Privacy Policy
Your privacy is important to us. It is Cloud Certitude’s policy to respect your
privacy
regarding
any information we may collect from you through our website, why we collect it, how
we use it
and what rights you might be entitled to as a data subject or consumer.
Please note: all information in this Privacy Policy is applicable to you unless
otherwise
indicated.
Purpose
The purpose of this Privacy Policy is to provide users with transparency with respect
to Cloud Certitude collection and use of personal data, including while using its
services. Cloud Certitude is committed to protecting the confidentiality of
information entrusted to it by users and has prepared this Privacy Policy to
describe our
policies and
procedures on the collection, use and disclosure of your information when you use
the service and explains your privacy rights and how the law protects you. We
use Your Personal data to provide and improve the service. By using the service, you
agree to the collection and use of information in accordance with this Privacy
Policy.
Scope
This Privacy Policy addresses all data, programs, systems, facilities, other tech
infrastructure, users of technology and Third-Parties at the Company, without
exception.
Definitions
-
“We,” “Our,” “Company,” “Us,”
“Cloud
Certitude” refers to Cloud Certitude Private
Limited, its affiliates.
-
“Affiliate” (or plurally
“affiliates”)
means any entity that controls, is controlled by, or is under common control
with the Party (or such other entity for which such determination is being
made). The term “control” (including the terms “controlling”, “controlled by”
and “under common control with”) means the possession, whether direct or
indirect, of the power to direct or cause the direction of the management and
policies of an entity or the composition of its board of directors or equivalent
body, whether through the ownership of shares, by contract, or otherwise.
Affiliate shall also include (i) any entity that is consolidated into either
Parties group of companies or accounted for under the equity method of
accounting under IFRS and/or (ii) any entity where either Party, directly or
indirectly, has ownership of at least 50% of the shares.
-
“Client” refers to any
entity(es) or
company(ies) that enter into business with us, or avail our products or
services.
-
“Party” (or plurally
“Parties”) refers to
us, the client, third parties and any of their respective affiliates that enter
an agreement with us to purchase or subscribe to any licensed property, service,
or product.
-
“Third party” (or plurally
“Third Parties”) refers to any entities outside of our company, the client and
either of their affiliates that provide or vend specialized software services or
dependencies.
-
“Employee” (or plurally
“Employees”) all refers to all employees officially appointed on our payroll.
-
“Senior managers” refers
to all team-leaders that grant data access to employees and maintain
corresponding records.
-
“Application security
program” refers to Security for flagship products that are
purchased.
-
“Security team” is the
technical team of Employees that makes security updates and changes to fully
address and report on any issues related to vulnerability management or issues
brought up by another internal team dedicated to security management and
incident response.
-
“Product” refers to all
licensed and unlicensed property owned by us.
-
“Licensed property” means
all the documentation and proprietary software, systems, inventions and designs
of Cloud Certitude, except for deliverables.
-
“Services” means the
products and services to be provided by Cloud Certitude or any of its
affiliates.
-
“People security” refers
to restricted communications for sensitive data for the company’s employees.
-
“Product security” refers
to the failsafe and guardrails implemented to secure all our products from
unauthorized access and control by malicious actors.
-
“Cloud and network infrastructure
security” refers to measures taken to ensure any data hosted over a
cloud or local network is safe from unauthorized access, destruction and
modification.
-
“Security” refers to any
recognized measures, best practices, protocols, enforcement and related
measures taken with the ultimate aim to secure a product or service or client
data from unauthorized access and modification.
-
“Security compliance”
refers to adherence and record-keeping for agreed measures and responsibilities
that constitute security.
-
“Third party security”
refers to measures and legal obligations for a third party as well as us for the
security of any client’s data.
-
“Vulnerability management”
refers to updates to address identified, potential, or future vulnerabilities
and flaws in security for products, services and any client’s data.
