This Privacy Statement is designed to enable you, as well as the recipients of the communications you send over Vertex’s platform, to make informed decisions about personal data when you make use of our communications services.
We only ask for personal data when we need it for business purposes or to provide you with relevant information. Whether you sign up for our newsletter or sign a Service Agreement, you provide your personal data to us for a particular purpose. You always have the opportunity to explicitly agree to the collection, use, disclosure, and sharing of the information you’ve provided. That applies even when you’re browsing our website, where you can manage your cookie preferences. You can review your personal data and change your settings at all times.
Since customers integrate our products in their own software applications, we don’t interact with their end-users directly. When customers do share end-user information with us, we always handle that data in accordance with the data protection regulations, including GDPR. We don’t use that data for any purposes other than those specifically issued by the customer who provides the data.
Throughout this document you’ll encounter the mention of several roles and responsibilities. Here’s a quick explanation of the different roles, responsibilities, and systems of governance that play an integral part in ensuring your data is protected.
The Controller determines the purpose (why) and means (how) of personal data sharing (e.g. to receive important information or sending invoices) and remains ultimately responsible for the correct handling of the subject’s data. The Controller is often the company that an individual (or data subject) provides their personal data to.
Processor is the company that provides part of the service of the Controller and needs specific personal data in control of the Controller in order to do so. To give an example: when one of our customers sends a campaign through our platform, we need personal data such as a phone number to fulfil the service. The Processor only processes personal data according to the instructions of the Controller.
Depending on your relationship with Vertex, we can be both Controller and Processor. If you have any questions about these terms or more general inquiries about how we handle identifiable data, you can always contact us at email@example.com
Why we collect personal data
All the personal data we process is lawfully obtained and with a legal basis. The purpose of the information we collect is so we can enable you to use our services and continue to conduct and expand our day-to-day business. Personal data can also help us to improve our products to fit the needs of our customers.
We process personal data based on a limited set of legal bases:
- explicit consent (e.g. ticking a box on our website when you want to download product information),
- negotiating and signing a contract to receive a Vertex’s service,
- legal obligation which requires us to do so (such as preventing misuse or our services, cooperating with formal disclosure requests and storing financial data for the duration required).
We collect personal data for specific purposes, and we’ll always tell you what those are when we collect it. We’ll use the collected data for the specified purpose alone, as long as our relationship stays the same. If our relationship changes, we may need more information. For example, if you fill out a form to request more information about one of our products, we’ll use your contact data to send the requested product information to you. If you then decide to become a customer, we’ll need additional information including your billing address for the purpose of providing you with the services you are interested in.
Here’s a list of the purposes for which we’ll request or use your data:
- Sharing relevant information about our products and services,
- Creating an account that’s connected to your person and company,
- Verifying your identity
- Provision of the services
- Finance and billing
- Analysing usage of our products and services
- Providing Customer Support to potential or existing customers
- Detecting and combating fraudulent or unlawful activity
- Training and quality improvement
- Expanding business through our marketing and sales channels
- Fulfil financial obligations such as paying taxes and ensuring invoices are paid
- Keeping your account secure.
You will always have the choice to provide personal data on our domain or not. Please keep in mind that declining to provide personal data might prevent you from using a certain product or service. We will tell you the implications of not providing the information asked for when you choose not to do so.
What personal data we collect
The exact type of data we collect depends on the related product or service. Applying your privacy settings on our website, signing up for a newsletter, downloading marketing materials, or using any of our products and services all require you to leave appropriate details, specific to that purpose. We never collect more data than we need and may ask for additional data at the appropriate time.
You will always remain to have a choice when it comes to the Vertex products and services you use and the data you share. When we ask you to provide personal data, you can decline. Many of our products require some personal data to provide you with a service. If you choose not to provide data required to provide you with a product or feature, you cannot use that product or feature.
Vertex’s personal data processing activities include three main categories when you use our products and services:
- Customer account data (or potential customer data) - your personal data as an account holder on behalf of your company.
- End-user data - the personal data of the intended recipients of the communication services you as a customer make use of. The category end-user data consists of both Communication data (all data related to the communication; e.g. metadata) and Customer Content of the communications.
