We also use session ID cookies for access to products and services by our licensed users and reporters. These session Cookies are used to make it easier to navigate our site, products and services. A session ID Cookie expires when your browser is closed.
If you reject Cookies, you may still use portions of our site, but your ability to use some areas of our site, products or services, may be limited.
In limited circumstances, and with appropriate notice to licensed users, we will use persistent Cookies (Cookies that do not expire when your browser is closed). In these situations, licensed users are required to consent to the placement of a Cookie prior to it being activated and consent may be withdrawn at any time by simply accessing the form and un-ticking the box giving ComplianceLine permission to store the information. Any persistent Cookie that is unused for 30 days will automatically expire.
We and our third party tracking-utility partners employ a software technology called clear gifs (a.k.a. Web Beacons/Web Bugs), that help us better manage content on our site by informing us what content is effective. Clear gifs are tiny graphics with a unique identifier, similar in function to cookies, and are used to track the online movements of Web users. In contrast to cookies, which are stored on a user’s computer hard drive, clear gifs are embedded invisibly on Web pages and are about the size of the period at the end of this sentence. We do not tie the information gathered by clear gifs to our customers’ personally identifiable information.
We use clear gifs in our HTML-based emails to let us know which emails have been opened by recipients. This allows us to gauge the effectiveness of certain communications and the effectiveness of our marketing campaigns.
As true of most web sites, we gather certain information automatically and store it in log files. This information may include internet protocol (IP) addresses, browser type, internet service provider (ISP), referring/exit pages, operating system, date/time stamp, and/or clickstream data. We do not link this automatically collected log information with other information we collect about you.
Local Storage Objects (Flash/HTML 5)
We use Local Storage Objects (LSOs) such as HTML 5 to store content and preferences. Third parties with whom we partner to provide certain features on our site to display advertising based upon your web browsing activity use LSOs such as HTML 5 to collect and store information. Various browsers may offer their own management tools for removing HTML 5 LSOs.
We partner with a third party ad network to either display advertising on our Web site or to manage our advertising on other sites. Our ad network partner users cookies and Web beacons to collect non-personal information about your activities on this and other Web sites to provide you targeted advertising based upon your interests. If you wish to not have this information used for the purpose of serving you targeted ads, you may opt-out by clicking here. Please note this does not opt you out of being served advertising. You will continue to receive generic ads.
ComplianceLine will take reasonable precautions to protect personal information in its possession from loss, misuse and unauthorized access, disclosure, alteration and destruction.
For licensed users and reporters, communications between the ComplianceLine site and a user’s web browser are accomplished using, at a minimum, 128 bit SSL encryption and various third party security certificates to protect confidential data. ComplianceLine does not allow users to transfer or receive confidential information unless they are using a validated 128 bit (or greater) encrypted session.
We follow generally accepted industry standards to protect the personal information submitted to us, both during transmission and once we receive it. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
If you have any questions about security on our Web site, you can e-mail us at email@example.com with “Questions about Web site Security” in the subject line. We do not link this automatically-collected data to personally identifiable information.
Automatic Information Storage
Session Variables may be used temporarily in your system cache to create ease-of-use during your transaction. Examples of such information are automatically-produced alphanumeric numbers held during your session on our site to facilitate page-to-page transactions. We only store name, e-mail, phone, address, company name or any other identifying information for licensed users; no information is stored for others unless otherwise stated in this policy.
Use of Third Party Services
ComplianceLine contracts with select third parties for Web-based services that include e-mail delivery and content streaming, that may collect non-personally identifiable visitor data including IP address and pages visited. These third parties may only use personally identifiable information, for example, e-mail addresses, for the service requested and not for their own marketing purposes.
ComplianceLine also contracts with select third parties in connection with the delivery of services to our clients. These third parties may not use any personally identifiable information other than to provide the specific contracted services.
Our Web site offers publicly accessible blogs or community forums. You should be aware that any information you provide in these areas may be read, collected, and used by others who access them. To request removal of your personal information from our blog or community forum, contact us at firstname.lastname@example.org. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.
Links to Other Sites
Our Site includes links to other Web sites whose privacy practices may differ from those of ComplianceLine. If you submit personal information to any of those sites, your information is governed by their privacy statements. We encourage you to carefully read the privacy statement of any Web site you visit.
Social Media Features and Widgets
No company other than ComplianceLine is allowed to access information stored on our servers, unless expressly authorized by ComplianceLine. Unauthorized access to this information is a violation of the law. ComplianceLine has placed security measures and firewalls on all network servers in an attempt to prevent outside parties from accessing private information. In the event of a breach of security, ComplianceLine will press charges to the fullest extent possible against those parties illegally accessing information on our servers.
EU-U.S. Privacy Shield and Swiss-US Privacy Shield
ComplianceLine participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. ComplianceLine is committed to subjecting all personal data received from European Union (EU) member countries or Switzerland, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List. [https://www.privacyshield.gov/list]
ComplianceLine is responsible for the processing of personal data it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. ComplianceLine complies with the Privacy Shield Principles for all onward transfers of personal data from the EU or Switzerland, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, ComplianceLine is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, ComplianceLine may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Under certain conditions, more fully described on the Privacy Shield website [https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint], you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
Access to Personal Information
Upon request, ComplianceLine will provide you with information about whether we hold, or process on behalf of a third party, any of your personal information. To make a request please contact us at email@example.com with “Request of Personal Information Status” in the subject line, and provide us with full details in relation to your request, including your contact information, your company’s name and any other detail you feel is relevant.
Upon request by mail or e-mail (to the addresses noted below in the Contact Information section), ComplianceLine will grant individuals reasonable access to personal information that it holds about them, unless otherwise legally unable to do so. In addition, ComplianceLine will take reasonable steps to permit individuals to correct, amend, or delete information that is demonstrated to be inaccurate or incomplete. ComplianceLine will also take reasonable steps to permit individuals to request to correct, amend, limit the use and disclosure of, or delete personal information through these means. ComplianceLine shall provide a response to an access request within 30 days of receiving such request.
We will retain your information for as long as your account is active or as needed to provide services to your organization. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Disclosure Pursuant to Judicial or Governmental Subpoenas, Warrants or Orders
In certain situations, ComplianceLine may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
We reserve the right to disclose your personally identifiable information as required by law and when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, or legal process served on us.
In the event ComplianceLine goes through a business transition, such as a merger, acquisition by another company, or sale of all or a portion of its assets, your personally identifiable information will likely be among the assets transferred. You will be notified via prominent notice on our Web site for 30 days of any such change in ownership or control of your personal information
If you have received unwanted, unsolicited e-mail sent by ComplianceLine or from any ComplianceLine system or purporting to be sent via ComplianceLine, please forward a copy of that e-mail with your comments to firstname.lastname@example.org for review.
In compliance with the Privacy Shield Principles, ComplianceLine commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact ComplianceLine at: email@example.com. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
ComplianceLine has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved Privacy Shield complaints concerning human resources data transferred from the EU and Switzerland in the context of the employment relationship. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact the EU DPAs and the Swiss FDPIC for more information or to file a complaint. The services of EU DPAs and the Swiss FDPIC are provided at no cost to you.
Questions or comments regarding this Policy should be submitted to ComplianceLine by mail or e-mail as follows:
Attention: Privacy Officer
301 McCullough Dr.
Charlotte, NC 28262
Any updates or changes to our privacy statement will be posted to this privacy statement, the homepage, and other places we deem appropriate so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. We reserve the right to modify this privacy statement at any time, so please review it frequently. If we make material changes to this policy, we will notify you here, by e-mail, or by means of a notice on our home page prior to the change becoming effective.