Protection of Personal Information
What personal information does ESP collect about me?
Information You Provide Directly
We collect the personal information you provide to us, for example:
Account Information: When you register for an account with ESP, we collect information that identifies you such as your name, username, email address and password.
Profile Information: We collect information that you voluntarily provide in your user profile; this may include your public avatar (which may be a photo), additional email addresses, company/organization name, job title, country, social media handles, and biography. Please note this information may be visible to other users of the Services and to the public depending on the privacy setting you apply.
Payment Information: If you purchase a paid subscription from ESP, we will collect payment information from you that may include your name, billing address and credit card or bank information.
Contact Information: If you request ESP to contact you, or sign up for marketing materials or events, ESP may collect information such as name, address, email address, telephone number, company name, and size of company.
Content you provide through the use of the Services: When you use the SaaS service, we collect and store content that you post, send, receive and share. Examples of content we collect and store include but are not limited to: the summary and description added to an issue, your repositories, commits, project contributions and comments. Content also includes any code, files and links you upload to the SaaS service.
If you are using our Self-managed product, we do not host, store, transmit, receive or collect information about you (including your content), except in limited cases, where permitted by your administrator. See the section on “Information about your use of the Services” for more details.
We may also collect other content that you submit to our Services. For example: feedback, comments and blog posts, or when you participate in any interactive features, surveys, contests, promotions, sweepstakes, activities or events.
Customer Support and Professional Services: If you contact ESP customer support or receive professional services, we will collect information about you related to your account and to the requests you are making or the services being provided.
Information About Your Use of the Services We Collect Automatically
Device Information and Identifiers: When you access and use our Services, we automatically collect information about your device, which may include: device type, your device operating system; browser type and version; language preference; IP address, cookie identifiers, hardware identifiers, and mobile IDs.
License Information: For our Self-managed products we may automatically collect information about the number of active users, historical user count, licensee name, email address, IP address and similar information.
Services Usage Data: ESP may also collect information about how you use our SaaS and Self-hosted products such as, activity data, feature usage, and product version data. This information may be aggregated or identifiable.
Services Usage Data
ESP collects information in order to help us understand how you use our products and services, so that we can improve and build better products and services. For information on what is collected and your options, please see below:
SaaS Nanoverse.Africa Software
ESP collects information about how you use the features and functionality of our SaaS service, such as the number of Items, staff, clients, bookings, sales, etc. We do not collect any information on the contents of your services. We automatically log information about how you interact with the application, such as the date and time of visit, and the feature and functionality you have clicked on or used. SaaS (Software as a Service)
Self-Managed ESP Evolve Software
ESP collects information about usage from each Self-managed ESP Evolve instances (Desktop Edition and Enterprise Edition) through Usage Ping. Usage Ping sends a payload containing data such as total number of items and sales, as well as license information, hardware and hostname and settings to ESP. Only aggregates of usage data is sent to ESP, we do not collect any information about what your sales contain. You can view the exact payload of the usage ping in the administration panel in ESP. To opt-out of Usage Ping, follow the instructions in the panel.
Website Usage Data: When you visit our Websites, we automatically log information about how you interact with the sites, such as the referring site, data and time of visit, and the pages you have viewed or links clicked on.
Email marketing: When we send you emails, they may include technology such as a web beacon, that tells us your device type, email client, and whether you have received and opened an email, or clicked on any links contained in the email.
Information from Third parties and Partners
We may also receive information about you from third parties such as vendors, resellers, partners, or affiliates. For example, we receive information from our resellers about you and your orders, or we may supplement the data we collect with demographic information licensed from third parties in order to personalize the Services and our offers to you.
Third Party sign-in services: ESP allows you to sign up for/in to our Services using third party accounts, such as Swarm, Paygate, Facebook or Google. When you give permission for this to happen, ESP will receive information about you from your third-party account, such as name, email address, location and demographic information.
When you are asked to provide personal data, you may decline. And you may use web browser or operating system controls to prevent certain types of automatic data collection. But if you choose not to provide or allow information that is necessary for certain products or features, those products or features may not be available or function correctly.
How is your personal information used?
ESP uses your personal information for the following purposes:
- To create your account, identify and authenticate your access to the Services and provide you with the Services you have requested;
- To process your payment for the Services you have purchased;
- To understand how our Services are used and to improve our Services;
- To provide personalized experiences;
- To conduct user research and development;
- To send you important information about the Services;
- To send you information you have requested;
- To send you advertising, marketing content, offers, promotions, newsletters, surveys or other information;
- To respond to your requests for customer support;
- To improve the security of and troubleshoot our Services, as necessary to perform the contract governing your use of our applications or to communicate with you;
- To detect, prevent, or otherwise address fraud and abuse to protect you, ESP, and third parties;
- To enforce the legal terms that govern our Services;
- To comply with our legal obligations;
- To protect the rights, safety and property of ESP, you, or any third party; and
- For other purposes, for which we obtain your consent.
Legal Basis for Processing of your information
If you are located in the African or European Economic Area, United Kingdom, or Switzerland, we collect and process your personal information on the following legal bases set out by applicable law:
Performance of a contract: We use your personal information to provide the Services you have subscribed to, and to complete and administer the contract you have entered into with ESP.
Legitimate Interests: We use your personal information for our legitimate interests, such as to provide you with relevant content, improve our products and services, and for administrative, security, fraud prevention and legal purposes. You may object to the processing of your personal information for these purposes at any time.
Consent: We may use your personal information, with your consent, for specific purposes such as marketing, surveys, and research. You may withdraw your consent for the specific purpose or object to the processing of your personal information at any time.
Who is your information shared with?
