Background and this Statement
Your privacy is of crucial importance to Caasco.
This Privacy Statement describes how Caasco collects, processes and protects your personal data. Overall, Caasco processes your personal data in compliance with regulation protecting personal data, according to best practices for secure handling of personal data, and with the utmost respect.
If you wish to contact Caasco about processing of your personal data, our contact information is found in the bottom of this document.
This Privacy Statement applies to all business processes in Caasco and to all Caasco websites, domains, digital solutions, cloud or other services, branches, subsidiaries and communities as well as Caasco branded websites (collectively referred to as also as Caasco).
The Privacy Statement provides information about data processing carried out by Caasco when Caasco determines the purpose and means of the processing (Caasco act as data controller). Data processing Caasco perform on behalf of our Customers based on their instructions (the Customer acts as data controller and Caasco as data processor) is described in our Data Processor Agreement and is a part of our Customer Agreement.
Personal data is information that can identify you as a person, such as an email address, street address or phone number. Processing your personal data is necessary for us to serve you and our Customers. Please do not use Caasco services if you do not agree with how we process personal data according to this Privacy Statement.
This Privacy Statement is published with the aim to make it easy for our users, customers and the public to understand what personal data we collect, store and process, why we do so, how we receive and/or obtain that information, and the rights an individual has with respect to their data in our possession.
Whose data do we collect and process
As a Data Controller, Caasco collects and process personal data about the following Data Subjects:
a) Caasco End Users (or just "Users", "End Users" or "Caasco Users"), either Registered Users of the Caasco platform (End Users with a personal Caasco account), or other Caasco End Users, including, but not limited to, visitors to Caasco's websites, and recipients of emails from a Caasco Customer sent via Caasco,
b) Submitters of support tickets (often Caasco Users already),
c) Job Applicants,
d) Potential customers' contact persons (Leads),
e) Customers' contact persons (Customer Representatives),
f) Customer companies' owners,
g) Visitors to Caasco's physical premises,
Why we collect your data
Caasco collects and process your personal data for a variety of reasons:
a) Deliver promised services to our Customers or promises made to you as a person,
b) Improve and develop quality, functionality and user experience of our products, services and sites,
c) Offer support, education and other useful interaction types to users of our products, services and sites,
d) Perform invoicing, payments, and other financial tasks,
e) Being able to operate our services, including maintaining, debugging and developing the technical platform,
f) Secure our business secrets, intellectual property and general service delivery by detecting and preventing threats and abuses,
g) Perform employee administration tasks for Employees,
h) Provide relevant, targeted content to Customer Leads,
i) Evaluate potential for becoming a Caasco employee for Job Applicants.
The legal basis for processing your personal data according to the above-listed purposes a) - h) is Caasco's legitimate business interest in simply being able to operate Caasco and deliver promised services to Customers. We sincerely believe that this does not conflict with your privacy rights. The legal basis for purpose i) is your consent, which we assume from your offering of personal data, but will confirm when processing, as part of the Job Application process.
How we collect your data
Caasco collects personal data through several channels:
a) Most personal data are collected directly from you, based on information you offer to us via the usage of Caasco products, services, or websites, or via other channels, such as a direct email or job application,
b) Some personal data are collected via cookies and other tracking technologies, such as pixel tagging in emails. Caasco uses such tracking mechanisms to pursue the purposes a)-f) of the previous section.
c) Finally, Caasco also collects data about you from other sources, such as third-party data aggregators, marketing, legal, accountant or other partners or subcontractors, or public sources. Caasco will in some instances be able to combine personal data about you from multiple sources, helping us improve and personalize your experience.
You can read more about cookies in the section below. If you have questions about the data collection, feel free to contact us.
Our Customers may list personal data about you on the Caasco platform: for instance, if you are a shareholder in company A, then company A may include personal information about you (such as name and address) in their registry of shareholders on Caasco. This holds true even if you have never registered as a Caasco user or interacted with Caasco in any way. In the situation where personal data about you is registered by a Customer of Caasco, that Customer is the Data Controller of your data. If you have privacy concerns or any questions in this situation, we recommend that you contact that company.
