AskEnola · ISMS No. POL-12
Data Privacy Policy
Revision 1.0
12.1 Purpose
This data privacy and management policy is a collective policy detailing the following policies:
- Data Integrity Policy
- Data Portability Policy
- Data Privacy Policy
- Data Protection Policy
- Data Sharing Policy
- Data Subject Access Request Policy
- Data Transfer Policy
- Information Transfer Policy
- Processing Customer Data Policy
12.2 Data Transfer Policy
The EU General Data Protection Regulation (GDPR) restricts the transfer of personal information outside of the European Economic Area except in cases where adequate protections are in place for the sufficient protection of personal information. As both a global enterprise and multinational company, AskEnola recognizes the need to provide adequate data protection to ensure that personal information is protected when transferred across borders and has put in place several measures to meet GDPR requirements.
What are cross-border data transfers?
Modern global enterprises expect information to be available regardless of where they are, where their workforce is, and where their customers are. Everything from human resources to product development and transportation is data-driven, and the ability to confidently transfer data between geographies is imperative for building and maintaining a global business. When the data being transferred is personal information, safeguards must be in place to ensure that the data subject's privacy — the person whose data is being transferred — is sufficiently protected.
More than 100 countries have data protection laws. Although many of these laws share common principles, their requirements vary for cross-border data transfers. For example, under the GDPR, personal information cannot be transferred outside the EU unless certain conditions are met. Other laws, such as restrictions on transferring personal information collected by government agencies or related to an individual's health or finances, may impose additional conditions or restrictions.
Why cross-border data transfers matter
The primary reason that people are concerned about data location is that it relates to which government has the right to make legal decisions and judgments regarding access to the data — what lawyers refer to as "jurisdiction." International legal rules regarding jurisdiction are based on an underlying recognition of a nation's sovereignty and often involve complex rules of interpretation when dealing with international transactions. Questions of jurisdiction are particularly concerning when dealing with individual rights of data privacy because different jurisdictions recognize and enforce individuals' rights regarding their personal data in different ways.
For example, in Europe, the GDPR restricts moving personal information outside of the European Economic Area except under certain circumstances. These circumstances include an adequacy decision by the European Commission that the receiving country has implemented adequate legal protections for personal data. The GDPR anticipated that countries outside the European Union may not be willing or able to change their laws to meet Europe's privacy requirements. Therefore, it has provided other options for cross-border data transfers, whereby individuals can rely on the private law of contracts to ensure that their personal information is adequately protected. For entities operating in those countries that don't have an adequacy decision, the GDPR permits cross-border transfers when the entity that is transferring the data is subject to Binding Corporate Rules or when the contracts for the treatment of such data include Standard Contractual Clauses.
How AskEnola addresses cross-border data transfers
As a company operating with global customers, AskEnola has long recognized the need for the responsible transfer of data across borders. Whatever your data residency requirements are, AskEnola aims to accommodate them.
Additionally, AskEnola provides Standard Contractual Clauses as part of its Customer Data Processing Addendum as further assurance for how data is transferred as part of processing activities. Each of these clauses is backed by administrative, technical, and operational safeguards that are regularly assessed for compliance.
Where AskEnola processes personal information
AskEnola processes personal information in its role as either a controller or a processor, as those terms are defined in the GDPR. Information on the contexts in which AskEnola is a controller or processor can be found in AskEnola's Privacy Policy and Data Processing Addendum. Where AskEnola is a controller of personal information, it can transfer that data to any of its corporate or hosting locations worldwide, subject to appropriate safeguards. Where AskEnola is a processor of personal information on behalf of Customer, primary processing occurs on Microsoft Azure infrastructure as described in AskEnola's Terms of Service and Data Processing Addendum.
What if company data needs to stay in a specific country?
Some types of personal information, such as information collected by a government on its citizens, may have additional restrictions on movement across borders. Customers with specific data residency requirements should contact AskEnola to discuss available options.
12.3 Data Subject Access Request Policy
12.3.1 Purpose
This policy and procedure establish an effective, accountable, and transparent framework for ensuring compliance with data subject access requests according to the GDPR regulations.
This procedure should be considered in conjunction with the following related documents:
- Data Privacy Policy
- Access Control Policy
- Data Retention Policy
- Data Protection Policy
12.3.2 Policy Statement
The GDPR details rights of access to both manual data (which is recorded in a relevant filing system) and electronic data for the data subject. This is known as a Data Subject Access Request ("DSAR").
