Global privacy policy

Last modified: January 17, 2019

1. Introduction

Spotlight Services and Technologies Incorporated (“Spotlight”) is registered as a Delaware C-Corporation in the United States of America. SANDC Services and Technologies Private Limited (“SANDC”) is Spotlight’s wholly-owned subsidiary in India, and is registered as a Private Limited Company in India.

Spotlight and SANDC (collectively “we”, “us”, or “our”) respect your privacy and know that you care about protecting your personal information. This Privacy Policy identifies what information we collect from you when you use http://getspotlight.co (the "Site," including all subdomains) and the services made available on it (the "Services") and explains how we will use or share that information. We will only use and share your information as described in this privacy policy.

For the purposes of the UK Data Protection Act 2018 (“DPA 2018”), and the General Data Protection Regulations (“GDPR”) (as applicable), Spotlight is the data controller for customer data relating to users who are established outside India, and SANDC is the data controller for customer data relating to users who are established within India. SANDC however is the data processor for the customer data relating to all users that share personal data through the use of our Site or our Services.

PLEASE READ THIS CAREFULLY AS THIS POLICY IS LEGALLY BINDING WHEN YOU VISIT OR USE OUR SITE OR OUR SERVICES.

2. What data do we collect?

We will directly collect and process the following information about you and your business:

  1. Personal Identification Information (such as your name, email address, official postal address, and official telephone number) that you provide or make available to us.
  2. Your place of work and your designation (including any documentation that is used to verify your authority to represent your business, such as your employee identification card and number)

You are under no obligation to provide any such information. We collect this data as they are necessary for us to fulfil our contractual obligations towards you, or to provide our Services when solicited by you, based on your consent. If you choose to withhold the requested information, we will not be able to provide you with certain services. If you choose to enter into a contract with us, you are consenting to the storage and processing of your data necessary to perform contractual obligations, which will restrict your rights to restrict processing, and/or your right to seek erasure, based on necessity.

We will automatically collect additional information about you when you visit the website, such as:

  1. The type of internet browser you use
  2. Any third-party website(s) from where you have reached out website,
  3. Your IP address (the unique address which identifies your computer on the internet), and
  4. Your operating system, which are automatically recognised by our web server.

We do not intend to identify you using this information, and this information is aggregated and anonymized. This information is used by us internally for the sole purpose of improving our Site and our customers’ experience.

3. How do we collect your data?

You directly provide us with most of the data we collect. We collect data and process data when you:

  1. Submit forms to solicit information about our Services, submit information or data to seek a product/service demonstration, or to subscribe to our Services;
  2. Register on our Site in connection with any of our services;
  3. Voluntarily complete any customer survey or provide us feedback via email or any of our message boards to report a problem, submit queries, or share any concerns or comments regarding our Site or our Services; or
  4. Use or view our Site via your browser’s cookies.

Our company may also receive your data indirectly from the following sources:

  1. Our affiliate referral partners who are authorised on your behalf to share your personal information.

4. How will we use your data?

We collect your data so that we can:

  1. Provide you with the information about our products and services, if requested;
  2. Process your request to use our Services, and the necessary legal documentation that our customers are required to execute to use our Services;
  3. Communicate with you in connection with the performance and/or delivery of our Services, including the exercise of contractual rights, or the enforcement of contractual obligations;
  4. Perform, administer and deliver our Services, and carry out any necessary internal operations, which would include service requests, troubleshooting, data analysis, research, statistical surveys, and grievance redressal;
  5. Measure and understand the usefulness and effectiveness of the information about our products and services on our Site, the features & components of our product in order to improve our Services;
  6. Allow you to participate in any interactive features of our Services, when you choose to do so;
  7. Seek your feedback about our Site and our Services;
  8. Provide you with information about other similar services we offer, and notify you of relevant updates related to our Services, including new features that we believe are useful or beneficial to your work/business;
  9. Use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger, or sale of a business, where we are required by law or where we believe it is necessary to protect our legal rights, legitimate business interests, and the interests of others.
  10. Comply with any applicable legal and/or regulatory requirements; and
  11. Notify you about changes to our Services, and the terms and conditions that govern the use of our Site and our Services; particularly any changes that impact your rights and obligations in connection with your use of our Site or our Services.

If you agree, we will share your data with our partner companies so that they can offer you their products and services. In such cases, your consent will be separately obtained for such specific purpose.

5. How do we process your data?

We are serious about guarding the security of your personal information and use the following data processing services, with who we have entered into the necessary Data Processing Agreements, to securely store and process your data in compliance with GDPR and the DPA 2018:

  1. Google Cloud SQL Platform:

    The storage and processing of your data and personal information on Google Cloud SQL is subject to Google’s Data Processing and Security Terms, which can be accessed from: https://cloud.google.com/terms/data-processing-terms. In particular, the applicable security measures and controls are highlighted in Clause 7.1 of these terms. Google’s Cloud Data Protection Team can be contacted at: https://support.google.com/cloud/contact/dpo.

  2. HubSpot:

    The storage and processing of your data and personal information on HubSpot is subject to HubSpot’s Data Processing Agreement, which can be accessed from: https://legal.hubspot.com/dpa. In particular, the applicable security measures and controls are highlighted in Clause 4b of these terms, read with Appendix 2 (Technical and Organizational Security Measures).

