42Peaks

Privacy Policy

Effective Date — 26th day of December, 2023

https://42peaks.co (the "Site") is owned and operated by 42Peaks Inc. 42Peaks Inc. is the data controller and can be contacted at:

+1 (302) 305-2748
hi@42peaks.co
1207 Delaware Ave #2748, Wilmington, DE 19806, USA

Purpose

The purpose of this privacy policy (this "Privacy Policy") is to inform users of our Site of the following:

  1. The personal data we will collect;
  2. Use of collected data;
  3. Who has access to the data collected;
  4. The rights of Site users; and
  5. The Site's cookie policy.

This Privacy Policy applies in addition to the terms and conditions of our Site.

GDPR

For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.

Consent

By using our Site users agree that they consent to the conditions set out in this Privacy Policy.

When the legal basis for us processing your personal data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing which we completed before you withdrew your consent unlawful.

You can withdraw your consent by contacting the Data Protection Officer.

Legal Basis for Processing

We collect and process personal data about users in the EU only when we have a legal basis for doing so under Article 6 of the GDPR. We rely on the following legal bases to collect and process the personal data of users in the EU:

  1. Users have provided their consent to the processing of their data for one or more specific purposes;
  2. Processing of user personal data is necessary for us or a third pary to pursue a legitimate interest. Our legitimate interest is not overriden by the interests or fundamenal rights and freedoms of users. Our legitimate interest(s) are: At 42peaks.co, our primary legitimate interest lies in ensuring the secure and appropriate use of our software products, particularly given their application in sensitive areas like healthcare and human resources. To achieve this, it is essential for us to collect a minimum amount of personal and corporate information from our users, including their email addresses. This information is crucial not only for basic communication and support but also to prevent misuse of our systems. By obtaining and verifying user details, we can maintain the integrity and security of our services, safeguarding both our interests and those of the users who rely on our software for critical functions. This practice is in line with our commitment to responsible and secure service delivery, ensuring that our products are used effectively and ethically in the industries we serve.; and
  3. Processing of user personal data is necessary for us to take, at the request of a user, steps before entering a contract or for the performance of a contract to which a user is a party. If a user does not provide the the personal data necessary to perform a contract the consequences are as follows: when a user chooses not to provide their personal data, it directly impacts our ability to fulfill the contractual obligations at 42peaks.co. Our services, especially in sectors like healthcare and HR, necessitate the collection of certain personal and corporate information not only for operational functionality but also for compliance with regulatory standards. Without this essential data, we are unable to activate or maintain a user's account, as the absence of such information compromises the security and integrity of our service delivery. It also hinders our ability to provide personalized support, updates, and ensure proper use of our systems. Therefore, while we respect the privacy and choices of our users, the lack of necessary personal data means we cannot extend our services under the agreed contractual terms. This policy is in place to maintain the high standards of service and security that our users expect from us.

Personal Data We Collect

We only collect data that helps us achieve the purpose set out in this Privacy Policy. We will not collect any additional data beyond the data listed below without notifying you first.

Data Collected in a Non-Automatic Way

We may also collect the following data when you perform certain functions on our Site:

  1. First and last name;
  2. Email address;
  3. Phone number;
  4. Address; and
  5. Autofill data.

This data may be collected whenever the User signs up, or fills our contact form.

How We Use Personal Data

Data collected on our Site will only be used for the purposes specified in this Privacy Policy or indicated on the relevant pages of our Site. We will not use your data beyond what we disclose in this Privacy Policy.

The data we collect when the user performs certain functions may be used for the following purposes:

  1. Communication;
  2. User-account provisioning; and
  3. Contract creation and execution.

Who We Share Personal Data With

Employees

We may disclose user data to any member of our organization who reasonably needs access to user data to achieve the purposes set out in this Privacy Policy.

