Effective on: 2019-02-18
1. Introduction and Scope
MadKudu Inc. ("MadKudu", "we," "us," "our") takes the protection of personal data ("PII") very seriously. This Privacy Notice (the "Notice") describes our processing of PII that we may receive from of our customers or business partners in our MadKudu platform. This Notice does not apply to PII we collect by other means, such as PII that we receive directly through MadKudu's own publicly accessible websites.
2. Controllership
In the context of this Notice, MadKudu acts as a data processor for the data we process.
3. Categories of PII
We may process the following types of PII:
4. How we Receive PII
We may receive PII in a variety of ways. For example:
5. Basis of Processing
Within the scope of this Notice, we will only process PII as instructed by our clients (the data controllers). When our engagement with a client ends, we will delete the PII submitted by that client within one month.
6. Purpose of Processing
The purposes for processing PII include:
7. Sharing PII with Third Parties
We share PII with third-party service providers that process PII on behalf of MadKudu. Such service providers include:
Our service providers may be located outside of the United States; however, we will require that those third parties maintain at least the same level of confidentiality that we maintain for such PII. MadKudu remains liable for the protection of PII that we transfer to our service providers, except to the extent that we are not responsible for the event giving rise to any unauthorized or improper processing.
Where such international PII transfers are regulated by the EU General Data Protection Regulation, we will transfer PII outside the European Economic Area (for example, to the United States of America, where MadKudu and some of our service providers are located) in compliance with the said Regulation.
In some cases, the European Commission may have determined that the data protection laws of some countries provide a level of protection equivalent to European Union law. You can see here the list of countries that the European Commission as recognized as providing an adequate level of protection to PII. We will only transfer PII to third parties in countries not recognized as providing an adequate level of protection to personal data when there are appropriate safeguards in place. One of the typical safeguards we implement with third parties are the Standard Contractual Clauses (“SCCs”) as approved by the European Commission under Article 46(2) of the Regulation. In compliance with the Schrems II judgment, MadKudu is continuously working on implementing supplementary measures as recommended by the European Data Protection Board in the agreements with its clients and service providers to enhance the protection of the transferred PII.
8. Other Disclosure of PII
We may disclose PII:
We reserve the right to use, transfer, sell, and share aggregated, anonymous data, which does not include any PII for any legal business purpose, such as analyzing usage trends and seeking compatible advertisers, sponsors, clients, and customers.
If we must disclose PII in order to comply with official investigations or legal proceedings initiated by governmental and/or law enforcement officials, we may not be able to ensure that such recipients of PII will maintain the privacy or security of said PII.
9. Access & Review
If you are a data subject about whom we store PII, you may have a right to request access to, and the opportunity to update, correct, or delete, such PII. You may also have the right to opt out of having your PII shared with third parties and to revoke your consent to our sharing your PII with third parties. You may also have the right to opt out if your PII is used for any purpose that is materially different from the purpose(s) for which it was originally collected or which you originally authorized. To submit such requests or raise any other questions, the affected data subjects should directly contact our client that submitted the PII to us.
10. Data Integrity & Security
MadKudu has implemented and will maintain technical, administrative, and physical measures that are reasonably designed to help protect PII from unauthorized processing, such as unauthorized access, disclosure, alteration, or destruction.
11. EU-U.S. and Swiss-U.S. Privacy Shield Frameworks
With respect to personal data processed within the scope of this Notice, MadKudu complies with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework (the "Privacy Shield"), as adopted and set forth by the U.S. Department of Commerce, regarding the collection, use, retention, and other processing of personal information transferred from the European Union/European Economic Area, the United Kingdom, and Switzerland to the United States in reliance on Privacy Shield. MadKudu commits to adhere to and has certified to the U.S. Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this Notice and the Privacy Shield Principles, the Privacy Shield Principles shall govern.
MadKudu relies upon the Standard Contractual Clauses as the transfer mechanism for the personal data transferred from the European Union/European Economic Area, the United Kingdom, and Switzerland to the United States, but continues to adhere to the Privacy Shield Program. MadKudu believes its commitment to the Privacy Shield Principles further demonstrates its commitment to data protection and security.
To learn more about the Privacy Shield, and to view MadKudu's certification, please visit https://www.privacyshield.gov and https://www.privacyshield.gov/participant?id=a2zt0000000TOH6AAO&status=Active, respectively.
12. Dispute Resolution
Where a privacy complaint or dispute cannot be resolved through MadKudu's internal processes, MadKudu has agreed to participate in the VeraSafe Privacy Shield Dispute Resolution Procedure. Subject to the terms of the VeraSafe Privacy Shield Dispute Resolution Procedure, VeraSafe will provide appropriate recourse free of charge to data subjects. To file a complaint with VeraSafe and participate in the VeraSafe Privacy Shield Dispute Resolution Procedure, please submit the required information here: https://www.verasafe.com/privacy-services/dispute-resolution/submit-dispute/
13. Binding Arbitration
If a dispute or complaint can't be resolved by us, nor through the dispute resolution program established by VeraSafe, data subjects may have the right to require that we enter into binding arbitration with the affected individual pursuant to the Privacy Shield's Recourse, Enforcement and Liability Principle and Annex I of the Privacy Shield.
14. Regulatory Oversight
MadKudu is subject to the investigatory and enforcement powers of the United States Federal Trade Commission.
15. Changes to this Privacy Notice
If we make any material change to this Notice, we will post the revised Notice to this web page and update the "Effective" date above to reflect the date on which the new Notice became effective.
16. Contact Us
If you have any questions about this Notice or our processing of PII, please contact our CPO Francis Brero by email at privacy@madkudu.com, by phone at +1 (203) 216-9872, or by postal mail at:
MadKudu Inc. Attn: Francis Brero 333 W Maude Ave., Suite 207, Sunnyvale, CA 94085 USA
Please allow up to four weeks for us to reply.
17. European Union Representative
We have appointed VeraSafe as our representative in the EU for data protection matters. While you may also contact us, VeraSafe can be contacted on matters related to the processing of PII. To contact VeraSafe, please use this contact form: https://www.verasafe.com/privacy-services/contact-article-27-representative/
Alternatively, VeraSafe can be contacted at:
VeraSafe Czech Republic s.r.o. Klimentská 46, Prague 1, 11002, Czech Republic