Under the GDPR, AskEnola is required to respond to subject access requests within one month. Failure to do so is a breach of the GDPR and could lead to a complaint being made to the Data Protection Regulator.
12.3.3 Data Subject Rights Include:
- Right to be informed — Data subjects have the right (subject to a few exceptions) to be provided with information on how their personal data will be handled by AskEnola. Articles 12–14 of the GDPR set out the information that must be provided, and typically, this information is provided by way of a privacy notice.
- Right of access to their personal data — The purpose of a subject access request is to allow individuals to confirm the accuracy of personal data and check the legality of processing to allow them to exercise rights of correction or objection if necessary. Individuals can request to see any personal data that AskEnola holds about them, which includes copies of email correspondence referring to them or opinions expressed about them.
- Right to rectification — The right of individuals to require AskEnola to rectify inaccuracies in personal data held about them. In some circumstances, if personal data is not complete, an individual can require AskEnola to complete the data or to record a supplementary statement.
- Right to be forgotten (erasure) — Individuals have the right to have their data erased in certain situations, such as where the data is no longer required for the purpose for which it was collected, the individual withdraws consent, the individual has objected to processing based on legitimate interests, public task, or official authority, or the information is being processed unlawfully. There are certain exemptions to this right, and there is no absolute obligation on AskEnola to erase the relevant data — it is important to identify whether any exemptions apply.
- Right to restriction — Individuals can ask AskEnola to "restrict" the processing of personal data while complaints (for example, about accuracy) are resolved, where processing is unlawful, where AskEnola no longer needs the data but the individual does not want it erased, or while an objection to processing is being considered.
- Right to portability — The data subject has the right to request that personal data concerning them and held by AskEnola be provided to the individual (or a third party) in a structured, commonly used, and machine-readable form. This right only applies to personal data processed by automated means (not paper records), where the processing is based on consent or contract.
- Right to object — Data subjects have the right to object to specific types of processing based on (i) public interest/official authority, (ii) legitimate interests, or (iii) direct marketing. Where the Organization receives an objection to direct marketing, it must stop processing the personal data for this purpose immediately. Otherwise, AskEnola may consider whether there are legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject.
- Rights in relation to automated decision-making and profiling — The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. "Profiling" is the processing of data to evaluate, analyze, or predict behavior or any feature of a person's behavior, preferences, or identity.
The foregoing right does not apply if:
- it is necessary to enter into a contract with the data subject and AskEnola;
- it is authorized by applicable law (and such law lays down suitable measures to safeguard the data subject's rights, freedoms, and legitimate interests); or
- it is based on the data subject's explicit consent.
Even where (a) or (c) applies, AskEnola must put in place suitable measures to safeguard the rights of the data subject, including the right to ask for a human to review the decision and to contest it. Automated decision-making based on a special category of data can only be done with explicit consent.
12.3.4 Subject Access Request Procedure
All Subject Access Requests received by AskEnola will be processed by the Information Governance Officer (IGO). When responding to data subject access requests, data subjects are entitled (unless an exemption applies) to be informed of the following:
- Confirmation that personal data about them is being processed.
- A copy of that personal data.
- Details of the purpose of the processing.
- Categories of the personal data concerned, e.g., whether it includes any special categories of sensitive personal information.
- Any recipients or categories of recipients the personal information has been shared with, particularly if these are situated or domiciled outside the EU.
- What safeguards are in place for transfers outside the EU.
- The period the personal information will be stored for, or the criteria for determining that period.
- The existence of the right to request correction or deletion of personal data or to restrict or object to its processing.
- The right to lodge a complaint with the Information Commissioner's Office.
- The source of the personal data if it has not been collected directly from the data subject.
- Details of any automated decision-making, including profiling and meaningful information about the logic involved and the envisaged consequences of such processing.
Each data subject access request is reviewed on its own merit, and AskEnola considers whether an exemption to disclosure applies. As a general rule, personal data relating to other individuals should not be disclosed (unless their permission has been obtained or it is reasonable to comply without consent); such information will generally be redacted.
Before processing a request, the requestor's identity must be verified. Examples of suitable documentation include a valid passport, valid identity card, valid driving license, or birth certificate, along with proof of address (e.g., a utility bill no more than three months old).