Data we collect
Caasco collects and process data about you such as:
a) Contact information provided by you or a Customer (name, addresses, emails, telephone numbers...),
b) Demographic information provided by you, directly or indirectly, or a Customer, such as, but not limited to, birth date, age, gender, and interests,
c) Contact information (such as the above), and employment information about you at a Customer company, such as job title,
d) Contact and CV information about you, if you provide it as a Job Applicant,
e) Personal information you provide to Caasco as a Registered User, such as profile pictures, comments, external profile links, content of texts, hashed versions of your Caasco password, and more,
f) Shared content about you on third party social networks explicitly linked to your Caasco account or used for Caasco login,
g) Technical identifiers, such as IP-address, geographic location, Caasco unique user id, browser information (type, device, language, referrer url, etc.),
h) Site navigation information about your behavior and movements on Caasco sites,
i) Email handling information such as which emails from Caasco you open when and how.
Caasco will only retain your personal data for a period of time necessary to fulfil the stated purpose of the data collected, however, to provide a better general service, comply with legal requirements, and speed up and ease support, we may keep relevant bits of data for a reasonable period of time after your last interaction with Caasco, unless otherwise stated, this period will be maximally 5 years from your last interaction. When we no longer retain your personal data, it is destroyed, deleted or anynomized suitably.
Caasco does not collect or process any kind of sensitive personal data, such as data about ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, data concerning health or sex life or sexual orientation, genetic data and/or biometric data. Neither does Caasco store collect or process any information about criminal offences or serious social problems.
Data we share
Caasco and its business partners, subsidiaries, and departments within Caasco may share your personal data among them to provide efficient and best possible customer service, user experience, and general delivery of services. Such sharing ensures that we can access updated and relevant information about you when we need it, and also ensures that we do not need to contact you more often than needed to obtain or update such data.
Caasco does not share your personal data with any third parties, unless:
a) You consent to a particular sharing of your data with a particular third party.
b) The third party is a subcontractor, vendor, affiliate or service partner, and the sharing is legitimate and necessary or even legally required, from a business perspective.
c) Public authorities legally require it. Caasco may be demanded to hand over personal information about you to e.g. police or courts, by court order or other legal instruments.
By agreeing to this Privacy Statement, you explicitly consent to share certain tracking information we collect about you as a Caasco website visitor, such as an IP-address, with third-parties in order to e.g. analyze webpage usage patterns. You can read more about cookies and similar technologies in the section below.
By agreeing to this Privacy Statement, you also consent to sharing certain personal data with third parties - Caasco Customer companies - which then become the data controllers of that shared data at the moment of sharing. The purpose of this is to connect users and companies on the Caasco platform, a core reason for the Caasco platform to exist; we believe that this does not conflict with your privacy rights. The legal ground for this is your consent to this Privacy Statement. In details, this means that you consent to:
a) As a Registered User in Caasco, any information you add to your Caasco account may be shared with Caasco Customer companies, if these companies are suitably linked to your profile.
This is a central feature of Caasco for both Customers and End Users, minimizing the work needed for keeping data entries up to date across such registers, and that is the legal ground for this automatic data-sharing.
Depending on your privacy settings (can be accessed and modified on your Caasco user profile), your personal data may also be shared with other Caasco End Users. If, for instance, your address is copied to a shareholder register of a Caasco Customer company, depending on your privacy settings, and the configuration of that Caasco Customer company, your address may be disclosed to other shareholders of that company.
b) As a Registered User in Caasco, your contact email(s) are shared with Caasco Customer companies that you are connected to on Caasco, and depending on your privacy settings, these companies may send you email notifications via Caasco for business reasons, such as to keep you updated on important news and events. It is the obligation of these companies to ensure that the email notifications are in compliance with applicable law.
