Userpace obtains Personal Data about you from various sources to provide our Services and to manage our Sites. "You" may be a visitor to one of our websites, a user of one or more of our Services ("User" or "Userpace User"), or a customer of a User ("Customer").
If you are a Customer, Userpace will generally not collect your Personal Data directly from you.
We provide in-depth details in our Data Processor Privacy section.
Personal Data that we collect about you.
Personal Data is any information that relates to an identified or identifiable individual. The Personal information we collect and provided to us directly through our services will always be (made) apparent from the context in which you provide the data. In particular:
Upon SignupWhen you register for a Userpace account we collect your full name, email address, and account log-in credentials.
Online FormWhen you fill-in our online form to contact our support or sales team, we collect your full name, work email, country, and anything else you tell us about your project, needs and timeline.
Emails and SurveyWhen you respond to Userpace emails or surveys we collect your email address, name and any other information you choose to include in the body of your email or responses.
Phone CallIf you contact us by phone, we will collect the phone number you use to call Userpace and may collect additional information in order to verify your identity.
If you are a Userpace User, as part of your business relationship with us, you may provide your organization contact and financial details, such as name, postal address, telephone number, and email address and tax number.
You may also choose to submit information to us via other methods, including:
- General Communicationin response to our marketing campaigns or other communications, online and offline.
- Brand Communicationwhen reacting on social media, online forums or review websites.
- Special Offersthrough participation in an offer, program or promotion .
- Commercial Inquiryin connection with an actual or potential business relationship with us
- In-person meetingby giving us your business card or contact details at trade shows, meetup or other events
Information that we collect automatically on our Services.
- Browser and device data We collect technical details such as IP address, device type, operating system, browser name and version, screen resolution, device manufacturer and model, browser language and network provider;
- Usage data We may track browsing history and navigation on our services using data collection such as time spent on the pages, pages visited, links clicked and the pages that led or referred you to our services.
For these purpose, we developed our own tracking technology to ensure none of your Personal Data leaves our systems. Within this scope, we make sure to send anonymised or limited information to other 3rd party services, indicated below.
|Entity Name||Entity Type||Entity Country|
|Google Analytics||Web Analytics||United States|
|SessionStack||Web App Error Recording||European Union|
|Sentry||Error Tracking||United States|
How We Use Personal Data
Our products and services
Marketing and events-related communications
We may send you email marketing communications about Userpace products and services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with the consent requirements that are imposed by applicable law. When we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and, with your permission, include you on our marketing information campaigns.
You may see our ads on other websites or mobile apps because we participate in advertising networks. Ad networks allow us to target our messaging to users based on a range of factors, including demographic data, users’ inferred interests and browsing context (for example, the time and date of your visit to our Sites, the pages that you viewed, and the links that you clicked on). This technology also helps us track the effectiveness of our marketing efforts and understand if you have seen one of our advertisements.
We work with Google AdWords and other advertising networks. To learn how to opt out of behavioral advertising delivered by Network Advertising Initiative member companies, please visit the Network Advertising Initative. At the moment, there is no industry standard for recognizing Do Not Track browser signals, so we do not respond to them.
How We Disclose Personal Data
Userpace does not sell or rent Personal Data to marketers or unaffiliated third parties.
We only share your Personal Data with trusted entities, as outlined below.
Onvey (our Legal Entity, editing the Services)
We share Personal Data with other Onvey entities in order to provide our Services and for internal administration purposes.
We share Personal Data with a limited number of our service providers. We have service providers that provide services on our behalf, such as identity verification services, website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, and auditing services.
These service providers may need to access Personal Data to perform their services. We authorize such service providers to use or disclose the Personal Data only as necessary to perform services on our behalf or comply with legal requirements. We require such service providers to contractually commit to protect the security and confidentiality of Personal Data they process on our behalf. Our service providers are predominantly located in the European Union and the United States of America.
|Entity Name||Entity Type||Entity Country|
|Mailjet||Email Service Provider||France, European Union|
|Google LLC||Hosting Service Provider||European Union, United States|
|Intercom||Customer Service||United States|
We share Personal Data with third party business partners when this is necessary to provide our Services to our Users. Examples of third parties to whom we may disclose Personal Data for this purpose are banks and payment method providers (such as credit card networks) when we provide payment processing services, and the professional services firms (ie: Lawyers, Accountants or Auditors) that we partner with to deliver Userpace.
|Entity Name||Entity Type||Entity Country|
|PayPal / Braintree||Payment Provider||European Union, United States|
Our Users and third parties authorized by our Users
In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Data with third parties for the purpose of facilitating and completing the transaction.
Compliance and harm prevention
We share Personal Data as we believe necessary: (i) to comply with applicable law, or payment method rules; (ii) to enforce our contractual rights; (iii) to protect the rights, privacy, safety and property of Userpace, you or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.
