HERITAGE IT PTY LTD - PRIVACY POLICY

Last Update: 16 June 2020

Heritage IT Pty Ltd., and its subsidiaries that make up the Heritage IT group of companies (collectively "HIT," “we,” “us” and “our”), is a leading developer, publisher and marketer of business integration and reporting software. This Privacy Policy explains our data practices for the products, services, and websites (collectively the "Services") that we offer to consumers.

When we say “personal data” we mean identifiable information about you, such as you name, email, and payment details. If you can not be identified, for instance when personal data is aggregated and anonymised, then this policy does not apply.

Scope of this Policy and Who We Are

This Privacy Policy applies to all divisions and labels that are part of HIT. Please read this Privacy Policy carefully. The Services also are subject to our Limited Software Warranty and License Agreement (“EULA”), Terms of Trade, and any other policies included in our Services. This Privacy Policy supplements privacy disclosures provided with your software product.

This Privacy Policy does not apply to personal information collected from job applicants.

Information We Collect and Our Lawful Bases for Processing

You provide us with information directly, such as when you set up an account with us. We also collect information about you and your activity when you use our Services – whether through computers, mobile devices, software platforms, third party social networks. We may use online tracking, such as cookies and similar technology, to collect information, when you connect to our Services, and we collect information from third parties (such as advertising networks and external business partners).

The types of information that we collect depend on how you use the Services and interact with us. You can control the personal information we collect from you unless we need it for the requested activity (e.g., to provide the Services you’ve requested or purchased, to confirm who you are, or to participate in an event). We will let you know when information is necessary.

Information You Provide

You provide us with information when you use the Services, such as when you:

  • create an account, or register for or use the Services;
  • subscribe to newsletters and communications;
  • comment on our message boards, forums, chat rooms, feeds, sites, or other Services;
  • purchase or redeem one of our products or services, including physical items;
  • download, install, or access demos, programs, or other software;
  • contact us for support or other purposes;
  • use our email / share features;
  • participate in events, contests, promotions, or surveys; or
  • participate in an activity where you can provide, or need to provide, your information.

Depending on the Service or your activity, we collect information such as your name, email address, phone number, photo, mailing address / post code, payment or purchase information, hardware configuration, software products used, survey data, IP address, geolocation, and the systems you work on. We combine this information across computers or other devices that you use.

Activity Information

When you use the Services on hardware connected to the Internet, HIT receives information about your work activity even if you are not specifically notified at the time or do not take any actions to actively give us this information. Activity information includes your IP address, MAC address or other device ID, other device information, and other information and statistics regarding your Service use.

Information from Third Parties

We receive information from third parties to update the information that we collect about you. For example, we receive information from public databases, analytics providers, software developers, and other business partners that includes demographic information and information about your interests. We obtain information from social media and other publicly available sources, which we may use to better understand our users or to seek intelligence about breaches of our Terms of Trade. We also receive information from other individuals who use our Services. This may include information about you if you are mentioned in comments on our message boards, forums, chat rooms, or other Services, or an individual sends us a direct message, for example, about an alleged breach of our Terms of Trade.

Lawful Basis to Process in Certain Locations

We collect, use, and otherwise process your information when we have a lawful basis, as follows:

  • Consent: We ask you for consent to collect or use your personal information for specific purposes, such as when we want to send you emails about special offers or competitions, or if you decide to link your HIT account with a third-party service.
  • Contract Performance: We process your personal information when we need to perform and manage a contract with you, such as our Terms of Trade, or to take steps at your request before we contract with you, such as to complete transactions with you.
  • Legal Requirement: We process your personal information when required by law.
  • Legitimate Interest: We process your personal information when necessary for our, or others', legitimate interests and when these interests do not outweigh your own rights and interests. This covers processing for purposes such as improving our products and services; performing analytics and using surveys to better understand our users; conducting direct marketing (when we do not need your consent); otherwise supporting our business, operations, and services; ensuring the proper function, security, and integrity of our services; dealing with user questions; enforcing our Terms of Trade and EULA; preventing fraud; preventing illegal activity; preventing violations of our EULA, Terms of Trade, Code of Conduct, or other policies; and preventing intellectual property right infringement.

Cookies and Similar Technology

Cookies are very small text files that companies place on your device when you visit or use some sites, applications, or other web-based services to help identify a computer, browser, or device. We use cookies, web beacons, Internet log files, and similar tracking technologies (ours and from third-party providers) to allow our Services to function; maintain your preferences and settings; provide enhanced features; analyse how users use our Services; combat fraud; prevent violations of our EULA and policies; and to provide you with targeted advertising based on your interests. If you choose to provide us with information, it may be linked to the information collected by cookies and similar technologies including advertising cookies. Our system may not respond to Do Not Track requests or headers from some or all browsers. The Manage Your Account, Communications, and Data section below provides additional information about our use of cookies and similar technologies and your ability to manage cookies You may also use the cookie preference tool, where available, or visit the cookie policy posted on the Service for more information.