If a request contains information relating to third parties, AskEnola will, where possible, ask the third party whether there is any reason the information should not be disclosed, and will anonymize or summarize such information rather than provide a copy of the whole document where appropriate.
12.3.5 Exceptions to the Data Subject Rights
The applicability of any exemption is reviewed on a case-by-case basis. In summary, the main exceptions likely to be applicable include reasons related to:
- protecting the personal data of third parties;
- legal professional privilege;
- prevention or detection of crime;
- apprehension or prosecution of offenders;
- assessment or collection of tax or duty;
- immigration; or
- information required to be disclosed by law or in relation to legal proceedings.
12.4 Data Sharing Policy
12.4.1 Interpretation
In this Policy, the following terms have the following meanings:
- Agreed Purposes: as set out in the applicable Contract between Customer and AskEnola.
- Contract: the contract made between the Customer and AskEnola.
- Controller, data controller, processor, data processor, data subject, personal data, processing, and appropriate technical and organizational measures: as set out in the Data Protection Legislation in force at the time.
- Customer: the person or company purchasing products or services from AskEnola.
- Data: the Customer's or any of its employees', workers', customers', or end users' personal data as defined in the Data Protection Legislation.
- Data Protection Legislation: (i) unless and until the GDPR is no longer directly applicable in the UK, the General Data Protection Regulation ((EU) 2016/679) and any national implementing laws, regulations, and secondary legislation, as amended or updated from time to time, in the UK, and then (ii) any successor legislation to the GDPR or the Data Protection Act 1998.
- Permitted Recipients: the parties to the applicable agreement, the employees of each party, and any third parties engaged to perform obligations in connection with the agreement.
- Policy: means this document and (unless the context otherwise requires) includes any special terms agreed in writing between the Customer and AskEnola.
- Shared Personal Data: the personal data shared between the parties under the applicable Contract, confined to the categories of information relevant to the applicable categories of data subject (e.g., recipient's name, recipient's address).
- Writing: means in writing, including telex, cable, facsimile transmission, email, and comparable means of communication.
12.4.2 Data Protection
This clause sets out the framework for the sharing of personal data between the parties as data controllers, and the particular obligations relating to data sharing.
The Customer shall: ensure that it has all necessary notices and consents in place to enable lawful transfer of the Shared Personal Data to AskEnola for the Agreed Purposes; and give full information to any data subject whose personal data may be processed of the nature of such processing, including that, on termination of the agreement, personal data relating to them may be retained by, or transferred to, one or more of the Permitted Recipients, their successors, and assignees.
Mutual assistance. Each party shall assist the other in complying with all applicable requirements of the Data Protection Legislation. In particular, each party shall:
- consult with the other party about any notices given to data subjects in relation to the Shared Personal Data;
- promptly inform the other party about the receipt of any data subject access request;
- provide the other party with reasonable assistance in complying with any data subject access request;
- not disclose or release any Shared Personal Data in response to a data subject access request without first consulting the other party wherever possible;
- assist the other party, at the other party's cost, in responding to any request from a data subject and in ensuring compliance with its obligations under the Data Protection Legislation with respect to security, breach notifications, impact assessments, and consultations with supervisory authorities or regulators;
- notify the other party without undue delay on becoming aware of any breach of the Data Protection Legislation;
- at the written direction of the disclosing party, delete or return Shared Personal Data and copies thereof on termination of the agreement, unless required by law to store the personal data;
- use compatible technology for the processing of Shared Personal Data to ensure there is no lack of accuracy resulting from personal data transfers;
- maintain complete and accurate records and information to demonstrate compliance and allow for audits by the other party or its designated auditor; and
- provide the other party with contact details of at least one employee as point of contact and responsible manager for issues arising out of the Data Protection Legislation, including joint training, breach procedures, and regular compliance reviews.
12.4.3 Data Processing
- AskEnola shall only process the Data provided by the Customer for the Agreed Purposes.
- AskEnola shall delete the Data after each delivery where the Purpose is a one-time delivery of products or services.
- If the Purpose is to deliver products or services on more than one occasion, the Customer shall provide the Data before each delivery.
- The Data shall only be accepted by AskEnola if provided by the Customer in a secure format as specified by AskEnola. Data provided by any other means will be refused.
- AskEnola shall not be responsible for updating the Data at any time.
- If AskEnola receives returned mail or failed delivery notices, it shall inform the Customer, and it shall be the Customer's responsibility to update the Data.
