This policy also explains your choices about how we use information about you. Your choices include how you can object to certain uses of information about you and how you can access and update certain information about you.
Information Collection and Use
Nexcess collects the following personal information from you:
- All information you enter when you register for an account, create or modify your profile, set preferences, and sign-up for or make purchases through the Services;
- Contact information such as name, email address, mailing address, phone number;
- Billing and payment information such as billing address and credit card numbers;
- Unique identifiers such as user name, account number and password;
- Information about the Services you purchase from Nexcess;
- All information contained within your email correspondence with Nexcess including any ticket opened with Nexcess’ support department;
- All information entered on Nexcess’ website (including the Customer Portal);
- Access logs, including the source IP address, and browser information.
Nexcess uses this information to:
- Assess your needs to determine suitable products;
- Send you requested product or service information;
- Respond to customer service requests;
- Administer your account with Nexcess;
- Send you newsletters/whitepapers;
- Send you marketing communications;
- Respond to your questions and concerns;
- Improve the Nexcess website and marketing efforts;
- Conduct research and analysis;
- Offer surveys and contests to you;
- Analyze trends, administer the Nexcess website, track user movement and gather broad demographic information.
How You Can Access, Update or Delete Your Data
To easily access, view, update, delete or port your personal data (where available), or to update your subscription preferences, please sign into the Customer Portal. If you make a request to delete your personal data and that data is necessary for the products or services you have purchased, the request will be honored only to the extent it is no longer necessary for any Services purchased or required for Nexcess’ legitimate business purposes or legal or contractual record keeping requirements.
If you are unable for any reason to access, update or delete your personal data within the Customer Portal, you may contact us by one of the methods described in the “Contact Us” section below.
How We Secure, Store and Retain Your Data
Nexcess follows generally accepted standards to store and protect the personal data we collect, both during transmission and once received and stored, including utilization of encryption where appropriate. While we implement safeguards designed to protect your information, no security system is impenetrable and due to the inherent nature of the Internet, we cannot guarantee that data, during transmission through the Internet or while stored on our systems or otherwise in our care, is absolutely safe from intrusion by others. Nexcess strongly recommends that users configure SSL to prevent interception of data transmitted over networks and to restrict access to the databases and other storage points used.
We retain personal data only for as long as necessary to provide the Services you have requested and thereafter for a variety of legitimate legal or business purposes. These might include retention periods:
- mandated by law, contract or similar obligations applicable to our business operations;
- for preserving, resolving, defending or enforcing our legal/contractual rights;
- to allow Nexcess to offer you the opportunity to purchase additional or new services; or
- needed to maintain adequate and accurate business and financial records.
If you have any questions about the security or retention of your personal data, you can contact us at firstname.lastname@example.org.
Legal Bases for Processing (for EEA Users)
If you are an individual in the European Economic Area (“EEA”), Nexcess collects and processes information about you only where we have legal bases for doing so under applicable EU laws. This means that Nexcess collects and uses your information only where:
- Nexcess needs it to provide you the Services, including to operate the Services, provide customer support, personalized features and to protect the safety and security of the Services;
- It satisfies a legitimate interest (which is not overridden by your data protection interests), such as for research and development, to market and promote the Services and to protect Nexcess’ legal rights and interests;
- You give us consent to do so for a specific purpose; or
- We need to process your data to comply with a legal obligation.
If you have consented to Nexcess’ use of information about you for a specific purpose, you have the right to change your mind at any time, but this will not affect any processing that has already taken place. Where Nexcess is using your information because we or a third party have a legitimate interest to do so, you have the right to object to that use though, in some cases, this may mean no longer using the Services.
The E.U. – U.S. Privacy Shield Framework
Nexcess participates in, and has certified its compliance with, the EU-U.S. Privacy Shield Framework. Nexcess is committed to subjecting all personal data received from the EU in reliance on the Privacy Shield Framework, according to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, please visit the U.S. Department of Commerce’s Privacy Shield list: https://www.privacyshield.gov/list.
Nexcess is responsible for the processing of personal data it receives, under the Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. Nexcess complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Nexcess is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Nexcess may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://www.jamsadr.com/eu-us-privacy-shield. Under certain conditions, more fully described on the Privacy Shield website, you may invoke binding arbitration when other dispute resolution procedures have been exhausted: https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint.