- Website visitor data - when visiting our website, you will be asked to (re)set your cookie preferences. Based on your preferences personal data may be collected. When you would like to be contacted by our Sales or Customer Support teams, subscribe for a newsletter or download product information you only share information with us that is relevant to the request made. Additionally, when logging in to your customer environment via the website Vertex collects data related to the usage of the dashboard and platform.
Depending on our relationship the personal data shared by you can include:
- Customer account and potential customer information
- Full name
- Email address
- Financial information
- Account ID
- Job title
- IP address
- Usage data of services and website
- Customer support call recordings
- Communication traffic data
- Communication body
- Traffic data
- Location related information
- Phone number sender and recipient
- Website visitor data
- Cookie preferences
- IP addresses
- Location related information
- Pages visited
- Browser and device information
How we collect and use data
The information below is not exhaustive and may be updated in accordance to new legislation, or because further clarification is needed based on a new product or service.
Vertex uses the data that you share with us to provide you with the best experience of our brand, the services and people connected to them. Most notably, we use data to:
- Enable you to use our products and services, including our Customer Support team and publicly facing website.
- Personalize your experience of our products and services and make recommendations.
- Improve and (further) develop products, which includes analyzing usage data.
- Operate our business
More detailed information on the purposes we fulfil can be found under Why we collect personal data.
Personal data is predominantly shared with us by you as a (potential) customer or website visitor; additionally, as a customer making use of our products you share information of end-user with us to enable the transmission of the communications services. In some cases, additional information related to the business you work for, your position and the industry it operates in will be gathered via online sources or enrichment providers to be able to address your business needs best.
When browsing our website based on your cookie preference, we automatically collect data by placing cookies and trusted tracking technologies on your browser. The information we collect helps us maintain and improve our website and business. It usually includes your IP address, browser type, the pages you’ve visited and in what order, and whether you’re a new or recurring visitor.
We use this data to ensure that the website works correctly and store any preferences you may have. It also helps us show relevant advertisements, generate and review data, and generate reports on our website user base and usage patterns.
When filling out a form on our website, you directly interact with us. When you ‘Contact sales’, send us an email, or subscribe to our newsletter, we use the data you provide.
When you sign up on our website, we ask for some personal data like your email address, company, name, and the content of your inquiries. The particular fields to fill in may differ per form, we’ll never ask you for irrelevant information, and we’ll always use the data for the purpose you submitted it for.
If you’re already a customer, we’ll use the data collected from your account. That gives us relevant insight into how you’re using our platform and our products, what your business needs are, past support issues, and so on. Pulling this information allows us to tailor our assistance, product offers and provide the best possible assistance support via our support, tech and sales teams.
When buying credits or subscribing to a plan, we need more information than just your name and password. In order to start billing, we need information including your company details, billing address and preferred payment method(s). You’re assigned an Account ID automatically that’s used to process your orders, assign invoices, and track API requests. If you integrate our APIs into your software application, you’ll be given an authentication token that allows us to identify you when you send API requests.
Your credentials will help us to improve our internal processes and services. We keep account credentials on record to identify the account that assigns the API commands, and to make sure the account manager and our support team can store and access relevant information about your account.
When using our products and services, we collect the commands your application communicates to Vertex. This includes your IP addresses, information on your usage, and routing information.
DATA FROM PUBLICLY AVAILABLE SOURCES AND DATA ENRICHMENT PROVIDERS
In order to develop our business, we make use of third parties that supply us with information collected from publicly available sources and data enrichment providers. The information we collect is based on personas created by automated processes. The purpose of enriching profiles is to assess that only relevant leads and customers are processed, and the additional information helps to address the specific needs, based on type of industry, company scale and is done so on the basis of the company’s legitimate interest. In order to make sure we only approach the right audience; we only retain information that will help us reach out to people and companies that would benefit from the use of our services and products. If you no longer want to be contacted by our sales team, you can always object by contacting your account manager or Vertex’s support team via firstname.lastname@example.org.
The categories of personal data below are involved. As you will see most of them are business related; nevertheless, even in a business relationship some information might be considered personal data; company name, company description and website, company (estimated) revenue and employee range, company industry, employment role and title, seniority, full name, phone number.