- AskEnola shall not share the Data with any other party unless requested to by the Customer, or sell the Data to any other party. Only authorized personnel within AskEnola shall have access to the Data.
12.4.4 Data Protection
- Both parties will comply with all applicable requirements of the Data Protection Legislation. This clause is in addition to, and does not relieve, remove, or replace, a party's obligations under the Data Protection Legislation.
- The parties acknowledge that, for purposes of the Data Protection Legislation, the Customer is the data controller and AskEnola is the data processor.
- The Customer will ensure that it has all necessary appropriate consents and notices in place to enable lawful transfer of the Data to AskEnola for the purpose and duration of the Contract.
- AskEnola shall, in relation to any Data processed in connection with performance of its obligations:
- process that Data only on the written instructions of the Customer, unless required by applicable EU member state or EU law ("Applicable Laws") to process the Data — in which case AskEnola shall promptly notify the Customer before performing the required processing, unless prohibited from doing so;
- ensure appropriate technical and organizational measures are in place to protect against unauthorized or unlawful processing of Data and against accidental loss or destruction of, or damage to, the Data, appropriate to the harm that might result and the nature of the data (which may include pseudonymization and encryption, ensuring confidentiality, integrity, availability, and resilience of systems and services, timely restoration of availability and access after an incident, and regular assessment of the effectiveness of such measures);
- ensure that all personnel who have access to and/or process the Data are obliged to keep it confidential; and
- not transfer any Data outside of the European Economic Area unless the Customer's prior written consent has been obtained and appropriate safeguards, enforceable data subject rights, and compliance with the Data Protection Legislation are ensured, and AskEnola complies with reasonable instructions notified in advance by the Customer.
AskEnola shall further: assist the Customer, at the Customer's cost, in responding to requests from end users and in ensuring compliance with obligations relating to security, breach notifications, impact assessments, and consultations with supervisory authorities or regulators; notify the Customer without undue delay on becoming aware of a Data breach; at the Customer's written direction, delete or return the Data and copies thereof on termination of the Contract unless required by Applicable Laws to store the Data; and maintain complete and accurate records and information to demonstrate compliance with this clause.
Either party may, on not less than 30 days' notice, revise this clause by replacing it with any applicable controller-to-processor standard clauses or similar terms forming part of an applicable certification scheme.
12.4.5 Indemnity
The Customer acknowledges that AskEnola places particular reliance upon the provisions of this Policy. In addition to any other remedy available, the Customer indemnifies AskEnola against all liabilities, costs, expenses, damages, and losses (including direct, indirect, or consequential losses, loss of profit, loss of reputation, interest, penalties, legal costs, and other professional costs and expenses) suffered or incurred by AskEnola arising out of or in connection with the breach of the Data Protection Legislation or this Policy by the Customer, its employees, or agents.
12.4.6 General
- Any notice required or permitted under this Policy shall be in Writing, addressed to the relevant party at its registered office or principal place of business or such other address as notified.
- AskEnola's rights and remedies shall not be diminished, waived, or extinguished by any indulgence, forbearance, or extension of time granted to the Customer, nor by any failure or delay in exercising such rights. Any waiver must be in writing and does not waive any subsequent breach.
- If any provision of this Policy is held invalid or unenforceable in whole or in part, the validity of the remaining provisions shall not be affected.
- Both parties irrevocably agree to submit to the exclusive jurisdiction of the courts specified in the applicable Contract, which shall be governed by and construed in accordance with the governing law specified therein.
- No person who is not a party to the Contract shall have a right to enforce any term of the Contract absent the express prior written agreement of the parties. The parties may vary or cancel the Contract by agreement without requiring the consent of any such third party.
12.5 Data Protection Policy
12.5.1 Definitions
- "GDPR" means the General Data Protection Regulation.
- "Responsible Person" means the individual designated by AskEnola as responsible for data protection within the organization.
- "Register of Systems" means a register of all systems or contexts in which personal data is processed by AskEnola.
12.5.2 Goal of the Data Protection Policy
The goal of the data protection policy is to depict the legal data protection aspects in one summarizing document. It can also be used as the basis for statutory data protection inspections, e.g., by a customer within the scope of commissioned processing. This is not only to ensure compliance with the GDPR and the Data Protection Act 2018 but also to provide proof of compliance.
