Last Updated: March 5, 2020
E.U. Model Clauses. Druva offers E.U. Model Clauses, also known as Standard Contractual Clauses, to meet the adequacy and security requirements for our Customers that operate in the E.U. and other international transfers of Customer data. To receive a copy of our standard Data Processing Addendum, incorporating Model Clauses, please email email@example.com.
Back to Top
Objecting to Processing. If you object to any processing by Druva, we will communicate such request to your employer as soon as we can.
Withdrawal of Consent. If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
Restriction of Processing. You can ask us to restrict further processing of your Personal Data.
Right to File Complaint. You have the right to lodge a complaint about Druva practices with respect to your Personal Data with the supervisory authority of your country or EU Member State. A list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en.
Additional Information or Assistance. From time to time, we may send you push notifications to perform administrator-initiated backups and restores and device decommissioning. If you wish to opt out of push notifications on your mobile device, please change your settings at the device level. To ensure you receive proper notifications, we will need to collect certain information about your device, such as operating system and user identification information.
Back to Top
- Applicability of this Policy
- Identifying the Data Controller and Data Processor
- Information We Collect and Receive
- Categories of Personal Data We Collect
- How We Use Information
- How We Share and Disclose Information
- inSync Mobile Application
- Data Retention
- Global Operations and E.U.-U.S. Privacy Shield and Swiss-U.S. Privacy Shield
- E.U. Data Subject Rights
- California Resident Rights
- Other State Law Privacy Rights
- Choice and Opt-out
- Personal Data About Children
- Changes to This Policy
- Email a Friend
- Blogs and Forums
- Social Media Widgets
- Data Protection Officer (DPO)
- Contacting Us
Applicability of this PolicyThis Policy applies to https://www.druva.com/ (“Site”) and services owned and operated by Druva. If you do not agree with the terms, do not access or use the Sites, services, or any other aspect of Druva’s business. By using or accessing the Sites or services in any manner, you acknowledge that you accept the practices and policies outlined in this Policy, and you hereby consent that we will collect, use, and share your information in the following ways. This Policy does not apply to any third-party applications or software that integrate with Druva’s services through the Druva platform or any other third-party products, services, or businesses. If you use the Site and services as part of an entity or organization that has a corporate account with Druva, like your employer or a university (“Customer”), that Customer may have entered into a separate agreement with Druva (“Customer Agreement”), which may contain more restrictive terms than what is described in this Policy. Back to Top
Identifying the Data Controller and Data ProcessorDruva acts as a data controller when we collect and process Personal Data (as defined below) for Druva’s legitimate interests, such as analyzing user interaction with our Site to enable the use of our Site. Druva acts as a data processor when we provide our products and services to our Customers. When acting as a data processor, Druva will only process Personal Data (as defined below) in accordance with a Customer’s instructions and this Policy. Druva’s affiliates or subsidiaries may also act as data controllers or data processors to the extent Customers purchase the product and services from those entities or Personal Data is shared with those entities. Back to Top
Information We Collect and ReceiveDruva may collect and receive Customer data and other information in various ways when you use our Site and services. We collect two types of information: Personal Data (defined below) and Aggregate Data. This Policy covers how we treat Personal Data that we gather when you access or use our Services. This Policy does not cover the practices of companies we do not own or control or people we do not manage. We may process Personal Data of our customers’ end users or employees in connection with our provision of certain services to our customers. This Policy applies only to Personal Data that we collect from you directly; if we did not collect data directly from you, you should contact the entity that collected your Personal Data in the first instance to address your rights with respect to such data. As used in this Policy, “Personal Data” means information that directly or indirectly identifies an individual, such as a name, email address, identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that individual, and also includes information referred to as “personally identifiable information” or “personal information” under applicable data privacy laws, rules, or regulations. “Personal Data” excludes Aggregate Data. As used in this Policy, “Aggregate Data” is anonymized information, learnings, logs, and data we collect about a group or category of services or users. Aggregate Data helps us understand trends in our users’ needs, so that we can consider new features or better tailor our services. This Policy in no way restricts or limits our collection and use of Aggregate Data. We may share Aggregate Data about our users with third parties for various purposes, including to help us better understand our Customers’ needs, improve our services, and for advertising and marketing purposes. We collect information you give us on our Site and when you register for and use our services. Examples include the following:
- Registration and Profile Information. When you register to use our services or update your profile, we may collect various kinds of information about you, including your name, email address, title, company and other profile information you provide, demographic information, and information you upload like photos, files, and documents.
