LAST UPDATED: August 21, 2018
SmartBear Software, Inc. and its affiliates (collectively, “SmartBear”, “we”, “us”) is a global organization offering software tools used by developers, testers and operations team members to deliver high quality software and applications. We offer products for code review, API and UI development, testing, and operations and end user experience monitoring across desktop, web, mobile, Internet of things devices, and cloud platforms.
and any other SmartBear products and services (collectively, the “SmartBear Services” or “Services”).
Due to the global nature of the SmartBear Services, our privacy practices may vary among the states, countries and regions in which we operate in order to comply with applicable legal requirements.
1. Information We May Collect
The SmartBear Services gather certain information automatically, some of which may be considered personal information under applicable law.
We may collect, among other things, the following types of information:
- Address (including billing and shipping address)
- Telephone number
- Email address
- Fax number
- Professional information, such as employer or organizational affiliation for a customer or partner
- Payment or financial information for billing purposes
- Screen name
- Screen sharing views, at the request of customers, for support and QA purposes
- Any data in any files uploaded, emailed or otherwise provided by customers for support and QA
- Operating system type and version, web server type and version, php version, database type and version
- Unique IDs such as a cookie placed on a computer or mobile device, or device IDs
- IP address or MAC address, and information derived from an IP or MAC address, such as geographic location
- Browsing activities, cookies and similar data, and platform or mobile application use data
- Referring domain, destination domain and destination path
- Geolocational data, including latitudinal and longitudinal data
- User IDs and passwords for customers with accounts on the SmartBear Services
- Information about the performance, security, software configuration and availability of our software on your servers and network
- Website user statistics and website and portal use and viewing activity records
- Communication preferences
- Other similar information
We may also collect information, including personal information, in the following situations:
- Registration, purchase and use of the SmartBear Services: Information such as name, email address, telephone number, company/organization, financial information (such as credit card number, expiration date), and other information, may be collected in connection with registration for, purchase of or use of the SmartBear Services (for example, to sign-up for and log into the SmartBear Services). Customers may update their information by logging into their account. Information may also be collected to track license use.
- Communications: Personal information such as name, email address, and other information, may be collected, when provided in any communications, whether via email, social media, telephone or otherwise.
- Support: Personal information may be collected in connection with customer support, whether via screensharing, email, social media, telephone or otherwise.
- Surveys, Research and Analytics: We may collect personal information from anyone participating in research and surveys, as well as for analytics purposes.
2. Use of Information
SmartBear Solutions may use the information, including personal information, collected in connection with the SmartBear Services for the purpose of providing the Services to our customers, as well as for supporting our business functions, such as fraud prevention, marketing, analytics and legal functions and other legitimate purposes.
To the extent permitted by applicable law and, for customer data, as permitted by our customer agreements, we may use information collected in connection with our Services:
- To operate the SmartBear Services and provide support.
- To fulfill customer requests, such as to create a SmartBear Services account or complete customer purchases.
- To communicate with our customers; to inform customers and users of products, programs, services and promotions.
- To send customers information regarding the SmartBear Services and issues specifically affecting SmartBear Services.
- To respond to reviews, comments, or other feedback provided to us.
- To support and personalize our Services, websites, mobile services, and advertising.
- To protect the security and integrity of our Services, content, and our business.
- To provide support.
- For benchmarking, data analysis, audits, developing new products, enhancing the SmartBear Services, facilitating product, software and applications development, improving our services, conducting research, analysis, studies or surveys, identifying usage trends, as well as for other analytics purposes.
- To meet our contractual requirements, to comply with applicable legal or regulatory requirements and our policies, and to protect against criminal activity, claims and other liabilities.
- For any other lawful purpose for which the information is provided.
Aggregate Information. To the extent permitted by applicable law, we may use, process, transfer, and store any data about individuals and customers or partners in an anonymous (or pseudonymous) and aggregated manner. We may combine personal information with other information, collected online and offline, including information from third party sources. We may also use information in other ways with consent or as permitted by applicable law. By using the SmartBear Services, our customers agree that we are hereby licensed to collect, use, share and store anonymized (or pseudonymized) aggregated data collected through the SmartBear Services for benchmarking, analytics, A/B testing, metrics, research, reporting, machine learning and other business purposes.
Automated Decisions. To the extent permitted by applicable law, we may collect data in an automated manner and make automated decisions, including using machine learning algorithms, about individual users of the SmartBear Services in order to provide or optimize the SmartBear Services offered and/or delivered, for security or analytics purposes, and for any other lawful purpose. To the extent permitted by applicable law, we may use automated decisions, for example, to display advertisements and offers based on the individual’s preferences.