-
“Security management and incident
response” means dealing with any emerging, persistent, or
envisioned security flaws or loopholes.
-
“Chief information and security
officer” is our designated head and principal decision-maker for a
dedicated internal team tasked with security management and information
response.
-
”Customer” or
“Data subject” refers to anyone whose data a client stores and
collects in a salesforce org or salesforce cloud.
References
-
Physical security policy -
A
document that describes all prerequisites in the form of measures, fail-safes,
restrictions and verifications undertaken by Cloud Certitude prior to and while
establishing physical access or control at all locations of availability.
Data collection & usage
-
Personal data - While
using our service, we may ask you to provide us with certain
personally identifiable information that can be used to contact or identify you.
Personally identifiable information may include, but is not limited to:
- First name and last name
- Phone number
- Usage data
Usage data
is collected automatically when using the service. Usage data
may
include information such as your device’s internet protocol address
(e.g. IP
address), browser type, browser version, the pages of our service that
you
visit, the time and date of your visit, the time spent on those pages,
unique
device identifiers and other diagnostic data. When you access the
service by
or
through a mobile device, we may collect certain information
automatically,
including, but not limited to, the type of mobile device you use, your
mobile
device unique ID, the IP address of your mobile device, your mobile
operating
system, the type of mobile internet browser you use, unique device
identifiers
and other diagnostic data. We may also collect information that your
browser
sends whenever you visit our service or when you access the service by
or
through a mobile device.
-
Use of your personal data -
To provide and maintain our service, including to monitor the usage of our
service.
- Manage your account - To manage your registration as a
user of the service. The personal data you provide can give you access
to different functionalities of the service that are available to you as
a registered user. For the performance of a contract: the development,
compliance and undertaking of the purchase contract for the products,
items, or services you have purchased or of any other contract with us
through the service.
- To contact you - To contact you by email, telephone
calls, SMS, or other equivalent forms of electronic communication, such
as a mobile application’s push notifications regarding updates or
informative communications related to the functionalities, products, or
contracted services, including the security updates, when necessary or
reasonable for their implementation.
- To manage your requests -
To attend and manage your requests to us.
- For business transfers -
We may use your information to evaluate or conduct a merger,
divestiture, restructuring, reorganization, dissolution, or another sale
or transfer of some or all of our assets, whether as a going concern or
as part of bankruptcy, liquidation, or similar proceeding, in which
personal data held by us about our service users is among the assets
transferred.
- With service providers -
We may share your personal information with service providers to monitor
and analyse the use of our service, to contact you. For business
transfers: We may share or transfer your personal information in
connection with, or during negotiations of, any merger, sale of company
assets, financing, or acquisition of all or a portion of our business to
another company.
- With affiliates -
We may share your information with our affiliates, in which case we will
require those affiliates to honour this Privacy Policy. Affiliates
include our parent company and any other subsidiaries, joint venture
partners, or other companies that we control or that are under common
control with us.
- With business partners -
We may share your information with our business partners to offer you
certain products, services, or promotions.
-
Disclosure
- Business transactions - If the company is involved in
a
merger, acquisition or asset sale, your personal data may be
transferred. We will provide notice before your personal data is
transferred and becomes subject to a different Privacy Policy.
- Law enforcement - Under certain circumstances, the
company may be required to disclose your personal data if required to do
so by law or in response to valid requests by public authorities (e.g. a
court or a government agency).
- Other legal requirements - The company may disclose
your
personal data in the good faith belief that such action is necessary to:
- Comply with a legal obligation.
- Protect and defend the rights or property of the company.
- Prevent or investigate possible wrongdoing in connection with
the
service.
- Protect the personal safety of users of the service or the
public.
- Protect against legal liability.
Cloud Certitude does not and will not sell, share or rent your
personal
data to anyone in exchange for monetary compensation.