- Contact Information. We collect the email addresses you provide for contacts you enter or upload into your private contacts page. When you choose to collaborate or share files with others, we also collect email addresses you provide to email invitations to those individuals on your behalf. When you provide us with personal information about your contacts, we will only use this information for the specific reason for which it is provided.
- Payment Information. If you choose to use a paid Druva account or service, our payment processing vendor collects your credit card information and billing address.
- Submissions and Customer Service. From time to time, we may use surveys, contests, or sweepstakes requesting personal or demographic information and Customer feedback. Participation in these surveys or contests is completely voluntary and thus, you have a choice whether or not to disclose this information.
- Automatically Collected Information. We automatically receive certain types of information when you interact with our Site, services, and communications. For example, it is standard for your web browser to automatically send information to every site you visit, including ours. That information includes your computer’s IP address, access times, your browser type and language, Internet service provider (ISP), and referring site addresses. We may also collect information about the type of operating system you use, your account activity, and files and pages accessed or used by you. We do not link this automatically-collected information to personal information.
- When You Download and Use Our Services. We automatically collect information on the type of device you use, operating system version, and the device identifier (“UDID”). We also access the device file storage for photos and contacts. You can opt out of this at the device level.
- Mobile Tracking and Data Loss Prevention (DLP). We do not ask for, access, or track any location-based information from your mobile device at any time, unless the DLP add-on is activated when using our mobile applications or services. A user must explicitly turn on the location information feature but may or may not be able to disable this feature depending on your employer’s policy.
- Mobile Analytics. We use mobile analytics software to allow us to better understand the functionality of our mobile software on your phone. This software may record information, such as how often you use the application, the events that occur within the application, aggregated usage, performance data, and from where the application was downloaded. We do not link the information we store within the analytics software to any personally identifiable information you submit within the mobile application.
- Local Storage (HTML5). We and our third-party partners use Local Storage (HTML5) to provide certain features on our Site, display advertising based on your web browsing activities, or store content information and preferences. Various browsers may offer their own management tools for removing HTML5.
Categories of Personal Data We CollectThe following chart details the categories of Personal Data that we collect and have collected over the past twelve (12) months. For each category of Personal Data, these subsections also set out our commercial or business purpose for collecting that Personal Data and the categories of third parties with whom we share that Personal Data.
|Category of Personal Data||Purposes of Use||Source of Personal Data||Categories of Third Parties To Whom We Disclose the Personal Data for Business Purposes|
|A.||Personal identifiers. Personal data collected: Name Email Address Phone Number IP address Postal Address||Provide the Sites and services Provide customer service Personalize your experience Improve the Sites and services Conduct marketing analysis Accomplish other purposes about which we notify you||You Third Parties||Service providers Our affiliates Other parties at your direction Parties which acquire your Personal Data through an acquisition or change of control of Druva|
|B.||Customer records identified by state law (including the California Customer Records statute (Cal. Civ. Code § 1798.80(e))). Personal data collected: Name Signature Job Title Company||Provide the Sites and services Provide customer service Personalize your experience Improve the Sites and services Conduct marketing analysis Accomplish other purposes about which we notify you||You||Service providers Our affiliates Other parties at your direction Parties which acquire your Personal Data through an acquisition or change of control of Druva|
|C.||Protected classification characteristics under state or federal law. Personal data collected: FOR APPLICANTS ONLY (Optional disclosure of): Gender Race Veteran status Disability status||Process employee applicants||You||Service providers Our affiliates Other parties at your direction Parties which acquire your Personal Data through an acquisition or change of control of Druva|
|D.||Commercial information. Personal data collected: Products or services purchased||Provide the Sites and services Provide customer service Personalize your experience Enable you to share and communicate with users you delegate Improve the Sites and services Conduct marketing analysis Accomplish other purposes about which we notify you||You|
|E.||Internet or other similar network activity information. Personal data collected: Information on a consumer’s interaction with Site Cookies Web Beacons Scripts Tracking tags||Provide the Sites and services Provide customer service Personalize your experience Improve the Sites and services Accomplish other purposes about which we notify you||You Third Parties|
|F.||Professional or employment-related information. Personal data collected: Job Title Company FOR APPLICANTS ONLY: Previous job history||Provide the Sites and services Provide customer service Process employee applicants Accomplish other purposes about which we notify you.||You|
How We Use InformationTo deliver a consistent and personalized user experience, Druva collects your personal information to understand your interests and requests. For example, we may use your personal information to:
- Facilitate your account administration and use of the operation of the Site and services;
- Process your request or assist you in completing a transaction;
- Provide you with information or services you request, including our product documentation and white papers;
- Inform you about other information, events, promotions, products, or services we find will be of interest to you;
- Contact you for feedback to enable us to develop, customize, and improve the Site and our publications, products, and services;
- Conduct marketing analysis, send you surveys or newsletters, contact you about services, products, activities, special events, or offers from Druva or our partners, and for other marketing, informational, product development, and promotional purposes;
- Send you a welcome email and contact you about your use of the Site and services; to respond to your emails, submissions, comments, requests, or complaints; to perform after-sales services; to anticipate and resolve problems with our service; to respond to Customer support inquiries, for assistance with our product and service development; and to inform you of updates to products and services from Druva that better meet your needs;
- Store contacts you enter or upload into your contacts list for your private use and viewing;
- Send emails to users you invite (and contacts you invite to become users) to collaborate and access your files;
- Enable you to communicate, collaborate, and share files with users you designate;
- Contact you if you win a contest; and
- Accomplish other purposes about which we notify you.