  • Cookies: Cookies are used to identify a computer, browser, or device. Certain cookies are necessary for the Services to function and others let us to provide you with an enhanced experience. You can disable cookies on your device or set your browser to alert you when we or others send cookies to your device but disabling cookies may affect your ability to use certain Services. For more information, including details of specific cookies we use, applicable for the Service, see the cookie preference tool or visit the cookie policy posted on the Service you are visiting. You can find more information and make choices about third-party cookie providers in the following sections of this Privacy Policy: When We Share Information, Advertising and Manage Your Account, Communications, and Data.
  • Flash Cookies: We may use flash cookies, also known as "local shared objects." You can clear flash cookies already on your device by adjusting the flash local storage setting on your device to zero. You may also prevent entities from placing flash cookies on your device by adjusting your preferences in your browser settings.
  • Web Beacons: A web beacon is an electronic image or tag that helps us deliver cookies, count users who have visited certain pages or viewed certain advertisements or mailings, and conduct analytics for our Services and communications.
  • Internet Log Files: We may collect Internet log files when you use the Services. These log files can include IP addresses, MAC addresses or other device IDs, depending on your network configuration. Depending on the Service you use or the activity you engage in, we associate these log files with your information.

How We Use Information

We use the information we collect from and about you within HIT for a variety of business purposes including to: provide the Services; fulfil orders and requests; analyse and improve our Services and our business; communicate with you; respond to questions or technical problems; develop internal marketing and demographic studies; provide support and security for our products.

We also use your information within HIT for commercial purposes, including: send you and similar consumers direct marketing and online / social media advertising from HIT and our business partners, including use of demographic information; for other purposes identified when you provide your information; or otherwise with your permission. We may further use your information as permitted by law.

Sales, Promotional Offers, Coupons and Pricing: Sales, promotions and other special discounted pricing offers are temporary and, upon the renewal of your subscription, any such discounted pricing offers may expire. We reserve the right to discontinue or modify any coupons, credits, sales and special promotional offers in our sole discretion.

We use information we collect from and about you for business purposes including to:

  • Provide the Services;
  • Fulfil product orders and other requests, respond to your questions, and communicate with you;
  • Enhance your experience on the Services, including to recognize you, maintain your preferences and settings, and link to your third-party systems, and social networking platforms;
  • Provide technical and other support;
  • Review the use and operations of the Services, develop new products or services, and conduct analyses to enhance or improve our software, content, internal marketing, support, and Services;
  • Conduct internal marketing and demographic studies;
  • Analyse our users, in combination with other data, to assess our user base and target marketing at other similar groups;
  • Address issues with the Services or other business needs;
  • To protect the security or integrity of the Services and our business such as by protecting against and preventing violation of our EULA and policies, including combating fraud, piracy, cheating, tampering, unauthorized transactions, claims, and other liabilities, and managing risk exposure; and
  • Interact on your behalf with the third-party systems and social networking platforms you connect with our Services.

We use information we collect from and about you for commercial purposes, including to:

  • Provide you and other users like you with customized content on the Services, targeted offers and advertising on the Services, via email and text message, or on other sites, mobile applications, or social media on behalf of HIT or our business partners; and
  • Contact you with information, newsletters, and promotional material.

We also use information we collect from and about you to:

  • Participate in other processing that we inform you about when you provide your information or when you consent to such processing; and
  • As permitted by law.

If you breach our Terms of Trade or other applicable policies, we may temporarily or permanently exclude you from the Services.

When We Share Information

As detailed in this Privacy Policy, we share your information with our vendors that perform support and other services in connection with the Services; advertising service providers and advertising partners that enable us to conduct and display advertising on the Services and third-party sites, mobile applications, or social media services; and with third parties for collaborative offerings, legal and safety purposes, in connection with the sale or transfer of a business or asset, for use in aggregate or anonymous form, and for other purposes with your permission.

