(2) Information We Collect
We collect information that you give us or that we get from your use of our Sites and Services, including without limitation, the following categories:
- email addresses;
- telephone numbers;
- financial data relating to orders;
- IP Addresses;
- log files;
- CV and and other information when applying to work with us through our Careers page; and
- We may also collect information about you when we undertake analysis of your interaction with us from cookies and tracking devices on your devices where you have permitted their use.
Platform.sh provides tools to make your development workflow more productive, such as our command-line interface (CLI). Also, Platform.sh will occasionally provide application-specific modules or libraries, which you may opt into, for integration into your software project in order to make its configuration simpler. Such applications, libraries, or modules may report usage information to us, which we may collect. Information collected may contain the type of actions performed, log data of API activity, as well as configuration information. This information may be linked to you, and we may use this information to better provide technical support to you and to improve our Services. We do not explicitly collect any special categories of personal data or sensitive personal information through our Sites and Services. However, we may collect special categories of personal data or sensitive personal information if you have signed up to attend a conference hosted by Platform.sh and have explicitly consented to the processing of your data regarding dietary restrictions or disability accommodations.
Cookies are small pieces of data stored on your device (computer or mobile device). Cookies can be used to provide you with a tailored user experience and to make it easier for you to use a site upon a future visit. When used, cookies are downloaded and stored on your device. Such information, on its own, will not identify you personally. It is statistical data. You have the option to accept all cookies, accept some cookies while rejecting others, or reject them all. Rejecting functional cookies may prevent you from using certain portions or functionalities of our sites and Services. We may use such cookies to deliver and improve our Services. Some third-party services that we use to improve the Services (including usage, measuring performance, and advertising), such as Google Analytics, may also place cookies on your device. Examples of Cookies we use:
- Strictly Necessary Cookies. These cookies are necessary for the website to function and cannot be switched off in our systems.
- Performance & Analytic Cookies. These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our Sites.
- Functional Cookies. These cookies enable the website to provide enhanced functionality and personalization.
- Advertising Cookies. These cookies deliver and measure the effectiveness of our marketing campaigns and may be set through our site by our advertising partners.
- Social Media Cookies. These cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks.
The validity period of cookies for our sites and Services is 6 months. We will request a new prior consent after this period.
Urchin Tracking Module ("UTM") tags are distinct from cookies as defined above. UTM works as a custom Uniform Resource Locator (“URL”) parameter for marketing campaigns and reports can be viewed in platforms like Google Analytics. UTM tags are appended as part of the visible URL in marketing programs to understand the specific instance of a link. UTM tag reports are observed in Google Analytics or Marketo to better understand how our visitors are getting to our websites, and as such, who our visitors are. Such data is collected at an aggregate level, and will not identify you personally. Customizing the URL with UTM tags allows us to better understand marketing activity, which then allows us to better serve our customers and audience.
As part of this process, non-identifying and non-profiling information (source, medium, campaign, and Click ID), will be stored in your browser in local storage. No Personally Identifiable Information (“PII”) or personal data will be stored. This information would only be used by Platform.sh if you sign up for and consent to our service. At that point in time, campaign attribution information would be made available to Platform.sh to gauge the effectiveness of the campaign. You may clear your browser cache prior to signing up for our service to opt out.
You can manage your cookies preference in our Cookies dashboard. For any questions on cookies or UTM opt-outs, or about our policy listed here, please contact us.
(4) How We Use Your Information
We use the information we collect from you to provide, maintain, protect, and improve our Sites and Services, and to develop new ones.
In addition, we may use the information for one or more of the following purposes:
- To provide information that you request from us relating to our products or Services;
- To provide information related to products or Services provided by us;
- To inform you of any changes, offers, updates, or other announcements about our Services when you have opted-in;
- To allow you to participate in interactive features of our Services when you choose to do so;
- To provide customer support;
- To gather analysis or valuable information so that we can improve our Services;
- To monitor the usage of our Services and Sites;
- To better provide technical support to you and to improve our Services and Sites;
- To detect, prevent, and address technical issues;
- To provide you with new Services offers and relevant Services information and events unless you have opted not to receive such information. We will never send Users or visitors commercial offers unrelated to our Services; and
- To detect, prevent, and address fraud and/or abuse of our products or Services.
(5) Why we process your personal information
We may process your personal information because:
- We need to provide a requested Service and honor our contractual obligations with you;
- You have given us permission to do so;
- The processing is in our legitimate interest and it is not overridden by your rights;
- For payment processing purposes; and
- To comply with applicable law.