How We Share and Disclose InformationThis section describes how Druva may share and disclose Information. Customers determine their own policies and practices for the sharing and disclosure of Information, and Druva does not control how they or any other third parties choose to share or disclose Information. We disclose your Personal Data to service providers and other parties for the following business purposes:
- Aggregate or De-identified Data. Druva reserves the right to share aggregated demographic information about our Customers, sales, and traffic to our partners and advertisers. We will not share any of your personal information or any data that you store using our services to any third party, except as outlined in this Policy or with your consent.
- Service Providers. We may engage with service providers to perform business functions and provide services to us in the U.S. and other countries. For example, we use a variety of third-party services to help operate our services, such as processing your payment or offering live Customer support chat. Druva may share your Personal Data with these service providers on the condition that they use your Personal Data only on our behalf and pursuant to our instructions and are subject to obligations consistent with this Policy and any other appropriate confidentiality and security measures.
- Corporate Affiliates. Druva may share other information with its corporate affiliates, parent(s), or subsidiaries.
- when you provide such information directly to us, and
- when Personal Data about you is automatically collected in connection with your use of our Services.
- Third parties, when they provide us with Personal Data about you (“Third Parties”). Third Parties that share your Personal Data with us include:
- Service providers. For example, we may use analytics service providers to analyze how you interact and engage with the Services, or third parties may help us provide you with customer support.
- Social networks connected to the services. If you provide your social network account credentials to us or otherwise sign in to the Services through a third-party site or service, you understand some content and/or information in those accounts may be transmitted into your Account with us.
- Advertising partners. We receive information about you from some of our service providers who assist us with marketing or promotional services related to how you interact with our websites, applications, products, services, advertisements, or communications.
- We may also obtain personal information from publicly-available information and when Users voluntarily provide data about other companies and other people. Additionally, we may license data from other data providers which may contain personal information.
- Service providers, including:
- Payment processors;
- Ad networks;
- Security and fraud prevention consultants;
- Hosting and other technology and communications providers;
- Analytics providers; and
- Staff augmentation and contract personnel.
- Our affiliates.
- Parties who acquire your Personal Data through an acquisition or other change of control.
- Personal Data may be transferred to a third party if we undergo a merger, acquisition, bankruptcy, or other transaction in which that third party assumes control of our business (in whole or in part).
- Other parties at your direction.
- Other users (where you post information publicly or as otherwise necessary to effect a transaction initiated or authorized by you through the Services);
- Social media services, publicly-accessible blogs, and community forums (if you intentionally interact with them through your use of the Services);
- Third-party business partners who you access through the Services; and
- Other parties authorized by you.