  • Vendors: We use vendors to perform services on our behalf. These vendors provide business, professional or technical support to us, help us operate our business and Services, or administer activities in connection with our business and the Services on our behalf. These vendors are not permitted to use or share your personal information for their own or a third party’s commercial purpose.
  • Advertising: We use HIT and third-party advertising to support our Services, such as ad networks, data exchanges, traffic management service providers, social networks and marketing analytics service providers. These providers use cookies and similar tracking technology (see Cookies and Similar Technology above) to collect information about your device and your Service use. This information, along with information that we share with them, enables us or our providers to recognize you or your device and to serve ads to you or your device. This includes, as relevant, your device type; IP address; MAC address or other device ID; a secured (hashed) version of an email address you have provided to us; IDFA, Android ID, or other advertising ID; browser type and version, character set, screen size and colour; language; operating system and version; font packages installed; geographic location; types of pages, content and ads viewed on the device; frequency of and time spent during your visit; and information about your use of a site or Service (e.g., whether you make a purchase).
    We (and sometimes our providers) collect or share this information when you use our Services, click on a site or an ad, or other mobile applications. This information: (1) allows us to accurately and properly pay for ads placed on our behalf (e.g., an ad that led you to purchase one of our services) and get paid when you see an ad on our Services; (2) helps prevent you from repeatedly seeing the same ads; (3) helps select and display targeted ads or other content on your computer or device (such as on a site or social networking service you are visiting or a mobile application you are using) that may be of particular interest to you; (4) helps with measuring and analysing the effectiveness of our ads, popularity of content, and traffic in our Services; and (5) helps us improve our Services.
    You can learn more about managing how we and our providers use your information in the Manage Your Account, Communications, and Data section below; and, as applicable for the Service, by using our cookie preference tool, where available, or visiting the cookie policy posted on the Service.
  • Third Parties: We share your information with third parties as described in this Privacy Policy, including as follows:
    • Collaborative Relationships: When we offer services or promotions in collaboration with a third party who will receive your information for its own use, we will inform you of that at the time of collection and you may choose whether to participate in the offering.
    • Legal & Safety: We may share your information to protect the security of our Services, servers, network systems, databases, and business and in connection with an investigation of fraud, intellectual property infringements, interference with our rights, property or users, or other activity that is illegal or may expose you or us to legal liability, including as required or requested by law enforcement or other government officials. We also may share your information with third parties when we have reason to believe that a disclosure is necessary to address potential or actual injury or interference with our rights, property, operations, users, or others who may be harmed or may suffer loss or damage, or when we believe that it is necessary to protect our rights, investigate, or enforce our policies, terms, combat fraud, or comply with a judicial proceeding, court order, or legal process served on HIT. We also may share your information when we have reason to believe it is necessary to investigate or enforce our policies, terms, or other legal document or contract related to the Services or rights of a third-party.
    • Sale or Transfer of Business or Assets: We may sell or purchase assets during the normal course of our business. We may disclose information about you and transfer that information to another entity as part of a potential or actual acquisition or merger of HIT or any of our assets. If we bring or are defending a reorganization, bankruptcy, or similar event, such information may be considered our asset and sold or transferred to third parties.
    • Aggregate or Anonymous Information: We may share aggregate or anonymise information with third parties for their marketing or analytics uses. This information cannot be used to identify you.
    • As Disclosed to You: We may share your information as disclosed to you at the time of collection.

Manage Your Account, Communications, and Data

We provide several options for you to manage your Service account, communications you receive from us, and how we use your information. These include through the settings in your Client account; utilizing email unsubscribe and deletion tools; opting out of interest-based ads; and, depending on your location, making a data request or exercising your right to object to our use of your personal information. This can include, in some countries, a right to object to our use of your data. If you do not have a Client account and wish to contact us please email our administration team at admin@heritageit.com.au. Additional information about California user rights are available in the the California Privacy Rights section below.

California Privacy Rights

This section provides information for California residents. HIT may require proof of California residency before responding to requests made under this section.

Categories of Information Collected

This section describes the types of personal information that HIT collects, uses, discloses, and may sell (as described more fully below). We discuss the business and commercial purposes for collecting this information in the How We Use Information section above. We categorize this personal information as follows:

  • Identifiers/Contact Information: Identifiers, including your real name, postal and email address, phone number, unique identifiers, location information, characteristics of protected classifications under California or United States of America federal law, and IP address.
  • Commercial Information: Your purchase and usage history and preferences.
  • Internet/Electronic Activity: Your web/app browsing information related to the Services and information related to your online interaction(s) with the Services or our advertising.
  • Profile Inferences: The inferences that we draw from your information and web activity to help create a personalized profile so we can better identify goods and services that may be of interest.
Your Rights

To make an access or deletion request, please contact the applicable label as identified in the Manage Your Account, Communications, and Data section above. We may take steps to verify your identity before we can respond to your request.

Access Request: You may make up to two requests per year for information as to:

  • The categories of personal information that we’ve collected and sold about you, or shared for a business or commercial purpose with our service providers;
  • The sources from which we’ve collected such personal information;
    • The third parties with whom we’ve shared that personal information and to whom we’ve sold that information;
    • The business or commercial purpose for collecting or selling that personal information; and
    • The specific pieces of personal information we’ve collected about you.