The information will not be retained longer than is necessary to fulfill the purpose, or if an objection is made by you that will take away the legal basis of consent or legitimate interest. The retention period may vary between a couple of weeks for leads, up to the duration of the services for existing customers.
Rest assured that all third parties involved in Vertex’s day-to-day business will have to comply with the appropriate cross-border transfer mechanisms.
Whether we fulfil the role of Controller, Processor, or even as a mere conduit, we always make sure that the parties we work with adhere to similar Data Protection and Security Standards as we agreed upon with you. Vertex engages three categories of recipients:
- Third party service and technology providers as well as (tele)communications services providers working on our behalf to provide you with products and services
- Vertex Company Family
- Government authorities, when required to do so by law
Here’s who we share information with and why:
(TELE)COMMUNICATIONS SERVICES PROVIDERS
Telecom operators, aggregators and other communications service providers for proper routing and connectivity. We reach people’s smartphones through telecom operators and other communication service providers. In order to make sure the message you send will reach the intended recipient, independent of their location, we make use of a global network of telecom providers. When it comes to the contents of electronic communications transmitted by communication providers, these operators, aggregators and service providers qualify neither as controllers nor as processors under the EU’s GDPR insofar as they act as mere conduits in transmitting the content. If they process content data for their own purposes (e.g. undertaking their own filtering or data retention activities), they act as controllers.
Third party service and technology providers who perform necessary actions on our behalf. We can share personal data with third party service providers, like our payment processor and hosting providers. We never share information without prior vetting, due contracts or for specific purposes that can be fulfilled in-house.
PAYMENT SERVICE PROVIDERS AND FINANCIAL INFORMATION
Payment Service Providers (PSPs) of Vertex provide our customers with ancillary services like Saved Payment Methods.
Saved Payment Methods allows our customers to save the financial information of a specific payment method on a consent basis for their own convenience. The information necessary to provide the service differs depending on the selected payment method (credit card, iDeal or Paypal) but for a credit card consist of the last four digits of a credit card number, the expiration date, and the name of the cardholder. For iDeal the IBAN/ BIC number and account name, and for PayPal the account email address.
You can withdraw your consent at any time by writing to us via our support email – email@example.com.
MESSAGEBIRD COMPANY FAMILY
In order to do business with our global offices, we might need to share personal data between our legal entities. Both Vertex LV. and all other entities in the Vertex Company Family will only ever use the data as described in this statement.
Targeted Advertising. We don’t sell any information to or from third parties for advertising or marketing purposes. We use direct marketing ourselves through Google Adwords, LinkedIn and Facebook.
We won’t share your information with third parties without your permission, except when we’re required to by law and in accordance with Vertex’s Disclosure Requests Policy.
Part of the policy requires Vertex to only respond to government requests when we are legally obliged to do so. Accordingly, the request needs to 1. be sent from a government agency, 2. be issued where we are subject to the respective jurisdiction, 3. be an enforceable subpoena, search warrant, court order or similar official instrument compelling us to disclose the information requested, and 4. state the categories of records sought and specific time period.
International transfer of data (outside EEA)
The usage of our services often involves the transfer of personal data, both within and outside the European Economic Area (EEA). We always take care to ensure our partners outside the EEA, and within the EU for that matter, have sufficient guarantees and safeguards in place to properly treat and protect your data in line with our data protection and (information) security standards.
Among others we make sure data transferred outside the EEA will only be done with the appropriate cross border transfer mechanisms in place. We always make sure we contractually agree on data protection to protect the rights and freedoms of all individuals, inside and outside the EU, and ensure compliance with our data protection standards and, when applicable, the GDPR.
Data security and compliance obligations
We do everything in our power to keep your data safe. We invest in state-of-the-art technology and thorough security screenings of our infrastructure and employees to minimize security risks.
Since all our accounts are password-, and possibly two-factor authentication, protected the only person with access to your account should be you. If your login information is stolen or used without your permission, it’s imperative you notify us immediately so we can secure your account. You can do so by sending an email to firstname.lastname@example.org with the subject ‘Urgent: account credentials’.
Retention of personal data
How long we keep personal data depends on its nature and the purpose for which it was obtained. We retain personal data to fulfil contractual or legal obligations which may vary depending on the geographical location you are residing in, the service is procured or the communications services are terminated.