We may share each of the categories of personal information we collect with the types of third parties described below, for the following business purposes:
Sharing with Users and the Public: We may share your personal information with other users of the Services and with the public if you choose to make your SaaS Profile public or utilise ZESP. You have control over what information is public. To change your settings, go to user settings in your profile. You should also be aware that any information you share as part of these services a blog, website etc. may be publicly available and you should consider this carefully when interacting with the Services.
Sharing with Managed Accounts and Administrators: If you have created a ESP account with your corporate email address, we may share your personal information with your Company if your Company enters into a commercial relationship with ESP. If this happens, then your use of the software and your account is subject to the terms and any data protection agreement between your Company and ESP.
In addition, if you choose to become a member of an account or service area, your username, email address, IP address, the date when access was granted, the date when access expires, and your access role will be shared with the group owners of that account or service area.
Sharing with Service Providers: We share your personal information with our service providers. These are companies who provide services on our behalf, such as hosting our Services, marketing, advertising, social, analytics, support ticketing, credit card processing, security and other such similar services. These companies are subject to contractual requirements that govern the security and confidentiality of your information.
For example, we use analytics providers, such as Google Analytics, to help us understand the operation and performance of our Services. To learn about how Google uses and shares data it collects through its services, please visit https://www.google.com/policies/privacy/partners/.
Sharing with Partners and Resellers: ESP works with third parties who provide sales, consulting, support and technical services for our Services. Where permitted and with your consent (if required), we may share your data with these partners and resellers.
Sharing for Fraud and Prevention Abuse: We may share your information when we have a good faith belief that the disclosure is necessary to prevent fraud, abuse of our services, defend against attacks, and to protect the safety of ESP and our users.
Law Enforcement: ESP may disclose personal information or other information we collect about you to law enforcement if required in response to a valid subpoena, court order, a similar government order, or when we believe in good faith that disclosure is necessary to comply with our legal obligations, to protect our property or rights, or those of third parties or the public at large.
Merger or Acquisition: We may share your personal information if we are involved in a merger, sale, or acquisition of corporate entities or business units. If any such change of ownership happens, we will ensure that it is under terms that preserve the confidentiality of your personal information, and we will notify you on our website or by email before any transfer of your personal information.
Is your personal information transferred across national borders?
Our Services are hosted in the United States, Ireland, South Africa and information we collect will be stored and processed on our servers. Our employees, contractors, affiliated organizations and processors that process personal information may be located in South Africa or outside of your home country. If you reside in the European Economic Area, United Kingdom, or Switzerland, and we transfer information about you to a jurisdiction that has not been found by the European Commission to have adequate data protections, we will use available safeguards and legal mechanisms to help ensure your rights and protections, including using Standard Contractual Clauses or obtaining your consent.
We work hard to protect your personal information. We employ administrative, technical, and physical security controls where appropriate, to protect your information.
ESP will retain your information for as long as your account is active or as needed to perform our contractual obligations, provide you the Services, comply with legal obligations, resolve disputes, preserve legal rights, or enforce our agreements.
We may delete inactive accounts and associated projects and repositories after a period of eighteen (18) months.
Rights and Choices
You have the right to access, correct, restrict or delete your personal information, and to port your personal information to another company. While these rights may vary by jurisdiction, ESP provides you with the same rights and choices, no matter where you live.
You may exercise your choices and rights as follows:
To opt out of email marketing: You may opt-out of email marketing by clicking the “unsubscribe” link located at the bottom of any email you receive. You may continue to receive transactional email messages about your account and the Service after you have unsubscribed.
Request a copy of your information: You may request a copy of the personal information that ESP has about you from the information officer email@example.com with the subject line “Information Officer – Data Subject Request” these will be responded to in the appropriate time frame and detail the resolution process and period.
Update your Information: If you already have an account, you may access, update, or alter your user profile information by logging into your account and updating profile settings.
To delete your Account: You may delete your account by logging into your account and going to the “Delete my Account” option in your profile settings.
Please note that due to the open source nature of our Services, we may retain limited personal information indefinitely in order to provide a transactional history. For example, if you provide your information in connection with a blog post or comment, we may display that information even if you have deleted your account as we do not automatically delete community posts. Also, if you contribute to a public project (not owned by ESP), and you provide your personal information in connection with that contribution, your personal information will be embedded and publicly displayed with your contribution, and we will not be able to delete or erase it because doing so would break the project.
If you contribute to a ESP project by commenting in, or creating an issue or merge request and you provide your personal information in connection with that contribution, your personal information associated with your contribution will be deleted and attributed to a ghost user. However, please note that if the content of the contribution contains personal information, this information would remain and you will need to submit a specific request to have this information deleted.
South African Privacy Rights
Under the POPI Act you are entitled to certain rights such as access to your specific personal information, details about our processing of your personal information, and the right to delete your information. You may exercise all of these rights as described in the “Your Rights and Choices” section. ESP does not sell your personal information, as defined under POPIA.
You may designate, in writing or through a power of attorney, an authorized agent to make requests on your behalf to exercise your rights under the POPIA. Before accepting such a request from an agent, we will require the agent to provide proof you have authorized it to act on your behalf, and we may need you to verify your identity directly with us. To provide or delete specific pieces of personal information we will need to verify your identity to the degree of certainty required by law.
Information ESP Does Not Collect
ESP does not intentionally collect sensitive personal information, such as social security numbers, genetic data, health information, or religious information. Although ESP does not request or intentionally collect any sensitive personal information, we realize that users might store this kind of information in a ESP repository. If you are a child under the age of 13, you may not have an account. ESP does not knowingly collect information from, or direct any of our Services to, children under 13. If we learn or have reason to suspect that a user is under the age of 13, we will close the child’s account.
Your information is controlled by ESP cc. If you have questions or concerns about the way we are handling your information, please email us with the subject line “Privacy Concern” at firstname.lastname@example.org