-
Transfer
your information, including personal data, is processed at the company’s
operating offices and in any other places where the parties involved in the
processing are located. It means that this information may be transferred to —
and maintained on — computers located outside of your state, province, country,
or other governmental jurisdiction where the data protection laws may differ
from those from your jurisdiction. Your consent to this Privacy Policy followed
by your submission of such information represents your agreement to that
transfer. The company will take all steps reasonably necessary to ensure that
your data is treated securely and in accordance with this Privacy Policy and no
transfer of your personal data will take place to an organization or a country
unless there are adequate controls in place including the security of your data
and other personal information.
-
Retention -
Our retention policy data use follows a principle of ‘end-to-end’ security from
disclosure to destruction. This is in keeping with our measures for privacy by
the company will retain your personal data only for as long as is necessary for
the purposes set out in this Privacy Policy. We will retain and use Your
personal data to the extent necessary to comply with our legal obligations (for
example, if we are required to retain your data to comply with applicable laws),
resolve disputes and enforce our legal agreements and policies. The company
will also retain usage data for internal analysis purposes. Usage data is
generally retained for a shorter period of time, except when this data is used
to strengthen the security or to improve the functionality of our service, or we
are legally obligated to retain this data for longer time periods. Still, in
case any data is provided by the client for operational purposes, it is
destroyed and formatted over 13 times to prevent retrieval.
Enforcement and dispute resolution
Cloud Certitude will investigate and attempt to resolve all disputes and complaints
regarding our use and disclosure of personal data in accordance with this Privacy
policy.
Jurisdiction-specific requirements and implementation
National data protection and privacy laws may impose additional requirements on Cloud
Certitude for the processing of personal data. Where required, Cloud Certitude will
establish procedures and guidelines in order to supplement the principles of this
policy and engage with relevant regulatory/supervisory authority, as required.
Privacy by enforcement
A dedicated privacy team headed by a designated, accessible administrator manages the
application's privacy program and assumes complete responsibility for all
privacy-related issues. Security measures are meant to be proactive and
preventative, not remedial and reactive. Our information security policies and
standards are approved by management and available to all employees.
-
Classification of data -
A
data classification policy may arrange the entire set of information as follows
- High-risk class - Data protected by state and federal
legislation (the Data Protection Act, HIPAA, FERPA as well as financial,
payroll and personnel (privacy requirements) are included here.
- Confidential class - Data in this class do enjoy the
privilege of being protected by laws explicitly, but nonetheless, data
owners are still extended equivalent protections against unauthorized
disclosure.
- Public class - This information is available publicly
and
can be freely distributed.
-
Data support & operations -
Support and operations like the regulation of general system mechanisms
responsible for data protection, data backup, movement of data.
Our security framework includes People Security, Product Security, Cloud and
Network Infrastructure Security, Security Compliance, Third Party Security,
Vulnerability Management, as well as Security Monitoring and Incident
Response.
-
Authority, access control and
restriction - Permissions and access to any client’s data, if found
necessary for
operation, are shared sparingly on a ‘need-to-know’ basis with a due record of
access. Employees with access are legally bound not to share the little amount
of information they may have unless explicitly authorized. This is affected in
ways that senior managers may have adequate authority to make a decision on what
data can be shared and with whom while assuming responsibility for keeping due
records of access. Monitoring on all systems must be implemented to record login
and access attempts.
-
Legal obligations - We
ourselves, our service providers, third-parties and all affiliates
thereof are contractually obligated to take meaningful active consent (or seek
obligations for the same) in accordance with mandated local regulations, before
storing any user data in an org. Obligations also include all situations
enumerated in the section titled “Privacy Rights & Data Removal.”
- Legitimate interest– The processing is based on our
legitimate interests or the legitimate interests of our subsidiaries and
affiliates to continuously operate, improve and/or personalize our
services and develop new services, monitor the usage of our website and
ensure the security and detect any frauds and abuse, unless the
requirement to protect the individual’s personal data overrides those
legitimate interests.