Personal data related to our communications services, such as leasing telephone numbers, location related information, and message body, all have a default retention period of two months to fulfil our European obligations to actively prevent misuse of our services and when formally requested disclose information to further a criminal investigation. We solely retain end-user communication data, including recipients’ phone numbers, for the purpose of preventing misuse of the Vertex services for the period of two months.
We provide all of our customers with ancillary services which, among others, include the possibility of maintaining an online address book for your convenience, and insights in the communication usage and transmission history, specific to your account and for the duration of the services. In relation to these ancillary services customer ensures that any end-user (communication recipient) personal data, such as phone numbers, email addresses, etc, are solely controlled by you as a controller and any data protection rights exercised by your end-users must be executed by you as a customer. We will neither access nor delete any such personal data on behalf of you as a controller and it is your responsibility as a customer to ensure compliance with your obligations towards the end-users whose personal data you control.
We keep information for marketing and sales purposes up to 3 months, or when applicable, for the duration of the service to you as a customer.
Additionally, we are under an obligation to demonstrate compliance with the applicable national and EU financial and tax laws and regulations. To do so, data related to a customer’s account such as name, email address, (company) address, (company) bank details and position within the company will be kept for a period up to 10 years. Proof that consent has been given will be retained for five years.
After the required retention period expires, we might keep data in a non-identifiable form for archival, statistical and/or other legitimate purposes. None of it will be able to identify you as an individual.
Controlling your rights and choices
Even though we collect your data to conduct business, your data stays your own. You stay in control of your, and the recipients of your communications, personal data and can at any time choose what you want us to do with it. You can: change your cookie settings as a website visitor, withdraw consent to our processing of your data when this applies, control and review your data, and object to and restrict the processing of data if you deem that necessary.
Change your cookie settings. When you visit our website for the first time, you can either allow us to place all the cookies we use on your browser, decide to accept specific ones or deny all our cookies. You can always change your preferences both in your browser settings and in the cookie settings on our website. Within our cookie settings, we outline each cookie type in use on our site and provide an explanation of the implications of accepting it.
Withdraw consent to our processing of your data. If for whatever reason you no longer want us to use your personal data, and you have provided that data to us on a consent basis, you’re free to change your mind. We will always comply with your request, unless we’re legally required to keep your data. Which basically means that if there is any legal obligation, about for example our responsibility to demonstrate we have acted upon a withdrawal of consent request, we must keep information that includes personal data in order to do so.
Control and review your or your end-user’s data. You can always view, amend, delete, and transfer the personal data your control. As a Vertex customer, if you want to exercise control over your or your end-users’ personal data, you must do so on your online account. We provide all of our customers with reasonable assistance to fulfill your obligations as a data controller towards the recipients of the communications you have sent over our platform. In order to verify your identity, or the genuinity of the request you make on behalf of the end-user whose data you control, we have made technical and organizational measures available that allow you to fulfil these obligations via your online account or a dedicated API. Unfortunately, requests sent by you as a customer via email are therefore not considered as a valid means to exercise these rights and as a result we are not in a position to process such requests. For the avoidance of doubt, you as a customer acting as a controller are responsible for processing any requests or complaints on behalf of your end-users whose personal data you control.
We’ll process your request as soon as possible with a maximum of one month after receiving it. If a request is complicated or we get too many requests to process at a given time period, our response time can be increased by two months. You’ll be informed when such an extension period applies. When you choose to delete your personal data, we hold the right to hold onto anonymized and aggregated data. If we do so, nothing will be able to identify you as a person in any way. If we’re required to retain your information for legal reasons, we will let you know in response to your request.
Object to and restrict the processing of data. When your personal data is being processed to fulfill a legitimate interest to us, such as direct marketing to existing customers, you’re able to object and unsubscribe. You can always exercise your right to restrict processing, and we’ll make sure to process your data in the way you specify. We will assess each request on a case-by-case basis according to the rules set out by the applicable data protection laws, often the GDPR. If we override your request, we need to demonstrate that we have compelling grounds to do so, or that there’s a legal claim which allows us to retain personal data. If you don’t agree with how we’ve handled your request, you can file a complaint with the Supervisory Authority of The Latvia, the authority related to the Member State you live or work in, or the country in which the suspected infringement has taken place.