Deletion Request: You may request that we delete the personal information that we’ve collected from or about you, although there are some reasons we will need to retain information, such as to complete a transaction for you, to detect and protect against fraudulent and illegal activity, to maintain for internal purposes, to comply with a legal obligation, or to exercise our rights.

We will respond to your access and deletion requests within 45 days, unless we require additional time, in which case we will let you know.

Opt-Out Request: You have the right to opt out of HIT’s sale of your personal information to third parties for their commercial purposes. This means that if you opt out, going forward, we will not share your personal information with such third parties to use for such purposes unless you later direct us to do so.

To opt out of online personalized advertising, please see the opt-out options identified in the Manage Your Account, Communications, and Data section above.

Data Retention

We retain your information while your account is active, as needed to provide you Services, or to administer our Services. If you wish to cancel your account or request that we no longer use your personal information to provide Services to you, contact us as identified in the Manage Your Account, Communications, and Data section above. If your account is inactive, we will maintain your account for the length of time for which we reasonably expect you to reengage with our Services. After such period, we will delete personal information, including your email address and log-in credentials, and you may no longer be able to access your account. We will notify you before we delete your account information so that you have the opportunity to keep your account active. We may still retain some of your personal information in our files for a reasonable period of time to resolve disputes, enforce our EULA or Terms of Trade, administer our services, comply with technical and legal requirements, and/or other constraints related to the security, integrity, and operation of our Services, after which we will take steps to delete or archive your personal information

Data Security

We follow generally accepted industry standards and maintain appropriate safeguards to help protect the security, integrity, and privacy of the information we collect about you. These security measures are designed to protect against the accidental or unlawful destruction, loss, misuse, alteration, and unauthorized disclosure of, or access to, the information under our control. However, no system can be 100% secure and we cannot guarantee our security measures.

International Transfers

We and our vendors may process, transfer, and store information about you in connection with the Services in Australia, the United States of America, and other countries that may not have data protection laws equivalent to the country where you reside. We take steps to apply appropriate safeguards when we transfer that information.

When your information is in another country, it may be accessed by the courts, law enforcement, and national security authorities pursuant to the laws of that country. If you reside in the UK, EU, EEA or Switzerland, we rely on Standard Contractual Clauses and/or other approved legal mechanisms to transfer personal information from the UK, EU, EEA or Switzerland to countries located outside of these locations (as applicable). To request a copy of such Standard Contractual Clauses, if applicable, please make a data request as provided under the Manage Your Account, Communications, and Data section above.

Other HIT Terms, Third-Party Terms, and Links to Other Sites

Use of our services and products may be subject to other terms and disclosures provided by us, software vendors such as Intuit or Sage, and other partners, including: (i) the EULA that accompanied your purchase or subscription; (ii) our Terms of Trade; (iii) other terms and disclosures made available to you by us or third parties. We are not responsible for practices on third-party sites that may be linked to the Services.

Third-Party Services If you connect to us through third-party services such as mobile device, social networking platforms, that third-party’s terms of service and privacy policy govern your use of that service. We are not responsible for third-party services.

Third-Party Sites Our Services may direct you to third-party sites. If we link to another site, it is not an endorsement, authorization, or representation of our affiliation with that third party. We recommend that you read the privacy policy of the other site before you submit any of your personal information to that site.

Public Postings

If you share personal information, post an image or video, or provide other content in public forums such as on a message board, chat room, comment field, or profile page, other people can view, collect, and use that information. If your username or ID contains your real name, then you acknowledge that your name will be made publicly available as described in this Privacy Policy. Users of such public forums may be able to identify you, use the information to send you messages, or copy any of the images, video or content you have shared. There is no expectation of privacy or confidentiality on any of these public forums. You are strongly encouraged not to share your personal information in public forums or in your username or ID. You are responsible for any information or content you publicly post using our Services.

Contact Us

If you have questions or concerns about this Privacy Policy or our practices, contact our Privacy Policy Administrator via email at admin@heritageit.com.au; or by postal mail at Heritage IT Pty Ltd, PO Box 1344, MILTON QLD 4064, AUSTRALIA. We do not respond to support requests or other non-privacy related correspondence at this point of contact.

Changes to Privacy Policy

We reserve the right to make changes to this Privacy Policy. Please check back from time to time to ensure that you are aware of these changes. If we change this Privacy Policy in a material way, we will provide appropriate notice to you and, as appropriate, provide additional choices regarding such change. As permitted by applicable law, your continued use of the Services means that you accept these changes.