Data you provide or share
When you share data with other people via Caasco, personal or other, you understand that they may be able to, on a worldwide basis, use, save, record, reproduce, broadcast, transmit, share and display that data without prior permission or compensating you. If you do not want others to have that ability, do not use Caasco to share that data. By using the Caasco, you represent that you have (and will have) all the rights necessary for your data that is uploaded, stored, or shared on or through Caasco and that the collection, use, and retention of your data will not violate any law or rights of others.
Do not share sensitive personal data on Caasco, and do not share data that violates the privacy of others, is harmful, or is illegal.
You have the right to opt-out of any consents to the usage of your personal data you have offered, and to demand corrections of personal data about you that Caasco controls. In such an event, depending on the nature of your request, some or all of your personal data within Caasco will be deleted, altered, blocked or anonymized.
To be more specific,
a) You have the right to access your personal data and to get it exported.
You can request us to inform you about what personal data we have collected about you, and you can request a copy of that personal data.
b) You have the right to rectify your personal data.
You can request us to correct any inaccuracies in your personal data, provided you inform us of the corrections. If you are a Registered User, you can usually correct data yourself by logging onto Caasco and accessing your User Profile.
c) You have the right of erasure.
You can request us to delete your personal data on Caasco. Depending on the circumstances, you may be entitled to demand the deletion be carried out before usual data retention periods expire.
d) You have the right of objection.
In some circumstances, you may object to the way we process your personal data.
In some instances, despite your request to the contrary, Caasco may be legally allowed to or obliged to keep your personal data unaltered, for instance in order to comply with regulation. In such cases, we will inform you about why we cannot fulfil your request or what partial fulfilment we can offer.
To assert your rights pertaining to personal data about you controlled by Caasco, you can contact us using the contact information found below.
To assert your rights pertaining to personal data about you, processed by Caasco as a Data Processor on behalf of a Customer (the Data Controller), please make your request with that Customer. For instance, if a company on Caasco lists an incorrect amount of shares held for you as a shareholder in that company's shareholder register on Caasco, please contact that company, not Caasco, in order to rectify the data.
Security and privacy
In the course of handling your personal data, Caasco will store your personal data safely and confidentially and comply with the applicable requirements on the appropriate technical and organizational security measures to ensure an adequate level of protection of your personal data: Caasco keeps your data safe on the application level (via authentication and account-level authorizations), on the communication level (by encrypting traffic to and from Caasco), and on the data level, by frequently backing up your data. We also have logging and auditing in place for incident analysis and continuous security improvements. In the unlikely event of data loss, Caasco is not liable for any claims related to such incidents.
When using subcontractors, Caasco will enter Data Processing Agreements with each subcontractor to make sure your personal data is as well-protected as if it were in Caasco's hands. Most of the time, your data physically resides in UK or the EU, but in some cases, your personal data may be exported outside the EU, for instance in case of backing up an encrypted database in a US-located data center. Whenever data is exported outside the EU, Caasco makes sure that the data importer is either certified according to the EU/US Privacy Shield framework (for US subcontractors) or offer a Data Processing Agreement that live up to the protection levels Caasco offer you.
A non-exhaustive list of some of our more central subcontractors is:
- AWS, provider of secure cloud storage for files uploaded to the Caasco Website
A cookie is a file that is stored on your computer's hard drive, smartphone or any other IT device. It allows for recognition of your computer/IP address and for collection of information about the websites you visit and which features you use.
Should you wish to remove cookies from your browser, the following websites provides you with specific guidelines in this regard:
- Guide on how to remove cookies from the various IE (Internet Explorer) versions
- Manage cookies and website data in Safari on Mac
- Guide on how to remove cookies from Google Chrome
This statement may be modified over time, and we recommend that you inspect the Privacy Statement regularly. The Statement is always available on Caasco's website. In case of substantial changes to our approach to privacy, we may notify you directly, such as by email or upon login to the Caasco platform.
If you have questions, experience any trouble, have any queries about your personal data at Caasco or Caasco privacy in general, or have any questions or comments concerning a possible breach of your privacy, feel free to contact Caasco Support (firstname.lastname@example.org). We will handle your request in full confidentiality.