3. Sharing of Information
To the extent permitted by applicable law, SmartBear may share and disclose information, including personal information, as set forth below:
- Customers. We may share information with our customers and their service providers and other platforms that may assist those customers.
- Affiliates and Agents. We may share information with our affiliates or any business partners or agents acting on our behalf.
- Service Providers. We may share information with our service providers, agents, vendors and other third parties we use to support and advertise the SmartBear Services and our business. We share personal information with such third parties to the extent necessary to provide services to us, and pursuant to binding contractual obligations.
- Advertising and Marketing. To the extent permitted by applicable law, we may share information with third parties for marketing, advertising, promotions, contests, or other similar purposes. If required by applicable law, we will share such data for advertising and marketing purposes only in an aggregate, anonymous, and de-identified manner.
- Mergers, Acquisitions, Divestitures. We may share, disclose or transfer information to a buyer, investor, new affiliate, or other successor in the event SmartBear, or any affiliate, portion, group or business unit thereof, undergoes a business transition, such as a merger, acquisition, consolidation, reorganization, divestiture, liquidation or dissolution (including bankruptcy), or a sale or other transfer of all or a portion of any assets of SmartBear or any affiliates or during steps in contemplation of such activities (e.g., negotiations and due diligence).
- Law Enforcement and National Security. We may share information with legal, governmental, or judicial authorities, as instructed or required by those authorities or applicable laws, or to comply with any law or directive, judicial or administrative order, legal process or investigation, warrant, subpoena, government request, regulatory request, law enforcement or national security investigation, or as otherwise required or authorized by law.
- Protection of Rights, Property or Safety. We may also share information if, in our sole discretion, we believe disclosure is necessary or appropriate to protect the rights, property or safety of any person, or if we suspect fraud or other illegal activity,
SmartBear may also disclose personal information for other purposes or to other third parties when an individual has consented to or requested such disclosure, or where a customer has obtained permission from such individual, or where such disclosure is otherwise legally permitted for legitimate business purposes, and, for customer data, with such customer’s authorization or otherwise in accordance with SmartBear’s agreement with such customer.
4. Cookies and Similar Technologies
We may use the following types of cookies and similar technologies:
- Strictly necessary cookies required for the operation of the SmartBear Services. They include, for example, cookies that enable you to log into secure areas.
- Analytical/performance cookies that collect information about how you use the SmartBear Services. They allow us to recognize and count the number of visitors and to see how visitors move around our website. This helps us to improve the way our website works. These cookies are sometimes placed by third party providers of web traffic analysis services.
- Functionality cookies that remember choices you make and recognize you when you return. This enables us to personalize our content, greet you by name and remember your preferences (for example, your choice of language or region).
- Targeting cookies that collect information about your browsing habits such as the pages you have visited and the links you have followed. We use this information to make our website more relevant to your interests, and, if we enable advertising, to make advertising more relevant to you, as well as to limit the number of times you see an ad. These cookies are usually placed by third-party advertising networks. They remember the other websites that you visit and this information is shared with third-party organizations, for example, advertisers.
Most internet browsers accept cookies by default. You can block cookies by activating the setting on your browser that allows you to reject all or some cookies. The help and support area on your internet browser should have instructions on how to block or delete cookies. Some web browsers (including some mobile web browsers) provide settings that allow you to control or reject cookies or to alert you to when a cookie is placed on your computer, tablet or mobile device. Although you are not required to accept cookies, if you block or reject them, you may not have access to all of the features available through the SmartBear Services.
For more information, visit the help page for your web browser or see http://www.allaboutcookies.org or visit www.youronlinechoices.com which has further information about behavioral advertising and online privacy.
We may use third party analytics such as Google Analytics or similar analytics services. For information on how Google processes and collects your information regarding Google Analytics and how you can opt-out, please see https://tools.google.com/dlpage/gaoptout.
5. Data Retention
To the extent permitted by applicable law, we may retain information for as long as the account of the customer for whom we collected the information is active, for at least twenty-four (24) months thereafter, or as long as is reasonably necessary to provide the SmartBear Services or as needed for other lawful purposes. We may retain cached or archived copies of information. We may retain anonymized or pseudonymized, aggregated data indefinitely, to the extent permitted under applicable law. We may be required to retain some data for a longer period of time because of various laws and regulations or because of contractual obligations. We also will retain information as long as reasonably necessary to comply with our legal obligations, resolve disputes and enforce our agreements.
6. Choices and Opt-Out
To the extent required by applicable law, or in our discretion otherwise, we will allow customers and individuals to limit use of personal information. If at any time after providing us with your personal information such information changes or you change your mind about receiving information from us, you may request access to your data or that your data be changed.