12.5.3 Data Protection Principles
AskEnola is committed to processing data in accordance with its responsibilities under the GDPR. Article 5 of the GDPR requires that personal data shall be:
- processed lawfully, fairly, and in a transparent manner in relation to individuals;
- collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes;
- adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;
- accurate and, where necessary, kept up to date, with reasonable steps taken to erase or rectify inaccurate data without delay;
- kept in a form which permits identification of data subjects for no longer than necessary for the purposes for which the personal data are processed; and
- processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.
12.5.4 Security Policy and Responsibilities
- This policy applies to all personal data processed by AskEnola.
- The Responsible Person shall take responsibility for AskEnola's ongoing compliance with this policy, which shall be reviewed at least annually.
- AskEnola shall register with the Information Commissioner's Office (or equivalent authority) as an organization that processes personal data, where applicable.
- Data protection goals are defined and documented in addition to existing corporate objectives, and are based on the data protection principles above.
- AskEnola is committed to continuous improvement of its data protection management system, including training, awareness, and obligations of employees.
12.5.5 Lawful, Fair, and Transparent Processing
To ensure its processing of data is lawful, fair, and transparent, AskEnola maintains a Register of Systems, reviewed at least annually. Individuals have the right to access their personal data, and any such requests are dealt with in a timely manner.
12.5.6 Lawful Purposes
All data processed by AskEnola must be done on one of the following lawful bases: consent, contract, legal obligation, vital interests, public task, or legitimate interests. AskEnola notes the appropriate lawful basis in its Register of Systems. Where consent is relied upon, evidence of opt-in consent is kept with the personal data, and individuals are given a clear ability to revoke consent, which is accurately reflected in AskEnola's systems.
12.5.7 Data Minimisation
AskEnola ensures that personal data are adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
12.5.8 Accuracy
AskEnola takes reasonable steps to ensure personal data is accurate and, where necessary for the lawful basis on which data is processed, kept up to date.
12.5.9 Archiving/Removal
To ensure that personal data is kept for no longer than necessary, AskEnola maintains an archiving policy for each area in which personal data is processed, reviewed annually, considering what data should or must be retained, for how long, and why.
12.5.10 Security
- AskEnola ensures personal data is stored securely using modern, up-to-date software.
- Access to personal data is limited to personnel who need access, with appropriate security in place to avoid unauthorized sharing of information.
- When personal data is deleted, this is done safely such that the data is irrecoverable.
- Appropriate back-up and disaster recovery solutions are in place.
12.5.11 Breach
In the event of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, AskEnola shall promptly assess the risk to people's rights and freedoms and, if appropriate, report the breach to the relevant supervisory authority.
12.6 Data Privacy Policy
12.6.1 Purpose of GDPR Policy
This section explains clearly how AskEnola collects, processes, and stores data. For the purposes of this policy, Customer is generally the data controller and AskEnola is the data processor with respect to Customer Personal Data, as further described in AskEnola's Terms of Service and Data Processing Addendum.
12.6.2 Data Processors
AskEnola engages data processors and Subprocessors (such as its cloud hosting and AI infrastructure providers) to help deliver the AskEnola Platform. This section summarizes the categories of information involved:
- How AskEnola collects data. AskEnola collects personal data such as names, email addresses, and account information directly from users, as well as usage data such as IP addresses and device information. AskEnola may also receive personal data from other sources, such as third-party services integrated with the AskEnola Platform.
- How AskEnola uses data. AskEnola processes data on the lawful bases of contract performance, legitimate interest, and consent, as applicable. AskEnola clearly states the purposes of processing and whether automated decision-making or profiling is involved.
- How AskEnola discloses data. AskEnola is transparent about which other parties (such as Subprocessors) have access to personal data it collects, as described in its Data Processing Addendum.
- How AskEnola stores data. AskEnola describes how it ensures data security, where it stores data (including whether it transfers data outside of the EU and how it protects data in that case), and for how long it stores data, consistent with its Terms of Service and Data Processing Addendum.
- The data subject's rights. Data subjects have several rights under the GDPR, including the right to access, the right to be forgotten, and the right to object, as described in Section 12.3 above.
- How to complain. Individuals may lodge a complaint with the relevant supervisory authority for their jurisdiction.
- Changes to this policy. AskEnola may modify this policy as needed and will notify data subjects of material changes, including via its website.
12.7 Data Portability Policy
Data Subject Request (DSR). The GDPR grants individuals (or data subjects) certain rights in connection with the processing of their personal data, including the right to correct inaccurate data, erase data or restrict its processing, receive their data, and request that it be transmitted to another controller. The controller is responsible for providing a timely, GDPR-consistent reply.