(6) Disclosing Your Personal Information
Our Affiliates and Subsidiaries: To provide the Services and for any of the purposes identified above.
When we have your consent: We may disclose personal information if we have your specific consent to do so, where you have expressly opted-in/consented to the disclosure of your personal data for a specific purpose. If you wish to withdraw this consent, please contact us. For existing customers, please file a support ticket.
Legal: We will share personal information with our regulators, law enforcement, or fraud prevention agencies, as well as legal advisers, and courts, if we have a good-faith belief that access, use, preservation, or disclosure of the information is reasonably necessary to:
- comply with legal obligations, meet applicable laws, regulations, or legal processes, or abide by enforceable governmental requests (however, we will use reasonable efforts to provide notice to Platform.sh’s customers when we receive a request for customer personal data unless Platform.sh is explicitly prohibited from doing so by applicable laws);
- enforce applicable Terms of Service or any of our other agreements with you, including investigation of potential breaches;
- detect, prevent, or otherwise address fraud, security, or technical issues in connection with the Services;
- protect against harm to the rights, property, liability, or safety of Platform.sh, our Users, customers and our employees, or the general public, as required or permitted by law;
- prevent an emergency when a person is at risk of potential imminent death or serious physical injury, and Platform.sh may have personal data necessary to prevent such emergency;
- protect against apparent instances of child exploitation or missing children detected on Platform.sh’s services;
Succession: If we are involved in a merger, acquisition, asset sale, restructuring or reorganization with prospective buyers or sellers of such business or assets.
All information you disclose in your public profile, forum posts, blogs, comments, issue queues, or other public portions of our Services becomes public information. Please be careful about what you choose to disclose publicly.
(7) Your Data Protection Rights Under GDPR, Canada’s PIPEDA, and California's Consumer Privacy Act
Your Rights Under GDPR:
If you are a resident of the European Economic Area, you have certain data protection and privacy rights. In certain circumstances, you have the following privacy rights:
- The right to access the information we have on you.
- The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete.
- The right of deletion. You can request us to delete the personal information we hold about you. Please note that this is not an absolute right and we might need to retain your personal information for compliance with laws or other legitimate reasons.
- The right to object. You have the right to object to our processing of your personal information.
The right of restriction. You have the right to request that we restrict the processing of your personal information.
- The right to data portability. In certain circumstances, You have the right to be provided with a copy of the information we have on you in a structured, machine-readable, and commonly used format.
- The right to withdraw consent. You also have the right to withdraw your consent at any time when Platform.sh relies on your consent to process your personal information, though we may have other lawful bases for processing your information for other purposes, such as those set above.
- The right not to be subject to automated decisions including profiling. You have the right not to be subject to a decision based solely on an automated process, including profiling, which produces legal effects concerning you or similarly significantly affects you.
- Please note that we may ask you to verify your identity before responding to such requests.
Your Rights Under Canada’s PIPEDA (Privacy Rights):
The Personal Information Protection and Electronic Documents Act (‘PIPEDA’) is the Canadian federal privacy law that regulates how private-sector organizations handle personal information in the course of commercial activity.
Platform.sh continuously strives to comply with PIPEDA Principles. We have procedures in place to receive and respond to any complaints and inquiries you may have. Contact us or email our Data Protection Officer at email@example.com. For existing customers, please file a support ticket. If you are a resident of Canada you have certain privacy rights:
Your rights under California Privacy Laws.
The California Consumer Privacy Act (‘CCPA’) and the California Privacy Rights Act (‘CPRA’), (together ‘California Privacy Laws’), give California consumers/residents (or your authorized agent) certain privacy rights and impose corresponding, and independent, obligations on businesses processing California consumers’ personal information.
Platform.sh does NOT sell your personal information. We do NOT collect sensitive personal information as defined under California Privacy Laws. Where applicable, we have added contractual requirements instructing our service providers to not further collect, sell, share, or use the consumers’ personal information except as necessary to perform their respective business purpose. If you are a resident of California you have certain privacy rights:
- Right to delete. You have the right to request us to delete your personal information and to tell our service providers to do the same. However, there are many exceptions that allow businesses to keep your personal information. Please note that this is not an absolute right and we might need to retain your personal information for compliance with laws or other legitimate reasons.
- Right to Correct. You have the right to request that we correct any inaccurate personal information about you.
- Right to portability. You have the right to receive your personal information in a portable and, to the extent technically feasible, readily usable format.