If you no longer wish to receive our communications, you may opt-out of receiving them at any time by following the instructions included in each communication, by going to our Unsubscribe Page, or by mail at 450 Artisan Way, Somerville, MA, 02145 USA; Attn: General Counsel, Legal Dept.
If you no longer wish to receive HipTest communications, you may opt-out of receiving them at any time by following the instructions included at the bottom of the HipTest email communications, by emailing Privacy@SmartBear.com and requesting to be unsubscribed, or by mail at 450 Artisan Way, Somerville, MA 02145 USA; Attn: General Counsel, Legal Dept.
7. Cross-Device Tracking
When you use your mobile device to interact with us or use the SmartBear Services, we may receive information about your mobile device, including a unique identifier for your device. We and our service providers and third parties we collaborate with, including ad networks, may use cross-device/cross-context tracking. For example, you might use multiple browsers on a single device, or use various devices (such as desktops, smartphones, and tablets), which can result in your having multiple accounts or profiles across these various contexts and devices. Cross-device/cross-context technology may be used to connect these various accounts or profiles and the corresponding data from the different contexts and devices.
8. Employment Opportunities
We provide you with a means for submitting your resume or other personal information through our website or Services for consideration for employment opportunities at SmartBear. Personal information received through resume submissions will be kept confidential. We may contact you for additional information to supplement your resume, and we may use your personal information within SmartBear, or keep it on file for future use, as we make our hiring decisions.
9. Third Party Sites
To prevent unauthorized access or disclosure, to maintain data accuracy, and to ensure the appropriate use of data, we employ procedural and technological measures that are reasonably designed to help safeguard the information we collect. SmartBear may use encryption, secure socket layer, firewall, password protection and other physical security measures to help prevent unauthorized access to such. SmartBear may also place internal restrictions on who in the company may access data to help prevent unauthorized access to such information.
Unfortunately, no data transmission over the Internet or data storage system can be guaranteed to be 100% secure. Therefore, despite our efforts, we cannot guarantee its absolute security. We do not warrant or represent that personal information about you will be protected against, loss, misuse, or alteration by third parties.
Where required under applicable law or by contract, we will notify the appropriate parties or individuals of any loss, misuse or alteration of personal information so that such parties or individuals can take the appropriate actions for the due protection of their rights. If such personal information is information of a SmartBear customer, we will notify such customer and coordinate with them regarding any required notices to particular individuals.
We recognize the importance of protecting the privacy and safety of children. The SmartBear Services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. Anyone under 16 should not use the SmartBear Services. If we learn we have collected or received personal information from a child under 16 without verification of parental consent, we will delete that information. If you believe we might have any information from or about a child under 16, please contact us as set forth below.
12. International Data Transfers
The SmartBear Services may be provided using resources and servers located in various countries around the world, including the United States and other countries. Therefore, personal information about individuals or customers may be transferred, processed and stored outside the country where the SmartBear Services are used, including to countries outside the European Union (“EU”), European Economic Area (“EEA”) or Switzerland, where the level of data protection may not be deemed adequate by the European Commission.
Canadian residents may have additional rights under Canadian law. Please see the information provided by the Office of the Privacy Commissioner of Canada for additional details. You, and we, confirm that it is our wish that this document and all other related documents be drawn up in English. Vous reconnaissent avoir exigé la rédaction en anglais du présent document ainsi que tous les documents qui s'y rattachent.
13. California Privacy Rights
Under California’s “Shine the Light” law, California residents who provide personal information in obtaining products or services for personal, family or household use may be entitled to request and obtain from us, once per calendar year, information about customer information we have shared, if any, with other businesses for such other businesses’ own direct marketing uses. If applicable, this information would include the categories of resident information and the names and addresses of those businesses with which we shared such resident information for the immediately prior calendar year. To obtain this information, please contact us as indicated below. Please include sufficient personal identification information so that we can process the request, including that you are a California resident.
14. Questions, Complaints and Disputes
Attn: General Counsel, Legal Dept.
450 Artisan Way
Somerville, MA 02145
Phone: +1 (617) 684-2600
CLASS ACTION WAIVER. YOU AND WE AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN YOUR OR OUR INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING.
“Personal Data” means any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of such natural person; and
“Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
EU-U.S. and Swiss-U.S. Privacy Shield Notice. We have certified our compliance with the EU-U.S. and Swiss-U.S. Privacy Shield with regards to the Personal Data of users of the SmartBear Services who are residents of the European Union (“EU”), European Economic Area (“EEA”) and Switzerland that we receive and process through the SmartBear Services. We certify that we adhere to the Privacy Shield Principles of notice, choice, onward transfer, security, data integrity, access, liability, and enforcement (“Privacy Shield Principles”) for Personal Data of users of the SmartBear Services in the countries participating in the EU-U.S. and Swiss-U.S. Privacy Shield Frameworks. Our certification is available here. We may also process Personal Data submitted relating to individuals in Europe via other compliance mechanisms, including use of the European Union Standard Contractual Clauses or Binding Corporate Rules. We are responsible for the processing of Personal Data we receive under the Privacy Shield Framework and subsequently transfer to a third-party agent, and may be liable for onward transfers in violation of the Privacy Shield Principles.