inSync Mobile ApplicationOur inSync mobile application for Android allows end users to use a special permission BIND_DEVICE_ADMIN to permit administrators to securely and remotely delete data on lost or stolen devices. This feature is subject to enterprise administrator’s enablement and must be accepted by the end user. Back to Top
Data RetentionDruva will retain data, including Personal Data, in accordance with a Customer’s instructions, any applicable terms in the Customer Agreement, and as required by law. We may retain and use your information, even after your account is suspended or terminated, to pursue legitimate business interests, conduct audits, comply with (and demonstrate compliance with) legal obligations, resolve disputes, and enforce our agreements. We may further retain information in an anonymous or aggregated form. We do not retain geo-location information, except current known location when DLP service is activated. For more information on Druva’s data retention policies, please email firstname.lastname@example.org. Back to Top
SecurityDruva maintains appropriate technical and organizational safeguards to protect the security, confidentiality, and integrity of the information we collect from you, including any personal information. These safeguards are designed to prevent loss, misuse, and unauthorized access, disclosure, alteration, and destruction of the information we collect from you and our platform. Such measures include, but are not limited to, logical data segregation, data encryption in flight and at rest, network security, security logging and monitoring, envelope encryption model, and regular third-party penetration testing. For more information on Druva’s security protocols, please email email@example.com or review Druva’s security white papers at https://www.druva.com/resources/white-papers/. While we take reasonable efforts to guard personal information we knowingly collect directly from you, no security system is impenetrable. We cannot guarantee that any passively-collected personal information you choose to include in documents you store on our systems are maintained at adequate levels of protection to meet specific needs or obligations you may have relating to that information. For some customers, your account information and access to our service are accessible only through the use of an individual user ID and password. To protect the confidentiality of personal information, you must keep your password confidential and not disclose it to any other person. Always log out and close your browser when you finish your session. Please advise us immediately if you believe your password has been misused. Please note that we will never ask you to disclose your password in an unsolicited phone call or email. If you have any questions about the security of your personal information, please email firstname.lastname@example.org. Back to Top
Global Operations and E.U.-U.S. Privacy Shield and Swiss-U.S. Privacy ShieldWe operate globally and have offices, partners, and subprocessors around the world to deliver our services. When you use our Site and services, your collected information may be sent to and processed in countries outside your country of residence, including the U.S. For individuals residing in the European Economic Area (“EEA”), and for Personal Data (as defined below) subject to European data protection laws, this includes transfers outside of the EEA. Some of these countries may not have data protection laws that provide an equivalent level of data protection as the laws in your country of residence. If Druva transfers Personal Data (as defined below) originating from the European Union (E.U.) to other countries not deemed adequate under applicable data protection laws, we will deploy the following safeguards: E.U.-U.S. Privacy Shield and Swiss-U.S. Privacy Shield.
Druva is responsible for the processing of personal data it receives, under each Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. Druva complies with the Privacy Shield Principles for all onward transfers of personal data from the E.U., U.K. and Switzerland, including the onward transfer liability provisions.”
With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, Druva is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Druva may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.Under certain conditions, more fully described on the Privacy Shield website at https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted. If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at https://feedback-form.truste.
- A. Personal identifiers.
- B. Customer records identified by state law.
- D. Commercial information.
- Legitimate Interest: We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties.
- A. Personal identifiers.
- B. Customer records identified by state law.
- C. Protected classification characteristics under state or federal law.
- D. Commercial information.
- F. Internet or other similar network activity information.
- I. Professional or employment-related information.
- Operation and improvement of our business, products and Services;
- Marketing of our products and Services;
- Provision of customer support;
- Protection from fraud or security threats;
- Compliance with legal obligations; and
- Completion of corporate transactions.
- Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
- Other Processing Grounds: From time to time we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other data subjects, or if it is necessary for a task carried out in the public interest.
|Druva does not have access to the Customer data that is stored and processed by using our services. If you would like to access or correct inaccurate or incomplete Personal Data, please contact your employer. If your employer requests Druva to remove your Personal Data, we will respond to their request within 30 business days. Even if you request that we, or your employer, delete your personal information, we may still retain data collected from you in an aggregated and anonymized form.||If you would like to access or correct in accurate or incomplete Personal Data, please contact us at email@example.com and we will respond to your request within 30 business days. Even if you request that we delete your personal information, we may still retain data collected from you in an aggregated and anonymized form.|
|Druva does not have access to the Customer data that is stored using our services. If you would like to delete your Personal Data, please contact your employer.||You can request your Personal Data to be deleted by contacting us at firstname.lastname@example.org and we will respond to your request within 30 business days. Even if you request that we delete your personal information, we may still retain data collected from you in an aggregated and anonymized form.|
|Druva does not have access to the Customer data that is stored using our services. However, your employer can provide a means to download the information you have shared through our services.||If you would like to receive a copy of the personal information Druva has collected about you, please email email@example.com and we will respond to your request within 30 business days.|
California Resident RightsIf you are a California resident, you have the rights outlined in this section. If you are a California resident and there are conflicts between this section and any other provision of this Policy, the portion that is more protective of your Personal Data shall control. If you have any questions about this section or whether any of the following applies to you, please email firstname.lastname@example.org. Access. You have the right to request certain information about our collection and use of your Personal Data over the past 12 months. We will provide you with the following information:
- The categories of Personal Data that we have collected about you;
- The categories of sources from which that Personal Data was collected;
- The business or commercial purpose for collecting or selling your Personal Data;
- The categories of third parties with whom we have shared your Personal Data; and
- The specific pieces of Personal Data that we have collected about you.