- Consent– You have provided express consent to the
processing of your personal data for the specific purposes by explicitly
ticking the relevant buttons, where applicable and by voluntarily
filling in and providing your personal data.
- Contract - Processing is required for the performance
of
a contract in which Cloud Certitude has been engaged to perform
services.
Privacy by transparency
-
Changes and approvals
- Privacy Policy - We reserve our right to update our
privacy policy from time to time. We will notify you of any changes by
posting the new privacy policy on this page from our data protection
team. We will let you know via email and/or a prominent notice on our
service, prior to the change becoming effective and update the “Last
Updated” date at the top of this privacy policy. You are advised to
review this privacy policy periodically for any changes. Changes to this
privacy policy are effective when they are posted on this page.
- Security Policy - Security is represented at the
highest
levels of the company, with our Chief Information Security Officer
meeting with executive management regularly to discuss issues and
coordinate company-wide security initiatives.
-
Disclosures -
It is possible that we will need to disclose information about you when required
by law, subpoena, or other legal process, or if we have a good faith belief that
disclosure is reasonably necessary to:
- Investigate, prevent, or take action regarding suspected or actual
illegal activities or to assist
government enforcement agencies,
- Enforce our agreements with you,
- Investigate and defend ourselves against any third-party claims or
allegations,
- Protect the security or integrity of our service (such as by sharing
with companies facing similar
threats).
We will attempt to notify you about legal demands for your personal data
when appropriate in our judgment unless prohibited by law or court order or
when the request is an emergency. We may dispute such demands when we
believe, in our discretion, that the requests are overbroad, vague, or lack
proper authority, but we do not promise to challenge any demand.
Security commitments for privacy
We consider our attitude towards security as a vital part of our commitment to and
enforcement of privacy. Security is a top priority for Cloud Certitude. We use the
best security practices and policies to ensure that our network is secured
physically, virtually and that our customer’s data is both private and secure. We
do not save the data of the organizations which install our app instead, We use
infrastructure from recognized third party organizations for sending and receiving
SMS, multimedia, or any other communication administered by our applications or
services. Our security practices and policies offer a transparent look into our
operations and the support that we offer our clients and their customers (or data
subjects).
-
Privacy by design -
At Cloud Certitude website, all operations are
‘zero-local-storage’, by design, even accelerated bulk messaging. That means
any communications you send out or receive in confidence or otherwise, lives
only on salesforce’s cloud storage, within your org.
-
Privacy by end-to-end security -
From salesforce, an HTTP request with the message body, sender number as well as
receiver number reaches the user’s (our) SMS Provider, which triggers an SMS
from salesforce. In its turn, the service provider then drafts an SMS from the
HTTP request and sends it over to the intended recipient’s carrier and device as
depicted in the schematic in Figure 1 below. Similarly, any replies or incoming
messages are routed to our salesforce site via the recipient’s carrier and then
our own provider.
-
Privacy by architecture security -
Our applications are completely ‘salesforce-native’, which means client
data
is hosted exclusively over the client’s own salesforce cloud instance
and
doesn’t store any NPI (Non-Public Information) of the client’s customers
on
any physical server of our own. Information travels from customer to
respective SMS API Provider and at no point is stored within the app.
The
app uses encrypted APIs to send/receive the text messages thus ensuring
data
encryption and privacy.
Therefore, by the combined virtue of the salesforce cloud platform being
HIPAA certified, our applications being completely salesforce-native
and our service providers being contractually obligated to observe and
enforce HIPAA compliance, all of our applications would be considered
HIPAA certified, even though we have never explicitly sought this
specific designation.
Penetration Testing is used as the primary security assessment type.
Security engineers continuously perform numerous activities to ensure
that our products are secure.
These include internal security reviews before products are launched,
regular penetration tests performed by third-party contractors,
continuously running bug bounty programs, continuously running internal
and external security tests and regularly conducted performance tests
against threat models.