Our legal bases for the processing of Personal Data are: (i) consent or (ii) any other applicable legal bases, such as our legitimate interest in engaging in commerce, offering products and services of value to the customers of the SmartBear Services, preventing fraud, ensuring information and network security, direct marketing and advertising, and complying with industry practices.
Additional Rights for European Residents. As a resident of the EU or a country following substantially similar legislation regarding the protection of Personal Data, individuals may have one or more of the following additional rights:
Access. To request a copy of the Personal Data we have collected about you by contacting us.
Rectification & Erasure. To request that we rectify or delete any of the Personal Data about you that is incomplete, incorrect, unnecessary or outdated.
Objection. To object, at any time, to Personal Data about you being Processed for direct marketing purposes.
Restriction of Processing. To request restriction of Processing of Personal Data about you for certain reasons, such as, for example, if you consider Personal Data about you collected by us to be inaccurate or you have objected to the Processing and the existence of legitimate grounds for Processing is still under consideration.
Data Portability. To request and receive the Personal Data we have collected about you in a commonly used and machine-readable form.
Right to Withdraw Consent. If Personal Data about you is processed solely based on your consent and not for any other legitimate interest, to withdraw your consent at any time, without affecting the lawfulness of our Processing based on such consent before it was withdrawn, including processing related to existing contracts for our products and services.
Right to Lodge a Complaint with a DPA. If you believe our Processing of Personal Data about you is inconsistent with the applicable data protection laws, to lodge a complaint with your local supervisory data protection authority (“DPA”).
To exercise any of the above listed rights, please contact us as set forth below and provide sufficient details so that we can respond appropriately. We will process any requests in accordance with applicable law and within a reasonable period of time. We may need to verify the identity of the individual submitting a request before we can address such request. If the request relates to data our customers collect and process through the SmartBear Services, we will refer the request to that customer and will support them in responding to the request. For SmartBear customers, certain information may be reviewed, corrected and updated by logging into the SmartBear Services account and editing the profile information.
Questions and Complaints. In compliance with the Privacy Shield Principles, SmartBear commits to resolve complaints about our collection or use of your Personal Data. Residents of a country participating in the Privacy Shield Framework may direct any questions or complaints concerning our Privacy Shield compliance to our Privacy Shield and Data Protection Contact. We will work with you to resolve your issue.
If we have not responded to a concern relating to data processed under the Privacy Shield Framework in a timely manner, or we have not addressed the concern satisfactorily, you may contact our U.S.-based dispute resolution provider, at no cost, at https://www.jamsadr.com/file-an-eu-us-privacy-shield-or-safe-harbor-claim. If neither SmartBear nor our independent dispute resolution provider resolve your complaint, you may have the possibility to invoke binding arbitration through the Privacy Shield Panel. However, prior to initiating such arbitration, a resident of a country participating in the Privacy Shield Framework must first: (1) contact us and afford us the opportunity to resolve the issue; (2) seek assistance from our designated independent dispute resolution provider; and (3) contact the U.S. Department of Commerce (either directly or through a European DPA) and afford the Department of Commerce time to attempt to resolve the issue. If such a resident invokes binding arbitration, each party shall be responsible for its own attorney’s fees. Pursuant to the Privacy Shield, the arbitrator(s) may only impose individual-specific, non-monetary, equitable relief necessary to remedy any violation of the Privacy Shield Principles with respect to the resident.
U.S. Federal Trade Commission Enforcement. SmartBear’s commitments under the Privacy Shield are subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
Compelled Disclosures. SmartBear may be required to disclose Personal Data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Privacy Shield and Data Protection Contact. Unless otherwise specified, the data controller of personal data uploaded to the SmartBear Services is the SmartBear customer for whom such Services are provided and SmartBear is the processor of such data for such customer. In certain cases, SmartBear may also be the controller of aggregated, anonymous or pseudonymous data relating to the SmartBear Services. Our Privacy Shield and Data Protection Contact for the personal information collected in connection with the SmartBear Services is:
Attn: General Counsel, Legal Dept.
SmartBear Software Inc.
450 Artisan Way
Somerville, MA 02145
Phone: +1 (617) 684-2600