DSR FAQs
What actions will be required to complete a DSR? DSRs involve six activities: Discovery, Access, Rectification, Restriction, Export, and Deletion.
What are the data sources? A large fraction of the data AskEnola processes is generated through the AskEnola Platform itself, including customer data, insights generated by the platform, and system-generated logs.
What kinds of data need to be searched? Personal data may be found in Customer Data and system-generated logs.
How will personal data be searched? Searching for personal data may vary across products and services; administrators may access system-generated logs associated with a user's activity, and content search tools may be used where applicable.
In what formats should personal data be made available? The GDPR "right of data portability" allows a data subject to request a copy of personal data in a structured, commonly used, machine-readable format, and to request that AskEnola transmit these files to another data controller.
What the GDPR requires of AskEnola as controller
As controller, the GDPR requires AskEnola to give data subjects a copy of their personal data, together with an explanation of the categories of data being processed, the purposes of processing, and the categories of third parties to whom data may be disclosed. AskEnola helps every individual exercise their right to correct inaccurate personal data, erase data or restrict its processing, receive their data in a readable form, and, where applicable, fulfill a request to transmit their data to another controller.
What the GDPR requires of AskEnola as processor
As processor, AskEnola implements appropriate technical and organizational measures to assist Customers in responding to requests from data subjects exercising their rights as discussed above. The AskEnola Platform's administrative controls help Customers, as controllers, discover, access, rectify, restrict, delete, and export personal data residing in their AskEnola account, and to obtain data in machine-readable form when needed.
12.8 Processing Customer Data Policy
This policy applies to all users who have a legitimate need to access sensitive data, including but not limited to the processing of data for customers and colleagues.
12.8.1 Purpose
In the course of providing services, AskEnola may receive, store, and manage sensitive data on its systems. Due to contractual, legal, and regulatory obligations, AskEnola must maintain strict confidentiality of such data at all times. This policy communicates AskEnola's expectations with respect to the transmittal, storage, processing, retention, protection, and disposal of sensitive data provided to AskEnola in the course of doing business.
12.8.2 Definitions
Users — AskEnola employees, contractors, partners, candidates, or any third party that does business with AskEnola. Sensitive Data — any data that is classified as Restricted or as Client data.
12.8.3 Policy
The use of Sensitive Data should always be treated with the utmost care and is governed according to AskEnola's Data Classification Policy. All questions regarding proper care of Sensitive Data should be directed to AskEnola's Data Protection Officer.
12.8.4 Data Protection
AskEnola will comply with data protection law and principles outlined in the GDPR, which means Sensitive Data will be used lawfully, fairly, and in a transparent way; collected only for valid purposes; accurate and kept up to date; maintained only for as long as necessary; and kept securely and protected against unauthorized or unlawful processing and against loss or destruction using appropriate technical and organizational measures.
12.8.5 Data Transmittal
When transmitting Sensitive Data in AskEnola's systems, the following requirements apply to maintain data confidentiality:
- Process Sensitive Data only for purposes specifically authorized, strictly in accordance with the services provided and in compliance with Applicable Data Protection Laws.
- Sensitive Data should be scrubbed prior to transmittal to eliminate transmittal of data not pertinent to the original purpose.
- Sensitive Data containing personally identifiable information (PII) or payment card industry (PCI) data should only be transmitted when its use is determined critical to accomplishing a specific task.
- Sensitive Data must be encrypted at all times using industry-standard (e.g., NIST-approved) encryption algorithms and key lengths.
- When using symmetric encryption, key exchange must be done in a secure fashion, using a communication channel separate from the channel used for data exchange.
- Electronic data transmittal must use a secure file transfer protocol (e.g., SFTP).
- Data transmittal using physical media must be done via secure courier with encrypted data, and such media should be destroyed following AskEnola's Data Destruction Policy.
- AskEnola will cooperate in any investigation by a governmental or regulatory authority, or any internal investigation, regarding the processing of Sensitive Data.
12.8.6 Data Storage
- Installation of Sensitive Data on systems not owned by AskEnola must be approved by AskEnola's Chief Information Security Officer (or equivalent).
- If not scrubbed prior to transmittal, Sensitive Data should be scrubbed immediately upon storage to eliminate storage of data not related to the original purpose of processing.