-
Privacy by data security
controls -
We don’t store any of the client’s data at our end but since we use
multiple texting providers to send and receive messages, providers store
data such as the number to which the message was sent or the date and
time the messages were sent or received.
Even within our applications, we don’t access or modify your salesforce
instance’s internal data.
We have provisioned a separate ‘SMS history’ object in which you hold the
records of all messages sent and received.
While communication platform multi-tenancy is an integral component of
our application architecture, logical identifiers ensure that a client’s
data isn’t accessed by other clients.
Cloud Certitude has a formal change-management process where all changes
are tracked and require approval. Changes are reviewed before being
moved into a staging environment where they get tested further before
finally being deployed to production.
Cloud Certitude performs third-party penetration tests periodically
-
Privacy by default -
Default Commitment & Intentions
We only ask for personal information when we truly need it to provide a
service to you. We collect it by fair and lawful means, with your knowledge
and consent. We also let you know why we’re collecting it and how it will be
used. We only retain collected information for as long as necessary to
provide you with your requested service. What data we store, we’ll protect
within commercially acceptable means to prevent loss and theft, as well as
unauthorized access, disclosure, copying, use, or modification. We don’t
share any personally identifying information publicly or with third-parties,
except when required to by law. Even in events not covered by this Privacy
Policy, we intend to uphold privacy for all clients and their customers (or
data subjects) in good faith. Your continued use of our app will be regarded
as acceptance of our practices around privacy and personal information. If
you have any questions about how we handle user data and personal
information, feel free to contact us.
How we will keep your information safe
We have put in place appropriate technical, organizational and security measures to
prevent your personal data from being accidentally lost, used or accessed in an
unauthorized way, altered or disclosed. In addition, we limit access to your
personal data to those employees, agents, contractors and other third parties who
have a business need to know. They will only process your personal data on our
instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected data security breach and
will notify you and any applicable regulator of a suspected breach where we are
legally required to do so.
Rights of the data subject residing in the European Union or to which GDPR applies
Residents of the European Union have certain rights under European data protection
law with respect to personal data, including the right to request access to,
correct, amend, delete, limit the use of, object to or withdraw your consent for the
processing of your personal data at any time. They may also have the right to
receive a copy of your personal information in a commonly used and machine-readable
format and to transmit such information to another controller.
You may write to us at any time requesting the above stated requests and we will
update, block, erase, remove or provide your personal information upon request in
line with applicable law.
Privacy Policy for California residents
Cloud Certitude adopted the California Consumer Privacy Statement which supplements
the information contained herein and represents an attachment to this Privacy
Policy, an integral part hereto. The California Consumer Privacy Statement applies
solely to personal information as defined in the relevant data privacy laws
collected about California consumers, such as our website visitors, attendees of our
webinars and events, representatives of our business customers and business
partners and job applicants.
Compliance measures
-
Assigned privacy and security
responsibility
- Security program - While security is a high priority
for all our teams, a
dedicated security team manages our security program.
- Security alert response - Security alerts are directed
at IT managers that can speak to
development team coordinators and are followed up with a proportionate
response and disciplinary measures
- Security initiatives - Data Protection and Chief
Information Security Officers (and
their respective teams) discuss and lead our security initiatives.
-
Standard compliance measures
&
best practice - Applications by Cloud Certitude adhere to a host of
privacy principles
and best practices required by most compliance regulations by design, through
architecture. Since it’s natively built on salesforce, it doesn’t store customer
information on any physical server of its own. Information travels from customer
to the respective service provider and at no point is stored with Cloud
Certitude. The website also encrypts the messages thus ensuring data encryption
and privacy.
Site usage
Our Service or website may contain links to other websites that are not operated by
us. If you click on a third-party link, you will be directed to that third-party’s
site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, Privacy
Policies or practices of any third-party sites or service.