Use of Subprocessors
Nexcess may use processors and subprocessors (including personnel and resources) in locations worldwide to help Nexcess with its business activities in providing the Services, offering customers new or additional goods and services and sending emails. A list of subprocessors is available upon request. If Nexcess subcontracts the performance of any of the Services, Nexcess will be liable to you for the acts and omissions of Nexcess subcontractors as if they were the acts or omissions of Nexcess under the agreement governing the Services (subject to the limits and exclusions of liability).
Additional Information for End Users
If end users of a Nexcess customer have any questions or complaints concerning Nexcess’ processing of personal data on behalf of a Nexcess customer, they are invited to contact the Nexcess customer directly, or they may contact Nexcess at email@example.com. End users who wish to access the personal data that Nexcess hosts on behalf of a customer, or to make choices concerning their data, are invited to contact the Nexcess customer directly.
As is true of most websites, Nexcess gathers certain information automatically and stores it in log files. This information includes Internet protocol (“IP”) addresses, browser type, Internet service provider (“ISP”), referring/exit pages, operating system, date/time stamp, and clickstream data. Nexcess uses this information, which does not identify individual users, to analyze trends, to administer Nexcess’ website, to track users’ movements around Nexcess’ website and to gather demographic information about our user base as a whole. Nexcess does not link this automatically collected data to personally identifiable information. Nexcess links some of this automatically collected data to personally identifiable information if you become a Nexcess customer.
Collection and Use of 3rd Party Personal Information
You may also provide Nexcess with personal information about other people, such as their name, date of birth, email address, mailing address and gender. This information is only used for the sole purpose of completing your request or for whatever reason it may have been provided.
Nexcess’ website offers a publicly accessible blog. You should be aware that any information you provide in these areas may be read, collected, and used by others who access the blog. To request removal of your personal information from Nexcess’ blog, contact us at firstname.lastname@example.org. In some cases, Nexcess may not be able to remove your personal information, in which case Nexcess will let you know if we are unable to do so and why.
Third Party Add-Ons
Social Media Widgets
Nexcess’ products and services are available for purchase only for those over the age of 18. Nexcess’ products and services are not targeted to, intended to be consumed by or designated to entice individuals under the age of 18. If you know of or have reason to believe anyone under the age of 18 has provided Nexcess with any personal data, please contact us.
Email Marketing and Opt-Out Preferences
Nexcess will periodically send you email advertisements regarding the services offered by Nexcess. Nexcess will not send you marketing messages if you have opted out. You may choose not to receive messages in the future by following the “unsubscribe” instructions located near the bottom of each email or by contacting Nexcess at email@example.com.
CAN-SPAM Act of 2003
Nexcess complies with the federal CAN-SPAM Act of 2003. As a result, please be aware that Nexcess uses the email address you provide to Nexcess in order to: (a) send information and respond to inquiries and/or other requests or questions; (b) process Customer orders and send information pertaining to Customer orders; (c) send you additional information related to the Services; and (d) send marketing emails or continue sending emails to our clients after the original transaction has occurred. In addition, Nexcess agrees to the following: (a) Nexcess will not use false or misleading subjects or email addresses; (b) Nexcess will identify the message as an advertisement in some reasonable way; (c) Nexcess will include the physical address of our business or site headquarters; (d) Nexcess will monitor third party email marketing services for compliance, if one is used; (e) Nexcess will honor unsubscribe requests promptly; and (f) Nexcess will allow users to unsubscribe by using the link at the bottom of each email advertisement
In certain situations, Nexcess may be required to disclose personal data in response to lawful requests by public authorities, including meeting national security or law enforcement requirements. In addition, if Nexcess is involved in a merger, acquisition, or sale of all its assets, Customer will be notified via email and/or prominent notice on the Nexcess website of any change in uses of your personal information, as well as any choices you may have regarding your personal information, to any other third party with your prior consent to do so.
We will respond to all requests, inquiries or concerns within thirty (30) days.
If you are based in the EEA, you have the right to lodge a complaint with a supervisory authority in the EU Member State of your habitual residence, place of work or place of the alleged infringement if you believe that our processing of your data infringes the GDPR.