You are sensitive about your personal information. At Catalytic, we are too.
As of July 24, 2019
A. Information directly and voluntarily provided to us.
If a User visits the Site, we may collect information the User provides to us when the User communicates with any of our departments such as customer service or technical services. If a User submits an inquiry to us regarding the Service through the Site, the User will be required to provide the User’s first and last name and email address. Users that sign up for our email mailing list will be required to provide their email address. Users may refuse to supply their information, however, it may prevent them from using certain features of the Site or Service.
B. Information automatically collected through the site.
We may automatically collect information about Users when they use the Site. For example, when Users access the Site through a computer, we will automatically collect information such as a User’s browser type and version, computer and connection information, IP address and standard web log information.
We may automatically collect information from Users when they use the Site through the use “cookies” and other similar technologies, such as web beacons. Cookies are small amounts of data that are stored within a computer’s Internet browser and that are accessed and recorded by the websites so that they can recognize the same browser navigating online at a later time.
Information that may be collected by cookies when Users use the Site may include, without limitation:
C. Information shared on third party websites or through social media services.
The Site may include links to third party websites and social media services where Users will be able to post comments, stories, reviews or other information. Use of these third party websites and social media services may result in the collection or sharing of information by these third party websites and social media services. The Company does not have access to or control over these third parties or the cookies, web beacons or other technology that these third parties may use. We are not responsible for the privacy practices of these third parties or the content on any third party website. We encourage Users to review the privacy policies and settings on the third party websites and social media services with which they interact to make sure they understand the information that may be collected, used, and shared by those third party websites and social media services.
D. Information collected by third party analytics Services.
E. Information provided to payment processors.
All payments made through the Service are processed by our third party providers. All information collected by these third party providers for purposes of processing payments is not available to us, unless a User has otherwise provided this information to us in connection with use of the Service.
F. Information prohibited.
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.
How we use the information we collect
We use the information we gather through the Service for the following purposes:
How we protect your information
We adopt appropriate data collection, storage and processing practices and security measures to protect against unauthorized access, alteration, disclosure or destruction of your personal information, username, password, transaction information and data stored on our Site. For more details on our security technical and organizational measures, see our Security page.
How long we hold your information
We will hold your information only for as long as required to deliver the Site or Service, as applicable, or as otherwise expressly agreed in the agreement for such Service or until requested by you to delete and, thereafter, the information is securely deleted.
Sharing information with third parties
We will disclose User information to our employees and agents with a need to know such information for purpose of delivering the Site and Service. Any vendors and suppliers (“Service Providers”) who provide certain services to us or on our behalf, such as specific functionality and integrations within the Service, may receive data as specified in the particular engagement for Service upon consent; you have the option to select which of these features and integrations to use.
These Service Providers will only have access to the information needed to perform these limited functions on our behalf.
Use of information outside a user’s country of residence
Compliance with Children’s Online Privacy Protection Act
Protecting the privacy of the very young is especially important. For that reason, we never collect or maintain information at our Site from those we actually know are under 13, and no part of our website is structured to attract anyone under age 18 or the applicable age of majority without involvement of a parent or guardian.
Your acceptance of these terms
By using this Site, you signify your acceptance of this policy. If you do not agree to this policy, please do not use our Site. Your continued use of the Site following the posting of changes to this policy will be deemed your acceptance of those changes.
Accessing, changing & managing your information
Users that are registered users of the Service may make changes to the information they have provided in connection with their accounts by logging in to their accounts and changing the applicable information. Users may also request changes to their information by contacting us as specified below under “Contacting Us.” Following receipt of a request from a User, we will take reasonable steps to update, correct or delete User information as requested.
Contacting us; complaints
If you feel we are not processing your data in accordance with GDPR, you may contact the ICO.
As of November 6, 2019
Catalytic processes Customer Data under the direction of our Customers and has no direct control or ownership of the personal data we process.
Use of the Catalytic Application
Our application allows Customers to process business data relating to various internal business needs. Catalytic processes our Customer’s information as they direct and in accordance with our agreements with our Customers.
We have no direct relationship with individuals who provide Personal Information to our Customers. Our Customers control and are responsible for correcting, deleting or updating information they have collected using Catalytic. We may work with our Customers to help them provide the notice to individuals about data collection, processing, and usage.
Our legal basis for collecting Personal Information from individuals is related to data processing necessary for the performance of an executed user agreement between the Customer and Catalytic.
Security of your Personal Information
We use a variety of security controls to protect your data. We ensure the Personal Information you provide to Catalytic is stored in a controlled, secure environment. All data, including Personal Information, is protected using appropriate physical, technical, and organizational measures. For more details on Security at Catalytic, including details on our SOC 2 Type 2 and HIPAA audits, see our Security page.
Catalytic Product Privacy
Catalytic utilizes cloud-based data centers, and our primary data centers and backup locations are located in the United States.
We use third parties to provide some functionality and integrations within the Catalytic platform. Customers have the choice to choose which of these features and integrations to use.
Information Automatically Collected
We may automatically collect information about users when they use the application. For example, when users access the application through a computer, we will automatically collect information such as a User’s browser type and version, computer and connection information, IP address and standard web log information.
We may automatically collect information from users when they use the application through the use “cookies” and other similar technologies, such as web beacons. Cookies are small amounts of data that are stored within a computer’s Internet browser and that are accessed and recorded by the websites so that they can recognize the same browser navigating online at a later time.
Information that may be collected by cookies when users use the application may include, without limitation:
Data Subject Requests
If you currently receive Catalytic emails regarding products and services and would like to unsubscribe from these communications, you may do so at any time. You may subscribe to these communications on our website, www.catalytic.com.
If you are a Catalytic user and provide us with your personal information, you have several rights with respect to that information. If you’d like to access, correct, amend, or delete data controlled by a Catalytic Customer, you may contact the Customer (the data controller), or you may submit your request below. As we are a data processor, we may need to communicate with the data controller to fulfill requests. We will respond to requests within 30 days.
If you feel we are not processing your data in accordance with GDPR, you may contact the ICO.
The data collected as part of the use of Catalytic is retained according to the agreements between the Customer and Catalytic. We will retain the personal data we process on behalf of our customers for as long as needed to provide services to our Customers. Catalytic will retain the personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
Data Protection Officer (DPO)
954 W Washington Blvd
Chicago, IL 60607