- Right to opt-out of sale or sharing. Platform.sh does not sell or share your personal information within the meaning of California Privacy Laws.
- Right not to be discriminated against for exercising any of your rights. We do not use financial incentive practices that are unjust, unreasonable, coercive, or usurious, and do not retaliate against those who choose to exercise their rights.
- Right to Limit Use and Disclosure of Sensitive PI. You have the right to direct that we limit the use of sensitive PI to the use that is reasonably necessary to perform the services expected by you. We do not collect sensitive personal information as defined under the CCPA.
- Right to Opt-in for Children: Business Obligation Not to Sell or Share Children’s PI unless there is Affirmative Authorization. We do not sell or share personal information as defined under the CCPA nor do we (knowingly) collect children's personal information.
(8) Accessing and Updating Your Personal Information
Whenever made possible on your account settings, you can access, update, or request deletion of your personal information and data we held about you directly within your account settings section. Please also file a support ticket to confirm any account changes, or contact us to assist you. If you are unable to perform these actions yourself (e.g. you don’t have an account), please contact us using the various methods detailed below to assist you. For customers located in Australia, you may also email "firstname.lastname@example.org".
(9) Storing, Securing, and Transfer of your Personal Data and Information
We take all reasonable measures to protect your personal data and information from unauthorized access to, or unauthorized alteration, disclosure or destruction of, information we maintain. To maintain your trust, we’ve achieved several independently audited industry certifications, ensuring your data is handled with appropriate care and according to industry standards. You can find more information here. We also use physical, organizational, and technological methods and policies to protect and safeguard your personal information. For more on our security, please visit https://platform.sh/trust-center/.
We may transfer personal data outside the European Economic Area (EEA) to countries with and without an EU adequacy decision to enable customers to rapidly deploy projects in any geographical region. Customer name, email, and ssh keys may be transferred from the Platform.sh Accounts portal located in Ireland to clusters in France, Ireland, USA, Australia, Canada, the UK, and Germany using securely encrypted transfer channels (TLS) and encrypted at rest. We transfer this data to companies that are GDPR compliant. Platform.sh signs Data Processing Agreements (DPAs) or Standard Contractual Clauses (SCCs) with all processors, and has replaced vendors who fail security, compliance, or privacy assessments. We also conduct Supplementary Measures Assessments on vendors who store personal data in non-adequate countries.
(10) Data Breaches
We will report any unlawful data breaches to any and all relevant persons and authorities within 72 hours (or sooner if it is required under applicable privacy laws) of the breach when such breach is likely to result in a high risk to the rights and freedoms of data subjects. Platform’s obligation to report or respond to a personal data breach or security incident will not be construed as an acknowledgement by Platform.sh of any fault or liability with respect to the personal data breach or security incident. Should you have any complaint about a breach, or the way in which we will handle a breach, please contact us.
(11) Third-party Links
Our Services may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party's site. We do not endorse these sites, nor are we responsible for the content or accuracy of any information contained on them. We strongly advise you to review the privacy policies of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
(12) Children’s Privacy
To the extent prohibited by applicable law, our Service does not address anyone under the age of 16 (“Children”). By agreeing to our Terms of Service, you represent that you are the age of majority in your state, province, or country of residence, or 16 years of age, whichever is greater. We do not knowingly collect personally identifiable information from children. If you are a parent or guardian and you are aware that your children have provided us with personal information, please contact us. If we become aware that we have collected personal information from children without verifiable verification of parental consent, we will take steps to delete that information from our databases and servers.
(13) About Us
Platform.sh has a designated Data Protection Officer who is accountable for the management of your personal information, including collection, usage, disclosure, retention, and transfer of personal information to third parties for processing. All privacy issues, compliance requests, inquiries, and other requests will be handled by our French parent company, Platform.sh SAS.
(14) Contact Us
Sites visitors have the following options for correcting personal information or removing their information from our database in order to discontinue future communications from Platform.sh.
- Click on the “Unsubscribe” link on any Platform.sh email
- Contact us using our website contact form
- Send a request by mail to: Attention Legal, Platform.sh, 22 rue de Palestro , Paris, 75002, France.
Should you deem that we have not satisfactorily handled your request or you have a complaint, you have the right to contact your local Data Protection Authority (or Attorney General). Our GDPR Supervisory Authority is the Commission Nationale de l'Informatique et des Libertés. Platform.sh is also registered with the Information Commissioner's Office in the United Kingdom and the Office of the Australian Information Commissioner.
This policy was last reviewed and updated: March 2023