Our company will keep your personal data for the duration of any legally binding agreement that you enter into with us in connection with our Services, and for such further duration as required in order to:

  1. Defend ourselves against any legal claims in connection with your use of our Services, and
  2. Raise any legal claims in connection with your use of our Services.

We hereby disclaim that the transmission of information via the internet is never completely secure. Although we will take all reasonable measures to protect your personal data, we cannot guarantee the security of your data during transmission, and any transmission is at your own risk. Once we have received your information, we will use reasonable security procedures and features to prevent unauthorised access.

The data that we collect from you will be processed by our Indian subsidiary, SANDC, which is situated outside the European Economic Area (“EEA”). It will also be processed by staff operating outside the EEA who are employed by us at SANDC. Such staff will be engaged in, among other things, the fulfilment or provision of our Services. By submitting your personal data, you agree to this processing. We will implement all reasonable safeguards to ensure that your data is treated securely and in accordance with this privacy policy, and we will comply with the GDPR and the DPA 2018 in respect of all such transfers.

We restrict access of your personal information to those employees of Spotlight and SANDC who have a business reason for knowing such information. We continuously educate and train our employees about the importance of confidentiality and privacy of customer information. We maintain physical, electronic and procedural safeguards that comply with the relevant laws and regulations to protect your personal information from unauthorised access.

6. Third parties who will access your data

THE DATA THAT WE COLLECT FROM YOU WILL BE PROCESSED BY OUR INDIAN SUBSIDIARY, SANDC, WHICH IS SITUATED OUTSIDE THE EUROPEAN ECONOMIC AREA (“EEA”). It will be processed by staff who are employed at SANDC. Such staff shall be engaged in, among other things, the fulfilment or provision of our Services. By submitting your personal data, you agree to this processing. We will implement all reasonable safeguards to ensure that your data is treated securely and in accordance with this privacy policy, and we will comply with the GDPR and the DPA 2018 in respect of all such transfers.

We will not disclose any personal information you submit via the Site to any of affiliates, agents, or contractors unless absolutely necessary to allow them to assist us in fulfilling requests for information, receiving and sending communications, updating marketing lists, analysing data, and providing support services from time to time. Our agents and contractors will only use your information to the extent necessary to perform their functions.

We will disclose aggregate statistics about visitors on our Site in order to describe our services to reputable third parties and for other lawful purposes, but these statistics will include no personally identifiable information.

In the event that we undergo re-organisation or are sold to a third party, you agree that any personal information we hold about you may be transferred to that re-organised entity or third party.

We may disclose your personal information if required to do so by law or if we believe that such action is necessary to prevent fraud or cyber-crime or to protect the Site or the rights, property or personal safety of any person.

7. Marketing

Our company would like to send you information about our products and services that we think you will find useful. If you have agreed to receive marketing communications, you may opt out at a later date. You have the right at any time to stop us from contact you for marketing purposes. If you no longer want to be contacted for marketing purposes, please send us an email at [email protected].

8. What are your data protection rights?

We would like to ensure that you are fully aware of all your data protection rights. Eery user is entitled to the following:

  1. The right to access:

    You have the right to access copies of your personal data held by us.

  2. The right to rectification:

    You have the right to request us to:

    • correct any information you believe is incorrect or out of date, and
    • complete any information that you believe is incomplete.
  3. The right to erasure:

    You have the right to request us to erase your personal data from our records when it is no longer necessary for its intended purpose, unless required to be stored by Spotlight under a contractual or statutory obligation, or to reasonably protect itself against any legal risk.

  4. The right to restrict processing:

    You have the right to request us to restrict the processing of your data, unless required to be stored by Spotlight under a contractual or statutory obligation, or to reasonably protect itself against any legal risk.

  5. The right to object to processing:

    You have the right to object to our processing of your personal data, unless required to be stored by Spotlight under a contractual or statutory obligation, or to reasonably protect itself against any legal risk.

  6. The right to portability:

    you have the right to request for a transfer of personal data we have collected directly to you, so that you may transfer that data to another organization.

If you make a request, we have one month to respond to you. If you would like to exercise any of these rights, please contact us at [email protected] with the subject line: “Re: Privacy Rights Enforcement Request | [Full Name], [Organization Name]”

9. How do we use cookies?

Please refer to our Cookies Policy by clicking here.

10. What types of cookies do we use?

Please refer to our Cookies Policy by clicking here.

11. How to manage cookies

Please refer to our Cookies Policy by clicking here.

12. Privacy policies of other websites

Our Site contains links to and from the Sites of our partner networks, affiliates, and existing/erstwhile customers. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility for them. Please check these policies before you submit any personal data to these websites.

13. Changes to our privacy policy

We keep our privacy policy under regular review and place any updates on this web page.

We reserve the right to periodically amend or revise this privacy policy. Any material changes will be effective immediately upon the display of the revised policy. The last revision will be reflected in the “Last modified” section. Your continued use of our Site and/or our Services, following the notification of such amendments on our Site, constitutes your acknowledgment of, and consent to, be bound by the amended privacy policy.

14. How to contact us

If you have any questions about our privacy policy, the data we hold about you, or if you wish to exercise one of your data protection rights, please do not hesitate to email us at: [email protected]