- Sensitive Data must be stored in a manner that ensures it is sufficiently segregated from other data to ensure proper access controls.
- Systems and disks containing Sensitive Data must use encryption consistent with current industry best practices.
- All systems housing Sensitive Data must have active anti-malware protection and adhere to AskEnola's Vulnerability Management Policy.
- Personnel must not store Sensitive Data on personal desktops or mobile devices.
12.8.7 Data Privacy
AskEnola ensures it only uses personnel and third parties who are bound to observe data and telecommunications secrecy under Applicable Data Protection Laws, have received appropriate training on their responsibilities, and are required to keep Sensitive Data strictly confidential — with obligations that survive termination of their engagement. AskEnola shall not disclose any Sensitive Data to a third party without prior written consent, except as necessary to use its designated Subprocessors in accordance with this policy.
12.8.8 Data Access
To ensure confidentiality of Sensitive Data, access must be strictly enforced at all times. Access is only granted to personnel with a legitimate purpose for such access, limited to the minimum access rights required to accomplish an assigned task or role. Personnel accessing Sensitive Data must use unique credentials and adhere to AskEnola's Password Policy, must not leave computers unattended while connected to systems containing Sensitive Data, and must terminate connections to such systems immediately upon completing work. All access to PII and PCI data must be logged.
12.8.9 Data Retention and Destruction
AskEnola recognizes that the efficient management of its data and records is necessary to support its core business functions, comply with legal, statutory, and regulatory obligations, protect personal information, and enable effective management of the organization. AskEnola only retains records and information for legitimate or legal business reasons and complies fully with applicable data protection laws, guidance, and best practice.
Sensitive Data is disposed of properly upon completion of the project for which it was processed. All copies of Sensitive Data must be securely deleted, and all Sensitive Data stored on removable media must be deleted following AskEnola's Data Destruction Policy.
12.9 Privacy Notice: How AskEnola Collects, Uses, and Protects Information
This section describes the kinds of information AskEnola processes depending on how you engage with it, and how that information is used, secured, shared, and retained.
12.9.1 What Kinds of Information AskEnola Processes
AskEnola processes different kinds of information depending on how you are engaging with it. This data includes Personal Information, Usage Information, and User Generated Information.
Personal Information is any data that identifies or describes you or another individual, and often relates to an individual's person, communications, movements, surroundings, and behaviors online and in the real world. Examples of Personal Information AskEnola may process include your name and contact information, government ID numbers, payment card or bank information, and photos. AskEnola obtains Personal Information by collecting it directly from you (e.g., through online forms, product registration, and account systems), through reports created using AskEnola's products and services, through automated methods integrated into AskEnola's products and websites, and from third parties AskEnola has contracted with.
Usage Information is data generated by your use of AskEnola's product, service, or website, including logs about pages visited, content interacted with, performance information such as crashes and memory consumption, and other information related to how AskEnola's products and services are performing.
User Generated Information varies depending on which products, services, or websites you interact with, and may include messages sent via AskEnola's websites, search queries, reports, charts, and other documents created using AskEnola's products, and the work product produced by using AskEnola's services. User Generated Information may also include Personal Information.
12.9.2 How AskEnola Uses Information
AskEnola processes information to fulfill its legitimate business purposes, including:
- Delivering requested functionality. Many features of AskEnola's products, services, and websites process information in response to your requests — for example, collecting your email address, password, and profile information so you can create an account and log in.
- Protecting AskEnola's rights. When AskEnola licenses its products to you, it reserves the right to collect Personal Information like account credentials and information about the devices you use to access licensed products, and Usage Information to monitor compliance with license terms.
- Supporting users. AskEnola collects Usage Information like errors and interaction logs to better diagnose and resolve technical problems.
- Improving products, services, and websites. AskEnola may use Personal Information to invite participation in surveys and feedback forums, and may use anonymized Usage Information and excerpts from User Generated Information (like support requests) to identify, prioritize, and develop improvements to its products and services.
- Promoting products and services. AskEnola may use Personal Information collected from its websites, sponsored events, and publications to identify potential users and contact them about AskEnola's products and services, and may supplement this information with data obtained from third parties to improve its records about potential leads.