Privacy rights and data removal
-
Your rights as a data subject -
At any point while we are in possession of or processing your personal
data, you, the data subject, have the
following rights:
- Right of access – you have the right to request a copy of the
information that we hold about you.
- Right of rectification – you have a right to correct data that we hold
about you that is inaccurate or
incomplete.
- Right to be forgotten – in certain circumstances, you can ask for the
data we hold about you to be
erased from our records.
- Right to restriction of processing – where certain conditions apply to
have a right to restrict the
processing.
- Right of portability – you have the right to have the data we hold about
you transferred to another
organization.
- Right to object – you have the right to object to certain types of
processing, such as direct marketing.
- Right to object to automated processing, including profiling – you also
have the right to be subject to
the legal effects of automated processing or profiling.
- Right to judicial review – in the event that website refuses your
request under rights of access, we will provide you with a reason as to
why. You have the right to
complain as outlined in clause 7
below.
You may also contact us using the contact information below and we will
consider your request in
accordance with applicable laws.
-
Privacy rights for minors -
We do not intentionally collect or store any data for clients or their
customers under the age of 18. All third-parties and clients are contractually
obligated to abstain from doing the same. However, if such data does make its
way past us or our clients unknowingly, we intend to destroy it as soon as we
can, once it is brought to our attention.
-
Data removal & complaints -
To request data removal or in the event that you wish to make a
complaint about how your personal data is being processed by Cloud Certitude
website (or third parties as described above), or how your complaint has been
handled, you have the right to lodge a complaint directly with the supervisory
authority with our Data Protection Officer.
Disclaimer
Cloud Certitude is the owner and controller of this website. We do not consent to the
use and/or reproduction of the content and information on this website without our
consent, pursuant to applicable copyright law.
Cloud Certitude is not responsible, nor do we have control of third-party
websites/links to and from our website.
Data minimization and purpose limitation
The Company shall collect and process personal data solely for specified, explicit
and legitimate purposes. No personal data shall be processed in a manner that is
incompatible with those purposes, adhering to the principle of data minimization.
Data sharing and third-party processors
Personal data may be shared with third-party processors only when necessary and under
conditions that ensure the data’s confidentiality and integrity. All third-party
processors must adhere to data protection standards comparable to those outlined
herein.
Specific rights under CCPA and Indian data protection guidelines
Data subjects under the California Consumer Privacy Act (CCPA) and applicable Indian
data protection guidelines are afforded specific rights, including the right to
access, delete and opt-out of the sale of their personal data. The company commits
to honouring these rights in compliance with the respective legislations.
Use of cookies and tracking technologies
The company employs cookies and similar tracking technologies to enhance user
experience and analyse service usage. Data subjects may control the use of such
technologies via their browser settings or through direct opt-out mechanisms
provided by the company.
Data breach and incident response
-
Incident reporting
- In the event of a data breach or unauthorized access to user data, Cloud
Certitude will take immediate steps to mitigate the impact and notify
affected users and relevant regulatory authorities as required by
applicable laws.
- Notification will be provided within 72 hours of becoming aware of the
breach, unless otherwise mandated by law.
-
Limitation of liability
- Cloud Certitude shall not be liable for any damages, losses, or
consequences arising from a data breach, including but not limited to
financial losses, reputational damage, or third-party claims, unless
such breach is directly attributable to the company’s gross negligence
or willful misconduct.
- Users are responsible for maintaining the security of their credentials,
passwords and systems. Cloud Certitude may assist in data recovery but
does not guarantee the restoration of lost or compromised data.
-
Force majeure
- Cloud Certitude shall not be liable for any failure or delay in
performance due to events beyond its reasonable control, including but
not limited to cyberattacks, hacking, or other security incidents caused
by third parties.
Third-party platforms and services
-
Salesforce Platform
- The Cloud Certitude website operates on the salesforce platform, which
is owned and controlled by a third party. Cloud Certitude does not own,
operate, or assume any responsibility for the salesforce platform.