We make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of Personal Data. We maintain organizational, technical and administrative measures designed to protect Personal Data within our organization against unauthorized access, destruction, loss, alteration or misuse. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure.
If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.
Product Security Measures
- 2-factor authentication (2FA)If you chose to signup using your Google or LinkedIn account, then you can and should turn on the 2-factor authentication (2FA).
- Password and Credential StorageWe enforce a password complexity standard and credentials are stored using a strong encryption protocol.
- UptimeWe have a 99% uptime or higher. You can check our services stats at https://userpace.doyoucheck.info/
- PermissionsWe enable permission levels within the app to be set for your teammates. Permissions can be set to include app settings, billing and user data.
Network and Application Security Measures
- Data Hosting and StorageUserpace services and data are hosted in Google Cloud Platform (GCP) facilities in the Europe, which encrypts all data at rest by default, in compliance with the Privacy Rule within HIPAA Title II.
- Private CloudAll of our servers are within our own virtual private cloud (VPC) with network access control lists (ACLs) that prevent unauthorized requests getting to our internal network.
- Back-upsAll our systems are automatically backed-up at least daily, using Google's solutions which guarantee the data integrity and their restoration procedures.
- MonitoringWe implemented various internal and external monitoring solutions, for continuous testing, troubleshooting and activity logs management (generation, audit, archive).
Userpace is served 100% over https.
All data sent to or from Userpace is encrypted in transit using 256 bit encryption.
Our Applications and APIs endpoints are TLS/SSL only and score an “A+" rating on Qualys SSL Labs‘ tests. This means we only use strong cipher suites and have features such as HSTS fully enabled.
Other Security Measures
- Employee Access, Permissions and Authentication
Your Personal Data is only accessible to a limited number of personnel who need access to the information to perform their duties.
Userpace runs a zero-trust corporate network. There are no corporate resources or additional privileges from being on Userpace's network.
We have Single Sign-on (SSO), 2-factor authentication (2FA) and strong password policies on GitHub, Google Services, Intercom and other Cloud Services to ensure protected access.
- Employee ConfidentialityAll employee contracts include a confidentiality agreement.
- Employee PoliciesUserpace has developed a comprehensive set of security policies covering a range of topics. These policies are updated frequently and shared with all employees.
- Office SecurityWhile no Personal Data should be made accessible offline, on hard-copies, or on employees devices, we relly on additional preventive security measures regarding our Offices and personnel access. Our building offers 24/7 guard and video surveillance, and only our employees with a personal access cards can access the office.
If you are a Userpace User, we retain your Personal Data as long as we are providing the Services to you. We retain Personal Data after we cease providing Services to you, even if you close your Userpace account, to the extent necessary to comply with our legal and regulatory obligations, and for the purpose of fraud monitoring, detection and prevention. We also retain Personal Data to comply with our tax, accounting, and financial reporting obligations, where we are required to retain the data by our contractual commitments to our financial partners, and where data retention is mandated by the payment methods that we support. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.
International Data Transfers
If you are located in the European Economic Area ("EEA") or Switzerland, we self-comply with applicable laws to provide an adequate level of data protection for the transfer of your Personal Data to the US.
You have choices regarding our use and disclosure of your Personal Data
1. Opting out of receiving electronic communications from us. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Services.
2. How you can see or change your account Personal Data. If You would like to review, correct, or update Personal Data that You have previously disclosed to us, You may do so by signing in to your Userpace account or by contacting us.
3. Your data protection rights. Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Data we control about you:
- Right to Withdraw ConsentWhere the processing of your Personal Data is based on your previously given consent, you have the right to withdraw your consent at any time.
- Exercise of the Rights of the Data SubjectAs described in this page;
- Right to Be InformedThe right to request confirmation of whether Userpace processes Personal Data relating to you.
- Right to AccessThe right to request a copy of that Personal Data;
- Right to RectificationThe right to request that Userpace rectifies or updates your Personal Data that is inaccurate, incomplete or outdated;
- Right to Erasure ("Right to be Forgotten")The right to request that Userpace erase your Personal Data in certain circumstances provided by law;
- Right to Restriction of ProcessingThe right to request that Userpace restrict the use of your Personal Data in certain circumstances, such as while Userpace considers another request that you have submitted (including a request that Userpace make an update to your Personal Data); and
- Right to Data PortabilityThe right to request that we export to another company, where technically feasible, your Personal Data that we hold in order to provide Services to you.
- Right to Object to ProcessingYou may also have the right to object to the processing of your Personal Data on grounds relating to your particular situation.
- Right to Object to Automated Individual Decision MakingThe right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
4. Process for exercising data protection rights. In order to exercise your data protection rights, you may contact Userpace as described in the Contact Us section below. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Data. If you feel that you have not received a satisfactory response from us, you may consult with the data protection authority in your country.
For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. If we no longer need to process Personal Data about you in order to provide our Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.