12.9.3 How AskEnola Secures Information
When AskEnola collects and stores information on its systems, it applies reasonable and appropriate administrative, physical, and technical safeguards to detect and prevent unauthorized access, disclosure, use, and loss of Personal and User Generated Information. These safeguards include monitoring and auditing of IT infrastructure, encryption of files in transit and at rest, strong password policies, limiting access to personnel with a legitimate business purpose, and data protection training for personnel. In the event AskEnola discovers or reasonably suspects unauthorized access, disclosure, use, loss, or other processing of your Personal or User Generated Information (a "security incident"), AskEnola will notify you within a reasonable period of time using the email address on file. No safeguards are 100% effective, and AskEnola does not warrant or guarantee that data it processes will never be affected by a security incident.
12.9.4 Cookies and Other Online Tracking Technologies
Cookies, web beacons, and similar local objects are small files that record or collect information, which AskEnola's websites place on your device when you visit. AskEnola uses local objects to save preferences and settings (like login information), to help understand how well its websites are working, to enable communication with you (e.g., via chat), and to promote its products and services. AskEnola relies on third-party service providers to help manage local objects and the information they collect. You can use your browser settings and other tools to control how your devices interact with cookies and other local objects; if you block them, some features of AskEnola's websites may not function properly. AskEnola's websites may not respond to "Do Not Track" settings from all browsers. Data collected from local objects is retained for varying lengths of time depending on the object and the data collected — from the duration of a single visit up to several months or longer.
12.9.5 Children's Personal Information
AskEnola's products, services, and websites are not intended for use by children, and AskEnola never intentionally collects information from children. If AskEnola discovers it has intentionally collected a child's Personal Information, it will delete it.
12.9.6 Who AskEnola Shares Information With
AskEnola will make information it has collected available to third parties under the following circumstances:
- Where required by law. AskEnola will make information available to government agencies that serve it with valid legal process, and will notify affected individuals of governmental requests where permitted to do so by law.
- Where AskEnola has relationships with service providers. AskEnola may partner with third parties (such as hosting providers, payment processors, and support providers) to perform services or provide product functionality on its behalf. AskEnola's contracts with service providers require reasonable and appropriate safeguards and limit their rights to use shared information for purposes consistent with this policy.
- To protect AskEnola's or third parties' rights. AskEnola may share information with legal counsel, auditors, and related service providers in the course of evaluating or pursuing potential claims involving enforcement of contractual and other legal rights, disclosing only the information necessary for this purpose.
- With AskEnola affiliates. AskEnola may have personnel and operations in multiple countries who work together to deliver products and services and process information as described in this policy; all affiliates and personnel comply with the terms of this policy when processing information.
12.9.7 Special Category Data
Owing to the products and services AskEnola offers, it sometimes needs to process sensitive personal information (known as special category data) in order to carry out the performance of a contract on behalf of a controller. Where such information is processed, AskEnola will do so only for the specified purpose and on behalf of the controller.
12.9.8 Your Rights
You have the right to access, modify, and object to the processing of Personal Information AskEnola has collected from you. Where applicable, your Personal Information is available by logging into your account, which you can update at any time. You also have the right to restrict information AskEnola processes, and can make other changes or delete your account and associated Personal Information by contacting AskEnola.
You have the right to export the Personal Information and Customer Generated Information AskEnola processes for you as a Customer. You have the right to opt into and out of receiving marketing communications from AskEnola; your decision will not affect your ability to receive communications based on existing business relationships, such as customer satisfaction outreach, transaction acknowledgements, and customer service follow-up. You have the right to lodge a complaint with the supervising authority where applicable, and the right to withdraw your consent at any time.
You have a right to be notified of material changes to this policy that affect the rights and/or responsibilities described herein; AskEnola will publish notice of such changes on its website. Continued use of AskEnola's products, services, or websites after such notice constitutes acceptance of the changes.
12.9.9 Data Subject Requests and Customer Responsibilities
Upon request, and to the extent such information is available to it, AskEnola shall provide reasonable cooperation and assistance to fulfill obligations under the GDPR to perform data protection impact assessments related to the use of its services.
As a condition of AskEnola processing any Sensitive Data, the Customer shall inform all data subjects concerned of the processing of their personal data pursuant to the applicable agreement and, where required by Applicable Data Protection Laws, ensure such data subjects have given unambiguous consent to such processing, and grant AskEnola and its Subprocessors the right to process Sensitive Data in accordance with the services being carried out.
12.9.10 Contact Us
If you have questions or requests relating to this Data Privacy Policy, you may contact AskEnola at legal@askenola.ai.