- Users acknowledge that their use of the salesforce platform is subject
to Salesforce’s Terms of Service and Privacy Policy and Cloud Certitude
shall not be liable for any issues arising from the use of the
salesforce platform.
-
Third-party service providers
- Cloud Certitude may use third-party service providers for messaging,
data storage and other services. These providers operate independently
of Cloud Certitude and the company shall not be liable for any actions,
omissions, or breaches by such third-party providers.
Global data protection compliance
-
GDPR compliance
- For users residing in the European Union, Cloud Certitude complies with
the General Data Protection Regulation (GDPR). Users have the right to
access, rectify, erase, restrict, or port their data, as outlined in
Section 12 of this Privacy Policy.
-
CCPA compliance
- For California residents, Cloud Certitude complies with the California
Consumer Privacy Act (CCPA). Users have the right to opt-out of the sale
of their personal data and request the deletion of their data, as
outlined in Section 13 of this Privacy Policy.
-
Indian data protection
compliance
- For users in India, Cloud Certitude complies with applicable data
protection laws, including the upcoming Digital Personal Data Protection
Act (DPDPA). Users have the right to access, correct and delete their
personal data, as outlined in Section 16 of this Privacy Policy.
User responsibilities
-
Security of credentials
- Users are solely responsible for maintaining the confidentiality and
security of their login credentials, passwords and access to the Cloud
Certitude website.
- Users must immediately notify Cloud Certitude of any unauthorized access
or suspected security breach.
-
Compliance with applicable laws
- Users agree to comply with all applicable laws and regulations,
including but not limited to TRAI regulations for SMS and WhatsApp
services, Meta’s policies for WhatsApp and FCC regulations for
telecommunications.
Dispute resolution and arbitration
-
Governing law
- This Privacy Policy and any disputes arising out of or related to it
shall be governed by the laws of the State of California, USA, without
regard to its conflict of law principles.
-
Arbitration
- Any disputes, claims, or controversies arising out of or relating to
this Privacy Policy shall be resolved through binding arbitration
administered by the American Arbitration Association (AAA) in accordance
with its Commercial Arbitration Rules.
- The arbitration shall take place in Laguna Beach, California and the
decision of the arbitrator shall be final and binding.
-
Class action waiver
- Users agree to resolve disputes on an individual basis and waive any
right to participate in class actions or class arbitrations.
Limitation of liability
-
Exclusion of consequential
damages
- In no event shall Cloud Certitude be liable for any indirect,
incidental, consequential, special, or punitive damages, including but
not limited to loss of profits, data, or business opportunities, arising
out of or related to the use of the website, services, or this privacy
policy.
-
Cap on liability
- Cloud Certitude total liability for any claims arising out of or related
to this Privacy Policy shall not exceed the amount paid by the User for
the services in the one (1) month preceding the claim.
Data minimization and retention
-
Data minimization
- Cloud Certitude shall collect and process only the minimum amount of
personal data necessary to provide the services.
-
Data retention
- Personal data shall be retained only for as long as necessary to fulfill
the purposes outlined in this Privacy Policy, unless a longer retention
period is required by law.
- Upon the expiration of the retention period, personal data shall be
securely deleted or anonymized.
Transparency and user consent
-
Explicit consent
- By using the website or services, users explicitly consent to the
collection, use and sharing of their personal data as described in this
Privacy Policy.
-
Withdrawal of consent
- Users may withdraw their consent at any time by contacting Cloud
Certitude at info@cloudcertitude.com Withdrawal of consent may result in
the termination of services.
Use of cookies and tracking technologies
-
Types of cookies
- Cloud Certitude uses cookies and similar tracking technologies to
enhance user experience, analyse service usage and deliver targeted
advertisements.
-
User control
- Users may control the use of cookies and tracking technologies through
their browser settings or by using the opt-out mechanisms provided by
Cloud Certitude.