Other Disclosures

We will not sell or share your data with other third parties, except in the following cases:

  1. If the law requires it;
  2. If it is required for any legal proceeding;
  3. To prove or protect our legal rights; and
  4. To buyers or potential buyers of this company in the event that we seek to sell the company.

If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.

How Long We Store Personal Data

User data will be stored until the purpose the data was collected for has been achieved. You will be notified if your data is kept for longer than this period.

How We Protect Your Personal Data

All personal data is only ever seen/used by our co-founders (2 people). Our analytics system - powered by Plausible - does not record any personal user data or use cookies for state persistence. All data which users enter into any form, is encrypted during transit and at rest with strictly controlled and audited access.

While we take all reasonable precautions to ensure that user data is secure and that users are protected, there always remains the risk of harm. The Internet as a whole can be insecure at times and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.

International Data Transfers

We transfer user personal data to the following countries:

  1. United States of America; and
  2. India.

When we transfer user personal data we will protect that data as described in this Privacy Policy and comply with applicable legal requirements for transferring personal data internationally.

If you are located in the United Kingdom or the European Union, we will only transfer your personal data if:

  1. The country your personal data is being transferred to has been deemed to have adequate data protection by the European Commission or, if you are in the United Kingdom, by the United Kingdom adequacy regulations; or
  2. We have implemented appropriate safeguards in respect of the transfer. For example, the recipient is a party to binding corporate rules, or we have entered into standard EU or United Kingdom data protection contractual clauses with the recipient.

Your Rights as a User

  1. Right to be informed;
  2. Right of access;
  3. Right to rectification;
  4. Right to erasure;
  5. Right to restrict processing;
  6. Right to data portability; and
  7. Right to object.

Children

We do not knowingly collect or use personal data from children under 16 years of age. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data their parent or guardian may contact our data protection officer.

How to Access, Modify, Delete, or Challenge the Data Collected

If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please contact our data protection officer here:

Shreyansh Pandey
+1 (302) 305-2748
s@42peaks.co
1207 Delaware Ave #2748, Wilmington, DE 19806, USA

Do Not Track Notice

Do Not Track ("DNT") is a privacy preference that you can set in certain web browsers. We do not track the users of our Site over time and across third party websites and therefore do not respond to browser-initiated DNT signals.

How to Opt-Out of Data Collection, Use or Disclosure

In addition to the method(s) described in theHow to Access, Modify, Delete, or Challenge the Data Collectedsection, we provide the following specific opt-out methods for the forms of collection, use, or disclosure of your personal data specified below:

You can opt-out of the use of your personal data for marketing emails. You can opt-out by you can click on the link sent in every marketing email, or you can get your contact details completely deleted from all of our systems (if you are a user/client) by emailing us at hi@42peaks.co.

Cookie Policy

A cookie is a small file, stored on a user's hard drive by a website. Its purpose is to collect data relating to the user's browsing habits. You can choose to be notified each time a cookie is transmitted. You can also choose to disable cookies entirely in your internet browser, but this may decrease the quality of your user experience.

We do not use cookies on our Site.

Modifications

This Privacy Policy may be amended from time to time in order to maintain compliance with the law and to reflect any changes to our data collection process. When we amend this Privacy Policy we will update the "Effective Date" at the top of this Privacy Policy. We recommend that our users periodically review our Privacy Policy to ensure that they are notified of any updates. If necessary, we may notify users by email of changes to this Privacy Policy.

Complaints

If you have any complaints about how we process your personal data, please contact us through the contact methods listed in the Contact Information section so that we can, where possible, resolve the issue. If you feel we have not addressed your concern in a satisfactory manner you may contact a supervisory authority. You also have the right to directly make a complaint to a supervisory authority.

Contact Information

If you have any questions, concerns or complaints, you can contact our data protection officer, Shreyansh Pandey, at:

Shreyansh Pandey
+1 (302) 305-2748
s@42peaks.co
1207 Delaware Ave #2748, Wilmington, DE 19806, USA